Greetings CatByte,thank you for responding to my query for help. I just bought this machine last month, when i got it home the hard drive was defective so I sent it back to ASUS and they replaced the drive. I bought the machine for entertaiment purpose only, I like to play some of the games. Im retired and have small SSI , this is the best I could afford and the salesman said the machine would be sufficent for my use. I bought game titled "Battlefield bad company2" by EA. I installed the game but it ran so badly I could not run the program. Also when surfing the net both my IE and Mozilla firefox browsers would crash several times per hour requiring restart. My computer knowledge is very limited,Ive been using them since they became available but never had any instruction and just used them mainly for entertainment purposes. the following inserts are the quick scan copies from OTL program as per your directions sent 6/13. Thank for your expertise and time I hope to make a donation in your honor for your kindness. regards, surfnwood(jeffrey)
OTL scan results ;OTL Extras logfile created on: 6/14/2010 8:57:08 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\Chris B. Stiffer\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 74.00% Memory free
15.00 Gb Paging File | 13.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): c:\pagefile.sys 9213 12000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86
THIS IS PART 2 OF 2
OTL logfile created on: 6/14/2010 8:57:08 AM - Run 1
OTL by OldTimer - Version 3.2.6.0 Folder = C:\Users\Chris B. Stiffer\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.18928)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
6.00 Gb Total Physical Memory | 4.00 Gb Available Physical Memory | 74.00% Memory free
15.00 Gb Paging File | 13.00 Gb Available in Paging File | 90.00% Paging File free
Paging file location(s): c:\pagefile.sys 9213 12000 [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 279.46 Gb Total Space | 187.15 Gb Free Space | 66.97% Space Free | Partition Type: NTFS
Drive D: | 409.17 Gb Total Space | 409.00 Gb Free Space | 99.96% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OFFICE
Current User Name: Chris B. Stiffer
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
========== Processes (SafeList) ==========
PRC - C:\Users\Chris B. Stiffer\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Windows\SysWOW64\PnkBstrB.exe ()
PRC - C:\Windows\SysWOW64\PnkBstrA.exe ()
PRC - C:\Program Files (x86)\IObit\IObit Security 360\is360.exe (IObit)
PRC - C:\Program Files (x86)\Kensington TrackballWorks\KTbWorksS.exe (Kensington Computer Products Group)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 3\AWC.exe (IObit)
PRC - C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files (x86)\Orbitdownloader\orbitdm.exe (Orbitdownloader.com)
PRC - C:\Program Files (x86)\IObit\IObit Security 360\is360tray.exe (IObit)
PRC - C:\Program Files (x86)\IObit\IObit Security 360\is360srv.exe (IObit)
PRC - C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
PRC - C:\Program Files (x86)\Microsoft\Office Live\OfficeLiveSignIn.exe (Microsoft Corp.)
PRC - C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Program Files (x86)\Microsoft Office\Office12\WINWORD.EXE (Microsoft Corporation)
PRC - C:\Program Files (x86)\Orbitdownloader\orbitnet.exe (Orbitdownloader.com)
PRC - C:\Program Files (x86)\Common Files\Logishrd\LVMVFM\LVPrS64H.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\ASUS\EPU-4 Engine\FourEngine.exe ()
PRC - C:\Program Files\ASUS\AI Manager\AsShellApplication.exe (ASUSTeK)
PRC - C:\Program Files (x86)\ASUS\AASP\1.00.82\aaCenter.exe ()
PRC - C:\Windows\SysWOW64\AsHookDevice.exe (ASUSTeK)
========== Modules (SafeList) ==========
MOD - C:\Users\Chris B. Stiffer\Desktop\OTL.exe (OldTimer Tools)
MOD - C:\Windows\SysWOW64\comdlg32.dll (Microsoft Corporation)
MOD - C:\Windows\SysWOW64\msscript.ocx (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:
64bit: - (MatSvc) – C:\Program Files\Microsoft Fix it Center\Matsvc.exe (Microsoft Corporation)
SRV:
64bit: - (LVPrcS64) – C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe (Logitech Inc.)
SRV:
64bit: - (FontCache) – C:\Windows\SysNative\FntCache.dll (Microsoft Corporation)
SRV:
64bit: - (wlidsvc) – C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE (Microsoft Corporation)
SRV:
64bit: - (BthServ) – C:\Windows\SysNative\bthserv.dll (Microsoft Corporation)
SRV:
64bit: - (getPlusHelper) – C:\Windows\SysNative\svchost.exe (Microsoft Corporation)
SRV:
64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Akamai) – C:/Program Files (x86)/Common Files/Akamai/rswin_3697.dll ()
SRV - (PnkBstrB) – C:\Windows\SysWOW64\PnkBstrB.exe ()
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (KTbWorksService) – C:\Program Files (x86)\Kensington TrackballWorks\KTbWorksS.exe (Kensington Computer Products Group)
SRV - (IS360service) – C:\Program Files (x86)\IObit\IObit Security 360\is360srv.exe (IObit)
SRV - (fsssvc) – C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe (Microsoft Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (StumbleUponUpdateService) – C:\Program Files (x86)\StumbleUpon\StumbleUponUpdateService.exe (stumbleupon.com)
SRV - (SeaPort) – C:\Program Files (x86)\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_64) – C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (Device Handle Service) – C:\Windows\SysWOW64\AsHookDevice.exe (ASUSTeK)
SRV - (MSDTC) – C:\Windows\SysWOW64\Msdtc [2006/11/02 06:34:14 | 000,000,000 | —D | M]
SRV - (vds) – C:\Windows\SysWOW64\wbem\vds.mof ()
SRV - (VSS) – C:\Windows\SysWOW64\wbem\vss.mof ()
========== Driver Services (SafeList) ==========
DRV:
64bit: - (HMuKstOO) – C:\Windows\SysNative\DRIVERS\HMuKstOO.sys (Dritek System Inc.)
DRV:
64bit: - (fssfltr) – C:\Windows\SysNative\DRIVERS\fssfltr.sys (Microsoft Corporation)
DRV:
64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek )
DRV:
64bit: - (Revoflt) – C:\Windows\SysNative\DRIVERS\revoflt.sys (VS Revo Group)
DRV:
64bit: - (LVPr2Mon) – C:\Windows\SysNative\DRIVERS\LVPr2M64.sys ()
DRV:
64bit: - (LVPr2M64) – C:\Windows\SysNative\DRIVERS\LVPr2M64.sys ()
DRV:
64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:
64bit: - (WmXlCore) – C:\Windows\SysNative\drivers\WmXlCore.sys (Logitech Inc.)
DRV:
64bit: - (WmVirHid) – C:\Windows\SysNative\drivers\WmVirHid.sys (Logitech Inc.)
DRV:
64bit: - (WmBEnum) – C:\Windows\SysNative\drivers\WmBEnum.sys (Logitech Inc.)
DRV:
64bit: - (pavboot) – C:\Windows\SysNative\drivers\pavboot64.sys (Panda Security, S.L.)
DRV:
64bit: - (LVRS64) – C:\Windows\SysNative\DRIVERS\lvrs64.sys (Logitech Inc.)
DRV:
64bit: - (PID_PEPI) Logitech QuickCam IM(PID_PEPI) – C:\Windows\SysNative\DRIVERS\LV302V64.SYS (Logitech Inc.)
DRV:
64bit: - (lvpepf64) – C:\Windows\SysNative\DRIVERS\lv302a64.sys (Logitech Inc.)
DRV:
64bit: - (BTHPORT) – C:\Windows\SysNative\Drivers\BTHport.sys (Microsoft Corporation)
DRV:
64bit: - (RFCOMM) Bluetooth Device (RFCOMM Protocol TDI) – C:\Windows\SysNative\DRIVERS\rfcomm.sys (Microsoft Corporation)
DRV:
64bit: - (BthEnum) – C:\Windows\SysNative\DRIVERS\BthEnum.sys (Microsoft Corporation)
DRV:
64bit: - (BTHUSB) – C:\Windows\SysNative\Drivers\BTHUSB.sys (Microsoft Corporation)
DRV:
64bit: - (HdAudAddService) – C:\Windows\SysNative\drivers\HdAudio.sys (Microsoft Corporation)
DRV:
64bit: - (usbaudio) USB Audio Driver (WDM) – C:\Windows\SysNative\drivers\usbaudio.sys (Microsoft Corporation)
DRV:
64bit: - (netr28x) – C:\Windows\SysNative\DRIVERS\netr28x.sys (Ralink Technology, Corp.)
DRV:
64bit: - (BthPan) Bluetooth Device (Personal Area Network) – C:\Windows\SysNative\DRIVERS\bthpan.sys (Microsoft Corporation)
DRV:
64bit: - (LVUSBS64) – C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.)
DRV:
64bit: - (MTsensor) – C:\Windows\SysNative\DRIVERS\ASACPI.sys ()
DRV:
64bit: - (ialm) – C:\Windows\SysNative\DRIVERS\igdkmd64.sys (Intel Corporation)
DRV - (ASInsHelp) – C:\Windows\SysWOW64\drivers\AsInsHelp64.sys ()
DRV - (AsIO) – C:\Windows\SysWOW64\drivers\AsIO.sys ()
DRV - (Tcpip) – C:\Windows\SysWOW64\wbem\tcpip.mof ()
DRV - (mpsdrv) – C:\Windows\SysWOW64\wbem\mpsdrv.mof ()
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "Yahoo! Search"
FF - prefs.js..browser.search.param.yahoo-fr: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-fr-cjkt: "chrf-ytbm"
FF - prefs.js..browser.search.param.yahoo-type: "${8}"
FF - prefs.js..browser.search.selectedEngine: "Yahoo! Search"
FF - prefs.js..browser.startup.homepage: "
http://starter.metacafe.com"
FF - prefs.js..extensions.enabledItems: showmemore@suskind:1.3
FF - prefs.js..extensions.enabledItems: {AE93811A-5C9A-4d34-8462-F7B864FC4696}:3.64
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: zoompage@DW-dev:1.8
FF - prefs.js..extensions.enabledItems: {ABDE892B-13A8-4d1b-88E6-365A6E755758}:1.1.4
FF - prefs.js..extensions.enabledItems: [removed]:[removed]
FF - prefs.js..extensions.enabledItems: {35379F86-8CCB-4724-AE33-4278DE266C70}:1.0.5
FF - prefs.js..keyword.URL: "
http://us.yhs.search.yahoo.com/avg/search?fr=yhs-avg&type;=yahoo_avg_hs2-tb-web_us&p;="
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2010/05/13 11:47:05 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2010/06/05 09:48:25 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 3.6.3\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2010/06/13 15:29:37 | 000,000,000 | —D | M]
[2010/05/23 02:30:06 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\Mozilla\Extensions
[2010/05/23 02:30:06 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\Mozilla\Extensions\[removed]
[2010/06/14 08:30:39 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\Mozilla\Firefox\Profiles\dt3te7m9.default\extensions
[2010/05/10 00:47:58 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Chris B. Stiffer\AppData\Roaming\Mozilla\Firefox\Profiles\dt3te7m9.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/05/12 16:21:01 | 000,000,000 | —D | M] (MouseZoom) – C:\Users\Chris B. Stiffer\AppData\Roaming\Mozilla\Firefox\Profiles\dt3te7m9.default\extensions\{28FAD68E-4001-48d5-B994-68069F7CFB1D}
[2010/05/05 19:16:08 | 000,000,000 | —D | M] (Google Toolbar for Firefox) – C:\Users\Chris B. Stiffer\AppData\Roaming\Mozilla\Firefox\Profiles\dt3te7m9.default\extensions\{3112ca9c-de6d-4884-a869-9855de68056c}
[2010/05/04 18:55:32 | 000,000,000 | —D | M] (No name found) – C:\Users\Chris B. Stiffer\AppData\Roaming\Mozilla\Firefox\Profiles\dt3te7m9.default\extensions\{AE93811A-5C9A-4d34-8462-F7B864FC4696}
[2010/05/18 20:50:44 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\Mozilla\Firefox\Profiles\dt3te7m9.default\extensions\[removed]
[2010/05/04 18:50:14 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\Mozilla\Firefox\Profiles\dt3te7m9.default\extensions\showmemore@suskind
[2010/05/12 17:57:59 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\Mozilla\Firefox\Profiles\dt3te7m9.default\extensions\zoompage@DW-dev
[2010/06/14 08:30:39 | 000,000,000 | —D | M] – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/05/07 11:39:58 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/05/07 11:39:53 | 000,411,368 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
O1 HOSTS File: ([2006/09/18 14:37:24 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (Octh Class) - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files (x86)\Orbitdownloader\orbitcth.dll (Orbitdownloader.com)
O3:
64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O3 - HKLM\..\Toolbar: (StumbleUpon Toolbar) - {5093EB4C-3E93-40AB-9266-B607BA87BDC8} - C:\Program Files (x86)\StumbleUpon\StumbleUponIEBar.dll (stumbleupon.com)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {D4027C7F-154A-4066-A1AD-4243D8127440} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\yt.dll (Yahoo! Inc.)
