========== Files/Folders - Created Within 30 Days ==========
[2013/06/20 16:32:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Java
[2013/06/20 16:32:45 | 000,096,168 | ---- | C] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/06/19 09:04:08 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2013/06/19 09:02:39 | 000,000,000 | ---D | C] -- C:\$RECYCLE.BIN
[2013/06/19 08:57:13 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2013/06/19 08:57:13 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2013/06/19 08:57:13 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2013/06/19 08:55:48 | 003,529,160 | ---- | C] (AVG Technologies CZ, s.r.o.) -- C:\avg_remover_stf_x64_2013_3341.exe
[2013/06/19 08:54:41 | 000,000,000 | ---D | C] -- C:\Users\Philippe Marchal\AppData\Local\Avg2013
[2013/06/19 08:47:37 | 000,000,000 | ---D | C] -- C:\Qoobox
[2013/06/19 08:47:31 | 000,000,000 | ---D | C] -- C:\Windows\erdnt
[2013/06/17 11:44:44 | 000,000,000 | ---D | C] -- C:\Users\Philippe Marchal\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Notepad++
[2013/06/17 11:44:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Notepad++
[2013/06/17 11:44:43 | 000,000,000 | ---D | C] -- C:\Users\Philippe Marchal\AppData\Roaming\Notepad++
[2013/06/17 11:44:43 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Notepad++
[2013/06/17 10:57:52 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2013/06/16 16:12:41 | 000,000,000 | ---D | C] -- C:\Windows\hpoj4500g510a-f
[2013/06/16 16:12:37 | 000,136,704 | ---- | C] (Hewlett-Packard Company) -- C:\Windows\SysNative\hpf3l70w.dll
[2013/06/16 16:12:36 | 000,000,000 | ---D | C] -- C:\Config.Msi
[2013/06/16 16:11:52 | 000,642,360 | ---- | C] (Hewlett-Packard) -- C:\Windows\SysNative\hpzids40.dll
[2013/06/16 16:02:04 | 000,000,000 | ---D | C] -- C:\TEMP
[2013/06/16 16:01:48 | 001,417,728 | ---- | C] (Hewlett-Packard Co.) -- C:\Windows\SysNative\hpwtiop6.dll
[2013/06/16 16:01:48 | 000,901,632 | ---- | C] (Hewlett-Packard) -- C:\Windows\SysNative\hpwwiax7.dll
[2013/06/16 16:01:48 | 000,502,272 | ---- | C] (Hewlett-Packard Co.) -- C:\Windows\SysNative\hpwvst01.dll
[2013/06/16 16:01:48 | 000,043,008 | ---- | C] (Hewlett-Packard) -- C:\Windows\SysNative\hpwentco.dll
[2013/06/16 15:59:01 | 000,000,000 | ---D | C] -- C:\Users\Philippe Marchal\AppData\Roaming\HP
[2013/06/16 15:57:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HP
[2013/06/16 15:57:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\HP
[2013/06/16 15:57:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Hewlett-Packard
[2013/06/16 15:57:25 | 000,000,000 | ---D | C] -- C:\Windows\hpoj4500g510g-m
[2013/06/16 15:57:09 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\HP
[2013/06/16 15:56:53 | 000,551,424 | ---- | C] (Hewlett-Packard) -- C:\Windows\SysNative\hppldcoi.dll
[2013/06/16 15:56:53 | 000,000,000 | ---D | C] -- C:\ProgramData\HP
[2013/06/16 15:29:44 | 000,000,000 | ---D | C] -- C:\Users\Philippe Marchal\Documents\Virus Logs
[2013/06/16 14:44:30 | 000,000,000 | ---D | C] -- C:\Users\Philippe Marchal\Desktop\Huis Expenses
[2013/06/09 18:51:22 | 000,000,000 | ---D | C] -- C:\Users\Philippe Marchal\AppData\Local\AviraSpeedup
[2013/06/09 18:51:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AviraSpeedup
[2013/06/06 16:47:51 | 000,328,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\services.exe
[2013/06/06 16:42:05 | 000,000,000 | ---D | C] -- C:\Users\Philippe Marchal\Desktop\RK_Quarantine
[2013/06/06 15:18:52 | 000,083,160 | ---- | C] (Avira GmbH) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2013/06/06 15:11:14 | 000,000,000 | ---D | C] -- C:\Users\Philippe Marchal\AppData\Roaming\Avira
[2013/06/06 15:07:25 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2013/06/06 15:07:24 | 000,130,016 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2013/06/06 15:07:24 | 000,100,712 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2013/06/06 15:07:24 | 000,028,600 | ---- | C] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2013/06/06 15:07:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Avira
[2013/06/06 15:07:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Avira
[2013/06/06 15:02:48 | 000,000,000 | ---D | C] -- C:\Users\Philippe Marchal\AppData\Roaming\TuneUp Software
[2013/06/06 14:56:46 | 000,000,000 | ---D | C] -- C:\Users\Philippe Marchal\AppData\Roaming\WTablet
