O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} »
java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {BEA7310D-06C4-4339-A784-DC3804819809} »
images3.pnimedia.com/ProductAsse···trol.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0016-0000-0007-ABCDEFFEDCBA} »
java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_07)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} »
java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} »
java.sun.com/update/1.6.0/jinsta···i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} »
java.sun.com/update/1.6.0/jinsta···i586.cab (Reg Error: Key error.)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} »
platformdl.adobe.com/NOS/getPlus···6/gp.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.64.48.1 205.171.2.25
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{677D4FD1-5C9D-47A5-8974-AFC972B4E3D3}: DhcpNameServer = 10.64.48.1 205.171.2.25
O18 - Protocol\Handler\linkscanner - No CLSID value found
O18 - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Handler\vnd.ms.radio {3DA2AA3B-3D96-11D2-9BD2-204C4F4F5020} - C:\Windows\System32\Msdxm6.ocx (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\!SASWinLogon: DllName - (Reg Error: Value error.) - Reg Error: Value error. File not found
O20 - Winlogon\Notify\klogon: DllName - (C:\Windows\system32\klogon.dll) - C:\Windows\System32\klogon.dll (Kaspersky Lab ZAO)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img22.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img22.jpg
O28 - HKLM ShellExecuteHooks: {5AE067D3-9AFB-48E0-853A-EBB7F4A000DA} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2011/01/31 15:42:32 | 000,000,062 | ---- | M] () - F:\Autorun.inf -- [ NTFS ]
O33 - MountPoints2\{1f574380-b599-11e1-8607-001f16d6ec81}\Shell - "" = AutoRun
O33 - MountPoints2\{1f574380-b599-11e1-8607-001f16d6ec81}\Shell\AutoRun\command - "" = G:\LaunchU3.exe -a
O33 - MountPoints2\{93ba8ebc-f13f-11e1-9472-001f16d6ec81}\Shell - "" = AutoRun
O33 - MountPoints2\{93ba8ebc-f13f-11e1-9472-001f16d6ec81}\Shell\AutoRun\command - "" = F:\Autorun.exe /s
O33 - MountPoints2\{e30ee68d-3436-11e0-b83f-001167d83a91}\Shell\AutoRun\command - "" = wscript.exe Deploy\Scripts\BDD_AutoRun.wsf
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~1\AVG\AVG2012\avgrsx.exe /sync /restart)
O34 - HKLM BootExecute: (autocheck smrgdf C:\Users\Vernon\AppData\Roaming\iolo\)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
[color=#E56717]========== Files/Folders - Created Within 30 Days ==========[/color]
[2012/11/10 06:35:33 | 000,000,000 | ---D | C] -- C:\Users\Vernon\Desktop\Chris Schultze
[2012/11/10 06:34:34 | 000,000,000 | ---D | C] -- C:\Users\Vernon\Desktop\Custody Reading
[2012/11/10 06:33:22 | 000,000,000 | ---D | C] -- C:\Users\Vernon\Desktop\Captures
[2012/11/10 06:29:34 | 000,000,000 | ---D | C] -- C:\Users\Vernon\Desktop\Shortcuts
[2012/11/10 06:26:47 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Vernon\Desktop\OTL.exe
[2012/11/05 07:05:14 | 000,000,000 | ---D | C] -- C:\Users\Vernon\Desktop\From Thumb drive
[2012/11/01 01:28:45 | 000,000,000 | ---D | C] -- C:\Users\Vernon\Desktop\Recovered3
[2012/10/31 08:40:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs
[2012/10/31 08:40:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012/10/31 08:21:11 | 000,000,000 | ---D | C] -- C:\Program Files\Minibar
[2012/10/31 08:21:10 | 000,000,000 | ---D | C] -- C:\Users\Vernon\AppData\Local\Minibar
[2012/10/31 08:21:08 | 000,000,000 | ---D | C] -- C:\Program Files\Video Download Button
[2012/10/31 08:20:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoDownloadToolbar
[2012/10/31 08:20:26 | 000,000,000 | ---D | C] -- C:\Users\Vernon\AppData\Roaming\VideoDownloadToolbar
[2012/10/31 08:20:26 | 000,000,000 | ---D | C] -- C:\Program Files\VideoDownloadToolbar
[2012/10/31 08:19:22 | 000,000,000 | ---D | C] -- C:\Users\Vernon\AppData\Local\TempDIR
[2012/10/24 10:42:29 | 000,000,000 | ---D | C] -- C:\ProgramData\Kaspersky Lab Setup Files
[2012/10/24 03:58:51 | 000,000,000 | ---D | C] -- C:\Program Files\Jpegsnoop
[2012/10/23 08:38:06 | 000,000,000 | ---D | C] -- C:\Users\Vernon\Documents\recov2
[2012/10/23 07:27:10 | 000,000,000 | ---D | C] -- C:\Program Files\Recover Files
[2012/10/23 07:24:24 | 000,000,000 | ---D | C] -- C:\Program Files\EaseUS
[2012/10/23 07:21:32 | 000,000,000 | ---D | C] -- C:\Users\Vernon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Convar
[2012/10/23 07:21:31 | 000,000,000 | ---D | C] -- C:\Program Files\Convar