O3:
64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3 - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_32.dll (Google Inc.)
O4:
64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:
64bit: - HKLM..\Run: [SKDaemon.exe] C:\Program Files\LTONHIS\Touch Manager\SKDaemon.exe ()
O4:
64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4:
64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [IObit Security 360] C:\Program Files (x86)\IObit\IObit Security 360\IS360tray.exe (IObit)
O4 - HKLM..\Run: [RunAIShell] C:\Program Files\ASUS\AI Manager\AsShellApplication.exe (ASUSTeK)
O4 - HKLM..\Run: [TkBellExe] C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe (RealNetworks, Inc.)
O4 - HKCU..\Run: [msnmsgr] C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe (Microsoft Corporation)
O4 - HKCU..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe (Google Inc.)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O8:
64bit: - Extra context menu item: &Download; by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:
64bit: - Extra context menu item: &Grab; video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:
64bit: - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8:
64bit: - Extra context menu item: Down&load; all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Download; by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: &Grab; video by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Do&wnload; selected by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O8 - Extra context menu item: Down&load; all by Orbit - C:\Program Files (x86)\Orbitdownloader\orbitmxt.dll (Orbitdownloader.com)
O9 - Extra Button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll (Microsoft Corporation)
O9 - Extra Button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office12\ONBttnIE.dll (Microsoft Corporation)
O9 - Extra Button: @shdoclc.dll,-866 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Windows\web\related.htm File not found
O9 - Extra 'Tools' menuitem : @shdoclc.dll,-864 - {c95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Windows\web\related.htm File not found
O10:
64bit: - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysNative\wshbth.dll (Microsoft Corporation)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Windows\SysWOW64\wshbth.dll (Microsoft Corporation)
O13 - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: wifi-soft.com ([www] http in Trusted sites)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_20)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7}
http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (get_atlcom Class)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.4.1
O18:
64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:
64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.14.0.8117.0416.dll (Microsoft Corporation)
O18 - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - C:\Program Files (x86)\Windows Live\Mail\mailcomm.dll (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Chris B. Stiffer\Pictures\Picasa Edits\picasabackground.bmp
O24 - Desktop BackupWallPaper: C:\Users\Chris B. Stiffer\Pictures\Picasa Edits\picasabackground.bmp
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk /p \??\C) - File not found
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
NetSvcs:
64bit: Ias - C:\Windows\SysNative\ias [2008/01/20 20:06:38 | 000,000,000 | —D | M]
NetSvcs:
64bit: Irmon - C:\Windows\SysNative\irmon.dll (Microsoft Corporation)
NetSvcs:
64bit: Wmi - C:\Windows\SysNative\wmi.dll (Microsoft Corporation)
NetSvcs: Ias - C:\Windows\SysWOW64\ias [2008/01/20 20:08:35 | 000,000,000 | —D | M]
NetSvcs: Wmi - C:\Windows\SysWOW64\wmi.dll (Microsoft Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 90 Days ==========
[2010/06/14 08:46:50 | 000,572,416 | —- | C] (OldTimer Tools) – C:\Users\Chris B. Stiffer\Desktop\OTL.exe
[2010/06/13 15:55:26 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2010/06/13 15:29:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\NOS
[2010/06/13 15:14:13 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2010/06/13 07:11:01 | 000,033,800 | —- | C] (Panda Security, S.L.) – C:\Windows\SysNative\drivers\pavboot64.sys
[2010/06/13 07:11:00 | 000,000,000 | —D | C] – C:\Program Files (x86)\Panda Security
[2010/06/13 07:02:12 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\ElevatedDiagnostics
[2010/06/13 04:11:14 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\NVIDIA
[2010/06/13 04:11:11 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Documents\My Games
[2010/06/13 04:08:58 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\InstallShield Installation Information
[2010/06/13 04:07:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\AGEIA Technologies
[2010/06/13 04:07:33 | 000,000,000 | —D | C] – C:\Windows\SysWow64\AGEIA
[2010/06/13 04:07:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2010/06/12 15:23:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Orbitdownloader
[2010/06/12 15:21:52 | 002,592,840 | —- | C] (www.orbitdownloader.com ) – C:\Users\Chris B. Stiffer\Desktop\OrbitDownloaderSetup3005.exe
[2010/06/10 23:34:28 | 000,000,000 | —D | C] – C:\ProgramData\PopCap Games
[2010/06/10 23:34:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\PopCap Games
[2010/06/10 17:29:43 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\FixItCenter
[2010/06/10 17:04:07 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Fix it Center
[2010/06/10 17:04:07 | 000,000,000 | —D | C] – C:\Windows\MATS
[2010/06/10 17:01:00 | 000,000,000 | —D | C] – C:\Windows\SysWow64\WindowsPowerShell
[2010/06/10 17:00:55 | 000,000,000 | —D | C] – C:\Windows\SysNative\WindowsPowerShell
[2010/06/10 10:10:49 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Documents\Bioshock
[2010/06/10 10:10:49 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Bioshock
[2010/06/10 09:57:32 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Documents\ArmA 2 Demo
[2010/06/10 09:57:31 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\ArmA 2 Demo
[2010/06/10 07:56:01 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Desktop\2010-05-10
[2010/06/08 12:49:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kensington TrackballWorks
[2010/06/08 12:48:56 | 000,370,912 | —- | C] (Dritek System Inc.) – C:\Windows\UnKWorks.exe
[2010/06/08 09:13:50 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\MetaGeek,_LLC
[2010/06/08 07:29:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\MetaGeek
[2010/06/07 18:50:50 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\runic games
[2010/06/07 09:55:22 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Documents\BFBC2
[2010/06/07 07:50:31 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\LogiShrd
[2010/06/07 07:50:13 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Leadertech
[2010/06/07 07:49:07 | 000,000,000 | —D | C] – C:\ProgramData\LogiShrd
[2010/06/07 07:49:06 | 000,000,000 | —D | C] – C:\Program Files\Logitech
[2010/06/07 07:26:02 | 000,000,000 | —D | C] – C:\Windows\SysNative\PrivacyShades
[2010/06/07 07:25:58 | 000,000,000 | —D | C] – C:\Windows\SysNative\ModelData
[2010/06/06 23:24:24 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Documents\Downloads
[2010/06/06 19:19:56 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Documents\Square Enix
[2010/06/06 15:07:33 | 000,000,000 | —D | C] – C:\Program Files\NVIDIA Corporation
[2010/06/06 11:56:27 | 000,000,000 | —D | C] – C:\Program Files (x86)\Steam
[2010/06/05 23:44:29 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Desktop\ASUSUpdate_V71513
[2010/06/05 23:40:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Digital Fusion
[2010/06/05 23:20:30 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Metacafe
[2010/06/05 23:20:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Akamai
[2010/06/05 23:19:30 | 000,000,000 | —D | C] – C:\ProgramData\Metacafe
[2010/06/05 23:19:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Metacafe
[2010/06/05 23:16:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\Infogrames Interactive
[2010/06/04 15:45:50 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\PeerNetworking
[2010/06/02 20:10:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\CoderGames.com
[2010/06/01 21:35:05 | 000,000,000 | —D | C] – C:\Windows\SysWow64\RTCOM
[2010/06/01 21:34:40 | 000,513,536 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSX64.dll
[2010/06/01 21:34:40 | 000,211,376 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSTSH64.dll
[2010/06/01 21:34:40 | 000,193,536 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSHP64.dll
[2010/06/01 21:34:40 | 000,150,528 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\SRSWOW64.dll
[2010/06/01 21:34:39 | 000,296,448 | —- | C] (Dolby Laboratories) – C:\Windows\SysNative\RTPCEE64.dll
[2010/06/01 21:34:37 | 000,311,296 | —- | C] (Waves Audio Ltd.) – C:\Windows\SysNative\MaxxAudioAPO20.dll
[2010/06/01 21:34:37 | 000,164,352 | —- | C] (Windows ® Codename Longhorn DDK provider) – C:\Windows\SysNative\FMAPO64.dll
[2010/06/01 21:32:59 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Documents\Realtek_Audio_V6015783_Vista
[2010/06/01 07:24:28 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Tracing
[2010/05/31 09:34:08 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Documents\E4712_CM5570_manual
[2010/05/28 17:47:34 | 000,000,000 | —D | C] – C:\Program Files\Microsoft ATS
[2010/05/28 16:37:34 | 001,213,800 | —- | C] (A&H; Software House, Inc.) – C:\Windows\SysWow64\DVRCodecsI.dll
[2010/05/28 16:37:34 | 000,742,760 | —- | C] (A&H; Software House, Inc.) – C:\Windows\SysWow64\DVRCodecs.dll
[2010/05/28 16:37:34 | 000,185,704 | —- | C] (A&H; Software House, Inc.) – C:\Windows\SysWow64\DVRCodecsF.dll
[2010/05/27 22:49:16 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Documents\Snagit
[2010/05/27 22:48:59 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\assembly
[2010/05/27 22:48:55 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\5BCC634A58AD42F9B3C62EA52F81CF85.TMP
[2010/05/27 22:48:23 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\TechSmith
[2010/05/27 18:48:05 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\VS Revo Group
[2010/05/27 18:48:04 | 000,031,800 | —- | C] (VS Revo Group) – C:\Windows\SysNative\drivers\revoflt.sys
[2010/05/27 18:48:02 | 000,000,000 | —D | C] – C:\Program Files\VS Revo Group
[2010/05/26 19:55:15 | 000,000,000 | —D | C] – C:\ProgramData\Isotx
[2010/05/26 11:10:51 | 000,000,000 | —D | C] – C:\Users\Public\Documents\microsoft
[2010/05/24 17:11:48 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Logitech
[2010/05/24 13:50:54 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\PunkBuster
[2010/05/24 13:40:17 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\VSRevoGroup
[2010/05/24 13:34:49 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2010/05/24 11:47:00 | 000,000,000 | R–D | C] – C:\Users\Chris B. Stiffer\Desktop\unused icons
[2010/05/24 09:39:47 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2010/05/24 09:39:46 | 000,000,000 | —D | C] – C:\Program Files\Windows Live
[2010/05/24 09:39:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Sync Framework
[2010/05/24 09:38:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft SQL Server Compact Edition
[2010/05/24 09:37:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live SkyDrive
[2010/05/24 09:37:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live
[2010/05/24 09:09:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Valve
[2010/05/24 08:56:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Steam
[2010/05/23 16:57:35 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Documents\Xonar_HDAV_08080581744_RC01_Vista3264
[2010/05/23 16:37:26 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Download Manager
[2010/05/23 09:57:41 | 000,000,000 | —D | C] – C:\ProgramData\Uniblue
[2010/05/23 09:57:37 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Uniblue
[2010/05/23 04:52:18 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\AskToolbar
[2010/05/23 02:30:11 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Documents\LimeWire
[2010/05/23 02:29:54 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\LimeWire
[2010/05/23 02:29:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\LimeWire
[2010/05/23 01:13:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\WebCamDV
[2010/05/20 23:40:58 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\capcom
[2010/05/20 03:05:16 | 000,051,024 | —- | C] (Dritek System Inc.) – C:\Windows\SysNative\drivers\HMuKstOO.sys
[2010/05/18 09:16:14 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\GrabPro
[2010/05/18 09:16:14 | 000,000,000 | —D | C] – C:\downloads
[2010/05/18 09:09:41 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Orbit
[2010/05/17 20:31:05 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Documents\gegl-0.0
[2010/05/17 20:31:05 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\.gimp-2.6
[2010/05/17 03:05:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Live Safety Center
[2010/05/17 02:52:44 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2010/05/17 02:52:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy
[2010/05/16 17:11:03 | 000,064,616 | —- | C] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2010/05/16 17:11:03 | 000,056,424 | —- | C] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2010/05/16 11:12:19 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\SystemRequirementsLab
[2010/05/16 11:09:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Windows Live
[2010/05/16 11:09:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft
[2010/05/16 10:29:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe
[2010/05/16 05:24:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Electronic Arts
[2010/05/15 13:04:19 | 000,000,000 | —D | C] – C:\Program Files (x86)\StumbleUpon
[2010/05/14 22:15:46 | 000,000,000 | -H-D | C] – C:\$AVG
[2010/05/14 10:44:00 | 000,000,000 | —D | C] – C:\Windows\SysNative\Interactive
[2010/05/14 10:18:12 | 000,000,000 | —D | C] – C:\Windows\SysNative\log
[2010/05/13 21:52:12 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Malwarebytes
[2010/05/13 21:52:03 | 000,038,224 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/05/13 21:52:02 | 000,024,664 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/05/13 21:52:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2010/05/13 21:52:02 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2010/05/13 21:45:30 | 000,000,000 | —D | C] – C:\ProgramData\McAfee
[2010/05/13 11:46:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[2010/05/12 16:49:22 | 000,000,000 | —D | C] – C:\Windows\SysNative\Service
[2010/05/11 15:46:36 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Incomplete
[2010/05/11 15:44:48 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Documents\FrostWire
[2010/05/11 15:44:44 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\FrostWire
[2010/05/11 07:17:25 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\Adobe
[2010/05/09 23:31:36 | 000,000,000 | —D | C] – C:\ProgramData\Yahoo! Companion
[2010/05/09 02:28:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2010/05/08 17:04:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\Windows Portable Devices
[2010/05/08 17:04:11 | 000,000,000 | —D | C] – C:\Windows\SysWow64\spool
[2010/05/08 17:04:10 | 000,000,000 | —D | C] – C:\Program Files\Windows Portable Devices
[2010/05/08 00:50:57 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\Yahoo
[2010/05/08 00:44:20 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Yahoo!