[2013/06/06 14:28:25 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2013/06/06 14:28:05 | 000,000,000 | ---D | C] -- C:\JRT
[2013/06/06 14:14:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PostgreSQL 9.3
[2013/06/06 14:01:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MALWAREBYTES ANTI-MALWARE
[2013/06/06 12:40:54 | 000,000,000 | ---D | C] -- C:\Users\Philippe Marchal\AppData\Local\Programs
[2013/06/05 17:59:13 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\%APPDATA%
[2013/06/05 13:31:22 | 000,033,856 | -H-- | C] (LogMeIn, Inc.) -- C:\Windows\SysNative\hamachi.sys
[2013/06/05 13:31:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2013/06/05 13:31:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
[2013/05/26 16:01:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2013/05/26 15:32:18 | 000,000,000 | ---D | C] -- C:\Users\Philippe Marchal\AppData\Local\Macromedia
[2013/05/26 14:18:32 | 000,692,104 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/05/26 14:18:31 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\Macromed
[2011/05/10 19:09:04 | 001,028,096 | ---- | C] (The OpenSSL Project,
http://www.openssl.org/) -- C:\Users\Philippe Marchal\libeay32.dll
[2011/05/10 19:09:04 | 000,632,656 | ---- | C] (Microsoft Corporation) -- C:\Users\Philippe Marchal\msvcr80.dll
[2011/05/10 19:09:04 | 000,554,832 | ---- | C] (Microsoft Corporation) -- C:\Users\Philippe Marchal\msvcp80.dll
[2011/05/10 19:09:04 | 000,200,704 | ---- | C] (The OpenSSL Project,
http://www.openssl.org/) -- C:\Users\Philippe Marchal\ssleay32.dll
========== Files - Modified Within 30 Days ==========
[2013/06/20 16:32:43 | 000,867,240 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\npdeployJava1.dll
[2013/06/20 16:32:43 | 000,789,416 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\deployJava1.dll
[2013/06/20 16:32:43 | 000,263,592 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaws.exe
[2013/06/20 16:32:43 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\javaw.exe
[2013/06/20 16:32:43 | 000,175,016 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\java.exe
[2013/06/20 16:32:43 | 000,096,168 | ---- | M] (Oracle Corporation) -- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/06/20 16:31:43 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/06/20 16:31:43 | 000,014,016 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/06/20 16:30:58 | 000,778,844 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2013/06/20 16:30:58 | 000,660,042 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2013/06/20 16:30:58 | 000,120,680 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2013/06/20 16:26:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2013/06/20 16:25:52 | 000,000,145 | ---- | M] () -- C:\Windows\DeleteOnReboot.bat
[2013/06/19 17:14:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/06/19 09:01:41 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2013/06/19 08:54:35 | 003,529,160 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\avg_remover_stf_x64_2013_3341.exe
[2013/06/17 11:44:44 | 000,001,059 | ---- | M] () -- C:\Users\Philippe Marchal\Desktop\Notepad++.lnk
[2013/06/17 10:43:15 | 000,001,664 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2013/06/16 16:14:15 | 000,098,440 | ---- | M] () -- C:\Windows\hpwins27.dat
[2013/06/16 15:59:00 | 000,142,516 | ---- | M] () -- C:\Windows\hpwins26.dat
[2013/06/15 14:14:06 | 000,692,104 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/06/15 14:14:06 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/06/09 18:51:22 | 000,001,163 | ---- | M] () -- C:\Users\Philippe Marchal\Desktop\Avira System Speedup.lnk
[2013/06/06 15:18:52 | 000,083,160 | ---- | M] (Avira GmbH) -- C:\Windows\SysNative\drivers\avnetflt.sys
[2013/06/06 15:07:25 | 000,002,066 | ---- | M] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2013/06/06 15:06:57 | 000,130,016 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avipbb.sys
[2013/06/06 15:06:57 | 000,100,712 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avgntflt.sys
[2013/06/06 15:06:57 | 000,028,600 | ---- | M] (Avira Operations GmbH & Co. KG) -- C:\Windows\SysNative\drivers\avkmgr.sys