[2012/10/23 07:18:41 | 000,000,000 | ---D | C] -- C:\Program Files\eSupport.com
[2012/10/23 07:17:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Ask
[2012/10/22 09:34:25 | 000,000,000 | ---D | C] -- C:\Program Files\Avira
[2012/10/22 08:59:01 | 000,000,000 | ---D | C] -- C:\Users\Vernon\AppData\Roaming\PandoraRecovery
[2012/10/22 08:58:56 | 000,000,000 | ---D | C] -- C:\Program Files\Pandora Recovery
[2012/10/22 08:52:12 | 000,000,000 | ---D | C] -- C:\Users\Vernon\AppData\Roaming\GlarySoft
[2012/10/22 08:52:11 | 000,000,000 | ---D | C] -- C:\Program Files\Glary Undelete
[2012/10/22 08:13:10 | 000,000,000 | ---D | C] -- C:\Users\Vernon\Documents\SFPR recovery
[2012/10/22 00:01:38 | 000,000,000 | ---D | C] -- C:\Users\Vernon\Documents\sppr recovery
[2012/10/21 23:50:10 | 000,000,000 | ---D | C] -- C:\Program Files\Recuva
[2012/10/21 07:45:34 | 000,000,000 | ---D | C] -- C:\Users\Vernon\Documents\Disk Images
[2012/10/21 02:17:42 | 000,000,000 | ---D | C] -- C:\Users\Vernon\AppData\Roaming\JPEGsnoop
[2012/10/20 22:54:22 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Fixit Center New
[2012/10/20 22:47:11 | 000,000,000 | ---D | C] -- C:\Program Files\Dreamweaver
[2012/10/19 21:13:57 | 000,000,000 | ---D | C] -- C:\MATS
[2012/10/17 21:24:50 | 000,000,000 | ---D | C] -- C:\Users\Vernon\AppData\Local\{79633115-2DB9-4BC5-8B65-610D42C64D67}
[2012/10/17 21:24:09 | 000,000,000 | ---D | C] -- C:\Users\Vernon\AppData\Local\{6F375659-E264-4BB4-9DF2-B889EB7DF2F4}
[2012/10/17 05:14:20 | 000,000,000 | ---D | C] -- C:\Users\Vernon\Documents\Software Keys, passwords, etc
[2012/10/17 05:12:34 | 000,000,000 | ---D | C] -- C:\Users\Vernon\Documents\Pictures
[2012/10/17 03:07:12 | 000,000,000 | ---D | C] -- C:\Program Files\Picture Doctor
[2012/10/17 02:31:03 | 000,000,000 | ---D | C] -- C:\Users\Vernon\AppData\Local\{10BC8E89-60FF-4BFB-A4DA-9E5126BB9186}
[2012/10/16 09:06:08 | 000,000,000 | ---D | C] -- C:\Users\Vernon\AppData\Local\antiphishing-vmninternethelper1_1dn
[2012/10/16 08:24:20 | 000,000,000 | ---D | C] -- C:\Users\Vernon\Desktop\How to Recover Deleted Facebook Messages Guide
[2012/10/15 19:47:56 | 000,000,000 | ---D | C] -- C:\Users\Vernon\AppData\Local\{09273C87-3D09-411B-9539-95E7D28A175B}
[2012/10/15 04:27:46 | 000,000,000 | ---D | C] -- C:\Users\Vernon\AppData\Local\{B478A01B-BDE1-4657-B52A-C70C48D2E2B1}
[color=#E56717]========== Files - Modified Within 30 Days ==========[/color]
[2012/11/11 08:26:49 | 000,001,230 | ---- | M] () -- C:\Windows\System32\bscs.ini
[2012/11/11 08:20:13 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-509414838-4269606527-2852130047-1000UA.job
[2012/11/11 08:19:20 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/11/11 08:17:54 | 000,604,752 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/11/11 08:17:54 | 000,104,420 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/11/11 08:16:01 | 000,000,284 | ---- | M] () -- C:\ProgramData\hpqp.ini
[2012/11/11 08:14:47 | 000,000,882 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/11/11 08:11:24 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/11/11 08:11:24 | 000,003,344 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/11/11 08:10:53 | 000,065,536 | ---- | M] () -- C:\Windows\System32\Ikeext.etl
[2012/11/11 08:10:47 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/11/11 08:10:42 | 3149,078,528 | -HS- | M] () -- C:\hiberfil.sys
[2012/11/11 08:08:21 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012/11/11 08:01:04 | 000,000,258 | ---- | M] () -- C:\Windows\tasks\HP Photo Creations Messager.job
[2012/11/11 07:44:18 | 000,000,886 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/11/11 03:25:41 | 000,000,404 | -H-- | M] () -- C:\Windows\tasks\Norton Security Scan for Vernon.job
[2012/11/10 14:20:30 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-509414838-4269606527-2852130047-1000Core.job
[2012/11/10 07:12:00 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/10 06:28:00 | 000,881,833 | ---- | M] () -- C:\Users\Vernon\Desktop\SecurityCheck.exe
[2012/11/10 06:26:57 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Vernon\Desktop\OTL.exe
[2012/11/10 06:26:22 | 000,008,939 | ---- | M] () -- C:\Users\Vernon\Desktop\cleaning.rtf
[2012/11/10 06:04:51 | 000,318,536 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/11/10 05:59:40 | 000,001,356 | ---- | M] () -- C:\Users\Vernon\AppData\Local\d3d9caps.dat
[2012/11/09 23:08:32 | 000,000,632 | RHS- | M] () -- C:\Users\Vernon\ntuser.pol