[2010/05/07 15:24:36 | 000,000,000 | —D | C] – C:\Windows\SysWow64\vi-VN
[2010/05/07 15:24:36 | 000,000,000 | —D | C] – C:\Windows\SysWow64\eu-ES
[2010/05/07 15:24:36 | 000,000,000 | —D | C] – C:\Windows\SysNative\eu-ES
[2010/05/07 15:24:36 | 000,000,000 | —D | C] – C:\Windows\SysWow64\ca-ES
[2010/05/07 15:24:36 | 000,000,000 | —D | C] – C:\Windows\SysNative\ca-ES
[2010/05/07 15:24:35 | 000,000,000 | —D | C] – C:\Windows\SysNative\vi-VN
[2010/05/07 15:09:30 | 000,000,000 | —D | C] – C:\Windows\SysNative\EventProviders
[2010/05/07 12:28:05 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\dotnetfx3530729.01
[2010/05/07 12:26:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\7-Zip
[2010/05/07 12:26:11 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\uTorrent
[2010/05/07 12:26:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\uTorrent
[2010/05/07 12:21:35 | 000,000,000 | —D | C] – C:\Windows\SysWow64\directx
[2010/05/07 12:20:56 | 000,278,528 | —- | C] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[2010/05/07 12:20:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Real
[2010/05/07 12:20:54 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Real
[2010/05/07 12:20:54 | 000,000,000 | —D | C] – C:\ProgramData\Real
[2010/05/07 12:20:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Real
[2010/05/07 12:20:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\GIMP-2.0
[2010/05/07 12:20:22 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Opera
[2010/05/07 12:20:22 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\Opera
[2010/05/07 11:41:31 | 000,000,000 | —D | C] – C:\ProgramData\Yahoo!
[2010/05/07 11:41:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Yahoo!
[2010/05/07 11:40:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\Opera
[2010/05/07 11:40:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\FrostWire
[2010/05/07 11:39:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2010/05/07 11:19:07 | 000,000,000 | —D | C] – C:\ProgramData\FreeApp
[2010/05/07 11:17:54 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\IObit
[2010/05/07 11:17:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2010/05/07 11:12:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\VS Revo Group
[2010/05/06 07:30:06 | 000,000,000 | —D | C] – C:\ProgramData\NOS
[2010/05/06 06:52:37 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2010/05/06 06:52:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2010/05/06 06:23:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\MSXML 4.0
[2010/05/06 06:23:33 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft CAPICOM 2.1.0.2
[2010/05/05 10:35:02 | 000,000,000 | —D | C] – C:\ProgramData\avg9
[2010/05/05 10:35:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\AVG
[2010/05/05 10:05:48 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\WindowsUpdate
[2010/05/04 22:34:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Logishrd
[2010/05/04 18:45:51 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Mozilla
[2010/05/04 18:45:51 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\Mozilla
[2010/05/04 18:38:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2010/05/04 14:44:59 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Google
[2010/05/04 14:44:39 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\Google
[2010/05/04 14:44:37 | 000,000,000 | —D | C] – C:\Program Files\Google
[2010/05/04 14:44:31 | 000,000,000 | —D | C] – C:\ProgramData\Google
[2010/05/04 14:44:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2010/05/04 13:44:44 | 000,000,000 | —D | C] – C:\Program Files\Common Files\logishrd
[2010/05/04 13:29:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\NVIDIA Corporation
[2010/05/04 13:28:18 | 000,000,000 | —D | C] – C:\NVIDIA
[2010/05/04 12:57:45 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Macromedia
[2010/05/04 12:57:45 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Adobe
[2010/05/04 12:57:44 | 000,000,000 | —D | C] – C:\Windows\SysWow64\Macromed
[2010/05/04 12:56:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\SystemRequirementsLab
[2010/05/04 12:12:46 | 000,000,000 | R–D | C] – C:\Users\Chris B. Stiffer\Searches
[2010/05/04 12:12:38 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Identities
[2010/05/04 12:12:37 | 000,000,000 | R–D | C] – C:\Users\Chris B. Stiffer\Contacts
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\Templates
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\Start Menu
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\SendTo
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\Recent
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\PrintHood
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\NetHood
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\Documents\My Videos
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\Documents\My Pictures
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\Documents\My Music
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\My Documents
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\Local Settings
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\AppData\Local\History
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\Cookies
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\Application Data
[2010/05/04 12:12:03 | 000,000,000 | -HSD | C] – C:\Users\Chris B. Stiffer\AppData\Local\Application Data
[2010/05/04 12:12:03 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\VirtualStore
[2010/05/04 12:12:02 | 000,000,000 | –SD | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Microsoft
[2010/05/04 12:12:02 | 000,000,000 | R–D | C] – C:\Users\Chris B. Stiffer\Videos
[2010/05/04 12:12:02 | 000,000,000 | R–D | C] – C:\Users\Chris B. Stiffer\Saved Games
[2010/05/04 12:12:02 | 000,000,000 | R–D | C] – C:\Users\Chris B. Stiffer\Links
[2010/05/04 12:12:02 | 000,000,000 | R–D | C] – C:\Users\Chris B. Stiffer\Downloads
[2010/05/04 12:12:02 | 000,000,000 | R–D | C] – C:\Users\Chris B. Stiffer\Documents
[2010/05/04 12:12:02 | 000,000,000 | R–D | C] – C:\Users\Chris B. Stiffer\Desktop
[2010/05/04 12:12:02 | 000,000,000 | -H-D | C] – C:\Users\Chris B. Stiffer\AppData
[2010/05/04 12:12:02 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\Temp
[2010/05/04 12:12:02 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\Music
[2010/05/04 12:12:02 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Local\Microsoft
[2010/05/04 12:12:02 | 000,000,000 | —D | C] – C:\Users\Chris B. Stiffer\AppData\Roaming\Media Center Programs
[2010/05/04 12:08:24 | 000,000,000 | -HSD | C] – C:\ProgramData\Templates
[2010/05/04 12:08:24 | 000,000,000 | -HSD | C] – C:\ProgramData\Start Menu
[2010/05/04 12:08:24 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Videos
[2010/05/04 12:08:24 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Pictures
[2010/05/04 12:08:24 | 000,000,000 | -HSD | C] – C:\Users\Public\Documents\My Music
[2010/05/04 12:08:24 | 000,000,000 | -HSD | C] – C:\ProgramData\Favorites
[2010/05/04 12:08:24 | 000,000,000 | -HSD | C] – C:\Documents and Settings
[2010/05/04 12:08:24 | 000,000,000 | -HSD | C] – C:\ProgramData\Documents
[2010/05/04 12:08:24 | 000,000,000 | -HSD | C] – C:\ProgramData\Desktop
[2010/05/04 12:08:24 | 000,000,000 | -HSD | C] – C:\ProgramData\Application Data
[2010/04/29 03:57:13 | 000,000,000 | -HSD | C] – C:\System Volume Information
[1 C:\Users\Chris B. Stiffer\*.tmp files -> C:\Users\Chris B. Stiffer\*.tmp -> ]
========== Files - Modified Within 90 Days ==========
[2010/06/14 08:57:15 | 003,670,016 | -HS- | M] () – C:\Users\Chris B. Stiffer\ntuser.dat
[2010/06/14 08:57:00 | 000,000,434 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{786FC7F5-D297-4266-8C89-27C18AC66DD6}.job
[2010/06/14 08:52:02 | 000,000,162 | -H– | M] () – C:\Users\Chris B. Stiffer\Desktop\~$ch ndoc.rtf
[2010/06/14 08:50:17 | 000,008,004 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\tech ndoc.rtf
[2010/06/14 08:49:49 | 000,000,440 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{8DCC1D6B-C9D0-43DE-B666-A0B12FC92D17}.job
[2010/06/14 08:49:12 | 000,000,918 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/06/14 08:36:52 | 000,000,240 | -HS- | M] () – C:\Windows\SysWow64\SysSecurity.ini
[2010/06/14 08:36:52 | 000,000,240 | -HS- | M] () – C:\Windows\SysWow64\DevState.ini
[2010/06/14 08:17:02 | 000,690,960 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2010/06/14 08:17:02 | 000,595,446 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2010/06/14 08:17:02 | 000,101,144 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2010/06/14 08:14:55 | 000,000,914 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/06/14 08:14:55 | 000,000,416 | —- | M] () – C:\Windows\tasks\AWC Startup.job
[2010/06/14 08:14:51 | 000,053,749 | —- | M] () – C:\ProgramData\nvModes.dat
[2010/06/14 08:14:51 | 000,053,749 | —- | M] () – C:\ProgramData\nvModes.001
[2010/06/14 08:11:34 | 000,003,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2010/06/14 08:11:34 | 000,003,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2010/06/14 08:11:30 | 000,000,006 | -H– | M] () – C:\Windows\tasks\SA.DAT
[2010/06/14 08:11:29 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2010/06/14 02:59:50 | 000,001,076 | —- | M] () – C:\Windows\bthservsdp.dat
[2010/06/14 02:59:49 | 000,524,288 | -HS- | M] () – C:\Users\Chris B. Stiffer\ntuser.dat{221338ce-6cfb-11df-b8bf-000272a7a4fb}.TMContainer00000000000000000001.regtrans-ms
[2010/06/14 02:59:49 | 000,065,536 | -HS- | M] () – C:\Users\Chris B. Stiffer\ntuser.dat{221338ce-6cfb-11df-b8bf-000272a7a4fb}.TM.blf
[2010/06/14 02:59:46 | 003,477,681 | -H– | M] () – C:\Users\Chris B. Stiffer\AppData\Local\IconCache.db
[2010/06/13 15:26:11 | 000,181,684 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\redplane.gadget
[2010/06/13 06:11:43 | 000,000,850 | —- | M] () – C:\Users\Public\Desktop\Microsoft Fix it Center.lnk
[2010/06/12 15:23:32 | 000,000,898 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\Orbit.lnk
[2010/06/12 15:21:55 | 002,592,840 | —- | M] (www.orbitdownloader.com ) – C:\Users\Chris B. Stiffer\Desktop\OrbitDownloaderSetup3005.exe
[2010/06/12 10:03:24 | 000,359,929 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\dds.scr
[2010/06/10 23:54:26 | 000,000,017 | —- | M] () – C:\Windows\popcinfo.dat
[2010/06/10 23:34:30 | 000,001,141 | —- | M] () – C:\Users\Public\Desktop\Heavy Weapon Deluxe.lnk
[2010/06/10 23:34:30 | 000,000,200 | —- | M] () – C:\Users\Public\Desktop\Play More Great Games!.url
[2010/06/10 23:09:31 | 000,272,560 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2010/06/10 17:00:10 | 003,473,408 | —- | M] () – C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
[2010/06/10 17:00:10 | 000,196,608 | —- | M] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
[2010/06/10 17:00:10 | 000,065,536 | —- | M] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
[2010/06/10 17:00:06 | 003,473,408 | —- | M] () – C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell2.etl
[2010/06/10 17:00:06 | 000,196,608 | —- | M] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell2.perf
[2010/06/10 17:00:06 | 000,065,536 | —- | M] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell2.dpx
[2010/06/10 07:22:27 | 000,059,480 | —- | M] () – C:\Users\Chris B. Stiffer\AppData\Local\GDIPFONTCACHEV1.DAT