[2013/06/06 12:41:07 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/31 09:15:04 | 000,001,154 | ---- | M] () -- C:\Users\Philippe Marchal\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/05/26 13:17:13 | 000,001,088 | ---- | M] () -- C:\Users\Philippe Marchal\Desktop\HoldemManager2.lnk
========== Files Created - No Company Name ==========
[2013/06/20 16:25:45 | 000,000,145 | ---- | C] () -- C:\Windows\DeleteOnReboot.bat
[2013/06/19 08:57:13 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2013/06/19 08:57:13 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2013/06/19 08:57:13 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2013/06/19 08:57:13 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2013/06/19 08:57:13 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2013/06/17 11:44:44 | 000,001,059 | ---- | C] () -- C:\Users\Philippe Marchal\Desktop\Notepad++.lnk
[2013/06/17 10:43:15 | 000,001,664 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Acrobat X Pro.lnk
[2013/06/16 16:12:22 | 000,098,440 | ---- | C] () -- C:\Windows\hpwins27.dat
[2013/06/16 16:12:22 | 000,000,385 | ---- | C] () -- C:\Windows\hpwmdl27.dat
[2013/06/16 15:56:55 | 000,142,516 | ---- | C] () -- C:\Windows\hpwins26.dat
[2013/06/16 15:56:55 | 000,000,370 | ---- | C] () -- C:\Windows\hpwmdl26.dat
[2013/06/09 18:51:22 | 000,001,163 | ---- | C] () -- C:\Users\Philippe Marchal\Desktop\Avira System Speedup.lnk
[2013/06/06 15:07:25 | 000,002,066 | ---- | C] () -- C:\Users\Public\Desktop\Avira Control Center.lnk
[2013/06/06 12:41:07 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/05/26 14:18:32 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/05/26 13:17:13 | 000,001,088 | ---- | C] () -- C:\Users\Philippe Marchal\Desktop\HoldemManager2.lnk
[2012/11/21 15:10:20 | 003,123,272 | R--- | C] () -- C:\Windows\SysWow64\pbsvc.exe
[2012/10/31 19:18:18 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2012/09/28 18:40:21 | 000,000,018 | ---- | C] () -- C:\Windows\Nexsyn.ini
[2012/09/28 18:34:41 | 000,005,729 | ---- | C] () -- C:\Windows\mgxoschk.ini
[2012/09/11 19:17:32 | 000,794,900 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2012/09/11 19:15:06 | 003,130,440 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_blr.exe
[2012/07/12 19:51:18 | 000,000,051 | ---- | C] () -- C:\ProgramData\ohbopdukkuuyhto
[2012/02/29 14:55:07 | 000,679,936 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2012/02/29 14:55:07 | 000,155,648 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2011/10/26 18:51:37 | 000,000,000 | ---- | C] () -- C:\Windows\SysWow64\cd.dat
[2011/10/26 18:30:07 | 000,298,016 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2011/10/26 18:30:06 | 000,075,136 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2011/10/15 00:54:52 | 000,321,856 | ---- | C] () -- C:\Windows\SysWow64\nvStreaming.exe
[2011/09/19 14:26:00 | 000,000,132 | ---- | C] () -- C:\Users\Philippe Marchal\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2011/08/10 15:11:44 | 000,124,540 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011/08/04 21:32:47 | 000,000,262 | ---- | C] () -- C:\Windows\{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}_WiseFW.ini
[2011/07/14 12:48:51 | 000,000,028 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/06/02 11:35:02 | 000,005,078 | ---- | C] () -- C:\ProgramData\bltofzsb.qlf
[2011/05/20 15:38:23 | 000,000,132 | ---- | C] () -- C:\Users\Philippe Marchal\AppData\Roaming\Adobe PNG Format CS5 Prefs
[2011/05/15 22:55:48 | 000,000,359 | ---- | C] () -- C:\Users\Philippe Marchal\Shentaku.xml
[2011/05/15 22:17:36 | 000,000,727 | ---- | C] () -- C:\Users\Philippe Marchal\application.prefs
[2011/05/10 19:09:38 | 000,158,643 | ---- | C] () -- C:\Users\Philippe Marchal\uninstall.dat
[2011/05/10 19:09:04 | 009,826,304 | ---- | C] () -- C:\Users\Philippe Marchal\QtWebKit4.dll
[2011/05/10 19:09:04 | 007,778,304 | ---- | C] () -- C:\Users\Philippe Marchal\QtGui4.dll
[2011/05/10 19:09:04 | 002,097,152 | ---- | C] () -- C:\Users\Philippe Marchal\QtCore4.dll
[2011/05/10 19:09:04 | 000,929,792 | ---- | C] () -- C:\Users\Philippe Marchal\QtNetwork4.dll
[2011/05/10 19:09:04 | 000,344,064 | ---- | C] () -- C:\Users\Philippe Marchal\QtXml4.dll
[2011/05/10 19:09:04 | 000,282,624 | ---- | C] () -- C:\Users\Philippe Marchal\QtSvg4.dll
[2011/05/10 19:09:04 | 000,250,033 | ---- | C] () -- C:\Users\Philippe Marchal\server.xml
[2011/05/10 19:09:04 | 000,245,760 | ---- | C] () -- C:\Users\Philippe Marchal\phonon4.dll
[2011/05/10 19:09:04 | 000,196,608 | ---- | C] () -- C:\Users\Philippe Marchal\QtSql4.dll
[2011/05/10 19:09:04 | 000,153,600 | ---- | C] () -- C:\Users\Philippe Marchal\setup.ilg
[2011/05/10 19:09:04 | 000,044,697 | ---- | C] () -- C:\Users\Philippe Marchal\preferences.orig
[2011/05/10 19:09:02 | 000,064,542 | ---- | C] () -- C:\Users\Philippe Marchal\ab.dat
[2011/05/10 19:09:02 | 000,002,933 | ---- | C] () -- C:\Users\Philippe Marchal\bdef.dat
[2011/05/10 19:09:02 | 000,000,000 | ---- | C] () -- C:\Users\Philippe Marchal\Aft.bin
[2011/05/10 19:04:02 | 000,244,408 | ---- | C] () -- C:\Users\Philippe Marchal\client.xml
========== ZeroAccess Check ==========
[2009/07/14 06:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2009/07/14 03:41:54 | 014,161,920 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2009/07/14 03:16:14 | 012,866,560 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/14 03:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2009/07/14 03:15:20 | 000,605,696 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/14 03:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/12/12 10:50:31 | 000,000,000 | ---D | M] -- C:\Users\Default\AppData\Roaming\TuneUp Software
[2012/12/12 10:50:31 | 000,000,000 | ---D | M] -- C:\Users\Default User\AppData\Roaming\TuneUp Software
[2012/12/05 18:23:53 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\.minecraft
[2011/05/16 13:09:44 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\Autodesk
[2011/05/27 19:24:42 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\DAEMON Tools Lite
[2012/12/05 11:02:15 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\DiskSpaceFan
[2012/10/27 15:31:35 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\FileZilla
[2011/05/30 13:57:53 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\FreeArc
[2011/07/31 23:47:42 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\Greyfirst
[2011/11/20 12:04:51 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\HEM Data
[2013/06/06 14:16:46 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\HoldemManager
[2011/05/28 14:31:08 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\Lionhead Studios
[2011/08/04 21:39:52 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\LolClient
[2012/09/28 18:58:49 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\MtStudio
[2012/11/18 01:43:52 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\Natural Selection 2
[2013/06/17 11:44:58 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\Notepad++
[2011/05/23 23:12:19 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\OpenOffice.org
[2011/10/26 17:59:56 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\Origin
[2011/05/12 23:39:42 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\PACE Anti-Piracy
[2012/10/03 16:26:17 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\PianoBooster
[2011/08/15 20:24:51 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\Poser
[2012/11/02 16:34:09 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\Sports Interactive
[2012/12/29 10:47:09 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\Spotify
[2012/12/05 18:01:30 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\Subversion
[2012/12/23 01:27:08 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\Synthesia
[2011/05/12 22:12:44 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\Thunderbird
[2013/06/06 15:02:48 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\TuneUp Software
[2013/06/05 17:51:43 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\uTorrent
[2012/03/07 10:45:55 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\Wacom
[2012/03/07 10:45:55 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\wacomid-desktop-launcher.DCFD4B89A63EE70BC162777F06D4B93B6397AEC7.1
[2012/12/05 18:00:12 | 000,000,000 | ---D | M] -- C:\Users\Philippe Marchal\AppData\Roaming\WaterProof
========== Purity Check ==========
========== Alternate Data Streams ==========
@Alternate Data Stream - 1234 bytes -> C:\ProgramData\Microsoft:LflBTErKbq7g0peT9KFDMilqzP5B
@Alternate Data Stream - 1123 bytes -> C:\ProgramData\Microsoft:ss3wdDmc81bKnvxHSUgAbKR
@Alternate Data Stream - 1105 bytes -> C:\Program Files\Common Files\System:TauFqBIYc2zV2nU0hsD5WW2
< End of report >