[2012/11/09 21:57:53 | 000,000,289 | ---- | M] () -- C:\Users\Vernon\Desktop\Paesseler network monitor.rtf
[2012/11/09 21:39:53 | 000,697,272 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerApp.exe
[2012/11/09 21:39:53 | 000,073,656 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\System32\FlashPlayerCPLApp.cpl
[2012/11/08 13:04:43 | 000,035,716 | ---- | M] () -- C:\Users\Vernon\AppData\Roaming\wklnhst.dat
[2012/11/07 09:02:13 | 000,081,920 | ---- | M] () -- C:\Users\Vernon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/11/07 00:50:55 | 000,002,009 | ---- | M] () -- C:\Users\Vernon\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/11/05 07:10:27 | 000,017,711 | ---- | M] () -- C:\Users\Vernon\Desktop\October 31, 2012.wlmp
[2012/11/05 06:49:17 | 010,952,370 | ---- | M] () -- C:\Users\Vernon\Documents\BE FREE2.wav
[2012/11/05 06:41:28 | 013,902,706 | ---- | M] () -- C:\Users\Vernon\Documents\BE FREE.wav
[2012/11/05 06:16:58 | 000,046,591 | ---- | M] () -- C:\Users\Vernon\Documents\JM 08 Nov. 05 06.16.jpg
[2012/11/05 06:16:35 | 000,037,710 | ---- | M] () -- C:\Users\Vernon\Documents\JM 06 Nov. 05 06.16.jpg
[2012/11/05 06:16:13 | 000,049,079 | ---- | M] () -- C:\Users\Vernon\Documents\JM Nov. 05 06.16.jpg
[2012/11/05 06:15:49 | 000,033,977 | ---- | M] () -- C:\Users\Vernon\Documents\JM 03 Nov. 05 06.15.jpg
[2012/11/05 06:15:07 | 000,033,820 | ---- | M] () -- C:\Users\Vernon\Documents\JM Nov. 05 06.15.jpg
[2012/11/05 05:35:45 | 000,115,202 | ---- | M] () -- C:\Users\Vernon\Documents\JM Nov. 05 05.35.jpg
[2012/11/05 05:24:03 | 000,002,790 | ---- | M] () -- C:\Users\Vernon\Documents\JM Nov. 05 05.24.jpg
[2012/11/05 05:15:15 | 000,011,145 | ---- | M] () -- C:\Users\Vernon\Documents\JM Nov. 05 05.15.jpg
[2012/11/05 04:58:44 | 002,201,646 | ---- | M] () -- C:\Users\Vernon\Documents\Bell 3x.wav
[2012/11/05 04:47:44 | 000,000,188 | ---- | M] () -- C:\Windows\sc.INI
[2012/11/05 04:35:12 | 004,163,098 | ---- | M] () -- C:\Users\Vernon\Documents\Bell Ring.wav
[2012/11/05 04:13:58 | 000,009,990 | ---- | M] () -- C:\Users\Vernon\Documents\JM Nov. 05 04.13.jpg
[2012/11/05 00:33:08 | 000,166,007 | ---- | M] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.33.jpg
[2012/11/05 00:29:19 | 000,017,515 | ---- | M] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.29.jpg
[2012/11/05 00:15:50 | 000,023,227 | ---- | M] () -- C:\Users\Vernon\Documents\JM 13 Nov. 05 00.15.jpg
[2012/11/05 00:15:32 | 000,027,183 | ---- | M] () -- C:\Users\Vernon\Documents\JM 11 Nov. 05 00.15.jpg
[2012/11/05 00:15:03 | 000,022,556 | ---- | M] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.15.jpg
[2012/11/05 00:09:24 | 000,018,124 | ---- | M] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.09.jpg
[2012/11/05 00:08:39 | 000,017,821 | ---- | M] () -- C:\Users\Vernon\Documents\JM 07 Nov. 05 00.08.jpg
[2012/11/05 00:08:24 | 000,023,533 | ---- | M] () -- C:\Users\Vernon\Documents\JM 05 Nov. 05 00.08.jpg
[2012/11/05 00:08:06 | 000,018,788 | ---- | M] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.08.jpg
[2012/11/05 00:07:37 | 000,013,185 | ---- | M] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.07.jpg
[2012/11/05 00:06:59 | 000,138,255 | ---- | M] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.06.jpg
[2012/11/02 07:57:55 | 000,676,646 | ---- | M] () -- C:\Users\Vernon\Documents\Texts to Susan.pdf
[2012/11/02 07:29:20 | 000,207,580 | ---- | M] () -- C:\Users\Vernon\Documents\SMS with BOBBI HENRY CUNINGHAM - rockerrr64@gmail -1.pdf
[2012/11/02 07:28:19 | 000,288,950 | ---- | M] () -- C:\Users\Vernon\Documents\Gmail - SMS with BOBBI HENRY CUNINGHAM - 2.pdf
[2012/11/01 05:37:57 | 000,000,438 | ---- | M] () -- C:\Windows\tasks\DriverNavigator Scheduled Scan.job
[2012/10/31 06:43:46 | 000,147,205 | ---- | M] () -- C:\Users\Vernon\Documents\The Salvation Army expands work to 117 countries.pdf
[2012/10/31 06:41:59 | 000,056,968 | ---- | M] () -- C:\Users\Vernon\Documents\501c9b7e404d6.image.jpg
[2012/10/31 06:41:39 | 002,599,064 | ---- | M] () -- C:\Users\Vernon\Documents\New Caldwell lieutenant hopes to help as Salvation Army sees surge in need - Idaho Press-Tribune_ Members.pdf
[2012/10/31 06:36:36 | 000,091,093 | ---- | M] () -- C:\Users\Vernon\Documents\4e0d534bb21a7.image.jpg
[2012/10/31 06:35:52 | 002,212,130 | ---- | M] () -- C:\Users\Vernon\Documents\Recession hits hard at Caldwell Salvation Army - Idaho Press-Tribune_ News2.pdf