[2010/06/09 07:39:28 | 000,572,416 | —- | M] (OldTimer Tools) – C:\Users\Chris B. Stiffer\Desktop\OTL.exe
[2010/06/08 12:51:21 | 000,000,102 | —- | M] () – C:\Windows\308CBAA-F2CC-4658-AC06-06613CBA4CEF.DSI
[2010/06/08 12:49:13 | 000,001,064 | —- | M] () – C:\Windows\UnKWorks.UNI
[2010/06/08 12:07:08 | 000,000,817 | —- | M] () – C:\Windows\System\cmiHDAV.ini
[2010/06/07 09:28:39 | 000,375,331 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\AnalysisLog.sr0
[2010/06/07 07:49:08 | 000,001,998 | —- | M] () – C:\Users\Public\Desktop\Logitech Webcam Software.lnk
[2010/06/06 23:24:53 | 000,000,430 | —- | M] () – C:\Windows\tasks\SmartDefrag.job
[2010/06/06 22:17:15 | 000,002,105 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\Google Chrome.lnk
[2010/06/06 12:02:28 | 000,000,836 | —- | M] () – C:\Users\Public\Desktop\Steam.lnk
[2010/06/05 23:19:27 | 000,000,854 | —- | M] () – C:\Users\Public\Desktop\Metacafe.lnk
[2010/06/05 18:35:11 | 000,189,248 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.exe
[2010/06/05 18:35:06 | 002,434,856 | —- | M] () – C:\Windows\SysWow64\pbsvc_bc2.exe
[2010/06/05 18:35:06 | 000,075,064 | —- | M] () – C:\Windows\SysWow64\PnkBstrA.exe
[2010/06/05 09:48:25 | 000,001,786 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/06/04 15:46:00 | 000,029,216 | —- | M] () – C:\Users\Chris B. Stiffer\AppData\Roaming\UserTile.png
[2010/06/01 21:34:29 | 000,001,746 | —- | M] () – C:\Windows\Language_trs.ini
[2010/06/01 16:05:00 | 000,001,196 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\001 - Shortcut.lnk
[2010/06/01 10:18:27 | 000,000,911 | —- | M] () – C:\Users\Public\Desktop\IObit Security 360.lnk
[2010/05/31 17:02:33 | 000,524,288 | -HS- | M] () – C:\Users\Chris B. Stiffer\ntuser.dat{221338ce-6cfb-11df-b8bf-000272a7a4fb}.TMContainer00000000000000000002.regtrans-ms
[2010/05/31 14:44:55 | 000,524,288 | -HS- | M] () – C:\Users\Chris B. Stiffer\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/05/31 14:44:55 | 000,065,536 | -HS- | M] () – C:\Users\Chris B. Stiffer\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/05/31 11:05:31 | 010,568,614 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\ASUSUpdate_V71513.zip
[2010/05/31 09:32:14 | 001,098,083 | —- | M] () – C:\Users\Chris B. Stiffer\Documents\E4712_CM5570_manual.zip
[2010/05/31 09:17:20 | 072,522,930 | —- | M] () – C:\Users\Chris B. Stiffer\Documents\Realtek_Audio_V6015783_Vista.zip
[2010/05/27 18:48:04 | 000,000,925 | —- | M] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2010/05/26 11:07:38 | 000,001,925 | —- | M] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/05/24 17:23:18 | 000,215,128 | —- | M] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2010/05/24 15:41:41 | 000,352,107 | —- | M] () – C:\AnalysisLog.sr0
[2010/05/24 11:52:00 | 000,001,652 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\Disk Cleanup.lnk
[2010/05/23 16:43:52 | 011,966,155 | —- | M] () – C:\Users\Chris B. Stiffer\Documents\Xonar_HDAV_08080581744_RC01_Vista3264.zip
[2010/05/23 02:29:21 | 000,001,762 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\LimeWire 5.5.8.lnk
[2010/05/21 20:13:57 | 000,370,912 | —- | M] (Dritek System Inc.) – C:\Windows\UnKWorks.exe
[2010/05/20 03:05:16 | 000,051,024 | —- | M] (Dritek System Inc.) – C:\Windows\SysNative\drivers\HMuKstOO.sys
[2010/05/15 12:51:31 | 000,002,560 | —- | M] () – C:\Windows\_MSRSTRT.EXE
[2010/05/14 22:56:35 | 000,000,915 | —- | M] () – C:\Users\Public\Desktop\Game Booster.lnk
[2010/05/13 21:03:03 | 000,000,761 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfud.bin
[2010/05/13 21:03:01 | 000,000,761 | —- | M] () – C:\Windows\SysNative\drivers\etc\tmvsthfss.bin
[2010/05/13 11:47:05 | 000,000,877 | —- | M] () – C:\Users\Public\Desktop\RealPlayer SP.lnk
[2010/05/13 11:46:44 | 000,278,528 | —- | M] (Real Networks, Inc) – C:\Windows\SysWow64\pncrt.dll
[2010/05/12 06:39:01 | 000,000,978 | —- | M] () – C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2010/05/08 17:03:13 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2010/05/08 00:02:46 | 000,000,000 | -H– | M] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010/05/07 12:20:45 | 000,000,936 | —- | M] () – C:\Users\Chris B. Stiffer\GIMP 2.lnk
[2010/05/07 11:40:53 | 000,000,752 | —- | M] () – C:\Users\Public\Desktop\Opera.lnk
[2010/05/07 11:29:56 | 000,000,951 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\Picasa.lnk
[2010/05/07 11:29:16 | 000,001,064 | —- | M] () – C:\Users\Public\Desktop\Advanced SystemCare.lnk
[2010/05/07 11:17:54 | 000,000,970 | —- | M] () – C:\Users\Public\Desktop\Smart Defrag.lnk
[2010/05/07 11:12:45 | 000,001,107 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\Revo Uninstaller.lnk
[2010/05/06 10:41:52 | 000,000,389 | —- | M] () – C:\Users\Chris B. Stiffer\Documents\Pictures - Shortcut.lnk
[2010/05/04 22:29:52 | 000,000,981 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\Launch Internet Explorer Browser.lnk
[2010/05/04 18:38:52 | 000,001,810 | —- | M] () – C:\Users\Chris B. Stiffer\Desktop\Mozilla Firefox.lnk
[2010/05/04 13:31:01 | 000,524,288 | -HS- | M] () – C:\Users\Chris B. Stiffer\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000002.regtrans-ms
[2010/05/04 12:12:03 | 000,000,020 | -HS- | M] () – C:\Users\Chris B. Stiffer\ntuser.ini
[2010/05/04 12:02:53 | 000,047,092 | —- | M] () – C:\Windows\SysNative\license.rtf
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWow64\drivers\mbamswissarmy.sys
[2010/04/29 15:39:28 | 000,024,664 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2010/04/15 17:16:52 | 000,185,704 | —- | M] (A&H; Software House, Inc.) – C:\Windows\SysWow64\DVRCodecsF.dll
[2010/04/15 17:16:44 | 001,213,800 | —- | M] (A&H; Software House, Inc.) – C:\Windows\SysWow64\DVRCodecsI.dll
[2010/04/15 17:16:40 | 000,742,760 | —- | M] (A&H; Software House, Inc.) – C:\Windows\SysWow64\DVRCodecs.dll
[2010/04/13 14:41:38 | 000,276,196 | —- | M] () – C:\Windows\SysNative\NvApps.xml
[2010/04/13 14:41:38 | 000,066,714 | —- | M] () – C:\Windows\SysNative\NvwsApps.xml
[2010/04/13 12:20:32 | 000,064,616 | —- | M] (Khronos Group) – C:\Windows\SysNative\OpenCL.dll
[2010/04/13 12:20:32 | 000,056,424 | —- | M] (Khronos Group) – C:\Windows\SysWow64\OpenCL.dll
[2010/04/13 12:20:32 | 000,009,832 | —- | M] () – C:\Windows\SysNative\nvinfo.pb
[1 C:\Users\Chris B. Stiffer\*.tmp files -> C:\Users\Chris B. Stiffer\*.tmp -> ]
========== Files Created - No Company Name ==========
[2010/06/14 08:52:02 | 000,000,162 | -H– | C] () – C:\Users\Chris B. Stiffer\Desktop\~$ch ndoc.rtf
[2010/06/14 08:50:17 | 000,008,004 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\tech ndoc.rtf
[2010/06/13 15:26:11 | 000,181,684 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\redplane.gadget
[2010/06/13 04:39:44 | 000,363,268 | —- | C] () – C:\Users\Chris B. Stiffer\AppData\Local\dd_vcredistMSI6A53.txt
[2010/06/13 04:39:43 | 000,014,402 | —- | C] () – C:\Users\Chris B. Stiffer\AppData\Local\dd_vcredistUI6A53.txt
[2010/06/12 15:23:32 | 000,000,898 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\Orbit.lnk
[2010/06/12 10:03:17 | 000,359,929 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\dds.scr
[2010/06/10 23:54:26 | 000,000,017 | —- | C] () – C:\Windows\popcinfo.dat
[2010/06/10 23:34:30 | 000,001,141 | —- | C] () – C:\Users\Public\Desktop\Heavy Weapon Deluxe.lnk
[2010/06/10 23:34:30 | 000,000,200 | —- | C] () – C:\Users\Public\Desktop\Play More Great Games!.url
[2010/06/10 17:04:07 | 000,000,850 | —- | C] () – C:\Users\Public\Desktop\Microsoft Fix it Center.lnk
[2010/06/10 17:00:06 | 000,196,608 | —- | C] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.perf
[2010/06/10 17:00:06 | 000,065,536 | —- | C] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell.dpx
[2010/06/10 16:59:50 | 003,473,408 | —- | C] () – C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell2.etl
[2010/06/10 16:59:50 | 000,196,608 | —- | C] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell2.perf
[2010/06/10 16:59:50 | 000,065,536 | —- | C] () – C:\Windows\ocsetup_cbs_install_MicrosoftWindowsPowerShell2.dpx
[2010/06/08 12:51:21 | 000,000,102 | —- | C] () – C:\Windows\308CBAA-F2CC-4658-AC06-06613CBA4CEF.DSI
[2010/06/08 12:49:00 | 000,001,064 | —- | C] () – C:\Windows\UnKWorks.UNI
[2010/06/07 09:28:27 | 000,375,331 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\AnalysisLog.sr0
[2010/06/07 07:49:08 | 000,001,998 | —- | C] () – C:\Users\Public\Desktop\Logitech Webcam Software.lnk
[2010/06/06 22:17:15 | 000,002,105 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\Google Chrome.lnk
[2010/06/06 16:28:19 | 000,053,749 | —- | C] () – C:\ProgramData\nvModes.001
[2010/06/06 15:15:37 | 000,053,749 | —- | C] () – C:\ProgramData\nvModes.dat
[2010/06/06 11:56:27 | 000,000,836 | —- | C] () – C:\Users\Public\Desktop\Steam.lnk
[2010/06/05 23:19:27 | 000,000,854 | —- | C] () – C:\Users\Public\Desktop\Metacafe.lnk
[2010/06/05 09:48:25 | 000,001,786 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2010/06/04 15:45:50 | 000,029,216 | —- | C] () – C:\Users\Chris B. Stiffer\AppData\Roaming\UserTile.png
[2010/06/01 21:34:39 | 000,331,808 | —- | C] () – C:\Windows\SysNative\RtlCPAPI64.dll
[2010/06/01 21:34:38 | 001,154,080 | —- | C] () – C:\Windows\SysNative\RTCOM64.dll
[2010/06/01 21:34:29 | 000,001,746 | —- | C] () – C:\Windows\Language_trs.ini
[2010/06/01 16:05:00 | 000,001,196 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\001 - Shortcut.lnk
[2010/06/01 10:18:27 | 000,000,911 | —- | C] () – C:\Users\Public\Desktop\IObit Security 360.lnk
[2010/05/31 14:54:33 | 000,524,288 | -HS- | C] () – C:\Users\Chris B. Stiffer\ntuser.dat{221338ce-6cfb-11df-b8bf-000272a7a4fb}.TMContainer00000000000000000002.regtrans-ms
[2010/05/31 14:54:33 | 000,524,288 | -HS- | C] () – C:\Users\Chris B. Stiffer\ntuser.dat{221338ce-6cfb-11df-b8bf-000272a7a4fb}.TMContainer00000000000000000001.regtrans-ms
[2010/05/31 14:54:33 | 000,065,536 | -HS- | C] () – C:\Users\Chris B. Stiffer\ntuser.dat{221338ce-6cfb-11df-b8bf-000272a7a4fb}.TM.blf
[2010/05/31 11:01:43 | 010,568,614 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\ASUSUpdate_V71513.zip
[2010/05/31 09:32:00 | 001,098,083 | —- | C] () – C:\Users\Chris B. Stiffer\Documents\E4712_CM5570_manual.zip
[2010/05/31 09:07:40 | 072,522,930 | —- | C] () – C:\Users\Chris B. Stiffer\Documents\Realtek_Audio_V6015783_Vista.zip
[2010/05/28 17:47:35 | 003,473,408 | —- | C] () – C:\Windows\ocsetup_install_MicrosoftWindowsPowerShell.etl
[2010/05/28 16:37:40 | 001,522,688 | —- | C] () – C:\Windows\SysWow64\avcodec-dvrcodecsf-52.dll
[2010/05/28 16:37:40 | 000,072,704 | —- | C] () – C:\Windows\SysWow64\avutil-dvrcodecsf-49.dll
[2010/05/27 18:48:04 | 000,000,925 | —- | C] () – C:\Users\Public\Desktop\Revo Uninstaller Pro.lnk
[2010/05/26 23:33:47 | 000,000,434 | -H– | C] () – C:\Windows\tasks\User_Feed_Synchronization-{786FC7F5-D297-4266-8C89-27C18AC66DD6}.job
[2010/05/26 11:07:38 | 000,001,925 | —- | C] () – C:\Users\Public\Desktop\Adobe Reader 9.lnk
[2010/05/24 13:50:57 | 000,215,128 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.xtr
[2010/05/24 12:47:10 | 000,189,248 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2010/05/24 12:46:53 | 002,434,856 | —- | C] () – C:\Windows\SysWow64\pbsvc_bc2.exe
[2010/05/24 12:46:53 | 000,075,064 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2010/05/24 11:52:00 | 000,001,652 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\Disk Cleanup.lnk
