Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

Astromenda detected by Malwarebytes


  • This topic is locked This topic is locked
9 replies to this topic

#1 Dizzy24

Dizzy24

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Baltimore
  • Local time:11:30 PM

Posted 16 October 2014 - 02:16 PM

I noticed a game on my desktop that I know was not downloaded by me. When I checked my programs list in the control panel the game was not listed but I had the WSE Astromenda file on my list. I then ran malwarebytes and avast to check the computer. Malwarebytes found it and quarantined the files. I have also uninstalled the "program" file via the programs list.  I then reset the internet options back to default. I wanted to double check that I was able to remove this in its entirety. When searching through my internet programs, it looks as though only internet explorer was going to the astromenda page and my google chrome had not yet been affected by this redirect.

Below is the dds file and the attach file is also included in this post. If you need any other files please let me know.

Thank you!

DDS (Ver_2012-11-20.01) - NTFS_AMD64 

Internet Explorer: 11.0.9600.17344  BrowserJavaVersion: 11.20.2
Run by Chrissy at 15:01:35 on 2014-10-16
Microsoft Windows 7 Professional   6.1.7601.1.1252.1.1033.18.6143.4028 [GMT -4:00]
.
AV: avast! Antivirus *Enabled/Updated* {17AD7D40-BA12-9C46-7131-94903A54AD8B}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
SP: avast! Antivirus *Enabled/Updated* {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\system32\atieclxx.exe
C:\Program Files\Dell\DellDock\DockLogin.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\AvastSvc.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
c:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe
C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
C:\Program Files\Bonjour\mDNSResponder.exe
C:\Windows\system32\taskhost.exe
C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
C:\Program Files (x86)\Coupons\CouponPrinterService.exe
C:\Windows\system32\spool\DRIVERS\x64\3\dleaserv.exe
C:\Windows\system32\dleacoms.exe
C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\SearchIndexer.exe
C:\Windows\System32\WUDFHost.exe
C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe
C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe
C:\Users\Chrissy\AppData\Local\Apps\2.0\YK8PCHXX.540\1ZKYKQYO.GAB\dell..tion_0f612f649c4a10af_0005.000a_17ece8424e43daec\DellSystemDetect.exe
C:\Program Files\Logitech\SetPoint\SetPoint.exe
C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
C:\Program Files\AVAST Software\Avast\avastui.exe
C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe
C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files\Dell\DellDock\DellDock.exe
C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE
C:\Program Files\iPod\bin\iPodService.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.google.com/
uSearch Bar = Preserve
uSearchMigratedDefaultURL = hxxp://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
mStart Page = hxxp://search.coupons.com/
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.8.0_20\bin\ssv.dll
BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Windows Live Messenger Companion Helper: {9FDDE16B-836F-4806-AB1F-1455CBEFF289} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
BHO: Skype Click to Call for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre1.8.0_20\bin\jp2ssv.dll
uRun: [DellSystemDetect] C:\Users\Chrissy\AppData\Local\Apps\2.0\YK8PCHXX.540\1ZKYKQYO.GAB\dell..tion_0f612f649c4a10af_0005.000a_17ece8424e43daec\DellSystemDetect.exe
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [Dell Webcam Central] "C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe" /mode2
mRun: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
mRun: [AvastUI.exe] "C:\Program Files\AVAST Software\Avast\AvastUI.exe" /nogui
mRun: [VERIZONDM] "C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe" /P VERIZONDM
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
StartupFolder: C:\Users\Chrissy\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\DELLDO~1.LNK - C:\Program Files\Dell\DellDock\DellDock.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\LOGITE~1.LNK - C:\Program Files\Logitech\SetPoint\SetPoint.exe
uPolicies-Explorer: NoDrives = dword:0
mPolicies-Explorer: NoDrives = dword:0
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: PromptOnSecureDesktop = dword:0
IE: {0000036B-C524-4050-81A0-243669A86B9F} - {B63DBA5F-523F-4B9C-A43D-65DF1977EAD3} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
IE: {92780B25-18CC-41C8-B9BE-3C9C571A8263} - {FF059E31-CC5A-4E2E-BF3B-96E929D65503}
Trusted Zone: dell.com
DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089} - hxxp://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} - hxxp://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
DPF: {166B1BCA-3F9C-11CF-8075-444553540000} - hxxp://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: {6F6FDB9E-5072-498C-BCB0-2B7F00C49EE7} - hxxp://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} - hxxp://download.eset.com/special/eos/OnlineScanner.cab
DPF: {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} - hxxp://zone.msn.com/bingame/chnz/default/mjolauncher.cab
DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} - hxxp://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {9AA73F41-EC64-489E-9A73-9CD52E528BC4} - hxxp://zone.msn.com/binGame/ZAxRcMgr.cab
DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.7.0/jinstall-1_7_0_21-windows-i586.cab
DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} - hxxp://zone.msn.com/bingame/popcaploader_v10.cab
DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - hxxp://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
TCP: NameServer = 192.168.1.1
TCP: Interfaces\{AE2C4D32-B7E0-4BF6-A72F-AC056B001E41} : DHCPNameServer = 192.168.1.1
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
Notify: FastAccess - C:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll
SSODL: WebCheck - <orphaned>
mASetup: {8A69D345-D564-463c-AFF1-A69D9E530F96} - "C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\Installer\chrmstp.exe" --configure-user-settings --verbose-logging --system-level --multi-install --chrome
x64-mSearch Bar = hxxp://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
x64-BHO: avast! Online Security: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Skype Click to Call for Internet Explorer: {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-BHO: {DBC80044-A445-435b-BC74-9C25C1C588A9} - <orphaned>
x64-Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
x64-Run: [dleamon.exe] "C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe"
x64-Run: [EzPrint] "C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe"
x64-Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXE
x64-IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - <orphaned>
x64-Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - <orphaned>
x64-Notify: LBTWlgn - c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll
x64-SSODL: WebCheck - <orphaned>
.
============= SERVICES / DRIVERS ===============
.
R0 aswRvrt;avast! Revert;C:\Windows\System32\drivers\aswRvrt.sys [2014-2-9 65776]
R0 aswVmm;avast! VM Monitor;C:\Windows\System32\drivers\aswVmm.sys [2014-2-9 224896]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2010-2-1 55280]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswsnx.sys [2014-2-9 1041168]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswsp.sys [2014-2-9 427360]
R2 AdobeActiveFileMonitor7.0;Adobe Active File Monitor V7;C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe [2008-12-8 169312]
R2 AERTFilters;Andrea RT Filters Service;C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe [2010-2-2 92160]
R2 AllShare Framework DMS;AllShare Framework DMS;C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [2013-12-21 404360]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2014-8-28 203264]
R2 aswHwid;avast! HardwareID;C:\Windows\System32\drivers\aswHwid.sys [2014-5-21 29208]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2014-2-9 79184]
R2 aswStm;aswStm;C:\Windows\System32\drivers\aswstm.sys [2014-2-9 92008]
R2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2014-7-14 50344]
R2 c2cautoupdatesvc;Skype Click to Call Updater;C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [2014-7-14 1390176]
R2 c2cpnrsvc;Skype Click to Call PNR Service;C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [2014-7-14 1767520]
R2 CouponPrinterService;Coupon Printer Service;C:\Program Files (x86)\Coupons\CouponPrinterService.exe [2014-2-13 177136]
R2 dlea_device;dlea_device;C:\Windows\System32\dleacoms.exe -service --> C:\Windows\System32\dleacoms.exe -service [?]
R2 dleaCATSCustConnectService;dleaCATSCustConnectService;C:\Windows\System32\spool\drivers\x64\3\dleaserv.exe [2010-2-10 33448]
R2 DockLoginService;Dock Login Service;C:\Program Files\Dell\DellDock\DockLogin.exe [2009-6-9 155648]
R2 Samsung Link Service;Samsung Link Service;C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [2013-6-3 609632]
R2 SftService;SoftThinks Agent Service;C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe [2010-2-1 656624]
R2 sprtsvc_verizondm;SupportSoft Sprocket Service (verizondm);C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe [2010-9-2 206120]
R2 TeamViewer6;TeamViewer 6;C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2010-12-23 2228008]
R2 tgsrvc_verizondm;SupportSoft Repair Service (verizondm);C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe [2010-9-2 185640]
R3 OA002Afx;Provides a software interface to control audio effects of OA002 camera.;C:\Windows\System32\drivers\OA002Afx.sys [2007-6-8 219544]
R3 OA002Ufd;Creative Camera OA002 Upper Filter Driver;C:\Windows\System32\drivers\OA002Ufd.sys [2008-6-3 168864]
R3 OA002Vid;Creative Camera OA002 Function Driver;C:\Windows\System32\drivers\OA002Vid.sys [2008-8-1 306560]
R3 RLDesignVirtualAudioCableWdm;Live! Cam Virtual;C:\Windows\System32\drivers\livecamv.sys [2014-3-27 49664]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2011-6-10 539240]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2013-9-11 105144]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2013-9-11 124088]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-10-23 172192]
S3 FACAP;facap, FastAccess Video Capture;C:\Windows\System32\drivers\facap.sys [2008-8-2 243840]
S3 fssfltr;fssfltr;C:\Windows\System32\drivers\fssfltr.sys [2012-7-2 48488]
S3 fsssvc;Windows Live Family Safety Service;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2012-3-8 1492840]
S3 IEEtwCollectorService;Internet Explorer ETW Collector Service;C:\Windows\System32\ieetwcollector.exe [2014-10-15 111616]
S3 StorSvc;Storage Service;C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted [2009-7-13 27136]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2011-6-6 59392]
S3 USBAAPL64;Apple Mobile USB Driver;C:\Windows\System32\drivers\usbaapl64.sys [2012-12-13 54784]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2010-4-1 1255736]
S4 wlcrasvc;Windows Live Mesh remote connections service;C:\Program Files\Windows Live\Mesh\wlcrasvc.exe [2010-9-22 57184]
.
=============== Created Last 30 ================
.
2014-10-16 17:38:40 -------- d-----w- C:\Users\Chrissy\AppData\Local\{CC28DDB6-19FC-4F9D-AA37-F91C0C275A68}
2014-10-16 07:10:25 -------- d-----w- C:\Users\Chrissy\AppData\Roaming\Western Software Technologies
2014-10-16 06:59:39 -------- d-----w- C:\Program Files (x86)\Gizmos - Riddle Of The Universe
2014-10-16 06:57:09 -------- d-----w- C:\Program Files (x86)\League of Light - Wicked Harvest Collectors Edition
2014-10-15 19:01:41 -------- d-----w- C:\Users\Chrissy\AppData\Roaming\AlawarEntertainment
2014-10-15 17:59:27 -------- d-----w- C:\Users\Chrissy\AppData\Roaming\Crunching Koalas
2014-10-15 15:32:59 752640 ----a-w- C:\Program Files (x86)\Common Files\Microsoft Shared\VGX\VGX.dll
2014-10-15 15:26:51 11578928 ----a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{987C3351-3852-4F37-A57F-E1DB494D7A07}\mpengine.dll
2014-10-12 15:29:28 -------- d-----w- C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-10-12 15:29:28 -------- d-----w- C:\Program Files\iTunes
2014-10-12 15:29:28 -------- d-----w- C:\Program Files\iPod
2014-10-06 20:30:01 -------- d-----w- C:\Users\Chrissy\AppData\Local\{269A14D5-3686-44C5-A9FA-1DDE4FF0321C}
2014-10-06 02:40:41 -------- d-----w- C:\Users\Chrissy\AppData\Local\{AA686C13-87C0-4B5F-BE86-F64581A95055}
2014-10-04 07:53:04 -------- d-----w- C:\Users\Chrissy\AppData\Local\{B56CAF92-70F3-415F-8BD6-2206A1CFB06B}
2014-10-03 14:27:18 -------- d-----w- C:\Users\Chrissy\AppData\Local\{F04061BF-8698-4CCF-8F47-22ED8561815A}
2014-10-02 15:09:31 -------- d-----w- C:\Users\Chrissy\AppData\Local\{07352911-8FFE-44AF-9FAF-B92D476B84CC}
2014-10-01 20:29:03 -------- d-----w- C:\Users\Chrissy\AppData\Local\{F693B78E-65E1-4AD6-AA17-47D32E5D2668}
2014-10-01 20:08:12 519680 ----a-w- C:\Windows\SysWow64\qdvd.dll
2014-10-01 20:08:12 371712 ----a-w- C:\Windows\System32\qdvd.dll
2014-09-29 05:11:00 -------- d-----w- C:\ProgramData\Fugazo
2014-09-29 05:09:26 -------- d-----w- C:\Program Files (x86)\World Mosaics 6
2014-09-28 19:50:23 368886 ----a-w- C:\ProgramData\SPLCD17.tmp
2014-09-28 01:29:56 -------- d-----w- C:\Program Files (x86)\Grim Facade - The Artist and The Pretender Collectors Edition
2014-09-28 00:26:00 -------- d-----w- C:\Users\Chrissy\AppData\Roaming\Eipix
2014-09-27 21:26:26 -------- d-----w- C:\Users\Chrissy\AppData\Local\Match 3. Story of Gimli
2014-09-27 20:20:00 -------- d-----w- C:\Users\Chrissy\AppData\Roaming\8floor
2014-09-26 06:46:28 -------- d-----w- C:\ProgramData\Arizona-Rose-2
2014-09-25 20:46:54 2048 ----a-w- C:\Windows\SysWow64\tzres.dll
2014-09-25 20:46:54 2048 ----a-w- C:\Windows\System32\tzres.dll
2014-09-19 15:40:58 -------- d-----w- C:\Users\Chrissy\AppData\Roaming\Tap It Games
2014-09-19 15:18:33 -------- d-----w- C:\Users\Chrissy\AppData\Roaming\InfernalBros
2014-09-19 01:53:21 849934 ----a-w- C:\ProgramData\SPL90EF.tmp
.
==================== Find3M  ====================
.
2014-10-16 18:05:08 122584 ----a-w- C:\Windows\System32\drivers\MBAMSwissArmy.sys
2014-10-15 20:06:49 71344 ----a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2014-10-15 20:06:49 701104 ----a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2014-10-10 02:05:59 276480 ----a-w- C:\Windows\System32\generaltel.dll
2014-10-10 02:05:42 507392 ----a-w- C:\Windows\System32\aepdu.dll
2014-10-10 02:00:38 424448 ----a-w- C:\Windows\System32\aeinv.dll
2014-09-29 00:58:48 3198976 ----a-w- C:\Windows\System32\win32k.sys
2014-09-25 22:32:04 2017280 ----a-w- C:\Windows\SysWow64\inetcpl.cpl
2014-09-25 22:31:02 2108416 ----a-w- C:\Windows\System32\inetcpl.cpl
2014-09-19 01:56:02 2724864 ----a-w- C:\Windows\System32\mshtml.tlb
2014-09-19 01:55:49 4096 ----a-w- C:\Windows\System32\ieetwcollectorres.dll
2014-09-19 01:40:43 66048 ----a-w- C:\Windows\System32\iesetup.dll
2014-09-19 01:40:03 547328 ----a-w- C:\Windows\System32\vbscript.dll
2014-09-19 01:39:58 48640 ----a-w- C:\Windows\System32\ieetwproxystub.dll
2014-09-19 01:38:27 83968 ----a-w- C:\Windows\System32\MshtmlDac.dll
2014-09-19 01:36:57 5829632 ----a-w- C:\Windows\System32\jscript9.dll
2014-09-19 01:26:00 139264 ----a-w- C:\Windows\System32\ieUnatt.exe
2014-09-19 01:25:49 111616 ----a-w- C:\Windows\System32\ieetwcollector.exe
2014-09-19 01:25:12 4201472 ----a-w- C:\Windows\SysWow64\jscript9.dll
2014-09-19 01:25:09 758272 ----a-w- C:\Windows\System32\jscript9diag.dll
2014-09-19 01:18:02 940032 ----a-w- C:\Windows\System32\MsSpellCheckingFacility.exe
2014-09-19 01:14:57 2724864 ----a-w- C:\Windows\SysWow64\mshtml.tlb
2014-09-19 01:06:47 72704 ----a-w- C:\Windows\System32\JavaScriptCollectionAgent.dll
2014-09-19 01:02:07 454656 ----a-w- C:\Windows\SysWow64\vbscript.dll
2014-09-19 01:01:47 61952 ----a-w- C:\Windows\SysWow64\iesetup.dll
2014-09-19 01:01:03 51200 ----a-w- C:\Windows\SysWow64\ieetwproxystub.dll
2014-09-19 00:59:40 61952 ----a-w- C:\Windows\SysWow64\MshtmlDac.dll
2014-09-19 00:50:16 112128 ----a-w- C:\Windows\SysWow64\ieUnatt.exe
2014-09-19 00:49:31 597504 ----a-w- C:\Windows\SysWow64\jscript9diag.dll
2014-09-19 00:40:12 1249280 ----a-w- C:\Windows\System32\mshtmlmedia.dll
2014-09-19 00:36:23 60416 ----a-w- C:\Windows\SysWow64\JavaScriptCollectionAgent.dll
2014-09-19 00:33:18 2309632 ----a-w- C:\Windows\System32\wininet.dll
2014-09-19 00:18:55 1068032 ----a-w- C:\Windows\SysWow64\mshtmlmedia.dll
2014-09-18 23:59:11 1810944 ----a-w- C:\Windows\SysWow64\wininet.dll
2014-09-18 02:00:42 3241472 ----a-w- C:\Windows\System32\msi.dll
2014-09-18 01:32:52 2363904 ----a-w- C:\Windows\SysWow64\msi.dll
2014-09-15 13:06:02 278152 ------w- C:\Windows\System32\MpSigStub.exe
2014-09-13 01:58:18 77312 ----a-w- C:\Windows\System32\packager.dll
2014-09-13 01:40:05 67072 ----a-w- C:\Windows\SysWow64\packager.dll
2014-09-04 05:23:20 424448 ----a-w- C:\Windows\System32\rastls.dll
2014-09-04 05:04:15 372736 ----a-w- C:\Windows\SysWow64\rastls.dll
2014-08-26 22:02:22 98216 ----a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2014-08-23 02:07:00 404480 ----a-w- C:\Windows\System32\gdi32.dll
2014-08-23 01:45:55 311808 ----a-w- C:\Windows\SysWow64\gdi32.dll
2014-08-19 03:11:28 693176 ----a-w- C:\Windows\System32\winload.efi
2014-08-19 03:10:10 616352 ----a-w- C:\Windows\System32\winresume.efi
2014-08-19 03:08:04 503808 ----a-w- C:\Windows\System32\srcore.dll
2014-08-19 03:08:04 50176 ----a-w- C:\Windows\System32\srclient.dll
2014-08-19 03:08:03 63488 ----a-w- C:\Windows\System32\setbcdlocale.dll
2014-08-19 03:07:51 58880 ----a-w- C:\Windows\System32\appidapi.dll
2014-08-19 03:07:51 32256 ----a-w- C:\Windows\System32\appidsvc.dll
2014-08-19 03:07:33 296960 ----a-w- C:\Windows\System32\rstrui.exe
2014-08-19 03:07:11 17920 ----a-w- C:\Windows\System32\appidcertstorecheck.exe
2014-08-19 03:07:11 146944 ----a-w- C:\Windows\System32\appidpolicyconverter.exe
2014-08-19 02:41:39 43008 ----a-w- C:\Windows\SysWow64\srclient.dll
2014-08-19 02:41:22 50688 ----a-w- C:\Windows\SysWow64\appidapi.dll
2014-08-19 02:06:56 61440 ----a-w- C:\Windows\System32\drivers\appid.sys
2014-08-01 11:53:22 1031168 ----a-w- C:\Windows\System32\TSWorkspace.dll
2014-08-01 11:35:06 793600 ----a-w- C:\Windows\SysWow64\TSWorkspace.dll
2014-07-25 06:35:46 875688 ----a-w- C:\Windows\SysWow64\msvcr120_clr0400.dll
2014-07-25 03:47:06 869544 ----a-w- C:\Windows\System32\msvcr120_clr0400.dll
2010-10-04 08:20:20 495 ----a-w- C:\Program Files (x86)\100420104202010.bat
2010-05-17 11:37:22 475 ----a-w- C:\Program Files (x86)\051720107372288.bat
2010-05-06 09:00:58 467 ----a-w- C:\Program Files (x86)\050620105005806.bat
.
============= FINISH: 15:02:28.02 ===============
 

Attached Files



BC AdBot (Login to Remove)

 


#2 TB-Psychotic

TB-Psychotic

  • Malware Response Team
  • 6,349 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:30 AM

Posted 17 October 2014 - 08:18 AM

Hi there,
my name is Marius and I will assist you with your malware related problems.

Before we move on, please read the following points carefully.

  • First, read my instructions completely. If there is anything that you do not understand kindly ask before proceeding.
  • Perform everything in the correct order. Sometimes one step requires the previous one.
  • If you have any problems while following my instructions, Stop there and tell me the exact nature of your problem.
  • Do not run any other scans without instruction or add/remove software unless I tell you to do so. This would change the output of our tools and could be confusing for me.
  • Post all logfiles as a reply rather than as an attachment unless I specifically ask you. If you can not post all logfiles in one reply, feel free to use more posts.
  • If I don't hear from you within 3 days from this initial or any subsequent post, then this thread will be closed.
  • Stay with me. I will give you some advice about prevention after the cleanup process. Absence of symptoms does not always mean the computer is clean.
  • My first language is not english. So please do not use slang or idioms. It could be hard for me to read. Thanks for your understanding.

  • Important: To help me reviewing your logs, please post them in code boxes. You can create them by clicking on the <>-symbol on top of the reply window.

 
 
 
 
HijackThis is not the preferred initial scanning tool in this forum. With today's malware, a more comprehensive set of logs is required to determine the presence of malware.
 
 
  
Scan with FRST in normal mode

Please download Farbar's Recovery Scan Tool to your desktop: FRST 32bit or FRST 64bit (If not sure: Start --> Computer (right click) --> properties)
 
  • Run FRST.
  • Don´t change one of the checkboxes and hit Scan.
  • Logfiles are created on your desktop.
  • Poste the FRST.txt and (after the first scan only!) the Addition.txt.

 
 
Scan with Gmer rootkit scanner

Please download Gmer from here by clicking on the "Download EXE" Button.
  • Double click on the randomly named GMER.exe. If asked to allow gmer.sys driver to load, please consent.
  • If it gives you a warning about rootkit activity and asks if you want to run scan...click on NO.
  • In the right panel, you will see several boxes that have been checked. Uncheck the following ...
    • Sections
    • IAT/EAT
    • Show All ( should be unchecked by default )
  • Leave everything else as it is.
  • Close all other running programs as well as your Browser.
  • Click the Scan button & wait for it to finish.
  • Once done click on the Save.. button, and in the File name area, type in "ark.txt" or it will save as a .log file which cannot be uploaded to your post.
  • Save it where you can easily find it, such as your desktop.
  • Please post the content of the ark.txt here.

**Caution**
Rootkit scans often produce false positives. Do NOT take any action on any "<--- ROOKIT" entries

Scan with TDSS-Killer

Please read and follow these instructions carefully. We do not want it to fix anything yet (if found), we need to see a report first.

Download TDSSKiller.zip and extract to your desktop
  • Execute TDSSKiller.exe by doubleclicking on it.
  • Press Start Scan
  • If Malicious objects are found, do NOT select Copy to quarantine. Change the action to Skip, and save the log.
  • Once complete, a log will be produced at the root drive which is typically C:\ ,for example, C:\TDSSKiller.<version_date_time>log.txt


Please attach this file to your next reply.
 


Proud Member of UNITE & TB
 
My help is free, however, if you want to support my fight against malware, click here --> btn_donate_SM.gif <--(no worries, every little bit helps)

#3 Dizzy24

Dizzy24
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Baltimore
  • Local time:11:30 PM

Posted 17 October 2014 - 05:50 PM

Hello Marius,

Thank you again for your help!

 

I am posting the FRST.txt and the addition.text... the ark.txt is blank and the TDSS-killer came up negative. Processed 470 objects, no threats found. It didn't give me an option to print a logfile. 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 16-10-2014
Ran by Chrissy (administrator) on HOME on 17-10-2014 18:27:51
Running from C:\Users\Chrissy\Downloads
Loaded Profile: Chrissy (Available profiles: Chrissy & Brian)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Coupons.com Inc.) C:\Program Files (x86)\Coupons\CouponPrinterService.exe
() C:\Windows\System32\spool\drivers\x64\3\dleaserv.exe
( ) C:\Windows\System32\dleacoms.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(SoftThinks) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(SupportSoft, Inc.) C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
(SupportSoft, Inc.) C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Microsoft Corporation) C:\Windows\System32\rundll32.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
() C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe
() C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(Creative Technology Ltd.) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(SupportSoft, Inc.) C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(PC-Doctor, Inc.) C:\Program Files\My Dell\uaclauncher.exe
(Microsoft Corporation) C:\Program Files\Windows Defender\MpCmdRun.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7834656 2009-06-02] (Realtek Semiconductor)
HKLM\...\Run: [dleamon.exe] => C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe [770728 2010-01-18] ()
HKLM\...\Run: [EzPrint] => C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe [139944 2010-01-18] ()
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-06-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe [442536 2008-11-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software)
HKLM-x32\...\Run: [VERIZONDM] => C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe [206120 2010-09-02] (SupportSoft, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Winlogon\Notify\FastAccess-x32: C:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll [X]
HKU\S-1-5-21-3777444554-1153240464-3734799716-1000\...\Run: [DellSystemDetect] => C:\Users\Chrissy\AppData\Local\Apps\2.0\YK8PCHXX.540\1ZKYKQYO.GAB\dell..tion_0f612f649c4a10af_0005.000a_17ece8424e43daec\DellSystemDetect.exe [265280 2014-08-27] (Dell)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
Startup: C:\Users\Brian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://search.coupons.com/
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = 
SearchScopes: HKLM-x32 - DefaultScope {7F1288EA-E0DE-4E28-AA5A-6E58FDCD67CE} URL = 
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {444B13D6-001A-4710-8DF6-8B105BC6C33D} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3315828&CUI=UN87734836013451164&UM=2
SearchScopes: HKCU - {664164BD-7255-4B06-865E-65ECFDC1E85A} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
SearchScopes: HKCU - {7F1288EA-E0DE-4E28-AA5A-6E58FDCD67CE} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_dnldstr_14_42_ch&cd=2XzuyEtN2Y1L1QzutDtDtBtCyBtDyCtDyB0D0C0A0EyCtAzztN0D0Tzu0StCtDtCzytN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAyCyBzzyBzy0FyCtGyCyD0EtBtG0DtBtB0DtGyE0C0C0DtGyEzztC0E0ByBtC0B0ByB0C0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCyE0AyEyE0F0CzztG0ByEtAyEtGyEzztByBtGzzzy0FyEtGzz0CtB0EyB0B0F0C0Bzyzzzy2Q&cr=2037860578&ir=
SearchScopes: HKCU - {AD0270AE-CBD0-4D98-AE60-0E72EB9EBB52} URL = 
SearchScopes: HKCU - {BBA54ACF-CC24-40CD-ACB3-3633B34BC954} URL = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7ADRA_enUS423
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} ->  No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: HKLM-x32 {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {6F6FDB9E-5072-498C-BCB0-2B7F00C49EE7} http://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
DPF: HKLM-x32 {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: HKLM-x32 {9AA73F41-EC64-489E-9A73-9CD52E528BC4} http://zone.msn.com/binGame/ZAxRcMgr.cab
DPF: HKLM-x32 {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://zone.msn.com/bingame/popcaploader_v10.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=11.20.2 -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.20.2 -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @oberon-media.com/ONCAdapter -> C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (Oberon-Media )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.24.15\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: samsung.com/SamsungLinkPCPlugin -> C:\Program Files\Samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll No File
FF Plugin HKCU: samsung.com/SamsungLinkPCPlugin -> C:\Program Files\Samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll No File
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-02-09]

Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com", "hxxp://search.conduit.com/?ctid=CT3315828&SearchSource=48&CUI=UN15338799328857141&UM=2", "hxxp://astromenda.com/?f=7&a=ast_dnldstr_14_42_ch&cd=2XzuyEtN2Y1L1QzutDtDtBtCyBtDyCtDyB0D0C0A0EyCtAzztN0D0Tzu0StCtDtCzytN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAyCyBzzyBzy0FyCtGyCyD0EtBtG0DtBtB0DtGyE0C0C0DtGyEzztC0E0ByBtC0B0ByB0C0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCyE0AyEyE0F0CzztG0ByEtAyEtGyEzztByBtGzzzy0FyEtGzz0CtB0EyB0B0F0C0Bzyzzzy2Q&cr=2037860578&ir="
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll No File
CHR Plugin: (Oberon com adapter) - C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (Oberon-Media )
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Reader Library) - C:\Program Files (x86)\Sony\Reader\Data\bin\npebldetectmoz.dll No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll No File
CHR Profile: C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-21]
CHR Extension: (YouTube) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-19]
CHR Extension: (Google Search) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-19]
CHR Extension: (avast! Online Security) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-02-10]
CHR Extension: (Skype Click to Call) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-03-20]
CHR Extension: (Google Wallet) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Gmail) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-19]
CHR HKCU\...\Chrome\Extension: [jhbbmmgbnjalccamlaefhepnajfmgopb] - C:\Users\Chrissy\AppData\Local\CRE\jhbbmmgbnjalccamlaefhepnajfmgopb.crx [2014-01-09]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-14]
CHR HKLM-x32\...\Chrome\Extension: [jhbbmmgbnjalccamlaefhepnajfmgopb] - C:\Users\Chrissy\AppData\Local\CRE\jhbbmmgbnjalccamlaefhepnajfmgopb.crx [2014-01-09]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-14] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [177136 2014-04-28] (Coupons.com Inc.)
R2 dleaCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\dleaserv.exe [33448 2010-01-07] ()
R2 dlea_device; C:\Windows\system32\dleacoms.exe [1052328 2010-01-07] ( )
R2 dlea_device; C:\Windows\SysWOW64\dleacoms.exe [598696 2010-01-07] ( )
R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2009-06-09] (Stardock Corporation) [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2010-02-01] (Macrovision Europe Ltd.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [609632 2014-03-13] (Copyright 2013 SAMSUNG)
R2 sprtsvc_verizondm; C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe [206120 2010-09-02] (SupportSoft, Inc.)
R2 tgsrvc_verizondm; C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe [185640 2010-09-02] (SupportSoft, Inc.)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-14] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-14] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-14] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-14] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-14] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-14] ()
R3 RLDesignVirtualAudioCableWdm; C:\Windows\System32\DRIVERS\livecamv.sys [49664 2007-02-05] ()
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-17 18:28 - 2014-10-17 18:28 - 00000000 ____D () C:\Users\Chrissy\Desktop\New folder
2014-10-17 18:27 - 2014-10-17 18:28 - 00024828 _____ () C:\Users\Chrissy\Downloads\FRST.txt
2014-10-17 18:27 - 2014-10-17 18:27 - 00000000 ____D () C:\FRST
2014-10-17 18:26 - 2014-10-17 18:26 - 02112000 _____ (Farbar) C:\Users\Chrissy\Downloads\FRST64.exe
2014-10-16 15:02 - 2014-10-16 15:03 - 00023803 _____ () C:\Users\Chrissy\Desktop\dds.txt
2014-10-16 15:02 - 2014-10-16 15:03 - 00011541 _____ () C:\Users\Chrissy\Desktop\attach.txt
2014-10-16 15:00 - 2014-10-16 15:00 - 00688992 ____R (Swearware) C:\Users\Chrissy\Downloads\dds.com
2014-10-16 13:38 - 2014-10-16 13:38 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{CC28DDB6-19FC-4F9D-AA37-F91C0C275A68}
2014-10-16 03:10 - 2014-10-16 03:10 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Western Software Technologies
2014-10-16 02:59 - 2014-10-16 02:59 - 00001292 _____ () C:\Users\Public\Desktop\More Great Games.lnk
2014-10-16 02:59 - 2014-10-16 02:59 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gizmos - Riddle Of The Universe
2014-10-16 02:59 - 2014-10-16 02:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gizmos - Riddle Of The Universe
2014-10-16 02:59 - 2014-10-16 02:59 - 00000000 ____D () C:\Program Files (x86)\Gizmos - Riddle Of The Universe
2014-10-16 02:58 - 2014-10-16 02:58 - 00002330 _____ () C:\Users\Public\Desktop\Play League of Light - Wicked Harvest Collectors Edition.lnk
2014-10-16 02:57 - 2014-10-16 02:58 - 00000000 ____D () C:\Program Files (x86)\League of Light - Wicked Harvest Collectors Edition
2014-10-16 02:57 - 2014-10-16 02:57 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\League of Light - Wicked Harvest Collectors Edition
2014-10-16 02:57 - 2014-10-16 02:57 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\League of Light - Wicked Harvest Collectors Edition
2014-10-15 17:03 - 2014-10-16 13:38 - 00000101 _____ () C:\Users\Chrissy\AppData\Roaming\WB.CFG
2014-10-15 16:06 - 2014-10-17 18:21 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-15 16:06 - 2014-10-15 16:06 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-10-15 16:02 - 2014-10-15 16:01 - 17334960 _____ (Adobe Systems Incorporated) C:\Users\Chrissy\Downloads\install_flash_player_ax.exe
2014-10-15 16:01 - 2014-10-15 16:01 - 00800688 _____ ( ) C:\Users\Chrissy\Downloads\Adobe_Flash_Setup.exe
2014-10-15 15:01 - 2014-10-15 15:01 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\AlawarEntertainment
2014-10-15 13:59 - 2014-10-15 13:59 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Crunching Koalas
2014-10-15 11:33 - 2014-10-09 22:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-15 11:33 - 2014-10-09 22:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-15 11:33 - 2014-10-09 22:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-15 11:33 - 2014-10-06 22:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-15 11:33 - 2014-10-06 22:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-15 11:33 - 2014-09-28 20:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-15 11:33 - 2014-09-25 18:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-15 11:33 - 2014-09-25 18:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-15 11:33 - 2014-09-25 18:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-15 11:33 - 2014-09-25 18:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-15 11:33 - 2014-09-25 18:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-15 11:33 - 2014-09-25 18:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-15 11:33 - 2014-09-18 21:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-15 11:33 - 2014-09-18 21:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-15 11:33 - 2014-09-18 21:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-15 11:33 - 2014-09-18 21:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-15 11:33 - 2014-09-18 21:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-15 11:33 - 2014-09-18 21:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-15 11:33 - 2014-09-18 21:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-15 11:33 - 2014-09-18 21:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-15 11:33 - 2014-09-18 21:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-15 11:33 - 2014-09-18 21:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-15 11:33 - 2014-09-18 21:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-15 11:33 - 2014-09-18 21:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-15 11:33 - 2014-09-18 21:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 11:33 - 2014-09-18 21:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-15 11:33 - 2014-09-18 21:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-10-15 11:33 - 2014-09-18 21:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-10-15 11:33 - 2014-09-18 20:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-15 11:33 - 2014-09-18 20:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-15 11:33 - 2014-09-18 20:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-10-15 11:33 - 2014-09-18 20:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-10-15 11:33 - 2014-09-18 20:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-10-15 11:33 - 2014-09-18 20:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-10-15 11:33 - 2014-09-18 20:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-10-15 11:33 - 2014-09-18 20:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-15 11:33 - 2014-09-18 20:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-15 11:33 - 2014-09-18 20:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-15 11:33 - 2014-09-18 20:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-10-15 11:33 - 2014-09-18 20:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-15 11:33 - 2014-09-18 20:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-10-15 11:33 - 2014-09-18 20:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-15 11:33 - 2014-09-18 19:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-15 11:33 - 2014-09-18 19:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-15 11:33 - 2014-09-18 19:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-15 11:33 - 2014-08-18 23:11 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-10-15 11:33 - 2014-08-18 23:10 - 00616352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-10-15 11:33 - 2014-08-18 23:08 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-10-15 11:33 - 2014-08-18 23:08 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-10-15 11:33 - 2014-08-18 23:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2014-10-15 11:33 - 2014-08-18 23:07 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-10-15 11:33 - 2014-08-18 23:07 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2014-10-15 11:33 - 2014-08-18 23:07 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2014-10-15 11:33 - 2014-08-18 23:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2014-10-15 11:33 - 2014-08-18 23:07 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2014-10-15 11:33 - 2014-08-18 22:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2014-10-15 11:33 - 2014-08-18 22:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-10-15 11:33 - 2014-08-18 22:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-10-15 11:33 - 2014-07-06 22:07 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-10-15 11:33 - 2014-07-06 22:07 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-10-15 11:33 - 2014-07-06 22:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 05551032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-10-15 11:33 - 2014-07-06 22:06 - 04120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-10-15 11:33 - 2014-07-06 22:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-10-15 11:33 - 2014-07-06 22:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-10-15 11:33 - 2014-07-06 22:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-10-15 11:33 - 2014-07-06 22:05 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-10-15 11:33 - 2014-07-06 22:05 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-10-15 11:33 - 2014-07-06 22:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-10-15 11:33 - 2014-07-06 21:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-10-15 11:33 - 2014-07-06 21:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2014-10-15 11:33 - 2014-07-06 21:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2014-10-15 11:33 - 2014-07-06 21:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-10-15 11:33 - 2014-07-06 21:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-10-15 11:33 - 2014-07-06 21:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-10-15 11:33 - 2014-07-06 21:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-10-15 11:33 - 2014-07-06 21:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-10-15 11:33 - 2014-07-06 21:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-10-15 11:33 - 2014-06-27 20:21 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-10-15 11:33 - 2014-06-27 20:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-10-15 11:33 - 2014-06-27 20:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-10-15 11:33 - 2014-06-18 18:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-15 11:33 - 2014-06-18 18:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-10-15 11:33 - 2014-06-18 18:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-10-15 11:33 - 2014-06-18 18:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-15 11:33 - 2014-06-18 18:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-10-15 11:33 - 2014-06-18 18:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-15 11:32 - 2014-09-25 18:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-15 11:32 - 2014-09-18 22:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-15 11:32 - 2014-09-18 21:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-15 11:32 - 2014-09-18 21:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-15 11:32 - 2014-09-18 21:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-15 11:32 - 2014-09-18 21:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-15 11:32 - 2014-09-18 21:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-15 11:32 - 2014-09-18 21:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-15 11:32 - 2014-09-18 21:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-15 11:32 - 2014-09-18 21:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-15 11:32 - 2014-09-18 21:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-15 11:32 - 2014-09-18 20:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-15 11:32 - 2014-09-18 20:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-15 11:32 - 2014-09-18 20:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-15 11:32 - 2014-09-18 19:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-15 11:32 - 2014-09-17 22:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-15 11:32 - 2014-09-17 21:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-15 11:32 - 2014-09-12 21:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-15 11:32 - 2014-09-12 21:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-15 11:32 - 2014-09-04 01:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-15 11:32 - 2014-09-04 01:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-15 11:32 - 2014-07-16 22:07 - 03722240 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-15 11:32 - 2014-07-16 22:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-10-15 11:32 - 2014-07-16 22:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-15 11:32 - 2014-07-16 22:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-15 11:32 - 2014-07-16 22:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-15 11:32 - 2014-07-16 22:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-15 11:32 - 2014-07-16 22:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-15 11:32 - 2014-07-16 22:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-15 11:32 - 2014-07-16 21:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-10-15 11:32 - 2014-07-16 21:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-10-15 11:32 - 2014-07-16 21:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-10-15 11:32 - 2014-07-16 21:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-10-15 11:32 - 2014-07-16 21:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-10-15 11:32 - 2014-07-16 21:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-10-15 11:32 - 2014-07-16 21:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-15 11:32 - 2014-07-16 21:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-12 11:30 - 2014-10-12 11:30 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-10-12 11:30 - 2014-10-12 11:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-10-12 11:29 - 2014-10-12 11:29 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-10-12 11:29 - 2014-10-12 11:29 - 00000000 ____D () C:\Program Files\iTunes
2014-10-12 11:29 - 2014-10-12 11:29 - 00000000 ____D () C:\Program Files\iPod
2014-10-06 16:30 - 2014-10-06 16:30 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{269A14D5-3686-44C5-A9FA-1DDE4FF0321C}
2014-10-05 22:40 - 2014-10-05 22:40 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{AA686C13-87C0-4B5F-BE86-F64581A95055}
2014-10-04 03:53 - 2014-10-04 03:53 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{B56CAF92-70F3-415F-8BD6-2206A1CFB06B}
2014-10-03 10:27 - 2014-10-03 10:27 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{F04061BF-8698-4CCF-8F47-22ED8561815A}
2014-10-02 11:09 - 2014-10-02 11:09 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{07352911-8FFE-44AF-9FAF-B92D476B84CC}
2014-10-01 16:29 - 2014-10-01 16:29 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{F693B78E-65E1-4AD6-AA17-47D32E5D2668}
2014-10-01 16:08 - 2014-09-24 22:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-10-01 16:08 - 2014-09-24 21:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll
2014-09-29 01:11 - 2014-09-29 01:11 - 00000000 ____D () C:\ProgramData\Fugazo
2014-09-29 01:09 - 2014-09-29 01:09 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\World Mosaics 6
2014-09-29 01:09 - 2014-09-29 01:09 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\World Mosaics 6
2014-09-29 01:09 - 2014-09-29 01:09 - 00000000 ____D () C:\Program Files (x86)\World Mosaics 6
2014-09-28 15:50 - 2014-09-28 15:50 - 00368886 _____ () C:\ProgramData\SPLCD17.tmp
2014-09-27 21:29 - 2014-09-27 21:34 - 00000000 ____D () C:\Program Files (x86)\Grim Facade - The Artist and The Pretender Collectors Edition
2014-09-27 21:29 - 2014-09-27 21:29 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Grim Facade - The Artist and The Pretender Collectors Edition
2014-09-27 21:29 - 2014-09-27 21:29 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Grim Facade - The Artist and The Pretender Collectors Edition
2014-09-27 21:22 - 2014-09-27 21:22 - 00237568 _____ (Big Fish Games) C:\Users\Chrissy\Downloads\bigfishgames_p221028615_s1_l1 (1).exe
2014-09-27 21:21 - 2014-09-27 21:21 - 00237568 _____ (Big Fish Games) C:\Users\Chrissy\Downloads\bigfishgames_p221028615_s1_l1.exe
2014-09-27 20:26 - 2014-09-27 20:26 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Eipix
2014-09-27 17:26 - 2014-09-27 20:25 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\Match 3. Story of Gimli
2014-09-27 16:20 - 2014-09-27 16:20 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\8floor
2014-09-26 02:46 - 2014-09-26 02:46 - 00000000 ____D () C:\ProgramData\Arizona-Rose-2
2014-09-26 02:42 - 2014-09-26 02:42 - 00237568 _____ (Big Fish Games) C:\Users\Chrissy\Downloads\arizona-rose-and-the-pharaohs-riddles_s1_l1_gF8337T1L1_d2366457459.exe
2014-09-25 16:46 - 2014-09-09 18:11 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\tzres.dll
2014-09-25 16:46 - 2014-09-09 17:47 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\tzres.dll
2014-09-19 11:40 - 2014-09-19 11:40 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Tap It Games
2014-09-19 11:18 - 2014-09-19 11:18 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\InfernalBros
2014-09-18 21:53 - 2014-09-18 21:53 - 00849934 _____ () C:\ProgramData\SPL90EF.tmp

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-17 18:27 - 2011-03-19 23:55 - 00000896 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-17 18:26 - 2009-07-14 00:45 - 00025424 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-17 18:26 - 2009-07-14 00:45 - 00025424 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-17 18:23 - 2014-05-29 19:58 - 01418898 _____ () C:\Windows\WindowsUpdate.log
2014-10-17 18:21 - 2014-02-09 22:36 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-10-17 18:21 - 2011-03-19 23:55 - 00000900 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-17 18:21 - 2010-04-17 11:27 - 00103020 _____ () C:\ProgramData\dlea.log
2014-10-16 18:15 - 2010-02-11 05:03 - 00000000 ____D () C:\ProgramData\TEMP
2014-10-16 14:31 - 2010-11-13 20:26 - 00000000 ___RD () C:\Users\Chrissy\Desktop\Game Shortcuts
2014-10-16 14:29 - 2010-02-10 01:54 - 00478140 _____ () C:\ProgramData\dleascan.log
2014-10-16 14:27 - 2014-08-26 18:14 - 00001680 _____ () C:\Windows\setupact.log
2014-10-16 14:27 - 2014-08-26 18:13 - 00016784 _____ () C:\Windows\PFRO.log
2014-10-16 14:27 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-16 14:05 - 2014-08-30 02:15 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-16 06:34 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-10-16 03:48 - 2013-07-27 10:47 - 00000000 ____D () C:\BigFishCache
2014-10-16 03:48 - 2009-07-14 01:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-10-16 03:33 - 2009-07-14 00:45 - 00426520 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-16 03:30 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-16 03:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-10-16 03:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-10-16 03:12 - 2010-02-01 23:28 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-16 03:07 - 2013-08-15 03:02 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-16 03:01 - 2010-04-01 02:59 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-16 02:59 - 2009-07-14 01:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-10-15 17:00 - 2014-08-27 00:18 - 00003440 _____ () C:\Windows\System32\Tasks\PCDEventLauncherTask
2014-10-15 16:06 - 2012-04-01 13:04 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-10-15 16:06 - 2011-06-05 04:37 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-12 11:29 - 2007-11-20 21:38 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-10-10 05:49 - 2010-02-10 02:25 - 00583320 _____ () C:\ProgramData\dleaJSW.log
2014-10-10 05:49 - 2010-02-10 02:07 - 00000000 ____D () C:\ProgramData\Dl_cats
2014-10-04 03:52 - 2013-11-01 22:58 - 00000404 _____ () C:\Windows\Tasks\EasyShare Registration Task.job
2014-09-19 17:59 - 2014-09-15 13:22 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\ERS Game Studios

Some content of TEMP:
====================
C:\Users\Chrissy\AppData\Local\temp\77842uninstall.exe
C:\Users\Chrissy\AppData\Local\temp\80540uninstall.exe
C:\Users\Chrissy\AppData\Local\temp\SkypeSetup.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-16 06:25

==================== End Of Log ============================
Additional scan result of Farbar Recovery Scan Tool (x64) Version: 16-10-2014
Ran by Chrissy at 2014-10-17 18:28:40
Running from C:\Users\Chrissy\Downloads
Boot Mode: Normal
==========================================================


==================== Security Center ========================

(If an entry is included in the fixlist, it will be removed.)

AV: avast! Antivirus (Enabled - Up to date) {17AD7D40-BA12-9C46-7131-94903A54AD8B}
AS: Windows Defender (Enabled - Up to date) {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
AS: avast! Antivirus (Enabled - Up to date) {ACCC9CA4-9C28-93C8-4B81-AFE241D3E736}

==================== Installed Programs ======================

(Only the adware programs with "hidden" flag could be added to the fixlist to unhide them. The adware programs should be uninstalled manually.)

 Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
 Update for Microsoft Office 2007 (KB2508958) (HKLM-x32\...\{91120000-0011-0000-0000-0000000FF1CE}_PROPLUSR_{0C5823AA-7B6F-44E1-8D5B-8FD1FF0E6438}) (Version:  - Microsoft)
ABBYY FineReader 6.0 Sprint (HKLM-x32\...\{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}) (Version: 6.00.2146.41621 - ABBYY Software House)
Adobe AIR (HKLM-x32\...\Adobe AIR) (Version: 15.0.0.293 - Adobe Systems Incorporated)
Adobe AIR (x32 Version: 15.0.0.293 - Adobe Systems Incorporated) Hidden
Adobe Flash Player 15 ActiveX (HKLM-x32\...\Adobe Flash Player ActiveX) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Flash Player 15 Plugin (HKLM-x32\...\Adobe Flash Player Plugin) (Version: 15.0.0.189 - Adobe Systems Incorporated)
Adobe Photoshop Elements 7.0 (HKLM-x32\...\Adobe Photoshop Elements 7) (Version: 7.0.1 - Adobe Systems Incorporated)
Adobe Photoshop Elements 7.0 (x32 Version: 7.0.1 - Adobe Systems Incorporated) Hidden
Adobe Photoshop Elements 7.0 (x32 Version: 7.0.1.3 - Adobe Systems Incorporated) Hidden
Adobe Reader X (10.1.12) (HKLM-x32\...\{AC76BA86-7AD7-1033-7B44-AA1000000001}) (Version: 10.1.12 - Adobe Systems Incorporated)
Adobe Shockwave Player 12.0 (HKLM-x32\...\Adobe Shockwave Player) (Version: 12.0.7.148 - Adobe Systems, Inc.)
Advanced Audio FX Engine (HKLM-x32\...\Advanced Audio FX Engine) (Version:  - )
AllShare Framework DMS (HKLM\...\{83232C27-8C3F-44A5-9EB2-BB7161228ADD}) (Version: 1.3.23 - Samsung)
Apple Application Support (HKLM-x32\...\{78002155-F025-4070-85B3-7C0453561701}) (Version: 3.0.6 - Apple Inc.)
Apple Mobile Device Support (HKLM\...\{B678797F-DF38-4556-8A31-8B818E261868}) (Version: 8.0.0.23 - Apple Inc.)
Apple Software Update (HKLM-x32\...\{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}) (Version: 2.1.3.127 - Apple Inc.)
ArcSoft Panorama Maker 5 (HKLM-x32\...\{F18046C5-1C4E-4BE1-A3D6-A6F970E2E8E8}) (Version: 5.0.1.25 - ArcSoft)
ArcSoft Print Creations - Album Page (HKLM-x32\...\{E6B4117F-AC59-4B13-9274-EB136E8897EE}) (Version:  - ArcSoft)
ArcSoft Print Creations - Funhouse (HKLM-x32\...\{9591C049-5CAE-4E89-A8D9-191F1899628B}) (Version:  - ArcSoft)
ArcSoft Print Creations - Greeting Card (HKLM-x32\...\{F04F9557-81A9-4293-BC49-2C216FA325A7}) (Version:  - ArcSoft)
ArcSoft Print Creations - Photo Book (HKLM-x32\...\{56589DFE-0C29-4DFE-8E42-887B771ECD23}) (Version:  - ArcSoft)
ArcSoft Print Creations - Photo Calendar (HKLM-x32\...\{CA9ED5E4-1548-485B-A293-417840060158}) (Version:  - ArcSoft)
ArcSoft Print Creations - Scrapbook (HKLM-x32\...\{B0D83FCD-9D42-43ED-8315-250326AADA02}) (Version:  - ArcSoft)
ArcSoft Print Creations - Slimline Card (HKLM-x32\...\{007B37D9-0C45-4202-834B-DD5FAAE99D63}) (Version:  - ArcSoft)
ArcSoft Print Creations (HKLM-x32\...\{CAE8A0F1-B498-4C23-95FA-55047E730C8F}) (Version: 2.8.255.384 - ArcSoft)
ATI Catalyst Control Center (HKLM-x32\...\{055EE59D-217B-43A7-ABFF-507B966405D8}) (Version: 2.009.0614.2130 - )
ATI Catalyst Install Manager (HKLM\...\{46D0EBFA-26B0-4261-D1B6-2EACE48AD24C}) (Version: 3.0.732.0 - ATI Technologies, Inc.)
avast! Free Antivirus (HKLM-x32\...\Avast) (Version: 9.0.2021 - AVAST Software)
Avery Wizard 3.1 (HKLM-x32\...\{B4E96960-5F6B-48B9-A5BD-6A5A9BB4F027}) (Version: 3.1.5 - Avery)
Big Fish: Game Manager (HKLM-x32\...\BFGC) (Version: 3.3.0.2 - )
Bonjour (HKLM\...\{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}) (Version: 3.0.0.10 - Apple Inc.)
Bush Whacker 2 - Free to Play (HKLM-x32\...\BFG-Bush Whacker 2 - Free to Play) (Version:  - )
Catalyst Control Center - Branding (x32 Version: 1.00.0000 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2009.0614.2131.36800 - ATI) Hidden
Catalyst Control Center Core Implementation (x32 Version: 2009.0625.1812.30825 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2009.0614.2131.36800 - ATI) Hidden
Catalyst Control Center Graphics Full Existing (x32 Version: 2009.0625.1812.30825 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2009.0614.2131.36800 - ATI) Hidden
Catalyst Control Center Graphics Full New (x32 Version: 2009.0625.1812.30825 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2009.0614.2131.36800 - ATI) Hidden
Catalyst Control Center Graphics Light (x32 Version: 2009.0625.1812.30825 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2009.0614.2131.36800 - ATI) Hidden
Catalyst Control Center Graphics Previews Common (x32 Version: 2009.0625.1812.30825 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2009.0614.2131.36800 - ATI) Hidden
Catalyst Control Center Graphics Previews Vista (x32 Version: 2009.0625.1812.30825 - ATI) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2009.0614.2131.36800 - ATI Technologies, Inc.) Hidden
Catalyst Control Center InstallProxy (x32 Version: 2009.0625.1812.30825 - ATI Technologies, Inc.) Hidden
Catalyst Control Center Localization All (x32 Version: 2009.0614.2131.36800 - ATI) Hidden
Catalyst Control Center Localization All (x32 Version: 2009.0625.1812.30825 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2009.0614.2130.36800 - ATI) Hidden
CCC Help Chinese Standard (x32 Version: 2009.0625.1811.30825 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2009.0614.2130.36800 - ATI) Hidden
CCC Help Chinese Traditional (x32 Version: 2009.0625.1811.30825 - ATI) Hidden
CCC Help English (x32 Version: 2009.0614.2130.36800 - ATI) Hidden
CCC Help English (x32 Version: 2009.0625.1811.30825 - ATI) Hidden
CCC Help French (x32 Version: 2009.0614.2130.36800 - ATI) Hidden
CCC Help French (x32 Version: 2009.0625.1811.30825 - ATI) Hidden
CCC Help German (x32 Version: 2009.0614.2130.36800 - ATI) Hidden
CCC Help German (x32 Version: 2009.0625.1811.30825 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2009.0614.2130.36800 - ATI) Hidden
CCC Help Hungarian (x32 Version: 2009.0625.1811.30825 - ATI) Hidden
CCC Help Italian (x32 Version: 2009.0614.2130.36800 - ATI) Hidden
CCC Help Italian (x32 Version: 2009.0625.1811.30825 - ATI) Hidden
CCC Help Japanese (x32 Version: 2009.0614.2130.36800 - ATI) Hidden
CCC Help Japanese (x32 Version: 2009.0625.1811.30825 - ATI) Hidden
CCC Help Korean (x32 Version: 2009.0614.2130.36800 - ATI) Hidden
CCC Help Korean (x32 Version: 2009.0625.1811.30825 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2009.0614.2130.36800 - ATI) Hidden
CCC Help Portuguese (x32 Version: 2009.0625.1811.30825 - ATI) Hidden
CCC Help Spanish (x32 Version: 2009.0614.2130.36800 - ATI) Hidden
CCC Help Spanish (x32 Version: 2009.0625.1811.30825 - ATI) Hidden
CCC Help Turkish (x32 Version: 2009.0614.2130.36800 - ATI) Hidden
CCC Help Turkish (x32 Version: 2009.0625.1811.30825 - ATI) Hidden
ccc-core-static (x32 Version: 2009.0614.2131.36800 - ATI) Hidden
ccc-core-static (x32 Version: 2009.0625.1812.30825 - ATI) Hidden
ccc-utility64 (Version: 2009.0614.2131.36800 - ATI) Hidden
ccc-utility64 (Version: 2009.0625.1812.30825 - ATI) Hidden
CCleaner (HKLM\...\CCleaner) (Version: 4.17 - Piriform)
CCScore (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden
CDDRV_Installer (Version: 4.60 - Logitech) Hidden
Compatibility Pack for the 2007 Office system (HKLM-x32\...\{90120000-0020-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Coupon Printer for Windows (HKLM-x32\...\Coupon Printer for Windows5.0.0.9) (Version: 5.0.0.9 - Coupons.com Incorporated)
D3DX10 (x32 Version: 15.4.2368.0902 - Microsoft) Hidden
Dell DataSafe Local Backup - Support Software (HKLM-x32\...\{A9668246-FB70-4103-A1E3-66C9BC2EFB49}) (Version: 2.31 - Dell)
Dell DataSafe Local Backup (HKLM-x32\...\{0ED7EE95-6A97-47AA-AD73-152C08A15B04}) (Version: 9.3.44 - Dell)
Dell DataSafe Online (HKLM-x32\...\{13766F76-6C8C-4E57-A9F3-3212D1C6E0D1}) (Version: 1.2.0011 - Dell, Inc.)
Dell Dock (HKLM\...\{E60B7350-EA5F-41E0-9D6F-E508781E36D2}) (Version: 2.0.0 - Dell)
Dell Edoc Viewer (HKLM\...\{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}) (Version: 1.0.0 - Dell Inc)
Dell Getting Started Guide (HKLM-x32\...\{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}) (Version: 1.00.0000 - Dell Inc.)
Dell System Detect (HKCU\...\9204f5692a8faf3b) (Version: 5.10.0.8 - Dell)
Dell V310-V510 Series (HKLM\...\Dell V310-V510 Series) (Version:  - Dell, Inc.)
Dell Webcam Central (HKLM-x32\...\Dell Webcam Central) (Version: 1.01.11 - Creative Technology Ltd)
erLT (x32 Version: 1.20.0137 - Logitech, Inc.) Hidden
ESSBrwr (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden
ESSCDBK (x32 Version: 8.03.0000.0001 - EASTMAN KODAK Company) Hidden
ESScore (x32 Version: 8.03.0000.0001 - EASTMAN KODAK Company) Hidden
ESSgui (x32 Version: 8.03.0000.0001 - EASTMAN KODAK Company) Hidden
ESSini (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden
ESSPCD (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden
ESSPDock (x32 Version: 6.03.0001.0004 - EASTMAN KODAK Company) Hidden
ESSTOOLS (x32 Version: 5.00.0000.0004 - EASTMAN KODAK Company) Hidden
essvatgt (x32 Version: 8.00.0000.0001 - EASTMAN KODAK Company) Hidden
File Uploader (HKLM-x32\...\{237CD223-1B9D-47E8-A76C-E478B83CCEA2}) (Version: 1.2.3 - Nikon)
Gizmos: Riddle Of The Universe (HKLM-x32\...\BFG-Gizmos - Riddle Of The Universe) (Version:  - )
Golden Ticket: An Amusement Park Sim Game (HKLM-x32\...\BFG-Golden Ticket - An Amusement Park Sim Game) (Version:  - )
Google Chrome (HKLM-x32\...\Google Chrome) (Version: 38.0.2125.104 - Google Inc.)
Google Update Helper (x32 Version: 1.3.24.15 - Google Inc.) Hidden
Grim Facade: The Artist and The Pretender Collector's Edition (HKLM-x32\...\BFG-Grim Facade - The Artist and The Pretender Collectors Edition) (Version:  - )
Haunted Manor: Lord of Mirrors (HKLM-x32\...\BFG-Haunted Manor - Lord of Mirrors) (Version:  - )
Haunted Manor: Queen of Death (HKLM-x32\...\BFG-Haunted Manor - Queen of Death) (Version:  - )
iCloud (HKLM\...\{704C0303-D20C-45AF-BD2B-556EAF31BE09}) (Version: 2.1.2.8 - Apple Inc.)
Internet TV for Windows Media Center (HKLM-x32\...\{9D318C86-AF4C-409F-A6AC-7183FF4CF424}) (Version: 3.2.1.0 - Microsoft Corporation)
iTunes (HKLM\...\{F46AA0F1-E284-4878-A462-5F11B9166C0E}) (Version: 11.4.0.18 - Apple Inc.)
Java 8 Update 20 (HKLM-x32\...\{26A24AE4-039D-4CA4-87B4-2F83218020F0}) (Version: 8.0.200 - Oracle Corporation)
Java Auto Updater (x32 Version: 2.8.20.26 - Oracle Corporation) Hidden
Junk Mail filter update (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
kgcbaby (x32 Version: 5.03.0000.0002 - EASTMAN KODAK Company) Hidden
kgchday (x32 Version: 5.03.0000.0002 - EASTMAN KODAK Company) Hidden
kgchlwn (x32 Version: 5.03.0000.0002 - EASTMAN KODAK Company) Hidden
kgcinvt (x32 Version: 5.03.0000.0003 - EASTMAN KODAK Company) Hidden
kgckids (x32 Version: 5.03.0000.0002 - EASTMAN KODAK Company) Hidden
kgcmove (x32 Version: 5.03.0000.0003 - EASTMAN KODAK Company) Hidden
kgcvday (x32 Version: 5.03.0000.0002 - EASTMAN KODAK Company) Hidden
KhalInstallWrapper (Version: 2.00.0000 - Logitech) Hidden
Kodak EasyShare software (HKLM-x32\...\{D32470A1-B10C-4059-BA53-CF0486F68EBC}) (Version:  - Eastman Kodak Company)
League of Light: Wicked Harvest Collector's Edition (HKLM-x32\...\BFG-League of Light - Wicked Harvest Collectors Edition) (Version:  - )
Live! Cam Avatar Creator (HKLM-x32\...\{65D0C510-D7B6-4438-9FC8-E6B91115AB0D}) (Version: 4.6.2303.1 - Creative Technology Ltd)
Logitech SetPoint (HKLM-x32\...\{F29B21BD-CAA6-445F-8EF7-A7E2B9D8B14E}) (Version: 4.80 - Logitech)
Malwarebytes Anti-Malware version 2.0.2.1012 (HKLM-x32\...\Malwarebytes Anti-Malware_is1) (Version: 2.0.2.1012 - Malwarebytes Corporation)
Mesh Runtime (x32 Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Messenger Companion (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Microsoft .NET Framework 4.5.1 (HKLM\...\{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033) (Version: 4.5.50938 - Microsoft Corporation)
Microsoft .NET Framework 4.5.1 (Version: 4.5.50938 - Microsoft Corporation) Hidden
Microsoft Application Error Reporting (Version: 12.0.6015.5000 - Microsoft Corporation) Hidden
Microsoft Office 2007 Service Pack 3 (SP3) (HKLM-x32\...\{91120000-0011-0000-0000-0000000FF1CE}_PROPLUSR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}) (Version:  - Microsoft)
Microsoft Office 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Access MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Access Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Excel MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office File Validation Add-In (HKLM-x32\...\{90140000-2005-0000-0000-0000000FF1CE}) (Version: 14.0.5130.5003 - Microsoft Corporation)
Microsoft Office InfoPath MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Office 64-bit Components 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Outlook Connector (HKLM-x32\...\{95140000-007A-0409-0000-0000000FF1CE}) (Version: 14.0.5118.5000 - Microsoft Corporation)
Microsoft Office Outlook MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office PowerPoint Viewer 2007 (English) (HKLM-x32\...\{95120000-00AF-0409-0000-0000000FF1CE}) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (HKLM-x32\...\PROPLUSR) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Professional Plus 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (French) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proof (Spanish) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Proofing (English) 2007 (x32 Version: 12.0.4518.1014 - Microsoft Corporation) Hidden
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Publisher MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007 (Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Shared Setup Metadata MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Suite Activation Assistant (HKLM-x32\...\{67635FB6-2F63-4FFB-830B-D4C01597EBA4}) (Version: 1.2.1 - DELL)
Microsoft Office Visio 2007 Service Pack 3 (SP3) (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{CE144BF4-4950-4CDB-A5F7-CCE1888F49CB}) (Version:  - Microsoft)
Microsoft Office Visio 2007 Service Pack 3 (SP3) (x32 Version:  - Microsoft) Hidden
Microsoft Office Visio MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Visio Professional 2007 (HKLM-x32\...\VISPRO) (Version: 12.0.6612.1000 - Microsoft Corporation)
Microsoft Office Visio Professional 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Office Word MUI (English) 2007 (x32 Version: 12.0.6612.1000 - Microsoft Corporation) Hidden
Microsoft Silverlight (HKLM\...\{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}) (Version: 5.1.30514.0 - Microsoft Corporation)
Microsoft SQL Server 2005 Compact Edition [ENU] (HKLM-x32\...\{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}) (Version: 3.1.0000 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053 (HKLM\...\{B6E3757B-5E77-3915-866A-CCFC4B8D194C}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053 (HKLM-x32\...\{770657D0-A123-3C07-8E44-1C83EC895118}) (Version: 8.0.50727.4053 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (HKLM-x32\...\{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}) (Version: 8.0.61001 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{071c9b48-7c32-4621-a0ac-3f809523288f}) (Version: 8.0.56336 - Microsoft Corporation)
Microsoft Visual C++ 2005 Redistributable (x64) (HKLM\...\{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}) (Version: 8.0.61000 - Microsoft Corporation)
Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148 (HKLM-x32\...\{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}) (Version: 9.0.30729.4148 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17 (HKLM\...\{8220EEFE-38CD-377E-8595-13398D740ACE}) (Version: 9.0.30729 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161 (HKLM\...\{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022 (HKLM-x32\...\{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}) (Version: 9.0.21022 - Microsoft Corporation)
Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161 (HKLM-x32\...\{9BE518E6-ECC6-35A9-88E4-87755C07200F}) (Version: 9.0.30729.6161 - Microsoft Corporation)
Microsoft Visual C++ 2010  x86 Redistributable - 10.0.30319 (HKLM-x32\...\{196BB40D-1578-3D01-B289-BEFC77A11A1E}) (Version: 10.0.30319 - Microsoft Corporation)
Microsoft Works (HKLM-x32\...\{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}) (Version: 9.7.0621 - Microsoft Corporation)
Microsoft XNA Framework Redistributable 3.1 (HKLM-x32\...\{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}) (Version: 3.1.10527.0 - Microsoft Corporation)
MobileMe Control Panel (HKLM\...\{6DD01FF3-63CE-436B-96DB-61363EAA4EB8}) (Version: 3.1.8.0 - Apple Inc.)
Monitor Webcam Driver (1.01.02.0804)   (HKLM\...\Creative OA002) (Version:  - )
MSVCRT (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSVCRT_amd64 (x32 Version: 15.4.2862.0708 - Microsoft) Hidden
MSXML 4.0 SP2 (KB954430) (HKLM-x32\...\{86493ADD-824D-4B8E-BD72-8C5DCDC52A71}) (Version: 4.20.9870.0 - Microsoft Corporation)
MSXML 4.0 SP2 (KB973688) (HKLM-x32\...\{F662A8E6-F4DC-41A2-901E-8C11F044BDEC}) (Version: 4.20.9876.0 - Microsoft Corporation)
My Dell (HKLM\...\PC-Doctor for Windows) (Version: 3.5.6426.22 - PC-Doctor, Inc.)
My Farm (HKLM-x32\...\BFG-My Farm) (Version:  - )
My Singing Monsters (HKLM-x32\...\BFG-My Singing Monsters) (Version:  - )
Nikon Message Center (HKLM-x32\...\{D2FCC1AE-6311-47C5-8130-C6C66D77DD71}) (Version: 0.92.000 - Nikon)
Nikon Transfer (HKLM-x32\...\{E9757890-7EC5-46C8-99AB-B00F07B6525C}) (Version: 1.5.2 - Nikon)
OfotoXMI (x32 Version: 8.03.0000.0001 - EASTMAN KODAK Company) Hidden
OpenAL (HKLM-x32\...\OpenAL) (Version:  - )
Picture Control Utility (HKLM-x32\...\{87441A59-5E64-4096-A170-14EFE67200C3}) (Version: 1.1.9 - Nikon)
PowerDVD DX (HKLM-x32\...\{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}) (Version: 8.3.6107 - CyberLink Corp.)
PowerISO (HKLM-x32\...\PowerISO) (Version: 4.6 - PowerISO Computing, Inc.)
QualXServ Service Agreement (HKLM-x32\...\{903679E8-44C8-4C07-9600-05C92654FC50}) (Version: 2.0.0 - Dell Inc.)
QuickTime 7 (HKLM-x32\...\{111EE7DF-FC45-40C7-98A7-753AC46B12FB}) (Version: 7.75.80.95 - Apple Inc.)
Realtek High Definition Audio Driver (HKLM-x32\...\{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}) (Version: 6.0.1.5864 - Realtek Semiconductor Corp.)
Roxio Burn (HKLM-x32\...\{B2E47DE7-800B-40BB-BD1F-9F221C3AEE87}) (Version: 1.01 - Roxio)
Roxio Burn (x32 Version: 1.01 - Roxio) Hidden
Samsung Link 1.8.0.1403131552 (HKLM\...\8474-7877-9059-0204) (Version: 1.8.0.1403131552 - Copyright 2013 SAMSUNG)
Secrets of the Dark: Eclipse Mountain (HKLM-x32\...\BFG-Secrets of the Dark - Eclipse Mountain) (Version:  - )
SFR (x32 Version: 8.01.0000.0001 - Eastman Kodak Company) Hidden
SHASTA (x32 Version: 7.01.0000.0001 - EASTMAN KODAK Company) Hidden
skin0001 (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden
Skins (x32 Version: 2009.0614.2131.36800 - ATI) Hidden
SKINXSDK (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden
Skype Click to Call (HKLM-x32\...\{6D1221A9-17BF-4EC0-81F2-27D30EC30701}) (Version: 7.3.16540.9015 - Microsoft Corporation)
Skype™ 6.16 (HKLM-x32\...\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}) (Version: 6.16.105 - Skype Technologies S.A.)
Spelling Dictionaries Support For Adobe Reader 9 (HKLM-x32\...\{AC76BA86-7AD7-5464-3428-900000000004}) (Version: 9.0.0 - Adobe Systems Incorporated)
staticcr (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden
swMSM (x32 Version: 12.0.0.1 - Adobe Systems, Inc) Hidden
TeamViewer 6 (HKLM-x32\...\TeamViewer 6) (Version: 6.0.9947 - TeamViewer GmbH)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for 2007 Microsoft Office System (KB967642) (HKLM-x32\...\{91120000-0011-0000-0000-0000000FF1CE}_PROPLUSR_{C444285D-5E4F-48A4-91DD-47AAAA68E92D}) (Version:  - Microsoft)
Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_PROPLUSR_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version:  - Microsoft)
Update for Microsoft Office 2007 Help for Common Features (KB963673) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_VISPRO_{AB365889-0395-4FAD-B702-CA5985D53D42}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2596620) 32-Bit Edition (HKLM-x32\...\{91120000-0011-0000-0000-0000000FF1CE}_PROPLUSR_{A024FC7B-77DE-45DE-A058-1C049A17BFB3}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_PROPLUSR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-002A-0000-1000-0000000FF1CE}_VISPRO_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767849) 32-Bit Edition (HKLM-x32\...\{91120000-0011-0000-0000-0000000FF1CE}_PROPLUSR_{CB68A5B0-3508-4193-AEB9-AF636DAECE0F}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{90120000-0051-0000-0000-0000000FF1CE}_VISPRO_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office 2007 suites (KB2767916) 32-Bit Edition (HKLM-x32\...\{91120000-0011-0000-0000-0000000FF1CE}_PROPLUSR_{E9A82945-BA29-4EE8-8F2A-2F49545E9CF2}) (Version:  - Microsoft)
Update for Microsoft Office Access 2007 Help (KB963663) (HKLM-x32\...\{90120000-0015-0409-0000-0000000FF1CE}_PROPLUSR_{6B76A18A-AA1E-42AB-A7AD-6C84BBB43987}) (Version:  - Microsoft)
Update for Microsoft Office Excel 2007 Help (KB963678) (HKLM-x32\...\{90120000-0016-0409-0000-0000000FF1CE}_PROPLUSR_{199DF7B6-169C-448C-B511-1054101BE9C9}) (Version:  - Microsoft)
Update for Microsoft Office Infopath 2007 Help (KB963662) (HKLM-x32\...\{90120000-0044-0409-0000-0000000FF1CE}_PROPLUSR_{716B81B8-B13C-41DF-8EAC-7A2F656CAB63}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2687404) 32-Bit Edition (HKLM-x32\...\{90120000-001A-0409-0000-0000000FF1CE}_PROPLUSR_{ED38F8A3-4F61-494E-8BCA-E3AC7760C924}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 (KB2863811) 32-Bit Edition (HKLM-x32\...\{91120000-0011-0000-0000-0000000FF1CE}_PROPLUSR_{53DEC068-4690-4F6B-9946-7D21EF02236B}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Help (KB963677) (HKLM-x32\...\{90120000-001A-0409-0000-0000000FF1CE}_PROPLUSR_{0451F231-E3E3-4943-AB9F-58EB96171784}) (Version:  - Microsoft)
Update for Microsoft Office Outlook 2007 Junk Email Filter (KB2899475) 32-Bit Edition (HKLM-x32\...\{91120000-0011-0000-0000-0000000FF1CE}_PROPLUSR_{23AE87D8-AB2F-4539-935C-442BC976F469}) (Version:  - Microsoft)
Update for Microsoft Office Powerpoint 2007 Help (KB963669) (HKLM-x32\...\{90120000-0018-0409-0000-0000000FF1CE}_PROPLUSR_{397B1D4F-ED7B-4ACA-A637-43B670843876}) (Version:  - Microsoft)
Update for Microsoft Office Publisher 2007 Help (KB963667) (HKLM-x32\...\{90120000-0019-0409-0000-0000000FF1CE}_PROPLUSR_{2E40DE55-B289-4C8B-8901-5D369B16814F}) (Version:  - Microsoft)
Update for Microsoft Office Script Editor Help (KB963671) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_PROPLUSR_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version:  - Microsoft)
Update for Microsoft Office Script Editor Help (KB963671) (HKLM-x32\...\{90120000-006E-0409-0000-0000000FF1CE}_VISPRO_{CD11C6A2-FFC6-4271-8EAB-79C3582F505C}) (Version:  - Microsoft)
Update for Microsoft Office Visio 2007 Help (KB963666) (HKLM-x32\...\{90120000-0054-0409-0000-0000000FF1CE}_VISPRO_{D2C4ACC9-12F5-4E1C-81A8-5DC878AC6278}) (Version:  - Microsoft)
Update for Microsoft Office Word 2007 Help (KB963665) (HKLM-x32\...\{90120000-001B-0409-0000-0000000FF1CE}_PROPLUSR_{80E762AA-C921-4839-9D7D-DB62A72C0726}) (Version:  - Microsoft)
Verizon Download Manager (HKLM-x32\...\{F54E5D65-CB60-4A31-A71B-BCFB0FA0076D}) (Version: 1.0.0 - Verizon)
ViewNX (HKLM-x32\...\{F007CBCE-D714-4C0B-8CE9-9B0D78116468}) (Version: 1.5.1 - Nikon)
VPRINTOL (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden
Windows Live Communications Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Essentials (HKLM-x32\...\WinLiveSuite) (Version: 15.4.3555.0308 - Microsoft Corporation)
Windows Live Essentials (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Family Safety (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live ID Sign-in Assistant (Version: 7.250.4232.0 - Microsoft Corporation) Hidden
Windows Live Installer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Language Selector (Version: 15.4.3555.0308 - Microsoft Corporation) Hidden
Windows Live Mail (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Mesh ActiveX Control for Remote Connections (HKLM-x32\...\{2902F983-B4C1-44BA-B85D-5C6D52E2C441}) (Version: 15.4.5722.2 - Microsoft Corporation)
Windows Live Messenger (x32 Version: 15.4.3538.0513 - Microsoft Corporation) Hidden
Windows Live Messenger Companion Core (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live MIME IFilter (Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Movie Maker (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Common (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Photo Gallery (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live PIMT Platform (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Remote Client (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Client Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live Remote Service Resources (Version: 15.4.5722.2 - Microsoft Corporation) Hidden
Windows Live SOXE (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live SOXE Definitions (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Sync (HKLM-x32\...\{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}) (Version: 14.0.8089.726 - Microsoft Corporation)
Windows Live UX Platform (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live UX Platform Language Pack (x32 Version: 15.4.3508.1109 - Microsoft Corporation) Hidden
Windows Live Writer (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Live Writer Resources (x32 Version: 15.4.3502.0922 - Microsoft Corporation) Hidden
Windows Media Center Add-in for Flash (HKLM-x32\...\{E2D09AC2-4153-4817-AAEB-24F92A8BCE88}) (Version: 3.1.1.0 - Microsoft Corporation)
WIRELESS (x32 Version: 8.02.0000.0001 - EASTMAN KODAK Company) Hidden
World Mosaics 6 (HKLM-x32\...\BFG-World Mosaics 6) (Version:  - )
Yahoo! Detect (HKLM-x32\...\YTdetect) (Version:  - )

==================== Custom CLSID (selected items): ==========================

(If an entry is included in the fixlist, it will be removed from registry. Any eventual file will not be moved.)


==================== Restore Points  =========================

26-09-2014 07:00:12 Windows Update
01-10-2014 20:08:13 Windows Update
02-10-2014 07:00:25 Windows Update
07-10-2014 19:30:07 Windows Update
15-10-2014 15:25:25 Windows Update
16-10-2014 07:00:38 Windows Update

==================== Hosts content: ==========================

(If needed Hosts: directive could be included in the fixlist to reset Hosts.)

2009-07-13 22:34 - 2014-05-29 19:47 - 00000027 ____A C:\Windows\system32\Drivers\etc\hosts
127.0.0.1       localhost

==================== Scheduled Tasks (whitelisted) =============

(If an entry is included in the fixlist, it will be removed from registry. Any associated file could be listed separately to be moved.)

Task: {0C0E7F8C-6F94-4D5B-BD37-09851FE76573} - System32\Tasks\SystemToolsDailyTest => uaclauncher.exe
Task: {1E62C29C-938B-4CCF-9F56-180040D38366} - System32\Tasks\Adobe Flash Player Updater => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe [2014-10-15] (Adobe Systems Incorporated)
Task: {2516EE98-0811-46DE-8B7F-B0F0AC02E5F0} - System32\Tasks\EasyShare Registration Task => Rundll32.exe C:\PROGRA~3\Kodak\EasyShareSetup\$REGIS~1\Registration_8.3.20.1.sxt _RegistrationOffer@16
Task: {434A4DC1-6AB9-488D-B0D2-C652184416E8} - System32\Tasks\CCleanerSkipUAC => C:\Program Files (x86)\CCleaner\CCleaner.exe [2014-08-21] (Piriform Ltd)
Task: {7768E124-B1C2-4536-89D6-05AE0085ECE1} - System32\Tasks\GoogleUpdateTaskMachineCore => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-19] (Google Inc.)
Task: {78B1E3EA-02CF-417B-BF73-3366D4DED823} - System32\Tasks\Apple\AppleSoftwareUpdate => C:\Program Files (x86)\Apple Software Update\SoftwareUpdate.exe [2011-06-01] (Apple Inc.)
Task: {8483AE21-980A-4A71-969B-4A4BF3F10C4E} - System32\Tasks\{DE0C114E-70F6-444C-A1A2-0B35CF289A1A} => Iexplore.exe http://ui.skype.com/ui/0/4.1.0.179.259/en/privacy?source=lightinstaller
Task: {C339CA45-49C0-445D-81B9-A8B0425E5D15} - System32\Tasks\avast! Emergency Update => C:\Program Files\AVAST Software\Avast\AvastEmUpdate.exe [2014-07-14] (AVAST Software)
Task: {D0C29A28-42FC-41EE-81D7-994665569DF0} - System32\Tasks\GoogleUpdateTaskMachineUA => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe [2011-03-19] (Google Inc.)
Task: {DF973A32-AD2A-4DD2-B619-06B44DE30FFA} - System32\Tasks\{51780307-D1A4-4D3D-8DD1-12B91824D1FE} => C:\Program Files (x86)\Skype\Phone\Skype.exe [2014-05-08] (Skype Technologies S.A.)
Task: {EB346EE2-B125-4BB5-95DF-E2557587F12C} - System32\Tasks\PCDoctorBackgroundMonitorTask => C:\Program Files\My Dell\uaclauncher.exe [2014-01-10] (PC-Doctor, Inc.)
Task: {FFAF6F97-770F-4BAC-8ABF-6B5460389D64} - System32\Tasks\PCDEventLauncherTask => C:\Program Files\My Dell\sessionchecker.exe [2014-01-10] (PC-Doctor, Inc.)
Task: C:\Windows\Tasks\Adobe Flash Player Updater.job => C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
Task: C:\Windows\Tasks\EasyShare Registration Task.job => à[ƒÃþ@²
W³_­9óFb<
 sÀ €!Þ
4'R!C:\Windows\system32\rundll32.exeZC:\PROGRA~3\Kodak\EasyShareSetup\$REGIS~1\Registration_8.3.20.1.sxt _RegistrationOffer@16Chrissy0Ý9
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
Task: C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job => C:\Program Files (x86)\Google\Update\GoogleUpdate.exe

==================== Loaded Modules (whitelisted) =============

2010-02-10 01:55 - 2009-11-04 09:17 - 00189440 _____ () C:\Windows\system32\spool\PRTPROCS\x64\dleadrpp.dll
2010-02-10 01:54 - 2010-01-07 17:09 - 00033448 _____ () C:\Windows\system32\spool\DRIVERS\x64\3\dleaserv.exe
2013-06-03 16:57 - 2014-03-13 15:52 - 00013824 _____ () C:\Program Files\Samsung\Samsung Link\JniSys.dll
2014-05-29 19:52 - 2014-05-29 19:52 - 00515584 ____N () C:\Windows\Temp\sqlite-3.7.2-sqlitejdbc.dll
2013-09-04 13:53 - 2014-03-13 15:52 - 02149376 _____ () C:\Program Files\Samsung\Samsung Link\scone_proxy.dll
2013-09-04 13:53 - 2014-03-13 15:52 - 01630720 _____ () C:\Program Files\Samsung\Samsung Link\scone_stub.dll
2013-12-21 12:25 - 2013-12-21 12:25 - 00036864 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\JNIInterface.dll
2013-12-21 12:26 - 2013-12-21 12:26 - 00144384 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\ASFAPI.dll
2013-12-21 12:27 - 2013-12-21 12:27 - 00018944 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\MediaDB_Manager.dll
2013-10-22 10:52 - 2013-10-22 10:52 - 00030720 _____ () C:\Windows\system32\MediaDB64.dll
2013-10-22 10:52 - 2013-10-22 10:52 - 00908800 _____ () C:\Windows\system32\ContentDirectoryPresenter64.dll
2013-12-21 12:27 - 2013-12-21 12:27 - 00521728 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\64bit\DMS_Manager.dll
2013-07-23 20:19 - 2013-07-23 20:19 - 00049152 _____ () C:\Windows\system32\boost_date_time-vc90-mt-1_47.dll
2013-07-23 20:19 - 2013-07-23 20:19 - 00016896 _____ () C:\Windows\system32\boost_system-vc90-mt-1_47.dll
2013-07-23 20:19 - 2013-07-23 20:19 - 00058880 _____ () C:\Windows\system32\boost_thread-vc90-mt-1_47.dll
2013-07-23 20:19 - 2013-07-23 20:19 - 00299520 _____ () C:\Windows\system32\boost_serialization-vc90-mt-1_47.dll
2013-06-03 16:57 - 2014-03-13 15:52 - 00048640 _____ () C:\Program Files\Samsung\Samsung Link\JniIO.dll
2010-02-10 01:54 - 2009-12-16 13:21 - 01558528 _____ () C:\Program Files\Dell\V310-V510 Series\dleadrs64.dll
2010-02-10 01:54 - 2009-11-26 04:54 - 00075264 _____ () C:\Program Files\Dell\V310-V510 Series\dleacfg64.dll
2010-02-10 01:54 - 2009-03-10 01:44 - 00015360 _____ () C:\Program Files\Dell\V310-V510 Series\dleacaps64.dll
2010-02-10 01:54 - 2009-03-05 13:55 - 00057344 _____ () C:\Program Files\Dell\V310-V510 Series\dleacnv464.dll
2010-02-10 01:54 - 2009-12-16 07:42 - 00205824 _____ () C:\Program Files\Dell\V310-V510 Series\dleamicro.dll
2010-02-10 01:53 - 2010-01-18 13:13 - 00770728 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe
2010-02-10 01:53 - 2010-01-18 13:13 - 00139944 _____ () C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe
2010-02-10 04:48 - 2009-07-20 13:35 - 00018960 _____ () C:\Program Files\Logitech\SetPoint\khalwrapper.dll
2014-10-16 03:47 - 2014-10-16 03:47 - 00472576 _____ () C:\Windows\assembly\NativeImages_v2.0.50727_64\VistaBridgeLibrary\27062a1bd5e07ac476c1ef919d9abff5\VistaBridgeLibrary.ni.dll
2010-02-10 04:48 - 2009-07-20 05:00 - 00077824 _____ () C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
2008-11-18 13:00 - 2008-11-18 13:00 - 00016384 ____R () c:\Program Files (x86)\ATI Technologies\ATI.ACE\Branding\Branding.dll
2014-08-28 16:56 - 2014-08-28 16:56 - 00270336 _____ () C:\Windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
2014-07-14 01:28 - 2014-07-14 01:28 - 00301152 _____ () C:\Program Files\AVAST Software\Avast\aswProperty.dll
2014-10-16 13:38 - 2014-10-16 13:38 - 02874368 _____ () C:\Program Files\AVAST Software\Avast\defs\14101601\algo.dll
2014-10-17 18:21 - 2014-10-17 18:21 - 02875904 _____ () C:\Program Files\AVAST Software\Avast\defs\14101701\algo.dll
2014-02-06 01:52 - 2014-02-06 01:52 - 00073544 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
2014-02-06 01:52 - 2014-02-06 01:52 - 01044808 _____ () C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
2013-12-11 17:46 - 2013-12-11 17:46 - 01114624 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DMSManager.dll
2013-10-22 10:48 - 2013-10-22 10:48 - 00707072 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ContentDirectoryPresenter.dll
2013-10-24 17:53 - 2013-10-24 17:53 - 00107008 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DCMCDP.dll
2013-12-11 17:46 - 2013-12-11 17:46 - 00102400 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\FolderCDP.dll
2013-12-11 17:46 - 2013-12-11 17:46 - 00077312 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\MetadataFramework.dll
2013-02-14 20:42 - 2013-02-14 20:42 - 00520234 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\sqlite3.dll
2013-02-14 20:42 - 2013-02-14 20:42 - 00450560 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\MoodExtractor.dll
2013-02-14 20:42 - 2013-02-14 20:42 - 05717504 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\DCMImgExtractor.dll
2013-10-25 20:48 - 2013-10-25 20:48 - 00028672 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AutoChaptering.dll
2013-02-14 20:42 - 2013-02-14 20:42 - 00147456 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libexpat.dll
2013-10-25 20:48 - 2013-10-25 20:48 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoThumb.dll
2013-02-14 20:42 - 2013-02-14 20:42 - 04671488 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avcodec-52.dll
2013-02-14 20:42 - 2013-02-14 20:42 - 00070656 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avutil-50.dll
2013-02-14 20:42 - 2013-02-14 20:42 - 00686080 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\avformat-52.dll
2013-02-14 20:42 - 2013-02-14 20:42 - 00152064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\swscale-0.dll
2013-10-25 20:49 - 2013-10-25 20:49 - 00028160 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AudioExtractor.dll
2013-10-25 20:48 - 2013-10-25 20:48 - 00064000 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ID3Driver.dll
2013-02-14 20:42 - 2013-02-14 20:42 - 00366592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\tag.dll
2013-10-25 20:48 - 2013-10-25 20:48 - 00289792 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libThumbnail.dll
2013-10-25 20:48 - 2013-10-25 20:48 - 00023040 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\RichInfoDriver.dll
2013-12-11 17:45 - 2013-12-11 17:45 - 00017920 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoExtractor.dll
2013-10-25 20:53 - 2013-10-25 20:53 - 00117248 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ThumbnailMaker.dll
2013-10-25 20:53 - 2013-10-25 20:53 - 01033728 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ImageMagickWrapper.dll
2013-12-11 17:45 - 2013-12-11 17:45 - 00134144 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\VideoMetadataDriver.dll
2013-10-25 20:48 - 2013-10-25 20:48 - 00290816 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libKeyFrame.dll
2013-10-25 20:48 - 2013-10-25 20:48 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\SECMetaDriver.dll
2013-10-25 20:53 - 2013-10-25 20:53 - 00012288 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\ImageExtractor.dll
2013-10-25 20:48 - 2013-10-25 20:48 - 00024064 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\photoDriver.dll
2013-02-14 20:42 - 2013-02-14 20:42 - 00399826 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\libexif-12.dll.dll
2013-10-25 20:48 - 2013-10-25 20:48 - 00013824 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\TextExtractor.dll
2013-10-24 17:53 - 2013-10-24 17:53 - 00032768 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\Autobackup.dll
2013-04-19 17:38 - 2013-04-19 17:38 - 00055808 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\RosettaAllShare.dll
2013-07-23 20:18 - 2013-07-23 20:18 - 00227840 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_serialization-vc90-mt-1_47.dll
2013-07-23 20:18 - 2013-07-23 20:18 - 00038912 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_date_time-vc90-mt-1_47.dll
2013-07-23 20:18 - 2013-07-23 20:18 - 00012800 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_system-vc90-mt-1_47.dll
2013-07-23 20:18 - 2013-07-23 20:18 - 00046592 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\boost_thread-vc90-mt-1_47.dll
2013-02-14 20:42 - 2013-02-14 20:42 - 00044032 _____ () C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\us.dll
2010-02-01 23:24 - 2009-09-17 14:04 - 00115952 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\PSTVdsDisk.dll
2010-02-01 23:24 - 2009-09-17 14:05 - 00128240 ____N () C:\Program Files (x86)\Dell DataSafe Local Backup\STLog.dll
2010-02-10 01:53 - 2009-11-26 04:49 - 00086180 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleacfg.dll
2010-02-10 01:53 - 2009-12-16 13:04 - 00389120 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleascw.dll
2010-02-10 01:53 - 2009-05-27 08:16 - 00192512 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleadatr.dll
2010-02-10 01:53 - 2009-05-27 08:13 - 00081920 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleacats.dll
2010-02-10 01:53 - 2009-12-16 13:07 - 01159168 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleaDRS.dll
2010-02-10 01:53 - 2009-03-10 01:43 - 00155648 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleacaps.dll
2010-02-10 01:53 - 2009-03-05 13:55 - 00059904 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleacnv4.dll
2010-02-10 01:49 - 2009-02-20 04:50 - 00381440 _____ () C:\Windows\system32\dleasm.dll
2010-02-10 01:49 - 2009-02-20 04:50 - 00028672 _____ () C:\Windows\system32\dleasmr.dll
2010-02-10 01:53 - 2009-06-22 09:08 - 00708608 _____ () C:\Program Files (x86)\Dell V310-V510 Series\Epwizard.DLL
2010-02-10 01:53 - 2009-06-22 09:06 - 00159744 _____ () C:\Program Files (x86)\Dell V310-V510 Series\customui.dll
2010-02-10 01:53 - 2009-06-22 09:06 - 00114688 _____ () C:\Program Files (x86)\Dell V310-V510 Series\Eputil.DLL
2010-02-10 01:53 - 2009-06-22 09:05 - 00139264 _____ () C:\Program Files (x86)\Dell V310-V510 Series\Imagutil.DLL
2010-02-10 01:53 - 2009-06-22 09:06 - 00061440 _____ () C:\Program Files (x86)\Dell V310-V510 Series\Epfunct.DLL
2010-02-10 01:53 - 2009-06-22 09:08 - 02203648 _____ () C:\Program Files (x86)\Dell V310-V510 Series\EPWizRes.dll
2010-02-10 01:53 - 2009-06-22 09:08 - 00045056 _____ () C:\Program Files (x86)\Dell V310-V510 Series\epstring.dll
2010-02-10 01:53 - 2009-06-22 09:08 - 00196608 _____ () C:\Program Files (x86)\Dell V310-V510 Series\EPOEMDll.dll
2010-02-10 01:53 - 2009-04-07 15:25 - 00409600 _____ () C:\Program Files (x86)\Dell V310-V510 Series\iptk.dll
2010-02-10 01:53 - 2009-03-02 10:25 - 00151552 _____ () C:\Program Files (x86)\Dell V310-V510 Series\dleaptp.dll
2014-07-14 01:28 - 2014-07-14 01:28 - 19329904 _____ () C:\Program Files\AVAST Software\Avast\libcef.dll
2014-10-15 16:13 - 2014-10-09 22:03 - 01042760 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libglesv2.dll
2014-10-15 16:13 - 2014-10-09 22:03 - 00211272 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\libegl.dll
2014-10-15 16:13 - 2014-10-09 22:04 - 08910664 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\pdf.dll
2014-10-15 16:13 - 2014-10-09 22:03 - 01681224 _____ () C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.104\ffmpegsumo.dll

==================== Alternate Data Streams (whitelisted) =========

(If an entry is included in the fixlist, only the Alternate Data Streams will be removed.)

AlternateDataStreams: C:\ProgramData\TEMP:008FE370
AlternateDataStreams: C:\ProgramData\TEMP:00D99749
AlternateDataStreams: C:\ProgramData\TEMP:0102CF0C
AlternateDataStreams: C:\ProgramData\TEMP:014BC3B4
AlternateDataStreams: C:\ProgramData\TEMP:0168CC60
AlternateDataStreams: C:\ProgramData\TEMP:017D5143
AlternateDataStreams: C:\ProgramData\TEMP:01F9D1B4
AlternateDataStreams: C:\ProgramData\TEMP:021496FB
AlternateDataStreams: C:\ProgramData\TEMP:025C72E5
AlternateDataStreams: C:\ProgramData\TEMP:02A78DF6
AlternateDataStreams: C:\ProgramData\TEMP:02CC0035
AlternateDataStreams: C:\ProgramData\TEMP:02F30776
AlternateDataStreams: C:\ProgramData\TEMP:036AA5DD
AlternateDataStreams: C:\ProgramData\TEMP:03D08225
AlternateDataStreams: C:\ProgramData\TEMP:0410A323
AlternateDataStreams: C:\ProgramData\TEMP:041C0562
AlternateDataStreams: C:\ProgramData\TEMP:041ED421
AlternateDataStreams: C:\ProgramData\TEMP:0474F714
AlternateDataStreams: C:\ProgramData\TEMP:04EAB86F
AlternateDataStreams: C:\ProgramData\TEMP:04FB3774
AlternateDataStreams: C:\ProgramData\TEMP:05113FB9
AlternateDataStreams: C:\ProgramData\TEMP:052A05A1
AlternateDataStreams: C:\ProgramData\TEMP:05F547A9
AlternateDataStreams: C:\ProgramData\TEMP:0696EC8E
AlternateDataStreams: C:\ProgramData\TEMP:069BAEA8
AlternateDataStreams: C:\ProgramData\TEMP:073139EC
AlternateDataStreams: C:\ProgramData\TEMP:07437A8C
AlternateDataStreams: C:\ProgramData\TEMP:0785072C
AlternateDataStreams: C:\ProgramData\TEMP:078B239B
AlternateDataStreams: C:\ProgramData\TEMP:07A75CBF
AlternateDataStreams: C:\ProgramData\TEMP:07C99568
AlternateDataStreams: C:\ProgramData\TEMP:083C8737
AlternateDataStreams: C:\ProgramData\TEMP:087CB364
AlternateDataStreams: C:\ProgramData\TEMP:08DB8D99
AlternateDataStreams: C:\ProgramData\TEMP:08E5EE32
AlternateDataStreams: C:\ProgramData\TEMP:0951C4CC
AlternateDataStreams: C:\ProgramData\TEMP:0968E571
AlternateDataStreams: C:\ProgramData\TEMP:097C4B7D
AlternateDataStreams: C:\ProgramData\TEMP:097FF903
AlternateDataStreams: C:\ProgramData\TEMP:0A701F26
AlternateDataStreams: C:\ProgramData\TEMP:0AC0213C
AlternateDataStreams: C:\ProgramData\TEMP:0ACF1AF5
AlternateDataStreams: C:\ProgramData\TEMP:0ADCCF52
AlternateDataStreams: C:\ProgramData\TEMP:0AE6CC6C
AlternateDataStreams: C:\ProgramData\TEMP:0AF3BFB9
AlternateDataStreams: C:\ProgramData\TEMP:0AF3C3DF
AlternateDataStreams: C:\ProgramData\TEMP:0B3F95D0
AlternateDataStreams: C:\ProgramData\TEMP:0B55751B
AlternateDataStreams: C:\ProgramData\TEMP:0B79AB8D
AlternateDataStreams: C:\ProgramData\TEMP:0BCD47A5
AlternateDataStreams: C:\ProgramData\TEMP:0C9E06A2
AlternateDataStreams: C:\ProgramData\TEMP:0CDBB2C2
AlternateDataStreams: C:\ProgramData\TEMP:0CDF8C3D
AlternateDataStreams: C:\ProgramData\TEMP:0D761AB3
AlternateDataStreams: C:\ProgramData\TEMP:0D797314
AlternateDataStreams: C:\ProgramData\TEMP:0DE96CF5
AlternateDataStreams: C:\ProgramData\TEMP:0E10B960
AlternateDataStreams: C:\ProgramData\TEMP:0E61938B
AlternateDataStreams: C:\ProgramData\TEMP:0E660858
AlternateDataStreams: C:\ProgramData\TEMP:0E8117B1
AlternateDataStreams: C:\ProgramData\TEMP:0EAA09AC
AlternateDataStreams: C:\ProgramData\TEMP:0EBD727C
AlternateDataStreams: C:\ProgramData\TEMP:0ED1C542
AlternateDataStreams: C:\ProgramData\TEMP:0F5DCBF5
AlternateDataStreams: C:\ProgramData\TEMP:0F64164E
AlternateDataStreams: C:\ProgramData\TEMP:0FAE191E
AlternateDataStreams: C:\ProgramData\TEMP:0FD8569B
AlternateDataStreams: C:\ProgramData\TEMP:0FE0A03C
AlternateDataStreams: C:\ProgramData\TEMP:1011DA7C
AlternateDataStreams: C:\ProgramData\TEMP:1013B07C
AlternateDataStreams: C:\ProgramData\TEMP:1044BAFC
AlternateDataStreams: C:\ProgramData\TEMP:104A1C3E
AlternateDataStreams: C:\ProgramData\TEMP:109734F6
AlternateDataStreams: C:\ProgramData\TEMP:10CB85CA
AlternateDataStreams: C:\ProgramData\TEMP:10D45FC3
AlternateDataStreams: C:\ProgramData\TEMP:10D7EE4B
AlternateDataStreams: C:\ProgramData\TEMP:10DB9BB7
AlternateDataStreams: C:\ProgramData\TEMP:10E295F9
AlternateDataStreams: C:\ProgramData\TEMP:114C90CA
AlternateDataStreams: C:\ProgramData\TEMP:1170D6E4
AlternateDataStreams: C:\ProgramData\TEMP:11C7FAE3
AlternateDataStreams: C:\ProgramData\TEMP:11EFE63D
AlternateDataStreams: C:\ProgramData\TEMP:120B3AFD
AlternateDataStreams: C:\ProgramData\TEMP:120E44A4
AlternateDataStreams: C:\ProgramData\TEMP:1224B4C3
AlternateDataStreams: C:\ProgramData\TEMP:12383CAE
AlternateDataStreams: C:\ProgramData\TEMP:124B94C0
AlternateDataStreams: C:\ProgramData\TEMP:128B55C8
AlternateDataStreams: C:\ProgramData\TEMP:12A012A1
AlternateDataStreams: C:\ProgramData\TEMP:12BCD9DC
AlternateDataStreams: C:\ProgramData\TEMP:12D136AA
AlternateDataStreams: C:\ProgramData\TEMP:12D21A9A
AlternateDataStreams: C:\ProgramData\TEMP:12D2EB9C
AlternateDataStreams: C:\ProgramData\TEMP:12D9D48F
AlternateDataStreams: C:\ProgramData\TEMP:12E189B0
AlternateDataStreams: C:\ProgramData\TEMP:13019F4B
AlternateDataStreams: C:\ProgramData\TEMP:1345C9DC
AlternateDataStreams: C:\ProgramData\TEMP:134FBDE2
AlternateDataStreams: C:\ProgramData\TEMP:13765436
AlternateDataStreams: C:\ProgramData\TEMP:13CDB0E0
AlternateDataStreams: C:\ProgramData\TEMP:140AD176
AlternateDataStreams: C:\ProgramData\TEMP:14168AA3
AlternateDataStreams: C:\ProgramData\TEMP:1416AAA6
AlternateDataStreams: C:\ProgramData\TEMP:149327FE
AlternateDataStreams: C:\ProgramData\TEMP:159A493A
AlternateDataStreams: C:\ProgramData\TEMP:1604D047
AlternateDataStreams: C:\ProgramData\TEMP:161B4B1D
AlternateDataStreams: C:\ProgramData\TEMP:164561C8
AlternateDataStreams: C:\ProgramData\TEMP:1656EE95
AlternateDataStreams: C:\ProgramData\TEMP:16BD7665
AlternateDataStreams: C:\ProgramData\TEMP:16F42F1F
AlternateDataStreams: C:\ProgramData\TEMP:16F4BC64
AlternateDataStreams: C:\ProgramData\TEMP:1802D824
AlternateDataStreams: C:\ProgramData\TEMP:183A9046
AlternateDataStreams: C:\ProgramData\TEMP:18B241CC
AlternateDataStreams: C:\ProgramData\TEMP:18E3BAF3
AlternateDataStreams: C:\ProgramData\TEMP:19474103
AlternateDataStreams: C:\ProgramData\TEMP:19C541B5
AlternateDataStreams: C:\ProgramData\TEMP:1A15E356
AlternateDataStreams: C:\ProgramData\TEMP:1A259A13
AlternateDataStreams: C:\ProgramData\TEMP:1A45D40E
AlternateDataStreams: C:\ProgramData\TEMP:1A5822A3
AlternateDataStreams: C:\ProgramData\TEMP:1A5CC80A
AlternateDataStreams: C:\ProgramData\TEMP:1ABFB99D
AlternateDataStreams: C:\ProgramData\TEMP:1ADC4BD5
AlternateDataStreams: C:\ProgramData\TEMP:1B3549F2
AlternateDataStreams: C:\ProgramData\TEMP:1B389835
AlternateDataStreams: C:\ProgramData\TEMP:1B47CB83
AlternateDataStreams: C:\ProgramData\TEMP:1B5B615D
AlternateDataStreams: C:\ProgramData\TEMP:1B7E916D
AlternateDataStreams: C:\ProgramData\TEMP:1B825050
AlternateDataStreams: C:\ProgramData\TEMP:1B8A258D
AlternateDataStreams: C:\ProgramData\TEMP:1B90AAB4
AlternateDataStreams: C:\ProgramData\TEMP:1B927722
AlternateDataStreams: C:\ProgramData\TEMP:1B96CF22
AlternateDataStreams: C:\ProgramData\TEMP:1B97BCB0
AlternateDataStreams: C:\ProgramData\TEMP:1C201DEB
AlternateDataStreams: C:\ProgramData\TEMP:1C5692E6
AlternateDataStreams: C:\ProgramData\TEMP:1C6D705B
AlternateDataStreams: C:\ProgramData\TEMP:1C9565AC
AlternateDataStreams: C:\ProgramData\TEMP:1CB8D545
AlternateDataStreams: C:\ProgramData\TEMP:1CB96B16
AlternateDataStreams: C:\ProgramData\TEMP:1CD511E5
AlternateDataStreams: C:\ProgramData\TEMP:1CF1FB36
AlternateDataStreams: C:\ProgramData\TEMP:1D60AEC3
AlternateDataStreams: C:\ProgramData\TEMP:1D6B18F1
AlternateDataStreams: C:\ProgramData\TEMP:1D9ED8F7
AlternateDataStreams: C:\ProgramData\TEMP:1DDD0008
AlternateDataStreams: C:\ProgramData\TEMP:1E288DA3
AlternateDataStreams: C:\ProgramData\TEMP:1E4D6E88
AlternateDataStreams: C:\ProgramData\TEMP:1E5EC928
AlternateDataStreams: C:\ProgramData\TEMP:1E86ADD2
AlternateDataStreams: C:\ProgramData\TEMP:1E942FB9
AlternateDataStreams: C:\ProgramData\TEMP:1EC13383
AlternateDataStreams: C:\ProgramData\TEMP:1F0FA039
AlternateDataStreams: C:\ProgramData\TEMP:1FA4C06F
AlternateDataStreams: C:\ProgramData\TEMP:1FF82161
AlternateDataStreams: C:\ProgramData\TEMP:2043337E
AlternateDataStreams: C:\ProgramData\TEMP:204BEE0F
AlternateDataStreams: C:\ProgramData\TEMP:207C4C79
AlternateDataStreams: C:\ProgramData\TEMP:217A2324
AlternateDataStreams: C:\ProgramData\TEMP:217A2A36
AlternateDataStreams: C:\ProgramData\TEMP:219DB32E
AlternateDataStreams: C:\ProgramData\TEMP:21D64A91
AlternateDataStreams: C:\ProgramData\TEMP:21D69AEA
AlternateDataStreams: C:\ProgramData\TEMP:220E9B9E
AlternateDataStreams: C:\ProgramData\TEMP:2211E7A0
AlternateDataStreams: C:\ProgramData\TEMP:2216A431
AlternateDataStreams: C:\ProgramData\TEMP:2245476B
AlternateDataStreams: C:\ProgramData\TEMP:22C80839
AlternateDataStreams: C:\ProgramData\TEMP:236FF5C6
AlternateDataStreams: C:\ProgramData\TEMP:23834E1E
AlternateDataStreams: C:\ProgramData\TEMP:241FA548
AlternateDataStreams: C:\ProgramData\TEMP:242749DF
AlternateDataStreams: C:\ProgramData\TEMP:244E4E3A
AlternateDataStreams: C:\ProgramData\TEMP:24C072FF
AlternateDataStreams: C:\ProgramData\TEMP:24C89EFC
AlternateDataStreams: C:\ProgramData\TEMP:24F08129
AlternateDataStreams: C:\ProgramData\TEMP:25005EFA
AlternateDataStreams: C:\ProgramData\TEMP:2512FA90
AlternateDataStreams: C:\ProgramData\TEMP:252E6179
AlternateDataStreams: C:\ProgramData\TEMP:2530BFBE
AlternateDataStreams: C:\ProgramData\TEMP:2556A8A0
AlternateDataStreams: C:\ProgramData\TEMP:258D2F8B
AlternateDataStreams: C:\ProgramData\TEMP:26140299
AlternateDataStreams: C:\ProgramData\TEMP:2640C43F
AlternateDataStreams: C:\ProgramData\TEMP:2652902F
AlternateDataStreams: C:\ProgramData\TEMP:26991AB9
AlternateDataStreams: C:\ProgramData\TEMP:2727F067
AlternateDataStreams: C:\ProgramData\TEMP:2773164E
AlternateDataStreams: C:\ProgramData\TEMP:27790C06
AlternateDataStreams: C:\ProgramData\TEMP:27A88EF2
AlternateDataStreams: C:\ProgramData\TEMP:27B99ED6
AlternateDataStreams: C:\ProgramData\TEMP:27C3CD07
AlternateDataStreams: C:\ProgramData\TEMP:282CE153
AlternateDataStreams: C:\ProgramData\TEMP:28CDD861
AlternateDataStreams: C:\ProgramData\TEMP:29861223
AlternateDataStreams: C:\ProgramData\TEMP:29ADC74D
AlternateDataStreams: C:\ProgramData\TEMP:29B37860
AlternateDataStreams: C:\ProgramData\TEMP:29C0641D
AlternateDataStreams: C:\ProgramData\TEMP:29DA7FEE
AlternateDataStreams: C:\ProgramData\TEMP:29F0CA7D
AlternateDataStreams: C:\ProgramData\TEMP:2A5BC0A9
AlternateDataStreams: C:\ProgramData\TEMP:2AD33723
AlternateDataStreams: C:\ProgramData\TEMP:2AE74FF9
AlternateDataStreams: C:\ProgramData\TEMP:2AF05C70
AlternateDataStreams: C:\ProgramData\TEMP:2AF322BF
AlternateDataStreams: C:\ProgramData\TEMP:2B37CCB6
AlternateDataStreams: C:\ProgramData\TEMP:2B40A7DB
AlternateDataStreams: C:\ProgramData\TEMP:2B5C4773
AlternateDataStreams: C:\ProgramData\TEMP:2B856118
AlternateDataStreams: C:\ProgramData\TEMP:2B9555D8
AlternateDataStreams: C:\ProgramData\TEMP:2C4F33F6
AlternateDataStreams: C:\ProgramData\TEMP:2C84CA43
AlternateDataStreams: C:\ProgramData\TEMP:2CA4B471
AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F
AlternateDataStreams: C:\ProgramData\TEMP:2CC32B31
AlternateDataStreams: C:\ProgramData\TEMP:2CFBE2D1
AlternateDataStreams: C:\ProgramData\TEMP:2D2461E7
AlternateDataStreams: C:\ProgramData\TEMP:2DE5673D
AlternateDataStreams: C:\ProgramData\TEMP:2DF54B62
AlternateDataStreams: C:\ProgramData\TEMP:2DF93164
AlternateDataStreams: C:\ProgramData\TEMP:2E3F04BC
AlternateDataStreams: C:\ProgramData\TEMP:2E636DD9
AlternateDataStreams: C:\ProgramData\TEMP:2E87E3DD
AlternateDataStreams: C:\ProgramData\TEMP:2E928E6E
AlternateDataStreams: C:\ProgramData\TEMP:2E9900EE
AlternateDataStreams: C:\ProgramData\TEMP:2F474C84
AlternateDataStreams: C:\ProgramData\TEMP:2F5A06FD
AlternateDataStreams: C:\ProgramData\TEMP:2F8138B7
AlternateDataStreams: C:\ProgramData\TEMP:2FAFBD6A
AlternateDataStreams: C:\ProgramData\TEMP:2FF4577A
AlternateDataStreams: C:\ProgramData\TEMP:302ECBD6
AlternateDataStreams: C:\ProgramData\TEMP:3086B95F
AlternateDataStreams: C:\ProgramData\TEMP:311A2F6A
AlternateDataStreams: C:\ProgramData\TEMP:31403DF7
AlternateDataStreams: C:\ProgramData\TEMP:31C9BA96
AlternateDataStreams: C:\ProgramData\TEMP:320208DA
AlternateDataStreams: C:\ProgramData\TEMP:321156F2
AlternateDataStreams: C:\ProgramData\TEMP:32289BE8
AlternateDataStreams: C:\ProgramData\TEMP:322D2CD3
AlternateDataStreams: C:\ProgramData\TEMP:3241739E
AlternateDataStreams: C:\ProgramData\TEMP:32D2A239
AlternateDataStreams: C:\ProgramData\TEMP:32EA849C
AlternateDataStreams: C:\ProgramData\TEMP:3313A48D
AlternateDataStreams: C:\ProgramData\TEMP:3393A1CA
AlternateDataStreams: C:\ProgramData\TEMP:33B04540
AlternateDataStreams: C:\ProgramData\TEMP:342886D8
AlternateDataStreams: C:\ProgramData\TEMP:3433021E
AlternateDataStreams: C:\ProgramData\TEMP:34445512
AlternateDataStreams: C:\ProgramData\TEMP:345A9A38
AlternateDataStreams: C:\ProgramData\TEMP:3480F458
AlternateDataStreams: C:\ProgramData\TEMP:34EFF1F2
AlternateDataStreams: C:\ProgramData\TEMP:34FDB459
AlternateDataStreams: C:\ProgramData\TEMP:35110824
AlternateDataStreams: C:\ProgramData\TEMP:3557EC26
AlternateDataStreams: C:\ProgramData\TEMP:35629AE6
AlternateDataStreams: C:\ProgramData\TEMP:3571475C
AlternateDataStreams: C:\ProgramData\TEMP:3595B780
AlternateDataStreams: C:\ProgramData\TEMP:35A8E846
AlternateDataStreams: C:\ProgramData\TEMP:35E8E596
AlternateDataStreams: C:\ProgramData\TEMP:361703F1
AlternateDataStreams: C:\ProgramData\TEMP:366B74CA
AlternateDataStreams: C:\ProgramData\TEMP:366EFA1A
AlternateDataStreams: C:\ProgramData\TEMP:36ED5C45
AlternateDataStreams: C:\ProgramData\TEMP:371A321E
AlternateDataStreams: C:\ProgramData\TEMP:373C6DC2
AlternateDataStreams: C:\ProgramData\TEMP:378824DE
AlternateDataStreams: C:\ProgramData\TEMP:37994DBE
AlternateDataStreams: C:\ProgramData\TEMP:37C279BE
AlternateDataStreams: C:\ProgramData\TEMP:38534D53
AlternateDataStreams: C:\ProgramData\TEMP:3867977D
AlternateDataStreams: C:\ProgramData\TEMP:395F6776
AlternateDataStreams: C:\ProgramData\TEMP:3969ACF7
AlternateDataStreams: C:\ProgramData\TEMP:397D67BA
AlternateDataStreams: C:\ProgramData\TEMP:398D2775
AlternateDataStreams: C:\ProgramData\TEMP:398EFF0F
AlternateDataStreams: C:\ProgramData\TEMP:3A4676D7
AlternateDataStreams: C:\ProgramData\TEMP:3AC0ED43
AlternateDataStreams: C:\ProgramData\TEMP:3AD6342E
AlternateDataStreams: C:\ProgramData\TEMP:3ADE134E
AlternateDataStreams: C:\ProgramData\TEMP:3AF262FC
AlternateDataStreams: C:\ProgramData\TEMP:3B07E6F4
AlternateDataStreams: C:\ProgramData\TEMP:3B633DE9
AlternateDataStreams: C:\ProgramData\TEMP:3B71586E
AlternateDataStreams: C:\ProgramData\TEMP:3C0887BF
AlternateDataStreams: C:\ProgramData\TEMP:3C8B784A
AlternateDataStreams: C:\ProgramData\TEMP:3C9B05C4
AlternateDataStreams: C:\ProgramData\TEMP:3CA18B6B
AlternateDataStreams: C:\ProgramData\TEMP:3CAE2A70
AlternateDataStreams: C:\ProgramData\TEMP:3D186293
AlternateDataStreams: C:\ProgramData\TEMP:3D3F1635
AlternateDataStreams: C:\ProgramData\TEMP:3D4B733E
AlternateDataStreams: C:\ProgramData\TEMP:3D887DCC
AlternateDataStreams: C:\ProgramData\TEMP:3D922890
AlternateDataStreams: C:\ProgramData\TEMP:3DBE461A
AlternateDataStreams: C:\ProgramData\TEMP:3E200C29
AlternateDataStreams: C:\ProgramData\TEMP:3ED5E595
AlternateDataStreams: C:\ProgramData\TEMP:3F9F662A
AlternateDataStreams: C:\ProgramData\TEMP:3FB26DBA
AlternateDataStreams: C:\ProgramData\TEMP:3FBB88CF
AlternateDataStreams: C:\ProgramData\TEMP:4018444F
AlternateDataStreams: C:\ProgramData\TEMP:401CAF8F
AlternateDataStreams: C:\ProgramData\TEMP:403C313B
AlternateDataStreams: C:\ProgramData\TEMP:404908B5
AlternateDataStreams: C:\ProgramData\TEMP:40512067
AlternateDataStreams: C:\ProgramData\TEMP:40546375
AlternateDataStreams: C:\ProgramData\TEMP:409F27A9
AlternateDataStreams: C:\ProgramData\TEMP:4149A170
AlternateDataStreams: C:\ProgramData\TEMP:4157BB05
AlternateDataStreams: C:\ProgramData\TEMP:415E77AB
AlternateDataStreams: C:\ProgramData\TEMP:417B6FAC
AlternateDataStreams: C:\ProgramData\TEMP:417C2BC3
AlternateDataStreams: C:\ProgramData\TEMP:41884BBE
AlternateDataStreams: C:\ProgramData\TEMP:41C283B2
AlternateDataStreams: C:\ProgramData\TEMP:42275BC2
AlternateDataStreams: C:\ProgramData\TEMP:42B6425E
AlternateDataStreams: C:\ProgramData\TEMP:432EC713
AlternateDataStreams: C:\ProgramData\TEMP:438C7496
AlternateDataStreams: C:\ProgramData\TEMP:43CBFAB2
AlternateDataStreams: C:\ProgramData\TEMP:43DA85AC
AlternateDataStreams: C:\ProgramData\TEMP:43ECEA33
AlternateDataStreams: C:\ProgramData\TEMP:43F5FA9D
AlternateDataStreams: C:\ProgramData\TEMP:44712999
AlternateDataStreams: C:\ProgramData\TEMP:447856CD
AlternateDataStreams: C:\ProgramData\TEMP:44E16D4A
AlternateDataStreams: C:\ProgramData\TEMP:45912F61
AlternateDataStreams: C:\ProgramData\TEMP:46283136
AlternateDataStreams: C:\ProgramData\TEMP:469B47D8
AlternateDataStreams: C:\ProgramData\TEMP:46A2F27B
AlternateDataStreams: C:\ProgramData\TEMP:46ADD59D
AlternateDataStreams: C:\ProgramData\TEMP:46CBC45C
AlternateDataStreams: C:\ProgramData\TEMP:46CF5C1F
AlternateDataStreams: C:\ProgramData\TEMP:46EF121E
AlternateDataStreams: C:\ProgramData\TEMP:4709F39D
AlternateDataStreams: C:\ProgramData\TEMP:471AD3D0
AlternateDataStreams: C:\ProgramData\TEMP:479B1CF9
AlternateDataStreams: C:\ProgramData\TEMP:47B391B0
AlternateDataStreams: C:\ProgramData\TEMP:4826868B
AlternateDataStreams: C:\ProgramData\TEMP:48529647
AlternateDataStreams: C:\ProgramData\TEMP:48862C37
AlternateDataStreams: C:\ProgramData\TEMP:488F7244
AlternateDataStreams: C:\ProgramData\TEMP:48977386
AlternateDataStreams: C:\ProgramData\TEMP:490BCC52
AlternateDataStreams: C:\ProgramData\TEMP:49B217F7
AlternateDataStreams: C:\ProgramData\TEMP:49BE0F68
AlternateDataStreams: C:\ProgramData\TEMP:49EB69E2
AlternateDataStreams: C:\ProgramData\TEMP:4A01545C
AlternateDataStreams: C:\ProgramData\TEMP:4A03F06E
AlternateDataStreams: C:\ProgramData\TEMP:4A077D87
AlternateDataStreams: C:\ProgramData\TEMP:4A448DB2
AlternateDataStreams: C:\ProgramData\TEMP:4A5CFD3B
AlternateDataStreams: C:\ProgramData\TEMP:4A8EB1C4
AlternateDataStreams: C:\ProgramData\TEMP:4A966CC2
AlternateDataStreams: C:\ProgramData\TEMP:4AC1DFA1
AlternateDataStreams: C:\ProgramData\TEMP:4AC7B5C1
AlternateDataStreams: C:\ProgramData\TEMP:4B244549
AlternateDataStreams: C:\ProgramData\TEMP:4B325725
AlternateDataStreams: C:\ProgramData\TEMP:4B3648ED
AlternateDataStreams: C:\ProgramData\TEMP:4BBF1137
AlternateDataStreams: C:\ProgramData\TEMP:4BEE39B0
AlternateDataStreams: C:\ProgramData\TEMP:4C16B46B
AlternateDataStreams: C:\ProgramData\TEMP:4C31986D
AlternateDataStreams: C:\ProgramData\TEMP:4C4BD66D
AlternateDataStreams: C:\ProgramData\TEMP:4C5C1DD3
AlternateDataStreams: C:\ProgramData\TEMP:4C6F9D77
AlternateDataStreams: C:\ProgramData\TEMP:4C8FA829
AlternateDataStreams: C:\ProgramData\TEMP:4CD2D817
AlternateDataStreams: C:\ProgramData\TEMP:4D066AD2
AlternateDataStreams: C:\ProgramData\TEMP:4D28BE4D
AlternateDataStreams: C:\ProgramData\TEMP:4D348522
AlternateDataStreams: C:\ProgramData\TEMP:4D551822
AlternateDataStreams: C:\ProgramData\TEMP:4D729D61
AlternateDataStreams: C:\ProgramData\TEMP:4D8FCBEF
AlternateDataStreams: C:\ProgramData\TEMP:4DDE401B
AlternateDataStreams: C:\ProgramData\TEMP:4DE8C719
AlternateDataStreams: C:\ProgramData\TEMP:4E79C4F8
AlternateDataStreams: C:\ProgramData\TEMP:4EAD6852
AlternateDataStreams: C:\ProgramData\TEMP:4EC7F009
AlternateDataStreams: C:\ProgramData\TEMP:4EDDC66F
AlternateDataStreams: C:\ProgramData\TEMP:4EE5EBE9
AlternateDataStreams: C:\ProgramData\TEMP:4EE95FE7
AlternateDataStreams: C:\ProgramData\TEMP:4EEC7800
AlternateDataStreams: C:\ProgramData\TEMP:4F28299B
AlternateDataStreams: C:\ProgramData\TEMP:4F7FE589
AlternateDataStreams: C:\ProgramData\TEMP:4FA837B4
AlternateDataStreams: C:\ProgramData\TEMP:5008417E
AlternateDataStreams: C:\ProgramData\TEMP:5014D98F
AlternateDataStreams: C:\ProgramData\TEMP:502EE511
AlternateDataStreams: C:\ProgramData\TEMP:506698B2
AlternateDataStreams: C:\ProgramData\TEMP:506E1E25
AlternateDataStreams: C:\ProgramData\TEMP:5080697C
AlternateDataStreams: C:\ProgramData\TEMP:50868536
AlternateDataStreams: C:\ProgramData\TEMP:50DD4118
AlternateDataStreams: C:\ProgramData\TEMP:51003EF4
AlternateDataStreams: C:\ProgramData\TEMP:512E1728
AlternateDataStreams: C:\ProgramData\TEMP:5133A494
AlternateDataStreams: C:\ProgramData\TEMP:518C333F
AlternateDataStreams: C:\ProgramData\TEMP:5197985B
AlternateDataStreams: C:\ProgramData\TEMP:5199C971
AlternateDataStreams: C:\ProgramData\TEMP:51A22C60
AlternateDataStreams: C:\ProgramData\TEMP:52329B88
AlternateDataStreams: C:\ProgramData\TEMP:5279F7BF
AlternateDataStreams: C:\ProgramData\TEMP:52C24010
AlternateDataStreams: C:\ProgramData\TEMP:5320A31B
AlternateDataStreams: C:\ProgramData\TEMP:53B8C5D2
AlternateDataStreams: C:\ProgramData\TEMP:53F09A92
AlternateDataStreams: C:\ProgramData\TEMP:53F381F1
AlternateDataStreams: C:\ProgramData\TEMP:54380FEC
AlternateDataStreams: C:\ProgramData\TEMP:54403233
AlternateDataStreams: C:\ProgramData\TEMP:54531C7D
AlternateDataStreams: C:\ProgramData\TEMP:5453E5AF
AlternateDataStreams: C:\ProgramData\TEMP:5466F106
AlternateDataStreams: C:\ProgramData\TEMP:54F0BBF5
AlternateDataStreams: C:\ProgramData\TEMP:5511B474
AlternateDataStreams: C:\ProgramData\TEMP:551BED5F
AlternateDataStreams: C:\ProgramData\TEMP:551E1CB4
AlternateDataStreams: C:\ProgramData\TEMP:5520ED93
AlternateDataStreams: C:\ProgramData\TEMP:553056F1
AlternateDataStreams: C:\ProgramData\TEMP:5539129F
AlternateDataStreams: C:\ProgramData\TEMP:554B3BF6
AlternateDataStreams: C:\ProgramData\TEMP:5607B58C
AlternateDataStreams: C:\ProgramData\TEMP:56C66609
AlternateDataStreams: C:\ProgramData\TEMP:56CE93C9
AlternateDataStreams: C:\ProgramData\TEMP:571CCF8E
AlternateDataStreams: C:\ProgramData\TEMP:57231008
AlternateDataStreams: C:\ProgramData\TEMP:57619D72
AlternateDataStreams: C:\ProgramData\TEMP:587F3582
AlternateDataStreams: C:\ProgramData\TEMP:5925E400
AlternateDataStreams: C:\ProgramData\TEMP:593E515D
AlternateDataStreams: C:\ProgramData\TEMP:59465B40
AlternateDataStreams: C:\ProgramData\TEMP:59A6876B
AlternateDataStreams: C:\ProgramData\TEMP:59C64924
AlternateDataStreams: C:\ProgramData\TEMP:5A068EE1
AlternateDataStreams: C:\ProgramData\TEMP:5A2E8BBF
AlternateDataStreams: C:\ProgramData\TEMP:5A5477A9
AlternateDataStreams: C:\ProgramData\TEMP:5A63CC20
AlternateDataStreams: C:\ProgramData\TEMP:5A9F1AE5
AlternateDataStreams: C:\ProgramData\TEMP:5AE33054
AlternateDataStreams: C:\ProgramData\TEMP:5B111056
AlternateDataStreams: C:\ProgramData\TEMP:5B307FD4
AlternateDataStreams: C:\ProgramData\TEMP:5B483FBC
AlternateDataStreams: C:\ProgramData\TEMP:5BF8F61F
AlternateDataStreams: C:\ProgramData\TEMP:5C28E25F
AlternateDataStreams: C:\ProgramData\TEMP:5C353220
AlternateDataStreams: C:\ProgramData\TEMP:5C3637D2
AlternateDataStreams: C:\ProgramData\TEMP:5C42F64A
AlternateDataStreams: C:\ProgramData\TEMP:5C4A588B
AlternateDataStreams: C:\ProgramData\TEMP:5C5F2761
AlternateDataStreams: C:\ProgramData\TEMP:5C66F780
AlternateDataStreams: C:\ProgramData\TEMP:5C9A6C78
AlternateDataStreams: C:\ProgramData\TEMP:5CB83528
AlternateDataStreams: C:\ProgramData\TEMP:5CBA5665
AlternateDataStreams: C:\ProgramData\TEMP:5CE91C67
AlternateDataStreams: C:\ProgramData\TEMP:5D057E09
AlternateDataStreams: C:\ProgramData\TEMP:5D10517E
AlternateDataStreams: C:\ProgramData\TEMP:5D1BA9DE
AlternateDataStreams: C:\ProgramData\TEMP:5D2D5608
AlternateDataStreams: C:\ProgramData\TEMP:5D34FAF9
AlternateDataStreams: C:\ProgramData\TEMP:5D570144
AlternateDataStreams: C:\ProgramData\TEMP:5DABFF83
AlternateDataStreams: C:\ProgramData\TEMP:5DB36C47
AlternateDataStreams: C:\ProgramData\TEMP:5E21B96B
AlternateDataStreams: C:\ProgramData\TEMP:5E358F67
AlternateDataStreams: C:\ProgramData\TEMP:5E481579
AlternateDataStreams: C:\ProgramData\TEMP:5E4A7758
AlternateDataStreams: C:\ProgramData\TEMP:5E73E1C2
AlternateDataStreams: C:\ProgramData\TEMP:5E8C18F1
AlternateDataStreams: C:\ProgramData\TEMP:5EC48C3A
AlternateDataStreams: C:\ProgramData\TEMP:5ECEFF17
AlternateDataStreams: C:\ProgramData\TEMP:5ED7E575
AlternateDataStreams: C:\ProgramData\TEMP:5EFEB6A1
AlternateDataStreams: C:\ProgramData\TEMP:5F2C9B5E
AlternateDataStreams: C:\ProgramData\TEMP:5F56E7C1
AlternateDataStreams: C:\ProgramData\TEMP:5FC043A8
AlternateDataStreams: C:\ProgramData\TEMP:5FD26EF3
AlternateDataStreams: C:\ProgramData\TEMP:6017A808
AlternateDataStreams: C:\ProgramData\TEMP:607A99D7
AlternateDataStreams: C:\ProgramData\TEMP:60AC3BC3
AlternateDataStreams: C:\ProgramData\TEMP:60D48570
AlternateDataStreams: C:\ProgramData\TEMP:60E0AB2A
AlternateDataStreams: C:\ProgramData\TEMP:611EAF9F
AlternateDataStreams: C:\ProgramData\TEMP:624A80FD
AlternateDataStreams: C:\ProgramData\TEMP:62525FE7
AlternateDataStreams: C:\ProgramData\TEMP:627153F1
AlternateDataStreams: C:\ProgramData\TEMP:6294B369
AlternateDataStreams: C:\ProgramData\TEMP:62AC0CCE
AlternateDataStreams: C:\ProgramData\TEMP:62AF94A0
AlternateDataStreams: C:\ProgramData\TEMP:6301CE40
AlternateDataStreams: C:\ProgramData\TEMP:63A71C6F
AlternateDataStreams: C:\ProgramData\TEMP:63B94956
AlternateDataStreams: C:\ProgramData\TEMP:63C29481
AlternateDataStreams: C:\ProgramData\TEMP:63CFD724
AlternateDataStreams: C:\ProgramData\TEMP:63F8EC77
AlternateDataStreams: C:\ProgramData\TEMP:640DDEFF
AlternateDataStreams: C:\ProgramData\TEMP:64FABDFB
AlternateDataStreams: C:\ProgramData\TEMP:65137F0D
AlternateDataStreams: C:\ProgramData\TEMP:65484F45
AlternateDataStreams: C:\ProgramData\TEMP:65684E14
AlternateDataStreams: C:\ProgramData\TEMP:65929158
AlternateDataStreams: C:\ProgramData\TEMP:65949863
AlternateDataStreams: C:\ProgramData\TEMP:65B8AF94
AlternateDataStreams: C:\ProgramData\TEMP:65C4D44A
AlternateDataStreams: C:\ProgramData\TEMP:6622852D
AlternateDataStreams: C:\ProgramData\TEMP:6622EB04
AlternateDataStreams: C:\ProgramData\TEMP:667565EE
AlternateDataStreams: C:\ProgramData\TEMP:669AB5E1
AlternateDataStreams: C:\ProgramData\TEMP:66C764F5
AlternateDataStreams: C:\ProgramData\TEMP:66F19688
AlternateDataStreams: C:\ProgramData\TEMP:66F7E5A9
AlternateDataStreams: C:\ProgramData\TEMP:67396145
AlternateDataStreams: C:\ProgramData\TEMP:67842DB7
AlternateDataStreams: C:\ProgramData\TEMP:67A91473
AlternateDataStreams: C:\ProgramData\TEMP:67B6E7FA
AlternateDataStreams: C:\ProgramData\TEMP:67CF910D
AlternateDataStreams: C:\ProgramData\TEMP:67E674B0
AlternateDataStreams: C:\ProgramData\TEMP:680F6474
AlternateDataStreams: C:\ProgramData\TEMP:687D1056
AlternateDataStreams: C:\ProgramData\TEMP:689AB7E9
AlternateDataStreams: C:\ProgramData\TEMP:68A41423
AlternateDataStreams: C:\ProgramData\TEMP:68DE552E
AlternateDataStreams: C:\ProgramData\TEMP:697DDE2B
AlternateDataStreams: C:\ProgramData\TEMP:69FE2EE4
AlternateDataStreams: C:\ProgramData\TEMP:6A129BAB
AlternateDataStreams: C:\ProgramData\TEMP:6A9EDD31
AlternateDataStreams: C:\ProgramData\TEMP:6AF6BB0E
AlternateDataStreams: C:\ProgramData\TEMP:6B28173C
AlternateDataStreams: C:\ProgramData\TEMP:6B5A665E
AlternateDataStreams: C:\ProgramData\TEMP:6B7447D4
AlternateDataStreams: C:\ProgramData\TEMP:6B9828AE
AlternateDataStreams: C:\ProgramData\TEMP:6BE79E11
AlternateDataStreams: C:\ProgramData\TEMP:6BEADDC0
AlternateDataStreams: C:\ProgramData\TEMP:6BF0805F
AlternateDataStreams: C:\ProgramData\TEMP:6BFA43EB
AlternateDataStreams: C:\ProgramData\TEMP:6C15BEAD
AlternateDataStreams: C:\ProgramData\TEMP:6C468A51
AlternateDataStreams: C:\ProgramData\TEMP:6C81A062
AlternateDataStreams: C:\ProgramData\TEMP:6CC1CB6D
AlternateDataStreams: C:\ProgramData\TEMP:6CF828C2
AlternateDataStreams: C:\ProgramData\TEMP:6D4F7F2B
AlternateDataStreams: C:\ProgramData\TEMP:6D65CED0
AlternateDataStreams: C:\ProgramData\TEMP:6DCFAD3B
AlternateDataStreams: C:\ProgramData\TEMP:6DD87D86
AlternateDataStreams: C:\ProgramData\TEMP:6DDBB86B
AlternateDataStreams: C:\ProgramData\TEMP:6E2D80C8
AlternateDataStreams: C:\ProgramData\TEMP:6E39144C
AlternateDataStreams: C:\ProgramData\TEMP:6E3C585B
AlternateDataStreams: C:\ProgramData\TEMP:6E65510A
AlternateDataStreams: C:\ProgramData\TEMP:6E6A4F42
AlternateDataStreams: C:\ProgramData\TEMP:6F16D671
AlternateDataStreams: C:\ProgramData\TEMP:6F94300C
AlternateDataStreams: C:\ProgramData\TEMP:700B8E2E
AlternateDataStreams: C:\ProgramData\TEMP:701B92FB
AlternateDataStreams: C:\ProgramData\TEMP:709E81D4
AlternateDataStreams: C:\ProgramData\TEMP:70E897B5
AlternateDataStreams: C:\ProgramData\TEMP:71112705
AlternateDataStreams: C:\ProgramData\TEMP:71A89A93
AlternateDataStreams: C:\ProgramData\TEMP:71AEFFEB
AlternateDataStreams: C:\ProgramData\TEMP:71B89F61
AlternateDataStreams: C:\ProgramData\TEMP:71F04C26
AlternateDataStreams: C:\ProgramData\TEMP:72449E7D
AlternateDataStreams: C:\ProgramData\TEMP:7247FE29
AlternateDataStreams: C:\ProgramData\TEMP:7254CF01
AlternateDataStreams: C:\ProgramData\TEMP:726A7C8D
AlternateDataStreams: C:\ProgramData\TEMP:72C99D4E
AlternateDataStreams: C:\ProgramData\TEMP:737160C1
AlternateDataStreams: C:\ProgramData\TEMP:73AFBB96
AlternateDataStreams: C:\ProgramData\TEMP:73B78E79
AlternateDataStreams: C:\ProgramData\TEMP:742F1EE5
AlternateDataStreams: C:\ProgramData\TEMP:74B502CB
AlternateDataStreams: C:\ProgramData\TEMP:751D6870
AlternateDataStreams: C:\ProgramData\TEMP:754E278B
AlternateDataStreams: C:\ProgramData\TEMP:75765D7B
AlternateDataStreams: C:\ProgramData\TEMP:75798D9A
AlternateDataStreams: C:\ProgramData\TEMP:75CC0165
AlternateDataStreams: C:\ProgramData\TEMP:75E7048E
AlternateDataStreams: C:\ProgramData\TEMP:762408BA
AlternateDataStreams: C:\ProgramData\TEMP:7641F818
AlternateDataStreams: C:\ProgramData\TEMP:76953F21
AlternateDataStreams: C:\ProgramData\TEMP:76DF754D
AlternateDataStreams: C:\ProgramData\TEMP:774A0E14
AlternateDataStreams: C:\ProgramData\TEMP:774C075A
AlternateDataStreams: C:\ProgramData\TEMP:77846FFE
AlternateDataStreams: C:\ProgramData\TEMP:77B64C59
AlternateDataStreams: C:\ProgramData\TEMP:77E239B1
AlternateDataStreams: C:\ProgramData\TEMP:77F49022
AlternateDataStreams: C:\ProgramData\TEMP:792BE0F5
AlternateDataStreams: C:\ProgramData\TEMP:793ABD2B
AlternateDataStreams: C:\ProgramData\TEMP:795F6DEC
AlternateDataStreams: C:\ProgramData\TEMP:79875988
AlternateDataStreams: C:\ProgramData\TEMP:79A7F369
AlternateDataStreams: C:\ProgramData\TEMP:79C6A9CE
AlternateDataStreams: C:\ProgramData\TEMP:79F970BE
AlternateDataStreams: C:\ProgramData\TEMP:7A0A894A
AlternateDataStreams: C:\ProgramData\TEMP:7ADB695A
AlternateDataStreams: C:\ProgramData\TEMP:7AF9CAEB
AlternateDataStreams: C:\ProgramData\TEMP:7B9BB187
AlternateDataStreams: C:\ProgramData\TEMP:7BB584AA
AlternateDataStreams: C:\ProgramData\TEMP:7BB6E2C8
AlternateDataStreams: C:\ProgramData\TEMP:7BD9473D
AlternateDataStreams: C:\ProgramData\TEMP:7BFAAE70
AlternateDataStreams: C:\ProgramData\TEMP:7BFFC6A9
AlternateDataStreams: C:\ProgramData\TEMP:7C27C41C
AlternateDataStreams: C:\ProgramData\TEMP:7C5E403A
AlternateDataStreams: C:\ProgramData\TEMP:7C819E94
AlternateDataStreams: C:\ProgramData\TEMP:7C8AA9A6
AlternateDataStreams: C:\ProgramData\TEMP:7CF8A507
AlternateDataStreams: C:\ProgramData\TEMP:7D04F8E2
AlternateDataStreams: C:\ProgramData\TEMP:7D288858
AlternateDataStreams: C:\ProgramData\TEMP:7D49B96B
AlternateDataStreams: C:\ProgramData\TEMP:7D938C9B
AlternateDataStreams: C:\ProgramData\TEMP:7D9B1030
AlternateDataStreams: C:\ProgramData\TEMP:7DC5D762
AlternateDataStreams: C:\ProgramData\TEMP:7E082023
AlternateDataStreams: C:\ProgramData\TEMP:7E0B06B5
AlternateDataStreams: C:\ProgramData\TEMP:7E1F211D
AlternateDataStreams: C:\ProgramData\TEMP:7E4E56EA
AlternateDataStreams: C:\ProgramData\TEMP:7E802BFF
AlternateDataStreams: C:\ProgramData\TEMP:7EC01D6D
AlternateDataStreams: C:\ProgramData\TEMP:7ECD9621
AlternateDataStreams: C:\ProgramData\TEMP:7EE43C06
AlternateDataStreams: C:\ProgramData\TEMP:7F66BF58
AlternateDataStreams: C:\ProgramData\TEMP:7FCB9D0D
AlternateDataStreams: C:\ProgramData\TEMP:7FD8AECC
AlternateDataStreams: C:\ProgramData\TEMP:80253E8D
AlternateDataStreams: C:\ProgramData\TEMP:8029E75F
AlternateDataStreams: C:\ProgramData\TEMP:8075370B
AlternateDataStreams: C:\ProgramData\TEMP:80974241
AlternateDataStreams: C:\ProgramData\TEMP:80BFDE16
AlternateDataStreams: C:\ProgramData\TEMP:80EA2EA3
AlternateDataStreams: C:\ProgramData\TEMP:81365633
AlternateDataStreams: C:\ProgramData\TEMP:817F0659
AlternateDataStreams: C:\ProgramData\TEMP:8204AA35
AlternateDataStreams: C:\ProgramData\TEMP:823606DE
AlternateDataStreams: C:\ProgramData\TEMP:8247A199
AlternateDataStreams: C:\ProgramData\TEMP:82529191
AlternateDataStreams: C:\ProgramData\TEMP:82EAE27C
AlternateDataStreams: C:\ProgramData\TEMP:8318A814
AlternateDataStreams: C:\ProgramData\TEMP:839A89FC
AlternateDataStreams: C:\ProgramData\TEMP:843D8419
AlternateDataStreams: C:\ProgramData\TEMP:8441E695
AlternateDataStreams: C:\ProgramData\TEMP:8470B630
AlternateDataStreams: C:\ProgramData\TEMP:84C34762
AlternateDataStreams: C:\ProgramData\TEMP:852F2262
AlternateDataStreams: C:\ProgramData\TEMP:85630A39
AlternateDataStreams: C:\ProgramData\TEMP:857692EC
AlternateDataStreams: C:\ProgramData\TEMP:85C3B823
AlternateDataStreams: C:\ProgramData\TEMP:85EA4795
AlternateDataStreams: C:\ProgramData\TEMP:861A898F
AlternateDataStreams: C:\ProgramData\TEMP:8634D9A3
AlternateDataStreams: C:\ProgramData\TEMP:865F21BF
AlternateDataStreams: C:\ProgramData\TEMP:86A8CE8D
AlternateDataStreams: C:\ProgramData\TEMP:86B7FDDB
AlternateDataStreams: C:\ProgramData\TEMP:86E0BFC8
AlternateDataStreams: C:\ProgramData\TEMP:871526BA
AlternateDataStreams: C:\ProgramData\TEMP:87E3D720
AlternateDataStreams: C:\ProgramData\TEMP:8836A712
AlternateDataStreams: C:\ProgramData\TEMP:8855A119
AlternateDataStreams: C:\ProgramData\TEMP:8866C899
AlternateDataStreams: C:\ProgramData\TEMP:8868F8ED
AlternateDataStreams: C:\ProgramData\TEMP:88FB7F72
AlternateDataStreams: C:\ProgramData\TEMP:89123481
AlternateDataStreams: C:\ProgramData\TEMP:891A7A73
AlternateDataStreams: C:\ProgramData\TEMP:895A78C5
AlternateDataStreams: C:\ProgramData\TEMP:8967C154
AlternateDataStreams: C:\ProgramData\TEMP:89C28CF6
AlternateDataStreams: C:\ProgramData\TEMP:89F44603
AlternateDataStreams: C:\ProgramData\TEMP:89FC8EEB
AlternateDataStreams: C:\ProgramData\TEMP:8A290D99
AlternateDataStreams: C:\ProgramData\TEMP:8A620099
AlternateDataStreams: C:\ProgramData\TEMP:8AC20936
AlternateDataStreams: C:\ProgramData\TEMP:8AE92FD3
AlternateDataStreams: C:\ProgramData\TEMP:8AEF2555
AlternateDataStreams: C:\ProgramData\TEMP:8B076EC5
AlternateDataStreams: C:\ProgramData\TEMP:8B3C3098
AlternateDataStreams: C:\ProgramData\TEMP:8B480195
AlternateDataStreams: C:\ProgramData\TEMP:8B4B9596
AlternateDataStreams: C:\ProgramData\TEMP:8B4C1181
AlternateDataStreams: C:\ProgramData\TEMP:8B69E3C3
AlternateDataStreams: C:\ProgramData\TEMP:8B9E766D
AlternateDataStreams: C:\ProgramData\TEMP:8BB2EE92
AlternateDataStreams: C:\ProgramData\TEMP:8BE8BFCD
AlternateDataStreams: C:\ProgramData\TEMP:8C12CFCD
AlternateDataStreams: C:\ProgramData\TEMP:8C443193
AlternateDataStreams: C:\ProgramData\TEMP:8C885EDD
AlternateDataStreams: C:\ProgramData\TEMP:8CE601F5
AlternateDataStreams: C:\ProgramData\TEMP:8CFF4966
AlternateDataStreams: C:\ProgramData\TEMP:8D565A9B
AlternateDataStreams: C:\ProgramData\TEMP:8DD20B4A
AlternateDataStreams: C:\ProgramData\TEMP:8E5EA40F
AlternateDataStreams: C:\ProgramData\TEMP:8E60033F
AlternateDataStreams: C:\ProgramData\TEMP:8EBF0142
AlternateDataStreams: C:\ProgramData\TEMP:8EEE3BBB
AlternateDataStreams: C:\ProgramData\TEMP:8F1B55BE
AlternateDataStreams: C:\ProgramData\TEMP:8F6B75BF
AlternateDataStreams: C:\ProgramData\TEMP:8F7ECF6A
AlternateDataStreams: C:\ProgramData\TEMP:8F925134
AlternateDataStreams: C:\ProgramData\TEMP:8F99ADAD
AlternateDataStreams: C:\ProgramData\TEMP:8FA3210E
AlternateDataStreams: C:\ProgramData\TEMP:8FBE0E9C
AlternateDataStreams: C:\ProgramData\TEMP:8FC027DE
AlternateDataStreams: C:\ProgramData\TEMP:8FF962C6
AlternateDataStreams: C:\ProgramData\TEMP:90108DD7
AlternateDataStreams: C:\ProgramData\TEMP:9026EFD0
AlternateDataStreams: C:\ProgramData\TEMP:902B3C72
AlternateDataStreams: C:\ProgramData\TEMP:902B6A44
AlternateDataStreams: C:\ProgramData\TEMP:902C848D
AlternateDataStreams: C:\ProgramData\TEMP:908A1B53
AlternateDataStreams: C:\ProgramData\TEMP:9124663C
AlternateDataStreams: C:\ProgramData\TEMP:9195103F
AlternateDataStreams: C:\ProgramData\TEMP:91A1C0FC
AlternateDataStreams: C:\ProgramData\TEMP:91CF76E3
AlternateDataStreams: C:\ProgramData\TEMP:91FE43FF
AlternateDataStreams: C:\ProgramData\TEMP:922DA2DB
AlternateDataStreams: C:\ProgramData\TEMP:926B6E7A
AlternateDataStreams: C:\ProgramData\TEMP:927EC486
AlternateDataStreams: C:\ProgramData\TEMP:928DF32E
AlternateDataStreams: C:\ProgramData\TEMP:92BD9737
AlternateDataStreams: C:\ProgramData\TEMP:92D18A5E
AlternateDataStreams: C:\ProgramData\TEMP:92D35C13
AlternateDataStreams: C:\ProgramData\TEMP:938EB9FC
AlternateDataStreams: C:\ProgramData\TEMP:943971F5
AlternateDataStreams: C:\ProgramData\TEMP:94874C0A
AlternateDataStreams: C:\ProgramData\TEMP:9491C9C7
AlternateDataStreams: C:\ProgramData\TEMP:94B25DF5
AlternateDataStreams: C:\ProgramData\TEMP:94B46CA2
AlternateDataStreams: C:\ProgramData\TEMP:95198126
AlternateDataStreams: C:\ProgramData\TEMP:952245B1
AlternateDataStreams: C:\ProgramData\TEMP:9524D821
AlternateDataStreams: C:\ProgramData\TEMP:953FDC1A
AlternateDataStreams: C:\ProgramData\TEMP:956EC010
AlternateDataStreams: C:\ProgramData\TEMP:9597EAFE
AlternateDataStreams: C:\ProgramData\TEMP:95D421DF
AlternateDataStreams: C:\ProgramData\TEMP:961B4D58
AlternateDataStreams: C:\ProgramData\TEMP:961B84C5
AlternateDataStreams: C:\ProgramData\TEMP:96372A73
AlternateDataStreams: C:\ProgramData\TEMP:96646EC1
AlternateDataStreams: C:\ProgramData\TEMP:96838F8A
AlternateDataStreams: C:\ProgramData\TEMP:968F624D
AlternateDataStreams: C:\ProgramData\TEMP:96F8F8AB
AlternateDataStreams: C:\ProgramData\TEMP:971DCCE2
AlternateDataStreams: C:\ProgramData\TEMP:9720EBEF
AlternateDataStreams: C:\ProgramData\TEMP:97AAB7F2
AlternateDataStreams: C:\ProgramData\TEMP:97B3B270
AlternateDataStreams: C:\ProgramData\TEMP:97BDBF49
AlternateDataStreams: C:\ProgramData\TEMP:97CA3B9E
AlternateDataStreams: C:\ProgramData\TEMP:98104906
AlternateDataStreams: C:\ProgramData\TEMP:981456CB
AlternateDataStreams: C:\ProgramData\TEMP:9825B52E
AlternateDataStreams: C:\ProgramData\TEMP:9836B5E4
AlternateDataStreams: C:\ProgramData\TEMP:983B4DC0
AlternateDataStreams: C:\ProgramData\TEMP:98BD93BF
AlternateDataStreams: C:\ProgramData\TEMP:991283D0
AlternateDataStreams: C:\ProgramData\TEMP:993185CB
AlternateDataStreams: C:\ProgramData\TEMP:99B20AD0
AlternateDataStreams: C:\ProgramData\TEMP:9A2A9D24
AlternateDataStreams: C:\ProgramData\TEMP:9AC8424E
AlternateDataStreams: C:\ProgramData\TEMP:9B0F9E15
AlternateDataStreams: C:\ProgramData\TEMP:9B3291FE
AlternateDataStreams: C:\ProgramData\TEMP:9B750A13
AlternateDataStreams: C:\ProgramData\TEMP:9BB8C675
AlternateDataStreams: C:\ProgramData\TEMP:9C012695
AlternateDataStreams: C:\ProgramData\TEMP:9C3AAD57
AlternateDataStreams: C:\ProgramData\TEMP:9C504A4D
AlternateDataStreams: C:\ProgramData\TEMP:9C7A32BB
AlternateDataStreams: C:\ProgramData\TEMP:9CE870B8
AlternateDataStreams: C:\ProgramData\TEMP:9CF728A6
AlternateDataStreams: C:\ProgramData\TEMP:9D06FB9C
AlternateDataStreams: C:\ProgramData\TEMP:9D2DE4B4
AlternateDataStreams: C:\ProgramData\TEMP:9D3C27E1
AlternateDataStreams: C:\ProgramData\TEMP:9D6EAEC3
AlternateDataStreams: C:\ProgramData\TEMP:9D91E651
AlternateDataStreams: C:\ProgramData\TEMP:9E5EA7A3
AlternateDataStreams: C:\ProgramData\TEMP:9EBE2014
AlternateDataStreams: C:\ProgramData\TEMP:9EE6560D
AlternateDataStreams: C:\ProgramData\TEMP:9F50A55A
AlternateDataStreams: C:\ProgramData\TEMP:9F81E94D
AlternateDataStreams: C:\ProgramData\TEMP:9FB6814A
AlternateDataStreams: C:\ProgramData\TEMP:9FCF32A8
AlternateDataStreams: C:\ProgramData\TEMP:9FD757A9
AlternateDataStreams: C:\ProgramData\TEMP:A015B193
AlternateDataStreams: C:\ProgramData\TEMP:A01F3A87
AlternateDataStreams: C:\ProgramData\TEMP:A039EDF9
AlternateDataStreams: C:\ProgramData\TEMP:A0921B2C
AlternateDataStreams: C:\ProgramData\TEMP:A1023D41
AlternateDataStreams: C:\ProgramData\TEMP:A10E88DE
AlternateDataStreams: C:\ProgramData\TEMP:A1460B2A
AlternateDataStreams: C:\ProgramData\TEMP:A1A86E40
AlternateDataStreams: C:\ProgramData\TEMP:A1FD5369
AlternateDataStreams: C:\ProgramData\TEMP:A243178D
AlternateDataStreams: C:\ProgramData\TEMP:A26AFC00
AlternateDataStreams: C:\ProgramData\TEMP:A26C6E72
AlternateDataStreams: C:\ProgramData\TEMP:A291068E
AlternateDataStreams: C:\ProgramData\TEMP:A3840F5B
AlternateDataStreams: C:\ProgramData\TEMP:A391510C
AlternateDataStreams: C:\ProgramData\TEMP:A3B8F70C
AlternateDataStreams: C:\ProgramData\TEMP:A3E0A552
AlternateDataStreams: C:\ProgramData\TEMP:A42B5698
AlternateDataStreams: C:\ProgramData\TEMP:A43B789A
AlternateDataStreams: C:\ProgramData\TEMP:A43EC514
AlternateDataStreams: C:\ProgramData\TEMP:A441D13F
AlternateDataStreams: C:\ProgramData\TEMP:A479BCC9
AlternateDataStreams: C:\ProgramData\TEMP:A4AF8D0D
AlternateDataStreams: C:\ProgramData\TEMP:A4B4192F
AlternateDataStreams: C:\ProgramData\TEMP:A4E7D25F
AlternateDataStreams: C:\ProgramData\TEMP:A5241382
AlternateDataStreams: C:\ProgramData\TEMP:A5256831
AlternateDataStreams: C:\ProgramData\TEMP:A52D07E2
AlternateDataStreams: C:\ProgramData\TEMP:A5584049
AlternateDataStreams: C:\ProgramData\TEMP:A57239FA
AlternateDataStreams: C:\ProgramData\TEMP:A6345BDA
AlternateDataStreams: C:\ProgramData\TEMP:A6346EE9
AlternateDataStreams: C:\ProgramData\TEMP:A69FAA24
AlternateDataStreams: C:\ProgramData\TEMP:A6D6E537
AlternateDataStreams: C:\ProgramData\TEMP:A6D89509
AlternateDataStreams: C:\ProgramData\TEMP:A6F28514
AlternateDataStreams: C:\ProgramData\TEMP:A6F30843
AlternateDataStreams: C:\ProgramData\TEMP:A6FE7BCC
AlternateDataStreams: C:\ProgramData\TEMP:A724744F
AlternateDataStreams: C:\ProgramData\TEMP:A78B31DD
AlternateDataStreams: C:\ProgramData\TEMP:A7CC0E50
AlternateDataStreams: C:\ProgramData\TEMP:A819A132
AlternateDataStreams: C:\ProgramData\TEMP:A81F86C8
AlternateDataStreams: C:\ProgramData\TEMP:A8369371
AlternateDataStreams: C:\ProgramData\TEMP:A851461E
AlternateDataStreams: C:\ProgramData\TEMP:A88BE334
AlternateDataStreams: C:\ProgramData\TEMP:A899E64E
AlternateDataStreams: C:\ProgramData\TEMP:A8A0D7A2
AlternateDataStreams: C:\ProgramData\TEMP:A8ADEA55
AlternateDataStreams: C:\ProgramData\TEMP:A8DFD30C
AlternateDataStreams: C:\ProgramData\TEMP:A900C3A3
AlternateDataStreams: C:\ProgramData\TEMP:A93CBF2B
AlternateDataStreams: C:\ProgramData\TEMP:A967571A
AlternateDataStreams: C:\ProgramData\TEMP:A99C1C81
AlternateDataStreams: C:\ProgramData\TEMP:A9F13D2D
AlternateDataStreams: C:\ProgramData\TEMP:AA0017FD
AlternateDataStreams: C:\ProgramData\TEMP:AA0BC725
AlternateDataStreams: C:\ProgramData\TEMP:AA5A61B2
AlternateDataStreams: C:\ProgramData\TEMP:AA6CA4C7
AlternateDataStreams: C:\ProgramData\TEMP:AA7BE830
AlternateDataStreams: C:\ProgramData\TEMP:AABECEFB
AlternateDataStreams: C:\ProgramData\TEMP:AB3339EF
AlternateDataStreams: C:\ProgramData\TEMP:AB501812
AlternateDataStreams: C:\ProgramData\TEMP:AB554F94
AlternateDataStreams: C:\ProgramData\TEMP:ABBFFEA2
AlternateDataStreams: C:\ProgramData\TEMP:AC57032B
AlternateDataStreams: C:\ProgramData\TEMP:ACB38255
AlternateDataStreams: C:\ProgramData\TEMP:AD020DC3
AlternateDataStreams: C:\ProgramData\TEMP:AD179392
AlternateDataStreams: C:\ProgramData\TEMP:ADEBE9CA
AlternateDataStreams: C:\ProgramData\TEMP:AE0B4487
AlternateDataStreams: C:\ProgramData\TEMP:AE324BE5
AlternateDataStreams: C:\ProgramData\TEMP:AE34D87E
AlternateDataStreams: C:\ProgramData\TEMP:AE47FDED
AlternateDataStreams: C:\ProgramData\TEMP:AE8D8202
AlternateDataStreams: C:\ProgramData\TEMP:AE9351E0
AlternateDataStreams: C:\ProgramData\TEMP:AEA33452
AlternateDataStreams: C:\ProgramData\TEMP:AEBC40EC
AlternateDataStreams: C:\ProgramData\TEMP:AECF4772
AlternateDataStreams: C:\ProgramData\TEMP:AED4A2B7
AlternateDataStreams: C:\ProgramData\TEMP:AF191C57
AlternateDataStreams: C:\ProgramData\TEMP:AF2F9D4A
AlternateDataStreams: C:\ProgramData\TEMP:AFB89C92
AlternateDataStreams: C:\ProgramData\TEMP:AFFA972E
AlternateDataStreams: C:\ProgramData\TEMP:B02249C3
AlternateDataStreams: C:\ProgramData\TEMP:B0456F0C
AlternateDataStreams: C:\ProgramData\TEMP:B0729CDB
AlternateDataStreams: C:\ProgramData\TEMP:B097AC8A
AlternateDataStreams: C:\ProgramData\TEMP:B0EA26E5
AlternateDataStreams: C:\ProgramData\TEMP:B1381B34
AlternateDataStreams: C:\ProgramData\TEMP:B190BE3A
AlternateDataStreams: C:\ProgramData\TEMP:B1E64E47
AlternateDataStreams: C:\ProgramData\TEMP:B2112128
AlternateDataStreams: C:\ProgramData\TEMP:B21F2857
AlternateDataStreams: C:\ProgramData\TEMP:B2D32F1D
AlternateDataStreams: C:\ProgramData\TEMP:B2DC8D6B
AlternateDataStreams: C:\ProgramData\TEMP:B310C233
AlternateDataStreams: C:\ProgramData\TEMP:B317D7ED
AlternateDataStreams: C:\ProgramData\TEMP:B3196E8D
AlternateDataStreams: C:\ProgramData\TEMP:B33464A5
AlternateDataStreams: C:\ProgramData\TEMP:B38BEEEE
AlternateDataStreams: C:\ProgramData\TEMP:B3A5945E
AlternateDataStreams: C:\ProgramData\TEMP:B3A7E7F8
AlternateDataStreams: C:\ProgramData\TEMP:B3C7433B
AlternateDataStreams: C:\ProgramData\TEMP:B47A7270
AlternateDataStreams: C:\ProgramData\TEMP:B4980368
AlternateDataStreams: C:\ProgramData\TEMP:B4F0E275
AlternateDataStreams: C:\ProgramData\TEMP:B4F7687B
AlternateDataStreams: C:\ProgramData\TEMP:B51B45A3
AlternateDataStreams: C:\ProgramData\TEMP:B5FD4AA1
AlternateDataStreams: C:\ProgramData\TEMP:B652B720
AlternateDataStreams: C:\ProgramData\TEMP:B6E58523
AlternateDataStreams: C:\ProgramData\TEMP:B723C5EF
AlternateDataStreams: C:\ProgramData\TEMP:B790962B
AlternateDataStreams: C:\ProgramData\TEMP:B80659FA
AlternateDataStreams: C:\ProgramData\TEMP:B8EA2C49
AlternateDataStreams: C:\ProgramData\TEMP:B8EB1B99
AlternateDataStreams: C:\ProgramData\TEMP:B9775780
AlternateDataStreams: C:\ProgramData\TEMP:BACC4A79
AlternateDataStreams: C:\ProgramData\TEMP:BAFAD1DF
AlternateDataStreams: C:\ProgramData\TEMP:BB718C46
AlternateDataStreams: C:\ProgramData\TEMP:BB99F46B
AlternateDataStreams: C:\ProgramData\TEMP:BC521608
AlternateDataStreams: C:\ProgramData\TEMP:BC593DD5
AlternateDataStreams: C:\ProgramData\TEMP:BCAB37A9
AlternateDataStreams: C:\ProgramData\TEMP:BCF55336
AlternateDataStreams: C:\ProgramData\TEMP:BD34FFC5
AlternateDataStreams: C:\ProgramData\TEMP:BDDA21B6
AlternateDataStreams: C:\ProgramData\TEMP:BE0654D6
AlternateDataStreams: C:\ProgramData\TEMP:BE3D639A
AlternateDataStreams: C:\ProgramData\TEMP:BE40B295
AlternateDataStreams: C:\ProgramData\TEMP:BE64143E
AlternateDataStreams: C:\ProgramData\TEMP:BE6B5FC3
AlternateDataStreams: C:\ProgramData\TEMP:BE6DC701
AlternateDataStreams: C:\ProgramData\TEMP:BEACE4C8
AlternateDataStreams: C:\ProgramData\TEMP:BEF18713
AlternateDataStreams: C:\ProgramData\TEMP:BF1E0621
AlternateDataStreams: C:\ProgramData\TEMP:BF4BA1F5
AlternateDataStreams: C:\ProgramData\TEMP:BF640EE5
AlternateDataStreams: C:\ProgramData\TEMP:BF6A2C54
AlternateDataStreams: C:\ProgramData\TEMP:BF6C4AAC
AlternateDataStreams: C:\ProgramData\TEMP:BF6C81B2
AlternateDataStreams: C:\ProgramData\TEMP:C0893153
AlternateDataStreams: C:\ProgramData\TEMP:C0913157
AlternateDataStreams: C:\ProgramData\TEMP:C0A9B815
AlternateDataStreams: C:\ProgramData\TEMP:C0D23A2F
AlternateDataStreams: C:\ProgramData\TEMP:C178954A
AlternateDataStreams: C:\ProgramData\TEMP:C18032C3
AlternateDataStreams: C:\ProgramData\TEMP:C1C3561E
AlternateDataStreams: C:\ProgramData\TEMP:C1D3D9A3
AlternateDataStreams: C:\ProgramData\TEMP:C1DBE635
AlternateDataStreams: C:\ProgramData\TEMP:C22B6EED
AlternateDataStreams: C:\ProgramData\TEMP:C26A6AB3
AlternateDataStreams: C:\ProgramData\TEMP:C2F24DB5
AlternateDataStreams: C:\ProgramData\TEMP:C2F43053
AlternateDataStreams: C:\ProgramData\TEMP:C30487EE
AlternateDataStreams: C:\ProgramData\TEMP:C356A185
AlternateDataStreams: C:\ProgramData\TEMP:C368C9EA
AlternateDataStreams: C:\ProgramData\TEMP:C36D0DFD
AlternateDataStreams: C:\ProgramData\TEMP:C37283B5
AlternateDataStreams: C:\ProgramData\TEMP:C3A047E3
AlternateDataStreams: C:\ProgramData\TEMP:C3AD9507
AlternateDataStreams: C:\ProgramData\TEMP:C3B04546
AlternateDataStreams: C:\ProgramData\TEMP:C3E7F2E9
AlternateDataStreams: C:\ProgramData\TEMP:C44E62F1
AlternateDataStreams: C:\ProgramData\TEMP:C48905F4
AlternateDataStreams: C:\ProgramData\TEMP:C4967F48
AlternateDataStreams: C:\ProgramData\TEMP:C4A88D6B
AlternateDataStreams: C:\ProgramData\TEMP:C5340FA1
AlternateDataStreams: C:\ProgramData\TEMP:C54A1A57
AlternateDataStreams: C:\ProgramData\TEMP:C5A156B6
AlternateDataStreams: C:\ProgramData\TEMP:C5D15631
AlternateDataStreams: C:\ProgramData\TEMP:C5DC2B0C
AlternateDataStreams: C:\ProgramData\TEMP:C66222F3
AlternateDataStreams: C:\ProgramData\TEMP:C67CB31A
AlternateDataStreams: C:\ProgramData\TEMP:C6920A5D
AlternateDataStreams: C:\ProgramData\TEMP:C7517D0A
AlternateDataStreams: C:\ProgramData\TEMP:C76CFF82
AlternateDataStreams: C:\ProgramData\TEMP:C7D35E8C
AlternateDataStreams: C:\ProgramData\TEMP:C7F08EA3
AlternateDataStreams: C:\ProgramData\TEMP:C82210DD
AlternateDataStreams: C:\ProgramData\TEMP:C82CA1C0
AlternateDataStreams: C:\ProgramData\TEMP:C8E3A625
AlternateDataStreams: C:\ProgramData\TEMP:C8E9D804
AlternateDataStreams: C:\ProgramData\TEMP:C98828D3
AlternateDataStreams: C:\ProgramData\TEMP:C9B27A06
AlternateDataStreams: C:\ProgramData\TEMP:CA1AFE85
AlternateDataStreams: C:\ProgramData\TEMP:CA23BCFD
AlternateDataStreams: C:\ProgramData\TEMP:CA400C1B
AlternateDataStreams: C:\ProgramData\TEMP:CAE3AE67
AlternateDataStreams: C:\ProgramData\TEMP:CB08ED9D
AlternateDataStreams: C:\ProgramData\TEMP:CB299F13
AlternateDataStreams: C:\ProgramData\TEMP:CB3667AF
AlternateDataStreams: C:\ProgramData\TEMP:CB5AA1E6
AlternateDataStreams: C:\ProgramData\TEMP:CB959782
AlternateDataStreams: C:\ProgramData\TEMP:CBAF0C30
AlternateDataStreams: C:\ProgramData\TEMP:CC141B05
AlternateDataStreams: C:\ProgramData\TEMP:CCD8056E
AlternateDataStreams: C:\ProgramData\TEMP:CDCDE97C
AlternateDataStreams: C:\ProgramData\TEMP:CE3AADB7
AlternateDataStreams: C:\ProgramData\TEMP:CE506F23
AlternateDataStreams: C:\ProgramData\TEMP:CE8A42A3
AlternateDataStreams: C:\ProgramData\TEMP:CEF2A14E
AlternateDataStreams: C:\ProgramData\TEMP:CF2C26D2
AlternateDataStreams: C:\ProgramData\TEMP:CF5ECDE7
AlternateDataStreams: C:\ProgramData\TEMP:CFA8C6E3
AlternateDataStreams: C:\ProgramData\TEMP:D0005E5A
AlternateDataStreams: C:\ProgramData\TEMP:D0149AB4
AlternateDataStreams: C:\ProgramData\TEMP:D01ACC06
AlternateDataStreams: C:\ProgramData\TEMP:D026A5A4
AlternateDataStreams: C:\ProgramData\TEMP:D03C22B4
AlternateDataStreams: C:\ProgramData\TEMP:D0570058
AlternateDataStreams: C:\ProgramData\TEMP:D05E7A8B
AlternateDataStreams: C:\ProgramData\TEMP:D086B88D
AlternateDataStreams: C:\ProgramData\TEMP:D103E81E
AlternateDataStreams: C:\ProgramData\TEMP:D115F6E4
AlternateDataStreams: C:\ProgramData\TEMP:D1361E51
AlternateDataStreams: C:\ProgramData\TEMP:D1787194
AlternateDataStreams: C:\ProgramData\TEMP:D1D597D0
AlternateDataStreams: C:\ProgramData\TEMP:D1D63BCA
AlternateDataStreams: C:\ProgramData\TEMP:D2593961
AlternateDataStreams: C:\ProgramData\TEMP:D26B6B0A
AlternateDataStreams: C:\ProgramData\TEMP:D2C44806
AlternateDataStreams: C:\ProgramData\TEMP:D3331ADB
AlternateDataStreams: C:\ProgramData\TEMP:D3930F74
AlternateDataStreams: C:\ProgramData\TEMP:D3A82449
AlternateDataStreams: C:\ProgramData\TEMP:D434342F
AlternateDataStreams: C:\ProgramData\TEMP:D43ACD11
AlternateDataStreams: C:\ProgramData\TEMP:D4558A0B
AlternateDataStreams: C:\ProgramData\TEMP:D47B19A6
AlternateDataStreams: C:\ProgramData\TEMP:D48500F8
AlternateDataStreams: C:\ProgramData\TEMP:D576A536
AlternateDataStreams: C:\ProgramData\TEMP:D5CCCBAA
AlternateDataStreams: C:\ProgramData\TEMP:D5D75FF0
AlternateDataStreams: C:\ProgramData\TEMP:D61EB62D
AlternateDataStreams: C:\ProgramData\TEMP:D621CFB8
AlternateDataStreams: C:\ProgramData\TEMP:D64467B5
AlternateDataStreams: C:\ProgramData\TEMP:D64DD961
AlternateDataStreams: C:\ProgramData\TEMP:D72D7897
AlternateDataStreams: C:\ProgramData\TEMP:D74C2847
AlternateDataStreams: C:\ProgramData\TEMP:D750EF68
AlternateDataStreams: C:\ProgramData\TEMP:D770A15D
AlternateDataStreams: C:\ProgramData\TEMP:D7740E2A
AlternateDataStreams: C:\ProgramData\TEMP:D7B7645F
AlternateDataStreams: C:\ProgramData\TEMP:D7C0213D
AlternateDataStreams: C:\ProgramData\TEMP:D7D0B4AF
AlternateDataStreams: C:\ProgramData\TEMP:D7DA89B1
AlternateDataStreams: C:\ProgramData\TEMP:D7F8D8A2
AlternateDataStreams: C:\ProgramData\TEMP:D82A9FCF
AlternateDataStreams: C:\ProgramData\TEMP:D8AE9DD1
AlternateDataStreams: C:\ProgramData\TEMP:D8EA2847
AlternateDataStreams: C:\ProgramData\TEMP:D9089E64
AlternateDataStreams: C:\ProgramData\TEMP:D92485C9
AlternateDataStreams: C:\ProgramData\TEMP:D9592966
AlternateDataStreams: C:\ProgramData\TEMP:D9656460
AlternateDataStreams: C:\ProgramData\TEMP:D9771F40
AlternateDataStreams: C:\ProgramData\TEMP:D987CB43
AlternateDataStreams: C:\ProgramData\TEMP:D9F34335
AlternateDataStreams: C:\ProgramData\TEMP:DA3C6C07
AlternateDataStreams: C:\ProgramData\TEMP:DA55B48C
AlternateDataStreams: C:\ProgramData\TEMP:DA7655EA
AlternateDataStreams: C:\ProgramData\TEMP:DA9A88B3
AlternateDataStreams: C:\ProgramData\TEMP:DAB09BDB
AlternateDataStreams: C:\ProgramData\TEMP:DB2748F7
AlternateDataStreams: C:\ProgramData\TEMP:DB76C881
AlternateDataStreams: C:\ProgramData\TEMP:DBB979D4
AlternateDataStreams: C:\ProgramData\TEMP:DBEF355E
AlternateDataStreams: C:\ProgramData\TEMP:DC0B1070
AlternateDataStreams: C:\ProgramData\TEMP:DC7EDF41
AlternateDataStreams: C:\ProgramData\TEMP:DCA79AB3
AlternateDataStreams: C:\ProgramData\TEMP:DCB27118
AlternateDataStreams: C:\ProgramData\TEMP:DCDE7C60
AlternateDataStreams: C:\ProgramData\TEMP:DD874E14
AlternateDataStreams: C:\ProgramData\TEMP:DD95E6D9
AlternateDataStreams: C:\ProgramData\TEMP:DDF112BD
AlternateDataStreams: C:\ProgramData\TEMP:DE3ABE3D
AlternateDataStreams: C:\ProgramData\TEMP:DE875C30
AlternateDataStreams: C:\ProgramData\TEMP:DEDAEF90
AlternateDataStreams: C:\ProgramData\TEMP:DF0DB8AB
AlternateDataStreams: C:\ProgramData\TEMP:DFB61534
AlternateDataStreams: C:\ProgramData\TEMP:DFFB9E98
AlternateDataStreams: C:\ProgramData\TEMP:E00A6A60
AlternateDataStreams: C:\ProgramData\TEMP:E0365B26
AlternateDataStreams: C:\ProgramData\TEMP:E06963C0
AlternateDataStreams: C:\ProgramData\TEMP:E0848D16
AlternateDataStreams: C:\ProgramData\TEMP:E0888117
AlternateDataStreams: C:\ProgramData\TEMP:E10DCAF3
AlternateDataStreams: C:\ProgramData\TEMP:E11D90D0
AlternateDataStreams: C:\ProgramData\TEMP:E14FA16F
AlternateDataStreams: C:\ProgramData\TEMP:E153075C
AlternateDataStreams: C:\ProgramData\TEMP:E1D06077
AlternateDataStreams: C:\ProgramData\TEMP:E21433CE
AlternateDataStreams: C:\ProgramData\TEMP:E23BF4AD
AlternateDataStreams: C:\ProgramData\TEMP:E2C51D18
AlternateDataStreams: C:\ProgramData\TEMP:E2CFA9CD
AlternateDataStreams: C:\ProgramData\TEMP:E329D971
AlternateDataStreams: C:\ProgramData\TEMP:E32D2701
AlternateDataStreams: C:\ProgramData\TEMP:E33D6212
AlternateDataStreams: C:\ProgramData\TEMP:E411AA0D
AlternateDataStreams: C:\ProgramData\TEMP:E4272706
AlternateDataStreams: C:\ProgramData\TEMP:E446CB48
AlternateDataStreams: C:\ProgramData\TEMP:E463CA56
AlternateDataStreams: C:\ProgramData\TEMP:E495057A
AlternateDataStreams: C:\ProgramData\TEMP:E4BC4A41
AlternateDataStreams: C:\ProgramData\TEMP:E4E83517
AlternateDataStreams: C:\ProgramData\TEMP:E4FD113F
AlternateDataStreams: C:\ProgramData\TEMP:E517FE76
AlternateDataStreams: C:\ProgramData\TEMP:E5438999
AlternateDataStreams: C:\ProgramData\TEMP:E5B07840
AlternateDataStreams: C:\ProgramData\TEMP:E60C72DB
AlternateDataStreams: C:\ProgramData\TEMP:E6433F27
AlternateDataStreams: C:\ProgramData\TEMP:E6708F08
AlternateDataStreams: C:\ProgramData\TEMP:E690114B
AlternateDataStreams: C:\ProgramData\TEMP:E6B95E40
AlternateDataStreams: C:\ProgramData\TEMP:E6BEADB7
AlternateDataStreams: C:\ProgramData\TEMP:E6C6EB3B
AlternateDataStreams: C:\ProgramData\TEMP:E6CDFB4A
AlternateDataStreams: C:\ProgramData\TEMP:E70FD81B
AlternateDataStreams: C:\ProgramData\TEMP:E8074E20
AlternateDataStreams: C:\ProgramData\TEMP:E81603BC
AlternateDataStreams: C:\ProgramData\TEMP:E83EE313
AlternateDataStreams: C:\ProgramData\TEMP:E87AB4E3
AlternateDataStreams: C:\ProgramData\TEMP:E894A3ED
AlternateDataStreams: C:\ProgramData\TEMP:E89EDC52
AlternateDataStreams: C:\ProgramData\TEMP:E8AEB2BF
AlternateDataStreams: C:\ProgramData\TEMP:E8B61305
AlternateDataStreams: C:\ProgramData\TEMP:E8BE0B80
AlternateDataStreams: C:\ProgramData\TEMP:E8C44CB4
AlternateDataStreams: C:\ProgramData\TEMP:E8C4808B
AlternateDataStreams: C:\ProgramData\TEMP:E900132A
AlternateDataStreams: C:\ProgramData\TEMP:E94FA418
AlternateDataStreams: C:\ProgramData\TEMP:E96A2658
AlternateDataStreams: C:\ProgramData\TEMP:E98C5DD9
AlternateDataStreams: C:\ProgramData\TEMP:E99D1D3C
AlternateDataStreams: C:\ProgramData\TEMP:E9CB5ECC
AlternateDataStreams: C:\ProgramData\TEMP:EA10407C
AlternateDataStreams: C:\ProgramData\TEMP:EA2D3047
AlternateDataStreams: C:\ProgramData\TEMP:EA500268
AlternateDataStreams: C:\ProgramData\TEMP:EA7D76BE
AlternateDataStreams: C:\ProgramData\TEMP:EA9D8B40
AlternateDataStreams: C:\ProgramData\TEMP:EB603FE4
AlternateDataStreams: C:\ProgramData\TEMP:EBF0842B
AlternateDataStreams: C:\ProgramData\TEMP:EC752217
AlternateDataStreams: C:\ProgramData\TEMP:ECF3C50F
AlternateDataStreams: C:\ProgramData\TEMP:ED2D63E4
AlternateDataStreams: C:\ProgramData\TEMP:ED51D3ED
AlternateDataStreams: C:\ProgramData\TEMP:ED6B6C83
AlternateDataStreams: C:\ProgramData\TEMP:ED92736E
AlternateDataStreams: C:\ProgramData\TEMP:EDB03249
AlternateDataStreams: C:\ProgramData\TEMP:EDED3240
AlternateDataStreams: C:\ProgramData\TEMP:EDF12A30
AlternateDataStreams: C:\ProgramData\TEMP:EE2B5DE3
AlternateDataStreams: C:\ProgramData\TEMP:EE2DD6CC
AlternateDataStreams: C:\ProgramData\TEMP:EE7AAC75
AlternateDataStreams: C:\ProgramData\TEMP:EE9B2879
AlternateDataStreams: C:\ProgramData\TEMP:EEB25EAE
AlternateDataStreams: C:\ProgramData\TEMP:EEC56B69
AlternateDataStreams: C:\ProgramData\TEMP:EEF1584F
AlternateDataStreams: C:\ProgramData\TEMP:EF0C5444
AlternateDataStreams: C:\ProgramData\TEMP:EF0F3F33
AlternateDataStreams: C:\ProgramData\TEMP:EF38B79C
AlternateDataStreams: C:\ProgramData\TEMP:EF4B1DA9
AlternateDataStreams: C:\ProgramData\TEMP:EFE4FB84
AlternateDataStreams: C:\ProgramData\TEMP:EFECABA9
AlternateDataStreams: C:\ProgramData\TEMP:EFF3C3C8
AlternateDataStreams: C:\ProgramData\TEMP:F0E908D5
AlternateDataStreams: C:\ProgramData\TEMP:F1381B87
AlternateDataStreams: C:\ProgramData\TEMP:F142DBA9
AlternateDataStreams: C:\ProgramData\TEMP:F193BFCF
AlternateDataStreams: C:\ProgramData\TEMP:F1F936DF
AlternateDataStreams: C:\ProgramData\TEMP:F2327E82
AlternateDataStreams: C:\ProgramData\TEMP:F27A649C
AlternateDataStreams: C:\ProgramData\TEMP:F2B81C2E
AlternateDataStreams: C:\ProgramData\TEMP:F2E92DCD
AlternateDataStreams: C:\ProgramData\TEMP:F2EDC57C
AlternateDataStreams: C:\ProgramData\TEMP:F2F115B4
AlternateDataStreams: C:\ProgramData\TEMP:F30757AC
AlternateDataStreams: C:\ProgramData\TEMP:F33C37D5
AlternateDataStreams: C:\ProgramData\TEMP:F3591DDB
AlternateDataStreams: C:\ProgramData\TEMP:F3A185AE
AlternateDataStreams: C:\ProgramData\TEMP:F3A27FDE
AlternateDataStreams: C:\ProgramData\TEMP:F3F9AB21
AlternateDataStreams: C:\ProgramData\TEMP:F41F8101
AlternateDataStreams: C:\ProgramData\TEMP:F4362715
AlternateDataStreams: C:\ProgramData\TEMP:F52DB269
AlternateDataStreams: C:\ProgramData\TEMP:F53B274A
AlternateDataStreams: C:\ProgramData\TEMP:F5B51004
AlternateDataStreams: C:\ProgramData\TEMP:F5E90ED3
AlternateDataStreams: C:\ProgramData\TEMP:F5FC5DCE
AlternateDataStreams: C:\ProgramData\TEMP:F610C203
AlternateDataStreams: C:\ProgramData\TEMP:F65A2273
AlternateDataStreams: C:\ProgramData\TEMP:F663BB74
AlternateDataStreams: C:\ProgramData\TEMP:F67947AF
AlternateDataStreams: C:\ProgramData\TEMP:F6910DB1
AlternateDataStreams: C:\ProgramData\TEMP:F6A0889A
AlternateDataStreams: C:\ProgramData\TEMP:F6DA3F39
AlternateDataStreams: C:\ProgramData\TEMP:F6E5C7FB
AlternateDataStreams: C:\ProgramData\TEMP:F7BF538D
AlternateDataStreams: C:\ProgramData\TEMP:F7F4DC88
AlternateDataStreams: C:\ProgramData\TEMP:F888E36D
AlternateDataStreams: C:\ProgramData\TEMP:F8A53745
AlternateDataStreams: C:\ProgramData\TEMP:F8C2E3B9
AlternateDataStreams: C:\ProgramData\TEMP:F8DE80DB
AlternateDataStreams: C:\ProgramData\TEMP:F8F070C2
AlternateDataStreams: C:\ProgramData\TEMP:F94DE3B1
AlternateDataStreams: C:\ProgramData\TEMP:FA09FC72
AlternateDataStreams: C:\ProgramData\TEMP:FA42DF8E
AlternateDataStreams: C:\ProgramData\TEMP:FA7EAF8F
AlternateDataStreams: C:\ProgramData\TEMP:FAB64002
AlternateDataStreams: C:\ProgramData\TEMP:FB08C210
AlternateDataStreams: C:\ProgramData\TEMP:FB384C06
AlternateDataStreams: C:\ProgramData\TEMP:FB65A4AA
AlternateDataStreams: C:\ProgramData\TEMP:FB71A279
AlternateDataStreams: C:\ProgramData\TEMP:FB9F749F
AlternateDataStreams: C:\ProgramData\TEMP:FBA79096
AlternateDataStreams: C:\ProgramData\TEMP:FC4B020F
AlternateDataStreams: C:\ProgramData\TEMP:FC60E0F8
AlternateDataStreams: C:\ProgramData\TEMP:FC8FFA4E
AlternateDataStreams: C:\ProgramData\TEMP:FCBEDCFD
AlternateDataStreams: C:\ProgramData\TEMP:FCE69FCE
AlternateDataStreams: C:\ProgramData\TEMP:FD32FD25
AlternateDataStreams: C:\ProgramData\TEMP:FD444D31
AlternateDataStreams: C:\ProgramData\TEMP:FD646198
AlternateDataStreams: C:\ProgramData\TEMP:FD6DB82C
AlternateDataStreams: C:\ProgramData\TEMP:FD786DCA
AlternateDataStreams: C:\ProgramData\TEMP:FD7DCDA6
AlternateDataStreams: C:\ProgramData\TEMP:FE4E15B1
AlternateDataStreams: C:\ProgramData\TEMP:FEE00EB9
AlternateDataStreams: C:\ProgramData\TEMP:FEF0DEE7
AlternateDataStreams: C:\ProgramData\TEMP:FF818E2B
AlternateDataStreams: C:\ProgramData\TEMP:FF8F1AE3
AlternateDataStreams: C:\ProgramData\TEMP:FF9C44FE
AlternateDataStreams: C:\ProgramData\TEMP:FFD58FFB

==================== Safe Mode (whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. The "AlternateShell" will be restored.)

HKLM\SYSTEM\CurrentControlSet\Control\SafeBoot\Network\MpfService => ""="Service"

==================== EXE Association (whitelisted) =============

(If an entry is included in the fixlist, the default will be restored. None default entries will be removed.)


==================== MSCONFIG/TASK MANAGER disabled items =========

(Currently there is no automatic fix for this section.)

MSCONFIG\startupfolder: C:^ProgramData^Microsoft^Windows^Start Menu^Programs^Startup^Kodak EasyShare software.lnk => C:\Windows\pss\Kodak EasyShare software.lnk.CommonStartup
MSCONFIG\startupreg: Adobe ARM => "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
MSCONFIG\startupreg: AppleSyncNotifier => C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleSyncNotifier.exe
MSCONFIG\startupreg: APSDaemon => "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
MSCONFIG\startupreg: Dell DataSafe Online => "C:\Program Files (x86)\Dell DataSafe Online\DataSafeOnline.exe" /m
MSCONFIG\startupreg: DellSupportCenter => "C:\Program Files (x86)\Dell Support Center\bin\sprtcmd.exe" /P DellSupportCenter
MSCONFIG\startupreg: Desktop Disc Tool => "C:\Program Files (x86)\Roxio\Roxio Burn\RoxioBurnLauncher.exe"
MSCONFIG\startupreg: FAStartup => 
MSCONFIG\startupreg: iTunesHelper => "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
MSCONFIG\startupreg: Launcher => C:\Program Files (x86)\Dell DataSafe Local Backup\Components\scheduler\Launcher.exe
MSCONFIG\startupreg: Nikon Transfer Monitor => C:\Program Files (x86)\Common Files\Nikon\Monitor\NkMonitor.exe
MSCONFIG\startupreg: PDVDDXSrv => "C:\Program Files (x86)\CyberLink\PowerDVD DX\PDVDDXSrv.exe"
MSCONFIG\startupreg: PWRISOVM.EXE => C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
MSCONFIG\startupreg: QuickTime Task => "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
MSCONFIG\startupreg: Samsung Link => "C:\Program Files\Samsung\Samsung Link\Samsung Link Tray Agent.exe"
MSCONFIG\startupreg: Skype => "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
MSCONFIG\startupreg: Speech Recognition => "C:\Windows\Speech\Common\sapisvr.exe" -SpeechUX -Startup
MSCONFIG\startupreg: SunJavaUpdateSched => "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
MSCONFIG\startupreg: swg => "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"

========================= Accounts: ==========================

Administrator (S-1-5-21-3777444554-1153240464-3734799716-500 - Administrator - Disabled)
Brian (S-1-5-21-3777444554-1153240464-3734799716-1003 - Administrator - Enabled) => C:\Users\Brian
Chrissy (S-1-5-21-3777444554-1153240464-3734799716-1000 - Administrator - Enabled) => C:\Users\Chrissy
Guest (S-1-5-21-3777444554-1153240464-3734799716-501 - Limited - Disabled)
HomeGroupUser$ (S-1-5-21-3777444554-1153240464-3734799716-1006 - Limited - Enabled)

==================== Faulty Device Manager Devices =============


==================== Event log errors: =========================

Application errors:
==================
Error: (10/16/2014 02:43:45 PM) (Source: Application Hang) (EventID: 1002) (User: )
Description: The program chrome.exe version 38.0.2125.104 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel.

Process ID: 1880

Start Time: 01cfe9709f6503f8

Termination Time: 15

Application Path: C:\Program Files (x86)\Google\Chrome\Application\chrome.exe

Report Id: 58f9f926-5564-11e4-a94e-002170607dca

Error: (10/15/2014 08:13:57 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 10982

Error: (10/15/2014 08:13:57 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 10982

Error: (10/15/2014 08:13:57 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (10/15/2014 08:13:56 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 9984

Error: (10/15/2014 08:13:56 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 9984

Error: (10/15/2014 08:13:56 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second

Error: (10/15/2014 08:13:55 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledSPRetry 8986

Error: (10/15/2014 08:13:55 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: m->NextScheduledEvent 8986

Error: (10/15/2014 08:13:55 PM) (Source: Bonjour Service) (EventID: 100) (User: )
Description: Task Scheduling Error: Continuously busy for more than a second


System errors:
=============
Error: (10/16/2014 02:43:50 PM) (Source: DCOM) (EventID: 10010) (User: )
Description: {3C5E2B20-B911-44E2-A2DD-9F05E7B5E775}

Error: (10/16/2014 02:29:27 PM) (Source: VDS Basic Provider) (EventID: 1) (User: )
Description: Unexpected failure. Error code: D@01010004

Error: (10/16/2014 02:29:27 PM) (Source: VDS Basic Provider) (EventID: 1) (User: )
Description: Unexpected failure. Error code: D@01010004

Error: (10/16/2014 02:29:27 PM) (Source: VDS Basic Provider) (EventID: 1) (User: )
Description: Unexpected failure. Error code: D@01010004

Error: (10/16/2014 03:39:13 AM) (Source: Microsoft-Windows-WindowsUpdateClient) (EventID: 20) (User: NT AUTHORITY)
Description: Installation Failure: Windows failed to install the following update with error 0x80242016: Update for Windows 7 for x64-based Systems (KB2952664).

Error: (10/16/2014 03:02:50 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (10/16/2014 03:02:47 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (10/15/2014 11:28:10 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (10/15/2014 11:28:08 AM) (Source: Disk) (EventID: 7) (User: )
Description: The device, \Device\Harddisk0\DR0, has a bad block.

Error: (10/10/2014 00:13:36 PM) (Source: Service Control Manager) (EventID: 7011) (User: )
Description: A timeout (30000 milliseconds) was reached while waiting for a transaction response from the lmhosts service.


Microsoft Office Sessions:
=========================

CodeIntegrity Errors:
===================================
  Date: 2014-05-29 19:46:27.589
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-05-29 19:46:27.277
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-05-29 19:46:26.981
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-05-29 19:46:26.684
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-02-09 20:09:27.665
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2014-02-09 20:09:27.478
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\ComboFix\catchme.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-03-11 15:41:37.832
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-03-11 15:41:37.702
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-03-11 15:39:48.339
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

  Date: 2013-03-11 15:39:48.215
  Description: Windows is unable to verify the image integrity of the file \Device\HarddiskVolume3\Windows\System32\drivers\usbaapl64.sys because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.


==================== Memory info =========================== 

Processor: Intel(R) Core(TM)2 Quad CPU Q9400 @ 2.66GHz
Percentage of memory in use: 30%
Total physical RAM: 6143.18 MB
Available physical RAM: 4278.24 MB
Total Pagefile: 12284.54 MB
Available Pagefile: 9528.59 MB
Total Virtual: 8192 MB
Available Virtual: 8191.83 MB

==================== Drives ================================

Drive c: (OS) (Fixed) (Total:585.81 GB) (Free:461.28 GB) NTFS

==================== MBR & Partition Table ==================

========================================================
Disk: 0 (MBR Code: Windows 7 or 8) (Size: 596.2 GB) (Disk ID: B0000000)
Partition 1: (Not Active) - (Size=71 MB) - (Type=DE)
Partition 2: (Active) - (Size=10.3 GB) - (Type=07 NTFS)
Partition 3: (Not Active) - (Size=585.8 GB) - (Type=07 NTFS)

==================== End Of Log ============================


#4 TB-Psychotic

TB-Psychotic

  • Malware Response Team
  • 6,349 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:30 AM

Posted 21 October 2014 - 06:43 AM

Fix with FRST (normal mode)

WARNING: This script was written specifically for this user, for use on that particular machine. Running this on another machine may cause damage to your operating system
 

  • Download the attached fixlist.txt and save it to the location where FRST is saved to.
  • Run FRST.exe (on 64bit, run FRST64.exe) and press the Fix button just once and wait.
  • The tool will make a log (Fixlog.txt) which you find where you saved FRST. Please post it to your reply.

 

 

 

 

Full System Scan with Malwarebytes Antimalware
 

  • If not existing, please download Malwarebytes Anti-Malware to your desktop.
  • Double-click the downloaded setup file and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to the following:
    • Launch Malwarebytes Anti-Malware
    • A 14 day trial of the Premium features is pre-selected. You may deselect this if you wish, and it will not diminish the scanning and removal capabilities of the program.
  • Click Finish.

If the program is already installed:

  • Run Malwarebytes Antimalware
  • On the Dashboard, click the 'Update Now >>' link
  • After the update completes, click the 'Scan Now >>' button.
  • Or, on the Dashboard, click the Scan Now >> button.
  • If an update is available, click the Update Now button.
  • A Threat Scan will begin.
  • When the scan is complete, if there have been detections, click Apply Actions to allow MBAM to clean what was detected.
  • In most cases, a restart will be required.
  • Wait for the prompt to restart the computer to appear, then click on Yes.

  • After the restart once you are back at your desktop, open MBAM once more.
  • Click on the History tab > Application Logs.
  • Double click on the scan log which shows the Date and time of the scan just performed.
  • Click 'Copy to Clipboard'
  • Paste the contents of the clipboard into your reply.

 

Attached Files


Proud Member of UNITE & TB
 
My help is free, however, if you want to support my fight against malware, click here --> btn_donate_SM.gif <--(no worries, every little bit helps)

#5 Dizzy24

Dizzy24
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Baltimore
  • Local time:11:30 PM

Posted 21 October 2014 - 03:12 PM

The MBAM scan came up negative for any threats. 

Here is the fixlog.txt :

Fix result of Farbar Recovery Tool (FRST written by Farbar) (x64) Version: 21-10-2014
Ran by Chrissy at 2014-10-21 15:48:28 Run:1
Running from C:\Users\Chrissy\Downloads
Loaded Profile: Chrissy (Available profiles: Chrissy & Brian)
Boot Mode: Normal
==============================================

Content of fixlist:
*****************
AlternateDataStreams: C:\ProgramData\TEMP:008FE370
AlternateDataStreams: C:\ProgramData\TEMP:00D99749
AlternateDataStreams: C:\ProgramData\TEMP:0102CF0C
AlternateDataStreams: C:\ProgramData\TEMP:014BC3B4
AlternateDataStreams: C:\ProgramData\TEMP:0168CC60
AlternateDataStreams: C:\ProgramData\TEMP:017D5143
AlternateDataStreams: C:\ProgramData\TEMP:01F9D1B4
AlternateDataStreams: C:\ProgramData\TEMP:021496FB
AlternateDataStreams: C:\ProgramData\TEMP:025C72E5
AlternateDataStreams: C:\ProgramData\TEMP:02A78DF6
AlternateDataStreams: C:\ProgramData\TEMP:02CC0035
AlternateDataStreams: C:\ProgramData\TEMP:02F30776
AlternateDataStreams: C:\ProgramData\TEMP:036AA5DD
AlternateDataStreams: C:\ProgramData\TEMP:03D08225
AlternateDataStreams: C:\ProgramData\TEMP:0410A323
AlternateDataStreams: C:\ProgramData\TEMP:041C0562
AlternateDataStreams: C:\ProgramData\TEMP:041ED421
AlternateDataStreams: C:\ProgramData\TEMP:0474F714
AlternateDataStreams: C:\ProgramData\TEMP:04EAB86F
AlternateDataStreams: C:\ProgramData\TEMP:04FB3774
AlternateDataStreams: C:\ProgramData\TEMP:05113FB9
AlternateDataStreams: C:\ProgramData\TEMP:052A05A1
AlternateDataStreams: C:\ProgramData\TEMP:05F547A9
AlternateDataStreams: C:\ProgramData\TEMP:0696EC8E
AlternateDataStreams: C:\ProgramData\TEMP:069BAEA8
AlternateDataStreams: C:\ProgramData\TEMP:073139EC
AlternateDataStreams: C:\ProgramData\TEMP:07437A8C
AlternateDataStreams: C:\ProgramData\TEMP:0785072C
AlternateDataStreams: C:\ProgramData\TEMP:078B239B
AlternateDataStreams: C:\ProgramData\TEMP:07A75CBF
AlternateDataStreams: C:\ProgramData\TEMP:07C99568
AlternateDataStreams: C:\ProgramData\TEMP:083C8737
AlternateDataStreams: C:\ProgramData\TEMP:087CB364
AlternateDataStreams: C:\ProgramData\TEMP:08DB8D99
AlternateDataStreams: C:\ProgramData\TEMP:08E5EE32
AlternateDataStreams: C:\ProgramData\TEMP:0951C4CC
AlternateDataStreams: C:\ProgramData\TEMP:0968E571
AlternateDataStreams: C:\ProgramData\TEMP:097C4B7D
AlternateDataStreams: C:\ProgramData\TEMP:097FF903
AlternateDataStreams: C:\ProgramData\TEMP:0A701F26
AlternateDataStreams: C:\ProgramData\TEMP:0AC0213C
AlternateDataStreams: C:\ProgramData\TEMP:0ACF1AF5
AlternateDataStreams: C:\ProgramData\TEMP:0ADCCF52
AlternateDataStreams: C:\ProgramData\TEMP:0AE6CC6C
AlternateDataStreams: C:\ProgramData\TEMP:0AF3BFB9
AlternateDataStreams: C:\ProgramData\TEMP:0AF3C3DF
AlternateDataStreams: C:\ProgramData\TEMP:0B3F95D0
AlternateDataStreams: C:\ProgramData\TEMP:0B55751B
AlternateDataStreams: C:\ProgramData\TEMP:0B79AB8D
AlternateDataStreams: C:\ProgramData\TEMP:0BCD47A5
AlternateDataStreams: C:\ProgramData\TEMP:0C9E06A2
AlternateDataStreams: C:\ProgramData\TEMP:0CDBB2C2
AlternateDataStreams: C:\ProgramData\TEMP:0CDF8C3D
AlternateDataStreams: C:\ProgramData\TEMP:0D761AB3
AlternateDataStreams: C:\ProgramData\TEMP:0D797314
AlternateDataStreams: C:\ProgramData\TEMP:0DE96CF5
AlternateDataStreams: C:\ProgramData\TEMP:0E10B960
AlternateDataStreams: C:\ProgramData\TEMP:0E61938B
AlternateDataStreams: C:\ProgramData\TEMP:0E660858
AlternateDataStreams: C:\ProgramData\TEMP:0E8117B1
AlternateDataStreams: C:\ProgramData\TEMP:0EAA09AC
AlternateDataStreams: C:\ProgramData\TEMP:0EBD727C
AlternateDataStreams: C:\ProgramData\TEMP:0ED1C542
AlternateDataStreams: C:\ProgramData\TEMP:0F5DCBF5
AlternateDataStreams: C:\ProgramData\TEMP:0F64164E
AlternateDataStreams: C:\ProgramData\TEMP:0FAE191E
AlternateDataStreams: C:\ProgramData\TEMP:0FD8569B
AlternateDataStreams: C:\ProgramData\TEMP:0FE0A03C
AlternateDataStreams: C:\ProgramData\TEMP:1011DA7C
AlternateDataStreams: C:\ProgramData\TEMP:1013B07C
AlternateDataStreams: C:\ProgramData\TEMP:1044BAFC
AlternateDataStreams: C:\ProgramData\TEMP:104A1C3E
AlternateDataStreams: C:\ProgramData\TEMP:109734F6
AlternateDataStreams: C:\ProgramData\TEMP:10CB85CA
AlternateDataStreams: C:\ProgramData\TEMP:10D45FC3
AlternateDataStreams: C:\ProgramData\TEMP:10D7EE4B
AlternateDataStreams: C:\ProgramData\TEMP:10DB9BB7
AlternateDataStreams: C:\ProgramData\TEMP:10E295F9
AlternateDataStreams: C:\ProgramData\TEMP:114C90CA
AlternateDataStreams: C:\ProgramData\TEMP:1170D6E4
AlternateDataStreams: C:\ProgramData\TEMP:11C7FAE3
AlternateDataStreams: C:\ProgramData\TEMP:11EFE63D
AlternateDataStreams: C:\ProgramData\TEMP:120B3AFD
AlternateDataStreams: C:\ProgramData\TEMP:120E44A4
AlternateDataStreams: C:\ProgramData\TEMP:1224B4C3
AlternateDataStreams: C:\ProgramData\TEMP:12383CAE
AlternateDataStreams: C:\ProgramData\TEMP:124B94C0
AlternateDataStreams: C:\ProgramData\TEMP:128B55C8
AlternateDataStreams: C:\ProgramData\TEMP:12A012A1
AlternateDataStreams: C:\ProgramData\TEMP:12BCD9DC
AlternateDataStreams: C:\ProgramData\TEMP:12D136AA
AlternateDataStreams: C:\ProgramData\TEMP:12D21A9A
AlternateDataStreams: C:\ProgramData\TEMP:12D2EB9C
AlternateDataStreams: C:\ProgramData\TEMP:12D9D48F
AlternateDataStreams: C:\ProgramData\TEMP:12E189B0
AlternateDataStreams: C:\ProgramData\TEMP:13019F4B
AlternateDataStreams: C:\ProgramData\TEMP:1345C9DC
AlternateDataStreams: C:\ProgramData\TEMP:134FBDE2
AlternateDataStreams: C:\ProgramData\TEMP:13765436
AlternateDataStreams: C:\ProgramData\TEMP:13CDB0E0
AlternateDataStreams: C:\ProgramData\TEMP:140AD176
AlternateDataStreams: C:\ProgramData\TEMP:14168AA3
AlternateDataStreams: C:\ProgramData\TEMP:1416AAA6
AlternateDataStreams: C:\ProgramData\TEMP:149327FE
AlternateDataStreams: C:\ProgramData\TEMP:159A493A
AlternateDataStreams: C:\ProgramData\TEMP:1604D047
AlternateDataStreams: C:\ProgramData\TEMP:161B4B1D
AlternateDataStreams: C:\ProgramData\TEMP:164561C8
AlternateDataStreams: C:\ProgramData\TEMP:1656EE95
AlternateDataStreams: C:\ProgramData\TEMP:16BD7665
AlternateDataStreams: C:\ProgramData\TEMP:16F42F1F
AlternateDataStreams: C:\ProgramData\TEMP:16F4BC64
AlternateDataStreams: C:\ProgramData\TEMP:1802D824
AlternateDataStreams: C:\ProgramData\TEMP:183A9046
AlternateDataStreams: C:\ProgramData\TEMP:18B241CC
AlternateDataStreams: C:\ProgramData\TEMP:18E3BAF3
AlternateDataStreams: C:\ProgramData\TEMP:19474103
AlternateDataStreams: C:\ProgramData\TEMP:19C541B5
AlternateDataStreams: C:\ProgramData\TEMP:1A15E356
AlternateDataStreams: C:\ProgramData\TEMP:1A259A13
AlternateDataStreams: C:\ProgramData\TEMP:1A45D40E
AlternateDataStreams: C:\ProgramData\TEMP:1A5822A3
AlternateDataStreams: C:\ProgramData\TEMP:1A5CC80A
AlternateDataStreams: C:\ProgramData\TEMP:1ABFB99D
AlternateDataStreams: C:\ProgramData\TEMP:1ADC4BD5
AlternateDataStreams: C:\ProgramData\TEMP:1B3549F2
AlternateDataStreams: C:\ProgramData\TEMP:1B389835
AlternateDataStreams: C:\ProgramData\TEMP:1B47CB83
AlternateDataStreams: C:\ProgramData\TEMP:1B5B615D
AlternateDataStreams: C:\ProgramData\TEMP:1B7E916D
AlternateDataStreams: C:\ProgramData\TEMP:1B825050
AlternateDataStreams: C:\ProgramData\TEMP:1B8A258D
AlternateDataStreams: C:\ProgramData\TEMP:1B90AAB4
AlternateDataStreams: C:\ProgramData\TEMP:1B927722
AlternateDataStreams: C:\ProgramData\TEMP:1B96CF22
AlternateDataStreams: C:\ProgramData\TEMP:1B97BCB0
AlternateDataStreams: C:\ProgramData\TEMP:1C201DEB
AlternateDataStreams: C:\ProgramData\TEMP:1C5692E6
AlternateDataStreams: C:\ProgramData\TEMP:1C6D705B
AlternateDataStreams: C:\ProgramData\TEMP:1C9565AC
AlternateDataStreams: C:\ProgramData\TEMP:1CB8D545
AlternateDataStreams: C:\ProgramData\TEMP:1CB96B16
AlternateDataStreams: C:\ProgramData\TEMP:1CD511E5
AlternateDataStreams: C:\ProgramData\TEMP:1CF1FB36
AlternateDataStreams: C:\ProgramData\TEMP:1D60AEC3
AlternateDataStreams: C:\ProgramData\TEMP:1D6B18F1
AlternateDataStreams: C:\ProgramData\TEMP:1D9ED8F7
AlternateDataStreams: C:\ProgramData\TEMP:1DDD0008
AlternateDataStreams: C:\ProgramData\TEMP:1E288DA3
AlternateDataStreams: C:\ProgramData\TEMP:1E4D6E88
AlternateDataStreams: C:\ProgramData\TEMP:1E5EC928
AlternateDataStreams: C:\ProgramData\TEMP:1E86ADD2
AlternateDataStreams: C:\ProgramData\TEMP:1E942FB9
AlternateDataStreams: C:\ProgramData\TEMP:1EC13383
AlternateDataStreams: C:\ProgramData\TEMP:1F0FA039
AlternateDataStreams: C:\ProgramData\TEMP:1FA4C06F
AlternateDataStreams: C:\ProgramData\TEMP:1FF82161
AlternateDataStreams: C:\ProgramData\TEMP:2043337E
AlternateDataStreams: C:\ProgramData\TEMP:204BEE0F
AlternateDataStreams: C:\ProgramData\TEMP:207C4C79
AlternateDataStreams: C:\ProgramData\TEMP:217A2324
AlternateDataStreams: C:\ProgramData\TEMP:217A2A36
AlternateDataStreams: C:\ProgramData\TEMP:219DB32E
AlternateDataStreams: C:\ProgramData\TEMP:21D64A91
AlternateDataStreams: C:\ProgramData\TEMP:21D69AEA
AlternateDataStreams: C:\ProgramData\TEMP:220E9B9E
AlternateDataStreams: C:\ProgramData\TEMP:2211E7A0
AlternateDataStreams: C:\ProgramData\TEMP:2216A431
AlternateDataStreams: C:\ProgramData\TEMP:2245476B
AlternateDataStreams: C:\ProgramData\TEMP:22C80839
AlternateDataStreams: C:\ProgramData\TEMP:236FF5C6
AlternateDataStreams: C:\ProgramData\TEMP:23834E1E
AlternateDataStreams: C:\ProgramData\TEMP:241FA548
AlternateDataStreams: C:\ProgramData\TEMP:242749DF
AlternateDataStreams: C:\ProgramData\TEMP:244E4E3A
AlternateDataStreams: C:\ProgramData\TEMP:24C072FF
AlternateDataStreams: C:\ProgramData\TEMP:24C89EFC
AlternateDataStreams: C:\ProgramData\TEMP:24F08129
AlternateDataStreams: C:\ProgramData\TEMP:25005EFA
AlternateDataStreams: C:\ProgramData\TEMP:2512FA90
AlternateDataStreams: C:\ProgramData\TEMP:252E6179
AlternateDataStreams: C:\ProgramData\TEMP:2530BFBE
AlternateDataStreams: C:\ProgramData\TEMP:2556A8A0
AlternateDataStreams: C:\ProgramData\TEMP:258D2F8B
AlternateDataStreams: C:\ProgramData\TEMP:26140299
AlternateDataStreams: C:\ProgramData\TEMP:2640C43F
AlternateDataStreams: C:\ProgramData\TEMP:2652902F
AlternateDataStreams: C:\ProgramData\TEMP:26991AB9
AlternateDataStreams: C:\ProgramData\TEMP:2727F067
AlternateDataStreams: C:\ProgramData\TEMP:2773164E
AlternateDataStreams: C:\ProgramData\TEMP:27790C06
AlternateDataStreams: C:\ProgramData\TEMP:27A88EF2
AlternateDataStreams: C:\ProgramData\TEMP:27B99ED6
AlternateDataStreams: C:\ProgramData\TEMP:27C3CD07
AlternateDataStreams: C:\ProgramData\TEMP:282CE153
AlternateDataStreams: C:\ProgramData\TEMP:28CDD861
AlternateDataStreams: C:\ProgramData\TEMP:29861223
AlternateDataStreams: C:\ProgramData\TEMP:29ADC74D
AlternateDataStreams: C:\ProgramData\TEMP:29B37860
AlternateDataStreams: C:\ProgramData\TEMP:29C0641D
AlternateDataStreams: C:\ProgramData\TEMP:29DA7FEE
AlternateDataStreams: C:\ProgramData\TEMP:29F0CA7D
AlternateDataStreams: C:\ProgramData\TEMP:2A5BC0A9
AlternateDataStreams: C:\ProgramData\TEMP:2AD33723
AlternateDataStreams: C:\ProgramData\TEMP:2AE74FF9
AlternateDataStreams: C:\ProgramData\TEMP:2AF05C70
AlternateDataStreams: C:\ProgramData\TEMP:2AF322BF
AlternateDataStreams: C:\ProgramData\TEMP:2B37CCB6
AlternateDataStreams: C:\ProgramData\TEMP:2B40A7DB
AlternateDataStreams: C:\ProgramData\TEMP:2B5C4773
AlternateDataStreams: C:\ProgramData\TEMP:2B856118
AlternateDataStreams: C:\ProgramData\TEMP:2B9555D8
AlternateDataStreams: C:\ProgramData\TEMP:2C4F33F6
AlternateDataStreams: C:\ProgramData\TEMP:2C84CA43
AlternateDataStreams: C:\ProgramData\TEMP:2CA4B471
AlternateDataStreams: C:\ProgramData\TEMP:2CB9631F
AlternateDataStreams: C:\ProgramData\TEMP:2CC32B31
AlternateDataStreams: C:\ProgramData\TEMP:2CFBE2D1
AlternateDataStreams: C:\ProgramData\TEMP:2D2461E7
AlternateDataStreams: C:\ProgramData\TEMP:2DE5673D
AlternateDataStreams: C:\ProgramData\TEMP:2DF54B62
AlternateDataStreams: C:\ProgramData\TEMP:2DF93164
AlternateDataStreams: C:\ProgramData\TEMP:2E3F04BC
AlternateDataStreams: C:\ProgramData\TEMP:2E636DD9
AlternateDataStreams: C:\ProgramData\TEMP:2E87E3DD
AlternateDataStreams: C:\ProgramData\TEMP:2E928E6E
AlternateDataStreams: C:\ProgramData\TEMP:2E9900EE
AlternateDataStreams: C:\ProgramData\TEMP:2F474C84
AlternateDataStreams: C:\ProgramData\TEMP:2F5A06FD
AlternateDataStreams: C:\ProgramData\TEMP:2F8138B7
AlternateDataStreams: C:\ProgramData\TEMP:2FAFBD6A
AlternateDataStreams: C:\ProgramData\TEMP:2FF4577A
AlternateDataStreams: C:\ProgramData\TEMP:302ECBD6
AlternateDataStreams: C:\ProgramData\TEMP:3086B95F
AlternateDataStreams: C:\ProgramData\TEMP:311A2F6A
AlternateDataStreams: C:\ProgramData\TEMP:31403DF7
AlternateDataStreams: C:\ProgramData\TEMP:31C9BA96
AlternateDataStreams: C:\ProgramData\TEMP:320208DA
AlternateDataStreams: C:\ProgramData\TEMP:321156F2
AlternateDataStreams: C:\ProgramData\TEMP:32289BE8
AlternateDataStreams: C:\ProgramData\TEMP:322D2CD3
AlternateDataStreams: C:\ProgramData\TEMP:3241739E
AlternateDataStreams: C:\ProgramData\TEMP:32D2A239
AlternateDataStreams: C:\ProgramData\TEMP:32EA849C
AlternateDataStreams: C:\ProgramData\TEMP:3313A48D
AlternateDataStreams: C:\ProgramData\TEMP:3393A1CA
AlternateDataStreams: C:\ProgramData\TEMP:33B04540
AlternateDataStreams: C:\ProgramData\TEMP:342886D8
AlternateDataStreams: C:\ProgramData\TEMP:3433021E
AlternateDataStreams: C:\ProgramData\TEMP:34445512
AlternateDataStreams: C:\ProgramData\TEMP:345A9A38
AlternateDataStreams: C:\ProgramData\TEMP:3480F458
AlternateDataStreams: C:\ProgramData\TEMP:34EFF1F2
AlternateDataStreams: C:\ProgramData\TEMP:34FDB459
AlternateDataStreams: C:\ProgramData\TEMP:35110824
AlternateDataStreams: C:\ProgramData\TEMP:3557EC26
AlternateDataStreams: C:\ProgramData\TEMP:35629AE6
AlternateDataStreams: C:\ProgramData\TEMP:3571475C
AlternateDataStreams: C:\ProgramData\TEMP:3595B780
AlternateDataStreams: C:\ProgramData\TEMP:35A8E846
AlternateDataStreams: C:\ProgramData\TEMP:35E8E596
AlternateDataStreams: C:\ProgramData\TEMP:361703F1
AlternateDataStreams: C:\ProgramData\TEMP:366B74CA
AlternateDataStreams: C:\ProgramData\TEMP:366EFA1A
AlternateDataStreams: C:\ProgramData\TEMP:36ED5C45
AlternateDataStreams: C:\ProgramData\TEMP:371A321E
AlternateDataStreams: C:\ProgramData\TEMP:373C6DC2
AlternateDataStreams: C:\ProgramData\TEMP:378824DE
AlternateDataStreams: C:\ProgramData\TEMP:37994DBE
AlternateDataStreams: C:\ProgramData\TEMP:37C279BE
AlternateDataStreams: C:\ProgramData\TEMP:38534D53
AlternateDataStreams: C:\ProgramData\TEMP:3867977D
AlternateDataStreams: C:\ProgramData\TEMP:395F6776
AlternateDataStreams: C:\ProgramData\TEMP:3969ACF7
AlternateDataStreams: C:\ProgramData\TEMP:397D67BA
AlternateDataStreams: C:\ProgramData\TEMP:398D2775
AlternateDataStreams: C:\ProgramData\TEMP:398EFF0F
AlternateDataStreams: C:\ProgramData\TEMP:3A4676D7
AlternateDataStreams: C:\ProgramData\TEMP:3AC0ED43
AlternateDataStreams: C:\ProgramData\TEMP:3AD6342E
AlternateDataStreams: C:\ProgramData\TEMP:3ADE134E
AlternateDataStreams: C:\ProgramData\TEMP:3AF262FC
AlternateDataStreams: C:\ProgramData\TEMP:3B07E6F4
AlternateDataStreams: C:\ProgramData\TEMP:3B633DE9
AlternateDataStreams: C:\ProgramData\TEMP:3B71586E
AlternateDataStreams: C:\ProgramData\TEMP:3C0887BF
AlternateDataStreams: C:\ProgramData\TEMP:3C8B784A
AlternateDataStreams: C:\ProgramData\TEMP:3C9B05C4
AlternateDataStreams: C:\ProgramData\TEMP:3CA18B6B
AlternateDataStreams: C:\ProgramData\TEMP:3CAE2A70
AlternateDataStreams: C:\ProgramData\TEMP:3D186293
AlternateDataStreams: C:\ProgramData\TEMP:3D3F1635
AlternateDataStreams: C:\ProgramData\TEMP:3D4B733E
AlternateDataStreams: C:\ProgramData\TEMP:3D887DCC
AlternateDataStreams: C:\ProgramData\TEMP:3D922890
AlternateDataStreams: C:\ProgramData\TEMP:3DBE461A
AlternateDataStreams: C:\ProgramData\TEMP:3E200C29
AlternateDataStreams: C:\ProgramData\TEMP:3ED5E595
AlternateDataStreams: C:\ProgramData\TEMP:3F9F662A
AlternateDataStreams: C:\ProgramData\TEMP:3FB26DBA
AlternateDataStreams: C:\ProgramData\TEMP:3FBB88CF
AlternateDataStreams: C:\ProgramData\TEMP:4018444F
AlternateDataStreams: C:\ProgramData\TEMP:401CAF8F
AlternateDataStreams: C:\ProgramData\TEMP:403C313B
AlternateDataStreams: C:\ProgramData\TEMP:404908B5
AlternateDataStreams: C:\ProgramData\TEMP:40512067
AlternateDataStreams: C:\ProgramData\TEMP:40546375
AlternateDataStreams: C:\ProgramData\TEMP:409F27A9
AlternateDataStreams: C:\ProgramData\TEMP:4149A170
AlternateDataStreams: C:\ProgramData\TEMP:4157BB05
AlternateDataStreams: C:\ProgramData\TEMP:415E77AB
AlternateDataStreams: C:\ProgramData\TEMP:417B6FAC
AlternateDataStreams: C:\ProgramData\TEMP:417C2BC3
AlternateDataStreams: C:\ProgramData\TEMP:41884BBE
AlternateDataStreams: C:\ProgramData\TEMP:41C283B2
AlternateDataStreams: C:\ProgramData\TEMP:42275BC2
AlternateDataStreams: C:\ProgramData\TEMP:42B6425E
AlternateDataStreams: C:\ProgramData\TEMP:432EC713
AlternateDataStreams: C:\ProgramData\TEMP:438C7496
AlternateDataStreams: C:\ProgramData\TEMP:43CBFAB2
AlternateDataStreams: C:\ProgramData\TEMP:43DA85AC
AlternateDataStreams: C:\ProgramData\TEMP:43ECEA33
AlternateDataStreams: C:\ProgramData\TEMP:43F5FA9D
AlternateDataStreams: C:\ProgramData\TEMP:44712999
AlternateDataStreams: C:\ProgramData\TEMP:447856CD
AlternateDataStreams: C:\ProgramData\TEMP:44E16D4A
AlternateDataStreams: C:\ProgramData\TEMP:45912F61
AlternateDataStreams: C:\ProgramData\TEMP:46283136
AlternateDataStreams: C:\ProgramData\TEMP:469B47D8
AlternateDataStreams: C:\ProgramData\TEMP:46A2F27B
AlternateDataStreams: C:\ProgramData\TEMP:46ADD59D
AlternateDataStreams: C:\ProgramData\TEMP:46CBC45C
AlternateDataStreams: C:\ProgramData\TEMP:46CF5C1F
AlternateDataStreams: C:\ProgramData\TEMP:46EF121E
AlternateDataStreams: C:\ProgramData\TEMP:4709F39D
AlternateDataStreams: C:\ProgramData\TEMP:471AD3D0
AlternateDataStreams: C:\ProgramData\TEMP:479B1CF9
AlternateDataStreams: C:\ProgramData\TEMP:47B391B0
AlternateDataStreams: C:\ProgramData\TEMP:4826868B
AlternateDataStreams: C:\ProgramData\TEMP:48529647
AlternateDataStreams: C:\ProgramData\TEMP:48862C37
AlternateDataStreams: C:\ProgramData\TEMP:488F7244
AlternateDataStreams: C:\ProgramData\TEMP:48977386
AlternateDataStreams: C:\ProgramData\TEMP:490BCC52
AlternateDataStreams: C:\ProgramData\TEMP:49B217F7
AlternateDataStreams: C:\ProgramData\TEMP:49BE0F68
AlternateDataStreams: C:\ProgramData\TEMP:49EB69E2
AlternateDataStreams: C:\ProgramData\TEMP:4A01545C
AlternateDataStreams: C:\ProgramData\TEMP:4A03F06E
AlternateDataStreams: C:\ProgramData\TEMP:4A077D87
AlternateDataStreams: C:\ProgramData\TEMP:4A448DB2
AlternateDataStreams: C:\ProgramData\TEMP:4A5CFD3B
AlternateDataStreams: C:\ProgramData\TEMP:4A8EB1C4
AlternateDataStreams: C:\ProgramData\TEMP:4A966CC2
AlternateDataStreams: C:\ProgramData\TEMP:4AC1DFA1
AlternateDataStreams: C:\ProgramData\TEMP:4AC7B5C1
AlternateDataStreams: C:\ProgramData\TEMP:4B244549
AlternateDataStreams: C:\ProgramData\TEMP:4B325725
AlternateDataStreams: C:\ProgramData\TEMP:4B3648ED
AlternateDataStreams: C:\ProgramData\TEMP:4BBF1137
AlternateDataStreams: C:\ProgramData\TEMP:4BEE39B0
AlternateDataStreams: C:\ProgramData\TEMP:4C16B46B
AlternateDataStreams: C:\ProgramData\TEMP:4C31986D
AlternateDataStreams: C:\ProgramData\TEMP:4C4BD66D
AlternateDataStreams: C:\ProgramData\TEMP:4C5C1DD3
AlternateDataStreams: C:\ProgramData\TEMP:4C6F9D77
AlternateDataStreams: C:\ProgramData\TEMP:4C8FA829
AlternateDataStreams: C:\ProgramData\TEMP:4CD2D817
AlternateDataStreams: C:\ProgramData\TEMP:4D066AD2
AlternateDataStreams: C:\ProgramData\TEMP:4D28BE4D
AlternateDataStreams: C:\ProgramData\TEMP:4D348522
AlternateDataStreams: C:\ProgramData\TEMP:4D551822
AlternateDataStreams: C:\ProgramData\TEMP:4D729D61
AlternateDataStreams: C:\ProgramData\TEMP:4D8FCBEF
AlternateDataStreams: C:\ProgramData\TEMP:4DDE401B
AlternateDataStreams: C:\ProgramData\TEMP:4DE8C719
AlternateDataStreams: C:\ProgramData\TEMP:4E79C4F8
AlternateDataStreams: C:\ProgramData\TEMP:4EAD6852
AlternateDataStreams: C:\ProgramData\TEMP:4EC7F009
AlternateDataStreams: C:\ProgramData\TEMP:4EDDC66F
AlternateDataStreams: C:\ProgramData\TEMP:4EE5EBE9
AlternateDataStreams: C:\ProgramData\TEMP:4EE95FE7
AlternateDataStreams: C:\ProgramData\TEMP:4EEC7800
AlternateDataStreams: C:\ProgramData\TEMP:4F28299B
AlternateDataStreams: C:\ProgramData\TEMP:4F7FE589
AlternateDataStreams: C:\ProgramData\TEMP:4FA837B4
AlternateDataStreams: C:\ProgramData\TEMP:5008417E
AlternateDataStreams: C:\ProgramData\TEMP:5014D98F
AlternateDataStreams: C:\ProgramData\TEMP:502EE511
AlternateDataStreams: C:\ProgramData\TEMP:506698B2
AlternateDataStreams: C:\ProgramData\TEMP:506E1E25
AlternateDataStreams: C:\ProgramData\TEMP:5080697C
AlternateDataStreams: C:\ProgramData\TEMP:50868536
AlternateDataStreams: C:\ProgramData\TEMP:50DD4118
AlternateDataStreams: C:\ProgramData\TEMP:51003EF4
AlternateDataStreams: C:\ProgramData\TEMP:512E1728
AlternateDataStreams: C:\ProgramData\TEMP:5133A494
AlternateDataStreams: C:\ProgramData\TEMP:518C333F
AlternateDataStreams: C:\ProgramData\TEMP:5197985B
AlternateDataStreams: C:\ProgramData\TEMP:5199C971
AlternateDataStreams: C:\ProgramData\TEMP:51A22C60
AlternateDataStreams: C:\ProgramData\TEMP:52329B88
AlternateDataStreams: C:\ProgramData\TEMP:5279F7BF
AlternateDataStreams: C:\ProgramData\TEMP:52C24010
AlternateDataStreams: C:\ProgramData\TEMP:5320A31B
AlternateDataStreams: C:\ProgramData\TEMP:53B8C5D2
AlternateDataStreams: C:\ProgramData\TEMP:53F09A92
AlternateDataStreams: C:\ProgramData\TEMP:53F381F1
AlternateDataStreams: C:\ProgramData\TEMP:54380FEC
AlternateDataStreams: C:\ProgramData\TEMP:54403233
AlternateDataStreams: C:\ProgramData\TEMP:54531C7D
AlternateDataStreams: C:\ProgramData\TEMP:5453E5AF
AlternateDataStreams: C:\ProgramData\TEMP:5466F106
AlternateDataStreams: C:\ProgramData\TEMP:54F0BBF5
AlternateDataStreams: C:\ProgramData\TEMP:5511B474
AlternateDataStreams: C:\ProgramData\TEMP:551BED5F
AlternateDataStreams: C:\ProgramData\TEMP:551E1CB4
AlternateDataStreams: C:\ProgramData\TEMP:5520ED93
AlternateDataStreams: C:\ProgramData\TEMP:553056F1
AlternateDataStreams: C:\ProgramData\TEMP:5539129F
AlternateDataStreams: C:\ProgramData\TEMP:554B3BF6
AlternateDataStreams: C:\ProgramData\TEMP:5607B58C
AlternateDataStreams: C:\ProgramData\TEMP:56C66609
AlternateDataStreams: C:\ProgramData\TEMP:56CE93C9
AlternateDataStreams: C:\ProgramData\TEMP:571CCF8E
AlternateDataStreams: C:\ProgramData\TEMP:57231008
AlternateDataStreams: C:\ProgramData\TEMP:57619D72
AlternateDataStreams: C:\ProgramData\TEMP:587F3582
AlternateDataStreams: C:\ProgramData\TEMP:5925E400
AlternateDataStreams: C:\ProgramData\TEMP:593E515D
AlternateDataStreams: C:\ProgramData\TEMP:59465B40
AlternateDataStreams: C:\ProgramData\TEMP:59A6876B
AlternateDataStreams: C:\ProgramData\TEMP:59C64924
AlternateDataStreams: C:\ProgramData\TEMP:5A068EE1
AlternateDataStreams: C:\ProgramData\TEMP:5A2E8BBF
AlternateDataStreams: C:\ProgramData\TEMP:5A5477A9
AlternateDataStreams: C:\ProgramData\TEMP:5A63CC20
AlternateDataStreams: C:\ProgramData\TEMP:5A9F1AE5
AlternateDataStreams: C:\ProgramData\TEMP:5AE33054
AlternateDataStreams: C:\ProgramData\TEMP:5B111056
AlternateDataStreams: C:\ProgramData\TEMP:5B307FD4
AlternateDataStreams: C:\ProgramData\TEMP:5B483FBC
AlternateDataStreams: C:\ProgramData\TEMP:5BF8F61F
AlternateDataStreams: C:\ProgramData\TEMP:5C28E25F
AlternateDataStreams: C:\ProgramData\TEMP:5C353220
AlternateDataStreams: C:\ProgramData\TEMP:5C3637D2
AlternateDataStreams: C:\ProgramData\TEMP:5C42F64A
AlternateDataStreams: C:\ProgramData\TEMP:5C4A588B
AlternateDataStreams: C:\ProgramData\TEMP:5C5F2761
AlternateDataStreams: C:\ProgramData\TEMP:5C66F780
AlternateDataStreams: C:\ProgramData\TEMP:5C9A6C78
AlternateDataStreams: C:\ProgramData\TEMP:5CB83528
AlternateDataStreams: C:\ProgramData\TEMP:5CBA5665
AlternateDataStreams: C:\ProgramData\TEMP:5CE91C67
AlternateDataStreams: C:\ProgramData\TEMP:5D057E09
AlternateDataStreams: C:\ProgramData\TEMP:5D10517E
AlternateDataStreams: C:\ProgramData\TEMP:5D1BA9DE
AlternateDataStreams: C:\ProgramData\TEMP:5D2D5608
AlternateDataStreams: C:\ProgramData\TEMP:5D34FAF9
AlternateDataStreams: C:\ProgramData\TEMP:5D570144
AlternateDataStreams: C:\ProgramData\TEMP:5DABFF83
AlternateDataStreams: C:\ProgramData\TEMP:5DB36C47
AlternateDataStreams: C:\ProgramData\TEMP:5E21B96B
AlternateDataStreams: C:\ProgramData\TEMP:5E358F67
AlternateDataStreams: C:\ProgramData\TEMP:5E481579
AlternateDataStreams: C:\ProgramData\TEMP:5E4A7758
AlternateDataStreams: C:\ProgramData\TEMP:5E73E1C2
AlternateDataStreams: C:\ProgramData\TEMP:5E8C18F1
AlternateDataStreams: C:\ProgramData\TEMP:5EC48C3A
AlternateDataStreams: C:\ProgramData\TEMP:5ECEFF17
AlternateDataStreams: C:\ProgramData\TEMP:5ED7E575
AlternateDataStreams: C:\ProgramData\TEMP:5EFEB6A1
AlternateDataStreams: C:\ProgramData\TEMP:5F2C9B5E
AlternateDataStreams: C:\ProgramData\TEMP:5F56E7C1
AlternateDataStreams: C:\ProgramData\TEMP:5FC043A8
AlternateDataStreams: C:\ProgramData\TEMP:5FD26EF3
AlternateDataStreams: C:\ProgramData\TEMP:6017A808
AlternateDataStreams: C:\ProgramData\TEMP:607A99D7
AlternateDataStreams: C:\ProgramData\TEMP:60AC3BC3
AlternateDataStreams: C:\ProgramData\TEMP:60D48570
AlternateDataStreams: C:\ProgramData\TEMP:60E0AB2A
AlternateDataStreams: C:\ProgramData\TEMP:611EAF9F
AlternateDataStreams: C:\ProgramData\TEMP:624A80FD
AlternateDataStreams: C:\ProgramData\TEMP:62525FE7
AlternateDataStreams: C:\ProgramData\TEMP:627153F1
AlternateDataStreams: C:\ProgramData\TEMP:6294B369
AlternateDataStreams: C:\ProgramData\TEMP:62AC0CCE
AlternateDataStreams: C:\ProgramData\TEMP:62AF94A0
AlternateDataStreams: C:\ProgramData\TEMP:6301CE40
AlternateDataStreams: C:\ProgramData\TEMP:63A71C6F
AlternateDataStreams: C:\ProgramData\TEMP:63B94956
AlternateDataStreams: C:\ProgramData\TEMP:63C29481
AlternateDataStreams: C:\ProgramData\TEMP:63CFD724
AlternateDataStreams: C:\ProgramData\TEMP:63F8EC77
AlternateDataStreams: C:\ProgramData\TEMP:640DDEFF
AlternateDataStreams: C:\ProgramData\TEMP:64FABDFB
AlternateDataStreams: C:\ProgramData\TEMP:65137F0D
AlternateDataStreams: C:\ProgramData\TEMP:65484F45
AlternateDataStreams: C:\ProgramData\TEMP:65684E14
AlternateDataStreams: C:\ProgramData\TEMP:65929158
AlternateDataStreams: C:\ProgramData\TEMP:65949863
AlternateDataStreams: C:\ProgramData\TEMP:65B8AF94
AlternateDataStreams: C:\ProgramData\TEMP:65C4D44A
AlternateDataStreams: C:\ProgramData\TEMP:6622852D
AlternateDataStreams: C:\ProgramData\TEMP:6622EB04
AlternateDataStreams: C:\ProgramData\TEMP:667565EE
AlternateDataStreams: C:\ProgramData\TEMP:669AB5E1
AlternateDataStreams: C:\ProgramData\TEMP:66C764F5
AlternateDataStreams: C:\ProgramData\TEMP:66F19688
AlternateDataStreams: C:\ProgramData\TEMP:66F7E5A9
AlternateDataStreams: C:\ProgramData\TEMP:67396145
AlternateDataStreams: C:\ProgramData\TEMP:67842DB7
AlternateDataStreams: C:\ProgramData\TEMP:67A91473
AlternateDataStreams: C:\ProgramData\TEMP:67B6E7FA
AlternateDataStreams: C:\ProgramData\TEMP:67CF910D
AlternateDataStreams: C:\ProgramData\TEMP:67E674B0
AlternateDataStreams: C:\ProgramData\TEMP:680F6474
AlternateDataStreams: C:\ProgramData\TEMP:687D1056
AlternateDataStreams: C:\ProgramData\TEMP:689AB7E9
AlternateDataStreams: C:\ProgramData\TEMP:68A41423
AlternateDataStreams: C:\ProgramData\TEMP:68DE552E
AlternateDataStreams: C:\ProgramData\TEMP:697DDE2B
AlternateDataStreams: C:\ProgramData\TEMP:69FE2EE4
AlternateDataStreams: C:\ProgramData\TEMP:6A129BAB
AlternateDataStreams: C:\ProgramData\TEMP:6A9EDD31
AlternateDataStreams: C:\ProgramData\TEMP:6AF6BB0E
AlternateDataStreams: C:\ProgramData\TEMP:6B28173C
AlternateDataStreams: C:\ProgramData\TEMP:6B5A665E
AlternateDataStreams: C:\ProgramData\TEMP:6B7447D4
AlternateDataStreams: C:\ProgramData\TEMP:6B9828AE
AlternateDataStreams: C:\ProgramData\TEMP:6BE79E11
AlternateDataStreams: C:\ProgramData\TEMP:6BEADDC0
AlternateDataStreams: C:\ProgramData\TEMP:6BF0805F
AlternateDataStreams: C:\ProgramData\TEMP:6BFA43EB
AlternateDataStreams: C:\ProgramData\TEMP:6C15BEAD
AlternateDataStreams: C:\ProgramData\TEMP:6C468A51
AlternateDataStreams: C:\ProgramData\TEMP:6C81A062
AlternateDataStreams: C:\ProgramData\TEMP:6CC1CB6D
AlternateDataStreams: C:\ProgramData\TEMP:6CF828C2
AlternateDataStreams: C:\ProgramData\TEMP:6D4F7F2B
AlternateDataStreams: C:\ProgramData\TEMP:6D65CED0
AlternateDataStreams: C:\ProgramData\TEMP:6DCFAD3B
AlternateDataStreams: C:\ProgramData\TEMP:6DD87D86
AlternateDataStreams: C:\ProgramData\TEMP:6DDBB86B
AlternateDataStreams: C:\ProgramData\TEMP:6E2D80C8
AlternateDataStreams: C:\ProgramData\TEMP:6E39144C
AlternateDataStreams: C:\ProgramData\TEMP:6E3C585B
AlternateDataStreams: C:\ProgramData\TEMP:6E65510A
AlternateDataStreams: C:\ProgramData\TEMP:6E6A4F42
AlternateDataStreams: C:\ProgramData\TEMP:6F16D671
AlternateDataStreams: C:\ProgramData\TEMP:6F94300C
AlternateDataStreams: C:\ProgramData\TEMP:700B8E2E
AlternateDataStreams: C:\ProgramData\TEMP:701B92FB
AlternateDataStreams: C:\ProgramData\TEMP:709E81D4
AlternateDataStreams: C:\ProgramData\TEMP:70E897B5
AlternateDataStreams: C:\ProgramData\TEMP:71112705
AlternateDataStreams: C:\ProgramData\TEMP:71A89A93
AlternateDataStreams: C:\ProgramData\TEMP:71AEFFEB
AlternateDataStreams: C:\ProgramData\TEMP:71B89F61
AlternateDataStreams: C:\ProgramData\TEMP:71F04C26
AlternateDataStreams: C:\ProgramData\TEMP:72449E7D
AlternateDataStreams: C:\ProgramData\TEMP:7247FE29
AlternateDataStreams: C:\ProgramData\TEMP:7254CF01
AlternateDataStreams: C:\ProgramData\TEMP:726A7C8D
AlternateDataStreams: C:\ProgramData\TEMP:72C99D4E
AlternateDataStreams: C:\ProgramData\TEMP:737160C1
AlternateDataStreams: C:\ProgramData\TEMP:73AFBB96
AlternateDataStreams: C:\ProgramData\TEMP:73B78E79
AlternateDataStreams: C:\ProgramData\TEMP:742F1EE5
AlternateDataStreams: C:\ProgramData\TEMP:74B502CB
AlternateDataStreams: C:\ProgramData\TEMP:751D6870
AlternateDataStreams: C:\ProgramData\TEMP:754E278B
AlternateDataStreams: C:\ProgramData\TEMP:75765D7B
AlternateDataStreams: C:\ProgramData\TEMP:75798D9A
AlternateDataStreams: C:\ProgramData\TEMP:75CC0165
AlternateDataStreams: C:\ProgramData\TEMP:75E7048E
AlternateDataStreams: C:\ProgramData\TEMP:762408BA
AlternateDataStreams: C:\ProgramData\TEMP:7641F818
AlternateDataStreams: C:\ProgramData\TEMP:76953F21
AlternateDataStreams: C:\ProgramData\TEMP:76DF754D
AlternateDataStreams: C:\ProgramData\TEMP:774A0E14
AlternateDataStreams: C:\ProgramData\TEMP:774C075A
AlternateDataStreams: C:\ProgramData\TEMP:77846FFE
AlternateDataStreams: C:\ProgramData\TEMP:77B64C59
AlternateDataStreams: C:\ProgramData\TEMP:77E239B1
AlternateDataStreams: C:\ProgramData\TEMP:77F49022
AlternateDataStreams: C:\ProgramData\TEMP:792BE0F5
AlternateDataStreams: C:\ProgramData\TEMP:793ABD2B
AlternateDataStreams: C:\ProgramData\TEMP:795F6DEC
AlternateDataStreams: C:\ProgramData\TEMP:79875988
AlternateDataStreams: C:\ProgramData\TEMP:79A7F369
AlternateDataStreams: C:\ProgramData\TEMP:79C6A9CE
AlternateDataStreams: C:\ProgramData\TEMP:79F970BE
AlternateDataStreams: C:\ProgramData\TEMP:7A0A894A
AlternateDataStreams: C:\ProgramData\TEMP:7ADB695A
AlternateDataStreams: C:\ProgramData\TEMP:7AF9CAEB
AlternateDataStreams: C:\ProgramData\TEMP:7B9BB187
AlternateDataStreams: C:\ProgramData\TEMP:7BB584AA
AlternateDataStreams: C:\ProgramData\TEMP:7BB6E2C8
AlternateDataStreams: C:\ProgramData\TEMP:7BD9473D
AlternateDataStreams: C:\ProgramData\TEMP:7BFAAE70
AlternateDataStreams: C:\ProgramData\TEMP:7BFFC6A9
AlternateDataStreams: C:\ProgramData\TEMP:7C27C41C
AlternateDataStreams: C:\ProgramData\TEMP:7C5E403A
AlternateDataStreams: C:\ProgramData\TEMP:7C819E94
AlternateDataStreams: C:\ProgramData\TEMP:7C8AA9A6
AlternateDataStreams: C:\ProgramData\TEMP:7CF8A507
AlternateDataStreams: C:\ProgramData\TEMP:7D04F8E2
AlternateDataStreams: C:\ProgramData\TEMP:7D288858
AlternateDataStreams: C:\ProgramData\TEMP:7D49B96B
AlternateDataStreams: C:\ProgramData\TEMP:7D938C9B
AlternateDataStreams: C:\ProgramData\TEMP:7D9B1030
AlternateDataStreams: C:\ProgramData\TEMP:7DC5D762
AlternateDataStreams: C:\ProgramData\TEMP:7E082023
AlternateDataStreams: C:\ProgramData\TEMP:7E0B06B5
AlternateDataStreams: C:\ProgramData\TEMP:7E1F211D
AlternateDataStreams: C:\ProgramData\TEMP:7E4E56EA
AlternateDataStreams: C:\ProgramData\TEMP:7E802BFF
AlternateDataStreams: C:\ProgramData\TEMP:7EC01D6D
AlternateDataStreams: C:\ProgramData\TEMP:7ECD9621
AlternateDataStreams: C:\ProgramData\TEMP:7EE43C06
AlternateDataStreams: C:\ProgramData\TEMP:7F66BF58
AlternateDataStreams: C:\ProgramData\TEMP:7FCB9D0D
AlternateDataStreams: C:\ProgramData\TEMP:7FD8AECC
AlternateDataStreams: C:\ProgramData\TEMP:80253E8D
AlternateDataStreams: C:\ProgramData\TEMP:8029E75F
AlternateDataStreams: C:\ProgramData\TEMP:8075370B
AlternateDataStreams: C:\ProgramData\TEMP:80974241
AlternateDataStreams: C:\ProgramData\TEMP:80BFDE16
AlternateDataStreams: C:\ProgramData\TEMP:80EA2EA3
AlternateDataStreams: C:\ProgramData\TEMP:81365633
AlternateDataStreams: C:\ProgramData\TEMP:817F0659
AlternateDataStreams: C:\ProgramData\TEMP:8204AA35
AlternateDataStreams: C:\ProgramData\TEMP:823606DE
AlternateDataStreams: C:\ProgramData\TEMP:8247A199
AlternateDataStreams: C:\ProgramData\TEMP:82529191
AlternateDataStreams: C:\ProgramData\TEMP:82EAE27C
AlternateDataStreams: C:\ProgramData\TEMP:8318A814
AlternateDataStreams: C:\ProgramData\TEMP:839A89FC
AlternateDataStreams: C:\ProgramData\TEMP:843D8419
AlternateDataStreams: C:\ProgramData\TEMP:8441E695
AlternateDataStreams: C:\ProgramData\TEMP:8470B630
AlternateDataStreams: C:\ProgramData\TEMP:84C34762
AlternateDataStreams: C:\ProgramData\TEMP:852F2262
AlternateDataStreams: C:\ProgramData\TEMP:85630A39
AlternateDataStreams: C:\ProgramData\TEMP:857692EC
AlternateDataStreams: C:\ProgramData\TEMP:85C3B823
AlternateDataStreams: C:\ProgramData\TEMP:85EA4795
AlternateDataStreams: C:\ProgramData\TEMP:861A898F
AlternateDataStreams: C:\ProgramData\TEMP:8634D9A3
AlternateDataStreams: C:\ProgramData\TEMP:865F21BF
AlternateDataStreams: C:\ProgramData\TEMP:86A8CE8D
AlternateDataStreams: C:\ProgramData\TEMP:86B7FDDB
AlternateDataStreams: C:\ProgramData\TEMP:86E0BFC8
AlternateDataStreams: C:\ProgramData\TEMP:871526BA
AlternateDataStreams: C:\ProgramData\TEMP:87E3D720
AlternateDataStreams: C:\ProgramData\TEMP:8836A712
AlternateDataStreams: C:\ProgramData\TEMP:8855A119
AlternateDataStreams: C:\ProgramData\TEMP:8866C899
AlternateDataStreams: C:\ProgramData\TEMP:8868F8ED
AlternateDataStreams: C:\ProgramData\TEMP:88FB7F72
AlternateDataStreams: C:\ProgramData\TEMP:89123481
AlternateDataStreams: C:\ProgramData\TEMP:891A7A73
AlternateDataStreams: C:\ProgramData\TEMP:895A78C5
AlternateDataStreams: C:\ProgramData\TEMP:8967C154
AlternateDataStreams: C:\ProgramData\TEMP:89C28CF6
AlternateDataStreams: C:\ProgramData\TEMP:89F44603
AlternateDataStreams: C:\ProgramData\TEMP:89FC8EEB
AlternateDataStreams: C:\ProgramData\TEMP:8A290D99
AlternateDataStreams: C:\ProgramData\TEMP:8A620099
AlternateDataStreams: C:\ProgramData\TEMP:8AC20936
AlternateDataStreams: C:\ProgramData\TEMP:8AE92FD3
AlternateDataStreams: C:\ProgramData\TEMP:8AEF2555
AlternateDataStreams: C:\ProgramData\TEMP:8B076EC5
AlternateDataStreams: C:\ProgramData\TEMP:8B3C3098
AlternateDataStreams: C:\ProgramData\TEMP:8B480195
AlternateDataStreams: C:\ProgramData\TEMP:8B4B9596
AlternateDataStreams: C:\ProgramData\TEMP:8B4C1181
AlternateDataStreams: C:\ProgramData\TEMP:8B69E3C3
AlternateDataStreams: C:\ProgramData\TEMP:8B9E766D
AlternateDataStreams: C:\ProgramData\TEMP:8BB2EE92
AlternateDataStreams: C:\ProgramData\TEMP:8BE8BFCD
AlternateDataStreams: C:\ProgramData\TEMP:8C12CFCD
AlternateDataStreams: C:\ProgramData\TEMP:8C443193
AlternateDataStreams: C:\ProgramData\TEMP:8C885EDD
AlternateDataStreams: C:\ProgramData\TEMP:8CE601F5
AlternateDataStreams: C:\ProgramData\TEMP:8CFF4966
AlternateDataStreams: C:\ProgramData\TEMP:8D565A9B
AlternateDataStreams: C:\ProgramData\TEMP:8DD20B4A
AlternateDataStreams: C:\ProgramData\TEMP:8E5EA40F
AlternateDataStreams: C:\ProgramData\TEMP:8E60033F
AlternateDataStreams: C:\ProgramData\TEMP:8EBF0142
AlternateDataStreams: C:\ProgramData\TEMP:8EEE3BBB
AlternateDataStreams: C:\ProgramData\TEMP:8F1B55BE
AlternateDataStreams: C:\ProgramData\TEMP:8F6B75BF
AlternateDataStreams: C:\ProgramData\TEMP:8F7ECF6A
AlternateDataStreams: C:\ProgramData\TEMP:8F925134
AlternateDataStreams: C:\ProgramData\TEMP:8F99ADAD
AlternateDataStreams: C:\ProgramData\TEMP:8FA3210E
AlternateDataStreams: C:\ProgramData\TEMP:8FBE0E9C
AlternateDataStreams: C:\ProgramData\TEMP:8FC027DE
AlternateDataStreams: C:\ProgramData\TEMP:8FF962C6
AlternateDataStreams: C:\ProgramData\TEMP:90108DD7
AlternateDataStreams: C:\ProgramData\TEMP:9026EFD0
AlternateDataStreams: C:\ProgramData\TEMP:902B3C72
AlternateDataStreams: C:\ProgramData\TEMP:902B6A44
AlternateDataStreams: C:\ProgramData\TEMP:902C848D
AlternateDataStreams: C:\ProgramData\TEMP:908A1B53
AlternateDataStreams: C:\ProgramData\TEMP:9124663C
AlternateDataStreams: C:\ProgramData\TEMP:9195103F
AlternateDataStreams: C:\ProgramData\TEMP:91A1C0FC
AlternateDataStreams: C:\ProgramData\TEMP:91CF76E3
AlternateDataStreams: C:\ProgramData\TEMP:91FE43FF
AlternateDataStreams: C:\ProgramData\TEMP:922DA2DB
AlternateDataStreams: C:\ProgramData\TEMP:926B6E7A
AlternateDataStreams: C:\ProgramData\TEMP:927EC486
AlternateDataStreams: C:\ProgramData\TEMP:928DF32E
AlternateDataStreams: C:\ProgramData\TEMP:92BD9737
AlternateDataStreams: C:\ProgramData\TEMP:92D18A5E
AlternateDataStreams: C:\ProgramData\TEMP:92D35C13
AlternateDataStreams: C:\ProgramData\TEMP:938EB9FC
AlternateDataStreams: C:\ProgramData\TEMP:943971F5
AlternateDataStreams: C:\ProgramData\TEMP:94874C0A
AlternateDataStreams: C:\ProgramData\TEMP:9491C9C7
AlternateDataStreams: C:\ProgramData\TEMP:94B25DF5
AlternateDataStreams: C:\ProgramData\TEMP:94B46CA2
AlternateDataStreams: C:\ProgramData\TEMP:95198126
AlternateDataStreams: C:\ProgramData\TEMP:952245B1
AlternateDataStreams: C:\ProgramData\TEMP:9524D821
AlternateDataStreams: C:\ProgramData\TEMP:953FDC1A
AlternateDataStreams: C:\ProgramData\TEMP:956EC010
AlternateDataStreams: C:\ProgramData\TEMP:9597EAFE
AlternateDataStreams: C:\ProgramData\TEMP:95D421DF
AlternateDataStreams: C:\ProgramData\TEMP:961B4D58
AlternateDataStreams: C:\ProgramData\TEMP:961B84C5
AlternateDataStreams: C:\ProgramData\TEMP:96372A73
AlternateDataStreams: C:\ProgramData\TEMP:96646EC1
AlternateDataStreams: C:\ProgramData\TEMP:96838F8A
AlternateDataStreams: C:\ProgramData\TEMP:968F624D
AlternateDataStreams: C:\ProgramData\TEMP:96F8F8AB
AlternateDataStreams: C:\ProgramData\TEMP:971DCCE2
AlternateDataStreams: C:\ProgramData\TEMP:9720EBEF
AlternateDataStreams: C:\ProgramData\TEMP:97AAB7F2
AlternateDataStreams: C:\ProgramData\TEMP:97B3B270
AlternateDataStreams: C:\ProgramData\TEMP:97BDBF49
AlternateDataStreams: C:\ProgramData\TEMP:97CA3B9E
AlternateDataStreams: C:\ProgramData\TEMP:98104906
AlternateDataStreams: C:\ProgramData\TEMP:981456CB
AlternateDataStreams: C:\ProgramData\TEMP:9825B52E
AlternateDataStreams: C:\ProgramData\TEMP:9836B5E4
AlternateDataStreams: C:\ProgramData\TEMP:983B4DC0
AlternateDataStreams: C:\ProgramData\TEMP:98BD93BF
AlternateDataStreams: C:\ProgramData\TEMP:991283D0
AlternateDataStreams: C:\ProgramData\TEMP:993185CB
AlternateDataStreams: C:\ProgramData\TEMP:99B20AD0
AlternateDataStreams: C:\ProgramData\TEMP:9A2A9D24
AlternateDataStreams: C:\ProgramData\TEMP:9AC8424E
AlternateDataStreams: C:\ProgramData\TEMP:9B0F9E15
AlternateDataStreams: C:\ProgramData\TEMP:9B3291FE
AlternateDataStreams: C:\ProgramData\TEMP:9B750A13
AlternateDataStreams: C:\ProgramData\TEMP:9BB8C675
AlternateDataStreams: C:\ProgramData\TEMP:9C012695
AlternateDataStreams: C:\ProgramData\TEMP:9C3AAD57
AlternateDataStreams: C:\ProgramData\TEMP:9C504A4D
AlternateDataStreams: C:\ProgramData\TEMP:9C7A32BB
AlternateDataStreams: C:\ProgramData\TEMP:9CE870B8
AlternateDataStreams: C:\ProgramData\TEMP:9CF728A6
AlternateDataStreams: C:\ProgramData\TEMP:9D06FB9C
AlternateDataStreams: C:\ProgramData\TEMP:9D2DE4B4
AlternateDataStreams: C:\ProgramData\TEMP:9D3C27E1
AlternateDataStreams: C:\ProgramData\TEMP:9D6EAEC3
AlternateDataStreams: C:\ProgramData\TEMP:9D91E651
AlternateDataStreams: C:\ProgramData\TEMP:9E5EA7A3
AlternateDataStreams: C:\ProgramData\TEMP:9EBE2014
AlternateDataStreams: C:\ProgramData\TEMP:9EE6560D
AlternateDataStreams: C:\ProgramData\TEMP:9F50A55A
AlternateDataStreams: C:\ProgramData\TEMP:9F81E94D
AlternateDataStreams: C:\ProgramData\TEMP:9FB6814A
AlternateDataStreams: C:\ProgramData\TEMP:9FCF32A8
AlternateDataStreams: C:\ProgramData\TEMP:9FD757A9
AlternateDataStreams: C:\ProgramData\TEMP:A015B193
AlternateDataStreams: C:\ProgramData\TEMP:A01F3A87
AlternateDataStreams: C:\ProgramData\TEMP:A039EDF9
AlternateDataStreams: C:\ProgramData\TEMP:A0921B2C
AlternateDataStreams: C:\ProgramData\TEMP:A1023D41
AlternateDataStreams: C:\ProgramData\TEMP:A10E88DE
AlternateDataStreams: C:\ProgramData\TEMP:A1460B2A
AlternateDataStreams: C:\ProgramData\TEMP:A1A86E40
AlternateDataStreams: C:\ProgramData\TEMP:A1FD5369
AlternateDataStreams: C:\ProgramData\TEMP:A243178D
AlternateDataStreams: C:\ProgramData\TEMP:A26AFC00
AlternateDataStreams: C:\ProgramData\TEMP:A26C6E72
AlternateDataStreams: C:\ProgramData\TEMP:A291068E
AlternateDataStreams: C:\ProgramData\TEMP:A3840F5B
AlternateDataStreams: C:\ProgramData\TEMP:A391510C
AlternateDataStreams: C:\ProgramData\TEMP:A3B8F70C
AlternateDataStreams: C:\ProgramData\TEMP:A3E0A552
AlternateDataStreams: C:\ProgramData\TEMP:A42B5698
AlternateDataStreams: C:\ProgramData\TEMP:A43B789A
AlternateDataStreams: C:\ProgramData\TEMP:A43EC514
AlternateDataStreams: C:\ProgramData\TEMP:A441D13F
AlternateDataStreams: C:\ProgramData\TEMP:A479BCC9
AlternateDataStreams: C:\ProgramData\TEMP:A4AF8D0D
AlternateDataStreams: C:\ProgramData\TEMP:A4B4192F
AlternateDataStreams: C:\ProgramData\TEMP:A4E7D25F
AlternateDataStreams: C:\ProgramData\TEMP:A5241382
AlternateDataStreams: C:\ProgramData\TEMP:A5256831
AlternateDataStreams: C:\ProgramData\TEMP:A52D07E2
AlternateDataStreams: C:\ProgramData\TEMP:A5584049
AlternateDataStreams: C:\ProgramData\TEMP:A57239FA
AlternateDataStreams: C:\ProgramData\TEMP:A6345BDA
AlternateDataStreams: C:\ProgramData\TEMP:A6346EE9
AlternateDataStreams: C:\ProgramData\TEMP:A69FAA24
AlternateDataStreams: C:\ProgramData\TEMP:A6D6E537
AlternateDataStreams: C:\ProgramData\TEMP:A6D89509
AlternateDataStreams: C:\ProgramData\TEMP:A6F28514
AlternateDataStreams: C:\ProgramData\TEMP:A6F30843
AlternateDataStreams: C:\ProgramData\TEMP:A6FE7BCC
AlternateDataStreams: C:\ProgramData\TEMP:A724744F
AlternateDataStreams: C:\ProgramData\TEMP:A78B31DD
AlternateDataStreams: C:\ProgramData\TEMP:A7CC0E50
AlternateDataStreams: C:\ProgramData\TEMP:A819A132
AlternateDataStreams: C:\ProgramData\TEMP:A81F86C8
AlternateDataStreams: C:\ProgramData\TEMP:A8369371
AlternateDataStreams: C:\ProgramData\TEMP:A851461E
AlternateDataStreams: C:\ProgramData\TEMP:A88BE334
AlternateDataStreams: C:\ProgramData\TEMP:A899E64E
AlternateDataStreams: C:\ProgramData\TEMP:A8A0D7A2
AlternateDataStreams: C:\ProgramData\TEMP:A8ADEA55
AlternateDataStreams: C:\ProgramData\TEMP:A8DFD30C
AlternateDataStreams: C:\ProgramData\TEMP:A900C3A3
AlternateDataStreams: C:\ProgramData\TEMP:A93CBF2B
AlternateDataStreams: C:\ProgramData\TEMP:A967571A
AlternateDataStreams: C:\ProgramData\TEMP:A99C1C81
AlternateDataStreams: C:\ProgramData\TEMP:A9F13D2D
AlternateDataStreams: C:\ProgramData\TEMP:AA0017FD
AlternateDataStreams: C:\ProgramData\TEMP:AA0BC725
AlternateDataStreams: C:\ProgramData\TEMP:AA5A61B2
AlternateDataStreams: C:\ProgramData\TEMP:AA6CA4C7
AlternateDataStreams: C:\ProgramData\TEMP:AA7BE830
AlternateDataStreams: C:\ProgramData\TEMP:AABECEFB
AlternateDataStreams: C:\ProgramData\TEMP:AB3339EF
AlternateDataStreams: C:\ProgramData\TEMP:AB501812
AlternateDataStreams: C:\ProgramData\TEMP:AB554F94
AlternateDataStreams: C:\ProgramData\TEMP:ABBFFEA2
AlternateDataStreams: C:\ProgramData\TEMP:AC57032B
AlternateDataStreams: C:\ProgramData\TEMP:ACB38255
AlternateDataStreams: C:\ProgramData\TEMP:AD020DC3
AlternateDataStreams: C:\ProgramData\TEMP:AD179392
AlternateDataStreams: C:\ProgramData\TEMP:ADEBE9CA
AlternateDataStreams: C:\ProgramData\TEMP:AE0B4487
AlternateDataStreams: C:\ProgramData\TEMP:AE324BE5
AlternateDataStreams: C:\ProgramData\TEMP:AE34D87E
AlternateDataStreams: C:\ProgramData\TEMP:AE47FDED
AlternateDataStreams: C:\ProgramData\TEMP:AE8D8202
AlternateDataStreams: C:\ProgramData\TEMP:AE9351E0
AlternateDataStreams: C:\ProgramData\TEMP:AEA33452
AlternateDataStreams: C:\ProgramData\TEMP:AEBC40EC
AlternateDataStreams: C:\ProgramData\TEMP:AECF4772
AlternateDataStreams: C:\ProgramData\TEMP:AED4A2B7
AlternateDataStreams: C:\ProgramData\TEMP:AF191C57
AlternateDataStreams: C:\ProgramData\TEMP:AF2F9D4A
AlternateDataStreams: C:\ProgramData\TEMP:AFB89C92
AlternateDataStreams: C:\ProgramData\TEMP:AFFA972E
AlternateDataStreams: C:\ProgramData\TEMP:B02249C3
AlternateDataStreams: C:\ProgramData\TEMP:B0456F0C
AlternateDataStreams: C:\ProgramData\TEMP:B0729CDB
AlternateDataStreams: C:\ProgramData\TEMP:B097AC8A
AlternateDataStreams: C:\ProgramData\TEMP:B0EA26E5
AlternateDataStreams: C:\ProgramData\TEMP:B1381B34
AlternateDataStreams: C:\ProgramData\TEMP:B190BE3A
AlternateDataStreams: C:\ProgramData\TEMP:B1E64E47
AlternateDataStreams: C:\ProgramData\TEMP:B2112128
AlternateDataStreams: C:\ProgramData\TEMP:B21F2857
AlternateDataStreams: C:\ProgramData\TEMP:B2D32F1D
AlternateDataStreams: C:\ProgramData\TEMP:B2DC8D6B
AlternateDataStreams: C:\ProgramData\TEMP:B310C233
AlternateDataStreams: C:\ProgramData\TEMP:B317D7ED
AlternateDataStreams: C:\ProgramData\TEMP:B3196E8D
AlternateDataStreams: C:\ProgramData\TEMP:B33464A5
AlternateDataStreams: C:\ProgramData\TEMP:B38BEEEE
AlternateDataStreams: C:\ProgramData\TEMP:B3A5945E
AlternateDataStreams: C:\ProgramData\TEMP:B3A7E7F8
AlternateDataStreams: C:\ProgramData\TEMP:B3C7433B
AlternateDataStreams: C:\ProgramData\TEMP:B47A7270
AlternateDataStreams: C:\ProgramData\TEMP:B4980368
AlternateDataStreams: C:\ProgramData\TEMP:B4F0E275
AlternateDataStreams: C:\ProgramData\TEMP:B4F7687B
AlternateDataStreams: C:\ProgramData\TEMP:B51B45A3
AlternateDataStreams: C:\ProgramData\TEMP:B5FD4AA1
AlternateDataStreams: C:\ProgramData\TEMP:B652B720
AlternateDataStreams: C:\ProgramData\TEMP:B6E58523
AlternateDataStreams: C:\ProgramData\TEMP:B723C5EF
AlternateDataStreams: C:\ProgramData\TEMP:B790962B
AlternateDataStreams: C:\ProgramData\TEMP:B80659FA
AlternateDataStreams: C:\ProgramData\TEMP:B8EA2C49
AlternateDataStreams: C:\ProgramData\TEMP:B8EB1B99
AlternateDataStreams: C:\ProgramData\TEMP:B9775780
AlternateDataStreams: C:\ProgramData\TEMP:BACC4A79
AlternateDataStreams: C:\ProgramData\TEMP:BAFAD1DF
AlternateDataStreams: C:\ProgramData\TEMP:BB718C46
AlternateDataStreams: C:\ProgramData\TEMP:BB99F46B
AlternateDataStreams: C:\ProgramData\TEMP:BC521608
AlternateDataStreams: C:\ProgramData\TEMP:BC593DD5
AlternateDataStreams: C:\ProgramData\TEMP:BCAB37A9
AlternateDataStreams: C:\ProgramData\TEMP:BCF55336
AlternateDataStreams: C:\ProgramData\TEMP:BD34FFC5
AlternateDataStreams: C:\ProgramData\TEMP:BDDA21B6
AlternateDataStreams: C:\ProgramData\TEMP:BE0654D6
AlternateDataStreams: C:\ProgramData\TEMP:BE3D639A
AlternateDataStreams: C:\ProgramData\TEMP:BE40B295
AlternateDataStreams: C:\ProgramData\TEMP:BE64143E
AlternateDataStreams: C:\ProgramData\TEMP:BE6B5FC3
AlternateDataStreams: C:\ProgramData\TEMP:BE6DC701
AlternateDataStreams: C:\ProgramData\TEMP:BEACE4C8
AlternateDataStreams: C:\ProgramData\TEMP:BEF18713
AlternateDataStreams: C:\ProgramData\TEMP:BF1E0621
AlternateDataStreams: C:\ProgramData\TEMP:BF4BA1F5
AlternateDataStreams: C:\ProgramData\TEMP:BF640EE5
AlternateDataStreams: C:\ProgramData\TEMP:BF6A2C54
AlternateDataStreams: C:\ProgramData\TEMP:BF6C4AAC
AlternateDataStreams: C:\ProgramData\TEMP:BF6C81B2
AlternateDataStreams: C:\ProgramData\TEMP:C0893153
AlternateDataStreams: C:\ProgramData\TEMP:C0913157
AlternateDataStreams: C:\ProgramData\TEMP:C0A9B815
AlternateDataStreams: C:\ProgramData\TEMP:C0D23A2F
AlternateDataStreams: C:\ProgramData\TEMP:C178954A
AlternateDataStreams: C:\ProgramData\TEMP:C18032C3
AlternateDataStreams: C:\ProgramData\TEMP:C1C3561E
AlternateDataStreams: C:\ProgramData\TEMP:C1D3D9A3
AlternateDataStreams: C:\ProgramData\TEMP:C1DBE635
AlternateDataStreams: C:\ProgramData\TEMP:C22B6EED
AlternateDataStreams: C:\ProgramData\TEMP:C26A6AB3
AlternateDataStreams: C:\ProgramData\TEMP:C2F24DB5
AlternateDataStreams: C:\ProgramData\TEMP:C2F43053
AlternateDataStreams: C:\ProgramData\TEMP:C30487EE
AlternateDataStreams: C:\ProgramData\TEMP:C356A185
AlternateDataStreams: C:\ProgramData\TEMP:C368C9EA
AlternateDataStreams: C:\ProgramData\TEMP:C36D0DFD
AlternateDataStreams: C:\ProgramData\TEMP:C37283B5
AlternateDataStreams: C:\ProgramData\TEMP:C3A047E3
AlternateDataStreams: C:\ProgramData\TEMP:C3AD9507
AlternateDataStreams: C:\ProgramData\TEMP:C3B04546
AlternateDataStreams: C:\ProgramData\TEMP:C3E7F2E9
AlternateDataStreams: C:\ProgramData\TEMP:C44E62F1
AlternateDataStreams: C:\ProgramData\TEMP:C48905F4
AlternateDataStreams: C:\ProgramData\TEMP:C4967F48
AlternateDataStreams: C:\ProgramData\TEMP:C4A88D6B
AlternateDataStreams: C:\ProgramData\TEMP:C5340FA1
AlternateDataStreams: C:\ProgramData\TEMP:C54A1A57
AlternateDataStreams: C:\ProgramData\TEMP:C5A156B6
AlternateDataStreams: C:\ProgramData\TEMP:C5D15631
AlternateDataStreams: C:\ProgramData\TEMP:C5DC2B0C
AlternateDataStreams: C:\ProgramData\TEMP:C66222F3
AlternateDataStreams: C:\ProgramData\TEMP:C67CB31A
AlternateDataStreams: C:\ProgramData\TEMP:C6920A5D
AlternateDataStreams: C:\ProgramData\TEMP:C7517D0A
AlternateDataStreams: C:\ProgramData\TEMP:C76CFF82
AlternateDataStreams: C:\ProgramData\TEMP:C7D35E8C
AlternateDataStreams: C:\ProgramData\TEMP:C7F08EA3
AlternateDataStreams: C:\ProgramData\TEMP:C82210DD
AlternateDataStreams: C:\ProgramData\TEMP:C82CA1C0
AlternateDataStreams: C:\ProgramData\TEMP:C8E3A625
AlternateDataStreams: C:\ProgramData\TEMP:C8E9D804
AlternateDataStreams: C:\ProgramData\TEMP:C98828D3
AlternateDataStreams: C:\ProgramData\TEMP:C9B27A06
AlternateDataStreams: C:\ProgramData\TEMP:CA1AFE85
AlternateDataStreams: C:\ProgramData\TEMP:CA23BCFD
AlternateDataStreams: C:\ProgramData\TEMP:CA400C1B
AlternateDataStreams: C:\ProgramData\TEMP:CAE3AE67
AlternateDataStreams: C:\ProgramData\TEMP:CB08ED9D
AlternateDataStreams: C:\ProgramData\TEMP:CB299F13
AlternateDataStreams: C:\ProgramData\TEMP:CB3667AF
AlternateDataStreams: C:\ProgramData\TEMP:CB5AA1E6
AlternateDataStreams: C:\ProgramData\TEMP:CB959782
AlternateDataStreams: C:\ProgramData\TEMP:CBAF0C30
AlternateDataStreams: C:\ProgramData\TEMP:CC141B05
AlternateDataStreams: C:\ProgramData\TEMP:CCD8056E
AlternateDataStreams: C:\ProgramData\TEMP:CDCDE97C
AlternateDataStreams: C:\ProgramData\TEMP:CE3AADB7
AlternateDataStreams: C:\ProgramData\TEMP:CE506F23
AlternateDataStreams: C:\ProgramData\TEMP:CE8A42A3
AlternateDataStreams: C:\ProgramData\TEMP:CEF2A14E
AlternateDataStreams: C:\ProgramData\TEMP:CF2C26D2
AlternateDataStreams: C:\ProgramData\TEMP:CF5ECDE7
AlternateDataStreams: C:\ProgramData\TEMP:CFA8C6E3
AlternateDataStreams: C:\ProgramData\TEMP:D0005E5A
AlternateDataStreams: C:\ProgramData\TEMP:D0149AB4
AlternateDataStreams: C:\ProgramData\TEMP:D01ACC06
AlternateDataStreams: C:\ProgramData\TEMP:D026A5A4
AlternateDataStreams: C:\ProgramData\TEMP:D03C22B4
AlternateDataStreams: C:\ProgramData\TEMP:D0570058
AlternateDataStreams: C:\ProgramData\TEMP:D05E7A8B
AlternateDataStreams: C:\ProgramData\TEMP:D086B88D
AlternateDataStreams: C:\ProgramData\TEMP:D103E81E
AlternateDataStreams: C:\ProgramData\TEMP:D115F6E4
AlternateDataStreams: C:\ProgramData\TEMP:D1361E51
AlternateDataStreams: C:\ProgramData\TEMP:D1787194
AlternateDataStreams: C:\ProgramData\TEMP:D1D597D0
AlternateDataStreams: C:\ProgramData\TEMP:D1D63BCA
AlternateDataStreams: C:\ProgramData\TEMP:D2593961
AlternateDataStreams: C:\ProgramData\TEMP:D26B6B0A
AlternateDataStreams: C:\ProgramData\TEMP:D2C44806
AlternateDataStreams: C:\ProgramData\TEMP:D3331ADB
AlternateDataStreams: C:\ProgramData\TEMP:D3930F74
AlternateDataStreams: C:\ProgramData\TEMP:D3A82449
AlternateDataStreams: C:\ProgramData\TEMP:D434342F
AlternateDataStreams: C:\ProgramData\TEMP:D43ACD11
AlternateDataStreams: C:\ProgramData\TEMP:D4558A0B
AlternateDataStreams: C:\ProgramData\TEMP:D47B19A6
AlternateDataStreams: C:\ProgramData\TEMP:D48500F8
AlternateDataStreams: C:\ProgramData\TEMP:D576A536
AlternateDataStreams: C:\ProgramData\TEMP:D5CCCBAA
AlternateDataStreams: C:\ProgramData\TEMP:D5D75FF0
AlternateDataStreams: C:\ProgramData\TEMP:D61EB62D
AlternateDataStreams: C:\ProgramData\TEMP:D621CFB8
AlternateDataStreams: C:\ProgramData\TEMP:D64467B5
AlternateDataStreams: C:\ProgramData\TEMP:D64DD961
AlternateDataStreams: C:\ProgramData\TEMP:D72D7897
AlternateDataStreams: C:\ProgramData\TEMP:D74C2847
AlternateDataStreams: C:\ProgramData\TEMP:D750EF68
AlternateDataStreams: C:\ProgramData\TEMP:D770A15D
AlternateDataStreams: C:\ProgramData\TEMP:D7740E2A
AlternateDataStreams: C:\ProgramData\TEMP:D7B7645F
AlternateDataStreams: C:\ProgramData\TEMP:D7C0213D
AlternateDataStreams: C:\ProgramData\TEMP:D7D0B4AF
AlternateDataStreams: C:\ProgramData\TEMP:D7DA89B1
AlternateDataStreams: C:\ProgramData\TEMP:D7F8D8A2
AlternateDataStreams: C:\ProgramData\TEMP:D82A9FCF
AlternateDataStreams: C:\ProgramData\TEMP:D8AE9DD1
AlternateDataStreams: C:\ProgramData\TEMP:D8EA2847
AlternateDataStreams: C:\ProgramData\TEMP:D9089E64
AlternateDataStreams: C:\ProgramData\TEMP:D92485C9
AlternateDataStreams: C:\ProgramData\TEMP:D9592966
AlternateDataStreams: C:\ProgramData\TEMP:D9656460
AlternateDataStreams: C:\ProgramData\TEMP:D9771F40
AlternateDataStreams: C:\ProgramData\TEMP:D987CB43
AlternateDataStreams: C:\ProgramData\TEMP:D9F34335
AlternateDataStreams: C:\ProgramData\TEMP:DA3C6C07
AlternateDataStreams: C:\ProgramData\TEMP:DA55B48C
AlternateDataStreams: C:\ProgramData\TEMP:DA7655EA
AlternateDataStreams: C:\ProgramData\TEMP:DA9A88B3
AlternateDataStreams: C:\ProgramData\TEMP:DAB09BDB
AlternateDataStreams: C:\ProgramData\TEMP:DB2748F7
AlternateDataStreams: C:\ProgramData\TEMP:DB76C881
AlternateDataStreams: C:\ProgramData\TEMP:DBB979D4
AlternateDataStreams: C:\ProgramData\TEMP:DBEF355E
AlternateDataStreams: C:\ProgramData\TEMP:DC0B1070
AlternateDataStreams: C:\ProgramData\TEMP:DC7EDF41
AlternateDataStreams: C:\ProgramData\TEMP:DCA79AB3
AlternateDataStreams: C:\ProgramData\TEMP:DCB27118
AlternateDataStreams: C:\ProgramData\TEMP:DCDE7C60
AlternateDataStreams: C:\ProgramData\TEMP:DD874E14
AlternateDataStreams: C:\ProgramData\TEMP:DD95E6D9
AlternateDataStreams: C:\ProgramData\TEMP:DDF112BD
AlternateDataStreams: C:\ProgramData\TEMP:DE3ABE3D
AlternateDataStreams: C:\ProgramData\TEMP:DE875C30
AlternateDataStreams: C:\ProgramData\TEMP:DEDAEF90
AlternateDataStreams: C:\ProgramData\TEMP:DF0DB8AB
AlternateDataStreams: C:\ProgramData\TEMP:DFB61534
AlternateDataStreams: C:\ProgramData\TEMP:DFFB9E98
AlternateDataStreams: C:\ProgramData\TEMP:E00A6A60
AlternateDataStreams: C:\ProgramData\TEMP:E0365B26
AlternateDataStreams: C:\ProgramData\TEMP:E06963C0
AlternateDataStreams: C:\ProgramData\TEMP:E0848D16
AlternateDataStreams: C:\ProgramData\TEMP:E0888117
AlternateDataStreams: C:\ProgramData\TEMP:E10DCAF3
AlternateDataStreams: C:\ProgramData\TEMP:E11D90D0
AlternateDataStreams: C:\ProgramData\TEMP:E14FA16F
AlternateDataStreams: C:\ProgramData\TEMP:E153075C
AlternateDataStreams: C:\ProgramData\TEMP:E1D06077
AlternateDataStreams: C:\ProgramData\TEMP:E21433CE
AlternateDataStreams: C:\ProgramData\TEMP:E23BF4AD
AlternateDataStreams: C:\ProgramData\TEMP:E2C51D18
AlternateDataStreams: C:\ProgramData\TEMP:E2CFA9CD
AlternateDataStreams: C:\ProgramData\TEMP:E329D971
AlternateDataStreams: C:\ProgramData\TEMP:E32D2701
AlternateDataStreams: C:\ProgramData\TEMP:E33D6212
AlternateDataStreams: C:\ProgramData\TEMP:E411AA0D
AlternateDataStreams: C:\ProgramData\TEMP:E4272706
AlternateDataStreams: C:\ProgramData\TEMP:E446CB48
AlternateDataStreams: C:\ProgramData\TEMP:E463CA56
AlternateDataStreams: C:\ProgramData\TEMP:E495057A
AlternateDataStreams: C:\ProgramData\TEMP:E4BC4A41
AlternateDataStreams: C:\ProgramData\TEMP:E4E83517
AlternateDataStreams: C:\ProgramData\TEMP:E4FD113F
AlternateDataStreams: C:\ProgramData\TEMP:E517FE76
AlternateDataStreams: C:\ProgramData\TEMP:E5438999
AlternateDataStreams: C:\ProgramData\TEMP:E5B07840
AlternateDataStreams: C:\ProgramData\TEMP:E60C72DB
AlternateDataStreams: C:\ProgramData\TEMP:E6433F27
AlternateDataStreams: C:\ProgramData\TEMP:E6708F08
AlternateDataStreams: C:\ProgramData\TEMP:E690114B
AlternateDataStreams: C:\ProgramData\TEMP:E6B95E40
AlternateDataStreams: C:\ProgramData\TEMP:E6BEADB7
AlternateDataStreams: C:\ProgramData\TEMP:E6C6EB3B
AlternateDataStreams: C:\ProgramData\TEMP:E6CDFB4A
AlternateDataStreams: C:\ProgramData\TEMP:E70FD81B
AlternateDataStreams: C:\ProgramData\TEMP:E8074E20
AlternateDataStreams: C:\ProgramData\TEMP:E81603BC
AlternateDataStreams: C:\ProgramData\TEMP:E83EE313
AlternateDataStreams: C:\ProgramData\TEMP:E87AB4E3
AlternateDataStreams: C:\ProgramData\TEMP:E894A3ED
AlternateDataStreams: C:\ProgramData\TEMP:E89EDC52
AlternateDataStreams: C:\ProgramData\TEMP:E8AEB2BF
AlternateDataStreams: C:\ProgramData\TEMP:E8B61305
AlternateDataStreams: C:\ProgramData\TEMP:E8BE0B80
AlternateDataStreams: C:\ProgramData\TEMP:E8C44CB4
AlternateDataStreams: C:\ProgramData\TEMP:E8C4808B
AlternateDataStreams: C:\ProgramData\TEMP:E900132A
AlternateDataStreams: C:\ProgramData\TEMP:E94FA418
AlternateDataStreams: C:\ProgramData\TEMP:E96A2658
AlternateDataStreams: C:\ProgramData\TEMP:E98C5DD9
AlternateDataStreams: C:\ProgramData\TEMP:E99D1D3C
AlternateDataStreams: C:\ProgramData\TEMP:E9CB5ECC
AlternateDataStreams: C:\ProgramData\TEMP:EA10407C
AlternateDataStreams: C:\ProgramData\TEMP:EA2D3047
AlternateDataStreams: C:\ProgramData\TEMP:EA500268
AlternateDataStreams: C:\ProgramData\TEMP:EA7D76BE
AlternateDataStreams: C:\ProgramData\TEMP:EA9D8B40
AlternateDataStreams: C:\ProgramData\TEMP:EB603FE4
AlternateDataStreams: C:\ProgramData\TEMP:EBF0842B
AlternateDataStreams: C:\ProgramData\TEMP:EC752217
AlternateDataStreams: C:\ProgramData\TEMP:ECF3C50F
AlternateDataStreams: C:\ProgramData\TEMP:ED2D63E4
AlternateDataStreams: C:\ProgramData\TEMP:ED51D3ED
AlternateDataStreams: C:\ProgramData\TEMP:ED6B6C83
AlternateDataStreams: C:\ProgramData\TEMP:ED92736E
AlternateDataStreams: C:\ProgramData\TEMP:EDB03249
AlternateDataStreams: C:\ProgramData\TEMP:EDED3240
AlternateDataStreams: C:\ProgramData\TEMP:EDF12A30
AlternateDataStreams: C:\ProgramData\TEMP:EE2B5DE3
AlternateDataStreams: C:\ProgramData\TEMP:EE2DD6CC
AlternateDataStreams: C:\ProgramData\TEMP:EE7AAC75
AlternateDataStreams: C:\ProgramData\TEMP:EE9B2879
AlternateDataStreams: C:\ProgramData\TEMP:EEB25EAE
AlternateDataStreams: C:\ProgramData\TEMP:EEC56B69
AlternateDataStreams: C:\ProgramData\TEMP:EEF1584F
AlternateDataStreams: C:\ProgramData\TEMP:EF0C5444
AlternateDataStreams: C:\ProgramData\TEMP:EF0F3F33
AlternateDataStreams: C:\ProgramData\TEMP:EF38B79C
AlternateDataStreams: C:\ProgramData\TEMP:EF4B1DA9
AlternateDataStreams: C:\ProgramData\TEMP:EFE4FB84
AlternateDataStreams: C:\ProgramData\TEMP:EFECABA9
AlternateDataStreams: C:\ProgramData\TEMP:EFF3C3C8
AlternateDataStreams: C:\ProgramData\TEMP:F0E908D5
AlternateDataStreams: C:\ProgramData\TEMP:F1381B87
AlternateDataStreams: C:\ProgramData\TEMP:F142DBA9
AlternateDataStreams: C:\ProgramData\TEMP:F193BFCF
AlternateDataStreams: C:\ProgramData\TEMP:F1F936DF
AlternateDataStreams: C:\ProgramData\TEMP:F2327E82
AlternateDataStreams: C:\ProgramData\TEMP:F27A649C
AlternateDataStreams: C:\ProgramData\TEMP:F2B81C2E
AlternateDataStreams: C:\ProgramData\TEMP:F2E92DCD
AlternateDataStreams: C:\ProgramData\TEMP:F2EDC57C
AlternateDataStreams: C:\ProgramData\TEMP:F2F115B4
AlternateDataStreams: C:\ProgramData\TEMP:F30757AC
AlternateDataStreams: C:\ProgramData\TEMP:F33C37D5
AlternateDataStreams: C:\ProgramData\TEMP:F3591DDB
AlternateDataStreams: C:\ProgramData\TEMP:F3A185AE
AlternateDataStreams: C:\ProgramData\TEMP:F3A27FDE
AlternateDataStreams: C:\ProgramData\TEMP:F3F9AB21
AlternateDataStreams: C:\ProgramData\TEMP:F41F8101
AlternateDataStreams: C:\ProgramData\TEMP:F4362715
AlternateDataStreams: C:\ProgramData\TEMP:F52DB269
AlternateDataStreams: C:\ProgramData\TEMP:F53B274A
AlternateDataStreams: C:\ProgramData\TEMP:F5B51004
AlternateDataStreams: C:\ProgramData\TEMP:F5E90ED3
AlternateDataStreams: C:\ProgramData\TEMP:F5FC5DCE
AlternateDataStreams: C:\ProgramData\TEMP:F610C203
AlternateDataStreams: C:\ProgramData\TEMP:F65A2273
AlternateDataStreams: C:\ProgramData\TEMP:F663BB74
AlternateDataStreams: C:\ProgramData\TEMP:F67947AF
AlternateDataStreams: C:\ProgramData\TEMP:F6910DB1
AlternateDataStreams: C:\ProgramData\TEMP:F6A0889A
AlternateDataStreams: C:\ProgramData\TEMP:F6DA3F39
AlternateDataStreams: C:\ProgramData\TEMP:F6E5C7FB
AlternateDataStreams: C:\ProgramData\TEMP:F7BF538D
AlternateDataStreams: C:\ProgramData\TEMP:F7F4DC88
AlternateDataStreams: C:\ProgramData\TEMP:F888E36D
AlternateDataStreams: C:\ProgramData\TEMP:F8A53745
AlternateDataStreams: C:\ProgramData\TEMP:F8C2E3B9
AlternateDataStreams: C:\ProgramData\TEMP:F8DE80DB
AlternateDataStreams: C:\ProgramData\TEMP:F8F070C2
AlternateDataStreams: C:\ProgramData\TEMP:F94DE3B1
AlternateDataStreams: C:\ProgramData\TEMP:FA09FC72
AlternateDataStreams: C:\ProgramData\TEMP:FA42DF8E
AlternateDataStreams: C:\ProgramData\TEMP:FA7EAF8F
AlternateDataStreams: C:\ProgramData\TEMP:FAB64002
AlternateDataStreams: C:\ProgramData\TEMP:FB08C210
AlternateDataStreams: C:\ProgramData\TEMP:FB384C06
AlternateDataStreams: C:\ProgramData\TEMP:FB65A4AA
AlternateDataStreams: C:\ProgramData\TEMP:FB71A279
AlternateDataStreams: C:\ProgramData\TEMP:FB9F749F
AlternateDataStreams: C:\ProgramData\TEMP:FBA79096
AlternateDataStreams: C:\ProgramData\TEMP:FC4B020F
AlternateDataStreams: C:\ProgramData\TEMP:FC60E0F8
AlternateDataStreams: C:\ProgramData\TEMP:FC8FFA4E
AlternateDataStreams: C:\ProgramData\TEMP:FCBEDCFD
AlternateDataStreams: C:\ProgramData\TEMP:FCE69FCE
AlternateDataStreams: C:\ProgramData\TEMP:FD32FD25
AlternateDataStreams: C:\ProgramData\TEMP:FD444D31
AlternateDataStreams: C:\ProgramData\TEMP:FD646198
AlternateDataStreams: C:\ProgramData\TEMP:FD6DB82C
AlternateDataStreams: C:\ProgramData\TEMP:FD786DCA
AlternateDataStreams: C:\ProgramData\TEMP:FD7DCDA6
AlternateDataStreams: C:\ProgramData\TEMP:FE4E15B1
AlternateDataStreams: C:\ProgramData\TEMP:FEE00EB9
AlternateDataStreams: C:\ProgramData\TEMP:FEF0DEE7
AlternateDataStreams: C:\ProgramData\TEMP:FF818E2B
AlternateDataStreams: C:\ProgramData\TEMP:FF8F1AE3
AlternateDataStreams: C:\ProgramData\TEMP:FF9C44FE
AlternateDataStreams: C:\ProgramData\TEMP:FFD58FFB
CHR HKCU\SOFTWARE\Policies\Google: Policy restriction <======= ATTENTION
CHR HKLM-x32\...\Chrome\Extension: [jhbbmmgbnjalccamlaefhepnajfmgopb] - C:\Users\Chrissy\AppData\Local\CRE\jhbbmmgbnjalccamlaefhepnajfmgopb.crx [2014-01-09]
CHR HKCU\...\Chrome\Extension: [jhbbmmgbnjalccamlaefhepnajfmgopb] - C:\Users\Chrissy\AppData\Local\CRE\jhbbmmgbnjalccamlaefhepnajfmgopb.crx [2014-01-09]
CHR StartupUrls: Default -> "hxxp://www.google.com", "hxxp://search.conduit.com/?ctid=CT3315828&SearchSource=48&CUI=UN15338799328857141&UM=2", "hxxp://astromenda.com/?f=7&a=ast_dnldstr_14_42_ch&cd=2XzuyEtN2Y1L1QzutDtDtBtCyBtDyCtDyB0D0C0A0EyCtAzztN0D0Tzu0StCtDtCzytN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAyCyBzzyBzy0FyCtGyCyD0EtBtG0DtBtB0DtGyE0C0C0DtGyEzztC0E0ByBtC0B0ByB0C0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCyE0AyEyE0F0CzztG0ByEtAyEtGyEzztByBtGzzzy0FyEtGzz0CtB0EyB0B0F0C0Bzyzzzy2Q&cr=2037860578&ir="
SearchScopes: HKCU - {7F1288EA-E0DE-4E28-AA5A-6E58FDCD67CE} URL = http://astromenda.com/results.php?f=4&q={searchTerms}&a=ast_dnldstr_14_42_ch&cd=2XzuyEtN2Y1L1QzutDtDtBtCyBtDyCtDyB0D0C0A0EyCtAzztN0D0Tzu0StCtDtCzytN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAyCyBzzyBzy0FyCtGyCyD0EtBtG0DtBtB0DtGyE0C0C0DtGyEzztC0E0ByBtC0B0ByB0C0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCyE0AyEyE0F0CzztG0ByEtAyEtGyEzztByBtGzzzy0FyEtGzz0CtB0EyB0B0F0C0Bzyzzzy2Q&cr=2037860578&ir=
SearchScopes: HKCU - {444B13D6-001A-4710-8DF6-8B105BC6C33D} URL = http://search.conduit.com/ResultsExt.aspx?q={searchTerms}&SearchSource=4&ctid=CT3315828&CUI=UN87734836013451164&UM=2
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main,Start Page = http://search.coupons.com/

EmptyTemp:

*****************

C:\ProgramData\TEMP => ":008FE370" ADS removed successfully.
C:\ProgramData\TEMP => ":00D99749" ADS removed successfully.
C:\ProgramData\TEMP => ":0102CF0C" ADS removed successfully.
C:\ProgramData\TEMP => ":014BC3B4" ADS removed successfully.
C:\ProgramData\TEMP => ":0168CC60" ADS removed successfully.
C:\ProgramData\TEMP => ":017D5143" ADS removed successfully.
C:\ProgramData\TEMP => ":01F9D1B4" ADS removed successfully.
C:\ProgramData\TEMP => ":021496FB" ADS removed successfully.
C:\ProgramData\TEMP => ":025C72E5" ADS removed successfully.
C:\ProgramData\TEMP => ":02A78DF6" ADS removed successfully.
C:\ProgramData\TEMP => ":02CC0035" ADS removed successfully.
C:\ProgramData\TEMP => ":02F30776" ADS removed successfully.
C:\ProgramData\TEMP => ":036AA5DD" ADS removed successfully.
C:\ProgramData\TEMP => ":03D08225" ADS removed successfully.
C:\ProgramData\TEMP => ":0410A323" ADS removed successfully.
C:\ProgramData\TEMP => ":041C0562" ADS removed successfully.
C:\ProgramData\TEMP => ":041ED421" ADS removed successfully.
C:\ProgramData\TEMP => ":0474F714" ADS removed successfully.
C:\ProgramData\TEMP => ":04EAB86F" ADS removed successfully.
C:\ProgramData\TEMP => ":04FB3774" ADS removed successfully.
C:\ProgramData\TEMP => ":05113FB9" ADS removed successfully.
C:\ProgramData\TEMP => ":052A05A1" ADS removed successfully.
C:\ProgramData\TEMP => ":05F547A9" ADS removed successfully.
C:\ProgramData\TEMP => ":0696EC8E" ADS removed successfully.
C:\ProgramData\TEMP => ":069BAEA8" ADS removed successfully.
C:\ProgramData\TEMP => ":073139EC" ADS removed successfully.
C:\ProgramData\TEMP => ":07437A8C" ADS removed successfully.
C:\ProgramData\TEMP => ":0785072C" ADS removed successfully.
C:\ProgramData\TEMP => ":078B239B" ADS removed successfully.
C:\ProgramData\TEMP => ":07A75CBF" ADS removed successfully.
C:\ProgramData\TEMP => ":07C99568" ADS removed successfully.
C:\ProgramData\TEMP => ":083C8737" ADS removed successfully.
C:\ProgramData\TEMP => ":087CB364" ADS removed successfully.
C:\ProgramData\TEMP => ":08DB8D99" ADS removed successfully.
C:\ProgramData\TEMP => ":08E5EE32" ADS removed successfully.
C:\ProgramData\TEMP => ":0951C4CC" ADS removed successfully.
C:\ProgramData\TEMP => ":0968E571" ADS removed successfully.
C:\ProgramData\TEMP => ":097C4B7D" ADS removed successfully.
C:\ProgramData\TEMP => ":097FF903" ADS removed successfully.
C:\ProgramData\TEMP => ":0A701F26" ADS removed successfully.
C:\ProgramData\TEMP => ":0AC0213C" ADS removed successfully.
C:\ProgramData\TEMP => ":0ACF1AF5" ADS removed successfully.
C:\ProgramData\TEMP => ":0ADCCF52" ADS removed successfully.
C:\ProgramData\TEMP => ":0AE6CC6C" ADS removed successfully.
C:\ProgramData\TEMP => ":0AF3BFB9" ADS removed successfully.
C:\ProgramData\TEMP => ":0AF3C3DF" ADS removed successfully.
C:\ProgramData\TEMP => ":0B3F95D0" ADS removed successfully.
C:\ProgramData\TEMP => ":0B55751B" ADS removed successfully.
C:\ProgramData\TEMP => ":0B79AB8D" ADS removed successfully.
C:\ProgramData\TEMP => ":0BCD47A5" ADS removed successfully.
C:\ProgramData\TEMP => ":0C9E06A2" ADS removed successfully.
C:\ProgramData\TEMP => ":0CDBB2C2" ADS removed successfully.
C:\ProgramData\TEMP => ":0CDF8C3D" ADS removed successfully.
C:\ProgramData\TEMP => ":0D761AB3" ADS removed successfully.
C:\ProgramData\TEMP => ":0D797314" ADS removed successfully.
C:\ProgramData\TEMP => ":0DE96CF5" ADS removed successfully.
C:\ProgramData\TEMP => ":0E10B960" ADS removed successfully.
C:\ProgramData\TEMP => ":0E61938B" ADS removed successfully.
C:\ProgramData\TEMP => ":0E660858" ADS removed successfully.
C:\ProgramData\TEMP => ":0E8117B1" ADS removed successfully.
C:\ProgramData\TEMP => ":0EAA09AC" ADS removed successfully.
C:\ProgramData\TEMP => ":0EBD727C" ADS removed successfully.
C:\ProgramData\TEMP => ":0ED1C542" ADS removed successfully.
C:\ProgramData\TEMP => ":0F5DCBF5" ADS removed successfully.
C:\ProgramData\TEMP => ":0F64164E" ADS removed successfully.
C:\ProgramData\TEMP => ":0FAE191E" ADS removed successfully.
C:\ProgramData\TEMP => ":0FD8569B" ADS removed successfully.
C:\ProgramData\TEMP => ":0FE0A03C" ADS removed successfully.
C:\ProgramData\TEMP => ":1011DA7C" ADS removed successfully.
C:\ProgramData\TEMP => ":1013B07C" ADS removed successfully.
C:\ProgramData\TEMP => ":1044BAFC" ADS removed successfully.
C:\ProgramData\TEMP => ":104A1C3E" ADS removed successfully.
C:\ProgramData\TEMP => ":109734F6" ADS removed successfully.
C:\ProgramData\TEMP => ":10CB85CA" ADS removed successfully.
C:\ProgramData\TEMP => ":10D45FC3" ADS removed successfully.
C:\ProgramData\TEMP => ":10D7EE4B" ADS removed successfully.
C:\ProgramData\TEMP => ":10DB9BB7" ADS removed successfully.
C:\ProgramData\TEMP => ":10E295F9" ADS removed successfully.
C:\ProgramData\TEMP => ":114C90CA" ADS removed successfully.
C:\ProgramData\TEMP => ":1170D6E4" ADS removed successfully.
C:\ProgramData\TEMP => ":11C7FAE3" ADS removed successfully.
C:\ProgramData\TEMP => ":11EFE63D" ADS removed successfully.
C:\ProgramData\TEMP => ":120B3AFD" ADS removed successfully.
C:\ProgramData\TEMP => ":120E44A4" ADS removed successfully.
C:\ProgramData\TEMP => ":1224B4C3" ADS removed successfully.
C:\ProgramData\TEMP => ":12383CAE" ADS removed successfully.
C:\ProgramData\TEMP => ":124B94C0" ADS removed successfully.
C:\ProgramData\TEMP => ":128B55C8" ADS removed successfully.
C:\ProgramData\TEMP => ":12A012A1" ADS removed successfully.
C:\ProgramData\TEMP => ":12BCD9DC" ADS removed successfully.
C:\ProgramData\TEMP => ":12D136AA" ADS removed successfully.
C:\ProgramData\TEMP => ":12D21A9A" ADS removed successfully.
C:\ProgramData\TEMP => ":12D2EB9C" ADS removed successfully.
C:\ProgramData\TEMP => ":12D9D48F" ADS removed successfully.
C:\ProgramData\TEMP => ":12E189B0" ADS removed successfully.
C:\ProgramData\TEMP => ":13019F4B" ADS removed successfully.
C:\ProgramData\TEMP => ":1345C9DC" ADS removed successfully.
C:\ProgramData\TEMP => ":134FBDE2" ADS removed successfully.
C:\ProgramData\TEMP => ":13765436" ADS removed successfully.
C:\ProgramData\TEMP => ":13CDB0E0" ADS removed successfully.
C:\ProgramData\TEMP => ":140AD176" ADS removed successfully.
C:\ProgramData\TEMP => ":14168AA3" ADS removed successfully.
C:\ProgramData\TEMP => ":1416AAA6" ADS removed successfully.
C:\ProgramData\TEMP => ":149327FE" ADS removed successfully.
C:\ProgramData\TEMP => ":159A493A" ADS removed successfully.
C:\ProgramData\TEMP => ":1604D047" ADS removed successfully.
C:\ProgramData\TEMP => ":161B4B1D" ADS removed successfully.
C:\ProgramData\TEMP => ":164561C8" ADS removed successfully.
C:\ProgramData\TEMP => ":1656EE95" ADS removed successfully.
C:\ProgramData\TEMP => ":16BD7665" ADS removed successfully.
C:\ProgramData\TEMP => ":16F42F1F" ADS removed successfully.
C:\ProgramData\TEMP => ":16F4BC64" ADS removed successfully.
C:\ProgramData\TEMP => ":1802D824" ADS removed successfully.
C:\ProgramData\TEMP => ":183A9046" ADS removed successfully.
C:\ProgramData\TEMP => ":18B241CC" ADS removed successfully.
C:\ProgramData\TEMP => ":18E3BAF3" ADS removed successfully.
C:\ProgramData\TEMP => ":19474103" ADS removed successfully.
C:\ProgramData\TEMP => ":19C541B5" ADS removed successfully.
C:\ProgramData\TEMP => ":1A15E356" ADS removed successfully.
C:\ProgramData\TEMP => ":1A259A13" ADS removed successfully.
C:\ProgramData\TEMP => ":1A45D40E" ADS removed successfully.
C:\ProgramData\TEMP => ":1A5822A3" ADS removed successfully.
C:\ProgramData\TEMP => ":1A5CC80A" ADS removed successfully.
C:\ProgramData\TEMP => ":1ABFB99D" ADS removed successfully.
C:\ProgramData\TEMP => ":1ADC4BD5" ADS removed successfully.
C:\ProgramData\TEMP => ":1B3549F2" ADS removed successfully.
C:\ProgramData\TEMP => ":1B389835" ADS removed successfully.
C:\ProgramData\TEMP => ":1B47CB83" ADS removed successfully.
C:\ProgramData\TEMP => ":1B5B615D" ADS removed successfully.
C:\ProgramData\TEMP => ":1B7E916D" ADS removed successfully.
C:\ProgramData\TEMP => ":1B825050" ADS removed successfully.
C:\ProgramData\TEMP => ":1B8A258D" ADS removed successfully.
C:\ProgramData\TEMP => ":1B90AAB4" ADS removed successfully.
C:\ProgramData\TEMP => ":1B927722" ADS removed successfully.
C:\ProgramData\TEMP => ":1B96CF22" ADS removed successfully.
C:\ProgramData\TEMP => ":1B97BCB0" ADS removed successfully.
C:\ProgramData\TEMP => ":1C201DEB" ADS removed successfully.
C:\ProgramData\TEMP => ":1C5692E6" ADS removed successfully.
C:\ProgramData\TEMP => ":1C6D705B" ADS removed successfully.
C:\ProgramData\TEMP => ":1C9565AC" ADS removed successfully.
C:\ProgramData\TEMP => ":1CB8D545" ADS removed successfully.
C:\ProgramData\TEMP => ":1CB96B16" ADS removed successfully.
C:\ProgramData\TEMP => ":1CD511E5" ADS removed successfully.
C:\ProgramData\TEMP => ":1CF1FB36" ADS removed successfully.
C:\ProgramData\TEMP => ":1D60AEC3" ADS removed successfully.
C:\ProgramData\TEMP => ":1D6B18F1" ADS removed successfully.
C:\ProgramData\TEMP => ":1D9ED8F7" ADS removed successfully.
C:\ProgramData\TEMP => ":1DDD0008" ADS removed successfully.
C:\ProgramData\TEMP => ":1E288DA3" ADS removed successfully.
C:\ProgramData\TEMP => ":1E4D6E88" ADS removed successfully.
C:\ProgramData\TEMP => ":1E5EC928" ADS removed successfully.
C:\ProgramData\TEMP => ":1E86ADD2" ADS removed successfully.
C:\ProgramData\TEMP => ":1E942FB9" ADS removed successfully.
C:\ProgramData\TEMP => ":1EC13383" ADS removed successfully.
C:\ProgramData\TEMP => ":1F0FA039" ADS removed successfully.
C:\ProgramData\TEMP => ":1FA4C06F" ADS removed successfully.
C:\ProgramData\TEMP => ":1FF82161" ADS removed successfully.
C:\ProgramData\TEMP => ":2043337E" ADS removed successfully.
C:\ProgramData\TEMP => ":204BEE0F" ADS removed successfully.
C:\ProgramData\TEMP => ":207C4C79" ADS removed successfully.
C:\ProgramData\TEMP => ":217A2324" ADS removed successfully.
C:\ProgramData\TEMP => ":217A2A36" ADS removed successfully.
C:\ProgramData\TEMP => ":219DB32E" ADS removed successfully.
C:\ProgramData\TEMP => ":21D64A91" ADS removed successfully.
C:\ProgramData\TEMP => ":21D69AEA" ADS removed successfully.
C:\ProgramData\TEMP => ":220E9B9E" ADS removed successfully.
C:\ProgramData\TEMP => ":2211E7A0" ADS removed successfully.
C:\ProgramData\TEMP => ":2216A431" ADS removed successfully.
C:\ProgramData\TEMP => ":2245476B" ADS removed successfully.
C:\ProgramData\TEMP => ":22C80839" ADS removed successfully.
C:\ProgramData\TEMP => ":236FF5C6" ADS removed successfully.
C:\ProgramData\TEMP => ":23834E1E" ADS removed successfully.
C:\ProgramData\TEMP => ":241FA548" ADS removed successfully.
C:\ProgramData\TEMP => ":242749DF" ADS removed successfully.
C:\ProgramData\TEMP => ":244E4E3A" ADS removed successfully.
C:\ProgramData\TEMP => ":24C072FF" ADS removed successfully.
C:\ProgramData\TEMP => ":24C89EFC" ADS removed successfully.
C:\ProgramData\TEMP => ":24F08129" ADS removed successfully.
C:\ProgramData\TEMP => ":25005EFA" ADS removed successfully.
C:\ProgramData\TEMP => ":2512FA90" ADS removed successfully.
C:\ProgramData\TEMP => ":252E6179" ADS removed successfully.
C:\ProgramData\TEMP => ":2530BFBE" ADS removed successfully.
C:\ProgramData\TEMP => ":2556A8A0" ADS removed successfully.
C:\ProgramData\TEMP => ":258D2F8B" ADS removed successfully.
C:\ProgramData\TEMP => ":26140299" ADS removed successfully.
C:\ProgramData\TEMP => ":2640C43F" ADS removed successfully.
C:\ProgramData\TEMP => ":2652902F" ADS removed successfully.
C:\ProgramData\TEMP => ":26991AB9" ADS removed successfully.
C:\ProgramData\TEMP => ":2727F067" ADS removed successfully.
C:\ProgramData\TEMP => ":2773164E" ADS removed successfully.
C:\ProgramData\TEMP => ":27790C06" ADS removed successfully.
C:\ProgramData\TEMP => ":27A88EF2" ADS removed successfully.
C:\ProgramData\TEMP => ":27B99ED6" ADS removed successfully.
C:\ProgramData\TEMP => ":27C3CD07" ADS removed successfully.
C:\ProgramData\TEMP => ":282CE153" ADS removed successfully.
C:\ProgramData\TEMP => ":28CDD861" ADS removed successfully.
C:\ProgramData\TEMP => ":29861223" ADS removed successfully.
C:\ProgramData\TEMP => ":29ADC74D" ADS removed successfully.
C:\ProgramData\TEMP => ":29B37860" ADS removed successfully.
C:\ProgramData\TEMP => ":29C0641D" ADS removed successfully.
C:\ProgramData\TEMP => ":29DA7FEE" ADS removed successfully.
C:\ProgramData\TEMP => ":29F0CA7D" ADS removed successfully.
C:\ProgramData\TEMP => ":2A5BC0A9" ADS removed successfully.
C:\ProgramData\TEMP => ":2AD33723" ADS removed successfully.
C:\ProgramData\TEMP => ":2AE74FF9" ADS removed successfully.
C:\ProgramData\TEMP => ":2AF05C70" ADS removed successfully.
C:\ProgramData\TEMP => ":2AF322BF" ADS removed successfully.
C:\ProgramData\TEMP => ":2B37CCB6" ADS removed successfully.
C:\ProgramData\TEMP => ":2B40A7DB" ADS removed successfully.
C:\ProgramData\TEMP => ":2B5C4773" ADS removed successfully.
C:\ProgramData\TEMP => ":2B856118" ADS removed successfully.
C:\ProgramData\TEMP => ":2B9555D8" ADS removed successfully.
C:\ProgramData\TEMP => ":2C4F33F6" ADS removed successfully.
C:\ProgramData\TEMP => ":2C84CA43" ADS removed successfully.
C:\ProgramData\TEMP => ":2CA4B471" ADS removed successfully.
C:\ProgramData\TEMP => ":2CB9631F" ADS removed successfully.
C:\ProgramData\TEMP => ":2CC32B31" ADS removed successfully.
C:\ProgramData\TEMP => ":2CFBE2D1" ADS removed successfully.
C:\ProgramData\TEMP => ":2D2461E7" ADS removed successfully.
C:\ProgramData\TEMP => ":2DE5673D" ADS removed successfully.
C:\ProgramData\TEMP => ":2DF54B62" ADS removed successfully.
C:\ProgramData\TEMP => ":2DF93164" ADS removed successfully.
C:\ProgramData\TEMP => ":2E3F04BC" ADS removed successfully.
C:\ProgramData\TEMP => ":2E636DD9" ADS removed successfully.
C:\ProgramData\TEMP => ":2E87E3DD" ADS removed successfully.
C:\ProgramData\TEMP => ":2E928E6E" ADS removed successfully.
C:\ProgramData\TEMP => ":2E9900EE" ADS removed successfully.
C:\ProgramData\TEMP => ":2F474C84" ADS removed successfully.
C:\ProgramData\TEMP => ":2F5A06FD" ADS removed successfully.
C:\ProgramData\TEMP => ":2F8138B7" ADS removed successfully.
C:\ProgramData\TEMP => ":2FAFBD6A" ADS removed successfully.
C:\ProgramData\TEMP => ":2FF4577A" ADS removed successfully.
C:\ProgramData\TEMP => ":302ECBD6" ADS removed successfully.
C:\ProgramData\TEMP => ":3086B95F" ADS removed successfully.
C:\ProgramData\TEMP => ":311A2F6A" ADS removed successfully.
C:\ProgramData\TEMP => ":31403DF7" ADS removed successfully.
C:\ProgramData\TEMP => ":31C9BA96" ADS removed successfully.
C:\ProgramData\TEMP => ":320208DA" ADS removed successfully.
C:\ProgramData\TEMP => ":321156F2" ADS removed successfully.
C:\ProgramData\TEMP => ":32289BE8" ADS removed successfully.
C:\ProgramData\TEMP => ":322D2CD3" ADS removed successfully.
C:\ProgramData\TEMP => ":3241739E" ADS removed successfully.
C:\ProgramData\TEMP => ":32D2A239" ADS removed successfully.
C:\ProgramData\TEMP => ":32EA849C" ADS removed successfully.
C:\ProgramData\TEMP => ":3313A48D" ADS removed successfully.
C:\ProgramData\TEMP => ":3393A1CA" ADS removed successfully.
C:\ProgramData\TEMP => ":33B04540" ADS removed successfully.
C:\ProgramData\TEMP => ":342886D8" ADS removed successfully.
C:\ProgramData\TEMP => ":3433021E" ADS removed successfully.
C:\ProgramData\TEMP => ":34445512" ADS removed successfully.
C:\ProgramData\TEMP => ":345A9A38" ADS removed successfully.
C:\ProgramData\TEMP => ":3480F458" ADS removed successfully.
C:\ProgramData\TEMP => ":34EFF1F2" ADS removed successfully.
C:\ProgramData\TEMP => ":34FDB459" ADS removed successfully.
C:\ProgramData\TEMP => ":35110824" ADS removed successfully.
C:\ProgramData\TEMP => ":3557EC26" ADS removed successfully.
C:\ProgramData\TEMP => ":35629AE6" ADS removed successfully.
C:\ProgramData\TEMP => ":3571475C" ADS removed successfully.
C:\ProgramData\TEMP => ":3595B780" ADS removed successfully.
C:\ProgramData\TEMP => ":35A8E846" ADS removed successfully.
C:\ProgramData\TEMP => ":35E8E596" ADS removed successfully.
C:\ProgramData\TEMP => ":361703F1" ADS removed successfully.
C:\ProgramData\TEMP => ":366B74CA" ADS removed successfully.
C:\ProgramData\TEMP => ":366EFA1A" ADS removed successfully.
C:\ProgramData\TEMP => ":36ED5C45" ADS removed successfully.
C:\ProgramData\TEMP => ":371A321E" ADS removed successfully.
C:\ProgramData\TEMP => ":373C6DC2" ADS removed successfully.
C:\ProgramData\TEMP => ":378824DE" ADS removed successfully.
C:\ProgramData\TEMP => ":37994DBE" ADS removed successfully.
C:\ProgramData\TEMP => ":37C279BE" ADS removed successfully.
C:\ProgramData\TEMP => ":38534D53" ADS removed successfully.
C:\ProgramData\TEMP => ":3867977D" ADS removed successfully.
C:\ProgramData\TEMP => ":395F6776" ADS removed successfully.
C:\ProgramData\TEMP => ":3969ACF7" ADS removed successfully.
C:\ProgramData\TEMP => ":397D67BA" ADS removed successfully.
C:\ProgramData\TEMP => ":398D2775" ADS removed successfully.
C:\ProgramData\TEMP => ":398EFF0F" ADS removed successfully.
C:\ProgramData\TEMP => ":3A4676D7" ADS removed successfully.
C:\ProgramData\TEMP => ":3AC0ED43" ADS removed successfully.
C:\ProgramData\TEMP => ":3AD6342E" ADS removed successfully.
C:\ProgramData\TEMP => ":3ADE134E" ADS removed successfully.
C:\ProgramData\TEMP => ":3AF262FC" ADS removed successfully.
C:\ProgramData\TEMP => ":3B07E6F4" ADS removed successfully.
C:\ProgramData\TEMP => ":3B633DE9" ADS removed successfully.
C:\ProgramData\TEMP => ":3B71586E" ADS removed successfully.
C:\ProgramData\TEMP => ":3C0887BF" ADS removed successfully.
C:\ProgramData\TEMP => ":3C8B784A" ADS removed successfully.
C:\ProgramData\TEMP => ":3C9B05C4" ADS removed successfully.
C:\ProgramData\TEMP => ":3CA18B6B" ADS removed successfully.
C:\ProgramData\TEMP => ":3CAE2A70" ADS removed successfully.
C:\ProgramData\TEMP => ":3D186293" ADS removed successfully.
C:\ProgramData\TEMP => ":3D3F1635" ADS removed successfully.
C:\ProgramData\TEMP => ":3D4B733E" ADS removed successfully.
C:\ProgramData\TEMP => ":3D887DCC" ADS removed successfully.
C:\ProgramData\TEMP => ":3D922890" ADS removed successfully.
C:\ProgramData\TEMP => ":3DBE461A" ADS removed successfully.
C:\ProgramData\TEMP => ":3E200C29" ADS removed successfully.
C:\ProgramData\TEMP => ":3ED5E595" ADS removed successfully.
C:\ProgramData\TEMP => ":3F9F662A" ADS removed successfully.
C:\ProgramData\TEMP => ":3FB26DBA" ADS removed successfully.
C:\ProgramData\TEMP => ":3FBB88CF" ADS removed successfully.
C:\ProgramData\TEMP => ":4018444F" ADS removed successfully.
C:\ProgramData\TEMP => ":401CAF8F" ADS removed successfully.
C:\ProgramData\TEMP => ":403C313B" ADS removed successfully.
C:\ProgramData\TEMP => ":404908B5" ADS removed successfully.
C:\ProgramData\TEMP => ":40512067" ADS removed successfully.
C:\ProgramData\TEMP => ":40546375" ADS removed successfully.
C:\ProgramData\TEMP => ":409F27A9" ADS removed successfully.
C:\ProgramData\TEMP => ":4149A170" ADS removed successfully.
C:\ProgramData\TEMP => ":4157BB05" ADS removed successfully.
C:\ProgramData\TEMP => ":415E77AB" ADS removed successfully.
C:\ProgramData\TEMP => ":417B6FAC" ADS removed successfully.
C:\ProgramData\TEMP => ":417C2BC3" ADS removed successfully.
C:\ProgramData\TEMP => ":41884BBE" ADS removed successfully.
C:\ProgramData\TEMP => ":41C283B2" ADS removed successfully.
C:\ProgramData\TEMP => ":42275BC2" ADS removed successfully.
C:\ProgramData\TEMP => ":42B6425E" ADS removed successfully.
C:\ProgramData\TEMP => ":432EC713" ADS removed successfully.
C:\ProgramData\TEMP => ":438C7496" ADS removed successfully.
C:\ProgramData\TEMP => ":43CBFAB2" ADS removed successfully.
C:\ProgramData\TEMP => ":43DA85AC" ADS removed successfully.
C:\ProgramData\TEMP => ":43ECEA33" ADS removed successfully.
C:\ProgramData\TEMP => ":43F5FA9D" ADS removed successfully.
C:\ProgramData\TEMP => ":44712999" ADS removed successfully.
C:\ProgramData\TEMP => ":447856CD" ADS removed successfully.
C:\ProgramData\TEMP => ":44E16D4A" ADS removed successfully.
C:\ProgramData\TEMP => ":45912F61" ADS removed successfully.
C:\ProgramData\TEMP => ":46283136" ADS removed successfully.
C:\ProgramData\TEMP => ":469B47D8" ADS removed successfully.
C:\ProgramData\TEMP => ":46A2F27B" ADS removed successfully.
C:\ProgramData\TEMP => ":46ADD59D" ADS removed successfully.
C:\ProgramData\TEMP => ":46CBC45C" ADS removed successfully.
C:\ProgramData\TEMP => ":46CF5C1F" ADS removed successfully.
C:\ProgramData\TEMP => ":46EF121E" ADS removed successfully.
C:\ProgramData\TEMP => ":4709F39D" ADS removed successfully.
C:\ProgramData\TEMP => ":471AD3D0" ADS removed successfully.
C:\ProgramData\TEMP => ":479B1CF9" ADS removed successfully.
C:\ProgramData\TEMP => ":47B391B0" ADS removed successfully.
C:\ProgramData\TEMP => ":4826868B" ADS removed successfully.
C:\ProgramData\TEMP => ":48529647" ADS removed successfully.
C:\ProgramData\TEMP => ":48862C37" ADS removed successfully.
C:\ProgramData\TEMP => ":488F7244" ADS removed successfully.
C:\ProgramData\TEMP => ":48977386" ADS removed successfully.
C:\ProgramData\TEMP => ":490BCC52" ADS removed successfully.
C:\ProgramData\TEMP => ":49B217F7" ADS removed successfully.
C:\ProgramData\TEMP => ":49BE0F68" ADS removed successfully.
C:\ProgramData\TEMP => ":49EB69E2" ADS removed successfully.
C:\ProgramData\TEMP => ":4A01545C" ADS removed successfully.
C:\ProgramData\TEMP => ":4A03F06E" ADS removed successfully.
C:\ProgramData\TEMP => ":4A077D87" ADS removed successfully.
C:\ProgramData\TEMP => ":4A448DB2" ADS removed successfully.
C:\ProgramData\TEMP => ":4A5CFD3B" ADS removed successfully.
C:\ProgramData\TEMP => ":4A8EB1C4" ADS removed successfully.
C:\ProgramData\TEMP => ":4A966CC2" ADS removed successfully.
C:\ProgramData\TEMP => ":4AC1DFA1" ADS removed successfully.
C:\ProgramData\TEMP => ":4AC7B5C1" ADS removed successfully.
C:\ProgramData\TEMP => ":4B244549" ADS removed successfully.
C:\ProgramData\TEMP => ":4B325725" ADS removed successfully.
C:\ProgramData\TEMP => ":4B3648ED" ADS removed successfully.
C:\ProgramData\TEMP => ":4BBF1137" ADS removed successfully.
C:\ProgramData\TEMP => ":4BEE39B0" ADS removed successfully.
C:\ProgramData\TEMP => ":4C16B46B" ADS removed successfully.
C:\ProgramData\TEMP => ":4C31986D" ADS removed successfully.
C:\ProgramData\TEMP => ":4C4BD66D" ADS removed successfully.
C:\ProgramData\TEMP => ":4C5C1DD3" ADS removed successfully.
C:\ProgramData\TEMP => ":4C6F9D77" ADS removed successfully.
C:\ProgramData\TEMP => ":4C8FA829" ADS removed successfully.
C:\ProgramData\TEMP => ":4CD2D817" ADS removed successfully.
C:\ProgramData\TEMP => ":4D066AD2" ADS removed successfully.
C:\ProgramData\TEMP => ":4D28BE4D" ADS removed successfully.
C:\ProgramData\TEMP => ":4D348522" ADS removed successfully.
C:\ProgramData\TEMP => ":4D551822" ADS removed successfully.
C:\ProgramData\TEMP => ":4D729D61" ADS removed successfully.
C:\ProgramData\TEMP => ":4D8FCBEF" ADS removed successfully.
C:\ProgramData\TEMP => ":4DDE401B" ADS removed successfully.
C:\ProgramData\TEMP => ":4DE8C719" ADS removed successfully.
C:\ProgramData\TEMP => ":4E79C4F8" ADS removed successfully.
C:\ProgramData\TEMP => ":4EAD6852" ADS removed successfully.
C:\ProgramData\TEMP => ":4EC7F009" ADS removed successfully.
C:\ProgramData\TEMP => ":4EDDC66F" ADS removed successfully.
C:\ProgramData\TEMP => ":4EE5EBE9" ADS removed successfully.
C:\ProgramData\TEMP => ":4EE95FE7" ADS removed successfully.
C:\ProgramData\TEMP => ":4EEC7800" ADS removed successfully.
C:\ProgramData\TEMP => ":4F28299B" ADS removed successfully.
C:\ProgramData\TEMP => ":4F7FE589" ADS removed successfully.
C:\ProgramData\TEMP => ":4FA837B4" ADS removed successfully.
C:\ProgramData\TEMP => ":5008417E" ADS removed successfully.
C:\ProgramData\TEMP => ":5014D98F" ADS removed successfully.
C:\ProgramData\TEMP => ":502EE511" ADS removed successfully.
C:\ProgramData\TEMP => ":506698B2" ADS removed successfully.
C:\ProgramData\TEMP => ":506E1E25" ADS removed successfully.
C:\ProgramData\TEMP => ":5080697C" ADS removed successfully.
C:\ProgramData\TEMP => ":50868536" ADS removed successfully.
C:\ProgramData\TEMP => ":50DD4118" ADS removed successfully.
C:\ProgramData\TEMP => ":51003EF4" ADS removed successfully.
C:\ProgramData\TEMP => ":512E1728" ADS removed successfully.
C:\ProgramData\TEMP => ":5133A494" ADS removed successfully.
C:\ProgramData\TEMP => ":518C333F" ADS removed successfully.
C:\ProgramData\TEMP => ":5197985B" ADS removed successfully.
C:\ProgramData\TEMP => ":5199C971" ADS removed successfully.
C:\ProgramData\TEMP => ":51A22C60" ADS removed successfully.
C:\ProgramData\TEMP => ":52329B88" ADS removed successfully.
C:\ProgramData\TEMP => ":5279F7BF" ADS removed successfully.
C:\ProgramData\TEMP => ":52C24010" ADS removed successfully.
C:\ProgramData\TEMP => ":5320A31B" ADS removed successfully.
C:\ProgramData\TEMP => ":53B8C5D2" ADS removed successfully.
C:\ProgramData\TEMP => ":53F09A92" ADS removed successfully.
C:\ProgramData\TEMP => ":53F381F1" ADS removed successfully.
C:\ProgramData\TEMP => ":54380FEC" ADS removed successfully.
C:\ProgramData\TEMP => ":54403233" ADS removed successfully.
C:\ProgramData\TEMP => ":54531C7D" ADS removed successfully.
C:\ProgramData\TEMP => ":5453E5AF" ADS removed successfully.
C:\ProgramData\TEMP => ":5466F106" ADS removed successfully.
C:\ProgramData\TEMP => ":54F0BBF5" ADS removed successfully.
C:\ProgramData\TEMP => ":5511B474" ADS removed successfully.
C:\ProgramData\TEMP => ":551BED5F" ADS removed successfully.
C:\ProgramData\TEMP => ":551E1CB4" ADS removed successfully.
C:\ProgramData\TEMP => ":5520ED93" ADS removed successfully.
C:\ProgramData\TEMP => ":553056F1" ADS removed successfully.
C:\ProgramData\TEMP => ":5539129F" ADS removed successfully.
C:\ProgramData\TEMP => ":554B3BF6" ADS removed successfully.
C:\ProgramData\TEMP => ":5607B58C" ADS removed successfully.
C:\ProgramData\TEMP => ":56C66609" ADS removed successfully.
C:\ProgramData\TEMP => ":56CE93C9" ADS removed successfully.
C:\ProgramData\TEMP => ":571CCF8E" ADS removed successfully.
C:\ProgramData\TEMP => ":57231008" ADS removed successfully.
C:\ProgramData\TEMP => ":57619D72" ADS removed successfully.
C:\ProgramData\TEMP => ":587F3582" ADS removed successfully.
C:\ProgramData\TEMP => ":5925E400" ADS removed successfully.
C:\ProgramData\TEMP => ":593E515D" ADS removed successfully.
C:\ProgramData\TEMP => ":59465B40" ADS removed successfully.
C:\ProgramData\TEMP => ":59A6876B" ADS removed successfully.
C:\ProgramData\TEMP => ":59C64924" ADS removed successfully.
C:\ProgramData\TEMP => ":5A068EE1" ADS removed successfully.
C:\ProgramData\TEMP => ":5A2E8BBF" ADS removed successfully.
C:\ProgramData\TEMP => ":5A5477A9" ADS removed successfully.
C:\ProgramData\TEMP => ":5A63CC20" ADS removed successfully.
C:\ProgramData\TEMP => ":5A9F1AE5" ADS removed successfully.
C:\ProgramData\TEMP => ":5AE33054" ADS removed successfully.
C:\ProgramData\TEMP => ":5B111056" ADS removed successfully.
C:\ProgramData\TEMP => ":5B307FD4" ADS removed successfully.
C:\ProgramData\TEMP => ":5B483FBC" ADS removed successfully.
C:\ProgramData\TEMP => ":5BF8F61F" ADS removed successfully.
C:\ProgramData\TEMP => ":5C28E25F" ADS removed successfully.
C:\ProgramData\TEMP => ":5C353220" ADS removed successfully.
C:\ProgramData\TEMP => ":5C3637D2" ADS removed successfully.
C:\ProgramData\TEMP => ":5C42F64A" ADS removed successfully.
C:\ProgramData\TEMP => ":5C4A588B" ADS removed successfully.
C:\ProgramData\TEMP => ":5C5F2761" ADS removed successfully.
C:\ProgramData\TEMP => ":5C66F780" ADS removed successfully.
C:\ProgramData\TEMP => ":5C9A6C78" ADS removed successfully.
C:\ProgramData\TEMP => ":5CB83528" ADS removed successfully.
C:\ProgramData\TEMP => ":5CBA5665" ADS removed successfully.
C:\ProgramData\TEMP => ":5CE91C67" ADS removed successfully.
C:\ProgramData\TEMP => ":5D057E09" ADS removed successfully.
C:\ProgramData\TEMP => ":5D10517E" ADS removed successfully.
C:\ProgramData\TEMP => ":5D1BA9DE" ADS removed successfully.
C:\ProgramData\TEMP => ":5D2D5608" ADS removed successfully.
C:\ProgramData\TEMP => ":5D34FAF9" ADS removed successfully.
C:\ProgramData\TEMP => ":5D570144" ADS removed successfully.
C:\ProgramData\TEMP => ":5DABFF83" ADS removed successfully.
C:\ProgramData\TEMP => ":5DB36C47" ADS removed successfully.
C:\ProgramData\TEMP => ":5E21B96B" ADS removed successfully.
C:\ProgramData\TEMP => ":5E358F67" ADS removed successfully.
C:\ProgramData\TEMP => ":5E481579" ADS removed successfully.
C:\ProgramData\TEMP => ":5E4A7758" ADS removed successfully.
C:\ProgramData\TEMP => ":5E73E1C2" ADS removed successfully.
C:\ProgramData\TEMP => ":5E8C18F1" ADS removed successfully.
C:\ProgramData\TEMP => ":5EC48C3A" ADS removed successfully.
C:\ProgramData\TEMP => ":5ECEFF17" ADS removed successfully.
C:\ProgramData\TEMP => ":5ED7E575" ADS removed successfully.
C:\ProgramData\TEMP => ":5EFEB6A1" ADS removed successfully.
C:\ProgramData\TEMP => ":5F2C9B5E" ADS removed successfully.
C:\ProgramData\TEMP => ":5F56E7C1" ADS removed successfully.
C:\ProgramData\TEMP => ":5FC043A8" ADS removed successfully.
C:\ProgramData\TEMP => ":5FD26EF3" ADS removed successfully.
C:\ProgramData\TEMP => ":6017A808" ADS removed successfully.
C:\ProgramData\TEMP => ":607A99D7" ADS removed successfully.
C:\ProgramData\TEMP => ":60AC3BC3" ADS removed successfully.
C:\ProgramData\TEMP => ":60D48570" ADS removed successfully.
C:\ProgramData\TEMP => ":60E0AB2A" ADS removed successfully.
C:\ProgramData\TEMP => ":611EAF9F" ADS removed successfully.
C:\ProgramData\TEMP => ":624A80FD" ADS removed successfully.
C:\ProgramData\TEMP => ":62525FE7" ADS removed successfully.
C:\ProgramData\TEMP => ":627153F1" ADS removed successfully.
C:\ProgramData\TEMP => ":6294B369" ADS removed successfully.
C:\ProgramData\TEMP => ":62AC0CCE" ADS removed successfully.
C:\ProgramData\TEMP => ":62AF94A0" ADS removed successfully.
C:\ProgramData\TEMP => ":6301CE40" ADS removed successfully.
C:\ProgramData\TEMP => ":63A71C6F" ADS removed successfully.
C:\ProgramData\TEMP => ":63B94956" ADS removed successfully.
C:\ProgramData\TEMP => ":63C29481" ADS removed successfully.
C:\ProgramData\TEMP => ":63CFD724" ADS removed successfully.
C:\ProgramData\TEMP => ":63F8EC77" ADS removed successfully.
C:\ProgramData\TEMP => ":640DDEFF" ADS removed successfully.
C:\ProgramData\TEMP => ":64FABDFB" ADS removed successfully.
C:\ProgramData\TEMP => ":65137F0D" ADS removed successfully.
C:\ProgramData\TEMP => ":65484F45" ADS removed successfully.
C:\ProgramData\TEMP => ":65684E14" ADS removed successfully.
C:\ProgramData\TEMP => ":65929158" ADS removed successfully.
C:\ProgramData\TEMP => ":65949863" ADS removed successfully.
C:\ProgramData\TEMP => ":65B8AF94" ADS removed successfully.
C:\ProgramData\TEMP => ":65C4D44A" ADS removed successfully.
C:\ProgramData\TEMP => ":6622852D" ADS removed successfully.
C:\ProgramData\TEMP => ":6622EB04" ADS removed successfully.
C:\ProgramData\TEMP => ":667565EE" ADS removed successfully.
C:\ProgramData\TEMP => ":669AB5E1" ADS removed successfully.
C:\ProgramData\TEMP => ":66C764F5" ADS removed successfully.
C:\ProgramData\TEMP => ":66F19688" ADS removed successfully.
C:\ProgramData\TEMP => ":66F7E5A9" ADS removed successfully.
C:\ProgramData\TEMP => ":67396145" ADS removed successfully.
C:\ProgramData\TEMP => ":67842DB7" ADS removed successfully.
C:\ProgramData\TEMP => ":67A91473" ADS removed successfully.
C:\ProgramData\TEMP => ":67B6E7FA" ADS removed successfully.
C:\ProgramData\TEMP => ":67CF910D" ADS removed successfully.
C:\ProgramData\TEMP => ":67E674B0" ADS removed successfully.
C:\ProgramData\TEMP => ":680F6474" ADS removed successfully.
C:\ProgramData\TEMP => ":687D1056" ADS removed successfully.
C:\ProgramData\TEMP => ":689AB7E9" ADS removed successfully.
C:\ProgramData\TEMP => ":68A41423" ADS removed successfully.
C:\ProgramData\TEMP => ":68DE552E" ADS removed successfully.
C:\ProgramData\TEMP => ":697DDE2B" ADS removed successfully.
C:\ProgramData\TEMP => ":69FE2EE4" ADS removed successfully.
C:\ProgramData\TEMP => ":6A129BAB" ADS removed successfully.
C:\ProgramData\TEMP => ":6A9EDD31" ADS removed successfully.
C:\ProgramData\TEMP => ":6AF6BB0E" ADS removed successfully.
C:\ProgramData\TEMP => ":6B28173C" ADS removed successfully.
C:\ProgramData\TEMP => ":6B5A665E" ADS removed successfully.
C:\ProgramData\TEMP => ":6B7447D4" ADS removed successfully.
C:\ProgramData\TEMP => ":6B9828AE" ADS removed successfully.
C:\ProgramData\TEMP => ":6BE79E11" ADS removed successfully.
C:\ProgramData\TEMP => ":6BEADDC0" ADS removed successfully.
C:\ProgramData\TEMP => ":6BF0805F" ADS removed successfully.
C:\ProgramData\TEMP => ":6BFA43EB" ADS removed successfully.
C:\ProgramData\TEMP => ":6C15BEAD" ADS removed successfully.
C:\ProgramData\TEMP => ":6C468A51" ADS removed successfully.
C:\ProgramData\TEMP => ":6C81A062" ADS removed successfully.
C:\ProgramData\TEMP => ":6CC1CB6D" ADS removed successfully.
C:\ProgramData\TEMP => ":6CF828C2" ADS removed successfully.
C:\ProgramData\TEMP => ":6D4F7F2B" ADS removed successfully.
C:\ProgramData\TEMP => ":6D65CED0" ADS removed successfully.
C:\ProgramData\TEMP => ":6DCFAD3B" ADS removed successfully.
C:\ProgramData\TEMP => ":6DD87D86" ADS removed successfully.
C:\ProgramData\TEMP => ":6DDBB86B" ADS removed successfully.
C:\ProgramData\TEMP => ":6E2D80C8" ADS removed successfully.
C:\ProgramData\TEMP => ":6E39144C" ADS removed successfully.
C:\ProgramData\TEMP => ":6E3C585B" ADS removed successfully.
C:\ProgramData\TEMP => ":6E65510A" ADS removed successfully.
C:\ProgramData\TEMP => ":6E6A4F42" ADS removed successfully.
C:\ProgramData\TEMP => ":6F16D671" ADS removed successfully.
C:\ProgramData\TEMP => ":6F94300C" ADS removed successfully.
C:\ProgramData\TEMP => ":700B8E2E" ADS removed successfully.
C:\ProgramData\TEMP => ":701B92FB" ADS removed successfully.
C:\ProgramData\TEMP => ":709E81D4" ADS removed successfully.
C:\ProgramData\TEMP => ":70E897B5" ADS removed successfully.
C:\ProgramData\TEMP => ":71112705" ADS removed successfully.
C:\ProgramData\TEMP => ":71A89A93" ADS removed successfully.
C:\ProgramData\TEMP => ":71AEFFEB" ADS removed successfully.
C:\ProgramData\TEMP => ":71B89F61" ADS removed successfully.
C:\ProgramData\TEMP => ":71F04C26" ADS removed successfully.
C:\ProgramData\TEMP => ":72449E7D" ADS removed successfully.
C:\ProgramData\TEMP => ":7247FE29" ADS removed successfully.
C:\ProgramData\TEMP => ":7254CF01" ADS removed successfully.
C:\ProgramData\TEMP => ":726A7C8D" ADS removed successfully.
C:\ProgramData\TEMP => ":72C99D4E" ADS removed successfully.
C:\ProgramData\TEMP => ":737160C1" ADS removed successfully.
C:\ProgramData\TEMP => ":73AFBB96" ADS removed successfully.
C:\ProgramData\TEMP => ":73B78E79" ADS removed successfully.
C:\ProgramData\TEMP => ":742F1EE5" ADS removed successfully.
C:\ProgramData\TEMP => ":74B502CB" ADS removed successfully.
C:\ProgramData\TEMP => ":751D6870" ADS removed successfully.
C:\ProgramData\TEMP => ":754E278B" ADS removed successfully.
C:\ProgramData\TEMP => ":75765D7B" ADS removed successfully.
C:\ProgramData\TEMP => ":75798D9A" ADS removed successfully.
C:\ProgramData\TEMP => ":75CC0165" ADS removed successfully.
C:\ProgramData\TEMP => ":75E7048E" ADS removed successfully.
C:\ProgramData\TEMP => ":762408BA" ADS removed successfully.
C:\ProgramData\TEMP => ":7641F818" ADS removed successfully.
C:\ProgramData\TEMP => ":76953F21" ADS removed successfully.
C:\ProgramData\TEMP => ":76DF754D" ADS removed successfully.
C:\ProgramData\TEMP => ":774A0E14" ADS removed successfully.
C:\ProgramData\TEMP => ":774C075A" ADS removed successfully.
C:\ProgramData\TEMP => ":77846FFE" ADS removed successfully.
C:\ProgramData\TEMP => ":77B64C59" ADS removed successfully.
C:\ProgramData\TEMP => ":77E239B1" ADS removed successfully.
C:\ProgramData\TEMP => ":77F49022" ADS removed successfully.
C:\ProgramData\TEMP => ":792BE0F5" ADS removed successfully.
C:\ProgramData\TEMP => ":793ABD2B" ADS removed successfully.
C:\ProgramData\TEMP => ":795F6DEC" ADS removed successfully.
C:\ProgramData\TEMP => ":79875988" ADS removed successfully.
C:\ProgramData\TEMP => ":79A7F369" ADS removed successfully.
C:\ProgramData\TEMP => ":79C6A9CE" ADS removed successfully.
C:\ProgramData\TEMP => ":79F970BE" ADS removed successfully.
C:\ProgramData\TEMP => ":7A0A894A" ADS removed successfully.
C:\ProgramData\TEMP => ":7ADB695A" ADS removed successfully.
C:\ProgramData\TEMP => ":7AF9CAEB" ADS removed successfully.
C:\ProgramData\TEMP => ":7B9BB187" ADS removed successfully.
C:\ProgramData\TEMP => ":7BB584AA" ADS removed successfully.
C:\ProgramData\TEMP => ":7BB6E2C8" ADS removed successfully.
C:\ProgramData\TEMP => ":7BD9473D" ADS removed successfully.
C:\ProgramData\TEMP => ":7BFAAE70" ADS removed successfully.
C:\ProgramData\TEMP => ":7BFFC6A9" ADS removed successfully.
C:\ProgramData\TEMP => ":7C27C41C" ADS removed successfully.
C:\ProgramData\TEMP => ":7C5E403A" ADS removed successfully.
C:\ProgramData\TEMP => ":7C819E94" ADS removed successfully.
C:\ProgramData\TEMP => ":7C8AA9A6" ADS removed successfully.
C:\ProgramData\TEMP => ":7CF8A507" ADS removed successfully.
C:\ProgramData\TEMP => ":7D04F8E2" ADS removed successfully.
C:\ProgramData\TEMP => ":7D288858" ADS removed successfully.
C:\ProgramData\TEMP => ":7D49B96B" ADS removed successfully.
C:\ProgramData\TEMP => ":7D938C9B" ADS removed successfully.
C:\ProgramData\TEMP => ":7D9B1030" ADS removed successfully.
C:\ProgramData\TEMP => ":7DC5D762" ADS removed successfully.
C:\ProgramData\TEMP => ":7E082023" ADS removed successfully.
C:\ProgramData\TEMP => ":7E0B06B5" ADS removed successfully.
C:\ProgramData\TEMP => ":7E1F211D" ADS removed successfully.
C:\ProgramData\TEMP => ":7E4E56EA" ADS removed successfully.
C:\ProgramData\TEMP => ":7E802BFF" ADS removed successfully.
C:\ProgramData\TEMP => ":7EC01D6D" ADS removed successfully.
C:\ProgramData\TEMP => ":7ECD9621" ADS removed successfully.
C:\ProgramData\TEMP => ":7EE43C06" ADS removed successfully.
C:\ProgramData\TEMP => ":7F66BF58" ADS removed successfully.
C:\ProgramData\TEMP => ":7FCB9D0D" ADS removed successfully.
C:\ProgramData\TEMP => ":7FD8AECC" ADS removed successfully.
C:\ProgramData\TEMP => ":80253E8D" ADS removed successfully.
C:\ProgramData\TEMP => ":8029E75F" ADS removed successfully.
C:\ProgramData\TEMP => ":8075370B" ADS removed successfully.
C:\ProgramData\TEMP => ":80974241" ADS removed successfully.
C:\ProgramData\TEMP => ":80BFDE16" ADS removed successfully.
C:\ProgramData\TEMP => ":80EA2EA3" ADS removed successfully.
C:\ProgramData\TEMP => ":81365633" ADS removed successfully.
C:\ProgramData\TEMP => ":817F0659" ADS removed successfully.
C:\ProgramData\TEMP => ":8204AA35" ADS removed successfully.
C:\ProgramData\TEMP => ":823606DE" ADS removed successfully.
C:\ProgramData\TEMP => ":8247A199" ADS removed successfully.
C:\ProgramData\TEMP => ":82529191" ADS removed successfully.
C:\ProgramData\TEMP => ":82EAE27C" ADS removed successfully.
C:\ProgramData\TEMP => ":8318A814" ADS removed successfully.
C:\ProgramData\TEMP => ":839A89FC" ADS removed successfully.
C:\ProgramData\TEMP => ":843D8419" ADS removed successfully.
C:\ProgramData\TEMP => ":8441E695" ADS removed successfully.
C:\ProgramData\TEMP => ":8470B630" ADS removed successfully.
C:\ProgramData\TEMP => ":84C34762" ADS removed successfully.
C:\ProgramData\TEMP => ":852F2262" ADS removed successfully.
C:\ProgramData\TEMP => ":85630A39" ADS removed successfully.
C:\ProgramData\TEMP => ":857692EC" ADS removed successfully.
C:\ProgramData\TEMP => ":85C3B823" ADS removed successfully.
C:\ProgramData\TEMP => ":85EA4795" ADS removed successfully.
C:\ProgramData\TEMP => ":861A898F" ADS removed successfully.
C:\ProgramData\TEMP => ":8634D9A3" ADS removed successfully.
C:\ProgramData\TEMP => ":865F21BF" ADS removed successfully.
C:\ProgramData\TEMP => ":86A8CE8D" ADS removed successfully.
C:\ProgramData\TEMP => ":86B7FDDB" ADS removed successfully.
C:\ProgramData\TEMP => ":86E0BFC8" ADS removed successfully.
C:\ProgramData\TEMP => ":871526BA" ADS removed successfully.
C:\ProgramData\TEMP => ":87E3D720" ADS removed successfully.
C:\ProgramData\TEMP => ":8836A712" ADS removed successfully.
C:\ProgramData\TEMP => ":8855A119" ADS removed successfully.
C:\ProgramData\TEMP => ":8866C899" ADS removed successfully.
C:\ProgramData\TEMP => ":8868F8ED" ADS removed successfully.
C:\ProgramData\TEMP => ":88FB7F72" ADS removed successfully.
C:\ProgramData\TEMP => ":89123481" ADS removed successfully.
C:\ProgramData\TEMP => ":891A7A73" ADS removed successfully.
C:\ProgramData\TEMP => ":895A78C5" ADS removed successfully.
C:\ProgramData\TEMP => ":8967C154" ADS removed successfully.
C:\ProgramData\TEMP => ":89C28CF6" ADS removed successfully.
C:\ProgramData\TEMP => ":89F44603" ADS removed successfully.
C:\ProgramData\TEMP => ":89FC8EEB" ADS removed successfully.
C:\ProgramData\TEMP => ":8A290D99" ADS removed successfully.
C:\ProgramData\TEMP => ":8A620099" ADS removed successfully.
C:\ProgramData\TEMP => ":8AC20936" ADS removed successfully.
C:\ProgramData\TEMP => ":8AE92FD3" ADS removed successfully.
C:\ProgramData\TEMP => ":8AEF2555" ADS removed successfully.
C:\ProgramData\TEMP => ":8B076EC5" ADS removed successfully.
C:\ProgramData\TEMP => ":8B3C3098" ADS removed successfully.
C:\ProgramData\TEMP => ":8B480195" ADS removed successfully.
C:\ProgramData\TEMP => ":8B4B9596" ADS removed successfully.
C:\ProgramData\TEMP => ":8B4C1181" ADS removed successfully.
C:\ProgramData\TEMP => ":8B69E3C3" ADS removed successfully.
C:\ProgramData\TEMP => ":8B9E766D" ADS removed successfully.
C:\ProgramData\TEMP => ":8BB2EE92" ADS removed successfully.
C:\ProgramData\TEMP => ":8BE8BFCD" ADS removed successfully.
C:\ProgramData\TEMP => ":8C12CFCD" ADS removed successfully.
C:\ProgramData\TEMP => ":8C443193" ADS removed successfully.
C:\ProgramData\TEMP => ":8C885EDD" ADS removed successfully.
C:\ProgramData\TEMP => ":8CE601F5" ADS removed successfully.
C:\ProgramData\TEMP => ":8CFF4966" ADS removed successfully.
C:\ProgramData\TEMP => ":8D565A9B" ADS removed successfully.
C:\ProgramData\TEMP => ":8DD20B4A" ADS removed successfully.
C:\ProgramData\TEMP => ":8E5EA40F" ADS removed successfully.
C:\ProgramData\TEMP => ":8E60033F" ADS removed successfully.
C:\ProgramData\TEMP => ":8EBF0142" ADS removed successfully.
C:\ProgramData\TEMP => ":8EEE3BBB" ADS removed successfully.
C:\ProgramData\TEMP => ":8F1B55BE" ADS removed successfully.
C:\ProgramData\TEMP => ":8F6B75BF" ADS removed successfully.
C:\ProgramData\TEMP => ":8F7ECF6A" ADS removed successfully.
C:\ProgramData\TEMP => ":8F925134" ADS removed successfully.
C:\ProgramData\TEMP => ":8F99ADAD" ADS removed successfully.
C:\ProgramData\TEMP => ":8FA3210E" ADS removed successfully.
C:\ProgramData\TEMP => ":8FBE0E9C" ADS removed successfully.
C:\ProgramData\TEMP => ":8FC027DE" ADS removed successfully.
C:\ProgramData\TEMP => ":8FF962C6" ADS removed successfully.
C:\ProgramData\TEMP => ":90108DD7" ADS removed successfully.
C:\ProgramData\TEMP => ":9026EFD0" ADS removed successfully.
C:\ProgramData\TEMP => ":902B3C72" ADS removed successfully.
C:\ProgramData\TEMP => ":902B6A44" ADS removed successfully.
C:\ProgramData\TEMP => ":902C848D" ADS removed successfully.
C:\ProgramData\TEMP => ":908A1B53" ADS removed successfully.
C:\ProgramData\TEMP => ":9124663C" ADS removed successfully.
C:\ProgramData\TEMP => ":9195103F" ADS removed successfully.
C:\ProgramData\TEMP => ":91A1C0FC" ADS removed successfully.
C:\ProgramData\TEMP => ":91CF76E3" ADS removed successfully.
C:\ProgramData\TEMP => ":91FE43FF" ADS removed successfully.
C:\ProgramData\TEMP => ":922DA2DB" ADS removed successfully.
C:\ProgramData\TEMP => ":926B6E7A" ADS removed successfully.
C:\ProgramData\TEMP => ":927EC486" ADS removed successfully.
C:\ProgramData\TEMP => ":928DF32E" ADS removed successfully.
C:\ProgramData\TEMP => ":92BD9737" ADS removed successfully.
C:\ProgramData\TEMP => ":92D18A5E" ADS removed successfully.
C:\ProgramData\TEMP => ":92D35C13" ADS removed successfully.
C:\ProgramData\TEMP => ":938EB9FC" ADS removed successfully.
C:\ProgramData\TEMP => ":943971F5" ADS removed successfully.
C:\ProgramData\TEMP => ":94874C0A" ADS removed successfully.
C:\ProgramData\TEMP => ":9491C9C7" ADS removed successfully.
C:\ProgramData\TEMP => ":94B25DF5" ADS removed successfully.
C:\ProgramData\TEMP => ":94B46CA2" ADS removed successfully.
C:\ProgramData\TEMP => ":95198126" ADS removed successfully.
C:\ProgramData\TEMP => ":952245B1" ADS removed successfully.
C:\ProgramData\TEMP => ":9524D821" ADS removed successfully.
C:\ProgramData\TEMP => ":953FDC1A" ADS removed successfully.
C:\ProgramData\TEMP => ":956EC010" ADS removed successfully.
C:\ProgramData\TEMP => ":9597EAFE" ADS removed successfully.
C:\ProgramData\TEMP => ":95D421DF" ADS removed successfully.
C:\ProgramData\TEMP => ":961B4D58" ADS removed successfully.
C:\ProgramData\TEMP => ":961B84C5" ADS removed successfully.
C:\ProgramData\TEMP => ":96372A73" ADS removed successfully.
C:\ProgramData\TEMP => ":96646EC1" ADS removed successfully.
C:\ProgramData\TEMP => ":96838F8A" ADS removed successfully.
C:\ProgramData\TEMP => ":968F624D" ADS removed successfully.
C:\ProgramData\TEMP => ":96F8F8AB" ADS removed successfully.
C:\ProgramData\TEMP => ":971DCCE2" ADS removed successfully.
C:\ProgramData\TEMP => ":9720EBEF" ADS removed successfully.
C:\ProgramData\TEMP => ":97AAB7F2" ADS removed successfully.
C:\ProgramData\TEMP => ":97B3B270" ADS removed successfully.
C:\ProgramData\TEMP => ":97BDBF49" ADS removed successfully.
C:\ProgramData\TEMP => ":97CA3B9E" ADS removed successfully.
C:\ProgramData\TEMP => ":98104906" ADS removed successfully.
C:\ProgramData\TEMP => ":981456CB" ADS removed successfully.
C:\ProgramData\TEMP => ":9825B52E" ADS removed successfully.
C:\ProgramData\TEMP => ":9836B5E4" ADS removed successfully.
C:\ProgramData\TEMP => ":983B4DC0" ADS removed successfully.
C:\ProgramData\TEMP => ":98BD93BF" ADS removed successfully.
C:\ProgramData\TEMP => ":991283D0" ADS removed successfully.
C:\ProgramData\TEMP => ":993185CB" ADS removed successfully.
C:\ProgramData\TEMP => ":99B20AD0" ADS removed successfully.
C:\ProgramData\TEMP => ":9A2A9D24" ADS removed successfully.
C:\ProgramData\TEMP => ":9AC8424E" ADS removed successfully.
C:\ProgramData\TEMP => ":9B0F9E15" ADS removed successfully.
C:\ProgramData\TEMP => ":9B3291FE" ADS removed successfully.
C:\ProgramData\TEMP => ":9B750A13" ADS removed successfully.
C:\ProgramData\TEMP => ":9BB8C675" ADS removed successfully.
C:\ProgramData\TEMP => ":9C012695" ADS removed successfully.
C:\ProgramData\TEMP => ":9C3AAD57" ADS removed successfully.
C:\ProgramData\TEMP => ":9C504A4D" ADS removed successfully.
C:\ProgramData\TEMP => ":9C7A32BB" ADS removed successfully.
C:\ProgramData\TEMP => ":9CE870B8" ADS removed successfully.
C:\ProgramData\TEMP => ":9CF728A6" ADS removed successfully.
C:\ProgramData\TEMP => ":9D06FB9C" ADS removed successfully.
C:\ProgramData\TEMP => ":9D2DE4B4" ADS removed successfully.
C:\ProgramData\TEMP => ":9D3C27E1" ADS removed successfully.
C:\ProgramData\TEMP => ":9D6EAEC3" ADS removed successfully.
C:\ProgramData\TEMP => ":9D91E651" ADS removed successfully.
C:\ProgramData\TEMP => ":9E5EA7A3" ADS removed successfully.
C:\ProgramData\TEMP => ":9EBE2014" ADS removed successfully.
C:\ProgramData\TEMP => ":9EE6560D" ADS removed successfully.
C:\ProgramData\TEMP => ":9F50A55A" ADS removed successfully.
C:\ProgramData\TEMP => ":9F81E94D" ADS removed successfully.
C:\ProgramData\TEMP => ":9FB6814A" ADS removed successfully.
C:\ProgramData\TEMP => ":9FCF32A8" ADS removed successfully.
C:\ProgramData\TEMP => ":9FD757A9" ADS removed successfully.
C:\ProgramData\TEMP => ":A015B193" ADS removed successfully.
C:\ProgramData\TEMP => ":A01F3A87" ADS removed successfully.
C:\ProgramData\TEMP => ":A039EDF9" ADS removed successfully.
C:\ProgramData\TEMP => ":A0921B2C" ADS removed successfully.
C:\ProgramData\TEMP => ":A1023D41" ADS removed successfully.
C:\ProgramData\TEMP => ":A10E88DE" ADS removed successfully.
C:\ProgramData\TEMP => ":A1460B2A" ADS removed successfully.
C:\ProgramData\TEMP => ":A1A86E40" ADS removed successfully.
C:\ProgramData\TEMP => ":A1FD5369" ADS removed successfully.
C:\ProgramData\TEMP => ":A243178D" ADS removed successfully.
C:\ProgramData\TEMP => ":A26AFC00" ADS removed successfully.
C:\ProgramData\TEMP => ":A26C6E72" ADS removed successfully.
C:\ProgramData\TEMP => ":A291068E" ADS removed successfully.
C:\ProgramData\TEMP => ":A3840F5B" ADS removed successfully.
C:\ProgramData\TEMP => ":A391510C" ADS removed successfully.
C:\ProgramData\TEMP => ":A3B8F70C" ADS removed successfully.
C:\ProgramData\TEMP => ":A3E0A552" ADS removed successfully.
C:\ProgramData\TEMP => ":A42B5698" ADS removed successfully.
C:\ProgramData\TEMP => ":A43B789A" ADS removed successfully.
C:\ProgramData\TEMP => ":A43EC514" ADS removed successfully.
C:\ProgramData\TEMP => ":A441D13F" ADS removed successfully.
C:\ProgramData\TEMP => ":A479BCC9" ADS removed successfully.
C:\ProgramData\TEMP => ":A4AF8D0D" ADS removed successfully.
C:\ProgramData\TEMP => ":A4B4192F" ADS removed successfully.
C:\ProgramData\TEMP => ":A4E7D25F" ADS removed successfully.
C:\ProgramData\TEMP => ":A5241382" ADS removed successfully.
C:\ProgramData\TEMP => ":A5256831" ADS removed successfully.
C:\ProgramData\TEMP => ":A52D07E2" ADS removed successfully.
C:\ProgramData\TEMP => ":A5584049" ADS removed successfully.
C:\ProgramData\TEMP => ":A57239FA" ADS removed successfully.
C:\ProgramData\TEMP => ":A6345BDA" ADS removed successfully.
C:\ProgramData\TEMP => ":A6346EE9" ADS removed successfully.
C:\ProgramData\TEMP => ":A69FAA24" ADS removed successfully.
C:\ProgramData\TEMP => ":A6D6E537" ADS removed successfully.
C:\ProgramData\TEMP => ":A6D89509" ADS removed successfully.
C:\ProgramData\TEMP => ":A6F28514" ADS removed successfully.
C:\ProgramData\TEMP => ":A6F30843" ADS removed successfully.
C:\ProgramData\TEMP => ":A6FE7BCC" ADS removed successfully.
C:\ProgramData\TEMP => ":A724744F" ADS removed successfully.
C:\ProgramData\TEMP => ":A78B31DD" ADS removed successfully.
C:\ProgramData\TEMP => ":A7CC0E50" ADS removed successfully.
C:\ProgramData\TEMP => ":A819A132" ADS removed successfully.
C:\ProgramData\TEMP => ":A81F86C8" ADS removed successfully.
C:\ProgramData\TEMP => ":A8369371" ADS removed successfully.
C:\ProgramData\TEMP => ":A851461E" ADS removed successfully.
C:\ProgramData\TEMP => ":A88BE334" ADS removed successfully.
C:\ProgramData\TEMP => ":A899E64E" ADS removed successfully.
C:\ProgramData\TEMP => ":A8A0D7A2" ADS removed successfully.
C:\ProgramData\TEMP => ":A8ADEA55" ADS removed successfully.
C:\ProgramData\TEMP => ":A8DFD30C" ADS removed successfully.
C:\ProgramData\TEMP => ":A900C3A3" ADS removed successfully.
C:\ProgramData\TEMP => ":A93CBF2B" ADS removed successfully.
C:\ProgramData\TEMP => ":A967571A" ADS removed successfully.
C:\ProgramData\TEMP => ":A99C1C81" ADS removed successfully.
C:\ProgramData\TEMP => ":A9F13D2D" ADS removed successfully.
C:\ProgramData\TEMP => ":AA0017FD" ADS removed successfully.
C:\ProgramData\TEMP => ":AA0BC725" ADS removed successfully.
C:\ProgramData\TEMP => ":AA5A61B2" ADS removed successfully.
C:\ProgramData\TEMP => ":AA6CA4C7" ADS removed successfully.
C:\ProgramData\TEMP => ":AA7BE830" ADS removed successfully.
C:\ProgramData\TEMP => ":AABECEFB" ADS removed successfully.
C:\ProgramData\TEMP => ":AB3339EF" ADS removed successfully.
C:\ProgramData\TEMP => ":AB501812" ADS removed successfully.
C:\ProgramData\TEMP => ":AB554F94" ADS removed successfully.
C:\ProgramData\TEMP => ":ABBFFEA2" ADS removed successfully.
C:\ProgramData\TEMP => ":AC57032B" ADS removed successfully.
C:\ProgramData\TEMP => ":ACB38255" ADS removed successfully.
C:\ProgramData\TEMP => ":AD020DC3" ADS removed successfully.
C:\ProgramData\TEMP => ":AD179392" ADS removed successfully.
C:\ProgramData\TEMP => ":ADEBE9CA" ADS removed successfully.
C:\ProgramData\TEMP => ":AE0B4487" ADS removed successfully.
C:\ProgramData\TEMP => ":AE324BE5" ADS removed successfully.
C:\ProgramData\TEMP => ":AE34D87E" ADS removed successfully.
C:\ProgramData\TEMP => ":AE47FDED" ADS removed successfully.
C:\ProgramData\TEMP => ":AE8D8202" ADS removed successfully.
C:\ProgramData\TEMP => ":AE9351E0" ADS removed successfully.
C:\ProgramData\TEMP => ":AEA33452" ADS removed successfully.
C:\ProgramData\TEMP => ":AEBC40EC" ADS removed successfully.
C:\ProgramData\TEMP => ":AECF4772" ADS removed successfully.
C:\ProgramData\TEMP => ":AED4A2B7" ADS removed successfully.
C:\ProgramData\TEMP => ":AF191C57" ADS removed successfully.
C:\ProgramData\TEMP => ":AF2F9D4A" ADS removed successfully.
C:\ProgramData\TEMP => ":AFB89C92" ADS removed successfully.
C:\ProgramData\TEMP => ":AFFA972E" ADS removed successfully.
C:\ProgramData\TEMP => ":B02249C3" ADS removed successfully.
C:\ProgramData\TEMP => ":B0456F0C" ADS removed successfully.
C:\ProgramData\TEMP => ":B0729CDB" ADS removed successfully.
C:\ProgramData\TEMP => ":B097AC8A" ADS removed successfully.
C:\ProgramData\TEMP => ":B0EA26E5" ADS removed successfully.
C:\ProgramData\TEMP => ":B1381B34" ADS removed successfully.
C:\ProgramData\TEMP => ":B190BE3A" ADS removed successfully.
C:\ProgramData\TEMP => ":B1E64E47" ADS removed successfully.
C:\ProgramData\TEMP => ":B2112128" ADS removed successfully.
C:\ProgramData\TEMP => ":B21F2857" ADS removed successfully.
C:\ProgramData\TEMP => ":B2D32F1D" ADS removed successfully.
C:\ProgramData\TEMP => ":B2DC8D6B" ADS removed successfully.
C:\ProgramData\TEMP => ":B310C233" ADS removed successfully.
C:\ProgramData\TEMP => ":B317D7ED" ADS removed successfully.
C:\ProgramData\TEMP => ":B3196E8D" ADS removed successfully.
C:\ProgramData\TEMP => ":B33464A5" ADS removed successfully.
C:\ProgramData\TEMP => ":B38BEEEE" ADS removed successfully.
C:\ProgramData\TEMP => ":B3A5945E" ADS removed successfully.
C:\ProgramData\TEMP => ":B3A7E7F8" ADS removed successfully.
C:\ProgramData\TEMP => ":B3C7433B" ADS removed successfully.
C:\ProgramData\TEMP => ":B47A7270" ADS removed successfully.
C:\ProgramData\TEMP => ":B4980368" ADS removed successfully.
C:\ProgramData\TEMP => ":B4F0E275" ADS removed successfully.
C:\ProgramData\TEMP => ":B4F7687B" ADS removed successfully.
C:\ProgramData\TEMP => ":B51B45A3" ADS removed successfully.
C:\ProgramData\TEMP => ":B5FD4AA1" ADS removed successfully.
C:\ProgramData\TEMP => ":B652B720" ADS removed successfully.
C:\ProgramData\TEMP => ":B6E58523" ADS removed successfully.
C:\ProgramData\TEMP => ":B723C5EF" ADS removed successfully.
C:\ProgramData\TEMP => ":B790962B" ADS removed successfully.
C:\ProgramData\TEMP => ":B80659FA" ADS removed successfully.
C:\ProgramData\TEMP => ":B8EA2C49" ADS removed successfully.
C:\ProgramData\TEMP => ":B8EB1B99" ADS removed successfully.
C:\ProgramData\TEMP => ":B9775780" ADS removed successfully.
C:\ProgramData\TEMP => ":BACC4A79" ADS removed successfully.
C:\ProgramData\TEMP => ":BAFAD1DF" ADS removed successfully.
C:\ProgramData\TEMP => ":BB718C46" ADS removed successfully.
C:\ProgramData\TEMP => ":BB99F46B" ADS removed successfully.
C:\ProgramData\TEMP => ":BC521608" ADS removed successfully.
C:\ProgramData\TEMP => ":BC593DD5" ADS removed successfully.
C:\ProgramData\TEMP => ":BCAB37A9" ADS removed successfully.
C:\ProgramData\TEMP => ":BCF55336" ADS removed successfully.
C:\ProgramData\TEMP => ":BD34FFC5" ADS removed successfully.
C:\ProgramData\TEMP => ":BDDA21B6" ADS removed successfully.
C:\ProgramData\TEMP => ":BE0654D6" ADS removed successfully.
C:\ProgramData\TEMP => ":BE3D639A" ADS removed successfully.
C:\ProgramData\TEMP => ":BE40B295" ADS removed successfully.
C:\ProgramData\TEMP => ":BE64143E" ADS removed successfully.
C:\ProgramData\TEMP => ":BE6B5FC3" ADS removed successfully.
C:\ProgramData\TEMP => ":BE6DC701" ADS removed successfully.
C:\ProgramData\TEMP => ":BEACE4C8" ADS removed successfully.
C:\ProgramData\TEMP => ":BEF18713" ADS removed successfully.
C:\ProgramData\TEMP => ":BF1E0621" ADS removed successfully.
C:\ProgramData\TEMP => ":BF4BA1F5" ADS removed successfully.
C:\ProgramData\TEMP => ":BF640EE5" ADS removed successfully.
C:\ProgramData\TEMP => ":BF6A2C54" ADS removed successfully.
C:\ProgramData\TEMP => ":BF6C4AAC" ADS removed successfully.
C:\ProgramData\TEMP => ":BF6C81B2" ADS removed successfully.
C:\ProgramData\TEMP => ":C0893153" ADS removed successfully.
C:\ProgramData\TEMP => ":C0913157" ADS removed successfully.
C:\ProgramData\TEMP => ":C0A9B815" ADS removed successfully.
C:\ProgramData\TEMP => ":C0D23A2F" ADS removed successfully.
C:\ProgramData\TEMP => ":C178954A" ADS removed successfully.
C:\ProgramData\TEMP => ":C18032C3" ADS removed successfully.
C:\ProgramData\TEMP => ":C1C3561E" ADS removed successfully.
C:\ProgramData\TEMP => ":C1D3D9A3" ADS removed successfully.
C:\ProgramData\TEMP => ":C1DBE635" ADS removed successfully.
C:\ProgramData\TEMP => ":C22B6EED" ADS removed successfully.
C:\ProgramData\TEMP => ":C26A6AB3" ADS removed successfully.
C:\ProgramData\TEMP => ":C2F24DB5" ADS removed successfully.
C:\ProgramData\TEMP => ":C2F43053" ADS removed successfully.
C:\ProgramData\TEMP => ":C30487EE" ADS removed successfully.
C:\ProgramData\TEMP => ":C356A185" ADS removed successfully.
C:\ProgramData\TEMP => ":C368C9EA" ADS removed successfully.
C:\ProgramData\TEMP => ":C36D0DFD" ADS removed successfully.
C:\ProgramData\TEMP => ":C37283B5" ADS removed successfully.
C:\ProgramData\TEMP => ":C3A047E3" ADS removed successfully.
C:\ProgramData\TEMP => ":C3AD9507" ADS removed successfully.
C:\ProgramData\TEMP => ":C3B04546" ADS removed successfully.
C:\ProgramData\TEMP => ":C3E7F2E9" ADS removed successfully.
C:\ProgramData\TEMP => ":C44E62F1" ADS removed successfully.
C:\ProgramData\TEMP => ":C48905F4" ADS removed successfully.
C:\ProgramData\TEMP => ":C4967F48" ADS removed successfully.
C:\ProgramData\TEMP => ":C4A88D6B" ADS removed successfully.
C:\ProgramData\TEMP => ":C5340FA1" ADS removed successfully.
C:\ProgramData\TEMP => ":C54A1A57" ADS removed successfully.
C:\ProgramData\TEMP => ":C5A156B6" ADS removed successfully.
C:\ProgramData\TEMP => ":C5D15631" ADS removed successfully.
C:\ProgramData\TEMP => ":C5DC2B0C" ADS removed successfully.
C:\ProgramData\TEMP => ":C66222F3" ADS removed successfully.
C:\ProgramData\TEMP => ":C67CB31A" ADS removed successfully.
C:\ProgramData\TEMP => ":C6920A5D" ADS removed successfully.
C:\ProgramData\TEMP => ":C7517D0A" ADS removed successfully.
C:\ProgramData\TEMP => ":C76CFF82" ADS removed successfully.
C:\ProgramData\TEMP => ":C7D35E8C" ADS removed successfully.
C:\ProgramData\TEMP => ":C7F08EA3" ADS removed successfully.
C:\ProgramData\TEMP => ":C82210DD" ADS removed successfully.
C:\ProgramData\TEMP => ":C82CA1C0" ADS removed successfully.
C:\ProgramData\TEMP => ":C8E3A625" ADS removed successfully.
C:\ProgramData\TEMP => ":C8E9D804" ADS removed successfully.
C:\ProgramData\TEMP => ":C98828D3" ADS removed successfully.
C:\ProgramData\TEMP => ":C9B27A06" ADS removed successfully.
C:\ProgramData\TEMP => ":CA1AFE85" ADS removed successfully.
C:\ProgramData\TEMP => ":CA23BCFD" ADS removed successfully.
C:\ProgramData\TEMP => ":CA400C1B" ADS removed successfully.
C:\ProgramData\TEMP => ":CAE3AE67" ADS removed successfully.
C:\ProgramData\TEMP => ":CB08ED9D" ADS removed successfully.
C:\ProgramData\TEMP => ":CB299F13" ADS removed successfully.
C:\ProgramData\TEMP => ":CB3667AF" ADS removed successfully.
C:\ProgramData\TEMP => ":CB5AA1E6" ADS removed successfully.
C:\ProgramData\TEMP => ":CB959782" ADS removed successfully.
C:\ProgramData\TEMP => ":CBAF0C30" ADS removed successfully.
C:\ProgramData\TEMP => ":CC141B05" ADS removed successfully.
C:\ProgramData\TEMP => ":CCD8056E" ADS removed successfully.
C:\ProgramData\TEMP => ":CDCDE97C" ADS removed successfully.
C:\ProgramData\TEMP => ":CE3AADB7" ADS removed successfully.
C:\ProgramData\TEMP => ":CE506F23" ADS removed successfully.
C:\ProgramData\TEMP => ":CE8A42A3" ADS removed successfully.
C:\ProgramData\TEMP => ":CEF2A14E" ADS removed successfully.
C:\ProgramData\TEMP => ":CF2C26D2" ADS removed successfully.
C:\ProgramData\TEMP => ":CF5ECDE7" ADS removed successfully.
C:\ProgramData\TEMP => ":CFA8C6E3" ADS removed successfully.
C:\ProgramData\TEMP => ":D0005E5A" ADS removed successfully.
C:\ProgramData\TEMP => ":D0149AB4" ADS removed successfully.
C:\ProgramData\TEMP => ":D01ACC06" ADS removed successfully.
C:\ProgramData\TEMP => ":D026A5A4" ADS removed successfully.
C:\ProgramData\TEMP => ":D03C22B4" ADS removed successfully.
C:\ProgramData\TEMP => ":D0570058" ADS removed successfully.
C:\ProgramData\TEMP => ":D05E7A8B" ADS removed successfully.
C:\ProgramData\TEMP => ":D086B88D" ADS removed successfully.
C:\ProgramData\TEMP => ":D103E81E" ADS removed successfully.
C:\ProgramData\TEMP => ":D115F6E4" ADS removed successfully.
C:\ProgramData\TEMP => ":D1361E51" ADS removed successfully.
C:\ProgramData\TEMP => ":D1787194" ADS removed successfully.
C:\ProgramData\TEMP => ":D1D597D0" ADS removed successfully.
C:\ProgramData\TEMP => ":D1D63BCA" ADS removed successfully.
C:\ProgramData\TEMP => ":D2593961" ADS removed successfully.
C:\ProgramData\TEMP => ":D26B6B0A" ADS removed successfully.
C:\ProgramData\TEMP => ":D2C44806" ADS removed successfully.
C:\ProgramData\TEMP => ":D3331ADB" ADS removed successfully.
C:\ProgramData\TEMP => ":D3930F74" ADS removed successfully.
C:\ProgramData\TEMP => ":D3A82449" ADS removed successfully.
C:\ProgramData\TEMP => ":D434342F" ADS removed successfully.
C:\ProgramData\TEMP => ":D43ACD11" ADS removed successfully.
C:\ProgramData\TEMP => ":D4558A0B" ADS removed successfully.
C:\ProgramData\TEMP => ":D47B19A6" ADS removed successfully.
C:\ProgramData\TEMP => ":D48500F8" ADS removed successfully.
C:\ProgramData\TEMP => ":D576A536" ADS removed successfully.
C:\ProgramData\TEMP => ":D5CCCBAA" ADS removed successfully.
C:\ProgramData\TEMP => ":D5D75FF0" ADS removed successfully.
C:\ProgramData\TEMP => ":D61EB62D" ADS removed successfully.
C:\ProgramData\TEMP => ":D621CFB8" ADS removed successfully.
C:\ProgramData\TEMP => ":D64467B5" ADS removed successfully.
C:\ProgramData\TEMP => ":D64DD961" ADS removed successfully.
C:\ProgramData\TEMP => ":D72D7897" ADS removed successfully.
C:\ProgramData\TEMP => ":D74C2847" ADS removed successfully.
C:\ProgramData\TEMP => ":D750EF68" ADS removed successfully.
C:\ProgramData\TEMP => ":D770A15D" ADS removed successfully.
C:\ProgramData\TEMP => ":D7740E2A" ADS removed successfully.
C:\ProgramData\TEMP => ":D7B7645F" ADS removed successfully.
C:\ProgramData\TEMP => ":D7C0213D" ADS removed successfully.
C:\ProgramData\TEMP => ":D7D0B4AF" ADS removed successfully.
C:\ProgramData\TEMP => ":D7DA89B1" ADS removed successfully.
C:\ProgramData\TEMP => ":D7F8D8A2" ADS removed successfully.
C:\ProgramData\TEMP => ":D82A9FCF" ADS removed successfully.
C:\ProgramData\TEMP => ":D8AE9DD1" ADS removed successfully.
C:\ProgramData\TEMP => ":D8EA2847" ADS removed successfully.
C:\ProgramData\TEMP => ":D9089E64" ADS removed successfully.
C:\ProgramData\TEMP => ":D92485C9" ADS removed successfully.
C:\ProgramData\TEMP => ":D9592966" ADS removed successfully.
C:\ProgramData\TEMP => ":D9656460" ADS removed successfully.
C:\ProgramData\TEMP => ":D9771F40" ADS removed successfully.
C:\ProgramData\TEMP => ":D987CB43" ADS removed successfully.
C:\ProgramData\TEMP => ":D9F34335" ADS removed successfully.
C:\ProgramData\TEMP => ":DA3C6C07" ADS removed successfully.
C:\ProgramData\TEMP => ":DA55B48C" ADS removed successfully.
C:\ProgramData\TEMP => ":DA7655EA" ADS removed successfully.
C:\ProgramData\TEMP => ":DA9A88B3" ADS removed successfully.
C:\ProgramData\TEMP => ":DAB09BDB" ADS removed successfully.
C:\ProgramData\TEMP => ":DB2748F7" ADS removed successfully.
C:\ProgramData\TEMP => ":DB76C881" ADS removed successfully.
C:\ProgramData\TEMP => ":DBB979D4" ADS removed successfully.
C:\ProgramData\TEMP => ":DBEF355E" ADS removed successfully.
C:\ProgramData\TEMP => ":DC0B1070" ADS removed successfully.
C:\ProgramData\TEMP => ":DC7EDF41" ADS removed successfully.
C:\ProgramData\TEMP => ":DCA79AB3" ADS removed successfully.
C:\ProgramData\TEMP => ":DCB27118" ADS removed successfully.
C:\ProgramData\TEMP => ":DCDE7C60" ADS removed successfully.
C:\ProgramData\TEMP => ":DD874E14" ADS removed successfully.
C:\ProgramData\TEMP => ":DD95E6D9" ADS removed successfully.
C:\ProgramData\TEMP => ":DDF112BD" ADS removed successfully.
C:\ProgramData\TEMP => ":DE3ABE3D" ADS removed successfully.
C:\ProgramData\TEMP => ":DE875C30" ADS removed successfully.
C:\ProgramData\TEMP => ":DEDAEF90" ADS removed successfully.
C:\ProgramData\TEMP => ":DF0DB8AB" ADS removed successfully.
C:\ProgramData\TEMP => ":DFB61534" ADS removed successfully.
C:\ProgramData\TEMP => ":DFFB9E98" ADS removed successfully.
C:\ProgramData\TEMP => ":E00A6A60" ADS removed successfully.
C:\ProgramData\TEMP => ":E0365B26" ADS removed successfully.
C:\ProgramData\TEMP => ":E06963C0" ADS removed successfully.
C:\ProgramData\TEMP => ":E0848D16" ADS removed successfully.
C:\ProgramData\TEMP => ":E0888117" ADS removed successfully.
C:\ProgramData\TEMP => ":E10DCAF3" ADS removed successfully.
C:\ProgramData\TEMP => ":E11D90D0" ADS removed successfully.
C:\ProgramData\TEMP => ":E14FA16F" ADS removed successfully.
C:\ProgramData\TEMP => ":E153075C" ADS removed successfully.
C:\ProgramData\TEMP => ":E1D06077" ADS removed successfully.
C:\ProgramData\TEMP => ":E21433CE" ADS removed successfully.
C:\ProgramData\TEMP => ":E23BF4AD" ADS removed successfully.
C:\ProgramData\TEMP => ":E2C51D18" ADS removed successfully.
C:\ProgramData\TEMP => ":E2CFA9CD" ADS removed successfully.
C:\ProgramData\TEMP => ":E329D971" ADS removed successfully.
C:\ProgramData\TEMP => ":E32D2701" ADS removed successfully.
C:\ProgramData\TEMP => ":E33D6212" ADS removed successfully.
C:\ProgramData\TEMP => ":E411AA0D" ADS removed successfully.
C:\ProgramData\TEMP => ":E4272706" ADS removed successfully.
C:\ProgramData\TEMP => ":E446CB48" ADS removed successfully.
C:\ProgramData\TEMP => ":E463CA56" ADS removed successfully.
C:\ProgramData\TEMP => ":E495057A" ADS removed successfully.
C:\ProgramData\TEMP => ":E4BC4A41" ADS removed successfully.
C:\ProgramData\TEMP => ":E4E83517" ADS removed successfully.
C:\ProgramData\TEMP => ":E4FD113F" ADS removed successfully.
C:\ProgramData\TEMP => ":E517FE76" ADS removed successfully.
C:\ProgramData\TEMP => ":E5438999" ADS removed successfully.
C:\ProgramData\TEMP => ":E5B07840" ADS removed successfully.
C:\ProgramData\TEMP => ":E60C72DB" ADS removed successfully.
C:\ProgramData\TEMP => ":E6433F27" ADS removed successfully.
C:\ProgramData\TEMP => ":E6708F08" ADS removed successfully.
C:\ProgramData\TEMP => ":E690114B" ADS removed successfully.
C:\ProgramData\TEMP => ":E6B95E40" ADS removed successfully.
C:\ProgramData\TEMP => ":E6BEADB7" ADS removed successfully.
C:\ProgramData\TEMP => ":E6C6EB3B" ADS removed successfully.
C:\ProgramData\TEMP => ":E6CDFB4A" ADS removed successfully.
C:\ProgramData\TEMP => ":E70FD81B" ADS removed successfully.
C:\ProgramData\TEMP => ":E8074E20" ADS removed successfully.
C:\ProgramData\TEMP => ":E81603BC" ADS removed successfully.
C:\ProgramData\TEMP => ":E83EE313" ADS removed successfully.
C:\ProgramData\TEMP => ":E87AB4E3" ADS removed successfully.
C:\ProgramData\TEMP => ":E894A3ED" ADS removed successfully.
C:\ProgramData\TEMP => ":E89EDC52" ADS removed successfully.
C:\ProgramData\TEMP => ":E8AEB2BF" ADS removed successfully.
C:\ProgramData\TEMP => ":E8B61305" ADS removed successfully.
C:\ProgramData\TEMP => ":E8BE0B80" ADS removed successfully.
C:\ProgramData\TEMP => ":E8C44CB4" ADS removed successfully.
C:\ProgramData\TEMP => ":E8C4808B" ADS removed successfully.
C:\ProgramData\TEMP => ":E900132A" ADS removed successfully.
C:\ProgramData\TEMP => ":E94FA418" ADS removed successfully.
C:\ProgramData\TEMP => ":E96A2658" ADS removed successfully.
C:\ProgramData\TEMP => ":E98C5DD9" ADS removed successfully.
C:\ProgramData\TEMP => ":E99D1D3C" ADS removed successfully.
C:\ProgramData\TEMP => ":E9CB5ECC" ADS removed successfully.
C:\ProgramData\TEMP => ":EA10407C" ADS removed successfully.
C:\ProgramData\TEMP => ":EA2D3047" ADS removed successfully.
C:\ProgramData\TEMP => ":EA500268" ADS removed successfully.
C:\ProgramData\TEMP => ":EA7D76BE" ADS removed successfully.
C:\ProgramData\TEMP => ":EA9D8B40" ADS removed successfully.
C:\ProgramData\TEMP => ":EB603FE4" ADS removed successfully.
C:\ProgramData\TEMP => ":EBF0842B" ADS removed successfully.
C:\ProgramData\TEMP => ":EC752217" ADS removed successfully.
C:\ProgramData\TEMP => ":ECF3C50F" ADS removed successfully.
C:\ProgramData\TEMP => ":ED2D63E4" ADS removed successfully.
C:\ProgramData\TEMP => ":ED51D3ED" ADS removed successfully.
C:\ProgramData\TEMP => ":ED6B6C83" ADS removed successfully.
C:\ProgramData\TEMP => ":ED92736E" ADS removed successfully.
C:\ProgramData\TEMP => ":EDB03249" ADS removed successfully.
C:\ProgramData\TEMP => ":EDED3240" ADS removed successfully.
C:\ProgramData\TEMP => ":EDF12A30" ADS removed successfully.
C:\ProgramData\TEMP => ":EE2B5DE3" ADS removed successfully.
C:\ProgramData\TEMP => ":EE2DD6CC" ADS removed successfully.
C:\ProgramData\TEMP => ":EE7AAC75" ADS removed successfully.
C:\ProgramData\TEMP => ":EE9B2879" ADS removed successfully.
C:\ProgramData\TEMP => ":EEB25EAE" ADS removed successfully.
C:\ProgramData\TEMP => ":EEC56B69" ADS removed successfully.
C:\ProgramData\TEMP => ":EEF1584F" ADS removed successfully.
C:\ProgramData\TEMP => ":EF0C5444" ADS removed successfully.
C:\ProgramData\TEMP => ":EF0F3F33" ADS removed successfully.
C:\ProgramData\TEMP => ":EF38B79C" ADS removed successfully.
C:\ProgramData\TEMP => ":EF4B1DA9" ADS removed successfully.
C:\ProgramData\TEMP => ":EFE4FB84" ADS removed successfully.
C:\ProgramData\TEMP => ":EFECABA9" ADS removed successfully.
C:\ProgramData\TEMP => ":EFF3C3C8" ADS removed successfully.
C:\ProgramData\TEMP => ":F0E908D5" ADS removed successfully.
C:\ProgramData\TEMP => ":F1381B87" ADS removed successfully.
C:\ProgramData\TEMP => ":F142DBA9" ADS removed successfully.
C:\ProgramData\TEMP => ":F193BFCF" ADS removed successfully.
C:\ProgramData\TEMP => ":F1F936DF" ADS removed successfully.
C:\ProgramData\TEMP => ":F2327E82" ADS removed successfully.
C:\ProgramData\TEMP => ":F27A649C" ADS removed successfully.
C:\ProgramData\TEMP => ":F2B81C2E" ADS removed successfully.
C:\ProgramData\TEMP => ":F2E92DCD" ADS removed successfully.
C:\ProgramData\TEMP => ":F2EDC57C" ADS removed successfully.
C:\ProgramData\TEMP => ":F2F115B4" ADS removed successfully.
C:\ProgramData\TEMP => ":F30757AC" ADS removed successfully.
C:\ProgramData\TEMP => ":F33C37D5" ADS removed successfully.
C:\ProgramData\TEMP => ":F3591DDB" ADS removed successfully.
C:\ProgramData\TEMP => ":F3A185AE" ADS removed successfully.
C:\ProgramData\TEMP => ":F3A27FDE" ADS removed successfully.
C:\ProgramData\TEMP => ":F3F9AB21" ADS removed successfully.
C:\ProgramData\TEMP => ":F41F8101" ADS removed successfully.
C:\ProgramData\TEMP => ":F4362715" ADS removed successfully.
C:\ProgramData\TEMP => ":F52DB269" ADS removed successfully.
C:\ProgramData\TEMP => ":F53B274A" ADS removed successfully.
C:\ProgramData\TEMP => ":F5B51004" ADS removed successfully.
C:\ProgramData\TEMP => ":F5E90ED3" ADS removed successfully.
C:\ProgramData\TEMP => ":F5FC5DCE" ADS removed successfully.
C:\ProgramData\TEMP => ":F610C203" ADS removed successfully.
C:\ProgramData\TEMP => ":F65A2273" ADS removed successfully.
C:\ProgramData\TEMP => ":F663BB74" ADS removed successfully.
C:\ProgramData\TEMP => ":F67947AF" ADS removed successfully.
C:\ProgramData\TEMP => ":F6910DB1" ADS removed successfully.
C:\ProgramData\TEMP => ":F6A0889A" ADS removed successfully.
C:\ProgramData\TEMP => ":F6DA3F39" ADS removed successfully.
C:\ProgramData\TEMP => ":F6E5C7FB" ADS removed successfully.
C:\ProgramData\TEMP => ":F7BF538D" ADS removed successfully.
C:\ProgramData\TEMP => ":F7F4DC88" ADS removed successfully.
C:\ProgramData\TEMP => ":F888E36D" ADS removed successfully.
C:\ProgramData\TEMP => ":F8A53745" ADS removed successfully.
C:\ProgramData\TEMP => ":F8C2E3B9" ADS removed successfully.
C:\ProgramData\TEMP => ":F8DE80DB" ADS removed successfully.
C:\ProgramData\TEMP => ":F8F070C2" ADS removed successfully.
C:\ProgramData\TEMP => ":F94DE3B1" ADS removed successfully.
C:\ProgramData\TEMP => ":FA09FC72" ADS removed successfully.
C:\ProgramData\TEMP => ":FA42DF8E" ADS removed successfully.
C:\ProgramData\TEMP => ":FA7EAF8F" ADS removed successfully.
C:\ProgramData\TEMP => ":FAB64002" ADS removed successfully.
C:\ProgramData\TEMP => ":FB08C210" ADS removed successfully.
C:\ProgramData\TEMP => ":FB384C06" ADS removed successfully.
C:\ProgramData\TEMP => ":FB65A4AA" ADS removed successfully.
C:\ProgramData\TEMP => ":FB71A279" ADS removed successfully.
C:\ProgramData\TEMP => ":FB9F749F" ADS removed successfully.
C:\ProgramData\TEMP => ":FBA79096" ADS removed successfully.
C:\ProgramData\TEMP => ":FC4B020F" ADS removed successfully.
C:\ProgramData\TEMP => ":FC60E0F8" ADS removed successfully.
C:\ProgramData\TEMP => ":FC8FFA4E" ADS removed successfully.
C:\ProgramData\TEMP => ":FCBEDCFD" ADS removed successfully.
C:\ProgramData\TEMP => ":FCE69FCE" ADS removed successfully.
C:\ProgramData\TEMP => ":FD32FD25" ADS removed successfully.
C:\ProgramData\TEMP => ":FD444D31" ADS removed successfully.
C:\ProgramData\TEMP => ":FD646198" ADS removed successfully.
C:\ProgramData\TEMP => ":FD6DB82C" ADS removed successfully.
C:\ProgramData\TEMP => ":FD786DCA" ADS removed successfully.
C:\ProgramData\TEMP => ":FD7DCDA6" ADS removed successfully.
C:\ProgramData\TEMP => ":FE4E15B1" ADS removed successfully.
C:\ProgramData\TEMP => ":FEE00EB9" ADS removed successfully.
C:\ProgramData\TEMP => ":FEF0DEE7" ADS removed successfully.
C:\ProgramData\TEMP => ":FF818E2B" ADS removed successfully.
C:\ProgramData\TEMP => ":FF8F1AE3" ADS removed successfully.
C:\ProgramData\TEMP => ":FF9C44FE" ADS removed successfully.
C:\ProgramData\TEMP => ":FFD58FFB" ADS removed successfully.
"HKCU\SOFTWARE\Policies\Google" => Key deleted successfully.
"HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\jhbbmmgbnjalccamlaefhepnajfmgopb" => Key deleted successfully.
C:\Users\Chrissy\AppData\Local\CRE\jhbbmmgbnjalccamlaefhepnajfmgopb.crx => Moved successfully.
"HKCU\SOFTWARE\Google\Chrome\Extensions\jhbbmmgbnjalccamlaefhepnajfmgopb" => Key deleted successfully.
"C:\Users\Chrissy\AppData\Local\CRE\jhbbmmgbnjalccamlaefhepnajfmgopb.crx" => File/Directory not found.
Chrome StartupUrls deleted successfully.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{7F1288EA-E0DE-4E28-AA5A-6E58FDCD67CE}" => Key deleted successfully.
"HKCR\CLSID\{7F1288EA-E0DE-4E28-AA5A-6E58FDCD67CE}" => Key not found.
"HKCU\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{444B13D6-001A-4710-8DF6-8B105BC6C33D}" => Key deleted successfully.
"HKCR\CLSID\{444B13D6-001A-4710-8DF6-8B105BC6C33D}" => Key not found.
HKLM\Software\Wow6432Node\Microsoft\Internet Explorer\Main\\Start Page => Value was restored successfully.
EmptyTemp: => Removed 800.4 MB temporary data.


The system needed a reboot. 

==== End of Fixlog ====


#6 Dizzy24

Dizzy24
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Baltimore
  • Local time:11:30 PM

Posted 25 October 2014 - 02:54 PM

I figured I would check with you since I have not heard anything back after the fixlog.txt 

Is everything good now? Everything clean?



#7 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:05:30 AM

Posted 29 October 2014 - 02:50 AM

Hi Dizzy24,

 

Marius is not available at the moment, so I will work with you from now on. Please post back with a fresh FRST logfile and tell me how the system is running.


regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#8 Dizzy24

Dizzy24
  • Topic Starter

  • Members
  • 6 posts
  • OFFLINE
  •  
  • Gender:Female
  • Location:Baltimore
  • Local time:11:30 PM

Posted 30 October 2014 - 11:00 AM

Schrauber,

 

The system has been running fine since the last steps that Marius had given me. I have not noticed any further issues with redirects on websites and it seems to be running smoothly. 

Here is the new frst file 

Scan result of Farbar Recovery Scan Tool (FRST.txt) (x64) Version: 30-10-2014
Ran by Chrissy (administrator) on HOME on 30-10-2014 11:55:51
Running from C:\Users\Chrissy\Downloads
Loaded Profile: Chrissy (Available profiles: Chrissy & Brian)
Platform: Windows 7 Professional Service Pack 1 (X64) OS Language: English (United States)
Internet Explorer Version 11
Boot Mode: Normal
Tutorial for Farbar Recovery Scan Tool: http://www.geekstogo.com/forum/topic/335081-frst-tutorial-how-to-use-farbar-recovery-scan-tool/

==================== Processes (Whitelisted) =================

(If an entry is included in the fixlist, the process will be closed. The file will not be moved.)

(AMD) C:\Windows\System32\atiesrxx.exe
(AMD) C:\Windows\System32\atieclxx.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DockLogin.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\AvastSvc.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Adobe\Photoshop Elements 7.0\PhotoshopElementsFileAgent.exe
(Andrea Electronics Corporation) C:\Program Files\Realtek\Audio\HDA\AERTSr64.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe
(Apple Inc.) C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
(Samsung) C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkDMS.exe
(Apple Inc.) C:\Program Files\Bonjour\mDNSResponder.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe
(Microsoft Corporation) C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe
(Realtek Semiconductor) C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
(Coupons.com Inc.) C:\Program Files (x86)\Coupons\CouponPrinterService.exe
() C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe
() C:\Windows\System32\spool\drivers\x64\3\dleaserv.exe
() C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe
(Logitech, Inc.) C:\Program Files\Logitech\SetPoint\SetPoint.exe
(Creative Technology Ltd.) C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe
(Stardock Corporation) C:\Program Files\Dell\DellDock\DellDock.exe
(Advanced Micro Devices Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
(AVAST Software) C:\Program Files\AVAST Software\Avast\avastui.exe
(ArcSoft Inc.) C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ArcCon.ac
(SupportSoft, Inc.) C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Copyright 2013 SAMSUNG) C:\Program Files\Samsung\Samsung Link\Samsung Link.exe
(Adobe Systems Incorporated) C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe
(Apple Inc.) C:\Program Files (x86)\iTunes\iTunesHelper.exe
() C:\Program Files\Logitech\SetPoint\x86\SetPoint32.exe
(SoftThinks) C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe
(Logitech, Inc.) C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.exe
(SupportSoft, Inc.) C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe
(TeamViewer GmbH) C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
(SupportSoft, Inc.) C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
(ATI Technologies Inc.) C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
(Microsoft Corp.) C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVCM.EXE
(Apple Inc.) C:\Program Files\iPod\bin\iPodService.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
() C:\Program Files (x86)\bfgclient\bfgclient.exe
() C:\Program Files (x86)\bfgclient\bfgclient.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Google Inc.) C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Microsoft Corporation) C:\Windows\System32\dllhost.exe
(Farbar) C:\Users\Chrissy\Downloads\FRST64 (2).exe


==================== Registry (Whitelisted) ==================

(If an entry is included in the fixlist, the registry item will be restored to default or removed. The file will not be moved.)

HKLM\...\Run: [RtHDVCpl] => C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe [7834656 2009-06-02] (Realtek Semiconductor)
HKLM\...\Run: [dleamon.exe] => C:\Program Files (x86)\Dell V310-V510 Series\dleamon.exe [770728 2010-01-18] ()
HKLM\...\Run: [EzPrint] => C:\Program Files (x86)\Dell V310-V510 Series\ezprint.exe [139944 2010-01-18] ()
HKLM\...\Run: [Kernel and Hardware Abstraction Layer] => C:\Windows\KHALMNPR.EXE [130576 2009-06-17] (Logitech, Inc.)
HKLM-x32\...\Run: [StartCCC] => C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe [98304 2009-06-14] (Advanced Micro Devices, Inc.)
HKLM-x32\...\Run: [Dell Webcam Central] => C:\Program Files (x86)\Dell Webcam\Dell Webcam Central\WebcamDell.exe [442536 2008-11-11] (Creative Technology Ltd.)
HKLM-x32\...\Run: [ArcSoft Connection Service] => C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe [207424 2010-10-27] (ArcSoft Inc.)
HKLM-x32\...\Run: [AvastUI.exe] => C:\Program Files\AVAST Software\Avast\AvastUI.exe [4085896 2014-07-31] (AVAST Software)
HKLM-x32\...\Run: [VERIZONDM] => C:\Program Files (x86)\VERIZONDM\bin\sprtcmd.exe [206120 2010-09-02] (SupportSoft, Inc.)
HKLM-x32\...\Run: [Adobe ARM] => C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe [959176 2014-08-21] (Adobe Systems Incorporated)
HKLM-x32\...\Run: [iTunesHelper] => C:\Program Files (x86)\iTunes\iTunesHelper.exe [152392 2014-09-01] (Apple Inc.)
Winlogon\Notify\LBTWlgn: c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll (Logitech, Inc.)
Winlogon\Notify\FastAccess-x32: C:\Program Files (x86)\Sensible Vision\Fast Access\FALogNot.dll [X]
HKU\S-1-5-21-3777444554-1153240464-3734799716-1000\...\Run: [DellSystemDetect] => C:\Users\Chrissy\AppData\Local\Apps\2.0\YK8PCHXX.540\1ZKYKQYO.GAB\dell..tion_0f612f649c4a10af_0005.000a_17ece8424e43daec\DellSystemDetect.exe [265280 2014-08-27] (Dell)
Startup: C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Logitech SetPoint.lnk
ShortcutTarget: Logitech SetPoint.lnk -> C:\Program Files\Logitech\SetPoint\SetPoint.exe (Logitech, Inc.)
Startup: C:\Users\Brian\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk
ShortcutTarget: Dell Dock.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
Startup: C:\Users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock First Run.lnk
ShortcutTarget: Dell Dock First Run.lnk -> C:\Program Files\Dell\DellDock\DellDock.exe (Stardock Corporation)
ShellIconOverlayIdentifiers: [00avast] -> {472083B0-C522-11CF-8763-00608CC02F24} => C:\Program Files\AVAST Software\Avast\ashShA64.dll (AVAST Software)
ShellIconOverlayIdentifiers: [DropboxExt1] -> {FB314ED9-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt2] -> {FB314EDA-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt3] -> {FB314EDB-A251-47B7-93E1-CDD82E34AF8B} =>  No File
ShellIconOverlayIdentifiers: [DropboxExt4] -> {FB314EDC-A251-47B7-93E1-CDD82E34AF8B} =>  No File

==================== Internet (Whitelisted) ====================

(If an item is included in the fixlist, if it is a registry item it will be removed or restored to default.)

HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
HKCU\Software\Microsoft\Internet Explorer\Main,SearchMigratedDefaultURL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr7/*http://www.yahoo.com/ext/search/search.html
StartMenuInternet: IEXPLORE.EXE - C:\Program Files (x86)\Internet Explorer\iexplore.exe
SearchScopes: HKLM - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = http://search.live.com/results.aspx?q={searchTerms}&src={referrer:source?}
SearchScopes: HKLM - {2E00D31D-D171-423D-836D-1A4D7EA7F1A9} URL = 
SearchScopes: HKLM-x32 - DefaultScope {7F1288EA-E0DE-4E28-AA5A-6E58FDCD67CE} URL = 
SearchScopes: HKLM-x32 - {0633EE93-D776-472f-A0FF-E1416B8B2E3A} URL = 
SearchScopes: HKCU - {664164BD-7255-4B06-865E-65ECFDC1E85A} URL = http://search.yahoo.com/search?p={searchTerms}&ei=utf-8&fr=b1ie7
SearchScopes: HKCU - {AD0270AE-CBD0-4D98-AE60-0E72EB9EBB52} URL = 
SearchScopes: HKCU - {BBA54ACF-CC24-40CD-ACB3-3633B34BC954} URL = http://www.google.com/search?q={searchTerms}&rls=com.microsoft:{language}&ie={inputEncoding}&oe={outputEncoding}&startIndex={startIndex?}&startPage={startPage}&rlz=1I7ADRA_enUS423
BHO: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
BHO: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
BHO: No Name -> {DBC80044-A445-435b-BC74-9C25C1C588A9} ->  No File
BHO-x32: Java(tm) Plug-In SSV Helper -> {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\ssv.dll (Oracle Corporation)
BHO-x32: avast! Online Security -> {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} -> C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
BHO-x32: Windows Live ID Sign-in Helper -> {9030D464-4C02-4ABF-8ECC-5164760863C6} -> C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll (Microsoft Corp.)
BHO-x32: Windows Live Messenger Companion Helper -> {9FDDE16B-836F-4806-AB1F-1455CBEFF289} -> C:\Program Files (x86)\Windows Live\Companion\companioncore.dll (Microsoft Corporation)
BHO-x32: Skype Click to Call for Internet Explorer -> {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} -> C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
BHO-x32: Java(tm) Plug-In 2 SSV Helper -> {DBC80044-A445-435b-BC74-9C25C1C588A9} -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\jp2ssv.dll (Oracle Corporation)
Toolbar: HKLM - No Name - {CC1A175A-E45B-41ED-A30C-C9B1D7A0C02F} -  No File
Toolbar: HKCU - No Name - {21FA44EF-376D-4D53-9B0F-8A89D3229068} -  No File
Toolbar: HKCU - No Name - {2318C2B1-4965-11D4-9B18-009027A5CD4F} -  No File
DPF: HKLM-x32 {02BCC737-B171-4746-94C9-0D8A0B2C0089} http://office.microsoft.com/sites/production/ieawsdc32.cab
DPF: HKLM-x32 {05CA9FB0-3E3E-4B36-BF41-0E3A5CAA8CD8} http://download.microsoft.com/download/C/B/F/CBF23A2C-3E55-4664-BC5C-762780D79BA0/OGAControl.cab
DPF: HKLM-x32 {166B1BCA-3F9C-11CF-8075-444553540000} http://download.macromedia.com/pub/shockwave/cabs/director/sw.cab
DPF: HKLM-x32 {6F6FDB9E-5072-498C-BCB0-2B7F00C49EE7} http://support.dell.com/systemprofiler/DellSystemLite.CAB
DPF: HKLM-x32 {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab
DPF: HKLM-x32 {7E980B9B-8AE5-466A-B6D6-DA8CF814E78A} http://zone.msn.com/bingame/chnz/default/mjolauncher.cab
DPF: HKLM-x32 {8100D56A-5661-482C-BEE8-AFECE305D968} http://upload.facebook.com/controls/2009.07.28_v5.5.8.1/FacebookPhotoUploader55.cab
DPF: HKLM-x32 {9AA73F41-EC64-489E-9A73-9CD52E528BC4} http://zone.msn.com/binGame/ZAxRcMgr.cab
DPF: HKLM-x32 {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} http://zone.msn.com/bingame/popcaploader_v10.cab
DPF: HKLM-x32 {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
Handler: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Microsoft Corporation)
Handler-x32: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
Handler-x32: skypec2c - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll (Microsoft Corporation)
Tcpip\Parameters: [DhcpNameServer] 192.168.1.1

FireFox:
========
FF Plugin: @adobe.com/FlashPlayer -> C:\Windows\system32\Macromed\Flash\NPSWF64_15_0_0_189.dll ()
FF Plugin: @microsoft.com/GENUINE -> disabled No File
FF Plugin: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @adobe.com/FlashPlayer -> C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_15_0_0_189.dll ()
FF Plugin-x32: @adobe.com/ShockwavePlayer -> C:\Windows\SysWOW64\Adobe\Director\np32dsw_1207148.dll (Adobe Systems, Inc.)
FF Plugin-x32: @Apple.com/iTunes,version=1.0 -> C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF Plugin-x32: @java.com/DTPlugin,version=11.20.2 -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF Plugin-x32: @java.com/JavaPlugin,version=11.20.2 -> C:\Program Files (x86)\Java\jre1.8.0_20\bin\plugin2\npjp2.dll (Oracle Corporation)
FF Plugin-x32: @microsoft.com/GENUINE -> disabled No File
FF Plugin-x32: @Microsoft.com/NpCtrl,version=1.0 -> c:\Program Files (x86)\Microsoft Silverlight\5.1.30514.0\npctrl.dll ( Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3502.0922 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3508.1109 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @microsoft.com/WLPG,version=15.4.3555.0308 -> C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF Plugin-x32: @oberon-media.com/ONCAdapter -> C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (Oberon-Media )
FF Plugin-x32: @tools.google.com/Google Update;version=3 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: @tools.google.com/Google Update;version=9 -> C:\Program Files (x86)\Google\Update\1.3.25.5\npGoogleUpdate3.dll (Google Inc.)
FF Plugin-x32: Adobe Reader -> C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF Plugin-x32: samsung.com/SamsungLinkPCPlugin -> C:\Program Files\Samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll No File
FF Plugin HKCU: samsung.com/SamsungLinkPCPlugin -> C:\Program Files\Samsung\Samsung Link\utils\npSamsungLinkPCPlugin.dll No File
FF HKLM-x32\...\Firefox\Extensions: [wrc@avast.com] - C:\Program Files\AVAST Software\Avast\WebRep\FF
FF Extension: avast! Online Security - C:\Program Files\AVAST Software\Avast\WebRep\FF [2014-02-09]

Chrome: 
=======
CHR HomePage: Default -> hxxp://www.google.com
CHR StartupUrls: Default -> "hxxp://www.google.com", "hxxp://search.conduit.com/?ctid=CT3315828&SearchSource=48&CUI=UN15338799328857141&UM=2", "hxxp://astromenda.com/?f=7&a=ast_dnldstr_14_42_ch&cd=2XzuyEtN2Y1L1QzutDtDtBtCyBtDyCtDyB0D0C0A0EyCtAzztN0D0Tzu0StCtDtCzytN1L2XzutAtFtBtFtCtFyDtN1L1CzutCyEtBzytDyD1V1StN1L1G1B1V1N2Y1L1Qzu2StAyCyBzzyBzy0FyCtGyCyD0EtBtG0DtBtB0DtGyE0C0C0DtGyEzztC0E0ByBtC0B0ByB0C0F2QtN1M1F1B2Z1V1N2Y1L1Qzu2SyCyE0AyEyE0F0CzztG0ByEtAyEtGyEzztByBtGzzzy0FyEtGzz0CtB0EyB0B0F0C0Bzyzzzy2Q&cr=2037860578&ir="
CHR DefaultSuggestURL: Default -> {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:inputType}{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}{google:searchVersion}{google:sessionToken}{google:prefetchQuery}sugkey={google:suggestAPIKeyParameter}
CHR Plugin: (Remoting Viewer) - internal-remoting-viewer
CHR Plugin: (Native Client) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\ppGoogleNaClPluginChrome.dll No File
CHR Plugin: (Chrome PDF Viewer) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\pdf.dll ()
CHR Plugin: (Shockwave Flash) - C:\Program Files (x86)\Google\Chrome\Application\38.0.2125.111\gcswf32.dll No File
CHR Plugin: (Adobe Acrobat) - C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll (Adobe Systems Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll (Apple Inc.)
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll No File
CHR Plugin: (QuickTime Plug-in 7.7.1) - C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll No File
CHR Plugin: (Oberon com adapter) - C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (Oberon-Media )
CHR Plugin: (Google Update) - C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll No File
CHR Plugin: (Java(TM) Platform SE 6 U31) - C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll No File
CHR Plugin: (Reader Library) - C:\Program Files (x86)\Sony\Reader\Data\bin\npebldetectmoz.dll No File
CHR Plugin: (Windows Live Photo Gallery) - C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
CHR Plugin: (iTunes Application Detector) - C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
CHR Plugin: (Silverlight Plug-In) - c:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll No File
CHR Profile: C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default
CHR Extension: (Google Voice Search Hotword (Beta)) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn [2014-05-21]
CHR Extension: (YouTube) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo [2011-12-19]
CHR Extension: (Google Search) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf [2011-12-19]
CHR Extension: (Avast Online Security) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki [2014-02-10]
CHR Extension: (Skype Click to Call) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl [2014-03-20]
CHR Extension: (Google Wallet) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda [2013-08-23]
CHR Extension: (Gmail) - C:\Users\Chrissy\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia [2011-12-19]
CHR HKLM-x32\...\Chrome\Extension: [gomekmidlodglbbmalcneegieacbdmki] - C:\Program Files\AVAST Software\Avast\WebRep\Chrome\aswWebRepChrome.crx [2014-07-14]
CHR HKLM-x32\...\Chrome\Extension: [lifbcibllhkdhoafpjfnlhfpfgnpldfl] - C:\Program Files (x86)\Skype\Toolbars\ChromeExtension\skype_chrome_extension.crx [2014-07-14]

==================== Services (Whitelisted) =================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 ACDaemon; C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe [113152 2010-03-18] (ArcSoft Inc.)
R2 AllShare Framework DMS; C:\Program Files\Samsung\AllShare Framework DMS\1.3.23\AllShareFrameworkManagerDMS.exe [404360 2013-12-21] (Samsung) [File not signed]
R2 avast! Antivirus; C:\Program Files\AVAST Software\Avast\AvastSvc.exe [50344 2014-07-14] (AVAST Software)
R2 c2cautoupdatesvc; C:\Program Files (x86)\Skype\Toolbars\AutoUpdate\SkypeC2CAutoUpdateSvc.exe [1390176 2014-07-14] (Microsoft Corporation)
R2 c2cpnrsvc; C:\Program Files (x86)\Skype\Toolbars\PNRSvc\SkypeC2CPNRSvc.exe [1767520 2014-07-14] (Microsoft Corporation)
R2 CouponPrinterService; C:\Program Files (x86)\Coupons\CouponPrinterService.exe [177136 2014-04-28] (Coupons.com Inc.)
R2 dleaCATSCustConnectService; C:\Windows\system32\spool\DRIVERS\x64\3\\dleaserv.exe [33448 2010-01-07] ()
S2 dlea_device; C:\Windows\system32\dleacoms.exe [1052328 2010-01-07] ( )
S2 dlea_device; C:\Windows\SysWOW64\dleacoms.exe [598696 2010-01-07] ( )
R2 DockLoginService; C:\Program Files\Dell\DellDock\DockLogin.exe [155648 2009-06-09] (Stardock Corporation) [File not signed]
S3 FLEXnet Licensing Service; C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe [651720 2010-02-01] (Macrovision Europe Ltd.) [File not signed]
S3 IDriverT; C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe [69632 2005-04-04] (Macrovision Corporation) [File not signed]
R2 Samsung Link Service; C:\Program Files\Samsung\Samsung Link\Samsung Link.exe [609632 2014-03-13] (Copyright 2013 SAMSUNG)
R2 sprtsvc_verizondm; C:\Program Files (x86)\VERIZONDM\bin\sprtsvc.exe [206120 2010-09-02] (SupportSoft, Inc.)
R2 tgsrvc_verizondm; C:\Program Files (x86)\VERIZONDM\bin\tgsrvc.exe [185640 2010-09-02] (SupportSoft, Inc.)

==================== Drivers (Whitelisted) ====================

(If an entry is included in the fixlist, the service will be removed from the registry. The file will not be moved unless listed separately.)

R2 aswHwid; C:\Windows\system32\drivers\aswHwid.sys [29208 2014-07-14] ()
R2 aswMonFlt; C:\Windows\system32\drivers\aswMonFlt.sys [79184 2014-07-14] (AVAST Software)
R1 aswRdr; C:\Windows\system32\drivers\aswRdr2.sys [93568 2014-07-14] (AVAST Software)
R0 aswRvrt; C:\Windows\System32\Drivers\aswRvrt.sys [65776 2014-07-14] ()
R1 aswSnx; C:\Windows\system32\drivers\aswSnx.sys [1041168 2014-07-14] (AVAST Software)
R1 aswSP; C:\Windows\system32\drivers\aswSP.sys [427360 2014-07-14] (AVAST Software)
R2 aswStm; C:\Windows\system32\drivers\aswStm.sys [92008 2014-07-14] (AVAST Software)
R0 aswVmm; C:\Windows\System32\Drivers\aswVmm.sys [224896 2014-07-14] ()
R3 RLDesignVirtualAudioCableWdm; C:\Windows\System32\DRIVERS\livecamv.sys [49664 2007-02-05] ()
S3 USBAAPL64; C:\Windows\System32\Drivers\usbaapl64.sys [54784 2012-12-13] (Apple, Inc.) [File not signed]
S3 catchme; \??\C:\ComboFix\catchme.sys [X]

==================== NetSvcs (Whitelisted) ===================

(If an item is included in the fixlist, it will be removed from the registry. Any associated file could be listed separately to be moved.)


==================== One Month Created Files and Folders ========

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-30 11:55 - 2014-10-30 11:55 - 02113536 _____ (Farbar) C:\Users\Chrissy\Downloads\FRST64 (2).exe
2014-10-29 12:36 - 2014-10-29 12:37 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Amanda's Sticker Book
2014-10-28 17:14 - 2014-10-28 17:14 - 00000000 ____D () C:\ProgramData\SugarGames
2014-10-27 22:48 - 2014-10-29 12:04 - 00001270 _____ () C:\Users\Public\Desktop\More Great Games.lnk
2014-10-27 22:47 - 2014-10-27 22:49 - 00000000 ____D () C:\Program Files (x86)\My Singing Monsters
2014-10-27 22:47 - 2014-10-27 22:47 - 00001945 _____ () C:\Users\Public\Desktop\Play Bella Design.lnk
2014-10-27 22:47 - 2014-10-27 22:47 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\My Singing Monsters
2014-10-27 22:47 - 2014-10-27 22:47 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\My Singing Monsters
2014-10-27 22:46 - 2014-10-27 22:47 - 00000000 ____D () C:\Program Files (x86)\Bella Design
2014-10-27 22:46 - 2014-10-27 22:46 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Bella Design
2014-10-27 22:46 - 2014-10-27 22:46 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Bella Design
2014-10-27 22:43 - 2014-10-27 22:43 - 00237568 _____ (Big Fish Games) C:\Users\Chrissy\Downloads\bella-design_s1_l1_gF8361T1L1_d2380777120.exe
2014-10-27 21:52 - 2014-10-27 21:52 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\GrandMA Studios
2014-10-26 21:15 - 2014-10-26 21:16 - 00237568 _____ (Big Fish Games) C:\Users\Chrissy\Downloads\myths-of-the-world-black-rose-ce_s1_l1_gF8384T1L1_d2380308676.exe
2014-10-25 18:36 - 2014-10-25 18:36 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
2014-10-25 16:10 - 2014-10-25 16:10 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\EleFun Games
2014-10-23 01:28 - 2014-10-26 23:50 - 00000000 ____D () C:\Users\Chrissy\Documents\The Silent Spy
2014-10-22 17:57 - 2014-10-22 22:10 - 00032395 _____ () C:\Windows\DirectX.log
2014-10-22 17:31 - 2014-10-22 17:31 - 00237568 _____ (Big Fish Games) C:\Users\Chrissy\Downloads\bigfishgames_p222631658_s1_l1.exe
2014-10-21 21:11 - 2014-10-21 21:11 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{FE16E048-FDC9-4063-8EFF-CF70674125FD}
2014-10-21 20:10 - 2014-10-21 20:10 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\com.baconbanditgames.spellquest
2014-10-21 19:55 - 2014-10-21 19:55 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Letter Quest - Grimms Journeyy
2014-10-21 19:55 - 2014-10-21 19:55 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Letter Quest - Grimms Journeyy
2014-10-21 19:55 - 2014-10-21 19:55 - 00000000 ____D () C:\Program Files (x86)\Letter Quest - Grimms Journey
2014-10-21 19:51 - 2014-10-21 19:51 - 00237568 _____ (Big Fish Games) C:\Users\Chrissy\Downloads\letter-quest-grimms-journey_s1_l1_gF8391T1L1_d2378035488.exe
2014-10-21 15:46 - 2014-10-21 15:46 - 02110976 _____ (Farbar) C:\Users\Chrissy\Downloads\FRST64 (1).exe
2014-10-18 02:41 - 2014-10-18 02:42 - 00506912 _____ () C:\Windows\Minidump\101814-22885-01.dmp
2014-10-18 02:41 - 2014-10-18 02:41 - 931634514 _____ () C:\Windows\MEMORY.DMP
2014-10-18 02:41 - 2014-10-18 02:41 - 00000000 ____D () C:\Windows\Minidump
2014-10-17 20:43 - 2014-10-17 20:43 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Mariaglorum
2014-10-17 18:39 - 2014-10-17 18:39 - 04161313 _____ () C:\Users\Chrissy\Downloads\tdsskiller (1).zip
2014-10-17 18:38 - 2014-10-17 18:38 - 04161313 _____ () C:\Users\Chrissy\Downloads\tdsskiller.zip
2014-10-17 18:30 - 2014-10-17 18:30 - 00380416 _____ () C:\Users\Chrissy\Downloads\98fu8hd0.exe
2014-10-17 18:28 - 2014-10-17 18:29 - 00120367 _____ () C:\Users\Chrissy\Downloads\Addition.txt
2014-10-17 18:27 - 2014-10-30 11:55 - 00023723 _____ () C:\Users\Chrissy\Downloads\FRST.txt
2014-10-17 18:27 - 2014-10-30 11:55 - 00000000 ____D () C:\FRST
2014-10-17 18:26 - 2014-10-17 18:26 - 02112000 _____ (Farbar) C:\Users\Chrissy\Downloads\FRST64.exe
2014-10-16 15:00 - 2014-10-16 15:00 - 00688992 ____R (Swearware) C:\Users\Chrissy\Downloads\dds.com
2014-10-16 13:38 - 2014-10-16 13:38 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{CC28DDB6-19FC-4F9D-AA37-F91C0C275A68}
2014-10-16 03:10 - 2014-10-16 03:10 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Western Software Technologies
2014-10-16 02:59 - 2014-10-16 02:59 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Gizmos - Riddle Of The Universe
2014-10-16 02:59 - 2014-10-16 02:59 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Gizmos - Riddle Of The Universe
2014-10-16 02:59 - 2014-10-16 02:59 - 00000000 ____D () C:\Program Files (x86)\Gizmos - Riddle Of The Universe
2014-10-15 17:03 - 2014-10-16 13:38 - 00000101 _____ () C:\Users\Chrissy\AppData\Roaming\WB.CFG
2014-10-15 16:06 - 2014-10-30 11:54 - 00000830 _____ () C:\Windows\Tasks\Adobe Flash Player Updater.job
2014-10-15 16:06 - 2014-10-15 16:06 - 00003768 _____ () C:\Windows\System32\Tasks\Adobe Flash Player Updater
2014-10-15 16:02 - 2014-10-15 16:01 - 17334960 _____ (Adobe Systems Incorporated) C:\Users\Chrissy\Downloads\install_flash_player_ax.exe
2014-10-15 16:01 - 2014-10-15 16:01 - 00800688 _____ ( ) C:\Users\Chrissy\Downloads\Adobe_Flash_Setup.exe
2014-10-15 15:01 - 2014-10-29 11:01 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\AlawarEntertainment
2014-10-15 13:59 - 2014-10-15 13:59 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Crunching Koalas
2014-10-15 11:33 - 2014-10-09 22:05 - 00507392 _____ (Microsoft Corporation) C:\Windows\system32\aepdu.dll
2014-10-15 11:33 - 2014-10-09 22:05 - 00276480 _____ (Microsoft Corporation) C:\Windows\system32\generaltel.dll
2014-10-15 11:33 - 2014-10-09 22:00 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\aeinv.dll
2014-10-15 11:33 - 2014-10-06 22:54 - 00378552 _____ (Microsoft Corporation) C:\Windows\system32\iedkcs32.dll
2014-10-15 11:33 - 2014-10-06 22:04 - 00331448 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iedkcs32.dll
2014-10-15 11:33 - 2014-09-28 20:58 - 03198976 _____ (Microsoft Corporation) C:\Windows\system32\win32k.sys
2014-10-15 11:33 - 2014-09-25 18:46 - 00365056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtmsft.dll
2014-10-15 11:33 - 2014-09-25 18:46 - 00243200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxtrans.dll
2014-10-15 11:33 - 2014-09-25 18:46 - 00069632 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmled.dll
2014-10-15 11:33 - 2014-09-25 18:43 - 11807232 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieframe.dll
2014-10-15 11:33 - 2014-09-25 18:32 - 02017280 _____ (Microsoft Corporation) C:\Windows\SysWOW64\inetcpl.cpl
2014-10-15 11:33 - 2014-09-25 18:31 - 02108416 _____ (Microsoft Corporation) C:\Windows\system32\inetcpl.cpl
2014-10-15 11:33 - 2014-09-18 21:56 - 02724864 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.tlb
2014-10-15 11:33 - 2014-09-18 21:55 - 00004096 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollectorres.dll
2014-10-15 11:33 - 2014-09-18 21:44 - 17484800 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.dll
2014-10-15 11:33 - 2014-09-18 21:41 - 02796032 _____ (Microsoft Corporation) C:\Windows\system32\iertutil.dll
2014-10-15 11:33 - 2014-09-18 21:40 - 00066048 _____ (Microsoft Corporation) C:\Windows\system32\iesetup.dll
2014-10-15 11:33 - 2014-09-18 21:39 - 00048640 _____ (Microsoft Corporation) C:\Windows\system32\ieetwproxystub.dll
2014-10-15 11:33 - 2014-09-18 21:31 - 00051200 _____ (Microsoft Corporation) C:\Windows\system32\jsproxy.dll
2014-10-15 11:33 - 2014-09-18 21:30 - 00033792 _____ (Microsoft Corporation) C:\Windows\system32\iernonce.dll
2014-10-15 11:33 - 2014-09-18 21:25 - 04201472 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9.dll
2014-10-15 11:33 - 2014-09-18 21:25 - 00111616 _____ (Microsoft Corporation) C:\Windows\system32\ieetwcollector.exe
2014-10-15 11:33 - 2014-09-18 21:14 - 02724864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtml.tlb
2014-10-15 11:33 - 2014-09-18 21:14 - 00446464 _____ (Microsoft Corporation) C:\Windows\system32\dxtmsft.dll
2014-10-15 11:33 - 2014-09-18 21:06 - 00072704 _____ (Microsoft Corporation) C:\Windows\system32\JavaScriptCollectionAgent.dll
2014-10-15 11:33 - 2014-09-18 21:02 - 00454656 _____ (Microsoft Corporation) C:\Windows\SysWOW64\vbscript.dll
2014-10-15 11:33 - 2014-09-18 21:01 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iesetup.dll
2014-10-15 11:33 - 2014-09-18 21:01 - 00051200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieetwproxystub.dll
2014-10-15 11:33 - 2014-09-18 20:59 - 00061952 _____ (Microsoft Corporation) C:\Windows\SysWOW64\MshtmlDac.dll
2014-10-15 11:33 - 2014-09-18 20:55 - 02187264 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iertutil.dll
2014-10-15 11:33 - 2014-09-18 20:54 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jsproxy.dll
2014-10-15 11:33 - 2014-09-18 20:53 - 00032768 _____ (Microsoft Corporation) C:\Windows\SysWOW64\iernonce.dll
2014-10-15 11:33 - 2014-09-18 20:51 - 00440320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieui.dll
2014-10-15 11:33 - 2014-09-18 20:50 - 00112128 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieUnatt.exe
2014-10-15 11:33 - 2014-09-18 20:49 - 00597504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\jscript9diag.dll
2014-10-15 11:33 - 2014-09-18 20:42 - 00731136 _____ (Microsoft Corporation) C:\Windows\system32\msfeeds.dll
2014-10-15 11:33 - 2014-09-18 20:42 - 00710656 _____ (Microsoft Corporation) C:\Windows\system32\ie4uinit.exe
2014-10-15 11:33 - 2014-09-18 20:36 - 00060416 _____ (Microsoft Corporation) C:\Windows\SysWOW64\JavaScriptCollectionAgent.dll
2014-10-15 11:33 - 2014-09-18 20:32 - 00164864 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msrating.dll
2014-10-15 11:33 - 2014-09-18 20:20 - 00607744 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msfeeds.dll
2014-10-15 11:33 - 2014-09-18 20:18 - 01068032 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mshtmlmedia.dll
2014-10-15 11:33 - 2014-09-18 20:14 - 01447936 _____ (Microsoft Corporation) C:\Windows\system32\urlmon.dll
2014-10-15 11:33 - 2014-09-18 19:59 - 01810944 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wininet.dll
2014-10-15 11:33 - 2014-09-18 19:53 - 01190400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\urlmon.dll
2014-10-15 11:33 - 2014-09-18 19:52 - 00678400 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ieapfltr.dll
2014-10-15 11:33 - 2014-08-18 23:11 - 00693176 _____ (Microsoft Corporation) C:\Windows\system32\winload.efi
2014-10-15 11:33 - 2014-08-18 23:10 - 00616352 _____ (Microsoft Corporation) C:\Windows\system32\winresume.efi
2014-10-15 11:33 - 2014-08-18 23:08 - 00503808 _____ (Microsoft Corporation) C:\Windows\system32\srcore.dll
2014-10-15 11:33 - 2014-08-18 23:08 - 00063488 _____ (Microsoft Corporation) C:\Windows\system32\setbcdlocale.dll
2014-10-15 11:33 - 2014-08-18 23:08 - 00050176 _____ (Microsoft Corporation) C:\Windows\system32\srclient.dll
2014-10-15 11:33 - 2014-08-18 23:07 - 00296960 _____ (Microsoft Corporation) C:\Windows\system32\rstrui.exe
2014-10-15 11:33 - 2014-08-18 23:07 - 00146944 _____ (Microsoft Corporation) C:\Windows\system32\appidpolicyconverter.exe
2014-10-15 11:33 - 2014-08-18 23:07 - 00058880 _____ (Microsoft Corporation) C:\Windows\system32\appidapi.dll
2014-10-15 11:33 - 2014-08-18 23:07 - 00032256 _____ (Microsoft Corporation) C:\Windows\system32\appidsvc.dll
2014-10-15 11:33 - 2014-08-18 23:07 - 00017920 _____ (Microsoft Corporation) C:\Windows\system32\appidcertstorecheck.exe
2014-10-15 11:33 - 2014-08-18 22:41 - 00050688 _____ (Microsoft Corporation) C:\Windows\SysWOW64\appidapi.dll
2014-10-15 11:33 - 2014-08-18 22:41 - 00043008 _____ (Microsoft Corporation) C:\Windows\SysWOW64\srclient.dll
2014-10-15 11:33 - 2014-08-18 22:06 - 00061440 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\appid.sys
2014-10-15 11:33 - 2014-07-06 22:07 - 14632960 _____ (Microsoft Corporation) C:\Windows\system32\wmp.dll
2014-10-15 11:33 - 2014-07-06 22:07 - 00782848 _____ (Microsoft Corporation) C:\Windows\system32\wmdrmsdk.dll
2014-10-15 11:33 - 2014-07-06 22:07 - 00229376 _____ (Microsoft Corporation) C:\Windows\system32\wintrust.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 05551032 _____ (Microsoft Corporation) C:\Windows\system32\ntoskrnl.exe
2014-10-15 11:33 - 2014-07-06 22:06 - 04120576 _____ (Microsoft Corporation) C:\Windows\system32\mf.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 01574400 _____ (Microsoft Corporation) C:\Windows\system32\quartz.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 01480192 _____ (Microsoft Corporation) C:\Windows\system32\crypt32.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 01202176 _____ (Microsoft Corporation) C:\Windows\system32\drmv2clt.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 01069056 _____ (Microsoft Corporation) C:\Windows\system32\cryptui.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00842240 _____ (Microsoft Corporation) C:\Windows\system32\blackbox.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00679424 _____ (Microsoft Corporation) C:\Windows\system32\audiosrv.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00641024 _____ (Microsoft Corporation) C:\Windows\system32\msscp.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00631808 _____ (Microsoft Corporation) C:\Windows\system32\evr.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00500224 _____ (Microsoft Corporation) C:\Windows\system32\AUDIOKSE.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00497664 _____ (Microsoft Corporation) C:\Windows\system32\drmmgrtn.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00440832 _____ (Microsoft Corporation) C:\Windows\system32\AudioEng.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00432128 _____ (Microsoft Corporation) C:\Windows\system32\mfplat.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00325632 _____ (Microsoft Corporation) C:\Windows\system32\msnetobj.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00296448 _____ (Microsoft Corporation) C:\Windows\system32\AudioSes.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00284672 _____ (Microsoft Corporation) C:\Windows\system32\EncDump.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00206848 _____ (Microsoft Corporation) C:\Windows\system32\mfps.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00188416 _____ (Microsoft Corporation) C:\Windows\system32\pcasvc.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00187904 _____ (Microsoft Corporation) C:\Windows\system32\cryptsvc.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00082432 _____ (Microsoft Corporation) C:\Windows\system32\cryptsp.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00055808 _____ (Microsoft Corporation) C:\Windows\system32\rrinstaller.exe
2014-10-15 11:33 - 2014-07-06 22:06 - 00024576 _____ (Microsoft Corporation) C:\Windows\system32\mfpmp.exe
2014-10-15 11:33 - 2014-07-06 22:06 - 00009728 _____ (Microsoft Corporation) C:\Windows\system32\spwmp.dll
2014-10-15 11:33 - 2014-07-06 22:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\msdxm.ocx
2014-10-15 11:33 - 2014-07-06 22:06 - 00005120 _____ (Microsoft Corporation) C:\Windows\system32\dxmasf.dll
2014-10-15 11:33 - 2014-07-06 22:05 - 12625920 _____ (Microsoft Corporation) C:\Windows\system32\wmploc.DLL
2014-10-15 11:33 - 2014-07-06 22:05 - 00126464 _____ (Microsoft Corporation) C:\Windows\system32\audiodg.exe
2014-10-15 11:33 - 2014-07-06 22:02 - 00002048 _____ (Microsoft Corporation) C:\Windows\system32\mferror.dll
2014-10-15 11:33 - 2014-07-06 21:52 - 00663552 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\PEAuth.sys
2014-10-15 11:33 - 2014-07-06 21:40 - 11411456 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmp.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 03208704 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mf.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 01329664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\quartz.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 01174528 _____ (Microsoft Corporation) C:\Windows\SysWOW64\crypt32.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 01005056 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptui.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00988160 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmv2clt.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00744960 _____ (Microsoft Corporation) C:\Windows\SysWOW64\blackbox.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00617984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmdrmsdk.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00504320 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msscp.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00489984 _____ (Microsoft Corporation) C:\Windows\SysWOW64\evr.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00442880 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AUDIOKSE.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00406016 _____ (Microsoft Corporation) C:\Windows\SysWOW64\drmmgrtn.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00374784 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioEng.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00354816 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfplat.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00265216 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msnetobj.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00195584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\AudioSes.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00179200 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wintrust.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00143872 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsvc.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00103424 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfps.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00081408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\cryptsp.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00008192 _____ (Microsoft Corporation) C:\Windows\SysWOW64\spwmp.dll
2014-10-15 11:33 - 2014-07-06 21:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msdxm.ocx
2014-10-15 11:33 - 2014-07-06 21:40 - 00004096 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dxmasf.dll
2014-10-15 11:33 - 2014-07-06 21:39 - 12625408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\wmploc.DLL
2014-10-15 11:33 - 2014-07-06 21:39 - 03970488 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntkrnlpa.exe
2014-10-15 11:33 - 2014-07-06 21:39 - 03914680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\ntoskrnl.exe
2014-10-15 11:33 - 2014-07-06 21:39 - 00050176 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rrinstaller.exe
2014-10-15 11:33 - 2014-07-06 21:39 - 00023040 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mfpmp.exe
2014-10-15 11:33 - 2014-07-06 21:37 - 00002048 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mferror.dll
2014-10-15 11:33 - 2014-06-27 20:21 - 00619056 _____ (Microsoft Corporation) C:\Windows\system32\winload.exe
2014-10-15 11:33 - 2014-06-27 20:21 - 00532176 _____ (Microsoft Corporation) C:\Windows\system32\winresume.exe
2014-10-15 11:33 - 2014-06-27 20:21 - 00457400 _____ (Microsoft Corporation) C:\Windows\system32\ci.dll
2014-10-15 11:33 - 2014-06-18 18:23 - 01943696 _____ (Microsoft Corporation) C:\Windows\system32\dfshim.dll
2014-10-15 11:33 - 2014-06-18 18:23 - 01131664 _____ (Microsoft Corporation) C:\Windows\SysWOW64\dfshim.dll
2014-10-15 11:33 - 2014-06-18 18:23 - 00156824 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscorier.dll
2014-10-15 11:33 - 2014-06-18 18:23 - 00156312 _____ (Microsoft Corporation) C:\Windows\system32\mscorier.dll
2014-10-15 11:33 - 2014-06-18 18:23 - 00081560 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mscories.dll
2014-10-15 11:33 - 2014-06-18 18:23 - 00073880 _____ (Microsoft Corporation) C:\Windows\system32\mscories.dll
2014-10-15 11:32 - 2014-09-25 18:50 - 13619200 _____ (Microsoft Corporation) C:\Windows\system32\ieframe.dll
2014-10-15 11:32 - 2014-09-18 22:25 - 23631360 _____ (Microsoft Corporation) C:\Windows\system32\mshtml.dll
2014-10-15 11:32 - 2014-09-18 21:40 - 00547328 _____ (Microsoft Corporation) C:\Windows\system32\vbscript.dll
2014-10-15 11:32 - 2014-09-18 21:38 - 00083968 _____ (Microsoft Corporation) C:\Windows\system32\MshtmlDac.dll
2014-10-15 11:32 - 2014-09-18 21:36 - 05829632 _____ (Microsoft Corporation) C:\Windows\system32\jscript9.dll
2014-10-15 11:32 - 2014-09-18 21:27 - 00595968 _____ (Microsoft Corporation) C:\Windows\system32\ieui.dll
2014-10-15 11:32 - 2014-09-18 21:26 - 00139264 _____ (Microsoft Corporation) C:\Windows\system32\ieUnatt.exe
2014-10-15 11:32 - 2014-09-18 21:25 - 00758272 _____ (Microsoft Corporation) C:\Windows\system32\jscript9diag.dll
2014-10-15 11:32 - 2014-09-18 21:18 - 00940032 _____ (Microsoft Corporation) C:\Windows\system32\MsSpellCheckingFacility.exe
2014-10-15 11:32 - 2014-09-18 21:01 - 00195584 _____ (Microsoft Corporation) C:\Windows\system32\msrating.dll
2014-10-15 11:32 - 2014-09-18 21:00 - 00085504 _____ (Microsoft Corporation) C:\Windows\system32\mshtmled.dll
2014-10-15 11:32 - 2014-09-18 20:58 - 00289280 _____ (Microsoft Corporation) C:\Windows\system32\dxtrans.dll
2014-10-15 11:32 - 2014-09-18 20:40 - 01249280 _____ (Microsoft Corporation) C:\Windows\system32\mshtmlmedia.dll
2014-10-15 11:32 - 2014-09-18 20:33 - 02309632 _____ (Microsoft Corporation) C:\Windows\system32\wininet.dll
2014-10-15 11:32 - 2014-09-18 19:59 - 00775168 _____ (Microsoft Corporation) C:\Windows\system32\ieapfltr.dll
2014-10-15 11:32 - 2014-09-17 22:00 - 03241472 _____ (Microsoft Corporation) C:\Windows\system32\msi.dll
2014-10-15 11:32 - 2014-09-17 21:32 - 02363904 _____ (Microsoft Corporation) C:\Windows\SysWOW64\msi.dll
2014-10-15 11:32 - 2014-09-12 21:58 - 00077312 _____ (Microsoft Corporation) C:\Windows\system32\packager.dll
2014-10-15 11:32 - 2014-09-12 21:40 - 00067072 _____ (Microsoft Corporation) C:\Windows\SysWOW64\packager.dll
2014-10-15 11:32 - 2014-09-04 01:23 - 00424448 _____ (Microsoft Corporation) C:\Windows\system32\rastls.dll
2014-10-15 11:32 - 2014-09-04 01:04 - 00372736 _____ (Microsoft Corporation) C:\Windows\SysWOW64\rastls.dll
2014-10-15 11:32 - 2014-07-16 22:07 - 03722240 _____ (Microsoft Corporation) C:\Windows\system32\mstscax.dll
2014-10-15 11:32 - 2014-07-16 22:07 - 01118720 _____ (Microsoft Corporation) C:\Windows\system32\mstsc.exe
2014-10-15 11:32 - 2014-07-16 22:07 - 00681984 _____ (Microsoft Corporation) C:\Windows\system32\termsrv.dll
2014-10-15 11:32 - 2014-07-16 22:07 - 00455168 _____ (Microsoft Corporation) C:\Windows\system32\winlogon.exe
2014-10-15 11:32 - 2014-07-16 22:07 - 00235520 _____ (Microsoft Corporation) C:\Windows\system32\winsta.dll
2014-10-15 11:32 - 2014-07-16 22:07 - 00150528 _____ (Microsoft Corporation) C:\Windows\system32\rdpcorekmts.dll
2014-10-15 11:32 - 2014-07-16 22:07 - 00086528 _____ (Microsoft Corporation) C:\Windows\system32\TSpkg.dll
2014-10-15 11:32 - 2014-07-16 22:07 - 00022016 _____ (Microsoft Corporation) C:\Windows\system32\credssp.dll
2014-10-15 11:32 - 2014-07-16 21:40 - 00157696 _____ (Microsoft Corporation) C:\Windows\SysWOW64\winsta.dll
2014-10-15 11:32 - 2014-07-16 21:39 - 03221504 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstscax.dll
2014-10-15 11:32 - 2014-07-16 21:39 - 01051136 _____ (Microsoft Corporation) C:\Windows\SysWOW64\mstsc.exe
2014-10-15 11:32 - 2014-07-16 21:39 - 00131584 _____ (Microsoft Corporation) C:\Windows\SysWOW64\aaclient.dll
2014-10-15 11:32 - 2014-07-16 21:39 - 00065536 _____ (Microsoft Corporation) C:\Windows\SysWOW64\TSpkg.dll
2014-10-15 11:32 - 2014-07-16 21:39 - 00017408 _____ (Microsoft Corporation) C:\Windows\SysWOW64\credssp.dll
2014-10-15 11:32 - 2014-07-16 21:21 - 00212480 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\rdpwd.sys
2014-10-15 11:32 - 2014-07-16 21:21 - 00039936 _____ (Microsoft Corporation) C:\Windows\system32\Drivers\tssecsrv.sys
2014-10-12 11:30 - 2014-10-12 11:30 - 00001785 _____ () C:\Users\Public\Desktop\iTunes.lnk
2014-10-12 11:30 - 2014-10-12 11:30 - 00000000 ____D () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
2014-10-12 11:29 - 2014-10-12 11:29 - 00000000 ____D () C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
2014-10-12 11:29 - 2014-10-12 11:29 - 00000000 ____D () C:\Program Files\iTunes
2014-10-12 11:29 - 2014-10-12 11:29 - 00000000 ____D () C:\Program Files\iPod
2014-10-06 16:30 - 2014-10-06 16:30 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{269A14D5-3686-44C5-A9FA-1DDE4FF0321C}
2014-10-05 22:40 - 2014-10-05 22:40 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{AA686C13-87C0-4B5F-BE86-F64581A95055}
2014-10-04 03:53 - 2014-10-04 03:53 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{B56CAF92-70F3-415F-8BD6-2206A1CFB06B}
2014-10-03 10:27 - 2014-10-03 10:27 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{F04061BF-8698-4CCF-8F47-22ED8561815A}
2014-10-02 11:09 - 2014-10-02 11:09 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{07352911-8FFE-44AF-9FAF-B92D476B84CC}
2014-10-01 16:29 - 2014-10-01 16:29 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\{F693B78E-65E1-4AD6-AA17-47D32E5D2668}
2014-10-01 16:08 - 2014-09-24 22:08 - 00371712 _____ (Microsoft Corporation) C:\Windows\system32\qdvd.dll
2014-10-01 16:08 - 2014-09-24 21:40 - 00519680 _____ (Microsoft Corporation) C:\Windows\SysWOW64\qdvd.dll

==================== One Month Modified Files and Folders =======

(If an entry is included in the fixlist, the file\folder will be moved.)

2014-10-30 11:54 - 2014-02-09 22:36 - 00004182 _____ () C:\Windows\System32\Tasks\avast! Emergency Update
2014-10-30 11:54 - 2011-03-19 23:55 - 00000898 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineUA.job
2014-10-30 11:54 - 2011-03-19 23:55 - 00000894 _____ () C:\Windows\Tasks\GoogleUpdateTaskMachineCore.job
2014-10-29 18:09 - 2010-02-11 05:03 - 00000000 ____D () C:\ProgramData\TEMP
2014-10-29 16:00 - 2014-08-27 00:18 - 00003440 _____ () C:\Windows\System32\Tasks\PCDEventLauncherTask
2014-10-29 15:55 - 2009-07-14 01:32 - 00000000 ___RD () C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Games
2014-10-29 14:59 - 2014-05-29 19:58 - 01751131 _____ () C:\Windows\WindowsUpdate.log
2014-10-29 12:02 - 2010-11-13 20:26 - 00000000 ___RD () C:\Users\Chrissy\Desktop\Game Shortcuts
2014-10-27 22:49 - 2014-09-27 16:20 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\8floor
2014-10-27 22:13 - 2014-08-26 18:14 - 00002408 _____ () C:\Windows\setupact.log
2014-10-26 21:21 - 2014-09-27 20:26 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Eipix
2014-10-25 18:38 - 2010-02-11 03:34 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Skype
2014-10-25 18:37 - 2010-02-11 03:33 - 00000000 ____D () C:\ProgramData\Skype
2014-10-25 18:36 - 2014-03-20 10:46 - 00000000 ___RD () C:\Program Files (x86)\Skype
2014-10-25 15:51 - 2013-07-27 10:47 - 00000000 ____D () C:\BigFishCache
2014-10-25 15:25 - 2009-07-14 00:45 - 00025424 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
2014-10-25 15:25 - 2009-07-14 00:45 - 00025424 ____H () C:\Windows\system32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
2014-10-22 11:06 - 2011-03-19 23:55 - 00003894 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineUA
2014-10-22 11:06 - 2011-03-19 23:55 - 00003642 _____ () C:\Windows\System32\Tasks\GoogleUpdateTaskMachineCore
2014-10-21 18:08 - 2014-08-29 14:04 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Elephant Games
2014-10-21 15:56 - 2010-02-10 02:07 - 00000000 ____D () C:\ProgramData\Dl_cats
2014-10-21 15:55 - 2014-08-30 02:15 - 00122584 _____ (Malwarebytes Corporation) C:\Windows\system32\Drivers\MBAMSwissArmy.sys
2014-10-21 15:52 - 2010-02-10 01:54 - 00478690 _____ () C:\ProgramData\dleascan.log
2014-10-21 15:51 - 2014-08-26 18:13 - 00058774 _____ () C:\Windows\PFRO.log
2014-10-21 15:51 - 2009-07-14 01:08 - 00000006 ____H () C:\Windows\Tasks\SA.DAT
2014-10-21 15:48 - 2014-01-09 18:08 - 00000000 ____D () C:\Users\Chrissy\AppData\Local\CRE
2014-10-21 15:45 - 2010-02-10 02:25 - 00585520 _____ () C:\ProgramData\dleaJSW.log
2014-10-20 16:29 - 2014-07-07 12:11 - 00000000 ____D () C:\Users\Chrissy\AppData\Roaming\Orneon
2014-10-17 22:57 - 2013-11-01 22:58 - 00000404 _____ () C:\Windows\Tasks\EasyShare Registration Task.job
2014-10-17 18:21 - 2010-04-17 11:27 - 00103020 _____ () C:\ProgramData\dlea.log
2014-10-16 06:34 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\rescache
2014-10-16 03:48 - 2009-07-14 01:09 - 00000000 ____D () C:\Windows\System32\Tasks\WPD
2014-10-16 03:33 - 2009-07-14 00:45 - 00426520 _____ () C:\Windows\system32\FNTCACHE.DAT
2014-10-16 03:30 - 2014-05-07 03:00 - 00000000 ___SD () C:\Windows\system32\CompatTel
2014-10-16 03:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\SysWOW64\Dism
2014-10-16 03:30 - 2009-07-13 23:20 - 00000000 ____D () C:\Windows\system32\Dism
2014-10-16 03:12 - 2010-02-01 23:28 - 00000000 ____D () C:\ProgramData\Microsoft Help
2014-10-16 03:07 - 2013-08-15 03:02 - 00000000 ____D () C:\Windows\system32\MRT
2014-10-16 03:01 - 2010-04-01 02:59 - 103265616 _____ (Microsoft Corporation) C:\Windows\system32\MRT.exe
2014-10-15 16:06 - 2012-04-01 13:04 - 00701104 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerApp.exe
2014-10-15 16:06 - 2011-06-05 04:37 - 00071344 _____ (Adobe Systems Incorporated) C:\Windows\SysWOW64\FlashPlayerCPLApp.cpl
2014-10-12 11:29 - 2007-11-20 21:38 - 00000000 ____D () C:\Program Files (x86)\iTunes
2014-10-02 15:53 - 2010-02-11 03:01 - 00278152 ____N (Microsoft Corporation) C:\Windows\system32\MpSigStub.exe

Some content of TEMP:
====================
C:\Users\Chrissy\AppData\Local\temp\SkypeSetup.exe


==================== Bamital & volsnap Check =================

(There is no automatic fix for files that do not pass verification.)

C:\Windows\System32\winlogon.exe => File is digitally signed
C:\Windows\System32\wininit.exe => File is digitally signed
C:\Windows\SysWOW64\wininit.exe => File is digitally signed
C:\Windows\explorer.exe => File is digitally signed
C:\Windows\SysWOW64\explorer.exe => File is digitally signed
C:\Windows\System32\svchost.exe => File is digitally signed
C:\Windows\SysWOW64\svchost.exe => File is digitally signed
C:\Windows\System32\services.exe => File is digitally signed
C:\Windows\System32\User32.dll => File is digitally signed
C:\Windows\SysWOW64\User32.dll => File is digitally signed
C:\Windows\System32\userinit.exe => File is digitally signed
C:\Windows\SysWOW64\userinit.exe => File is digitally signed
C:\Windows\System32\rpcss.dll => File is digitally signed
C:\Windows\System32\Drivers\volsnap.sys => File is digitally signed


LastRegBack: 2014-10-27 00:18

==================== End Of Log ============================


#9 schrauber

schrauber

    Mr.Mechanic


  • Malware Response Team
  • 24,794 posts
  • OFFLINE
  •  
  • Gender:Male
  • Location:Munich,Germany
  • Local time:05:30 AM

Posted 30 October 2014 - 01:17 PM

Perfect, then we just need to cleanup our work.
  • Download OTC to your desktop and run it
  • Click Yes to beginning the Cleanup process and remove these components, including this application.
  • You will be asked to reboot the machine to finish the Cleanup process. Choose Yes.
Your machine appears to be clean, please take the time to read below on how to secure the machine and take the necessary steps to keep it Clean :)

Hiding Hidden Files
Please set your system to hide all hidden files.
Click Start, open My Computer, select the Tools menu and click Folder Options.
Select the View Tab. Under the Hidden files and folders heading, uncheck Show hidden files and folders.
Check: Hide file extensions for known file types
Check the Hide protected operating system files (recommended) option.
Click Yes to confirm.

Purging System Restore Points
Now you should Set a New Restore Point to prevent possible reinfection from an old one. Some of the malware you picked up could have been saved in System Restore. Since System Restore is a protected directory, your tools can not access it to delete these bad files which sometimes can reinfect your system. Setting a new restore point AFTER cleaning your system will help prevent this and enable your computer to "roll-back" to a clean working state.

The easiest and safest way to do this is:
  • Go to Start > Programs > Accessories > System Tools and click "System Restore".
  • Choose the radio button marked "Create a Restore Point" on the first screen then click "Next". Give the R.P. a name then click "Create". The new point will be stamped with the current date and time. Keep a log of this so you can find it easily should you need to use System Restore.
  • Then go to Start > Run and type: Cleanmgr
  • Click "OK".
  • Click the "More Options" Tab.
  • Click "Clean Up" in the System Restore section to remove all previous restore points except the newly created one.
One of the most common questions found when cleaning Spyware or other Malware is "how did my machine get infected?". There are a variety of reasons, but the most common ones are that you are going to sites that you are not practicing Safe Internet, you are not running the proper security software, and that your computer's security settings are set too low.

Below I have outlined a series of categories that outline how you can increase the security of your computer so that you will not be infected again in the future.


Practice Safe Internet

One of the main reasons people get infected in the first place is that they are not practicing Safe Internet. You practice Safe Internet when you educate yourself on how to properly use the Internet through the use of security tools and good practice. Knowing how you can get infected and what types of files and sites to avoid will be the most crucial step in keeping your computer malware free. The reality is that the majority of people who are infected with malware are ones who click on things they shouldn't be clicking on. Whether these things are files or sites it doesn't really matter. If something is out to get you, and you click on it, it most likely will. Below are a list of simple precautions to take to keep your computer clean and running securely:
  • If you receive an attachment from someone you do not know, DO NOT OPEN IT! Simple as that. Opening attachments from people you do not know is a very common method for viruses or worms to infect your computer.
  • If you receive an attachment and it ends with a .exe, .com, .bat, or .pif do not open the attachment unless you know for a fact that it is clean. For the casual computer user, you will almost never receive a valid attachment of this type.
  • If you receive an attachment from someone you know, and it looks suspicious, then it probably is. The email could be from someone you know infected with a malware that is trying to infect everyone in their address book.
  • If you are browsing the Internet and a popup appears saying that you are infected, ignore it!. These are, as far as I am concerned, scams that are being used to scare you into purchasing a piece of software.

    There are also programs that disguise themselves as Anti-Spyware or security products but are instead scams. For a list of these types of programs we recommend you visit this link: Rogue/Suspect Anti-Spyware Products & Web Sites
  • Another tactic to fool you on the web is when a site displays a popup that looks like a normal Windows message or alert. When you click on them, though, they instead bring you to another site that is trying to push a product on you. We suggest that you close these windows by clicking on the X instead of the OK button. Alternatively, you can check to see if it's a real alert by right-clicking on the window. If there is a menu that comes up saying Add to Favorites... you know it's a fake.
  • Do not go to adult sites. I know this may bother some of you, but the fact is that a large amount of malware is pushed through these types of sites. I am not saying all adult sites do this, but a lot do.
  • When using an Instant Messaging program be cautious about clicking on links people send to you. It is not uncommon for infections to send a message to everyone in the infected person's contact list that contains a link to an infection. Instead when you receive a message that contains a link, message back to the person asking if it is legit before you click on it.
  • Stay away from Warez and Crack sites! In addition to the obvious copyright issues, the downloads from these sites are typically overrun with infections.
  • Be careful of what you download off of web sites and Peer-2-Peer networks. Some sites disguise malware as legitimate software to trick you into installing them and Peer-2-Peer networks are crawling with it. If you want to download a piece of software a from a site, and are not sure if they are legitimate, you can use McAfee Siteadvisor to look up info on the site.
  • DO NOT INSTALL any software without first reading the End User License Agreement, otherwise known as the EULA. A tactic that some developers use is to offer their software for free, but have spyware and other programs you do not want bundled with it. This is where they make their money. By reading the agreement there is a good chance you can spot this and not install the software.
Visit Microsoft's Windows Update Site Frequently

It is important that you visit http://www.windowsupdate.com regularly. This will ensure your computer has always the latest security updates available installed on your computer. If there are new updates to install, install them immediately, reboot your computer, and revisit the site until there are no more critical updates.
regards,
schrauber

Posted Image
Posted Image

If I've not posted back within 48 hrs., feel free to send a PM with your topic link. Thank you!

If I have helped you then please consider donating to continue the fight against malware Posted Image

#10 TB-Psychotic

TB-Psychotic

  • Malware Response Team
  • 6,349 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:05:30 AM

Posted 10 November 2014 - 07:24 AM

It appears that this issue is resolved, therefore I am closing the topic. If that is not the case and you need or wish to continue with this topic, please send me or any Moderator a Personal Message (PM) that you would like this topic re-opened.
Proud Member of UNITE & TB
 
My help is free, however, if you want to support my fight against malware, click here --> btn_donate_SM.gif <--(no worries, every little bit helps)




0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users