[2012/10/31 06:32:42 | 000,109,732 | ---- | M] () -- C:\Users\Vernon\Documents\Recession hits hard at Caldwell Salvation Army - Idaho Press-Tribune_ News.pdf
[2012/10/30 03:56:48 | 000,000,000 | ---- | M] () -- C:\ProgramData\LauncherAccess.dt
[2012/10/24 20:15:08 | 000,013,824 | ---- | M] () -- C:\Users\Vernon\Documents\Key Database.xlr
[2012/10/22 08:52:13 | 000,000,870 | ---- | M] () -- C:\Users\Vernon\Application Data\Microsoft\Internet Explorer\Quick Launch\Glary Undelete.lnk
[2012/10/21 08:55:05 | 000,005,409 | ---- | M] () -- C:\Users\Vernon\Documents\JPEG_000194.jpg.export.000001.jpg
[2012/10/21 08:52:27 | 000,000,264 | ---- | M] () -- C:\Users\Vernon\Documents\JPEG_000194.jpg.tif
[2012/10/19 20:15:22 | 003,327,000 | ---- | M] () -- C:\Users\Vernon\Desktop\WindowsXP-KB942288-v3-x86.exe
[2012/10/18 04:53:09 | 000,000,326 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForVernon.job
[2012/10/18 03:53:31 | 000,000,352 | ---- | M] () -- C:\Users\Vernon\Desktop\Phone Forensics.rtf
[2012/10/17 04:33:19 | 000,000,571 | ---- | M] () -- C:\Users\Vernon\Desktop\Free Photo and File Recovery Software.rtf
[2012/10/17 02:31:39 | 000,444,348 | R--- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[color=#E56717]========== Files Created - No Company Name ==========[/color]
[2012/11/10 07:12:00 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/11/10 06:27:49 | 000,881,833 | ---- | C] () -- C:\Users\Vernon\Desktop\SecurityCheck.exe
[2012/11/10 06:26:22 | 000,008,939 | ---- | C] () -- C:\Users\Vernon\Desktop\cleaning.rtf
[2012/11/10 06:04:28 | 3149,078,528 | -HS- | C] () -- C:\hiberfil.sys
[2012/11/09 21:57:53 | 000,000,289 | ---- | C] () -- C:\Users\Vernon\Desktop\Paesseler network monitor.rtf
[2012/11/05 06:49:15 | 010,952,370 | ---- | C] () -- C:\Users\Vernon\Documents\BE FREE2.wav
[2012/11/05 06:41:23 | 013,902,706 | ---- | C] () -- C:\Users\Vernon\Documents\BE FREE.wav
[2012/11/05 06:16:58 | 000,046,591 | ---- | C] () -- C:\Users\Vernon\Documents\JM 08 Nov. 05 06.16.jpg
[2012/11/05 06:16:35 | 000,037,710 | ---- | C] () -- C:\Users\Vernon\Documents\JM 06 Nov. 05 06.16.jpg
[2012/11/05 06:16:13 | 000,049,079 | ---- | C] () -- C:\Users\Vernon\Documents\JM Nov. 05 06.16.jpg
[2012/11/05 06:15:49 | 000,033,977 | ---- | C] () -- C:\Users\Vernon\Documents\JM 03 Nov. 05 06.15.jpg
[2012/11/05 06:15:07 | 000,033,820 | ---- | C] () -- C:\Users\Vernon\Documents\JM Nov. 05 06.15.jpg
[2012/11/05 05:35:45 | 000,115,202 | ---- | C] () -- C:\Users\Vernon\Documents\JM Nov. 05 05.35.jpg
[2012/11/05 05:24:03 | 000,002,790 | ---- | C] () -- C:\Users\Vernon\Documents\JM Nov. 05 05.24.jpg
[2012/11/05 05:15:15 | 000,011,145 | ---- | C] () -- C:\Users\Vernon\Documents\JM Nov. 05 05.15.jpg
[2012/11/05 04:58:39 | 002,201,646 | ---- | C] () -- C:\Users\Vernon\Documents\Bell 3x.wav
[2012/11/05 04:32:40 | 004,163,098 | ---- | C] () -- C:\Users\Vernon\Documents\Bell Ring.wav
[2012/11/05 04:24:38 | 000,017,711 | ---- | C] () -- C:\Users\Vernon\Desktop\October 31, 2012.wlmp
[2012/11/05 04:13:58 | 000,009,990 | ---- | C] () -- C:\Users\Vernon\Documents\JM Nov. 05 04.13.jpg
[2012/11/05 00:33:08 | 000,166,007 | ---- | C] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.33.jpg
[2012/11/05 00:29:19 | 000,017,515 | ---- | C] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.29.jpg
[2012/11/05 00:15:50 | 000,023,227 | ---- | C] () -- C:\Users\Vernon\Documents\JM 13 Nov. 05 00.15.jpg
[2012/11/05 00:15:32 | 000,027,183 | ---- | C] () -- C:\Users\Vernon\Documents\JM 11 Nov. 05 00.15.jpg
[2012/11/05 00:15:03 | 000,022,556 | ---- | C] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.15.jpg
[2012/11/05 00:09:24 | 000,018,124 | ---- | C] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.09.jpg
[2012/11/05 00:08:39 | 000,017,821 | ---- | C] () -- C:\Users\Vernon\Documents\JM 07 Nov. 05 00.08.jpg
[2012/11/05 00:08:24 | 000,023,533 | ---- | C] () -- C:\Users\Vernon\Documents\JM 05 Nov. 05 00.08.jpg
[2012/11/05 00:08:06 | 000,018,788 | ---- | C] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.08.jpg
[2012/11/05 00:07:37 | 000,013,185 | ---- | C] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.07.jpg
[2012/11/05 00:06:58 | 000,138,255 | ---- | C] () -- C:\Users\Vernon\Documents\JM Nov. 05 00.06.jpg
[2012/11/02 07:57:51 | 000,676,646 | ---- | C] () -- C:\Users\Vernon\Documents\Texts to Susan.pdf
[2012/11/02 07:28:19 | 000,288,950 | ---- | C] () -- C:\Users\Vernon\Documents\Gmail - SMS with BOBBI HENRY CUNINGHAM - 2.pdf
[2012/11/02 07:24:33 | 000,207,580 | ---- | C] () -- C:\Users\Vernon\Documents\SMS with BOBBI HENRY CUNINGHAM - rockerrr64@gmail -1.pdf
[2012/10/31 08:40:36 | 000,000,923 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Prism Video File Converter.lnk
[2012/10/31 06:43:46 | 000,147,205 | ---- | C] () -- C:\Users\Vernon\Documents\The Salvation Army expands work to 117 countries.pdf
[2012/10/31 06:41:59 | 000,056,968 | ---- | C] () -- C:\Users\Vernon\Documents\501c9b7e404d6.image.jpg
[2012/10/31 06:41:38 | 002,599,064 | ---- | C] () -- C:\Users\Vernon\Documents\New Caldwell lieutenant hopes to help as Salvation Army sees surge in need - Idaho Press-Tribune_ Members.pdf
[2012/10/31 06:36:36 | 000,091,093 | ---- | C] () -- C:\Users\Vernon\Documents\4e0d534bb21a7.image.jpg
[2012/10/31 06:35:52 | 002,212,130 | ---- | C] () -- C:\Users\Vernon\Documents\Recession hits hard at Caldwell Salvation Army - Idaho Press-Tribune_ News2.pdf
[2012/10/31 06:32:42 | 000,109,732 | ---- | C] () -- C:\Users\Vernon\Documents\Recession hits hard at Caldwell Salvation Army - Idaho Press-Tribune_ News.pdf
[2012/10/24 16:37:27 | 000,013,824 | ---- | C] () -- C:\Users\Vernon\Documents\Key Database.xlr
[2012/10/22 08:52:13 | 000,000,870 | ---- | C] () -- C:\Users\Vernon\Application Data\Microsoft\Internet Explorer\Quick Launch\Glary Undelete.lnk
[2012/10/21 08:55:05 | 000,005,409 | ---- | C] () -- C:\Users\Vernon\Documents\JPEG_000194.jpg.export.000001.jpg
[2012/10/21 08:52:22 | 000,000,264 | ---- | C] () -- C:\Users\Vernon\Documents\JPEG_000194.jpg.tif
[2012/10/19 20:15:18 | 003,327,000 | ---- | C] () -- C:\Users\Vernon\Desktop\WindowsXP-KB942288-v3-x86.exe
[2012/10/19 19:44:26 | 000,007,188 | ---- | C] () -- C:\Users\Vernon\Desktop\msiserver.reg
[2012/10/19 08:41:04 | 000,001,728 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Play.lnk
[2012/10/18 03:53:31 | 000,000,352 | ---- | C] () -- C:\Users\Vernon\Desktop\Phone Forensics.rtf
[2012/10/17 04:33:19 | 000,000,571 | ---- | C] () -- C:\Users\Vernon\Desktop\Free Photo and File Recovery Software.rtf
[2012/09/17 05:06:04 | 000,044,240 | ---- | C] () -- C:\Windows\System32\drivers\fsbts.sys
[2012/09/16 23:50:47 | 000,416,382 | ---- | C] () -- C:\Users\Vernon\AppData\Local\census.cache
[2012/09/16 23:50:01 | 000,337,899 | ---- | C] () -- C:\Users\Vernon\AppData\Local\ars.cache
[2012/09/16 23:17:30 | 000,000,036 | ---- | C] () -- C:\Users\Vernon\AppData\Local\housecall.guid.cache
[2012/08/28 16:49:10 | 000,584,584 | ---- | C] () -- C:\Windows\adb.exe
[2012/08/27 09:08:42 | 000,032,768 | ---- | C] () -- C:\Windows\System32\diskio.dll
[2012/08/27 09:08:42 | 000,020,296 | ---- | C] () -- C:\Windows\System32\diskrw.dll
[2012/07/30 13:16:20 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012/07/30 13:16:18 | 000,974,848 | ---- | C] () -- C:\Windows\System32\cis-2.4.dll
[2012/07/30 13:16:18 | 000,081,920 | ---- | C] () -- C:\Windows\System32\issacapi_bs-2.3.dll
[2012/07/30 13:16:18 | 000,065,536 | ---- | C] () -- C:\Windows\System32\issacapi_pe-2.3.dll
[2012/07/30 13:16:18 | 000,057,344 | ---- | C] () -- C:\Windows\System32\issacapi_se-2.3.dll
[2012/07/11 16:47:37 | 000,002,189 | ---- | C] () -- C:\Users\Vernon\July Backup
[2012/07/06 15:02:27 | 000,017,408 | ---- | C] () -- C:\Users\Vernon\AppData\Local\WebpageIcons.db
[2012/07/06 15:01:15 | 000,116,189 | ---- | C] () -- C:\Windows\System32\drivers\klin.dat
[2012/07/06 15:01:15 | 000,098,168 | ---- | C] () -- C:\Windows\System32\drivers\klick.dat
[2012/07/02 18:06:11 | 000,003,400 | ---- | C] () -- C:\Windows\System32\EasyRedirect.ini
[2012/07/02 18:06:11 | 000,002,008 | ---- | C] () -- C:\Windows\System32\EasyRedirectOff.ini
[2012/07/01 18:21:43 | 000,204,800 | ---- | C] () -- C:\Windows\System32\IVIresizeW7.dll
[2012/07/01 18:21:43 | 000,200,704 | ---- | C] () -- C:\Windows\System32\IVIresizeA6.dll
[2012/07/01 18:21:43 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeP6.dll
[2012/07/01 18:21:43 | 000,192,512 | ---- | C] () -- C:\Windows\System32\IVIresizeM6.dll
[2012/07/01 18:21:43 | 000,188,416 | ---- | C] () -- C:\Windows\System32\IVIresizePX.dll
[2012/07/01 18:21:42 | 000,020,480 | ---- | C] () -- C:\Windows\System32\IVIresize.dll
[2012/07/01 18:21:01 | 000,831,600 | ---- | C] () -- C:\Windows\System32\Ctaa1.dat
[2012/07/01 18:21:01 | 000,122,880 | ---- | C] () -- C:\Windows\System32\cddvdint.dll
[2012/05/31 22:22:42 | 000,074,703 | ---- | C] () -- C:\Windows\System32\mfc45.dll
[2012/05/18 07:36:43 | 000,000,220 | -HS- | C] () -- C:\Windows\dwin.sys
[2012/05/07 08:01:46 | 000,000,188 | ---- | C] () -- C:\Windows\sc.INI
[2012/05/05 22:48:12 | 000,000,632 | RHS- | C] () -- C:\Users\Vernon\ntuser.pol
[2012/04/17 09:50:02 | 000,001,745 | ---- | C] () -- C:\Windows\IF40LE.INI
[2012/04/17 09:50:02 | 000,000,265 | ---- | C] () -- C:\Windows\PEXPLORE.INI
[2012/04/17 08:55:24 | 000,010,624 | ---- | C] () -- C:\Windows\System32\GENEUSB.SYS
[2012/04/17 08:37:22 | 000,061,440 | ---- | C] () -- C:\Windows\System32\fCommstr.dll
[2012/04/17 08:37:21 | 000,139,264 | ---- | C] () -- C:\Windows\System32\faspi32u.dll
[2012/04/17 08:37:21 | 000,049,152 | ---- | C] () -- C:\Windows\System32\Fmuscrl32.dll
[2012/04/17 08:37:21 | 000,031,232 | ---- | C] () -- C:\Windows\System32\FSCMD32u.dll
[2012/04/15 22:14:39 | 000,000,040 | -HS- | C] () -- C:\ProgramData\.zreglib
[2012/04/13 08:04:50 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2012/03/21 20:55:24 | 000,033,539 | ---- | C] () -- C:\Windows\System32\dischandler.exe
[2012/03/13 11:06:30 | 004,417,024 | ---- | C] () -- C:\Windows\System32\ffmpeg.dll
[2012/03/10 06:55:16 | 000,172,032 | ---- | C] () -- C:\Windows\System32\libbluray.dll
[2012/03/10 06:55:10 | 006,454,984 | ---- | C] () -- C:\Windows\System32\avcodec-lav-54.dll
[2012/03/10 06:55:10 | 001,146,161 | ---- | C] () -- C:\Windows\System32\avformat-lav-54.dll
[2012/03/10 06:55:10 | 000,371,592 | ---- | C] () -- C:\Windows\System32\swscale-lav-2.dll
[2012/03/10 06:55:10 | 000,206,473 | ---- | C] () -- C:\Windows\System32\avutil-lav-51.dll
[2012/03/10 06:55:10 | 000,142,473 | ---- | C] () -- C:\Windows\System32\avfilter-lav-2.dll
[2012/03/04 11:15:11 | 000,118,784 | ---- | C] () -- C:\Windows\ShowBmp.exe
[2012/03/04 11:15:11 | 000,014,381 | ---- | C] () -- C:\Windows\Tw500c.ini
[2012/03/04 11:15:11 | 000,001,325 | ---- | C] () -- C:\Windows\Remove.ini
[2012/02/26 09:47:02 | 000,079,360 | ---- | C] () -- C:\Windows\System32\ff_vfw.dll
[2012/02/26 09:46:18 | 000,260,608 | ---- | C] () -- C:\Windows\System32\TomsMoComp_ff.dll
[2012/02/26 09:46:00 | 000,158,720 | ---- | C] () -- C:\Windows\System32\ff_unrar.dll
[2012/02/26 09:46:00 | 000,099,840 | ---- | C] () -- C:\Windows\System32\ff_wmv9.dll
[2012/02/26 09:45:58 | 001,525,248 | ---- | C] () -- C:\Windows\System32\ff_samplerate.dll
[2012/02/26 09:45:58 | 000,146,944 | ---- | C] () -- C:\Windows\System32\ff_libmad.dll
[2012/02/26 09:45:56 | 000,212,480 | ---- | C] () -- C:\Windows\System32\ff_libdts.dll
[2012/02/26 09:45:56 | 000,115,200 | ---- | C] () -- C:\Windows\System32\ff_liba52.dll
[2012/02/26 09:45:54 | 000,328,704 | ---- | C] () -- C:\Windows\System32\ff_libfaad2.dll
[2012/02/26 09:45:54 | 000,137,728 | ---- | C] () -- C:\Windows\System32\libmpeg2_ff.dll
[2011/12/30 06:19:17 | 000,004,110 | ---- | C] () -- C:\ProgramData\aaukbyma.jmq
[2011/12/14 20:44:03 | 000,000,064 | ---- | C] () -- C:\Windows\System32\rp_stats.dat
[2011/12/14 20:44:03 | 000,000,044 | ---- | C] () -- C:\Windows\System32\rp_rules.dat
[2011/12/08 15:42:14 | 000,000,055 | ---- | C] () -- C:\Windows\System32\BRDH2240.DAT
[2011/12/07 12:32:24 | 000,216,064 | ---- | C] ( ) -- C:\Windows\System32\Lagarith.dll
[2011/12/02 10:24:28 | 000,910,920 | ---- | C] () -- C:\Windows\System32\pwNative.exe
[2011/12/02 10:24:27 | 000,016,472 | ---- | C] () -- C:\Windows\System32\pwdrvio.sys
[2011/12/02 10:24:07 | 000,011,104 | ---- | C] () -- C:\Windows\System32\pwdspio.sys
[2011/11/29 01:37:17 | 000,000,345 | ---- | C] () -- C:\Windows\pagebreeze.ini
[2011/11/29 01:37:17 | 000,000,044 | ---- | C] () -- C:\Windows\formbreeze.ini
[2011/10/21 09:46:26 | 000,159,744 | ---- | C] () -- C:\Windows\System32\msrOnlern.dll
[2011/09/08 07:00:52 | 000,150,528 | ---- | C] () -- C:\Windows\System32\mkx.dll
[2011/09/08 07:00:48 | 000,142,336 | ---- | C] () -- C:\Windows\System32\mp4.dll
[2011/09/08 07:00:42 | 000,123,392 | ---- | C] () -- C:\Windows\System32\ogm.dll
[2011/09/08 07:00:38 | 000,249,856 | ---- | C] () -- C:\Windows\System32\dxr.dll
[2011/09/08 07:00:34 | 000,113,152 | ---- | C] () -- C:\Windows\System32\dsmux.exe
[2011/09/08 07:00:24 | 000,154,624 | ---- | C] () -- C:\Windows\System32\ts.dll
[2011/09/08 07:00:10 | 000,137,728 | ---- | C] () -- C:\Windows\System32\mkv2vfr.exe
[2011/09/08 07:00:06 | 000,358,400 | ---- | C] () -- C:\Windows\System32\gdsmux.exe
[2011/09/08 06:59:54 | 000,080,384 | ---- | C] () -- C:\Windows\System32\mkzlib.dll
[2011/09/08 06:59:52 | 000,024,576 | ---- | C] () -- C:\Windows\System32\mkunicode.dll
[2011/08/14 06:36:15 | 002,319,536 | ---- | C] () -- C:\Windows\System32\Incinerator.dll
[2011/08/04 09:46:26 | 000,009,845 | ---- | C] () -- C:\Windows\System32\mswcnlope.dll
[2011/06/22 18:39:22 | 000,155,648 | ---- | C] () -- C:\Windows\System32\daspi32u.dll
[2011/06/22 18:39:22 | 000,143,360 | ---- | C] () -- C:\Windows\System32\PF1800LC.Dll
[2011/06/22 18:39:22 | 000,106,496 | ---- | C] () -- C:\Windows\System32\IO_PORT.DLL
[2011/06/22 18:39:22 | 000,102,400 | ---- | C] () -- C:\Windows\System32\FVC.DLL
[2011/06/22 18:39:22 | 000,049,152 | ---- | C] () -- C:\Windows\System32\PWiaExt.dll
[2011/06/22 18:39:22 | 000,032,768 | ---- | C] () -- C:\Windows\System32\SQ1394.DLL
[2011/06/22 18:39:22 | 000,010,624 | ---- | C] () -- C:\Windows\System32\drivers\GENEUSB.SYS
[2011/06/22 18:39:21 | 000,000,234 | ---- | C] () -- C:\Windows\Scanner.ini
[2011/06/17 23:31:38 | 000,001,940 | ---- | C] () -- C:\Users\Vernon\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/05/30 06:42:50 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2011/05/23 00:46:30 | 000,645,632 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2011/03/11 11:43:54 | 000,029,763 | ---- | C] () -- C:\Windows\System32\drivers\klopp.dat
[2011/03/03 04:39:56 | 000,109,568 | ---- | C] () -- C:\Windows\System32\avi.dll
[2011/03/03 04:38:10 | 000,097,792 | ---- | C] () -- C:\Windows\System32\avs.dll
[2011/03/03 04:37:50 | 000,093,184 | ---- | C] () -- C:\Windows\System32\avss.dll
[2011/02/18 07:08:39 | 000,159,744 | ---- | C] () -- C:\Windows\System32\msrcclopd.dll
[2011/02/11 18:40:40 | 000,004,096 | ---- | C] ( ) -- C:\Windows\System32\IGFXDEVLib.dll
[2011/02/10 08:35:43 | 000,000,056 | -H-- | C] () -- C:\ProgramData\ezsidmv.dat
[2011/01/14 16:47:57 | 003,799,951 | ---- | C] () -- C:\Windows\System32\erdmpg-6.dll
[2011/01/05 09:10:40 | 000,004,957 | ---- | C] () -- C:\ProgramData\gcmsfupc.omw
[2010/12/29 09:36:11 | 000,065,536 | ---- | C] () -- C:\Windows\System32\afasrv32.exe
[2010/09/13 06:59:19 | 000,000,000 | -H-- | C] () -- C:\Users\Vernon\AppData\Roaming\1 .exe
[2010/07/16 00:30:21 | 000,000,000 | ---- | C] () -- C:\ProgramData\LauncherAccess.dt
[2010/03/07 15:35:28 | 000,001,492 | ---- | C] () -- C:\ProgramData\ss.ini
[2009/10/14 13:45:05 | 000,027,503 | ---- | C] () -- C:\Users\Vernon\AppData\Roaming\UserTile.png
[2009/09/28 09:24:11 | 000,035,716 | ---- | C] () -- C:\Users\Vernon\AppData\Roaming\wklnhst.dat
[2009/09/08 07:48:05 | 000,081,920 | ---- | C] () -- C:\Users\Vernon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/08/18 06:23:51 | 000,001,356 | ---- | C] () -- C:\Users\Vernon\AppData\Local\d3d9caps.dat
[2009/06/08 16:50:53 | 000,000,284 | ---- | C] () -- C:\ProgramData\hpqp.ini
[color=#E56717]========== ZeroAccess Check ==========[/color]
[2006/11/02 05:54:22 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 10:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/04/10 23:28:19 | 000,614,912 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/10 23:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[color=#E56717]========== LOP Check ==========[/color]
[2012/08/31 16:04:38 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Ad-Aware Antivirus
[2012/04/06 07:57:55 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Amrak phoneMiner
[2012/05/05 06:21:49 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\AnnVideo
[2012/05/31 05:45:47 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\AVG2012
[2012/10/19 10:22:19 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Azureus
[2010/12/30 03:28:27 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Blitware
[2012/11/07 13:21:16 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\CoreFTP
[2012/02/22 15:48:30 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Dekart
[2011/01/14 16:48:21 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Doblon
[2012/09/11 08:09:41 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\DocFetcher
[2012/02/25 17:00:38 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\DriverCure
[2011/12/27 10:44:50 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Easeware
[2012/07/22 09:20:36 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Foxit Software
[2012/10/22 08:52:12 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\GlarySoft
[2012/01/08 22:01:18 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Hermetic Systems
[2012/09/15 04:49:00 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\ICQ
[2012/04/09 15:49:36 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\InfraRecorder
[2012/07/01 18:27:05 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\InterVideo
[2012/09/11 08:09:41 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\iolo
[2012/09/16 01:04:48 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\IrfanView
[2012/09/09 06:32:22 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\iSpy
[2012/10/24 04:11:04 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\JPEGsnoop
[2011/01/08 11:06:31 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Leadertech
[2011/09/03 02:59:18 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\ManyCam
[2012/02/25 14:19:43 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Motorola
[2012/05/25 14:01:01 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Motorola Mobility
[2010/02/05 01:08:53 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\muvee Technologies
[2012/09/11 08:09:49 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\MyPhoneExplorer
[2011/01/22 19:06:47 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\NCH Swift Sound
[2012/04/13 08:04:45 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Netscape
[2012/08/07 23:52:48 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Nico Mak Computing
[2012/03/19 05:31:53 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\OxyForensic
[2012/04/04 11:05:02 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\PACE Anti-Piracy
[2012/10/22 08:59:01 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\PandoraRecovery
[2012/08/31 05:35:15 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\PC Cleaners
[2012/08/28 03:38:20 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\PC Suite
[2012/08/31 05:35:16 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\PCPro
[2012/10/10 17:15:40 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\PDAppFlex
[2009/10/14 13:45:04 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\PeerNetworking
[2010/08/01 08:38:36 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Philipp Winterberg
[2011/07/29 20:09:46 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\PIE
[2011/01/21 13:36:01 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Recordpad
[2011/02/26 01:14:32 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Recover Files from CD
[2012/09/11 08:09:49 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\RipIt4Me
[2012/08/28 03:38:21 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Samsung
[2012/01/27 22:33:59 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Scooter Software
[2010/06/23 14:01:02 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Skinux
[2012/02/25 17:00:37 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\SpeedMaxPc
[2012/10/10 03:34:19 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\SpeedyPC Software
[2010/05/04 20:44:21 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\SumatraPDF
[2012/03/20 07:53:43 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Teleca
[2009/09/28 09:24:14 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Template
[2010/07/04 03:26:56 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Tific
[2012/04/04 11:14:15 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Unity
[2012/10/31 08:28:57 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\VideoDownloadToolbar
[2011/01/30 04:16:12 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Visan
[2012/01/02 20:23:44 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Wal-Mart
[2010/10/01 13:29:13 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\WalaSoft
[2009/09/29 07:09:39 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\WildTangent
[2010/05/18 08:21:11 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\WinBatch
[2010/10/29 12:47:23 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Windows Live Writer
[2011/12/27 10:15:21 | 000,000,000 | ---D | M] -- C:\Users\Vernon\AppData\Roaming\Xilisoft Corporation
[color=#E56717]========== Purity Check ==========[/color]
[color=#E56717]========== Alternate Data Streams ==========[/color]
@Alternate Data Stream - 361 bytes -> C:\ProgramData\Temp:8927A071
@Alternate Data Stream - 160 bytes -> C:\ProgramData\Temp:7631EA83
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:B468194E
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:D1B5B4F1
@Alternate Data Stream - 126 bytes -> C:\ProgramData\Temp:0CFE8F97
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:C895616B
--
~Safe Hex~ Team Discovery ~ Project Hope ~ Like A Hurricane~