[2010/05/23 16:58:25 | 000,313,344 | —- | C] () – C:\Windows\SysNative\CmiInstallResAll64.dll
[2010/05/23 16:58:25 | 000,000,817 | —- | C] () – C:\Windows\System\cmiHDAV.ini
[2010/05/23 16:58:25 | 000,000,555 | —- | C] () – C:\Windows\cmhdav.ini
[2010/05/23 16:37:37 | 011,966,155 | —- | C] () – C:\Users\Chris B. Stiffer\Documents\Xonar_HDAV_08080581744_RC01_Vista3264.zip
[2010/05/23 02:29:21 | 000,001,762 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\LimeWire 5.5.8.lnk
[2010/05/16 17:11:03 | 000,009,832 | —- | C] () – C:\Windows\SysNative\nvinfo.pb
[2010/05/16 14:08:21 | 000,352,107 | —- | C] () – C:\AnalysisLog.sr0
[2010/05/16 11:15:20 | 000,000,240 | -HS- | C] () – C:\Windows\SysWow64\SysSecurity.ini
[2010/05/16 11:15:20 | 000,000,240 | -HS- | C] () – C:\Windows\SysWow64\DevState.ini
[2010/05/15 12:51:30 | 000,002,560 | —- | C] () – C:\Windows\_MSRSTRT.EXE
[2010/05/14 22:56:35 | 000,000,915 | —- | C] () – C:\Users\Public\Desktop\Game Booster.lnk
[2010/05/13 11:47:05 | 000,000,877 | —- | C] () – C:\Users\Public\Desktop\RealPlayer SP.lnk
[2010/05/13 01:27:00 | 000,000,416 | —- | C] () – C:\Windows\tasks\AWC Startup.job
[2010/05/12 06:39:01 | 000,000,978 | —- | C] () – C:\Users\Public\Desktop\Yahoo! Messenger.lnk
[2010/05/08 17:03:13 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_07_00.Wdf
[2010/05/08 00:02:46 | 000,000,000 | -H– | C] () – C:\Windows\SysNative\drivers\Msft_User_WpdMtpDr_01_00_00.Wdf
[2010/05/07 12:20:45 | 000,000,936 | —- | C] () – C:\Users\Chris B. Stiffer\GIMP 2.lnk
[2010/05/07 11:40:53 | 000,000,752 | —- | C] () – C:\Users\Public\Desktop\Opera.lnk
[2010/05/07 11:29:56 | 000,000,951 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\Picasa.lnk
[2010/05/07 11:29:16 | 000,001,064 | —- | C] () – C:\Users\Public\Desktop\Advanced SystemCare.lnk
[2010/05/07 11:17:58 | 000,000,430 | —- | C] () – C:\Windows\tasks\SmartDefrag.job
[2010/05/07 11:17:54 | 000,000,970 | —- | C] () – C:\Users\Public\Desktop\Smart Defrag.lnk
[2010/05/07 11:12:45 | 000,001,107 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\Revo Uninstaller.lnk
[2010/05/07 11:09:55 | 000,001,076 | —- | C] () – C:\Windows\bthservsdp.dat
[2010/05/07 06:49:23 | 000,121,856 | —- | C] () – C:\Windows\SysNative\EhStorAuthn.dll
[2010/05/07 06:49:23 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2010/05/07 06:49:17 | 000,262,552 | —- | C] () – C:\Windows\SysNative\systemsf.ebd
[2010/05/07 06:49:08 | 000,471,992 | —- | C] () – C:\Windows\SysNative\dot3.tmf
[2010/05/07 06:49:05 | 000,700,507 | —- | C] () – C:\Windows\SysNative\eaphost.tmf
[2010/05/07 06:48:58 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2010/05/07 06:48:58 | 000,107,612 | —- | C] () – C:\Windows\SysNative\StructuredQuerySchema.bin
[2010/05/07 06:48:55 | 003,662,128 | —- | C] () – C:\Windows\SysWow64\locale.nls
[2010/05/07 06:48:55 | 003,662,128 | —- | C] () – C:\Windows\SysNative\locale.nls
[2010/05/07 06:48:55 | 000,395,723 | —- | C] () – C:\Windows\SysNative\onex.tmf
[2010/05/07 06:48:40 | 000,207,968 | —- | C] () – C:\Windows\SysNative\WFP.TMF
[2010/05/07 06:48:38 | 000,092,918 | —- | C] () – C:\Windows\SysWow64\slmgr.vbs
[2010/05/07 06:48:38 | 000,092,918 | —- | C] () – C:\Windows\SysNative\slmgr.vbs
[2010/05/07 06:48:36 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2010/05/07 06:48:28 | 000,009,239 | —- | C] () – C:\Windows\SysWow64\spcinstrumentation.man
[2010/05/07 06:48:28 | 000,009,239 | —- | C] () – C:\Windows\SysNative\spcinstrumentation.man
[2010/05/07 06:48:22 | 000,009,212 | —- | C] () – C:\Windows\SysWow64\RacUR.xml
[2010/05/07 06:48:22 | 000,009,212 | —- | C] () – C:\Windows\SysNative\RacUR.xml
[2010/05/06 10:41:52 | 000,000,389 | —- | C] () – C:\Users\Chris B. Stiffer\Documents\Pictures - Shortcut.lnk
[2010/05/04 18:38:52 | 000,001,810 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\Mozilla Firefox.lnk
[2010/05/04 18:19:49 | 000,057,667 | —- | C] () – C:\Windows\SysWow64\ieuinit.inf
[2010/05/04 18:19:49 | 000,057,667 | —- | C] () – C:\Windows\SysNative\ieuinit.inf
[2010/05/04 14:44:55 | 000,000,918 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2010/05/04 14:44:54 | 000,000,914 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2010/05/04 13:36:48 | 002,608,861 | —- | C] () – C:\Windows\SysNative\wlan.tmf
[2010/05/04 13:07:11 | 000,000,440 | -H– | C] () – C:\Windows\tasks\User_Feed_Synchronization-{8DCC1D6B-C9D0-43DE-B666-A0B12FC92D17}.job
[2010/05/04 12:24:48 | 000,000,981 | —- | C] () – C:\Users\Chris B. Stiffer\Desktop\Launch Internet Explorer Browser.lnk
[2010/05/04 12:16:55 | 000,053,355 | —- | C] () – C:\Users\Chris B. Stiffer\Documents\license.rtf
[2010/05/04 12:12:03 | 000,000,020 | -HS- | C] () – C:\Users\Chris B. Stiffer\ntuser.ini
[2010/05/04 12:12:02 | 003,670,016 | -HS- | C] () – C:\Users\Chris B. Stiffer\ntuser.dat
[2010/05/04 12:12:02 | 000,524,288 | -HS- | C] () – C:\Users\Chris B. Stiffer\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000002.regtrans-ms
[2010/05/04 12:12:02 | 000,524,288 | -HS- | C] () – C:\Users\Chris B. Stiffer\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TMContainer00000000000000000001.regtrans-ms
[2010/05/04 12:12:02 | 000,262,144 | -H– | C] () – C:\Users\Chris B. Stiffer\ntuser.dat.LOG1
[2010/05/04 12:12:02 | 000,065,536 | -HS- | C] () – C:\Users\Chris B. Stiffer\NTUSER.DAT{c328fef1-6a85-11db-9fbd-cf3689cba3de}.TM.blf
[2010/05/04 12:12:02 | 000,000,000 | -H– | C] () – C:\Users\Chris B. Stiffer\ntuser.dat.LOG2
[2010/04/13 14:41:38 | 000,276,196 | —- | C] () – C:\Windows\SysNative\NvApps.xml
[2010/04/13 14:41:38 | 000,066,714 | —- | C] () – C:\Windows\SysNative\NvwsApps.xml
[2009/05/12 03:12:27 | 000,221,184 | —- | C] () – C:\Windows\SysWow64\drivers\ServiceHelp.dll
[2009/05/12 03:07:14 | 000,024,576 | R— | C] () – C:\Windows\SysWow64\AsIO.dll
[2009/05/12 03:07:14 | 000,014,392 | R— | C] () – C:\Windows\SysWow64\drivers\AsIO.sys
[2009/05/12 03:07:11 | 000,011,832 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp64.sys
[2009/05/12 03:07:11 | 000,010,216 | —- | C] () – C:\Windows\SysWow64\drivers\AsInsHelp32.sys
[2009/05/12 02:56:41 | 000,023,788 | —- | C] () – C:\Windows\Ascd_log.ini
[2009/05/12 02:56:33 | 000,017,480 | —- | C] () – C:\Windows\Ascd_tmp.ini
[2008/10/07 09:13:30 | 000,197,912 | —- | C] () – C:\Windows\SysWow64\physxcudart_20.dll
[2008/10/07 09:13:22 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelTraditionalChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSwedish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSpanish.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelSimplifiedChinese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelPortugese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelKorean.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelJapanese.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelGerman.dll
[2008/10/07 09:13:20 | 000,058,648 | —- | C] () – C:\Windows\SysWow64\AgCPanelFrench.dll
[2008/01/20 19:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2007/12/28 08:22:02 | 000,010,296 | —- | C] () – C:\Windows\SysWow64\drivers\ASUSHWIO.SYS
========== LOP Check ==========
[2010/06/10 11:15:02 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\Bioshock
[2010/05/30 22:37:58 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\FrostWire
[2010/05/18 09:16:14 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\GrabPro
[2010/06/10 06:54:08 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\IObit
[2010/06/07 07:50:13 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\Leadertech
[2010/05/24 12:09:25 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\LimeWire
[2010/06/11 06:17:44 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\Metacafe
[2010/05/07 12:20:22 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\Opera
[2010/06/14 08:46:54 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\Orbit
[2010/06/04 15:45:50 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\PeerNetworking
[2010/06/07 18:50:50 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\runic games
[2010/05/16 11:12:22 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\SystemRequirementsLab
[2010/05/23 09:57:37 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\Uniblue
[2010/05/17 21:29:32 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\uTorrent
[2010/05/24 13:40:17 | 000,000,000 | —D | M] – C:\Users\Chris B. Stiffer\AppData\Roaming\VSRevoGroup
[2010/06/14 08:14:55 | 000,000,416 | —- | M] () – C:\Windows\Tasks\AWC Startup.job
[2010/06/14 02:59:50 | 000,032,646 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2010/06/06 23:24:53 | 000,000,430 | —- | M] () – C:\Windows\Tasks\SmartDefrag.job
[2010/06/14 08:57:00 | 000,000,434 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{786FC7F5-D297-4266-8C89-27C18AC66DD6}.job
[2010/06/14 08:49:49 | 000,000,440 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{8DCC1D6B-C9D0-43DE-B666-A0B12FC92D17}.job
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.exe >
< MD5 for: AGP440.SYS >
[2008/01/20 19:46:51 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6001.18000_none_163188bf770e4ab0\AGP440.sys
[2008/01/20 19:46:51 | 000,064,568 | —- | M] (Microsoft Corporation) MD5=F6F6793B7F17B550ECFDBD3B229173F7 – C:\Windows\winsxs\amd64_machine.inf_31bf3856ad364e35_6.0.6002.18005_none_181d01cb743015fc\AGP440.sys
< MD5 for: ATAPI.SYS >
[2008/01/20 19:46:50 | 000,022,584 | —- | M] (Microsoft Corporation) MD5=1898FAE8E07D97F2F6C2D5326C633FAC – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6001.18000_none_3956c39dd9e73fd2\atapi.sys
[2009/04/11 00:15:00 | 000,020,952 | —- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 – C:\Windows\SoftwareDistribution\Download\b7a36a24530dbf6d856c57e20cf520d9\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
[2009/04/11 00:15:00 | 000,020,952 | —- | M] (Microsoft Corporation) MD5=E68D9B3A3905619732F7FE039466A623 – C:\Windows\winsxs\amd64_mshdc.inf_31bf3856ad364e35_6.0.6002.18005_none_3b423ca9d7090b1e\atapi.sys
< MD5 for: CNGAUDIT.DLL >
[2006/11/02 04:16:48 | 000,014,848 | —- | M] (Microsoft Corporation) MD5=21322B1A2AD337C579F4A65EA0D25193 – C:\Windows\winsxs\amd64_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_424bc4aceb06de1c\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\SysWOW64\cngaudit.dll
[2006/11/02 02:46:03 | 000,011,776 | —- | M] (Microsoft Corporation) MD5=7F15B4953378C8B5161D65C26D5FED4D – C:\Windows\winsxs\x86_microsoft-windows-cngaudit-dll_31bf3856ad364e35_6.0.6000.16386_none_e62d292932a96ce6\cngaudit.dll
< MD5 for: IASTORV.SYS >
[2008/01/20 19:46:59 | 000,290,872 | —- | M] (Intel Corporation) MD5=3E3BF3627D886736D0B4E90054F929F6 – C:\Windows\winsxs\amd64_iastorv.inf_31bf3856ad364e35_6.0.6001.18000_none_0b2fedfc40256bc5\iaStorV.sys
< MD5 for: NETLOGON.DLL >
[2008/01/20 19:51:03 | 000,716,800 | —- | M] (Microsoft Corporation) MD5=5D0A4891F8CD0E9E64FF57A6A34044F5 – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_59d652c6f057598d\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SoftwareDistribution\Download\b7a36a24530dbf6d856c57e20cf520d9\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\SysWOW64\netlogon.dll
[2009/04/10 23:28:23 | 000,592,896 | —- | M] (Microsoft Corporation) MD5=95DAECF0FB120A7B5DA679CC54E37DDE – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_6616762521d9e6d4\netlogon.dll
[2009/04/11 00:11:16 | 000,717,312 | —- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB – C:\Windows\SoftwareDistribution\Download\b7a36a24530dbf6d856c57e20cf520d9\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2009/04/11 00:11:16 | 000,717,312 | —- | M] (Microsoft Corporation) MD5=A3F1B171702CA04744EE514243B45BFB – C:\Windows\winsxs\amd64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6002.18005_none_5bc1cbd2ed7924d9\netlogon.dll
[2008/01/20 19:48:28 | 000,592,384 | —- | M] (Microsoft Corporation) MD5=A8EFC0B6E75B789F7FD3BA5025D4E37F – C:\Windows\winsxs\wow64_microsoft-windows-security-netlogon_31bf3856ad364e35_6.0.6001.18000_none_642afd1924b81b88\netlogon.dll
< MD5 for: NVSTOR.SYS >
[2008/01/20 19:46:54 | 000,054,328 | —- | M] (NVIDIA Corporation) MD5=F7EA0FE82842D05EDA3EFDD376DBFDBA – C:\Windows\winsxs\amd64_nvraid.inf_31bf3856ad364e35_6.0.6001.18000_none_95f95eab775c159d\nvstor.sys
< MD5 for: SCECLI.DLL >
[2008/01/20 19:50:28 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=28B84EB538F7E8A0FE8B9299D591E0B9 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_9e812831c5d9a243\scecli.dll
[2008/01/20 19:49:49 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=35F1DD99F9903BC267C2AF16B09F9BF7 – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6001.18000_none_942c7ddf9178e048\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SoftwareDistribution\Download\b7a36a24530dbf6d856c57e20cf520d9\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\SysWOW64\scecli.dll
[2009/04/10 23:28:24 | 000,177,152 | —- | M] (Microsoft Corporation) MD5=8FC182167381E9915651267044105EE1 – C:\Windows\winsxs\wow64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_a06ca13dc2fb6d8f\scecli.dll
[2009/04/11 00:11:23 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B – C:\Windows\SoftwareDistribution\Download\b7a36a24530dbf6d856c57e20cf520d9\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
[2009/04/11 00:11:23 | 000,235,520 | —- | M] (Microsoft Corporation) MD5=9922ADB6DCA8F0F5EA038BEFF339C08B – C:\Windows\winsxs\amd64_microsoft-windows-s..urationengineclient_31bf3856ad364e35_6.0.6002.18005_none_9617f6eb8e9aab94\scecli.dll
< %systemroot%\*. /mp /s >
< %systemroot%\system32\*.dll /lockedfiles >
< %systemroot%\Tasks\*.job /lockedfiles >
< %systemroot%\system32\drivers\*.sys /lockedfiles >
< %systemroot%\System32\config\*.sav >
< %systemroot%\system32\drivers\*.sys /90 >
[2010/04/29 15:39:38 | 000,038,224 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysWOW64\drivers\mbamswissarmy.sys
< End of report >
Drive C: | 279.46 Gb Total Space | 187.15 Gb Free Space | 66.97% Space Free | Partition Type: NTFS
Drive D: | 409.17 Gb Total Space | 409.00 Gb Free Space | 99.96% Space Free | Partition Type: NTFS
E: Drive not present or media not loaded
F: Drive not present or media not loaded
G: Drive not present or media not loaded
H: Drive not present or media not loaded
I: Drive not present or media not loaded
Computer Name: OFFICE
Current User Name: Chris B. Stiffer
Logged in as Administrator.
Current Boot Mode: Normal
Scan Mode: Current user
Include 64bit Scans
Company Name Whitelist: On
Skip Microsoft Files: On
File Age = 90 Days
Output = Minimal
Quick Scan
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = Opera.HTML] – C:\Program Files (x86)\Opera\opera.exe (Opera Software)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Opera.HTML] – C:\Program Files (x86)\Opera\opera.exe (Opera Software)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files (x86)\Opera\opera.exe" "%1" (Opera Software)
https [open] – "C:\Program Files (x86)\Opera\opera.exe" "%1" (Opera Software)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] – "C:\Program Files (x86)\Microsoft Office\Office12\msohtmed.exe" /p %1 (Microsoft Corporation)
http [open] – "C:\Program Files (x86)\Opera\opera.exe" "%1" (Opera Software)
https [open] – "C:\Program Files (x86)\Opera\opera.exe" "%1" (Opera Software)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l (Microsoft Corporation)
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [OneNote.Open] – C:\PROGRA~2\MICROS~1\Office12\ONENOTE.EXE "%L" (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"AutoUpdateDisableNotify" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 26 57 A9 88 34 EE CA 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2112477045-800725573-1140253011-1000]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\S-1-5-21-2112477045-800725573-1140253011-1001]
"EnableNotifications" = 0
"EnableNotificationsRef" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 0
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Orbitdownloader\orbitdm.exe" = C:\Program Files (x86)\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files (x86)\Orbitdownloader\orbitnet.exe" = C:\Program Files (x86)\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files (x86)\Orbitdownloader\orbitdm.exe" = C:\Program Files (x86)\Orbitdownloader\orbitdm.exe:*:Enabled:Orbit – (Orbitdownloader.com)
"C:\Program Files (x86)\Orbitdownloader\orbitnet.exe" = C:\Program Files (x86)\Orbitdownloader\orbitnet.exe:*:Enabled:Orbit – (Orbitdownloader.com)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{079A8417-1335-4177-9D20-306558720A0C}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\netproj.exe |
"{0B6F6979-E347-4C53-AD9F-9CD7DC7F3F69}" = lport=49529 | protocol=6 | dir=in | name=akamai netsession interface |
"{0CDE59F8-5A26-4AB7-B887-13240655BFE0}" = lport=138 | protocol=17 | dir=in | app=system |
"{15BB5B38-816B-450B-AFD1-F193218CB564}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{1D476099-B7A9-4456-8CF5-C07A91020813}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1E4BD707-4247-44EC-844E-2983703F3EF1}" = rport=445 | protocol=6 | dir=out | app=system |
"{1E882710-1786-499F-B655-D144708C5CB2}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{24C491EE-3655-44B7-B3D5-3346292D78AB}" = lport=445 | protocol=6 | dir=in | app=system |
"{2EE54E0E-60A7-4FA1-90E7-9FB1BFEE4BF5}" = rport=139 | protocol=6 | dir=out | app=system |
"{3293FF38-02DF-4529-80EE-45772D50B9DF}" = rport=138 | protocol=17 | dir=out | app=system |
"{337B344A-3FC7-4891-B142-A580F158E229}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{37443391-0368-42E0-9FFF-F53034017AAA}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{39A010C7-9B9C-4671-AC8C-286403B978AF}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{3FFF4511-F12C-490F-A781-FE3FBDF101BC}" = lport=5722 | protocol=6 | dir=in | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{4E21B71C-BB31-4271-B8A8-0CA749A8479E}" = lport=139 | protocol=6 | dir=in | app=system |
"{5FE32947-7A35-491D-93BF-392B0D1015FB}" = lport=2869 | protocol=6 | dir=in | app=system |
"{6040A399-37BD-4CC4-916C-35A8C10EC62E}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{63BB88C5-5E4E-41CB-AC52-86C28907BEC7}" = lport=5358 | protocol=6 | dir=in | app=system |
"{72BBDB1F-B009-401B-8ABE-7FDFB403D88F}" = lport=137 | protocol=17 | dir=in | app=system |
"{72CE7086-2CF1-4A89-831A-8CAF88DBEA41}" = rport=5357 | protocol=6 | dir=out | app=system |
"{7646B590-6F60-4960-82D8-A4A65041AD8A}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{7731F6D1-C42C-46D7-9044-99A8510B9EE7}" = rport=137 | protocol=17 | dir=out | app=system |
"{838A8769-D652-4C7D-8BE6-5964C1E6CD80}" = lport=2869 | protocol=6 | dir=in | app=system |
"{869199D8-8B50-4F3E-97A2-D0BB2123E8B1}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{8FA87BD3-E6F1-47AA-B3DB-37CCF26EB6C8}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface |
"{922A4AD3-CCF1-4B4B-AC0F-C2DB5613C810}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\netproj.exe |
"{927A49E1-0E2D-4AD3-9BC0-30E0D2CCFDBA}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{93145584-482A-4740-8AE3-AEBC077EA7D4}" = rport=3540 | protocol=17 | dir=out | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{949154AC-CA2E-4D6E-ABC6-F34DC17946DC}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{9C9F0C17-31A8-48AF-A6DE-F7197E59B84A}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\netproj.exe |
"{A12A7066-05BC-4583-8E73-08D5F34772DB}" = rport=3587 | protocol=6 | dir=out | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{A5064433-430A-4982-8E2A-A926D7EEC879}" = lport=3702 | protocol=17 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{A582D91B-5F80-45E5-BBE0-648C76D5A92E}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{BBF31E4A-D4AC-438C-B1F6-A51D994807B9}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C02307FE-4105-4367-8AF3-B6D00186197F}" = lport=3540 | protocol=17 | dir=in | svc=pnrpsvc | app=%systemroot%\system32\svchost.exe |
"{C86D7352-A84D-4701-B3BB-21B7D3E2F162}" = lport=5357 | protocol=6 | dir=in | app=system |
"{CA344915-3D6E-4196-8844-0880AECC1196}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{CCE06FBC-4843-4CBF-9CAA-21563A600A74}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{CD3D1A72-BEB3-4169-8126-9A80DD5B8BDB}" = rport=3702 | protocol=17 | dir=out | app=%systemroot%\system32\netproj.exe |
"{D0FFC748-1C47-4005-9416-91853DA61C45}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{D86A501B-724D-4F82-A41C-CF719E460D38}" = rport=5358 | protocol=6 | dir=out | app=system |
"{DA0132E7-20B0-4862-B5D9-DD8A1F1D6A7C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{E2555734-9423-4E2E-9D0E-2CB517B31936}" = rport=5722 | protocol=6 | dir=out | svc=dfsr | app=%systemroot%\system32\dfsr.exe |
"{E3CE72C8-5486-4D81-98EF-2C9609DE3802}" = lport=3587 | protocol=6 | dir=in | svc=p2psvc | app=%systemroot%\system32\svchost.exe |
"{EC3C0A70-7F1C-4AF7-8DBB-4E5E47FD3131}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{006A0EF0-B420-4EE4-975F-BB1E12008E68}" = protocol=6 | dir=in | app=c:\program files (x86)\iobit\iobit smartdefrag\iobit smartdefrag.exe |
"{008D2E6B-29CA-42D3-9BF2-DC2B0F4BCA92}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{0244AE8A-C89A-4257-BD5F-5282ADBF3D34}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\jollyroverdemo\jolly_rover_demo.exe |
"{150B498F-E6D5-4F9D-B4AE-6AFF23EB33F9}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{1F68076F-2E0F-496D-AFD5-2D9629641073}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{28665A3C-C2A4-488F-8B77-73535F6A4F4D}" = protocol=6 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"{30630F15-CE20-4D87-B51B-9D84BE22555F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{34491EC8-6828-4C9B-8CFA-78BB08F12258}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{358BA78C-BBB8-4CCC-BD52-5B9109A41970}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{3D1E17EF-AE51-400D-94A0-C59A74505180}" = protocol=17 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{3F6FD396-1001-49C2-8B71-042C0323907A}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{40200B9E-5D9B-41E7-933E-37BFB7DC159E}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{451E65C3-9D8C-4A83-AA0E-22780ED083C6}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{4564A038-675E-4ED7-BACC-258887D0EBA2}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{4D4947EF-7E52-4691-854D-259186BE97AB}" = protocol=17 | dir=out | app=c:\program files (x86)\windows media player\wmplayer.exe |
"{501F203B-0105-44D1-A6AF-64C0DDCF2386}" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{54ABCE7F-7032-43D9-98D6-9BFFE85D82D7}" = protocol=17 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"{55B60A5F-B74F-490C-84FB-EF7E2E726BDD}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{58F40C68-6FB1-4CB1-839E-5BB030DCA526}" = protocol=6 | dir=out | app=%systemroot%\system32\netproj.exe |
"{5980EA19-30B9-4AC6-ACC8-918E643CBD58}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{5B2866D2-CA25-441D-89AD-97BB2DB25D48}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{5ECD6F04-237C-4429-966B-094D5786A1D0}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{6B50221D-0F55-4A02-92DB-112A754DC7DF}" = protocol=6 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{70B42495-48E0-4D41-8B2D-29329F121650}" = protocol=6 | dir=out | app=system |
"{74E23A3A-E669-49A6-AC1F-137DC66AC9A3}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 demo\arma2demo.exe |
"{75789BEB-0C5C-4797-9530-51F13F47A89C}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{75F547CB-B2C9-4DD0-891A-F257DF385860}" = protocol=6 | dir=in | app=c:\program files (x86)\nvidia corporation\3d vision\nvstview.exe |
"{7688E348-BA87-444A-9786-AACA1D121B88}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torchlight.exe |
"{78FFCD8F-798B-46AF-BC9B-96FFC9B2AF47}" = protocol=17 | dir=in | app=c:\program files (x86)\nvidia corporation\3d vision\nvstview.exe |
"{80B53636-88C6-41BA-950B-ADD4D8E11B74}" = protocol=6 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{890833C3-3F19-41AB-A0A3-730EF2EDEFCF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\shattered_horizon\client_exe\shattered_horizon.exe |
"{89E12231-6ED2-471F-8160-A9B2224DBD7E}" = protocol=6 | dir=in | app=%systemroot%\system32\p2phost.exe |
"{8AA033BF-256B-4B2B-BF82-40A732907615}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{8C9194AA-6C29-4110-9BF4-CE10CF9A6834}" = protocol=17 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{8F389949-19EF-4ECC-8AB7-BCF41EDDE90D}" = protocol=6 | dir=in | app=%systemroot%\system32\netproj.exe |
"{92AEC141-971F-40F8-AA7F-C5247C0D673F}" = protocol=17 | dir=in | app=c:\program files (x86)\iobit\iobit smartdefrag\iobit smartdefrag.exe |
"{92B7AAF1-2EEF-41EE-9AD6-76794BC8C84B}" = protocol=6 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{A00383C1-B49F-45B0-B622-565163DACC9F}" = protocol=6 | dir=out | svc=upnphost | app=c:\windows\system32\svchost.exe |
"{A13BD638-AB43-48C2-8127-B4BBBBB66AA0}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{A2E38A2D-19D9-481F-9C7E-14637C9D64D7}" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{A39DD7A1-A837-42DC-AC52-9100C9A733B5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\just cause 2 demo\justcause2.exe |
"{A67F1AB8-A09F-4531-81BC-9ED0DD896304}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arma 2 demo\arma2demo.exe |
"{AEB94B06-2837-45F6-B1F3-12728CBF3AC1}" = protocol=17 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{B4700953-B95E-41F3-AD3B-5B16274793AF}" = protocol=17 | dir=in | app=c:\program files\windows media player\wmplayer.exe |
"{B6B6097C-94E7-4425-8AA5-C8B2BFDF48AF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torchlight.exe |
"{B804080D-E91F-448F-B822-0CF48366FC49}" = protocol=17 | dir=in | app=c:\program files (x86)\iobit\advanced systemcare 3\awc.exe |
"{BF8F980E-D96E-433C-A036-E6C3B026C27C}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{C19B8E65-5018-4E7C-9B2A-218B1E86831D}" = protocol=17 | dir=in | app=c:\program files (x86)\windows media player\wmplayer.exe |
"{C2D936FB-FE60-4B2B-9569-4FD60A2CAC73}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\just cause 2 demo\justcause2.exe |
"{C756B3DE-A37A-4C95-A73F-55B1160D9965}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\jollyroverdemo\jolly_rover_demo.exe |
"{C770319D-84EC-4E67-973E-E6908E8F3701}" = protocol=6 | dir=in | app=c:\program files (x86)\vs revo group\revo uninstaller\revouninstaller.exe |
"{C91AD01F-759B-4B21-B071-EB1598C530C7}" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"{CCFE047F-26AB-4CD1-8C66-ACA3F7B407C5}" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\logitech vid\vid.exe |
"{D15AFB50-1F22-4E69-A06E-39C8B64924E9}" = protocol=6 | dir=out | app=c:\program files\windows media player\wmplayer.exe |
"{D545EFD7-2F73-4BB6-9CEB-94B775BCB3C9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\shattered_horizon\client_exe\shattered_horizon.exe |
"{D5A4FC63-147C-4635-A9B0-E49CB31188D1}" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\logitech vid\vid.exe |
"{D9E877EA-6BD7-4EC0-BCF6-3CC541660781}" = protocol=6 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{E3684CFF-42D4-4D74-BCD2-B65ECCEA9B3D}" = protocol=6 | dir=in | app=c:\program files (x86)\iobit\advanced systemcare 3\awc.exe |
"{E5D77EB8-9A68-4CE9-B8FC-890B564D6017}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{E64D57F7-BA1F-44E8-88DE-CC6768F69F81}" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"{E9BE944D-B0F5-4C25-B340-310B3D2716FA}" = protocol=17 | dir=in | app=%programfiles%\windows collaboration\wincollab.exe |
"{EA2B9561-9216-4BE3-B393-21A62DD1E522}" = protocol=6 | dir=out | app=%systemroot%\system32\p2phost.exe |
"{EBBC2530-54AC-4442-8442-B04AEF3E61A7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{ECCB98E1-927A-4BC9-9C41-A373B7496FBA}" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{F34C5B7F-65A6-447E-89FE-CA409DEE007C}" = protocol=6 | dir=out | app=c:\windows\system32\wudfhost.exe |
"{F4B51636-F631-4131-AA0A-896E0CDFF500}" = protocol=6 | dir=out | app=c:\program files (x86)\windows media player\wmplayer.exe |
"{F58551EC-199E-403D-8BFB-C04437BBDFE9}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{F5EE24FA-62FE-4881-9C80-2812CEF6DD81}" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\battlefield bad company 2\bfbc2updater.exe |
"{F716B63D-AFA4-47F9-AA12-CAE64BF76D18}" = protocol=17 | dir=out | app=%programfiles%\windows collaboration\wincollab.exe |
"{FDE89E61-54F0-4E9E-B795-740A15069386}" = protocol=17 | dir=in | app=c:\program files (x86)\vs revo group\revo uninstaller\revouninstaller.exe |
"TCP Query User{3DC1FC29-C20B-47AA-853D-D91377993446}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"TCP Query User{43D65AC9-EBD0-42E0-B5D9-C68C29FC01A5}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"TCP Query User{54012E5A-D6C7-4090-BC73-3B2E736A2E13}C:\program files (x86)\frostwire\frostwire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"TCP Query User{7C690E37-8862-40F8-8322-117BE7AF2EC6}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"TCP Query User{7D039626-9F85-4D2D-972C-D42052C26FEA}C:\program files (x86)\orbitdownloader\orbitnet.exe" = protocol=6 | dir=in | app=c:\program files (x86)\orbitdownloader\orbitnet.exe |
"TCP Query User{7D428E13-44C9-49E2-9C7E-BE3F4259F683}C:\program files (x86)\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"TCP Query User{A8E969C9-6F21-47FD-8BB0-52636EAF24A8}C:\program files (x86)\orbitdownloader\orbitnet.exe" = protocol=6 | dir=in | app=c:\program files (x86)\orbitdownloader\orbitnet.exe |
"TCP Query User{CA7FACF5-023B-4EF9-A8F7-A0D66B56246F}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"TCP Query User{DB49AA7E-08FC-4A91-A304-D01B92112DCC}C:\program files (x86)\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"TCP Query User{E5E95EA9-90E6-4EBD-835F-07E67D76B37A}C:\program files (x86)\limewire\limewire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"TCP Query User{F6017955-7552-42C4-9540-A5CD83EE0728}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{1647DDFF-5EF7-4DB9-A41B-7DAF1C25F591}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{35B618A4-C079-4B72-8DF0-DCCCF1A13B5B}C:\program files (x86)\orbitdownloader\orbitnet.exe" = protocol=17 | dir=in | app=c:\program files (x86)\orbitdownloader\orbitnet.exe |
"UDP Query User{3ABCC43E-8BA7-443E-A7ED-3856D11634E0}C:\program files (x86)\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"UDP Query User{5B360970-AA8F-420F-990B-415BDA9DCC71}C:\program files (x86)\mozilla firefox\firefox.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\firefox.exe |
"UDP Query User{762D74DA-3770-48DB-9611-D1F6F927A0A1}C:\program files (x86)\frostwire\frostwire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\frostwire\frostwire.exe |
"UDP Query User{986F8F1B-9611-4EFF-9AD4-A37DC3187943}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
"UDP Query User{A82DAE64-25EC-4E56-A021-4F4E776248FA}C:\program files (x86)\yahoo!\messenger\yahoomessenger.exe" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"UDP Query User{AA33C71C-9FC2-4930-AC4C-78FC3AA67FEB}C:\program files (x86)\orbitdownloader\orbitnet.exe" = protocol=17 | dir=in | app=c:\program files (x86)\orbitdownloader\orbitnet.exe |
"UDP Query User{BCFAEAA1-E17B-476C-A67D-C073E8BBD678}C:\program files (x86)\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files (x86)\opera\opera.exe |
"UDP Query User{DCE5876C-FB13-4BAB-8BD8-0BC85DE61316}C:\program files (x86)\limewire\limewire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"UDP Query User{F1622837-BF0C-432B-AACD-CEC9503A224F}C:\program files (x86)\internet explorer\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{5AC309D7-93D6-418F-8DCA-DD710724A5B4}" = Windows Live Family Safety
"{5AFA78B0-D9BE-4EBE-ACE4-358F14A32044}" = Touch Manager
"{67579783-0FB7-4F7B-B881-E5BE47C9DBE0}_is1" = Revo Uninstaller Pro 2.2.0
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0407-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (German) 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-002A-040C-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (French) 2007
"{90120000-002A-0413-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Dutch) 2007
"{90120000-002A-0C0A-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (Spanish) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{987FE247-4E69-4A2E-A961-D14F901FDBF6}" = Logitech Webcam Software
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{B6E3757B-5E77-3915-866A-CCFC4B8D194C}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x64 8.0.50727.4053
"{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
"{c9920352-04e6-469d-bab8-e2b9c7c75415}.sdb" = Microsoft Automated Troubleshooting Services Shim
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"lvdrivers_12.10" = Logitech Webcam Software Driver Package
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"NVIDIA Display Control Panel" = NVIDIA Display Control Panel
"NVIDIA Drivers" = NVIDIA Drivers
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{1BD07DF4-FB06-41BA-B896-B2DA59000C96}" = Windows Live Toolbar
"{226b64e8-dc75-4eea-a6c8-abcb496320f2}-Google Talk" = Google Talk (remove only)
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{240CE762-0ECF-3EA9-9B88-59EFA15C781A}" = Visual C++ 9.0 ATL (x86) WinSXS MSM
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 20
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{3175E049-F9A9-4A3D-8F19-AC9FB04514D1}" = Windows Live Communications Platform
"{3AC8457C-0385-4BEA-A959-E095F05D6D67}" = Battlefield: Bad Company™ 2
"{474F25F5-BDC9-40E5-B1B6-F6BF23FC106F}" = Windows Live Essentials
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4AF95DE2-B54D-4C3F-9494-FD3B558E2C2D}" = AI Manager
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{644DE414-7746-31B5-908B-E938B4078584}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{6530FDAA-5B1F-4830-95BB-650E9804D239}" = UE3Redist
"{70312451-0D00-4A84-B9B1-0D59B5180A4F}" = Opera 10.53
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8F66047B-1AF3-40D9-80D7-106E2EDC2C2A}" = EPU-4 Engine
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Azurewave Wireless LAN Card
"{90120000-0016-0407-0000-0000000FF1CE}" = Microsoft Office Excel MUI (German) 2007
"{90120000-0016-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-040C-0000-0000000FF1CE}" = Microsoft Office Excel MUI (French) 2007
"{90120000-0016-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0413-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Dutch) 2007
"{90120000-0016-0413-0000-0000000FF1CE}_HOMESTUDENTR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0016-0C0A-0000-0000000FF1CE}" = Microsoft Office Excel MUI (Spanish) 2007
"{90120000-0016-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0407-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (German) 2007
"{90120000-0018-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-040C-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (French) 2007
"{90120000-0018-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0413-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Dutch) 2007
"{90120000-0018-0413-0000-0000000FF1CE}_HOMESTUDENTR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0018-0C0A-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (Spanish) 2007
"{90120000-0018-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0407-0000-0000000FF1CE}" = Microsoft Office Word MUI (German) 2007
"{90120000-001B-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-040C-0000-0000000FF1CE}" = Microsoft Office Word MUI (French) 2007
"{90120000-001B-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0413-0000-0000000FF1CE}" = Microsoft Office Word MUI (Dutch) 2007
"{90120000-001B-0413-0000-0000000FF1CE}_HOMESTUDENTR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001B-0C0A-0000-0000000FF1CE}" = Microsoft Office Word MUI (Spanish) 2007
"{90120000-001B-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-001F-0401-0000-0000000FF1CE}" = Microsoft Office Proof (Arabic) 2007
"{90120000-001F-0401-0000-0000000FF1CE}_HOMESTUDENTR_{14809F99-C601-4D4A-9391-F1E8FAA964C5}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0403-0000-0000000FF1CE}" = Microsoft Office Proof (Catalan) 2007
"{90120000-001F-0403-0000-0000000FF1CE}_HOMESTUDENTR_{4B47C31E-46B0-462B-BEE4-DC383B6A1F2A}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0407-0000-0000000FF1CE}" = Microsoft Office Proof (German) 2007
"{90120000-001F-0407-0000-0000000FF1CE}_HOMESTUDENTR_{A0516415-ED61-419A-981D-93596DA74165}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{ABDDE972-355B-4AF1-89A8-DA50B7B5C045}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{F580DDD5-8D37-4998-968E-EBB76BB86787}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0410-0000-0000000FF1CE}" = Microsoft Office Proof (Italian) 2007
"{90120000-001F-0410-0000-0000000FF1CE}_HOMESTUDENTR_{322296D4-1EAE-4030-9FBC-D2787EB25FA2}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0413-0000-0000000FF1CE}" = Microsoft Office Proof (Dutch) 2007
"{90120000-001F-0413-0000-0000000FF1CE}_HOMESTUDENTR_{D66D5A44-E480-4BA4-B4F2-C554F6B30EBB}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-0416-0000-0000000FF1CE}" = Microsoft Office Proof (Portuguese (Brazil)) 2007
"{90120000-001F-0416-0000-0000000FF1CE}_HOMESTUDENTR_{75EBE365-7FC5-4720-A7D3-804BF550D1BC}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-001F-042D-0000-0000000FF1CE}" = Microsoft Office Proof (Basque) 2007
"{90120000-001F-0456-0000-0000000FF1CE}" = Microsoft Office Proof (Galician) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{187308AB-5FA7-4F14-9AB9-D290383A10D9}" = Microsoft Office Proofing Tools 2007 Service Pack 2 (SP2)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{E64BA721-2310-4B55-BE5A-2925F9706192}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0407-1000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-040C-1000-0000000FF1CE}_HOMESTUDENTR_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0413-1000-0000000FF1CE}_HOMESTUDENTR_{89C8E56A-90D8-4598-B0E6-EB28F6270E07}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002A-0C0A-1000-0000000FF1CE}_HOMESTUDENTR_{6113C11D-BACA-4D8E-8002-03C8D06FD5E6}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-002C-0407-0000-0000000FF1CE}" = Microsoft Office Proofing (German) 2007
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-002C-040C-0000-0000000FF1CE}" = Microsoft Office Proofing (French) 2007
"{90120000-002C-0413-0000-0000000FF1CE}" = Microsoft Office Proofing (Dutch) 2007
"{90120000-002C-0C0A-0000-0000000FF1CE}" = Microsoft Office Proofing (Spanish) 2007
"{90120000-006E-0407-0000-0000000FF1CE}" = Microsoft Office Shared MUI (German) 2007
"{90120000-006E-0407-0000-0000000FF1CE}_HOMESTUDENTR_{26454C26-D259-4543-AA60-3189E09C5F76}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-040C-0000-0000000FF1CE}" = Microsoft Office Shared MUI (French) 2007
"{90120000-006E-040C-0000-0000000FF1CE}_HOMESTUDENTR_{B165D3C2-40AE-4D39-86F7-E5C87C4264C0}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0413-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Dutch) 2007
"{90120000-006E-0413-0000-0000000FF1CE}_HOMESTUDENTR_{89C8E56A-90D8-4598-B0E6-EB28F6270E07}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-006E-0C0A-0000-0000000FF1CE}" = Microsoft Office Shared MUI (Spanish) 2007
"{90120000-006E-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{6113C11D-BACA-4D8E-8002-03C8D06FD5E6}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0407-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (German) 2007
"{90120000-00A1-0407-0000-0000000FF1CE}_HOMESTUDENTR_{9BD40163-B95D-4B07-8991-0AB775B6D88B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{2FC4457D-409E-466F-861F-FB0CB796B53E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-040C-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (French) 2007
"{90120000-00A1-040C-0000-0000000FF1CE}_HOMESTUDENTR_{AE187E0D-EBA5-4EE1-A397-BF1A577CB24C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0413-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Dutch) 2007
"{90120000-00A1-0413-0000-0000000FF1CE}_HOMESTUDENTR_{DC387AA5-94A6-4920-B004-D59846526D81}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-00A1-0C0A-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (Spanish) 2007
"{90120000-00A1-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{91A7F72A-3273-4C1E-8BE0-BC9DD0D9345C}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{9074AFC0-CFDA-11DE-B484-005056806466}" = Google Earth
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{0B36C6D6-F5D8-4EAF-BF94-4376A230AD5B}" = Microsoft Office 2007 Service Pack 2 (SP2)
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9F479685-180E-4C05-9400-D59292A1B29C}" = Windows Live Movie Maker
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-A93000000001}" = Adobe Reader 9.3.2
"{B10914FD-8812-47A4-85A1-50FCDE7F1F33}" = Windows Live Sync
"{B57EAFF2-D6EE-4C6C-9175-ED9F17BFC1BC}" = Windows Live Messenger
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C7DEE429-4C9B-4126-894F-50B4F54FF196}" = inSSIDer
"{D56B0E27-4A3E-46C9-B5C1-D93D580C099C}" = NVIDIA PhysX v8.10.29
"{D8D85FD0-537C-3A3A-9BEC-7A1B426637EC}" = Visual C++ 9.0 CRT (x86) WinSXS MSM
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E6158D07-2637-4ECF-B576-37C489669174}" = Windows Live Call
"{EE39FFBD-544E-49E4-A999-6819828EAE91}" = Windows Live Photo Gallery
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F40BBEC7-C2A4-4A00-9B24-7A055A2C5262}" = Microsoft Office Live Add-in 1.5
"{F4F4F84E-804F-4E9A-84D7-C34283F0088F}" = RealUpgrade 1.0
"{F8131A35-47FD-27AD-116D-0E79AF5DE5EE}" = Acrobat.com
"{FE0646A7-19D0-41B4-A2BB-2C35D644270D}" = Windows Live OneCare safety scanner
"7-Zip" = 7-Zip 9.13 beta
"ActiveScan 2.0" = Panda ActiveScan 2.0
"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Advanced SystemCare 3_is1" = Advanced SystemCare 3
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"FrostWire" = FrostWire 4.20.6
"Game Booster_is1" = Game Booster
"Heavy Weapon Deluxe 1.0" = Heavy Weapon Deluxe 1.0
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IObit Security 360_is1" = IObit Security 360
"KTbWorks" = Kensington TrackballWorks
"LimeWire" = LimeWire 5.5.8
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Metacafe" = Metacafe
"Mozilla Firefox (3.6.3)" = Mozilla Firefox (3.6.3)
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"Orbit_is1" = Orbit Downloader
"OWC WebCamDV" = OrangeWare WebCamDV
"Picasa 3" = Picasa 3
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 12.0" = RealPlayer
"Revo Uninstaller" = Revo Uninstaller 1.87
"Smart Defrag_is1" = Smart Defrag
"Steam App 18110" = Shattered Horizon
"Steam App 31710" = Iron Grip: Warlord - Demo
"Steam App 33920" = ARMA 2 Demo
"Steam App 35110" = Just Cause 2 Demo
"Steam App 58220" = Jolly Rover Demo
"StumbleUponIEToolbar" = StumbleUpon IE Toolbar
"SystemRequirementsLab" = System Requirements Lab
"WinGimp-2.0_is1" = GIMP 2.6.8
"WinLiveSuite_Wave3" = Windows Live Essentials
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Messenger" = Yahoo! Messenger
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"InstallShield_{6530FDAA-5B1F-4830-95BB-650E9804D239}" = UE3Redist
========== Last 10 Event Log Errors ==========
[ Application Events ]
Error - 6/10/2010 10:21:54 AM | Computer Name = office | Source = WinMgmt | ID = 10
Description =
Error - 6/10/2010 10:22:23 AM | Computer Name = office | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 6/10/2010 10:22:23 AM | Computer Name = office | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 6/10/2010 10:56:02 AM | Computer Name = office | Source = Windows Search Service | ID = 3013
Description =
Error - 6/10/2010 12:57:30 PM | Computer Name = office | Source = System Restore | ID = 8193
Description =
Error - 6/10/2010 6:44:05 PM | Computer Name = office | Source = WinMgmt | ID = 10
Description =
Error - 6/10/2010 8:27:05 PM | Computer Name = office | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 6/10/2010 8:27:21 PM | Computer Name = office | Source = Microsoft-Windows-CAPI2 | ID = 131083
Description =
Error - 6/10/2010 8:30:40 PM | Computer Name = office | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
Error - 6/10/2010 8:30:40 PM | Computer Name = office | Source = SideBySide | ID = 16842787
Description = Activation context generation failed for "C:\Program Files (x86)\Windows
Live\Photo Gallery\MovieMaker.Exe".Error in manifest or policy file "C:\Program
Files (x86)\Windows Live\Photo Gallery\WLMFDS.DLL" on line 8. Component identity
found in manifest does not match the identity of the component requested. Reference
is WLMFDS,processorArchitecture="AMD64",type="win32",version="1.0.0.1". Definition
is WLMFDS,processorArchitecture="x86",type="win32",version="1.0.0.1". Please use
sxstrace.exe for detailed diagnosis.
[ System Events ]
Error - 5/6/2010 11:44:40 AM | Computer Name = office | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
Error - 5/6/2010 1:15:48 PM | Computer Name = office | Source = HTTP | ID = 15016
Description =
Error - 5/6/2010 1:16:16 PM | Computer Name = office | Source = Microsoft-Windows-LanguagePackSetup | ID = 1001
Description =
< End of report >
ults: