Ultima_Weapon
Topic Starter
Safe mode still works 100% fine.
Basically, just as I said in the title. You can get one program up real quickly, which is how I got Avast! to do a boot-time scan. Then, it'll just be really really slow and just load, nothing will show up. After a bit, the screen will go white as it's "not responding" and then all black, with the mouse cursor movable.
Avast is being weird in safe mode, though.. I did a full-time scan and a boot-time scan, got 3 things then 2 things. Two of the things from the first was put in the chest easy, but this "root kit system modification" thing is what I believe the problem is. It won't let me delete it until "a system restart". The thing is found at "System32.RegBack.SECURITY.OLD".
However, if I do that with Avast or schedule a boot-time scan, it'll just do nothing when I turn the computer on/restart it. Heck, you can schedule a boot-time scan, click something else, then go back to Avast and it's off. It says the "Avast" service is off, but trying to turn it back on doesn't work.
I've also done a Malwarebyte's quick and full scan, aswMBR scans, OTS scan/fix, tdsskiller and ComboFix (followed another forum's directions on this), but to no avail. However, asides from the Avast and Malwarebytes scans, these are of dubious quality - some of them had the computer restart even though there's no mention in the program/guide that it would cause it to restart, so they may have not finished.
Just did a Spybot Search + Destroy, had some results but the problem persists.
Thanks in advance for any help you can offer me.
OTL Logs:
OTL
OTL logfile created on: 6/21/2011 7:36:20 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Chameleon\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 3.07 Gb Available Physical Memory | 76.71% Memory free
8.17 Gb Paging File | 7.41 Gb Available in Paging File | 90.69% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.40 Gb Total Space | 46.37 Gb Free Space | 16.25% Space Free | Partition Type: NTFS
Drive E: | 7.91 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 931.51 Gb Total Space | 359.20 Gb Free Space | 38.56% Space Free | Partition Type: NTFS
Drive G: | 539.19 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: CHA-PC | User Name: Chameleon | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Chameleon\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
========== Modules (SafeList) ==========
MOD - C:\Users\Chameleon\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:64bit: - (ADSMService) – C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (ATKGFNEXSrv) – C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ASLDRService) – C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe ()
SRV - (Viewpoint Manager Service) – C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (SmartDefragDriver) – C:\Windows\SysNative\Drivers\SmartDefragDriver.sys ()
DRV:64bit: - (cpuz135) – C:\Windows\SysNative\drivers\cpuz135_x64.sys (CPUID)
DRV:64bit: - (SaiNtBus) – C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) – C:\Windows\SysNative\DRIVERS\SaiMini.sys (Saitek)
DRV:64bit: - (SaiK0CFA) – C:\Windows\SysNative\DRIVERS\SaiK0CFA.sys (Saitek)
DRV:64bit: - (SaiU0CFA) – C:\Windows\SysNative\DRIVERS\SaiU0CFA.sys (Saitek)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (MotioninJoyXFilter) – C:\Windows\SysNative\DRIVERS\MijXfilt.sys (MotioninJoy)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\DRIVERS\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (Point64) – C:\Windows\SysNative\DRIVERS\point64k.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\DRIVERS\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (mcdbus) – C:\Windows\SysNative\DRIVERS\mcdbus.sys (MagicISO, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\DRIVERS\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\Windows\SysNative\DRIVERS\snp2uvc.sys ()
DRV:64bit: - (NETw5v64) Intel® – C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (rimmptsk) – C:\Windows\SysNative\DRIVERS\rimmpx64.sys (REDC)
DRV:64bit: - (kbfiltr) – C:\Windows\SysNative\DRIVERS\kbfiltr.sys ( )
DRV:64bit: - (itecir) – C:\Windows\SysNative\DRIVERS\itecir.sys (ITE Tech. Inc. )
DRV:64bit: - (SynTP) – C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV:64bit: - (rismxdp) – C:\Windows\SysNative\DRIVERS\rixdpx64.sys (REDC)
DRV:64bit: - (rimsptsk) – C:\Windows\SysNative\DRIVERS\rimspx64.sys (REDC)
DRV:64bit: - (ASMMAP64) – C:\Program Files\ATKGFNEX\ASMMAP64.sys ()
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\DRIVERS\ATK64AMD.sys ()
DRV:64bit: - (yukonx64) – C:\Windows\SysNative\DRIVERS\yk60x64.sys (Marvell)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\Wbem\ntfs.mof ()
DRV - (RivaTuner64) – C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys ()
DRV - (mcdbus) – C:\Windows\SysWOW64\drivers\mcdbus.sys (MagicISO, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…S&bmod;=ASUS
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gamefaqs.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:18810
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;="
FF - prefs.js..browser.search.selectedEngine: "AIM Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.gamefaqs.com/"
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {f701c26a-479a-4724-b4f1-870db12f063c}:1.4.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {6dd0bdba-0a02-429e-b595-87a7dfdca7a1}:0.7.12
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:[removed]
FF - prefs.js..extensions.enabledItems: FFToolbar@upromise:7.0.2.4181
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;="
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011/05/17 15:54:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/06/03 12:53:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/03 12:52:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/06/06 17:28:02 | 000,000,000 | —D | M]
[2009/09/10 20:40:37 | 000,000,000 | —D | M] (No name found) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Extensions
[2011/04/29 18:14:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions
[2011/01/29 13:10:07 | 000,000,000 | —D | M] (Winamp Toolbar) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010/04/26 20:18:09 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/18 16:32:41 | 000,000,000 | —D | M] (Linkification) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2011/02/09 13:34:36 | 000,000,000 | —D | M] (GameFOX) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions\{6dd0bdba-0a02-429e-b595-87a7dfdca7a1}
[2011/03/15 23:01:40 | 000,000,000 | —D | M] (Text-to-Image) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions\{f701c26a-479a-4724-b4f1-870db12f063c}
[2011/03/10 14:57:50 | 000,000,000 | —D | M] ("Upromise TurboSaver") – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions\FFToolbar@upromise
[2009/09/10 20:44:39 | 000,004,261 | —- | M] () – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\searchplugins\aim-search.xml
[2011/01/29 13:11:56 | 000,001,196 | —- | M] () – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\searchplugins\winamp-search.xml
[2011/06/10 23:36:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/06/09 15:40:11 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/16 15:00:25 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/01/13 08:29:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/12 20:54:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) –
[2011/05/17 15:54:11 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF
[2011/06/03 12:53:09 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/04/14 11:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2011/02/02 22:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/04/16 12:07:12 | 000,180,293 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\plugins\npViewpoint.dll
[2010/12/09 05:47:06 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/06/21 13:15:32 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4:64bit: - HKLM..\Run: [DisableS3S4] File not found
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe (Saitek)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe (Saitek)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ATK)
O4 - HKLM..\Run: [ADSMTray] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe ()
O4 - HKLM..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe ()
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDRShortCut] C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [Aim] C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: &Winamp; Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: &Winamp; Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Chameleon\Documents\Pix\[AnimePaper]wallpapers_Kara-no-Kyoukai_redxxii(1_33)_1024x768_72601.jpg
O24 - Desktop BackupWallPaper: C:\Users\Chameleon\Documents\Pix\[AnimePaper]wallpapers_Kara-no-Kyoukai_redxxii(1_33)_1024x768_72601.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/06 08:21:01 | 000,000,000 | R–D | M] - F:\autorun – [ NTFS ]
O32 - AutoRun File - [2005/10/25 20:53:00 | 000,000,044 | R— | M] () - G:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2011/06/21 13:38:08 | 000,000,000 | —D | C] – C:\_OTS
[2011/06/21 13:31:47 | 000,000,000 | —D | C] – C:\Users\Chameleon\Desktop\tdsskiller
[2011/06/21 13:25:05 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/06/21 13:25:04 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Local\temp
[2011/06/21 13:15:43 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/06/21 12:46:50 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/06/21 12:46:50 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/06/21 12:46:50 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/06/21 12:46:38 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/06/21 12:45:19 | 000,000,000 | —D | C] – C:\Qoobox
[2011/06/21 12:45:12 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2011/06/18 23:38:33 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Roaming\TerrariaMod
[2011/06/16 14:38:15 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/06/16 14:37:46 | 000,710,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/06/16 14:37:45 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/06/16 14:37:44 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/06/16 14:37:43 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/06/16 14:37:40 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/06/16 14:37:39 | 001,538,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/06/16 14:37:39 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/06/16 14:37:39 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/06/16 14:37:39 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/06/16 14:37:38 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/06/16 14:37:38 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/06/16 14:37:38 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/06/16 14:37:37 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/06/16 14:37:37 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/06/16 14:37:37 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/06/16 14:37:36 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/06/16 14:37:36 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/06/16 14:37:36 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/06/16 14:37:36 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/06/16 14:37:36 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/06/16 14:37:36 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/06/16 14:37:36 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/06/16 14:37:35 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/06/16 14:37:35 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/06/16 14:37:35 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/06/16 14:37:30 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/06/16 14:37:30 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/06/16 14:37:30 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/06/13 20:20:23 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Earth2Me
[2011/06/13 20:19:47 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Local\Apps
[2011/06/13 20:19:46 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Local\Deployment
[2011/06/13 20:19:28 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Synchronization Services
[2011/06/13 20:19:28 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2011/06/13 20:18:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Synchronization Services
[2011/06/13 16:50:14 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Roaming\IObit
[2011/06/13 16:50:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 2
[2011/06/13 16:49:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Booster
[2011/06/13 16:49:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2011/06/13 16:46:57 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2011/06/10 01:43:21 | 000,000,000 | —D | C] – C:\ProgramData\Skype Extras
[2011/06/10 01:39:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/06/10 01:39:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2011/06/09 23:23:34 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Roaming\TerrariaWorldViewer
[2011/06/08 15:05:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\osu!
[2011/06/08 15:04:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\osu!
[2011/06/08 15:03:38 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Roaming\Downloaded Installations
[2011/06/07 01:01:53 | 000,000,000 | —D | C] – C:\Users\Chameleon\Documents\Thief - Deadly Shadows
[2011/06/06 17:28:16 | 000,000,000 | —D | C] – C:\ProgramData\AIM
[2011/06/06 17:28:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIM
[2011/06/06 17:28:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\AIM
[2011/06/06 17:28:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Software Update Utility
[2011/06/03 17:52:36 | 000,000,000 | —D | C] – C:\ProgramData\Google
[2011/06/03 12:54:56 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Local\Real
[2011/06/03 12:53:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[2011/06/03 12:46:09 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Local\Google
[2011/06/03 12:45:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2011/05/30 13:06:47 | 000,033,856 | -H– | C] (LogMeIn, Inc.) – C:\Windows\SysNative\hamachi.sys
[2011/05/30 13:06:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2011/05/30 13:06:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn Hamachi
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/21 19:36:14 | 000,000,306 | —- | M] () – C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-3660194186-3126353062-2202063419-1000.job
[2011/06/21 17:13:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/21 17:10:00 | 000,000,426 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{306F3F19-2941-4C0D-81FA-6F323DC8EEBE}.job
[2011/06/21 17:09:10 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/21 17:09:09 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/21 13:31:23 | 001,309,375 | —- | M] () – C:\Users\Chameleon\Desktop\tdsskiller.zip
[2011/06/21 13:15:32 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/06/21 13:09:16 | 000,045,056 | —- | M] () – C:\Windows\SysNative\acovcnt.exe
[2011/06/20 17:24:27 | 000,008,592 | —- | M] () – C:\Users\Chameleon\AppData\Local\d3d9caps.dat
[2011/06/20 03:27:07 | 000,104,448 | —- | M] () – C:\Users\Chameleon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/19 00:08:41 | 000,001,002 | —- | M] () – C:\Users\Chameleon\Desktop\tMod.lnk
[2011/06/18 23:34:03 | 000,000,221 | —- | M] () – C:\Users\Chameleon\Desktop\Global Agenda.url
[2011/06/18 17:46:55 | 026,836,992 | —- | M] () – C:\Users\Chameleon\Documents\Produce.mpg
[2011/06/16 22:54:34 | 000,322,552 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/16 12:14:30 | 000,754,836 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/16 12:14:30 | 000,640,344 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/16 12:14:30 | 000,118,564 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/16 01:23:11 | 000,000,221 | —- | M] () – C:\Users\Chameleon\Desktop\Spiral Knights.url
[2011/06/15 15:25:24 | 000,002,861 | —- | M] () – C:\Users\Chameleon\Desktop\nwcreport.php.htm
[2011/06/13 16:50:11 | 000,000,996 | —- | M] () – C:\Users\Chameleon\Application Data\Microsoft\Internet Explorer\Quick Launch\Smart Defrag 2.lnk
[2011/06/13 16:50:11 | 000,000,972 | —- | M] () – C:\Users\Public\Desktop\Smart Defrag 2.lnk
[2011/06/13 16:49:37 | 000,000,982 | —- | M] () – C:\Users\Chameleon\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk
[2011/06/13 16:49:37 | 000,000,970 | —- | M] () – C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2011/06/13 16:49:37 | 000,000,958 | —- | M] () – C:\Users\Public\Desktop\Game Booster.lnk
[2011/06/10 01:39:02 | 000,001,890 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/06/09 21:22:44 | 009,745,558 | —- | M] () – C:\Users\Chameleon\Documents\Chronotorious - 03 Rockin' On Heaven's Door.mp3
[2011/06/09 21:21:14 | 007,052,646 | —- | M] () – C:\Users\Chameleon\Documents\Chronotorious - 03 Rockin' On Heaven's Door.flv
[2011/06/09 11:47:17 | 015,207,576 | —- | M] () – C:\Users\Chameleon\Documents\Dissidia 012 Duodecim Final Fantasy_ Prishe Full Voice Data.mp3
[2011/06/09 11:44:45 | 022,083,652 | —- | M] () – C:\Users\Chameleon\Documents\Dissidia 012 Duodecim Final Fantasy_ Prishe Full Voice Data.flv
[2011/06/08 15:05:13 | 000,000,763 | —- | M] () – C:\Users\Public\Desktop\osu!.lnk
[2011/06/07 00:06:43 | 000,000,220 | —- | M] () – C:\Users\Chameleon\Desktop\Thief Deadly Shadows.url
[2011/06/06 19:43:07 | 006,351,767 | —- | M] () – C:\Users\Chameleon\Documents\mulan -I'll make a man out of you lyrics.mp3
[2011/06/06 19:39:14 | 009,630,680 | —- | M] () – C:\Users\Chameleon\Documents\mulan -I'll make a man out of you lyrics.flv
[2011/06/06 17:28:46 | 000,000,738 | -H– | M] () – C:\IPH.PH
[2011/06/06 17:28:15 | 000,001,717 | —- | M] () – C:\Users\Public\Desktop\AIM.lnk
[2011/06/06 12:13:07 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/06/04 19:34:21 | 008,690,327 | —- | M] () – C:\Users\Chameleon\Documents\Mulan _I'll Make a Man Out of You_ (English) No intro.mp3
[2011/06/03 12:53:55 | 000,000,877 | —- | M] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/06/03 12:52:47 | 000,198,848 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\rmoc3260.dll
[2011/06/03 12:52:09 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5032.dll
[2011/06/03 12:52:08 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5016.dll
[2011/06/03 12:52:04 | 000,272,896 | —- | M] (Progressive Networks) – C:\Windows\SysWow64\pncrt.dll
[2011/06/03 12:51:58 | 000,499,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp71.dll
[2011/06/03 12:51:58 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71.dll
[2011/06/02 13:32:00 | 000,001,190 | —- | M] () – C:\Users\Chameleon\Desktop\TerrariaServer - Shortcut.lnk
[2011/06/01 02:26:29 | 031,068,233 | —- | M] () – C:\Users\Chameleon\Documents\Mulan _I'll Make a Man Out of You_ (English) No intro.mp4
[2011/06/01 00:04:10 | 016,305,686 | —- | M] () – C:\Users\Chameleon\Documents\Mulan _I'll Make a Man Out of You_ (English) No intro.flv
[2011/05/31 00:38:28 | 000,000,219 | —- | M] () – C:\Users\Chameleon\Desktop\Portal 2.url
[2011/05/31 00:17:01 | 048,816,129 | —- | M] () – C:\Users\Chameleon\Documents\No More Heroes - Dr. Peace (CUT SCENES) - Rank 9.flv
[2011/05/30 22:50:02 | 000,000,221 | —- | M] () – C:\Users\Chameleon\Desktop\The Witcher 2 - Bonus Content.url
[2011/05/30 13:06:36 | 000,000,804 | —- | M] () – C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
[2011/05/29 22:28:28 | 005,682,493 | —- | M] () – C:\Users\Chameleon\Documents\Cows Mooing.flv
[2011/05/28 01:26:33 | 000,243,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/05/28 01:24:36 | 000,096,768 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/05/28 01:24:33 | 000,710,656 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/05/28 01:24:04 | 000,056,832 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/05/28 01:23:47 | 001,538,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/05/28 01:23:30 | 000,219,136 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/05/28 01:23:30 | 000,132,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/05/28 01:23:29 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/05/28 01:23:29 | 000,072,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/05/28 01:23:28 | 000,252,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/05/28 01:07:19 | 000,206,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/05/28 01:04:59 | 000,066,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/05/28 01:04:56 | 000,602,112 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/05/28 01:04:30 | 000,043,520 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/05/28 01:04:17 | 001,469,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/05/28 01:04:03 | 000,164,352 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/05/28 01:04:03 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/05/28 01:04:03 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/05/28 01:04:02 | 000,184,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/05/28 01:04:02 | 000,055,808 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/05/28 00:33:37 | 000,479,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/05/28 00:10:26 | 000,385,024 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/05/27 23:53:37 | 000,162,816 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/05/27 23:53:19 | 000,070,656 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/05/27 23:52:45 | 000,012,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/05/27 23:33:03 | 000,133,632 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/05/27 23:32:51 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/05/27 23:32:15 | 000,013,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/21 13:31:19 | 001,309,375 | —- | C] () – C:\Users\Chameleon\Desktop\tdsskiller.zip
[2011/06/21 12:46:50 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/06/21 12:46:50 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/06/21 12:46:50 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/06/21 12:46:50 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/06/21 12:46:50 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/06/20 16:11:02 | 000,000,306 | —- | C] () – C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-3660194186-3126353062-2202063419-1000.job
[2011/06/19 00:08:41 | 000,001,002 | —- | C] () – C:\Users\Chameleon\Desktop\tMod.lnk
[2011/06/18 23:34:03 | 000,000,221 | —- | C] () – C:\Users\Chameleon\Desktop\Global Agenda.url
[2011/06/18 17:45:46 | 026,836,992 | —- | C] () – C:\Users\Chameleon\Documents\Produce.mpg
[2011/06/16 01:47:08 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat
[2011/06/16 01:23:11 | 000,000,221 | —- | C] () – C:\Users\Chameleon\Desktop\Spiral Knights.url
[2011/06/15 15:25:20 | 000,002,861 | —- | C] () – C:\Users\Chameleon\Desktop\nwcreport.php.htm
[2011/06/13 16:50:13 | 000,032,648 | —- | C] () – C:\Windows\SysNative\SmartDefragBootTime.exe
[2011/06/13 16:50:13 | 000,018,232 | —- | C] () – C:\Windows\SysNative\drivers\SmartDefragDriver.sys
[2011/06/13 16:50:11 | 000,000,996 | —- | C] () – C:\Users\Chameleon\Application Data\Microsoft\Internet Explorer\Quick Launch\Smart Defrag 2.lnk
[2011/06/13 16:50:11 | 000,000,972 | —- | C] () – C:\Users\Public\Desktop\Smart Defrag 2.lnk
[2011/06/13 16:49:37 | 000,000,982 | —- | C] () – C:\Users\Chameleon\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk
[2011/06/13 16:49:37 | 000,000,970 | —- | C] () – C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2011/06/13 16:49:37 | 000,000,958 | —- | C] () – C:\Users\Public\Desktop\Game Booster.lnk
[2011/06/10 01:39:02 | 000,001,890 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2011/06/09 21:22:14 | 009,745,558 | —- | C] () – C:\Users\Chameleon\Documents\Chronotorious - 03 Rockin' On Heaven's Door.mp3
[2011/06/09 21:21:14 | 007,052,646 | —- | C] () – C:\Users\Chameleon\Documents\Chronotorious - 03 Rockin' On Heaven's Door.flv
[2011/06/09 11:46:45 | 015,207,576 | —- | C] () – C:\Users\Chameleon\Documents\Dissidia 012 Duodecim Final Fantasy_ Prishe Full Voice Data.mp3
[2011/06/09 11:44:44 | 022,083,652 | —- | C] () – C:\Users\Chameleon\Documents\Dissidia 012 Duodecim Final Fantasy_ Prishe Full Voice Data.flv
[2011/06/08 15:05:13 | 000,000,763 | —- | C] () – C:\Users\Public\Desktop\osu!.lnk
[2011/06/07 00:06:43 | 000,000,220 | —- | C] () – C:\Users\Chameleon\Desktop\Thief Deadly Shadows.url
[2011/06/06 19:42:45 | 006,351,767 | —- | C] () – C:\Users\Chameleon\Documents\mulan -I'll make a man out of you lyrics.mp3
[2011/06/06 19:39:13 | 009,630,680 | —- | C] () – C:\Users\Chameleon\Documents\mulan -I'll make a man out of you lyrics.flv
[2011/06/06 17:28:15 | 000,001,717 | —- | C] () – C:\Users\Public\Desktop\AIM.lnk
[2011/06/04 19:33:45 | 008,690,327 | —- | C] () – C:\Users\Chameleon\Documents\Mulan _I'll Make a Man Out of You_ (English) No intro.mp3
[2011/06/03 12:53:55 | 000,000,877 | —- | C] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/06/02 13:32:00 | 000,001,190 | —- | C] () – C:\Users\Chameleon\Desktop\TerrariaServer - Shortcut.lnk
[2011/06/01 02:23:45 | 031,068,233 | —- | C] () – C:\Users\Chameleon\Documents\Mulan _I'll Make a Man Out of You_ (English) No intro.mp4
[2011/06/01 00:04:08 | 016,305,686 | —- | C] () – C:\Users\Chameleon\Documents\Mulan _I'll Make a Man Out of You_ (English) No intro.flv
[2011/05/31 00:38:28 | 000,000,219 | —- | C] () – C:\Users\Chameleon\Desktop\Portal 2.url
[2011/05/31 00:16:57 | 048,816,129 | —- | C] () – C:\Users\Chameleon\Documents\No More Heroes - Dr. Peace (CUT SCENES) - Rank 9.flv
[2011/05/30 22:50:02 | 000,000,221 | —- | C] () – C:\Users\Chameleon\Desktop\The Witcher 2 - Bonus Content.url
[2011/05/30 13:06:36 | 000,000,804 | —- | C] () – C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
[2011/05/29 22:28:26 | 005,682,493 | —- | C] () – C:\Users\Chameleon\Documents\Cows Mooing.flv
[2011/05/18 22:46:28 | 000,750,254 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/10 21:15:02 | 000,139,128 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011/05/03 18:38:43 | 000,090,112 | —- | C] () – C:\Windows\lol.launcher.exe
[2011/05/03 18:38:43 | 000,090,112 | —- | C] () – C:\Windows\lol.launcher.admin.exe
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/01/10 22:42:21 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/03/09 08:20:38 | 000,270,904 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2010/03/09 08:20:37 | 002,434,856 | —- | C] () – C:\Windows\SysWow64\pbsvc_bc2.exe
[2010/03/09 08:20:37 | 000,075,136 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2010/02/28 16:20:55 | 000,157,407 | —- | C] () – C:\Windows\hpoins27.dat
[2010/02/28 16:20:55 | 000,000,932 | —- | C] () – C:\Windows\hpomdl27.dat
[2009/11/15 14:47:56 | 000,000,268 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/10/20 22:27:29 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/10/20 22:26:51 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/10/20 22:26:13 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/10/13 06:56:12 | 000,001,460 | —- | C] () – C:\Users\Chameleon\AppData\Local\d3d9caps64.dat
[2009/10/13 06:56:09 | 000,008,592 | —- | C] () – C:\Users\Chameleon\AppData\Local\d3d9caps.dat
[2009/10/13 06:56:08 | 000,000,552 | —- | C] () – C:\Users\Chameleon\AppData\Local\d3d8caps.dat
[2009/10/11 21:22:45 | 000,104,448 | —- | C] () – C:\Users\Chameleon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/13 11:43:30 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/09/10 22:05:48 | 000,027,648 | —- | C] () – C:\Windows\SysWow64\AVSredirect.dll
[2009/08/11 20:22:49 | 000,033,136 | —- | C] () – C:\Windows\ASScrPro.exe
[2009/08/11 20:22:29 | 000,047,672 | —- | C] () – C:\Windows\AsScrProlog.exe
[2009/08/11 19:25:00 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/10/08 22:38:27 | 000,015,497 | —- | C] () – C:\Windows\snp2uvc.ini
[2008/09/19 06:41:00 | 000,000,010 | —- | C] () – C:\Windows\SysWow64\ABLKSR.ini
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2007/08/06 12:18:31 | 000,081,920 | —- | C] () – C:\Windows\PGMonitor.exe
[2006/11/02 10:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 07:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 07:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 04:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
========== LOP Check ==========
[2011/06/09 14:14:48 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\.minecraft
[2009/09/10 20:44:24 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\acccore
[2010/05/15 03:07:45 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Beat Hazard
[2010/01/24 16:33:04 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Bioshock
[2010/03/18 23:04:39 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Bioshock2
[2010/03/25 18:43:24 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\cYo
[2011/06/08 15:03:38 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Downloaded Installations
[2010/01/31 17:55:31 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\GetRightToGo
[2011/06/13 16:50:14 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\IObit
[2010/11/25 01:01:16 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\JAM Software
[2010/05/11 16:02:20 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\LolClient
[2009/12/05 00:44:59 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\MotioninJoy
[2010/04/25 14:10:00 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Mount&Blade;
[2010/04/25 18:11:26 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Mount&Blade; Warband
[2011/05/04 19:16:16 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Mount&Blade; With Fire and Sword
[2011/03/22 20:54:57 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Mumble
[2009/10/21 09:49:32 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\OpenOffice.org
[2011/02/25 02:11:04 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Rift
[2011/01/20 00:11:43 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\runic games
[2010/12/12 02:35:14 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\SEGA Corporation
[2010/11/22 12:57:15 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\storytron
[2011/03/26 17:31:13 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\SystemRequirementsLab
[2011/06/18 23:38:33 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\TerrariaMod
[2011/06/09 23:37:58 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\TerrariaWorldViewer
[2011/03/11 17:07:05 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\The Creative Assembly
[2011/06/16 00:58:59 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\uTorrent
[2009/09/10 20:01:39 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\WinPatrol
[2011/04/25 18:09:32 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\XRay Engine
[2011/06/20 23:23:56 | 000,032,634 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/06/21 17:10:00 | 000,000,426 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{306F3F19-2941-4C0D-81FA-6F323DC8EEBE}.job
========== Purity Check ==========
========== Custom Scans ==========
< >
< %SYSTEMDRIVE%\*.* >
[2009/07/24 02:58:10 | 000,000,028 | —- | M] () – C:\addon.log
[2008/11/27 21:10:54 | 000,000,016 | —- | M] () – C:\app14.log
[2009/05/11 08:49:02 | 000,000,022 | —- | M] () – C:\app2.log
[2008/11/12 21:04:09 | 000,000,081 | —- | M] () – C:\app4.log
[2009/04/07 23:02:41 | 000,002,076 | —- | M] () – C:\ASUS_27140015.icm
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/09/18 09:01:40 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2011/06/21 13:25:03 | 000,021,113 | —- | M] () – C:\ComboFix.txt
[2009/08/11 20:36:36 | 000,018,483 | —- | M] () – C:\devlist.txt
[2009/06/23 01:28:11 | 000,000,027 | —- | M] () – C:\Driver.20
[2008/04/11 11:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2009/08/11 20:34:35 | 000,000,009 | —- | M] () – C:\Finish.log
[2009/05/27 01:02:07 | 001,048,576 | RH– | M] () – C:\G60VxAS.BIN
[2009/08/11 20:27:15 | 001,556,324 | —- | M] () – C:\if.log
[2009/09/25 20:56:04 | 000,087,616 | —- | M] () – C:\immacraaab_gs1444.vtf
[2009/08/11 20:12:57 | 023,789,568 | —- | M] () – C:\inject.log
[2009/08/11 20:12:57 | 023,065,984 | —- | M] () – C:\inject.log.txt
[2008/04/11 11:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2011/06/06 17:28:46 | 000,000,738 | -H– | M] () – C:\IPH.PH
[2008/09/19 06:33:21 | 000,000,003 | —- | M] () – C:\K522.txt
[2009/07/02 02:17:15 | 000,000,037 | —- | M] () – C:\Nero.Log
[2011/06/21 17:12:03 | 312,647,679 | -HS- | M] () – C:\pagefile.sys
[2009/08/11 07:29:03 | 000,000,146 | —- | M] () – C:\Pass.txt
[2009/06/19 07:10:05 | 000,003,502 | —- | M] () – C:\Patch.LOG
[2009/03/30 22:04:29 | 000,000,022 | —- | M] () – C:\RECOVERY.DAT
[2009/08/11 20:01:10 | 000,002,008 | —- | M] () – C:\RHDSetup.log
[2011/03/03 13:40:25 | 000,000,370 | —- | M] () – C:\rkill.log
[2009/08/11 20:03:00 | 000,000,209 | —- | M] () – C:\setup.log
[2008/09/19 06:43:09 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2008/09/19 06:43:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2006/05/13 11:22:24 | 000,000,005 | —- | M] () – C:\store.log
[2009/08/11 18:57:50 | 000,000,166 | —- | M] () – C:\SumHidd.txt
[2009/08/11 18:57:20 | 000,000,098 | —- | M] () – C:\SumOS.txt
[2011/06/21 13:32:27 | 000,063,472 | —- | M] () – C:\TDSSKiller.2.5.5.0_21.06.2011_13.31.56_log.txt
[2009/07/15 14:58:38 | 000,000,025 | —- | M] () – C:\v624.txt
[2009/05/20 21:44:34 | 000,000,043 | —- | M] () – C:\WindowsLive_US.TXT
< %systemroot%\Fonts\*.com >
[2006/11/02 10:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 10:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 10:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/11/05 20:39:10 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/05/10 07:10:59 | 000,040,112 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2008/12/05 00:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 22:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/03/08 23:52:40 | 000,000,355 | -HS- | M] () – C:\Users\Chameleon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/11/07 11:45:13 | 000,232,501 | —- | M] () – C:\Users\Chameleon\Desktop\Minecraft.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2008/10/08 22:38:27 | 000,013,022 | —- | M] () – C:\Windows\snp2uvc.src
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Files - Unicode (All) ==========
[2011/03/28 20:26:31 | 003,653,015 | —- | M] ()(C:\Users\Chameleon\Documents\God Eater OST - Strategy Briefing (???.mp3) – C:\Users\Chameleon\Documents\God Eater OST - Strategy Briefing (作戦会.mp3
[2011/03/28 20:26:04 | 003,653,015 | —- | C] ()(C:\Users\Chameleon\Documents\God Eater OST - Strategy Briefing (???.mp3) – C:\Users\Chameleon\Documents\God Eater OST - Strategy Briefing (作戦会.mp3
[2011/03/28 20:14:54 | 004,497,047 | —- | M] ()(C:\Users\Chameleon\Documents\God Eater OST- Howl of the Wolf (????).mp3) – C:\Users\Chameleon\Documents\God Eater OST- Howl of the Wolf (狼の咆哮).mp3
[2011/03/28 20:14:33 | 004,497,047 | —- | C] ()(C:\Users\Chameleon\Documents\God Eater OST- Howl of the Wolf (????).mp3) – C:\Users\Chameleon\Documents\God Eater OST- Howl of the Wolf (狼の咆哮).mp3
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\ProgramData\Temp:5C321E34
@Alternate Data Stream - 55920 bytes -> C:\ProgramData:$SS_DESCRIPTOR_LVVWVBGV0VFBTLX4D06YH7LVUTPXGJMBKE1R0WT1VH7E24F7PHCTVF4VMVFVV
X4VM
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
< End of report >
Extras.txt
OTL Extras logfile created on: 6/21/2011 7:36:20 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Chameleon\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 3.07 Gb Available Physical Memory | 76.71% Memory free
8.17 Gb Paging File | 7.41 Gb Available in Paging File | 90.69% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.40 Gb Total Space | 46.37 Gb Free Space | 16.25% Space Free | Partition Type: NTFS
Drive E: | 7.91 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 931.51 Gb Total Space | 359.20 Gb Free Space | 38.56% Space Free | Partition Type: NTFS
Drive G: | 539.19 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: CHA-PC | User Name: Chameleon | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html[@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
https [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
https [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 9F 60 A8 70 8B 5E CA 01 [binary data]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08E72EB3-DDC5-4DBD-8104-124C59E61ED4}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{1916AFF7-6C41-4756-9285-F2E70FC63A46}" = lport=6969 | protocol=17 | dir=in | name=league of legends launcher |
"{30DA7857-F82B-4DB0-9CBD-C29E980357FD}" = lport=6890 | protocol=17 | dir=in | name=league of legends launcher |
"{326434D4-BF6A-4D3A-AB2A-06C759D44666}" = lport=6894 | protocol=17 | dir=in | name=league of legends launcher |
"{34688267-5189-4AF1-BD57-DAE262D39E87}" = lport=6947 | protocol=6 | dir=in | name=league of legends launcher |
"{347FE30C-C97F-46C3-8124-25F4C686767E}" = lport=8383 | protocol=6 | dir=in | name=league of legends launcher |
"{35F40154-9CBD-4281-8518-D1690386B52C}" = lport=8393 | protocol=6 | dir=in | name=league of legends lobby |
"{3E0B742F-5A94-4062-9F64-D2D858E91828}" = lport=6922 | protocol=17 | dir=in | name=league of legends launcher |
"{483ECB82-7B0D-4631-AADE-4CBD7CBDF8F2}" = lport=6890 | protocol=6 | dir=in | name=league of legends launcher |
"{53C03845-7D79-487E-B139-EAD54F6AD370}" = lport=1778 | protocol=17 | dir=in | name=hava service |
"{54759F23-FE2E-4B70-A131-8CE0563BEB22}" = lport=6959 | protocol=17 | dir=in | name=league of legends launcher |
"{561DE3BA-56D0-43B1-A8FF-DA7E1148029D}" = lport=8381 | protocol=17 | dir=in | name=league of legends launcher |
"{6C369BDD-29A5-40C4-81BB-EB2BD8E0D509}" = lport=6947 | protocol=17 | dir=in | name=league of legends launcher |
"{6C6E0A06-BE10-43B6-83E6-6A0D20BB5D3F}" = lport=6910 | protocol=6 | dir=in | name=league of legends launcher |
"{6CF8D1CF-C084-4972-BCFD-DF53B33FAA95}" = lport=6922 | protocol=6 | dir=in | name=league of legends launcher |
"{6D5F3133-B569-4B2C-AB62-C83DE9A3123F}" = lport=6919 | protocol=6 | dir=in | name=league of legends launcher |
"{6EB17246-ECE4-4BE3-A489-7D3E51C26307}" = lport=8390 | protocol=17 | dir=in | name=league of legends game client |
"{6EBA713B-E0E8-4455-9B97-05A500BD9807}" = lport=2869 | protocol=6 | dir=in | app=system |
"{71F723ED-D79B-45C8-B4DC-24BDBE0FB326}" = lport=8379 | protocol=6 | dir=in | name=league of legends launcher |
"{76E07CA3-1921-471B-8476-0C0F9F1D90F5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{7C8F8C31-789A-474B-8466-884F8FBE19F1}" = lport=6910 | protocol=6 | dir=in | name=league of legends launcher |
"{802E4ED2-007A-432A-810C-924B012EF429}" = lport=8393 | protocol=17 | dir=in | name=league of legends lobby |
"{833BECE2-EA11-473F-865D-B9F7271F27BE}" = lport=8382 | protocol=6 | dir=in | name=league of legends launcher |
"{844A02A0-D4AE-442D-A5E6-B575D2DCF123}" = lport=8382 | protocol=17 | dir=in | name=league of legends launcher |
"{93CFDDFE-BD0C-45AE-826B-6AE69B2F41EE}" = lport=8382 | protocol=6 | dir=in | name=league of legends launcher |
"{957B2644-F24C-4A9E-A1AD-A3838AB97BA6}" = lport=6959 | protocol=6 | dir=in | name=league of legends launcher |
"{A3CDDDE6-3C1A-4484-8AC4-1AF0B5B54049}" = lport=6940 | protocol=17 | dir=in | name=league of legends launcher |
"{B7AFFBD6-0332-45FC-A4D3-5D6EEA2AF8EA}" = lport=8381 | protocol=6 | dir=in | name=league of legends launcher |
"{C73F74E9-1474-44E0-88CA-98B548625659}" = lport=6969 | protocol=6 | dir=in | name=league of legends launcher |
"{C8F21D5F-A1F9-4AC3-B6EB-23DA7CF9231E}" = lport=8383 | protocol=17 | dir=in | name=league of legends launcher |
"{C90CBA02-1409-4C6A-A690-25A8CBAA4F0B}" = lport=6940 | protocol=6 | dir=in | name=league of legends launcher |
"{DBEB6CF2-745A-4E19-AC5C-91D739BDD94D}" = lport=1900 | protocol=17 | dir=in | name=hava upnp udp service |
"{DD1F0A56-2586-4316-8E5F-60D724893CBF}" = lport=6910 | protocol=17 | dir=in | name=league of legends launcher |
"{E090F18B-C5D2-4063-A37C-3A5BA772CF3E}" = lport=8381 | protocol=6 | dir=in | name=league of legends launcher |
"{E0C69200-C589-441E-B01B-782C1A35DCAA}" = lport=6919 | protocol=17 | dir=in | name=league of legends launcher |
"{E3750D84-5977-40B3-8B2E-688075569A69}" = lport=8379 | protocol=17 | dir=in | name=league of legends launcher |
"{E62AB00A-80AF-449E-9EE7-15CF20B9362B}" = lport=2869 | protocol=6 | dir=in | name=hava upnp tcp service |
"{EA276EE8-DDB1-48F4-A0FD-E058E5389182}" = lport=8382 | protocol=17 | dir=in | name=league of legends launcher |
"{EF6E647E-BDFE-440A-87CC-1D03691FDBDA}" = lport=8381 | protocol=17 | dir=in | name=league of legends launcher |
"{F3F61B47-88FF-49F7-A2C3-5E987F030EB2}" = lport=6910 | protocol=17 | dir=in | name=league of legends launcher |
"{FE25361D-CB6B-4D2F-A9A8-0455EFE6DC8C}" = lport=6894 | protocol=6 | dir=in | name=league of legends launcher |
"{FF2A0017-E153-4571-BA03-DC0645974519}" = lport=8390 | protocol=6 | dir=in | name=league of legends game client |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{001964FC-66D7-48A5-8CE8-171BA511072B}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{001DC0DB-A04C-40D3-A5F3-B3D991ED6AB3}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{009FA32C-7CF4-44E5-84AF-40C14E003968}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\launcher.exe |
"{0299C55D-A463-4747-97BD-F707F95C9DC5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alpha protocol\aplauncher.exe |
"{0496557F-33DF-4585-B9F0-4BB14D4A180E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{04ACF575-8A4C-443F-8A76-0C3E9FFDEF86}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{06BD72C9-123F-4985-8990-3833536D6145}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{075A764B-0C37-4EF7-9AFF-15D8ADDA0427}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alpha protocol\aplauncher.exe |
"{0865D3CF-1660-461A-BFAD-5A0C8E474817}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\crysis 2 - demo\bin32\crysis2demo.exe |
"{0EE837DA-005A-402A-B986-0CFE80DDDEBA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\launcher.exe |
"{0F52DFE0-0775-46DC-A586-64A21C7AB1D2}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{1285359D-D7D3-4791-9E26-98D1A5BC81D6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brink\brink.exe |
"{12A1322E-EBDE-4CB8-8E46-070C57DC6E05}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fear ultimate shooter edition\fear.exe |
"{138C9F4A-836C-4400-876B-75C3BBC98AC5}" = protocol=6 | dir=in | app=c:\windows\lol.launcher.exe |
"{14C0086F-FFD4-4272-A599-BD63216D766D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fear ultimate shooter edition\fear.exe |
"{14FDF285-E9FB-4761-B6D8-2A5C690A7CD9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |
"{16029DAA-FF2D-4A6A-8A4F-70428B0A3DD3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction guerrilla\rfg_launcher.exe |
"{1A13C35C-CA68-4B13-AAD8-1E8D8CD06F17}" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{1C90953C-4138-4837-96E5-273E34CCF111}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief deadly shadows\system\runme.exe |
"{1CF1F912-F7D9-4597-8B5E-FA2B8A0F859F}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{1FBB3798-4033-486F-99FD-5908A05606FD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lead and gold gangs of the wild west\lag_win32_public_dev.exe |
"{20F6D83D-5446-46B6-AC52-68CD5257BDA2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
"{216973AD-A1C6-42BE-AD4C-45F061567C98}" = protocol=6 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{25B6424C-9CBD-4551-95F9-501CFDB204A4}" = protocol=17 | dir=in | app=c:\windows\game\league of legends.exe |
"{25E0E730-1590-4A7F-BD65-C6AA3FFCE3A6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{26A50C08-AB35-4AB9-809E-00CB22CA82FF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead rising 2\deadrising2.exe |
"{26DDD45C-0DBB-4C3A-84CF-E180204F8846}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe |
"{2724F4CB-4E80-4A34-A97E-2B687F4D7BFD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{2761BAC8-43CE-4EC7-8288-45AF19E849F8}" = protocol=17 | dir=in | app=c:\windows\game\league of legends.exe |
"{2A52A791-67C2-4495-81BE-062569F8C8ED}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{2C410537-3101-45E4-B6D7-E033B75D298F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\just cause 2\justcause2.exe |
"{2C826D4F-87A5-4ED8-91EA-3A05C4148313}" = protocol=6 | dir=in | app=c:\windows\air\lolclient.exe |
"{2CECEAE0-2018-456B-A6C9-C16417637323}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe |
"{2E3403DA-5962-4015-B4A1-673B7BAD1745}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout 3\falloutlauncher.exe |
"{3064AE63-A38E-4C59-9576-75F225874760}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swkotor\swkotor.exe |
"{3073447A-BB19-4A2A-8C91-5BB77FF94ADC}" = protocol=17 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
"{3236F9E8-65B8-41EC-B411-B902655FD46A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |
"{3374FFE6-5BA3-447D-97F5-119D3381963B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\total war shogun 2 demo\shogun2.exe |
"{360C2891-A655-4E1D-8D81-17139EC071E4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\help.htm |
"{38E90E57-67E0-45F2-85F8-8C7F1912D1A9}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{394FEAF7-F9C4-4978-9794-2AA410F2A772}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brink\brink.exe |
"{3D401BDF-A4B5-4AB4-9266-7D3EFDDCC4F2}" = protocol=6 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{3F8ACB7C-04DA-4F79-8E27-92B80C4C38A9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
"{486D611B-F429-431E-8CE2-92DAFB2FBA86}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{4A1EE20F-8194-4677-9892-B32FEEFE1805}" = protocol=17 | dir=in | app=c:\windows\air\lolclient.exe |
"{4BE47254-4EEB-4094-8E9C-F12C433273E2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mount & blade with fire and sword\mb_wfas.exe |
"{4BFDDC24-FF9B-49D3-BC5B-EDDC2FE9226D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{4CB660D6-267E-42D3-A557-30EE6DF5B922}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\globalagenda.exe |
"{4DEAFC76-2B80-4A84-BF28-AD7868C40ECD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\globalagenda.exe |
"{4FBEA574-5325-4A75-876F-02F7093BAA53}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\launcher.exe |
"{5115A506-EA85-4E0C-BD38-E6A44C37376B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\total war shogun 2 demo\shogun2.exe |
"{5882EFC3-005E-4258-BAFE-8E7378994BC5}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{58CD2D93-C554-48CA-B7B1-84AA989011D5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction guerrilla\rfg_launcher.exe |
"{5A0664FB-43A9-44A2-B8D1-8CACC7575832}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\dead space.exe |
"{5F7A9BA9-7971-42E4-A94A-D91B3B44F339}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\binaries\masseffect.exe |
"{604558AE-CFC0-48B7-B012-8DED35415D54}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe |
"{61A1F245-B196-4970-94FF-E0CA120CDF9F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{64F5EA8A-72D4-4A9F-BAA2-3FA2CCF523C3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\bmlauncher.exe |
"{661AFF46-2EDB-4706-A91B-5E888CA72691}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\djinni!.exe |
"{678B2DC7-5E17-435D-B4EA-7E907787AD82}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{6B862157-8058-4517-A44B-A3EC69518448}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\launcher.exe |
"{6CC0958F-14CD-45C2-99A3-696915D3BD0D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock\builds\release\bioshock.exe |
"{6DC7F18E-04F3-4A14-B0DA-D2F3703243DD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{6F66EFBB-0075-4E65-BBC9-85996732AEB3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\just cause 2\justcause2.exe |
"{708E5B8D-804C-4375-997A-29FB09E270C2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\crysis 2 - demo\bin32\crysis2demo.exe |
"{70B3FE43-EA2F-4181-B7BE-383F60F1FB5F}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{71B76490-6D9E-4920-B15F-FDAFEF50F8DA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brink\brink.exe |
"{73A3CAEE-DB40-4571-AF00-873864FDEFF1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{748A73BB-8DBC-4BBA-82EB-5C7247AC1F3C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{76713048-8981-4DAC-B5B9-4EE4B0B69E3D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iv beyond the sword\beyond the sword\civ4beyondsword.exe |
"{76CE4320-9867-486F-B3A7-213EC56500FE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{78CC49E2-BDB0-4481-95B1-1F15FF167DD0}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{7AED2ACA-253E-464C-B3B7-C5D424744D4A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |
"{7B51A294-42F0-4077-965B-EBC0DE48A091}" = protocol=17 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{7D3BF2F5-CE2C-4B26-921C-BA6F80A32B97}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
"{7F6BC6BE-E901-4D88-8827-DFB85A635FFB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fear ultimate shooter edition\fearxp2\fearxp2.exe |
"{7FC18DF3-53BA-46E4-905C-B099FBBCC5DC}" = protocol=6 | dir=in | app=c:\windows\game\league of legends.exe |
"{7FCAE4F5-5768-4E25-84F1-3837B195E9AE}" = protocol=6 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"{804669C9-CBF0-467F-B978-0EB49A670353}" = protocol=6 | dir=in | app=c:\windows\game\league of legends.exe |
"{81243262-C671-4BEF-9B37-5C8EFC0B3A5A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"{816C78E8-1342-4D52-9BB9-64D206855A19}" = protocol=17 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{83914562-F010-4F2A-80EF-F1F82C4C5494}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\launcher.exe |
"{83FECF65-DDA6-4C99-938A-465E5EF1570A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iv\civilization4.exe |
"{85549A6A-51F9-4AB7-881C-309AB9E371A2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\dead space.exe |
"{85ACDFBB-6B94-4963-B36A-D2968D949711}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{86EAA61E-29F3-4437-8758-953BCBD8DC2C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mountblade warband\mb_warband.exe |
"{8824565B-6E6E-44CF-BB7E-658129AC3E74}" = protocol=6 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{8A427AFB-F139-446B-9C3A-2FE1A72F0E64}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"{8A8849EB-B591-4A46-8198-8B10AA891B6E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex\system\deusex.exe |
"{8C0E4E17-6968-4F13-A620-A7F12943B1C3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rift\riftpatchlive.exe |
"{8C5465A8-98B3-4F45-8767-729171FA4F6D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{8EAEB658-202E-4EC8-9D4F-E3DA83149862}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{900F0C75-4552-4670-8609-1F79F407CDCE}" = protocol=17 | dir=in | app=c:\windows\air\lolclient.exe |
"{923749DC-538B-43C6-932A-3F6D6884E6B2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{924FE9AC-52A0-4C5E-A5D6-AD8C504C8DBE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's pirates!\pirates!.exe |
"{941C774D-FFCA-49D8-A78B-A121CAA2E54B}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{94E16FEC-9385-4F0D-8254-5A006C53C326}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{979AAE3A-6D8D-46AC-8AB5-26F40CCAB37D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{98F49112-2081-4A97-9CBB-2654535FBFEB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rift\riftpatchlive.exe |
"{99078532-D8D9-4C65-844C-FFA866AF423F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{9995F195-AB11-4087-81F3-7E12A4F4BA55}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\bonuscontent\launch.bat |
"{9C1E16B1-7C94-432E-AA6F-33ACD9E700D1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead rising 2\deadrising2.exe |
"{9CE096AD-2D55-4F32-8A9C-6534514D84D5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iv beyond the sword\beyond the sword\civ4beyondsword.exe |
"{9F8ADEF7-B4F7-4354-AA74-DE5D7A7BF840}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mount & blade with fire and sword\mb_wfas.exe |
"{A04BAFFB-EC90-469E-B477-A1C0F517C662}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{A0CFC9C1-A5D2-4C72-9AD9-548062C0F05B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{A71CE0C7-FE87-4AA3-89EF-C55CC0CFB03B}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{AA056A07-4F8C-491B-8054-64A6D01FE24E}" = protocol=17 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{AAE2C869-7CD7-4924-AA41-F3937F5FCC4B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{AB6C5EBB-D68B-44FB-B9EF-DF7DF34C939B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex\system\deusex.exe |
"{AE01CC64-FA8B-4213-942F-0F1B6C857B7B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |
"{AE1FCA29-F2F7-4DF0-9B37-E37A45F0EAA7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{AE243AF2-DFD7-4C0E-AD2D-F9CC60DEEC47}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{AE281F3B-5E12-4815-A48B-FC1503DC6C10}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock\builds\release\bioshock.exe |
"{AE9FC146-F51F-41A7-8CC6-A1EEDE5CC7A9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{B25E878C-FC7C-46C2-BD12-8321BF56E00D}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{B33CE3B7-08A1-4971-96AC-BAB0572E4B8E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{B4070CE4-D13A-4D5E-A63D-265A1A4283BA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout 3\falloutlauncher.exe |
"{B6135776-06C5-429D-8101-69906BC407C8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lead and gold gangs of the wild west\lag_win32_public_dev.exe |
"{B8E601F4-C3AA-4693-A1CD-B81C25268E18}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mountblade warband\mb_warband.exe |
"{B9CFA702-41AE-468D-A65E-32DFBBDF169D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\binaries\masseffect.exe |
"{BA520CEF-872F-4F10-86BB-D2B1039EED74}" = protocol=6 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{BAB3B2C7-7AF1-4CBA-BE0E-F6E8612658CB}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base16755\sc2.exe |
"{BC54265A-6CC6-40C7-8658-DB7AE7D9AA9C}" = protocol=17 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"{BC86F908-261C-405D-B231-069613C6C44E}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{BE47BE6E-2582-432F-9B10-432EAD334F1A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brink\brink.exe |
"{BE6520CA-F130-44D2-AB77-5E7DEA613ACE}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{BF54D443-FE53-4A4D-83A6-64728DABAC90}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{C078DF96-DA02-4E94-91FE-B7744B823F58}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iv beyond the sword\beyond the sword\civ4beyondsword.exe |
"{C1CEA4AF-BE88-4EE6-87A0-BB8ED120DA45}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\help.htm |
"{C50ACF01-7B2B-4BD4-882B-3008E588ED25}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\counter-strike source\hl2.exe |
"{C5633F80-CF3B-41ED-9D7D-25E5427D12CA}" = protocol=17 | dir=in | app=c:\windows\lol.launcher.exe |
"{C904D985-97F9-4B27-AE56-2203AAD90802}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iv\civilization4.exe |
"{CE2958C8-9EE1-463D-92D5-6F94B879EF1F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\globalagenda.exe |
"{CE9F688A-3E92-473C-8981-F2E163488D64}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fear ultimate shooter edition\fearxp2\fearxp2.exe |
"{CF2142F2-4FE8-4A05-9DA9-D18CEF867A9C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\monday night combat\binaries\win32\mnc.exe |
"{CF56036B-B8D8-4237-8CBA-C7FBA687F0E3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\monday night combat\binaries\win32\mnc.exe |
"{D0E1D89D-817F-45BA-927D-31E8E695C57F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\djinni!.exe |
"{D3229D39-F86E-422E-AE9F-DA83C7501516}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\launcher.exe |
"{D3C9B251-FAAE-470A-9FD1-7B425D48618A}" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{D3DDF78E-9BFE-4FE0-944C-B0FA541FFCEC}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{D5D9176E-F582-46CA-9F7C-5A56DBD53D0E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\bmlauncher.exe |
"{D774BCEE-5D85-41D7-9682-01B1C23E1293}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{D81E5CE0-0353-43D5-B90F-BAB8E1D06224}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{DC57E94D-39D0-483D-A748-B371D9782D82}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{DD1D07D7-C063-494F-8CAB-0E00BA002D82}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\witcher.exe |
"{DD335C26-EE38-4810-A82F-89AB14E73FBB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's pirates!\pirates!.exe |
"{DD367EBA-89BE-4406-901C-844E825BCA4E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
"{DDEE983D-120B-4113-9462-892C85AA0CBB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{E0D57ECA-775E-4C10-8BCC-EDAE9535E9A1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swkotor\swkotor.exe |
"{E36C02DC-922E-4F0B-9D24-231D0027F40D}" = protocol=17 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{E792FCC1-3CCE-47FF-B07F-9A13F3EAE772}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base16755\sc2.exe |
"{E813A8FA-65D9-4A8E-9C74-4C1E0A669C90}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{E8D69578-3689-4822-9F85-76F66A3685EC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E91EDA45-93D8-46A7-B37F-DA9FD35B9158}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\witcher.exe |
"{E970D097-21B0-4D83-9BC3-F176130F810B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe |
"{E9BA4055-140B-4073-B724-109AC3582A6A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{E9C6EC3A-7ABD-4D31-A397-4DBB5D350285}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{EB8B422A-06D6-457A-B599-61701C67FF0D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief deadly shadows\system\runme.exe |
"{EEC3055F-9FA2-41A9-9110-809DB96F02B0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{EFE49E39-670C-4375-BD5F-1EEA583B7EAA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard demo\beathazarddemo.exe |
"{F1D7389B-C6B0-4C2B-81F6-28C11E194252}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{F31940F9-A64B-485D-981B-526C56271B75}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\counter-strike source\hl2.exe |
"{F3A5EFED-45C2-4048-8856-B13A641EC8B2}" = protocol=6 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
"{F3BB7A1B-0B9A-45CA-82F6-E860DC094CB3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swkotor\swkotor.exe |
"{F3D2E59F-CE61-4AC1-8E11-5873C6CFCC6A}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{F7F1B830-7F4F-4177-ADD5-7AB60E5344CC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{F7F9DB58-31EF-4418-9476-50133F4C7EBB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{F8C3B869-01E3-4C46-BD87-7CF297CB7F5B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard demo\beathazarddemo.exe |
"{F97805F8-8353-4E2C-832E-294E81694BD8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iv beyond the sword\beyond the sword\civ4beyondsword.exe |
"{FCC57F12-795D-49A6-B109-AE5BB68DE93F}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{FD74C1FC-26CC-4423-8162-DADA7159D068}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\bonuscontent\launch.bat |
"{FE0E4DC8-B4C3-49B0-B2D8-41FFC7E5C6BA}" = protocol=6 | dir=in | app=c:\windows\air\lolclient.exe |
"{FE1FD12C-C8DE-4E59-80BA-A740CAB5961F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\globalagenda.exe |
"{FFE602FA-0A93-49F3-B8DC-E3A087D1414B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swkotor\swkotor.exe |
"TCP Query User{034734D8-A4A2-4C95-B14C-D2A829F5316D}C:\program files (x86)\squareenix\final fantasy xiv\ffxivboot.exe" = protocol=6 | dir=in | app=c:\program files (x86)\squareenix\final fantasy xiv\ffxivboot.exe |
"TCP Query User{04345BF4-AD0E-48D7-8ABB-E41D56620EE2}C:\program files (x86)\interplay\fallout tactics\bos.exe" = protocol=6 | dir=in | app=c:\program files (x86)\interplay\fallout tactics\bos.exe |
"TCP Query User{09240C58-F6E9-420D-BAD3-CFC8B53AF139}C:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe |
"TCP Query User{11611FC8-9064-433B-BA11-48E014087AF4}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe |
"TCP Query User{165E8561-F04F-4A0A-AF05-2991825E8DE6}C:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
"TCP Query User{1A4BBEBB-5CCD-41B5-A91D-AE7A82E3D17A}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe |
"TCP Query User{1E640592-3A4B-4D9E-87B5-7CA4EA43E8B3}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe |
"TCP Query User{1E8C893F-5E11-45D2-BE86-1FB3BCB81A3A}C:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe |
"TCP Query User{1FE13BB2-F89D-4DC8-8A82-87EF6C7D34A7}C:\program files (x86)\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
"TCP Query User{2ACD3F63-5230-4404-AA34-5011413E59BA}C:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe |
"TCP Query User{355C47F1-A7D1-46F8-A907-F421494C1083}C:\users\chameleon\downloads\starcraft_2_na_en-us(2).exe" = protocol=6 | dir=in | app=c:\users\chameleon\downloads\starcraft_2_na_en-us(2).exe |
"TCP Query User{37B419B5-EB36-41E6-BCCE-4D6F5B3718C8}C:\program files (x86)\steam\steamapps\common\dead space 2\deadspace2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space 2\deadspace2.exe |
"TCP Query User{3F1A7609-E54E-4CFB-8174-CD6564D8D25D}C:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe |
"TCP Query User{405FAEF6-89A0-422A-8D4A-23A98142BC5B}C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe |
"TCP Query User{4072D61A-8F8B-4312-BC49-A3B5A23CFCA1}C:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
"TCP Query User{41D702F6-BCC1-4924-A59D-348AE61E05A9}C:\program files (x86)\starcraft ii\versions\base16939\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base16939\sc2.exe |
"TCP Query User{42C760C5-5E29-4391-AAD2-08ECF326A7DB}C:\users\chameleon\downloads\starcraft_2_na_en-us.exe" = protocol=6 | dir=in | app=c:\users\chameleon\downloads\starcraft_2_na_en-us.exe |
"TCP Query User{46AC67B7-AEE7-40FA-AA54-13BDD9500847}C:\program files\comicrack\comicrack.exe" = protocol=6 | dir=in | app=c:\program files\comicrack\comicrack.exe |
"TCP Query User{57C9789F-3752-46C1-A4C7-B284EF0BA03B}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe |
"TCP Query User{5F07BE8C-4E15-4A50-866A-F5CBF85EC8B1}C:\program files (x86)\steam\steamapps\ultima_weapon33\source 2007 dedicated server\srcds.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\source 2007 dedicated server\srcds.exe |
"TCP Query User{620AABCF-CD3B-4D4E-A420-1ACCC46E4868}C:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe |
"TCP Query User{623AB92A-2484-418D-9609-36B6AB54F9E2}C:\riot games\league of legends\lol.launcher.exe" = protocol=6 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"TCP Query User{62DE1CB2-FA5D-45B1-8E93-9F02ACCED88C}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"TCP Query User{6862131A-7F87-400C-9688-347E2EA8BE19}C:\program files (x86)\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mirc\mirc.exe |
"TCP Query User{705C1A76-BA47-4A8C-992C-7BB71E8F003A}C:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe |
"TCP Query User{70B37E55-DC04-4D4B-BBAE-6E234BDE5BA9}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe |
"TCP Query User{719F393E-67E5-4594-837F-16CB160774C4}C:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe |
"TCP Query User{73773757-73B7-42A0-ADDC-EB1FFC6F2BC2}C:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe |
"TCP Query User{7426683E-B084-4D94-A903-BFD2AE4E4DD0}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe |
"TCP Query User{7EF99E23-EF91-4809-BD79-F7EC141CA959}C:\program files (x86)\starcraft ii\versions\base18574\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18574\sc2.exe |
"TCP Query User{8C92ACBA-0571-4E42-A05B-BBCDDCDC66E2}C:\program files (x86)\steam\steamapps\common\altitude\altitude.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\altitude\altitude.exe |
"TCP Query User{8CF5BA9E-FF5D-4E35-B99F-BF0F3545617D}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"TCP Query User{95076591-2EFF-4A00-A602-AADB07427A86}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe |
"TCP Query User{A5991553-4329-4B2A-A0A2-1187777FAE32}C:\users\chameleon\downloads\starcraft_2_na_en-us.exe" = protocol=6 | dir=in | app=c:\users\chameleon\downloads\starcraft_2_na_en-us.exe |
"TCP Query User{A8EA534B-E708-4BAC-84E6-EFD0631C3E89}C:\program files\comicrack\comicrack.exe" = protocol=6 | dir=in | app=c:\program files\comicrack\comicrack.exe |
"TCP Query User{B59D4743-647F-4CF5-B448-853C20AA08EC}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"TCP Query User{BB1F3A9C-E811-4CA3-AFC1-5F0C6DCE1CCC}C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe |
"TCP Query User{BCDAAEC3-AE56-4CFB-A55C-C2DC2BC8EB6C}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe |
"TCP Query User{C1FB1E44-0031-49A8-A2B6-5CE08B7662C5}C:\program files (x86)\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
"TCP Query User{C2FBC567-E20F-4854-AC78-FEC2C1B4302E}C:\program files (x86)\steam\steam.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"TCP Query User{C77C1DC5-C2F7-4F11-90EE-46FB714801C0}C:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_c558aa83b9a650d4\tmod.exe" = protocol=6 | dir=in | app=c:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_c558aa83b9a650d4\tmod.exe |
"TCP Query User{C7C7459C-2FE6-4883-8580-371F4A65BCEA}C:\program files (x86)\steam\steamapps\common\altitude\altitude.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\altitude\altitude.exe |
"TCP Query User{CC423869-7D91-464C-9D29-85398EA84622}C:\riot games\league of legends\lol.launcher.exe" = protocol=6 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"TCP Query User{D86510C7-7BA3-44C5-B945-33925B693FF2}C:\program files (x86)\steam\steamapps\common\terraria\terraria.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"TCP Query User{DD8148BB-1FCA-48A8-922C-F1C4F15DD2F8}C:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx9.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx9.exe |
"TCP Query User{DFADF842-A1C7-4DDF-B92C-3CE86C3873AE}C:\program files (x86)\starcraft ii\versions\base16939\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base16939\sc2.exe |
"TCP Query User{E262ED6E-482C-456F-96F7-698797FADB57}C:\program files (x86)\aim6\aim6.exe" = protocol=6 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"TCP Query User{E41BF951-2A85-43F9-9D2B-7E8CF39BB627}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe |
"TCP Query User{EC928031-9708-42B3-B7AF-C9865F87A2CF}C:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe |
"TCP Query User{F128A92F-2A7B-48CE-8157-1A09987CD1DF}C:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe |
"TCP Query User{F781A091-9FEA-46C8-9D2E-CAD307A3A545}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"TCP Query User{F822738F-83EA-4E63-BF91-8510E64ECE6D}C:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_b6908e294fd27714\tmod.exe" = protocol=6 | dir=in | app=c:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_b6908e294fd27714\tmod.exe |
"TCP Query User{FF9A6101-D35E-4762-AA58-7C50AF5E4CD2}C:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe |
"UDP Query User{02E3C03A-685B-4763-8478-260082459DC3}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe |
"UDP Query User{030F09AF-99A7-4044-830D-870894741B19}C:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
"UDP Query User{057C4EEA-A677-47BE-99B9-858309800307}C:\users\chameleon\downloads\starcraft_2_na_en-us.exe" = protocol=17 | dir=in | app=c:\users\chameleon\downloads\starcraft_2_na_en-us.exe |
"UDP Query User{0FA57773-63C4-4CD4-B7E2-F7E0217D0D23}C:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
"UDP Query User{226FA98A-26C2-493E-9C99-296A9EF5ACB4}C:\program files (x86)\starcraft ii\versions\base18574\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18574\sc2.exe |
"UDP Query User{2BE02504-8783-4401-89D1-021250389438}C:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_c558aa83b9a650d4\tmod.exe" = protocol=17 | dir=in | app=c:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_c558aa83b9a650d4\tmod.exe |
"UDP Query User{2D8ABEAF-04BE-410E-9A79-BD4980A63142}C:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe |
"UDP Query User{30679C93-F085-4921-BA82-70BA24F321A2}C:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe |
"UDP Query User{31BD0710-8721-4D55-8C28-7B34018FDAF1}C:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe |
"UDP Query User{3F504F97-59EB-4DF2-AD97-4351C7E72D71}C:\users\chameleon\downloads\starcraft_2_na_en-us.exe" = protocol=17 | dir=in | app=c:\users\chameleon\downloads\starcraft_2_na_en-us.exe |
"UDP Query User{504801CB-BACA-4E11-B645-6F73C26D3457}C:\program files (x86)\starcraft ii\versions\base16939\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base16939\sc2.exe |
"UDP Query User{5827E479-268A-4B69-8593-44831B602541}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe |
"UDP Query User{5A56A753-542B-4DC0-9169-3F6FA8DDB6AC}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe |
"UDP Query User{6642B495-0ECE-4641-BB75-9F05E5BAF02A}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe |
"UDP Query User{6A0C775D-BBBB-461C-A933-A6374F7CB6BE}C:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe |
"UDP Query User{708BFC1A-BA8A-4733-910A-273891F31039}C:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe |
"UDP Query User{817E2A74-15C8-4455-AD69-5D39B407C0A1}C:\program files (x86)\steam\steamapps\ultima_weapon33\source 2007 dedicated server\srcds.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\source 2007 dedicated server\srcds.exe |
"UDP Query User{868D33DE-29BF-4A85-B33B-89E55A9AF1B9}C:\users\chameleon\downloads\starcraft_2_na_en-us(2).exe" = protocol=17 | dir=in | app=c:\users\chameleon\downloads\starcraft_2_na_en-us(2).exe |
"UDP Query User{8BB6B29C-7D42-4AC2-95E5-ED408C5D3F45}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe |
"UDP Query User{8FCF15F7-73E9-4D81-8D3D-A3B696D99150}C:\program files (x86)\starcraft ii\versions\base16939\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base16939\sc2.exe |
"UDP Query User{913ACC39-5862-4A04-9B42-E8252EDAD1B8}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"UDP Query User{9164E789-F777-45B3-A21C-3627B6D8D94F}C:\program files\comicrack\comicrack.exe" = protocol=17 | dir=in | app=c:\program files\comicrack\comicrack.exe |
"UDP Query User{95BA6079-5AAB-490B-B35E-E9F30CDBC982}C:\program files (x86)\aim6\aim6.exe" = protocol=17 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"UDP Query User{9A1631F3-1A28-49FC-8233-754C90A92757}C:\program files (x86)\steam\steam.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"UDP Query User{9C69564C-0E7A-48DD-A8A4-F03F276FB185}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"UDP Query User{A1475F6E-BD17-4741-A075-BFA4D8B0E3A1}C:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe |
"UDP Query User{A9577645-1CF9-4294-8EBE-4468077AFD6D}C:\program files (x86)\steam\steamapps\common\altitude\altitude.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\altitude\altitude.exe |
"UDP Query User{B904FC79-0BCD-4781-9C33-5BCAF043E4B6}C:\program files (x86)\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mirc\mirc.exe |
"UDP Query User{BDA08904-4453-4654-B82B-14FE4482D5F5}C:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe |
"UDP Query User{BE67F50E-9C93-4BE2-B59C-5541EE534F65}C:\program files (x86)\steam\steamapps\common\altitude\altitude.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\altitude\altitude.exe |
"UDP Query User{BF8F4BE9-84CE-4995-80D1-1E6D7AAE4570}C:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe |
"UDP Query User{C2E71C4B-0E1E-4690-A43C-697FDADD7CD0}C:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe |
"UDP Query User{C62D37A9-5DC9-408F-ACE9-AB588E0B1965}C:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_b6908e294fd27714\tmod.exe" = protocol=17 | dir=in | app=c:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_b6908e294fd27714\tmod.exe |
"UDP Query User{C807EAE9-61AD-4B5C-A76D-CFF691286FAA}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe |
"UDP Query User{CEB68492-D0FA-4DB4-9FED-67F5C6DF1844}C:\program files (x86)\steam\steamapps\common\terraria\terraria.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"UDP Query User{D3F2D478-50A0-4530-A5A5-A6B91EF60886}C:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe |
"UDP Query User{D6701D58-A6A8-49FA-9EE6-4F53279C5454}C:\program files (x86)\interplay\fallout tactics\bos.exe" = protocol=17 | dir=in | app=c:\program files (x86)\interplay\fallout tactics\bos.exe |
"UDP Query User{D84F58D2-4C62-461A-8B98-F00CCAFD5CFB}C:\program files\comicrack\comicrack.exe" = protocol=17 | dir=in | app=c:\program files\comicrack\comicrack.exe |
"UDP Query User{DAF0C6E9-D491-42FA-B82D-43AB35BEAFA2}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe |
"UDP Query User{DEA99E92-8CA1-4D3D-B67C-0F25455CA38F}C:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe |
"UDP Query User{E32C0A62-78FD-4399-8ED6-0C982AE3C0D1}C:\program files (x86)\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
"UDP Query User{E8E940BB-79C0-4F15-A2E1-D35044D49C91}C:\program files (x86)\squareenix\final fantasy xiv\ffxivboot.exe" = protocol=17 | dir=in | app=c:\program files (x86)\squareenix\final fantasy xiv\ffxivboot.exe |
"UDP Query User{EB03754D-5FA2-4A71-BFE9-3474E1338355}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"UDP Query User{EB2C4060-BF9F-43E3-ACC4-60789ED8B739}C:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx9.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx9.exe |
"UDP Query User{ED41724B-CA4A-45CC-B25B-517DBBEA32E7}C:\riot games\league of legends\lol.launcher.exe" = protocol=17 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"UDP Query User{F3A4538C-0964-4511-8CDD-88F7ED8951BE}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe |
"UDP Query User{F3E552A4-9574-4CF6-B6BF-B9FB883C10CC}C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe |
"UDP Query User{F4D54F8E-41A5-41A0-935C-EEE67A6A4602}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"UDP Query User{F7772F90-0817-4476-BF61-8446374428A5}C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe |
"UDP Query User{F9A79B77-44CD-4F8A-A93D-7645EE200F1E}C:\riot games\league of legends\lol.launcher.exe" = protocol=17 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"UDP Query User{FB10D8FA-D305-41D0-8D2A-2491AD1BD913}C:\program files (x86)\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
"UDP Query User{FD8081F2-4D5D-4961-B6C1-7C87F30D83A8}C:\program files (x86)\steam\steamapps\common\dead space 2\deadspace2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space 2\deadspace2.exe |
"UDP Query User{FE55E179-C255-4EB0-B957-53CEA68C929D}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08D401E5-E23D-4372-8F9E-764963B19483}" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
"{1686C4D1-B1FD-42E8-B7A8-FB4C4DBA5BA8}" = ASUS Power4Gear Hybrid
"{20387B45-18A4-4D48-ABD9-A23D2CBE42B3}" = Dolby Control Center
"{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition)
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{48B0F24F-B828-4B1A-A22E-C65454B32A7A}" = Windows Live Family Safety
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6D41B4C4-FCD7-4F9B-99B9-A01F63F71F0F}" = Smart Technology Programming Software [removed]
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{9F560BEB-021F-43AC-825F-AA60442D8DE4}" = 64 Bit HP CIO Components Installer
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 266.58
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{C74A84EC-7C5F-4C36-A4A6-381E516D643B}" = Microsoft IntelliPoint 7.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{D77D43B5-ED55-426b-B67B-E21F804F6102}" = HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"ComicRack" = ComicRack v0.9.118
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.17
"Defraggler" = Defraggler
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
"Shop for HP Supplies" = Shop for HP Supplies
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"USB 2.0 UVC 1.3M WebCam" = USB 2.0 UVC 1.3M WebCam
"WinRAR archiver" = WinRAR archiver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{111DB3F0-0C58-4475-9954-1BD5B7B28618}" = League of Legends
"{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.7.1
"{1C8521E5-5A7B-4A4E-A9CD-AD53116EAEE0}" = ASUS Data Security Manager
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2208D65A-1BF9-485E-A308-1BA6CADCDC1D}" = Windows Live Movie Maker Beta
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 24
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2B4C7E1E-E446-4740-ADB5-9842E742EE8A}" = Windows Live Toolbar
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3B05F2FB-745B-4012-ADF2-439F36B2E70B}" = ATKOSD2
"{40580068-9B10-40B5-9548-536CE88AB23C}" = ITECIR
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4343080E-448E-4E2C-B27F-B91000018201}" = Dead Rising 2
"{4343080E-448E-4E2C-B27F-B91000028201}" = Dead Rising 2
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{5454085C-840F-4070-8FAA-441000018301}" = BioShock 2
"{5454085C-840F-4070-8FAA-441000028301}" = BioShock 2
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.55.03
"{5A347920-4AFC-11D5-9FB0-800649886934}" = SDFormatter
"{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71929EC1-FDB2-4A67-AAAD-936E4539FA84}_is1" = Driver Sweeper 2.1.0
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7988ba74-4a27-4685-991a-53f072f22808}" = F2200_Help
"{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey
"{83F73CB1-7705-49D1-9852-84D839CA2A45}" = Wireless Console 2
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95C5F81D-0779-4932-BE83-32AAF814F4B9}" = League of Legends
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A0B9F8DF-C949-45ed-9808-7DC5C0C19C81}" = Status
"{A11409F1-CD33-4076-85CB-4EE4A8439BFE}" = Scan
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB6F4AB9-AC85-4002-9829-B6EEA55AE3A5}" = Microsoft Visual C++ 2005 Express Edition - ENU
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AE0259D4-7A01-4E47-BBAF-2604D03DF07C}" = LoJack Factory Installer
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BCB4C18A-ACA6-4383-8688-E19933A705DD}" = Microsoft SOAP Toolkit 3.0
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}" = QuickTime
"{C3592426-531E-4110-911D-BFECE2CE284C}" = osu!
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{c6922d7f-c698-4d9e-9671-8b3de04d1511}" = DJ_AIO_03_F2200_Software_Min
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{D1E5870E-E3E5-4475-98A6-ADD614524ADF}" = ATK Media
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
"{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service
"{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{db18dc72-cd20-4801-be82-f5d2caeec4d7}" = DJ_AIO_03_F2200_Software
"{DC905847-D537-427F-BF91-47CC7ACCDE58}" = ASUS FancyStart
"{DE10AB76-4756-4913-BE25-55D1C1051F9A}" = WinFlash
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{e97a9fd7-2fa1-4474-820d-3f8893a5b78a}" = F2200
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{eca3039b-e429-420f-bd5e-7dec0683fc32}" = DJ_AIO_03_F2200_ProductContext
"{EEF985E8-8B36-4230-B174-117A2381C17F}" = LogMeIn Hamachi
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F204E2B3-225D-419D-A5DE-3F97E8ADDD1B}" = Geek Squad 24 Hour Computer Support
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F42CD69D-E393-47c8-B2CD-B139C4ADA9A8}" = Copy
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{F7FC9307-374E-4017-8E9D-DE1154780480}" = System Requirements Lab for Intel
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AIM_7" = AIM 7
"ALSee_is1" = ALSee
"ALUpdate_is1" = ALTools Update
"Asus_Camera_ScreenSaver" = Asus_Camera_ScreenSaver
"AutoHotkey" = AutoHotkey 1.0.48.05
"avast" = avast! Free Antivirus
"Call of Pripyat Complete_is1" = Call of Pripyat Complete v1.0.1
"Comical_is1" = Comical 0.8
"DragonUnPACKer5_is1" = Dragon UnPACKer 5
"Driver Cleaner Pro" = DH Driver Cleaner Professional Edition
"Fallout Collection" = Fallout Collection
"Fallout Mod Manager_is1" = Fallout Mod Manager 0.9.15
"Fraps" = Fraps (remove only)
"Game Booster_is1" = Game Booster
"HaaliMkx" = Haali Media Splitter
"HijackThis" = HijackThis 2.0.2
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{AE0259D4-7A01-4E47-BBAF-2604D03DF07C}" = LoJack Factory Installer
"InstallShield_{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}" = QuickTime
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
"LogMeIn Hamachi" = LogMeIn Hamachi
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Matroska Pack" = Matroska Pack
"Microsoft Visual C++ 2005 Express Edition - ENU" = Microsoft Visual C++ 2005 Express Edition - ENU
"mIRC" = mIRC
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"Mumble" = Mumble and Murmur
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 12.0" = RealPlayer
"RivaTuner" = RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"Smart Defrag 2_is1" = Smart Defrag 2
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SpywareBlaster_is1" = SpywareBlaster 4.4
"StarCraft II" = StarCraft II
"Steam App 105600" = Terraria
"Steam App 12910" = Audiosurf Demo
"Steam App 17020" = Global Agenda
"Steam App 18500" = Defense Grid: The Awakening
"Steam App 20500" = Red Faction: Guerrilla
"Steam App 20540" = Company of Heroes: Tales of Valor
"Steam App 20920" = The Witcher 2
"Steam App 20930" = The Witcher 2: Bonus Content
"Steam App 310" = Team Fortress 2 Dedicated Server
"Steam App 32370" = Star Wars: Knights of The Old Republic
"Steam App 35140" = Batman: Arkham Asylum GOTY Edition
"Steam App 3590" = Plants vs. Zombies: Game of the Year
"Steam App 3900" = Sid Meier's Civilization IV
"Steam App 40800" = Super Meat Boy
"Steam App 440" = Team Fortress 2
"Steam App 4560" = Company of Heroes
"Steam App 45740" = Dead Rising 2
"Steam App 550" = Left 4 Dead 2
"Steam App 620" = Portal 2
"Steam App 6980" = Thief: Deadly Shadows
"Steam App 8190" = Just Cause 2
"Steam App 8800" = Sid Meier's Civilization IV: Beyond the Sword
"Steam App 99900" = Spiral Knights
"SUPER ©" = SUPER © Version 2009.bld.36 (June 10, 2009)
"SystemRequirementsLab" = System Requirements Lab
"The Witcher - Scabbard Mod_is1" = Scabbar Mod ver 1.03
"TreeSize Free_is1" = TreeSize Free V2.5
"Unofficial Oblivion Patch_is1" = Unofficial Oblivion Patch v3.2.0
"uTorrent" = µTorrent
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.0.1
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPatrol" = WinPatrol 2009
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"3495513a08ab089c" = tMod
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Antivirus Events ]
Error - 1/27/2011 8:34:22 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:22 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:23 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:23 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:23 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:23 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:24 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:26 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:26 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:27 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
[ Application Events ]
Error - 1/10/2011 9:15:51 AM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/10/2011 1:57:35 PM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/10/2011 6:26:37 PM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/10/2011 11:43:56 PM | Computer Name = CHA-PC | Source = Application Error | ID = 1000
Description = Faulting application Skype.exe, version 5.1.0.104, time stamp 0x4d21d204,
faulting module virtualCamera.ax, version 0.0.0.0, time stamp 0x4933ab74, exception
code 0xc0000005, fault offset 0x000088e7, process id 0x10a8, application start time
0x01cbb1417e72c961.
Error - 1/11/2011 9:20:15 AM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/12/2011 9:13:43 AM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/12/2011 3:56:30 PM | Computer Name = CHA-PC | Source = Winlogon | ID = 4005
Description = The Windows logon process has unexpectedly terminated.
Error - 1/12/2011 3:59:49 PM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/13/2011 9:20:23 AM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/13/2011 1:44:05 PM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
[ Media Center Events ]
Error - 10/3/2009 11:32:04 PM | Computer Name = CHA-PC | Source = ehRecvr | ID = 4
Description =
[ System Events ]
Error - 6/21/2011 6:09:06 PM | Computer Name = CHA-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 4:50:55 PM on 6/21/2011 was unexpected.
Error - 6/21/2011 6:13:17 PM | Computer Name = CHA-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 5:10:04 PM on 6/21/2011 was unexpected.
Error - 6/21/2011 6:13:31 PM | Computer Name = CHA-PC | Source = DCOM | ID = 10005
Description =
Error - 6/21/2011 6:13:42 PM | Computer Name = CHA-PC | Source = DCOM | ID = 10005
Description =
Error - 6/21/2011 6:13:48 PM | Computer Name = CHA-PC | Source = DCOM | ID = 10005
Description =
Error - 6/21/2011 6:13:58 PM | Computer Name = CHA-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 6/21/2011 6:13:58 PM | Computer Name = CHA-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 6/21/2011 6:13:58 PM | Computer Name = CHA-PC | Source = DCOM | ID = 10005
Description =
Error - 6/21/2011 8:09:03 PM | Computer Name = CHA-PC | Source = DCOM | ID = 10005
Description =
Error - 6/21/2011 8:32:37 PM | Computer Name = CHA-PC | Source = DCOM | ID = 10005
Description =
< End of report >
HiJack This Log; done in safe mode, with networking support. If it is really important I can try to get one in normal mode… I should be able to get it and save it before it freezes up.
I guess I have an old version, but I can't get the new one in Safe Mode it seems. To bypass the redirection, I've changed the version number directly below. If these are essentially worthless since it's not the newest version, I apologize.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:25:06 PM, on 6/21/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19088)
Boot mode: Safe mode with network support
Running processes:
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gamefaqs.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:18810
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: &Windows; Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ADSMTray] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
O4 - HKLM\..\Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [UpdatePDRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" –auto-start
O4 - HKLM\..\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
O4 - HKCU\..\Run: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Winamp; Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - Unknown owner - c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 10820 bytes
Again, this was an older version of HyjackThis. To bypass the redirection, I've changed the version number in the first line. If these are essentially worthless since it's not the newest version, I apologize.
DDS
.
DDS (Ver_11-03-05.01) - NTFS_AMD64 NETWORK
Run by [removed] at 20:18:00.73 on Tue 06/21/2011
Internet Explorer: 8.0.6001.19088 BrowserJavaVersion: 1.6.0_24
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.2742 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Users\Chameleon\Downloads\OTL.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Chameleon\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.gamefaqs.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod;=ASUS
uInternet Settings,ProxyServer = http=127.0.0.1:18810
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: &Windows; Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
uRun: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US
mRun: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
mRun: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
mRun: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
mRun: [ADSMTray] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
mRun: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
mRun: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe
mRun: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
mRun: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun: [UpdatePDRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" –auto-start
mRun: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FANCYS~1.LNK - C:\Windows\Installer\{DC905847-D537-427F-BF91-47CC7ACCDE58}\_DF3A81D17C478A2A6C60A5.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MAGICD~1.LNK - C:\Program Files (x86)\MagicDisc\MagicDisc.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Winamp; Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
LSA: Notification Packages = scecli C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT
BHO-X64: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
BHO-X64: Windows Live Family Safety Browser Helper - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB-X64: Winamp Toolbar: {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} -
mRun-x64: [DisableS3S4] c:\DisableS3S4.cmd
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
mRun-x64: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
mRun-x64: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
mRun-x64: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
mRun-x64: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\CHAMEL~1\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.gamefaqs.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;=
FF - prefs.js: network.proxy.type - 4
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true
FF - user.js: browser.sessionstore.resume_from_crash - false
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
============= SERVICES / DRIVERS ===============
.
R0 SmartDefragDriver;SmartDefragDriver;C:\Windows\System32\drivers\SmartDefragDriver.sys [2011-6-13 18232]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-5-25 2275720]
R3 itecir;ITECIR Infrared Receiver;C:\Windows\System32\drivers\itecir.sys [2009-8-11 59392]
R3 NETw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2008-8-28 4745216]
R3 SaiK0CFA;SaiK0CFA;C:\Windows\System32\drivers\SaiK0CFA.sys [2010-12-19 174600]
R3 SaiU0CFA;SaiU0CFA;C:\Windows\System32\drivers\SaiU0CFA.sys [2010-12-19 41352]
S1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2011-2-26 600920]
S1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2009-9-10 287576]
S2 ASMMAP64;ASMMAP64;C:\Program Files\ATKGFNEX\ASMMAP64.sys [2009-8-11 14904]
S2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2009-9-10 22360]
S2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2009-9-10 64344]
S2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-1-29 42184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 cpuz135;cpuz135;C:\Windows\System32\drivers\cpuz135_x64.sys [2011-2-11 21992]
S2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2009-9-10 304464]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-1-7 378984]
S2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe [2009-9-10 24652]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe –> c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [?]
S3 fssfltr;FssFltr;C:\Windows\System32\drivers\fssfltr.sys [2009-8-11 61792]
S3 fsssvc;Windows Live Family Safety;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2008-12-8 533344]
S3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2009-9-10 24664]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;C:\Windows\System32\drivers\MijXfilt.sys [2009-12-5 53248]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 Point64;Microsoft IntelliPoint Filter Driver;C:\Windows\System32\drivers\point64k.sys [2009-5-8 33160]
S3 RivaTuner64;RivaTuner64;C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2009-8-22 19952]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk60x64.sys [2006-11-2 273408]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-10-20 89920]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-06-21 18:38:08 ——– d—–w- C:\_OTS
2011-06-21 18:25:04 ——– d—–w- C:\Users\CHAMEL~1\AppData\Local\temp
2011-06-21 18:15:43 ——– d-sh–w- C:\$RECYCLE.BIN
2011-06-21 17:46:50 98816 —-a-w- C:\Windows\sed.exe
2011-06-21 17:46:50 518144 —-a-w- C:\Windows\SWREG.exe
2011-06-21 17:46:50 256512 —-a-w- C:\Windows\PEV.exe
2011-06-21 17:46:50 208896 —-a-w- C:\Windows\MBR.exe
2011-06-19 04:38:33 ——– d—–w- C:\Users\CHAMEL~1\AppData\Roaming\TerrariaMod
2011-06-18 02:21:07 8718160 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{4B70ECE2-C3FB-4D54-A41A-2A725956ED5D}\mpengine.dll
2011-06-16 19:37:53 916480 —-a-w- C:\Windows\SysWow64\wininet.dll
2011-06-14 01:19:47 ——– d—–w- C:\Users\CHAMEL~1\AppData\Local\Apps
2011-06-14 01:19:46 ——– d—–w- C:\Users\CHAMEL~1\AppData\Local\Deployment
2011-06-14 01:19:28 ——– d—–w- C:\Program Files\Microsoft Synchronization Services
2011-06-14 01:19:28 ——– d—–w- C:\Program Files\Microsoft SQL Server Compact Edition
2011-06-14 01:18:55 ——– d—–w- C:\Program Files (x86)\Microsoft Synchronization Services
2011-06-13 21:50:14 ——– d—–w- C:\Users\CHAMEL~1\AppData\Roaming\IObit
2011-06-13 21:50:13 32648 —-a-w- C:\Windows\System32\SmartDefragBootTime.exe
2011-06-13 21:50:13 18232 —-a-w- C:\Windows\System32\drivers\SmartDefragDriver.sys
2011-06-13 21:49:35 ——– d—–w- C:\Program Files (x86)\IObit
2011-06-13 21:46:57 ——– d—–w- C:\PROGRA~3\IObit
2011-06-10 06:43:21 ——– d—–w- C:\PROGRA~3\Skype Extras
2011-06-10 04:23:34 ——– d—–w- C:\Users\CHAMEL~1\AppData\Roaming\TerrariaWorldViewer
2011-06-08 20:04:50 ——– d—–w- C:\Program Files (x86)\osu!
2011-06-08 20:03:38 ——– d—–w- C:\Users\CHAMEL~1\AppData\Roaming\Downloaded Installations
2011-06-06 22:28:16 ——– d—–w- C:\PROGRA~3\AIM
2011-06-06 22:28:03 ——– d—–w- C:\Program Files (x86)\AIM
2011-06-06 22:28:02 ——– d—–w- C:\Program Files (x86)\Common Files\Software Update Utility
2011-06-03 17:54:56 ——– d—–w- C:\Users\CHAMEL~1\AppData\Local\Real
2011-06-03 17:53:34 ——– d—–w- C:\Program Files (x86)\Common Files\xing shared
2011-06-03 17:46:09 ——– d—–w- C:\Users\CHAMEL~1\AppData\Local\Google
2011-05-30 18:06:47 33856 —ha-w- C:\Windows\System32\hamachi.sys
2011-05-30 18:06:21 ——– d—–w- C:\Program Files (x86)\LogMeIn Hamachi
.
==================== Find3M ====================
.
2011-06-21 18:09:16 45056 —-a-w- C:\Windows\System32\acovcnt.exe
2011-06-06 17:13:07 404640 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-03 17:51:58 499712 —-a-w- C:\Windows\SysWow64\msvcp71.dll
2011-06-03 17:51:58 348160 —-a-w- C:\Windows\SysWow64\msvcr71.dll
2011-05-28 06:28:00 1147904 —-a-w- C:\Windows\System32\wininet.dll
2011-05-28 06:24:04 56832 —-a-w- C:\Windows\System32\licmgr10.dll
2011-05-28 06:23:47 1538560 —-a-w- C:\Windows\System32\inetcpl.cpl
2011-05-28 06:23:30 132096 —-a-w- C:\Windows\System32\iesysprep.dll
2011-05-28 06:23:29 77312 —-a-w- C:\Windows\System32\iesetup.dll
2011-05-28 06:04:30 43520 —-a-w- C:\Windows\SysWow64\licmgr10.dll
2011-05-28 06:04:17 1469440 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-05-28 06:04:03 71680 —-a-w- C:\Windows\SysWow64\iesetup.dll
2011-05-28 06:04:03 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll
2011-05-28 05:33:37 479232 —-a-w- C:\Windows\System32\html.iec
2011-05-28 05:10:26 385024 —-a-w- C:\Windows\SysWow64\html.iec
2011-05-28 04:53:37 162816 —-a-w- C:\Windows\System32\ieUnatt.exe
2011-05-28 04:52:18 1638912 —-a-w- C:\Windows\System32\mshtml.tlb
2011-05-28 04:33:03 133632 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2011-05-28 04:31:44 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2011-05-18 13:56:59 2762752 —-a-w- C:\Windows\System32\win32k.sys
2011-05-10 12:10:59 40112 —-a-w- C:\Windows\avastSS.scr
2011-05-10 12:04:08 600920 —-a-w- C:\Windows\System32\drivers\aswSnx.sys
2011-05-10 11:59:48 64344 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2011-05-03 23:38:44 90112 —-a-w- C:\Windows\lol.launcher.exe
2011-05-03 23:38:43 90112 —-a-w- C:\Windows\lol.launcher.admin.exe
2011-05-02 17:16:14 739328 —-a-w- C:\Windows\SysWow64\inetcomm.dll
2011-05-02 17:13:21 975360 —-a-w- C:\Windows\System32\inetcomm.dll
2011-04-29 13:41:02 176128 —-a-w- C:\Windows\System32\drivers\srv2.sys
2011-04-29 13:40:56 145920 —-a-w- C:\Windows\System32\drivers\srvnet.sys
2011-04-29 13:39:34 275456 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-04-29 13:39:34 135680 —-a-w- C:\Windows\System32\drivers\mrxsmb.sys
2011-04-29 13:39:31 107008 —-a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2011-04-21 14:20:24 405504 —-a-w- C:\Windows\System32\drivers\afd.sys
2011-04-14 15:14:19 97792 —-a-w- C:\Windows\System32\drivers\dfsc.sys
2011-04-09 23:55:44 15453336 —-a-w- C:\Windows\SysWow64\xlive.dll
2011-04-09 23:55:42 13642904 —-a-w- C:\Windows\SysWow64\xlivefnt.dll
2006-05-03 09:06:54 163328 –sh–r- C:\Windows\SysWOW64\flvDX.dll
2007-02-21 10:47:16 31232 –sh–r- C:\Windows\SysWOW64\msfDX.dll
2008-03-16 12:30:52 216064 –sh–r- C:\Windows\SysWOW64\nbDX.dll
.
============= FINISH: 20:18:51.50 ===============
Once again, thanks in advance for any help you have to offer.
Basically, just as I said in the title. You can get one program up real quickly, which is how I got Avast! to do a boot-time scan. Then, it'll just be really really slow and just load, nothing will show up. After a bit, the screen will go white as it's "not responding" and then all black, with the mouse cursor movable.
Avast is being weird in safe mode, though.. I did a full-time scan and a boot-time scan, got 3 things then 2 things. Two of the things from the first was put in the chest easy, but this "root kit system modification" thing is what I believe the problem is. It won't let me delete it until "a system restart". The thing is found at "System32.RegBack.SECURITY.OLD".
However, if I do that with Avast or schedule a boot-time scan, it'll just do nothing when I turn the computer on/restart it. Heck, you can schedule a boot-time scan, click something else, then go back to Avast and it's off. It says the "Avast" service is off, but trying to turn it back on doesn't work.
I've also done a Malwarebyte's quick and full scan, aswMBR scans, OTS scan/fix, tdsskiller and ComboFix (followed another forum's directions on this), but to no avail. However, asides from the Avast and Malwarebytes scans, these are of dubious quality - some of them had the computer restart even though there's no mention in the program/guide that it would cause it to restart, so they may have not finished.
Just did a Spybot Search + Destroy, had some results but the problem persists.
Thanks in advance for any help you can offer me.
OTL Logs:
OTL
OTL logfile created on: 6/21/2011 7:36:20 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Chameleon\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 3.07 Gb Available Physical Memory | 76.71% Memory free
8.17 Gb Paging File | 7.41 Gb Available in Paging File | 90.69% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.40 Gb Total Space | 46.37 Gb Free Space | 16.25% Space Free | Partition Type: NTFS
Drive E: | 7.91 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 931.51 Gb Total Space | 359.20 Gb Free Space | 38.56% Space Free | Partition Type: NTFS
Drive G: | 539.19 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: CHA-PC | User Name: Chameleon | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Chameleon\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
PRC - C:\Program Files\Alwil Software\Avast5\AvastUI.exe (AVAST Software)
========== Modules (SafeList) ==========
MOD - C:\Users\Chameleon\Downloads\OTL.exe (OldTimer Tools)
MOD - C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3\comctl32.dll (Microsoft Corporation)
========== Win32 Services (SafeList) ==========
SRV:64bit: - (avast! Antivirus) – C:\Program Files\Alwil Software\Avast5\AvastSvc.exe (AVAST Software)
SRV:64bit: - (ADSMService) – C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe (ASUSTek Computer Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (ATKGFNEXSrv) – C:\Program Files\ATKGFNEX\GFNEXSrv.exe ()
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Hamachi2Svc) – C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (PnkBstrA) – C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (ASLDRService) – C:\Program Files (x86)\ASUS\ATK Hotkey\AsLdrSrv.exe ()
SRV - (Viewpoint Manager Service) – C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe (Viewpoint Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (SmartDefragDriver) – C:\Windows\SysNative\Drivers\SmartDefragDriver.sys ()
DRV:64bit: - (cpuz135) – C:\Windows\SysNative\drivers\cpuz135_x64.sys (CPUID)
DRV:64bit: - (SaiNtBus) – C:\Windows\SysNative\drivers\SaiBus.sys (Saitek)
DRV:64bit: - (SaiMini) – C:\Windows\SysNative\DRIVERS\SaiMini.sys (Saitek)
DRV:64bit: - (SaiK0CFA) – C:\Windows\SysNative\DRIVERS\SaiK0CFA.sys (Saitek)
DRV:64bit: - (SaiU0CFA) – C:\Windows\SysNative\DRIVERS\SaiU0CFA.sys (Saitek)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (MotioninJoyXFilter) – C:\Windows\SysNative\DRIVERS\MijXfilt.sys (MotioninJoy)
DRV:64bit: - (xusb21) – C:\Windows\SysNative\DRIVERS\xusb21.sys (Microsoft Corporation)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (Point64) – C:\Windows\SysNative\DRIVERS\point64k.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\DRIVERS\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (hamachi) – C:\Windows\SysNative\DRIVERS\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (mcdbus) – C:\Windows\SysNative\DRIVERS\mcdbus.sys (MagicISO, Inc.)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (fssfltr) – C:\Windows\SysNative\DRIVERS\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (SNP2UVC) USB2.0 PC Camera (SNP2UVC) – C:\Windows\SysNative\DRIVERS\snp2uvc.sys ()
DRV:64bit: - (NETw5v64) Intel® – C:\Windows\SysNative\DRIVERS\NETw5v64.sys (Intel Corporation)
DRV:64bit: - (RTL8169) – C:\Windows\SysNative\DRIVERS\Rtlh64.sys (Realtek Corporation )
DRV:64bit: - (rimmptsk) – C:\Windows\SysNative\DRIVERS\rimmpx64.sys (REDC)
DRV:64bit: - (kbfiltr) – C:\Windows\SysNative\DRIVERS\kbfiltr.sys ( )
DRV:64bit: - (itecir) – C:\Windows\SysNative\DRIVERS\itecir.sys (ITE Tech. Inc. )
DRV:64bit: - (SynTP) – C:\Windows\SysNative\DRIVERS\SynTP.sys (Synaptics, Inc.)
DRV:64bit: - (rismxdp) – C:\Windows\SysNative\DRIVERS\rixdpx64.sys (REDC)
DRV:64bit: - (rimsptsk) – C:\Windows\SysNative\DRIVERS\rimspx64.sys (REDC)
DRV:64bit: - (ASMMAP64) – C:\Program Files\ATKGFNEX\ASMMAP64.sys ()
DRV:64bit: - (MTsensor) – C:\Windows\SysNative\DRIVERS\ATK64AMD.sys ()
DRV:64bit: - (yukonx64) – C:\Windows\SysNative\DRIVERS\yk60x64.sys (Marvell)
DRV:64bit: - (Ntfs) – C:\Windows\SysNative\Wbem\ntfs.mof ()
DRV - (RivaTuner64) – C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys ()
DRV - (mcdbus) – C:\Windows\SysWOW64\drivers\mcdbus.sys (MagicISO, Inc.)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/ig/redirectdomain?br…S&bmod;=ASUS
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.gamefaqs.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:18810
========== FireFox ==========
FF - prefs.js..browser.search.defaultenginename: "AIM Search"
FF - prefs.js..browser.search.defaulturl: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;="
FF - prefs.js..browser.search.selectedEngine: "AIM Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.gamefaqs.com/"
FF - prefs.js..extensions.enabledItems: {35106bca-6c78-48c7-ac28-56df30b51d2a}:1.3.8
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {f701c26a-479a-4724-b4f1-870db12f063c}:1.4.4
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {6dd0bdba-0a02-429e-b595-87a7dfdca7a1}:0.7.12
FF - prefs.js..extensions.enabledItems: {0b38152b-1b20-484d-a11f-5e04a9b0661f}:[removed]
FF - prefs.js..extensions.enabledItems: FFToolbar@upromise:7.0.2.4181
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..keyword.URL: "http://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;="
FF - prefs.js..network.proxy.type: 4
FF - HKLM\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Alwil Software\Avast5\WebRep\FF [2011/05/17 15:54:11 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\Firefox\Ext [2011/06/03 12:53:09 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2011/06/03 12:52:48 | 000,000,000 | —D | M]
FF - HKLM\software\mozilla\Mozilla Firefox 4.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/06/06 17:28:02 | 000,000,000 | —D | M]
[2009/09/10 20:40:37 | 000,000,000 | —D | M] (No name found) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Extensions
[2011/04/29 18:14:51 | 000,000,000 | —D | M] (No name found) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions
[2011/01/29 13:10:07 | 000,000,000 | —D | M] (Winamp Toolbar) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions\{0b38152b-1b20-484d-a11f-5e04a9b0661f}
[2010/04/26 20:18:09 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2010/02/18 16:32:41 | 000,000,000 | —D | M] (Linkification) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions\{35106bca-6c78-48c7-ac28-56df30b51d2a}
[2011/02/09 13:34:36 | 000,000,000 | —D | M] (GameFOX) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions\{6dd0bdba-0a02-429e-b595-87a7dfdca7a1}
[2011/03/15 23:01:40 | 000,000,000 | —D | M] (Text-to-Image) – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions\{f701c26a-479a-4724-b4f1-870db12f063c}
[2011/03/10 14:57:50 | 000,000,000 | —D | M] ("Upromise TurboSaver") – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\extensions\FFToolbar@upromise
[2009/09/10 20:44:39 | 000,004,261 | —- | M] () – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\searchplugins\aim-search.xml
[2011/01/29 13:11:56 | 000,001,196 | —- | M] () – C:\Users\Chameleon\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\searchplugins\winamp-search.xml
[2011/06/10 23:36:14 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2010/06/09 15:40:11 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}
[2010/08/16 15:00:25 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}
[2011/01/13 08:29:30 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}
[2011/03/12 20:54:01 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}
File not found (No name found) –
[2011/05/17 15:54:11 | 000,000,000 | —D | M] (avast! WebRep) – C:\PROGRAM FILES\ALWIL SOFTWARE\AVAST5\WEBREP\FF
[2011/06/03 12:53:09 | 000,000,000 | —D | M] (RealPlayer Browser Record Plugin) – C:\PROGRAMDATA\REAL\REALPLAYER\BROWSERRECORDPLUGIN\FIREFOX\EXT
[2011/04/14 11:26:02 | 000,142,296 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\Mozilla Firefox\components\browsercomps.dll
[2011/02/02 22:40:24 | 000,472,808 | —- | M] (Sun Microsystems, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
[2007/04/16 12:07:12 | 000,180,293 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\plugins\npViewpoint.dll
[2010/12/09 05:47:06 | 000,012,800 | —- | M] (Nullsoft, Inc.) – C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\Mozilla Firefox\searchplugins\bing.xml
O1 HOSTS File: ([2011/06/21 13:15:32 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Windows Live Family Safety Browser Helper Class) - {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll (Microsoft Corporation)
O2 - BHO: (Adobe PDF Reader Link Helper) - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll (Adobe Systems Incorporated)
O2 - BHO: (Winamp Toolbar Loader) - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O2 - BHO: (RealPlayer Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll (RealPlayer)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Skype Browser Helper) - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Winamp Toolbar) - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O3 - HKCU\..\Toolbar\WebBrowser: (Winamp Toolbar) - {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll (AOL LLC.)
O4:64bit: - HKLM..\Run: [DisableS3S4] File not found
O4:64bit: - HKLM..\Run: [IntelliPoint] C:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe (Saitek)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe (Saitek)
O4:64bit: - HKLM..\Run: [Skytel] C:\Program Files\Realtek\Audio\HDA\SkyTel.exe (Realtek Semiconductor Corp.)
O4 - HKLM..\Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe (ATK)
O4 - HKLM..\Run: [ADSMTray] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe (ASUSTek Computer Inc.)
O4 - HKLM..\Run: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe ()
O4 - HKLM..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe ()
O4 - HKLM..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe (ASUS)
O4 - HKLM..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe (ASUS)
O4 - HKLM..\Run: [CLMLServer] C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe (CyberLink)
O4 - HKLM..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe (ASUS)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [TkBellExe] c:\program files (x86)\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [UpdateLBPShortCut] C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdateP2GoShortCut] C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePDRShortCut] C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [WinampAgent] C:\Program Files (x86)\Winamp\winampa.exe (Nullsoft, Inc.)
O4 - HKLM..\Run: [WinPatrol] C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe (BillP Studios)
O4 - HKCU..\Run: [Aim] C:\Program Files (x86)\AIM\aim.exe (AOL Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: &Winamp; Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O8 - Extra context menu item: &Winamp; Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html ()
O9 - Extra Button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O9 - Extra 'Tools' menuitem : Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_24)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O18:64bit: - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\ms-itss {0A9007C0-4076-11D3-8789-0000F8105754} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - Reg Error: Key error. File not found
O18:64bit: - Protocol\Handler\wlmailhtml {03C514A3-1EFB-4856-9F99-10D7BE1653C0} - Reg Error: Key error. File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Users\Chameleon\Documents\Pix\[AnimePaper]wallpapers_Kara-no-Kyoukai_redxxii(1_33)_1024x768_72601.jpg
O24 - Desktop BackupWallPaper: C:\Users\Chameleon\Documents\Pix\[AnimePaper]wallpapers_Kara-no-Kyoukai_redxxii(1_33)_1024x768_72601.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/03/06 08:21:01 | 000,000,000 | R–D | M] - F:\autorun – [ NTFS ]
O32 - AutoRun File - [2005/10/25 20:53:00 | 000,000,044 | R— | M] () - G:\autorun.inf – [ CDFS ]
O34 - HKLM BootExecute: (autocheck autochk *) - File not found
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: VIDC.FPS1 - frapsv64.dll (Beepa P/L)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: VIDC.FPS1 - C:\Windows\SysWow64\frapsvid.dll (Beepa P/L)
Drivers32: vidc.i420 - C:\Windows\SysWow64\i420vfw.dll (www.helixcommunity.org)
Drivers32: vidc.yv12 - C:\Windows\SysWow64\yv12vfw.dll (www.helixcommunity.org)
CREATERESTOREPOINT
Error creating restore point.
========== Files/Folders - Created Within 30 Days ==========
[2011/06/21 13:38:08 | 000,000,000 | —D | C] – C:\_OTS
[2011/06/21 13:31:47 | 000,000,000 | —D | C] – C:\Users\Chameleon\Desktop\tdsskiller
[2011/06/21 13:25:05 | 000,000,000 | —D | C] – C:\Windows\temp
[2011/06/21 13:25:04 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Local\temp
[2011/06/21 13:15:43 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2011/06/21 12:46:50 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2011/06/21 12:46:50 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2011/06/21 12:46:50 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2011/06/21 12:46:38 | 000,000,000 | —D | C] – C:\Windows\ERDNT
[2011/06/21 12:45:19 | 000,000,000 | —D | C] – C:\Qoobox
[2011/06/21 12:45:12 | 000,000,000 | —D | C] – C:\32788R22FWJFW
[2011/06/18 23:38:33 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Roaming\TerrariaMod
[2011/06/16 14:38:15 | 000,847,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\oleaut32.dll
[2011/06/16 14:37:46 | 000,710,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/06/16 14:37:45 | 000,602,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/06/16 14:37:44 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/06/16 14:37:43 | 000,252,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/06/16 14:37:40 | 000,072,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/06/16 14:37:39 | 001,538,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/06/16 14:37:39 | 000,219,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/06/16 14:37:39 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/06/16 14:37:39 | 000,056,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/06/16 14:37:38 | 001,469,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/06/16 14:37:38 | 000,479,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/06/16 14:37:38 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/06/16 14:37:37 | 000,385,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/06/16 14:37:37 | 000,162,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/06/16 14:37:37 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/06/16 14:37:36 | 000,206,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/06/16 14:37:36 | 000,184,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/06/16 14:37:36 | 000,164,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/06/16 14:37:36 | 000,133,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/06/16 14:37:36 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/06/16 14:37:36 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/06/16 14:37:36 | 000,066,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/06/16 14:37:35 | 000,070,656 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/06/16 14:37:35 | 000,055,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/06/16 14:37:35 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/06/16 14:37:30 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/06/16 14:37:30 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2011/06/16 14:37:30 | 000,012,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/06/13 20:20:23 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Earth2Me
[2011/06/13 20:19:47 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Local\Apps
[2011/06/13 20:19:46 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Local\Deployment
[2011/06/13 20:19:28 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Synchronization Services
[2011/06/13 20:19:28 | 000,000,000 | —D | C] – C:\Program Files\Microsoft SQL Server Compact Edition
[2011/06/13 20:18:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Synchronization Services
[2011/06/13 16:50:14 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Roaming\IObit
[2011/06/13 16:50:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Smart Defrag 2
[2011/06/13 16:49:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Game Booster
[2011/06/13 16:49:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2011/06/13 16:46:57 | 000,000,000 | —D | C] – C:\ProgramData\IObit
[2011/06/10 01:43:21 | 000,000,000 | —D | C] – C:\ProgramData\Skype Extras
[2011/06/10 01:39:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2011/06/10 01:39:01 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2011/06/09 23:23:34 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Roaming\TerrariaWorldViewer
[2011/06/08 15:05:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\osu!
[2011/06/08 15:04:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\osu!
[2011/06/08 15:03:38 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Roaming\Downloaded Installations
[2011/06/07 01:01:53 | 000,000,000 | —D | C] – C:\Users\Chameleon\Documents\Thief - Deadly Shadows
[2011/06/06 17:28:16 | 000,000,000 | —D | C] – C:\ProgramData\AIM
[2011/06/06 17:28:15 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AIM
[2011/06/06 17:28:03 | 000,000,000 | —D | C] – C:\Program Files (x86)\AIM
[2011/06/06 17:28:02 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Software Update Utility
[2011/06/03 17:52:36 | 000,000,000 | —D | C] – C:\ProgramData\Google
[2011/06/03 12:54:56 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Local\Real
[2011/06/03 12:53:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\xing shared
[2011/06/03 12:46:09 | 000,000,000 | —D | C] – C:\Users\Chameleon\AppData\Local\Google
[2011/06/03 12:45:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\Google
[2011/05/30 13:06:47 | 000,033,856 | -H– | C] (LogMeIn, Inc.) – C:\Windows\SysNative\hamachi.sys
[2011/05/30 13:06:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2011/05/30 13:06:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\LogMeIn Hamachi
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2011/06/21 19:36:14 | 000,000,306 | —- | M] () – C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-3660194186-3126353062-2202063419-1000.job
[2011/06/21 17:13:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2011/06/21 17:10:00 | 000,000,426 | -H– | M] () – C:\Windows\tasks\User_Feed_Synchronization-{306F3F19-2941-4C0D-81FA-6F323DC8EEBE}.job
[2011/06/21 17:09:10 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2011/06/21 17:09:09 | 000,003,616 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2011/06/21 13:31:23 | 001,309,375 | —- | M] () – C:\Users\Chameleon\Desktop\tdsskiller.zip
[2011/06/21 13:15:32 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2011/06/21 13:09:16 | 000,045,056 | —- | M] () – C:\Windows\SysNative\acovcnt.exe
[2011/06/20 17:24:27 | 000,008,592 | —- | M] () – C:\Users\Chameleon\AppData\Local\d3d9caps.dat
[2011/06/20 03:27:07 | 000,104,448 | —- | M] () – C:\Users\Chameleon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/06/19 00:08:41 | 000,001,002 | —- | M] () – C:\Users\Chameleon\Desktop\tMod.lnk
[2011/06/18 23:34:03 | 000,000,221 | —- | M] () – C:\Users\Chameleon\Desktop\Global Agenda.url
[2011/06/18 17:46:55 | 026,836,992 | —- | M] () – C:\Users\Chameleon\Documents\Produce.mpg
[2011/06/16 22:54:34 | 000,322,552 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2011/06/16 12:14:30 | 000,754,836 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2011/06/16 12:14:30 | 000,640,344 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2011/06/16 12:14:30 | 000,118,564 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2011/06/16 01:23:11 | 000,000,221 | —- | M] () – C:\Users\Chameleon\Desktop\Spiral Knights.url
[2011/06/15 15:25:24 | 000,002,861 | —- | M] () – C:\Users\Chameleon\Desktop\nwcreport.php.htm
[2011/06/13 16:50:11 | 000,000,996 | —- | M] () – C:\Users\Chameleon\Application Data\Microsoft\Internet Explorer\Quick Launch\Smart Defrag 2.lnk
[2011/06/13 16:50:11 | 000,000,972 | —- | M] () – C:\Users\Public\Desktop\Smart Defrag 2.lnk
[2011/06/13 16:49:37 | 000,000,982 | —- | M] () – C:\Users\Chameleon\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk
[2011/06/13 16:49:37 | 000,000,970 | —- | M] () – C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2011/06/13 16:49:37 | 000,000,958 | —- | M] () – C:\Users\Public\Desktop\Game Booster.lnk
[2011/06/10 01:39:02 | 000,001,890 | —- | M] () – C:\Users\Public\Desktop\Skype.lnk
[2011/06/09 21:22:44 | 009,745,558 | —- | M] () – C:\Users\Chameleon\Documents\Chronotorious - 03 Rockin' On Heaven's Door.mp3
[2011/06/09 21:21:14 | 007,052,646 | —- | M] () – C:\Users\Chameleon\Documents\Chronotorious - 03 Rockin' On Heaven's Door.flv
[2011/06/09 11:47:17 | 015,207,576 | —- | M] () – C:\Users\Chameleon\Documents\Dissidia 012 Duodecim Final Fantasy_ Prishe Full Voice Data.mp3
[2011/06/09 11:44:45 | 022,083,652 | —- | M] () – C:\Users\Chameleon\Documents\Dissidia 012 Duodecim Final Fantasy_ Prishe Full Voice Data.flv
[2011/06/08 15:05:13 | 000,000,763 | —- | M] () – C:\Users\Public\Desktop\osu!.lnk
[2011/06/07 00:06:43 | 000,000,220 | —- | M] () – C:\Users\Chameleon\Desktop\Thief Deadly Shadows.url
[2011/06/06 19:43:07 | 006,351,767 | —- | M] () – C:\Users\Chameleon\Documents\mulan -I'll make a man out of you lyrics.mp3
[2011/06/06 19:39:14 | 009,630,680 | —- | M] () – C:\Users\Chameleon\Documents\mulan -I'll make a man out of you lyrics.flv
[2011/06/06 17:28:46 | 000,000,738 | -H– | M] () – C:\IPH.PH
[2011/06/06 17:28:15 | 000,001,717 | —- | M] () – C:\Users\Public\Desktop\AIM.lnk
[2011/06/06 12:13:07 | 000,404,640 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2011/06/04 19:34:21 | 008,690,327 | —- | M] () – C:\Users\Chameleon\Documents\Mulan _I'll Make a Man Out of You_ (English) No intro.mp3
[2011/06/03 12:53:55 | 000,000,877 | —- | M] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/06/03 12:52:47 | 000,198,848 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\rmoc3260.dll
[2011/06/03 12:52:09 | 000,005,632 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5032.dll
[2011/06/03 12:52:08 | 000,006,656 | —- | M] (RealNetworks, Inc.) – C:\Windows\SysWow64\pndx5016.dll
[2011/06/03 12:52:04 | 000,272,896 | —- | M] (Progressive Networks) – C:\Windows\SysWow64\pncrt.dll
[2011/06/03 12:51:58 | 000,499,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcp71.dll
[2011/06/03 12:51:58 | 000,348,160 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msvcr71.dll
[2011/06/02 13:32:00 | 000,001,190 | —- | M] () – C:\Users\Chameleon\Desktop\TerrariaServer - Shortcut.lnk
[2011/06/01 02:26:29 | 031,068,233 | —- | M] () – C:\Users\Chameleon\Documents\Mulan _I'll Make a Man Out of You_ (English) No intro.mp4
[2011/06/01 00:04:10 | 016,305,686 | —- | M] () – C:\Users\Chameleon\Documents\Mulan _I'll Make a Man Out of You_ (English) No intro.flv
[2011/05/31 00:38:28 | 000,000,219 | —- | M] () – C:\Users\Chameleon\Desktop\Portal 2.url
[2011/05/31 00:17:01 | 048,816,129 | —- | M] () – C:\Users\Chameleon\Documents\No More Heroes - Dr. Peace (CUT SCENES) - Rank 9.flv
[2011/05/30 22:50:02 | 000,000,221 | —- | M] () – C:\Users\Chameleon\Desktop\The Witcher 2 - Bonus Content.url
[2011/05/30 13:06:36 | 000,000,804 | —- | M] () – C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
[2011/05/29 22:28:28 | 005,682,493 | —- | M] () – C:\Users\Chameleon\Documents\Cows Mooing.flv
[2011/05/28 01:26:33 | 000,243,712 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\occache.dll
[2011/05/28 01:24:36 | 000,096,768 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2011/05/28 01:24:33 | 000,710,656 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2011/05/28 01:24:04 | 000,056,832 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\licmgr10.dll
[2011/05/28 01:23:47 | 001,538,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2011/05/28 01:23:30 | 000,219,136 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2011/05/28 01:23:30 | 000,132,096 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2011/05/28 01:23:29 | 000,077,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2011/05/28 01:23:29 | 000,072,192 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2011/05/28 01:23:28 | 000,252,416 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\iepeers.dll
[2011/05/28 01:07:19 | 000,206,848 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\occache.dll
[2011/05/28 01:04:59 | 000,066,560 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2011/05/28 01:04:56 | 000,602,112 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeeds.dll
[2011/05/28 01:04:30 | 000,043,520 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\licmgr10.dll
[2011/05/28 01:04:17 | 001,469,440 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2011/05/28 01:04:03 | 000,164,352 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2011/05/28 01:04:03 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2011/05/28 01:04:03 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2011/05/28 01:04:02 | 000,184,320 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iepeers.dll
[2011/05/28 01:04:02 | 000,055,808 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2011/05/28 00:33:37 | 000,479,232 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\html.iec
[2011/05/28 00:10:26 | 000,385,024 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\html.iec
[2011/05/27 23:53:37 | 000,162,816 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2011/05/27 23:53:19 | 000,070,656 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2011/05/27 23:52:45 | 000,012,288 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\msfeedssync.exe
[2011/05/27 23:33:03 | 000,133,632 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2011/05/27 23:32:51 | 000,173,568 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ie4uinit.exe
[2011/05/27 23:32:15 | 000,013,312 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\msfeedssync.exe
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2011/06/21 13:31:19 | 001,309,375 | —- | C] () – C:\Users\Chameleon\Desktop\tdsskiller.zip
[2011/06/21 12:46:50 | 000,256,512 | —- | C] () – C:\Windows\PEV.exe
[2011/06/21 12:46:50 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2011/06/21 12:46:50 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2011/06/21 12:46:50 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2011/06/21 12:46:50 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2011/06/20 16:11:02 | 000,000,306 | —- | C] () – C:\Windows\tasks\RealUpgradeScheduledTaskS-1-5-21-3660194186-3126353062-2202063419-1000.job
[2011/06/19 00:08:41 | 000,001,002 | —- | C] () – C:\Users\Chameleon\Desktop\tMod.lnk
[2011/06/18 23:34:03 | 000,000,221 | —- | C] () – C:\Users\Chameleon\Desktop\Global Agenda.url
[2011/06/18 17:45:46 | 026,836,992 | —- | C] () – C:\Users\Chameleon\Documents\Produce.mpg
[2011/06/16 01:47:08 | 000,000,032 | R— | C] () – C:\ProgramData\hash.dat
[2011/06/16 01:23:11 | 000,000,221 | —- | C] () – C:\Users\Chameleon\Desktop\Spiral Knights.url
[2011/06/15 15:25:20 | 000,002,861 | —- | C] () – C:\Users\Chameleon\Desktop\nwcreport.php.htm
[2011/06/13 16:50:13 | 000,032,648 | —- | C] () – C:\Windows\SysNative\SmartDefragBootTime.exe
[2011/06/13 16:50:13 | 000,018,232 | —- | C] () – C:\Windows\SysNative\drivers\SmartDefragDriver.sys
[2011/06/13 16:50:11 | 000,000,996 | —- | C] () – C:\Users\Chameleon\Application Data\Microsoft\Internet Explorer\Quick Launch\Smart Defrag 2.lnk
[2011/06/13 16:50:11 | 000,000,972 | —- | C] () – C:\Users\Public\Desktop\Smart Defrag 2.lnk
[2011/06/13 16:49:37 | 000,000,982 | —- | C] () – C:\Users\Chameleon\Application Data\Microsoft\Internet Explorer\Quick Launch\Game Booster.lnk
[2011/06/13 16:49:37 | 000,000,970 | —- | C] () – C:\Users\Public\Desktop\Switch to Gaming Mode.lnk
[2011/06/13 16:49:37 | 000,000,958 | —- | C] () – C:\Users\Public\Desktop\Game Booster.lnk
[2011/06/10 01:39:02 | 000,001,890 | —- | C] () – C:\Users\Public\Desktop\Skype.lnk
[2011/06/09 21:22:14 | 009,745,558 | —- | C] () – C:\Users\Chameleon\Documents\Chronotorious - 03 Rockin' On Heaven's Door.mp3
[2011/06/09 21:21:14 | 007,052,646 | —- | C] () – C:\Users\Chameleon\Documents\Chronotorious - 03 Rockin' On Heaven's Door.flv
[2011/06/09 11:46:45 | 015,207,576 | —- | C] () – C:\Users\Chameleon\Documents\Dissidia 012 Duodecim Final Fantasy_ Prishe Full Voice Data.mp3
[2011/06/09 11:44:44 | 022,083,652 | —- | C] () – C:\Users\Chameleon\Documents\Dissidia 012 Duodecim Final Fantasy_ Prishe Full Voice Data.flv
[2011/06/08 15:05:13 | 000,000,763 | —- | C] () – C:\Users\Public\Desktop\osu!.lnk
[2011/06/07 00:06:43 | 000,000,220 | —- | C] () – C:\Users\Chameleon\Desktop\Thief Deadly Shadows.url
[2011/06/06 19:42:45 | 006,351,767 | —- | C] () – C:\Users\Chameleon\Documents\mulan -I'll make a man out of you lyrics.mp3
[2011/06/06 19:39:13 | 009,630,680 | —- | C] () – C:\Users\Chameleon\Documents\mulan -I'll make a man out of you lyrics.flv
[2011/06/06 17:28:15 | 000,001,717 | —- | C] () – C:\Users\Public\Desktop\AIM.lnk
[2011/06/04 19:33:45 | 008,690,327 | —- | C] () – C:\Users\Chameleon\Documents\Mulan _I'll Make a Man Out of You_ (English) No intro.mp3
[2011/06/03 12:53:55 | 000,000,877 | —- | C] () – C:\Users\Public\Desktop\RealPlayer.lnk
[2011/06/02 13:32:00 | 000,001,190 | —- | C] () – C:\Users\Chameleon\Desktop\TerrariaServer - Shortcut.lnk
[2011/06/01 02:23:45 | 031,068,233 | —- | C] () – C:\Users\Chameleon\Documents\Mulan _I'll Make a Man Out of You_ (English) No intro.mp4
[2011/06/01 00:04:08 | 016,305,686 | —- | C] () – C:\Users\Chameleon\Documents\Mulan _I'll Make a Man Out of You_ (English) No intro.flv
[2011/05/31 00:38:28 | 000,000,219 | —- | C] () – C:\Users\Chameleon\Desktop\Portal 2.url
[2011/05/31 00:16:57 | 048,816,129 | —- | C] () – C:\Users\Chameleon\Documents\No More Heroes - Dr. Peace (CUT SCENES) - Rank 9.flv
[2011/05/30 22:50:02 | 000,000,221 | —- | C] () – C:\Users\Chameleon\Desktop\The Witcher 2 - Bonus Content.url
[2011/05/30 13:06:36 | 000,000,804 | —- | C] () – C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
[2011/05/29 22:28:26 | 005,682,493 | —- | C] () – C:\Users\Chameleon\Documents\Cows Mooing.flv
[2011/05/18 22:46:28 | 000,750,254 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/05/10 21:15:02 | 000,139,128 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011/05/03 18:38:43 | 000,090,112 | —- | C] () – C:\Windows\lol.launcher.exe
[2011/05/03 18:38:43 | 000,090,112 | —- | C] () – C:\Windows\lol.launcher.admin.exe
[2011/04/09 18:55:28 | 000,179,261 | —- | C] () – C:\Windows\SysWow64\xlive.dll.cat
[2011/01/10 22:42:21 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2010/03/09 08:20:38 | 000,270,904 | —- | C] () – C:\Windows\SysWow64\PnkBstrB.exe
[2010/03/09 08:20:37 | 002,434,856 | —- | C] () – C:\Windows\SysWow64\pbsvc_bc2.exe
[2010/03/09 08:20:37 | 000,075,136 | —- | C] () – C:\Windows\SysWow64\PnkBstrA.exe
[2010/02/28 16:20:55 | 000,157,407 | —- | C] () – C:\Windows\hpoins27.dat
[2010/02/28 16:20:55 | 000,000,932 | —- | C] () – C:\Windows\hpomdl27.dat
[2009/11/15 14:47:56 | 000,000,268 | —- | C] () – C:\Windows\{789289CA-F73A-4A16-A331-54D498CE069F}_WiseFW.ini
[2009/10/20 22:27:29 | 000,117,248 | —- | C] () – C:\Windows\SysWow64\EhStorAuthn.dll
[2009/10/20 22:26:51 | 000,107,612 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchema.bin
[2009/10/20 22:26:13 | 000,368,640 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2009/10/13 06:56:12 | 000,001,460 | —- | C] () – C:\Users\Chameleon\AppData\Local\d3d9caps64.dat
[2009/10/13 06:56:09 | 000,008,592 | —- | C] () – C:\Users\Chameleon\AppData\Local\d3d9caps.dat
[2009/10/13 06:56:08 | 000,000,552 | —- | C] () – C:\Users\Chameleon\AppData\Local\d3d8caps.dat
[2009/10/11 21:22:45 | 000,104,448 | —- | C] () – C:\Users\Chameleon\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2009/09/13 11:43:30 | 000,000,258 | RHS- | C] () – C:\ProgramData\ntuser.pol
[2009/09/10 22:05:48 | 000,027,648 | —- | C] () – C:\Windows\SysWow64\AVSredirect.dll
[2009/08/11 20:22:49 | 000,033,136 | —- | C] () – C:\Windows\ASScrPro.exe
[2009/08/11 20:22:29 | 000,047,672 | —- | C] () – C:\Windows\AsScrProlog.exe
[2009/08/11 19:25:00 | 000,018,904 | —- | C] () – C:\Windows\SysWow64\StructuredQuerySchemaTrivial.bin
[2008/10/08 22:38:27 | 000,015,497 | —- | C] () – C:\Windows\snp2uvc.ini
[2008/09/19 06:41:00 | 000,000,010 | —- | C] () – C:\Windows\SysWow64\ABLKSR.ini
[2008/01/20 21:50:05 | 000,060,124 | —- | C] () – C:\Windows\SysWow64\tcpmon.ini
[2007/08/06 12:18:31 | 000,081,920 | —- | C] () – C:\Windows\PGMonitor.exe
[2006/11/02 10:37:05 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2006/11/02 07:37:14 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2006/11/02 07:24:17 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2006/11/02 07:18:17 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2006/11/02 04:47:54 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
========== LOP Check ==========
[2011/06/09 14:14:48 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\.minecraft
[2009/09/10 20:44:24 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\acccore
[2010/05/15 03:07:45 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Beat Hazard
[2010/01/24 16:33:04 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Bioshock
[2010/03/18 23:04:39 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Bioshock2
[2010/03/25 18:43:24 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\cYo
[2011/06/08 15:03:38 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Downloaded Installations
[2010/01/31 17:55:31 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\GetRightToGo
[2011/06/13 16:50:14 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\IObit
[2010/11/25 01:01:16 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\JAM Software
[2010/05/11 16:02:20 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\LolClient
[2009/12/05 00:44:59 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\MotioninJoy
[2010/04/25 14:10:00 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Mount&Blade;
[2010/04/25 18:11:26 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Mount&Blade; Warband
[2011/05/04 19:16:16 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Mount&Blade; With Fire and Sword
[2011/03/22 20:54:57 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Mumble
[2009/10/21 09:49:32 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\OpenOffice.org
[2011/02/25 02:11:04 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\Rift
[2011/01/20 00:11:43 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\runic games
[2010/12/12 02:35:14 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\SEGA Corporation
[2010/11/22 12:57:15 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\storytron
[2011/03/26 17:31:13 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\SystemRequirementsLab
[2011/06/18 23:38:33 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\TerrariaMod
[2011/06/09 23:37:58 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\TerrariaWorldViewer
[2011/03/11 17:07:05 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\The Creative Assembly
[2011/06/16 00:58:59 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\uTorrent
[2009/09/10 20:01:39 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\WinPatrol
[2011/04/25 18:09:32 | 000,000,000 | —D | M] – C:\Users\Chameleon\AppData\Roaming\XRay Engine
[2011/06/20 23:23:56 | 000,032,634 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
[2011/06/21 17:10:00 | 000,000,426 | -H– | M] () – C:\Windows\Tasks\User_Feed_Synchronization-{306F3F19-2941-4C0D-81FA-6F323DC8EEBE}.job
========== Purity Check ==========
========== Custom Scans ==========
< >
< %SYSTEMDRIVE%\*.* >
[2009/07/24 02:58:10 | 000,000,028 | —- | M] () – C:\addon.log
[2008/11/27 21:10:54 | 000,000,016 | —- | M] () – C:\app14.log
[2009/05/11 08:49:02 | 000,000,022 | —- | M] () – C:\app2.log
[2008/11/12 21:04:09 | 000,000,081 | —- | M] () – C:\app4.log
[2009/04/07 23:02:41 | 000,002,076 | —- | M] () – C:\ASUS_27140015.icm
[2009/04/11 01:36:36 | 000,333,257 | RHS- | M] () – C:\bootmgr
[2008/09/18 09:01:40 | 000,008,192 | R-S- | M] () – C:\BOOTSECT.BAK
[2011/06/21 13:25:03 | 000,021,113 | —- | M] () – C:\ComboFix.txt
[2009/08/11 20:36:36 | 000,018,483 | —- | M] () – C:\devlist.txt
[2009/06/23 01:28:11 | 000,000,027 | —- | M] () – C:\Driver.20
[2008/04/11 11:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2009/08/11 20:34:35 | 000,000,009 | —- | M] () – C:\Finish.log
[2009/05/27 01:02:07 | 001,048,576 | RH– | M] () – C:\G60VxAS.BIN
[2009/08/11 20:27:15 | 001,556,324 | —- | M] () – C:\if.log
[2009/09/25 20:56:04 | 000,087,616 | —- | M] () – C:\immacraaab_gs1444.vtf
[2009/08/11 20:12:57 | 023,789,568 | —- | M] () – C:\inject.log
[2009/08/11 20:12:57 | 023,065,984 | —- | M] () – C:\inject.log.txt
[2008/04/11 11:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2011/06/06 17:28:46 | 000,000,738 | -H– | M] () – C:\IPH.PH
[2008/09/19 06:33:21 | 000,000,003 | —- | M] () – C:\K522.txt
[2009/07/02 02:17:15 | 000,000,037 | —- | M] () – C:\Nero.Log
[2011/06/21 17:12:03 | 312,647,679 | -HS- | M] () – C:\pagefile.sys
[2009/08/11 07:29:03 | 000,000,146 | —- | M] () – C:\Pass.txt
[2009/06/19 07:10:05 | 000,003,502 | —- | M] () – C:\Patch.LOG
[2009/03/30 22:04:29 | 000,000,022 | —- | M] () – C:\RECOVERY.DAT
[2009/08/11 20:01:10 | 000,002,008 | —- | M] () – C:\RHDSetup.log
[2011/03/03 13:40:25 | 000,000,370 | —- | M] () – C:\rkill.log
[2009/08/11 20:03:00 | 000,000,209 | —- | M] () – C:\setup.log
[2008/09/19 06:43:09 | 000,000,268 | -H– | M] () – C:\sqmdata00.sqm
[2008/09/19 06:43:09 | 000,000,244 | -H– | M] () – C:\sqmnoopt00.sqm
[2006/05/13 11:22:24 | 000,000,005 | —- | M] () – C:\store.log
[2009/08/11 18:57:50 | 000,000,166 | —- | M] () – C:\SumHidd.txt
[2009/08/11 18:57:20 | 000,000,098 | —- | M] () – C:\SumOS.txt
[2011/06/21 13:32:27 | 000,063,472 | —- | M] () – C:\TDSSKiller.2.5.5.0_21.06.2011_13.31.56_log.txt
[2009/07/15 14:58:38 | 000,000,025 | —- | M] () – C:\v624.txt
[2009/05/20 21:44:34 | 000,000,043 | —- | M] () – C:\WindowsLive_US.TXT
< %systemroot%\Fonts\*.com >
[2006/11/02 10:06:41 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2006/11/02 10:06:41 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2006/11/02 10:06:41 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/11/05 20:39:10 | 000,037,665 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2006/09/18 16:35:48 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2011/05/10 07:10:59 | 000,040,112 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2008/12/05 00:55:20 | 000,307,560 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2008/01/20 22:21:59 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/03/08 23:52:40 | 000,000,355 | -HS- | M] () – C:\Users\Chameleon\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/11/07 11:45:13 | 000,232,501 | —- | M] () – C:\Users\Chameleon\Desktop\Minecraft.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
[2008/10/08 22:38:27 | 000,013,022 | —- | M] () – C:\Windows\snp2uvc.src
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Files - Unicode (All) ==========
[2011/03/28 20:26:31 | 003,653,015 | —- | M] ()(C:\Users\Chameleon\Documents\God Eater OST - Strategy Briefing (???.mp3) – C:\Users\Chameleon\Documents\God Eater OST - Strategy Briefing (作戦会.mp3
[2011/03/28 20:26:04 | 003,653,015 | —- | C] ()(C:\Users\Chameleon\Documents\God Eater OST - Strategy Briefing (???.mp3) – C:\Users\Chameleon\Documents\God Eater OST - Strategy Briefing (作戦会.mp3
[2011/03/28 20:14:54 | 004,497,047 | —- | M] ()(C:\Users\Chameleon\Documents\God Eater OST- Howl of the Wolf (????).mp3) – C:\Users\Chameleon\Documents\God Eater OST- Howl of the Wolf (狼の咆哮).mp3
[2011/03/28 20:14:33 | 004,497,047 | —- | C] ()(C:\Users\Chameleon\Documents\God Eater OST- Howl of the Wolf (????).mp3) – C:\Users\Chameleon\Documents\God Eater OST- Howl of the Wolf (狼の咆哮).mp3
========== Alternate Data Streams ==========
@Alternate Data Stream - 95 bytes -> C:\ProgramData\Temp:5C321E34
@Alternate Data Stream - 55920 bytes -> C:\ProgramData:$SS_DESCRIPTOR_LVVWVBGV0VFBTLX4D06YH7LVUTPXGJMBKE1R0WT1VH7E24F7PHCTVF4VMVFVV
X4VM
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:DFC5A2B2
< End of report >
Extras.txt
OTL Extras logfile created on: 6/21/2011 7:36:20 PM - Run 1
OTL by OldTimer - Version 3.2.24.1 Folder = C:\Users\Chameleon\Downloads
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 8.0.6001.19088)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
4.00 Gb Total Physical Memory | 3.07 Gb Available Physical Memory | 76.71% Memory free
8.17 Gb Paging File | 7.41 Gb Available in Paging File | 90.69% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 285.40 Gb Total Space | 46.37 Gb Free Space | 16.25% Space Free | Partition Type: NTFS
Drive E: | 7.91 Gb Total Space | 0.00 Gb Free Space | 0.00% Space Free | Partition Type: UDF
Drive F: | 931.51 Gb Total Space | 359.20 Gb Free Space | 38.56% Space Free | Partition Type: NTFS
Drive G: | 539.19 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS
Computer Name: CHA-PC | User Name: Chameleon | Logged in as Administrator.
Boot Mode: SafeMode with Networking | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html[@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %* File not found
cmdfile [open] – "%1" %* File not found
comfile [open] – "%1" %* File not found
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%* File not found
exefile [open] – "%1" %* File not found
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
https [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
inffile [install] – %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %* File not found
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1" File not found
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l File not found
scrfile [open] – "%1" /S File not found
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1 File not found
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
https [open] – "C:\Program Files (x86)\Mozilla Firefox\firefox.exe" -requestPending -osint -url "%1" (Mozilla Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" ()
Directory [Winamp.Bookmark] – "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] – "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] – "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = 9F 60 A8 70 8B 5E CA 01 [binary data]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== System Restore Settings ==========
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0
========== Firewall Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{08E72EB3-DDC5-4DBD-8104-124C59E61ED4}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{1916AFF7-6C41-4756-9285-F2E70FC63A46}" = lport=6969 | protocol=17 | dir=in | name=league of legends launcher |
"{30DA7857-F82B-4DB0-9CBD-C29E980357FD}" = lport=6890 | protocol=17 | dir=in | name=league of legends launcher |
"{326434D4-BF6A-4D3A-AB2A-06C759D44666}" = lport=6894 | protocol=17 | dir=in | name=league of legends launcher |
"{34688267-5189-4AF1-BD57-DAE262D39E87}" = lport=6947 | protocol=6 | dir=in | name=league of legends launcher |
"{347FE30C-C97F-46C3-8124-25F4C686767E}" = lport=8383 | protocol=6 | dir=in | name=league of legends launcher |
"{35F40154-9CBD-4281-8518-D1690386B52C}" = lport=8393 | protocol=6 | dir=in | name=league of legends lobby |
"{3E0B742F-5A94-4062-9F64-D2D858E91828}" = lport=6922 | protocol=17 | dir=in | name=league of legends launcher |
"{483ECB82-7B0D-4631-AADE-4CBD7CBDF8F2}" = lport=6890 | protocol=6 | dir=in | name=league of legends launcher |
"{53C03845-7D79-487E-B139-EAD54F6AD370}" = lport=1778 | protocol=17 | dir=in | name=hava service |
"{54759F23-FE2E-4B70-A131-8CE0563BEB22}" = lport=6959 | protocol=17 | dir=in | name=league of legends launcher |
"{561DE3BA-56D0-43B1-A8FF-DA7E1148029D}" = lport=8381 | protocol=17 | dir=in | name=league of legends launcher |
"{6C369BDD-29A5-40C4-81BB-EB2BD8E0D509}" = lport=6947 | protocol=17 | dir=in | name=league of legends launcher |
"{6C6E0A06-BE10-43B6-83E6-6A0D20BB5D3F}" = lport=6910 | protocol=6 | dir=in | name=league of legends launcher |
"{6CF8D1CF-C084-4972-BCFD-DF53B33FAA95}" = lport=6922 | protocol=6 | dir=in | name=league of legends launcher |
"{6D5F3133-B569-4B2C-AB62-C83DE9A3123F}" = lport=6919 | protocol=6 | dir=in | name=league of legends launcher |
"{6EB17246-ECE4-4BE3-A489-7D3E51C26307}" = lport=8390 | protocol=17 | dir=in | name=league of legends game client |
"{6EBA713B-E0E8-4455-9B97-05A500BD9807}" = lport=2869 | protocol=6 | dir=in | app=system |
"{71F723ED-D79B-45C8-B4DC-24BDBE0FB326}" = lport=8379 | protocol=6 | dir=in | name=league of legends launcher |
"{76E07CA3-1921-471B-8476-0C0F9F1D90F5}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{7C8F8C31-789A-474B-8466-884F8FBE19F1}" = lport=6910 | protocol=6 | dir=in | name=league of legends launcher |
"{802E4ED2-007A-432A-810C-924B012EF429}" = lport=8393 | protocol=17 | dir=in | name=league of legends lobby |
"{833BECE2-EA11-473F-865D-B9F7271F27BE}" = lport=8382 | protocol=6 | dir=in | name=league of legends launcher |
"{844A02A0-D4AE-442D-A5E6-B575D2DCF123}" = lport=8382 | protocol=17 | dir=in | name=league of legends launcher |
"{93CFDDFE-BD0C-45AE-826B-6AE69B2F41EE}" = lport=8382 | protocol=6 | dir=in | name=league of legends launcher |
"{957B2644-F24C-4A9E-A1AD-A3838AB97BA6}" = lport=6959 | protocol=6 | dir=in | name=league of legends launcher |
"{A3CDDDE6-3C1A-4484-8AC4-1AF0B5B54049}" = lport=6940 | protocol=17 | dir=in | name=league of legends launcher |
"{B7AFFBD6-0332-45FC-A4D3-5D6EEA2AF8EA}" = lport=8381 | protocol=6 | dir=in | name=league of legends launcher |
"{C73F74E9-1474-44E0-88CA-98B548625659}" = lport=6969 | protocol=6 | dir=in | name=league of legends launcher |
"{C8F21D5F-A1F9-4AC3-B6EB-23DA7CF9231E}" = lport=8383 | protocol=17 | dir=in | name=league of legends launcher |
"{C90CBA02-1409-4C6A-A690-25A8CBAA4F0B}" = lport=6940 | protocol=6 | dir=in | name=league of legends launcher |
"{DBEB6CF2-745A-4E19-AC5C-91D739BDD94D}" = lport=1900 | protocol=17 | dir=in | name=hava upnp udp service |
"{DD1F0A56-2586-4316-8E5F-60D724893CBF}" = lport=6910 | protocol=17 | dir=in | name=league of legends launcher |
"{E090F18B-C5D2-4063-A37C-3A5BA772CF3E}" = lport=8381 | protocol=6 | dir=in | name=league of legends launcher |
"{E0C69200-C589-441E-B01B-782C1A35DCAA}" = lport=6919 | protocol=17 | dir=in | name=league of legends launcher |
"{E3750D84-5977-40B3-8B2E-688075569A69}" = lport=8379 | protocol=17 | dir=in | name=league of legends launcher |
"{E62AB00A-80AF-449E-9EE7-15CF20B9362B}" = lport=2869 | protocol=6 | dir=in | name=hava upnp tcp service |
"{EA276EE8-DDB1-48F4-A0FD-E058E5389182}" = lport=8382 | protocol=17 | dir=in | name=league of legends launcher |
"{EF6E647E-BDFE-440A-87CC-1D03691FDBDA}" = lport=8381 | protocol=17 | dir=in | name=league of legends launcher |
"{F3F61B47-88FF-49F7-A2C3-5E987F030EB2}" = lport=6910 | protocol=17 | dir=in | name=league of legends launcher |
"{FE25361D-CB6B-4D2F-A9A8-0455EFE6DC8C}" = lport=6894 | protocol=6 | dir=in | name=league of legends launcher |
"{FF2A0017-E153-4571-BA03-DC0645974519}" = lport=8390 | protocol=6 | dir=in | name=league of legends game client |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{001964FC-66D7-48A5-8CE8-171BA511072B}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{001DC0DB-A04C-40D3-A5F3-B3D991ED6AB3}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{009FA32C-7CF4-44E5-84AF-40C14E003968}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\launcher.exe |
"{0299C55D-A463-4747-97BD-F707F95C9DC5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alpha protocol\aplauncher.exe |
"{0496557F-33DF-4585-B9F0-4BB14D4A180E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{04ACF575-8A4C-443F-8A76-0C3E9FFDEF86}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{06BD72C9-123F-4985-8990-3833536D6145}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{075A764B-0C37-4EF7-9AFF-15D8ADDA0427}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alpha protocol\aplauncher.exe |
"{0865D3CF-1660-461A-BFAD-5A0C8E474817}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\crysis 2 - demo\bin32\crysis2demo.exe |
"{0EE837DA-005A-402A-B986-0CFE80DDDEBA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\launcher.exe |
"{0F52DFE0-0775-46DC-A586-64A21C7AB1D2}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{1285359D-D7D3-4791-9E26-98D1A5BC81D6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brink\brink.exe |
"{12A1322E-EBDE-4CB8-8E46-070C57DC6E05}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fear ultimate shooter edition\fear.exe |
"{138C9F4A-836C-4400-876B-75C3BBC98AC5}" = protocol=6 | dir=in | app=c:\windows\lol.launcher.exe |
"{14C0086F-FFD4-4272-A599-BD63216D766D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fear ultimate shooter edition\fear.exe |
"{14FDF285-E9FB-4761-B6D8-2A5C690A7CD9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |
"{16029DAA-FF2D-4A6A-8A4F-70428B0A3DD3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction guerrilla\rfg_launcher.exe |
"{1A13C35C-CA68-4B13-AAD8-1E8D8CD06F17}" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{1C90953C-4138-4837-96E5-273E34CCF111}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief deadly shadows\system\runme.exe |
"{1CF1F912-F7D9-4597-8B5E-FA2B8A0F859F}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{1FBB3798-4033-486F-99FD-5908A05606FD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lead and gold gangs of the wild west\lag_win32_public_dev.exe |
"{20F6D83D-5446-46B6-AC52-68CD5257BDA2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
"{216973AD-A1C6-42BE-AD4C-45F061567C98}" = protocol=6 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{25B6424C-9CBD-4551-95F9-501CFDB204A4}" = protocol=17 | dir=in | app=c:\windows\game\league of legends.exe |
"{25E0E730-1590-4A7F-BD65-C6AA3FFCE3A6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{26A50C08-AB35-4AB9-809E-00CB22CA82FF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead rising 2\deadrising2.exe |
"{26DDD45C-0DBB-4C3A-84CF-E180204F8846}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe |
"{2724F4CB-4E80-4A34-A97E-2B687F4D7BFD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |
"{2761BAC8-43CE-4EC7-8288-45AF19E849F8}" = protocol=17 | dir=in | app=c:\windows\game\league of legends.exe |
"{2A52A791-67C2-4495-81BE-062569F8C8ED}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{2C410537-3101-45E4-B6D7-E033B75D298F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\just cause 2\justcause2.exe |
"{2C826D4F-87A5-4ED8-91EA-3A05C4148313}" = protocol=6 | dir=in | app=c:\windows\air\lolclient.exe |
"{2CECEAE0-2018-456B-A6C9-C16417637323}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\spiral knights\java_vm\bin\javaw.exe |
"{2E3403DA-5962-4015-B4A1-673B7BAD1745}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout 3\falloutlauncher.exe |
"{3064AE63-A38E-4C59-9576-75F225874760}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swkotor\swkotor.exe |
"{3073447A-BB19-4A2A-8C91-5BB77FF94ADC}" = protocol=17 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
"{3236F9E8-65B8-41EC-B411-B902655FD46A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |
"{3374FFE6-5BA3-447D-97F5-119D3381963B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\total war shogun 2 demo\shogun2.exe |
"{360C2891-A655-4E1D-8D81-17139EC071E4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\help.htm |
"{38E90E57-67E0-45F2-85F8-8C7F1912D1A9}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{394FEAF7-F9C4-4978-9794-2AA410F2A772}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brink\brink.exe |
"{3D401BDF-A4B5-4AB4-9266-7D3EFDDCC4F2}" = protocol=6 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{3F8ACB7C-04DA-4F79-8E27-92B80C4C38A9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
"{486D611B-F429-431E-8CE2-92DAFB2FBA86}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{4A1EE20F-8194-4677-9892-B32FEEFE1805}" = protocol=17 | dir=in | app=c:\windows\air\lolclient.exe |
"{4BE47254-4EEB-4094-8E9C-F12C433273E2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mount & blade with fire and sword\mb_wfas.exe |
"{4BFDDC24-FF9B-49D3-BC5B-EDDC2FE9226D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{4CB660D6-267E-42D3-A557-30EE6DF5B922}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\globalagenda.exe |
"{4DEAFC76-2B80-4A84-BF28-AD7868C40ECD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\globalagenda.exe |
"{4FBEA574-5325-4A75-876F-02F7093BAA53}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\launcher.exe |
"{5115A506-EA85-4E0C-BD38-E6A44C37376B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\total war shogun 2 demo\shogun2.exe |
"{5882EFC3-005E-4258-BAFE-8E7378994BC5}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{58CD2D93-C554-48CA-B7B1-84AA989011D5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\red faction guerrilla\rfg_launcher.exe |
"{5A0664FB-43A9-44A2-B8D1-8CACC7575832}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\dead space.exe |
"{5F7A9BA9-7971-42E4-A94A-D91B3B44F339}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\binaries\masseffect.exe |
"{604558AE-CFC0-48B7-B012-8DED35415D54}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe |
"{61A1F245-B196-4970-94FF-E0CA120CDF9F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |
"{64F5EA8A-72D4-4A9F-BAA2-3FA2CCF523C3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\bmlauncher.exe |
"{661AFF46-2EDB-4706-A91B-5E888CA72691}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\djinni!.exe |
"{678B2DC7-5E17-435D-B4EA-7E907787AD82}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{6B862157-8058-4517-A44B-A3EC69518448}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\launcher.exe |
"{6CC0958F-14CD-45C2-99A3-696915D3BD0D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock\builds\release\bioshock.exe |
"{6DC7F18E-04F3-4A14-B0DA-D2F3703243DD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{6F66EFBB-0075-4E65-BBC9-85996732AEB3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\just cause 2\justcause2.exe |
"{708E5B8D-804C-4375-997A-29FB09E270C2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\crysis 2 - demo\bin32\crysis2demo.exe |
"{70B3FE43-EA2F-4181-B7BE-383F60F1FB5F}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{71B76490-6D9E-4920-B15F-FDAFEF50F8DA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brink\brink.exe |
"{73A3CAEE-DB40-4571-AF00-873864FDEFF1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{748A73BB-8DBC-4BBA-82EB-5C7247AC1F3C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{76713048-8981-4DAC-B5B9-4EE4B0B69E3D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iv beyond the sword\beyond the sword\civ4beyondsword.exe |
"{76CE4320-9867-486F-B3A7-213EC56500FE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{78CC49E2-BDB0-4481-95B1-1F15FF167DD0}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe |
"{7AED2ACA-253E-464C-B3B7-C5D424744D4A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |
"{7B51A294-42F0-4077-965B-EBC0DE48A091}" = protocol=17 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{7D3BF2F5-CE2C-4B26-921C-BA6F80A32B97}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\stalker call of pripyat\stalker-cop.exe |
"{7F6BC6BE-E901-4D88-8827-DFB85A635FFB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fear ultimate shooter edition\fearxp2\fearxp2.exe |
"{7FC18DF3-53BA-46E4-905C-B099FBBCC5DC}" = protocol=6 | dir=in | app=c:\windows\game\league of legends.exe |
"{7FCAE4F5-5768-4E25-84F1-3837B195E9AE}" = protocol=6 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"{804669C9-CBF0-467F-B978-0EB49A670353}" = protocol=6 | dir=in | app=c:\windows\game\league of legends.exe |
"{81243262-C671-4BEF-9B37-5C8EFC0B3A5A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"{816C78E8-1342-4D52-9BB9-64D206855A19}" = protocol=17 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{83914562-F010-4F2A-80EF-F1F82C4C5494}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\launcher.exe |
"{83FECF65-DDA6-4C99-938A-465E5EF1570A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iv\civilization4.exe |
"{85549A6A-51F9-4AB7-881C-309AB9E371A2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\dead space.exe |
"{85ACDFBB-6B94-4963-B36A-D2968D949711}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{86EAA61E-29F3-4437-8758-953BCBD8DC2C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mountblade warband\mb_warband.exe |
"{8824565B-6E6E-44CF-BB7E-658129AC3E74}" = protocol=6 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{8A427AFB-F139-446B-9C3A-2FE1A72F0E64}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"{8A8849EB-B591-4A46-8198-8B10AA891B6E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex\system\deusex.exe |
"{8C0E4E17-6968-4F13-A620-A7F12943B1C3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rift\riftpatchlive.exe |
"{8C5465A8-98B3-4F45-8767-729171FA4F6D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{8EAEB658-202E-4EC8-9D4F-E3DA83149862}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{900F0C75-4552-4670-8609-1F79F407CDCE}" = protocol=17 | dir=in | app=c:\windows\air\lolclient.exe |
"{923749DC-538B-43C6-932A-3F6D6884E6B2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |
"{924FE9AC-52A0-4C5E-A5D6-AD8C504C8DBE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's pirates!\pirates!.exe |
"{941C774D-FFCA-49D8-A78B-A121CAA2E54B}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{94E16FEC-9385-4F0D-8254-5A006C53C326}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{979AAE3A-6D8D-46AC-8AB5-26F40CCAB37D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |
"{98F49112-2081-4A97-9CBB-2654535FBFEB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rift\riftpatchlive.exe |
"{99078532-D8D9-4C65-844C-FFA866AF423F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{9995F195-AB11-4087-81F3-7E12A4F4BA55}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\bonuscontent\launch.bat |
"{9C1E16B1-7C94-432E-AA6F-33ACD9E700D1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead rising 2\deadrising2.exe |
"{9CE096AD-2D55-4F32-8A9C-6534514D84D5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iv beyond the sword\beyond the sword\civ4beyondsword.exe |
"{9F8ADEF7-B4F7-4354-AA74-DE5D7A7BF840}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mount & blade with fire and sword\mb_wfas.exe |
"{A04BAFFB-EC90-469E-B477-A1C0F517C662}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{A0CFC9C1-A5D2-4C72-9AD9-548062C0F05B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{A71CE0C7-FE87-4AA3-89EF-C55CC0CFB03B}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{AA056A07-4F8C-491B-8054-64A6D01FE24E}" = protocol=17 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{AAE2C869-7CD7-4924-AA41-F3937F5FCC4B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{AB6C5EBB-D68B-44FB-B9EF-DF7DF34C939B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex\system\deusex.exe |
"{AE01CC64-FA8B-4213-942F-0F1B6C857B7B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |
"{AE1FCA29-F2F7-4DF0-9B37-E37A45F0EAA7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{AE243AF2-DFD7-4C0E-AD2D-F9CC60DEEC47}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |
"{AE281F3B-5E12-4815-A48B-FC1503DC6C10}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock\builds\release\bioshock.exe |
"{AE9FC146-F51F-41A7-8CC6-A1EEDE5CC7A9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{B25E878C-FC7C-46C2-BD12-8321BF56E00D}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |
"{B33CE3B7-08A1-4971-96AC-BAB0572E4B8E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |
"{B4070CE4-D13A-4D5E-A63D-265A1A4283BA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout 3\falloutlauncher.exe |
"{B6135776-06C5-429D-8101-69906BC407C8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lead and gold gangs of the wild west\lag_win32_public_dev.exe |
"{B8E601F4-C3AA-4693-A1CD-B81C25268E18}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mountblade warband\mb_warband.exe |
"{B9CFA702-41AE-468D-A65E-32DFBBDF169D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\binaries\masseffect.exe |
"{BA520CEF-872F-4F10-86BB-D2B1039EED74}" = protocol=6 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |
"{BAB3B2C7-7AF1-4CBA-BE0E-F6E8612658CB}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base16755\sc2.exe |
"{BC54265A-6CC6-40C7-8658-DB7AE7D9AA9C}" = protocol=17 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"{BC86F908-261C-405D-B231-069613C6C44E}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{BE47BE6E-2582-432F-9B10-432EAD334F1A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\brink\brink.exe |
"{BE6520CA-F130-44D2-AB77-5E7DEA613ACE}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |
"{BF54D443-FE53-4A4D-83A6-64728DABAC90}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{C078DF96-DA02-4E94-91FE-B7744B823F58}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iv beyond the sword\beyond the sword\civ4beyondsword.exe |
"{C1CEA4AF-BE88-4EE6-87A0-BB8ED120DA45}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\help.htm |
"{C50ACF01-7B2B-4BD4-882B-3008E588ED25}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\counter-strike source\hl2.exe |
"{C5633F80-CF3B-41ED-9D7D-25E5427D12CA}" = protocol=17 | dir=in | app=c:\windows\lol.launcher.exe |
"{C904D985-97F9-4B27-AE56-2203AAD90802}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iv\civilization4.exe |
"{CE2958C8-9EE1-463D-92D5-6F94B879EF1F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\globalagenda.exe |
"{CE9F688A-3E92-473C-8981-F2E163488D64}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fear ultimate shooter edition\fearxp2\fearxp2.exe |
"{CF2142F2-4FE8-4A05-9DA9-D18CEF867A9C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\monday night combat\binaries\win32\mnc.exe |
"{CF56036B-B8D8-4237-8CBA-C7FBA687F0E3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\monday night combat\binaries\win32\mnc.exe |
"{D0E1D89D-817F-45BA-927D-31E8E695C57F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\djinni!.exe |
"{D3229D39-F86E-422E-AE9F-DA83C7501516}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\launcher.exe |
"{D3C9B251-FAAE-470A-9FD1-7B425D48618A}" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe |
"{D3DDF78E-9BFE-4FE0-944C-B0FA541FFCEC}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\aol\loader\aolload.exe |
"{D5D9176E-F582-46CA-9F7C-5A56DBD53D0E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\bmlauncher.exe |
"{D774BCEE-5D85-41D7-9682-01B1C23E1293}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |
"{D81E5CE0-0353-43D5-B90F-BAB8E1D06224}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{DC57E94D-39D0-483D-A748-B371D9782D82}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{DD1D07D7-C063-494F-8CAB-0E00BA002D82}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\witcher.exe |
"{DD335C26-EE38-4810-A82F-89AB14E73FBB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's pirates!\pirates!.exe |
"{DD367EBA-89BE-4406-901C-844E825BCA4E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |
"{DDEE983D-120B-4113-9462-892C85AA0CBB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |
"{E0D57ECA-775E-4C10-8BCC-EDAE9535E9A1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swkotor\swkotor.exe |
"{E36C02DC-922E-4F0B-9D24-231D0027F40D}" = protocol=17 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |
"{E792FCC1-3CCE-47FF-B07F-9A13F3EAE772}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base16755\sc2.exe |
"{E813A8FA-65D9-4A8E-9C74-4C1E0A669C90}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |
"{E8D69578-3689-4822-9F85-76F66A3685EC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{E91EDA45-93D8-46A7-B37F-DA9FD35B9158}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher enhanced edition\system\witcher.exe |
"{E970D097-21B0-4D83-9BC3-F176130F810B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe |
"{E9BA4055-140B-4073-B724-109AC3582A6A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{E9C6EC3A-7ABD-4D31-A397-4DBB5D350285}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |
"{EB8B422A-06D6-457A-B599-61701C67FF0D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\thief deadly shadows\system\runme.exe |
"{EEC3055F-9FA2-41A9-9110-809DB96F02B0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |
"{EFE49E39-670C-4375-BD5F-1EEA583B7EAA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard demo\beathazarddemo.exe |
"{F1D7389B-C6B0-4C2B-81F6-28C11E194252}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |
"{F31940F9-A64B-485D-981B-526C56271B75}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\counter-strike source\hl2.exe |
"{F3A5EFED-45C2-4048-8856-B13A641EC8B2}" = protocol=6 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |
"{F3BB7A1B-0B9A-45CA-82F6-E860DC094CB3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swkotor\swkotor.exe |
"{F3D2E59F-CE61-4AC1-8E11-5873C6CFCC6A}" = dir=in | app=c:\program files (x86)\windows live\messenger\wlcsdk.exe |
"{F7F1B830-7F4F-4177-ADD5-7AB60E5344CC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{F7F9DB58-31EF-4418-9476-50133F4C7EBB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |
"{F8C3B869-01E3-4C46-BD87-7CF297CB7F5B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard demo\beathazarddemo.exe |
"{F97805F8-8353-4E2C-832E-294E81694BD8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization iv beyond the sword\beyond the sword\civ4beyondsword.exe |
"{FCC57F12-795D-49A6-B109-AE5BB68DE93F}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |
"{FD74C1FC-26CC-4423-8162-DADA7159D068}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\bonuscontent\launch.bat |
"{FE0E4DC8-B4C3-49B0-B2D8-41FFC7E5C6BA}" = protocol=6 | dir=in | app=c:\windows\air\lolclient.exe |
"{FE1FD12C-C8DE-4E59-80BA-A740CAB5961F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\globalagenda.exe |
"{FFE602FA-0A93-49F3-B8DC-E3A087D1414B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swkotor\swkotor.exe |
"TCP Query User{034734D8-A4A2-4C95-B14C-D2A829F5316D}C:\program files (x86)\squareenix\final fantasy xiv\ffxivboot.exe" = protocol=6 | dir=in | app=c:\program files (x86)\squareenix\final fantasy xiv\ffxivboot.exe |
"TCP Query User{04345BF4-AD0E-48D7-8ABB-E41D56620EE2}C:\program files (x86)\interplay\fallout tactics\bos.exe" = protocol=6 | dir=in | app=c:\program files (x86)\interplay\fallout tactics\bos.exe |
"TCP Query User{09240C58-F6E9-420D-BAD3-CFC8B53AF139}C:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe |
"TCP Query User{11611FC8-9064-433B-BA11-48E014087AF4}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe |
"TCP Query User{165E8561-F04F-4A0A-AF05-2991825E8DE6}C:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
"TCP Query User{1A4BBEBB-5CCD-41B5-A91D-AE7A82E3D17A}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe |
"TCP Query User{1E640592-3A4B-4D9E-87B5-7CA4EA43E8B3}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe |
"TCP Query User{1E8C893F-5E11-45D2-BE86-1FB3BCB81A3A}C:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe |
"TCP Query User{1FE13BB2-F89D-4DC8-8A82-87EF6C7D34A7}C:\program files (x86)\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
"TCP Query User{2ACD3F63-5230-4404-AA34-5011413E59BA}C:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe |
"TCP Query User{355C47F1-A7D1-46F8-A907-F421494C1083}C:\users\chameleon\downloads\starcraft_2_na_en-us(2).exe" = protocol=6 | dir=in | app=c:\users\chameleon\downloads\starcraft_2_na_en-us(2).exe |
"TCP Query User{37B419B5-EB36-41E6-BCCE-4D6F5B3718C8}C:\program files (x86)\steam\steamapps\common\dead space 2\deadspace2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space 2\deadspace2.exe |
"TCP Query User{3F1A7609-E54E-4CFB-8174-CD6564D8D25D}C:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe |
"TCP Query User{405FAEF6-89A0-422A-8D4A-23A98142BC5B}C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe |
"TCP Query User{4072D61A-8F8B-4312-BC49-A3B5A23CFCA1}C:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
"TCP Query User{41D702F6-BCC1-4924-A59D-348AE61E05A9}C:\program files (x86)\starcraft ii\versions\base16939\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base16939\sc2.exe |
"TCP Query User{42C760C5-5E29-4391-AAD2-08ECF326A7DB}C:\users\chameleon\downloads\starcraft_2_na_en-us.exe" = protocol=6 | dir=in | app=c:\users\chameleon\downloads\starcraft_2_na_en-us.exe |
"TCP Query User{46AC67B7-AEE7-40FA-AA54-13BDD9500847}C:\program files\comicrack\comicrack.exe" = protocol=6 | dir=in | app=c:\program files\comicrack\comicrack.exe |
"TCP Query User{57C9789F-3752-46C1-A4C7-B284EF0BA03B}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe |
"TCP Query User{5F07BE8C-4E15-4A50-866A-F5CBF85EC8B1}C:\program files (x86)\steam\steamapps\ultima_weapon33\source 2007 dedicated server\srcds.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\source 2007 dedicated server\srcds.exe |
"TCP Query User{620AABCF-CD3B-4D4E-A420-1ACCC46E4868}C:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe |
"TCP Query User{623AB92A-2484-418D-9609-36B6AB54F9E2}C:\riot games\league of legends\lol.launcher.exe" = protocol=6 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"TCP Query User{62DE1CB2-FA5D-45B1-8E93-9F02ACCED88C}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"TCP Query User{6862131A-7F87-400C-9688-347E2EA8BE19}C:\program files (x86)\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mirc\mirc.exe |
"TCP Query User{705C1A76-BA47-4A8C-992C-7BB71E8F003A}C:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe |
"TCP Query User{70B37E55-DC04-4D4B-BBAE-6E234BDE5BA9}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe |
"TCP Query User{719F393E-67E5-4594-837F-16CB160774C4}C:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe |
"TCP Query User{73773757-73B7-42A0-ADDC-EB1FFC6F2BC2}C:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe |
"TCP Query User{7426683E-B084-4D94-A903-BFD2AE4E4DD0}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe |
"TCP Query User{7EF99E23-EF91-4809-BD79-F7EC141CA959}C:\program files (x86)\starcraft ii\versions\base18574\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18574\sc2.exe |
"TCP Query User{8C92ACBA-0571-4E42-A05B-BBCDDCDC66E2}C:\program files (x86)\steam\steamapps\common\altitude\altitude.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\altitude\altitude.exe |
"TCP Query User{8CF5BA9E-FF5D-4E35-B99F-BF0F3545617D}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"TCP Query User{95076591-2EFF-4A00-A602-AADB07427A86}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe |
"TCP Query User{A5991553-4329-4B2A-A0A2-1187777FAE32}C:\users\chameleon\downloads\starcraft_2_na_en-us.exe" = protocol=6 | dir=in | app=c:\users\chameleon\downloads\starcraft_2_na_en-us.exe |
"TCP Query User{A8EA534B-E708-4BAC-84E6-EFD0631C3E89}C:\program files\comicrack\comicrack.exe" = protocol=6 | dir=in | app=c:\program files\comicrack\comicrack.exe |
"TCP Query User{B59D4743-647F-4CF5-B448-853C20AA08EC}C:\program files (x86)\winamp\winamp.exe" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"TCP Query User{BB1F3A9C-E811-4CA3-AFC1-5F0C6DCE1CCC}C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe |
"TCP Query User{BCDAAEC3-AE56-4CFB-A55C-C2DC2BC8EB6C}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe |
"TCP Query User{C1FB1E44-0031-49A8-A2B6-5CE08B7662C5}C:\program files (x86)\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
"TCP Query User{C2FBC567-E20F-4854-AC78-FEC2C1B4302E}C:\program files (x86)\steam\steam.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"TCP Query User{C77C1DC5-C2F7-4F11-90EE-46FB714801C0}C:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_c558aa83b9a650d4\tmod.exe" = protocol=6 | dir=in | app=c:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_c558aa83b9a650d4\tmod.exe |
"TCP Query User{C7C7459C-2FE6-4883-8580-371F4A65BCEA}C:\program files (x86)\steam\steamapps\common\altitude\altitude.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\altitude\altitude.exe |
"TCP Query User{CC423869-7D91-464C-9D29-85398EA84622}C:\riot games\league of legends\lol.launcher.exe" = protocol=6 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"TCP Query User{D86510C7-7BA3-44C5-B945-33925B693FF2}C:\program files (x86)\steam\steamapps\common\terraria\terraria.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"TCP Query User{DD8148BB-1FCA-48A8-922C-F1C4F15DD2F8}C:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx9.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx9.exe |
"TCP Query User{DFADF842-A1C7-4DDF-B92C-3CE86C3873AE}C:\program files (x86)\starcraft ii\versions\base16939\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base16939\sc2.exe |
"TCP Query User{E262ED6E-482C-456F-96F7-698797FADB57}C:\program files (x86)\aim6\aim6.exe" = protocol=6 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"TCP Query User{E41BF951-2A85-43F9-9D2B-7E8CF39BB627}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe |
"TCP Query User{EC928031-9708-42B3-B7AF-C9865F87A2CF}C:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe |
"TCP Query User{F128A92F-2A7B-48CE-8157-1A09987CD1DF}C:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe |
"TCP Query User{F781A091-9FEA-46C8-9D2E-CAD307A3A545}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"TCP Query User{F822738F-83EA-4E63-BF91-8510E64ECE6D}C:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_b6908e294fd27714\tmod.exe" = protocol=6 | dir=in | app=c:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_b6908e294fd27714\tmod.exe |
"TCP Query User{FF9A6101-D35E-4762-AA58-7C50AF5E4CD2}C:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe |
"UDP Query User{02E3C03A-685B-4763-8478-260082459DC3}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe |
"UDP Query User{030F09AF-99A7-4044-830D-870894741B19}C:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
"UDP Query User{057C4EEA-A677-47BE-99B9-858309800307}C:\users\chameleon\downloads\starcraft_2_na_en-us.exe" = protocol=17 | dir=in | app=c:\users\chameleon\downloads\starcraft_2_na_en-us.exe |
"UDP Query User{0FA57773-63C4-4CD4-B7E2-F7E0217D0D23}C:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2 demo\left4dead2.exe |
"UDP Query User{226FA98A-26C2-493E-9C99-296A9EF5ACB4}C:\program files (x86)\starcraft ii\versions\base18574\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18574\sc2.exe |
"UDP Query User{2BE02504-8783-4401-89D1-021250389438}C:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_c558aa83b9a650d4\tmod.exe" = protocol=17 | dir=in | app=c:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_c558aa83b9a650d4\tmod.exe |
"UDP Query User{2D8ABEAF-04BE-410E-9A79-BD4980A63142}C:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe |
"UDP Query User{30679C93-F085-4921-BA82-70BA24F321A2}C:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\reliccoh.exe |
"UDP Query User{31BD0710-8721-4D55-8C28-7B34018FDAF1}C:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe |
"UDP Query User{3F504F97-59EB-4DF2-AD97-4351C7E72D71}C:\users\chameleon\downloads\starcraft_2_na_en-us.exe" = protocol=17 | dir=in | app=c:\users\chameleon\downloads\starcraft_2_na_en-us.exe |
"UDP Query User{504801CB-BACA-4E11-B645-6F73C26D3457}C:\program files (x86)\starcraft ii\versions\base16939\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base16939\sc2.exe |
"UDP Query User{5827E479-268A-4B69-8593-44831B602541}C:\program files (x86)\videolan\vlc\vlc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\videolan\vlc\vlc.exe |
"UDP Query User{5A56A753-542B-4DC0-9169-3F6FA8DDB6AC}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe |
"UDP Query User{6642B495-0ECE-4641-BB75-9F05E5BAF02A}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe |
"UDP Query User{6A0C775D-BBBB-461C-A933-A6374F7CB6BE}C:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe |
"UDP Query User{708BFC1A-BA8A-4733-910A-273891F31039}C:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe |
"UDP Query User{817E2A74-15C8-4455-AD69-5D39B407C0A1}C:\program files (x86)\steam\steamapps\ultima_weapon33\source 2007 dedicated server\srcds.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\source 2007 dedicated server\srcds.exe |
"UDP Query User{868D33DE-29BF-4A85-B33B-89E55A9AF1B9}C:\users\chameleon\downloads\starcraft_2_na_en-us(2).exe" = protocol=17 | dir=in | app=c:\users\chameleon\downloads\starcraft_2_na_en-us(2).exe |
"UDP Query User{8BB6B29C-7D42-4AC2-95E5-ED408C5D3F45}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe |
"UDP Query User{8FCF15F7-73E9-4D81-8D3D-A3B696D99150}C:\program files (x86)\starcraft ii\versions\base16939\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base16939\sc2.exe |
"UDP Query User{913ACC39-5862-4A04-9B42-E8252EDAD1B8}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"UDP Query User{9164E789-F777-45B3-A21C-3627B6D8D94F}C:\program files\comicrack\comicrack.exe" = protocol=17 | dir=in | app=c:\program files\comicrack\comicrack.exe |
"UDP Query User{95BA6079-5AAB-490B-B35E-E9F30CDBC982}C:\program files (x86)\aim6\aim6.exe" = protocol=17 | dir=in | app=c:\program files (x86)\aim6\aim6.exe |
"UDP Query User{9A1631F3-1A28-49FC-8233-754C90A92757}C:\program files (x86)\steam\steam.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"UDP Query User{9C69564C-0E7A-48DD-A8A4-F03F276FB185}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |
"UDP Query User{A1475F6E-BD17-4741-A075-BFA4D8B0E3A1}C:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe |
"UDP Query User{A9577645-1CF9-4294-8EBE-4468077AFD6D}C:\program files (x86)\steam\steamapps\common\altitude\altitude.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\altitude\altitude.exe |
"UDP Query User{B904FC79-0BCD-4781-9C33-5BCAF043E4B6}C:\program files (x86)\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mirc\mirc.exe |
"UDP Query User{BDA08904-4453-4654-B82B-14FE4482D5F5}C:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\company of heroes\relicdownloader\relicdownloader.exe |
"UDP Query User{BE67F50E-9C93-4BE2-B59C-5541EE534F65}C:\program files (x86)\steam\steamapps\common\altitude\altitude.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\altitude\altitude.exe |
"UDP Query User{BF8F4BE9-84CE-4995-80D1-1E6D7AAE4570}C:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe |
"UDP Query User{C2E71C4B-0E1E-4690-A43C-697FDADD7CD0}C:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\ultima_weapon33\team fortress 2\hl2.exe |
"UDP Query User{C62D37A9-5DC9-408F-ACE9-AB588E0B1965}C:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_b6908e294fd27714\tmod.exe" = protocol=17 | dir=in | app=c:\users\chameleon\appdata\local\apps\2.0\40l55rbm.3mt\6ebc5t40.4bc\tmod..tion_78560e3cafd11e84_0001.0003_b6908e294fd27714\tmod.exe |
"UDP Query User{C807EAE9-61AD-4B5C-A76D-CFF691286FAA}C:\program files (x86)\starcraft ii\versions\base18092\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base18092\sc2.exe |
"UDP Query User{CEB68492-D0FA-4DB4-9FED-67F5C6DF1844}C:\program files (x86)\steam\steamapps\common\terraria\terraria.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terraria.exe |
"UDP Query User{D3F2D478-50A0-4530-A5A5-A6B91EF60886}C:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe |
"UDP Query User{D6701D58-A6A8-49FA-9EE6-4F53279C5454}C:\program files (x86)\interplay\fallout tactics\bos.exe" = protocol=17 | dir=in | app=c:\program files (x86)\interplay\fallout tactics\bos.exe |
"UDP Query User{D84F58D2-4C62-461A-8B98-F00CCAFD5CFB}C:\program files\comicrack\comicrack.exe" = protocol=17 | dir=in | app=c:\program files\comicrack\comicrack.exe |
"UDP Query User{DAF0C6E9-D491-42FA-B82D-43AB35BEAFA2}C:\program files (x86)\starcraft ii\versions\base17326\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\versions\base17326\sc2.exe |
"UDP Query User{DEA99E92-8CA1-4D3D-B67C-0F25455CA38F}C:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx10.exe |
"UDP Query User{E32C0A62-78FD-4399-8ED6-0C982AE3C0D1}C:\program files (x86)\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\battlefield bad company 2\bfbc2game.exe |
"UDP Query User{E8E940BB-79C0-4F15-A2E1-D35044D49C91}C:\program files (x86)\squareenix\final fantasy xiv\ffxivboot.exe" = protocol=17 | dir=in | app=c:\program files (x86)\squareenix\final fantasy xiv\ffxivboot.exe |
"UDP Query User{EB03754D-5FA2-4A71-BFE9-3474E1338355}C:\program files (x86)\winamp\winamp.exe" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe |
"UDP Query User{EB2C4060-BF9F-43E3-ACC4-60789ED8B739}C:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx9.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\resident evil 5\re5dx9.exe |
"UDP Query User{ED41724B-CA4A-45CC-B25B-517DBBEA32E7}C:\riot games\league of legends\lol.launcher.exe" = protocol=17 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"UDP Query User{F3A4538C-0964-4511-8CDD-88F7ED8951BE}C:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\bin\witcher2.exe |
"UDP Query User{F3E552A4-9574-4CF6-B6BF-B9FB883C10CC}C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe |
"UDP Query User{F4D54F8E-41A5-41A0-935C-EEE67A6A4602}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"UDP Query User{F7772F90-0817-4476-BF61-8446374428A5}C:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\batman arkham asylum goty\binaries\shippingpc-bmgame.exe |
"UDP Query User{F9A79B77-44CD-4F8A-A93D-7645EE200F1E}C:\riot games\league of legends\lol.launcher.exe" = protocol=17 | dir=in | app=c:\riot games\league of legends\lol.launcher.exe |
"UDP Query User{FB10D8FA-D305-41D0-8D2A-2491AD1BD913}C:\program files (x86)\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect 2\binaries\masseffect2.exe |
"UDP Query User{FD8081F2-4D5D-4961-B6C1-7C87F30D83A8}C:\program files (x86)\steam\steamapps\common\dead space 2\deadspace2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space 2\deadspace2.exe |
"UDP Query User{FE55E179-C255-4EB0-B957-53CEA68C929D}C:\program files (x86)\starcraft ii\support\blizzarddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\support\blizzarddownloader.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{08D401E5-E23D-4372-8F9E-764963B19483}" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
"{1686C4D1-B1FD-42E8-B7A8-FB4C4DBA5BA8}" = ASUS Power4Gear Hybrid
"{20387B45-18A4-4D48-ABD9-A23D2CBE42B3}" = Dolby Control Center
"{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition)
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{48B0F24F-B828-4B1A-A22E-C65454B32A7A}" = Windows Live Family Safety
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6D41B4C4-FCD7-4F9B-99B9-A01F63F71F0F}" = Smart Technology Programming Software [removed]
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9B48B0AC-C813-4174-9042-476A887592C7}" = Windows Live ID Sign-in Assistant
"{9F560BEB-021F-43AC-825F-AA60442D8DE4}" = 64 Bit HP CIO Components Installer
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 266.58
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 266.58
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.10.0514
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{C74A84EC-7C5F-4C36-A4A6-381E516D643B}" = Microsoft IntelliPoint 7.0
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{D77D43B5-ED55-426b-B67B-E21F804F6102}" = HP Deskjet F2200 All-In-One Driver Software 10.0 Rel .3
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"ComicRack" = ComicRack v0.9.118
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.17
"Defraggler" = Defraggler
"HP Imaging Device Functions" = HP Imaging Device Functions 10.0
"HP Photosmart Essential" = HP Photosmart Essential 2.5
"HP Smart Web Printing" = HP Smart Web Printing
"HP Solution Center & Imaging Support Tools" = HP Solution Center 10.0
"HPExtendedCapabilities" = HP Customer Participation Program 10.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU" = Microsoft Visual Studio 2005 Remote Debugger Light (x64) - ENU
"Shop for HP Supplies" = Shop for HP Supplies
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"USB 2.0 UVC 1.3M WebCam" = USB 2.0 UVC 1.3M WebCam
"WinRAR archiver" = WinRAR archiver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{020D8396-D6D9-4B53-A9A1-83C47E2E27AA}" = Windows Live Call
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{0969AF05-4FF6-4C00-9406-43599238DE0D}" = ASUS Splendid Video Enhancement Technology
"{0AAA9C97-74D4-47CE-B089-0B147EF3553C}" = Windows Live Messenger
"{0F7C2E47-089E-4d23-B9F7-39BE00100776}" = Toolbox
"{111DB3F0-0C58-4475-9954-1BD5B7B28618}" = League of Legends
"{11B83AD3-7A46-4C2E-A568-9505981D4C6F}" = HP Update
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{18669FF9-C8FE-407a-9F70-E674896B1DB4}" = GPBaseService
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YouTube Downloader 2.7.1
"{1C8521E5-5A7B-4A4E-A9CD-AD53116EAEE0}" = ASUS Data Security Manager
"{1DBD1F12-ED93-49C0-A7CC-56CBDE488158}" = ASUS LifeFrame3
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{2208D65A-1BF9-485E-A308-1BA6CADCDC1D}" = Windows Live Movie Maker Beta
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{26A24AE4-039D-4CA4-87B4-2F83216020FF}" = Java™ 6 Update 24
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2B4C7E1E-E446-4740-ADB5-9842E742EE8A}" = Windows Live Toolbar
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{34BFB099-07B2-4E95-A673-7362D60866A2}" = PSSWCORE
"{36FDBE6E-6684-462b-AE98-9A39A1B200CC}" = HPProductAssistant
"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{3B05F2FB-745B-4012-ADF2-439F36B2E70B}" = ATKOSD2
"{40580068-9B10-40B5-9548-536CE88AB23C}" = ITECIR
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"{4343080E-448E-4E2C-B27F-B91000018201}" = Dead Rising 2
"{4343080E-448E-4E2C-B27F-B91000028201}" = Dead Rising 2
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4AB8B41B-3AF1-46BE-99B0-0ACD3B300C0A}" = Junk Mail filter update
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4CBA3D4C-8F51-4D60-B27E-F6B641C571E7}" = Microsoft Search Enhancement Pack
"{5109C064-813E-4e87-B0DE-C8AF7B5BC02B}" = SmartWebPrintingOC
"{52A69E11-7CEB-4a7d-9607-68BA4F39A89B}" = DeviceDiscovery
"{5335DADB-34BA-4AE8-A519-648D78498846}" = Skype™ 5.3
"{5454085C-840F-4070-8FAA-441000018301}" = BioShock 2
"{5454085C-840F-4070-8FAA-441000028301}" = BioShock 2
"{57F0ED40-8F11-41AA-B926-4A66D0D1A9CC}" = Microsoft Office Live Add-in 1.3
"{59F6A514-9813-47A3-948C-8A155460CC2A}" = RICOH R5C83x/84x Flash Media Controller Driver Ver.3.55.03
"{5A347920-4AFC-11D5-9FB0-800649886934}" = SDFormatter
"{5ACE69F0-A3E8-44eb-88C1-0A841E700180}" = TrayApp
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{63C1109E-D977-49ED-BCE3-D00D0BF187D6}" = Windows Live Mail
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{687FEF8A-8597-40b4-832C-297EA3F35817}" = BufferChm
"{6A92E5C5-0578-443D-91F3-92ECE5F2CAE2}" = Windows Live Writer
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71929EC1-FDB2-4A67-AAAD-936E4539FA84}_is1" = Driver Sweeper 2.1.0
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789289CA-F73A-4A16-A331-54D498CE069F}" = Ventrilo Client
"{7988ba74-4a27-4685-991a-53f072f22808}" = F2200_Help
"{7C05592D-424B-46CB-B505-E0013E8E75C9}" = ATK Hotkey
"{83F73CB1-7705-49D1-9852-84D839CA2A45}" = Wireless Console 2
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek 8169 8168 8101E 8102E Ethernet Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A74E887-8F0F-4017-AF53-CBA42211AAA5}" = Microsoft Sync Framework Runtime Native v1.0 (x86)
"{8A85DEAD-7C1F-4368-881C-72AC74CB2E91}" = UnloadSupport
"{8FFC5648-FAF8-43A3-BC8F-42BA1E275C4E}" = Choice Guard
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95C5F81D-0779-4932-BE83-32AAF814F4B9}" = League of Legends
"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A0B9F8DF-C949-45ed-9808-7DC5C0C19C81}" = Status
"{A11409F1-CD33-4076-85CB-4EE4A8439BFE}" = Scan
"{A2BCA9F1-566C-4805-97D1-7FDC93386723}" = Adobe AIR
"{A5AB9D5E-52E2-440e-A3ED-9512E253C81A}" = SolutionCenter
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AB6F4AB9-AC85-4002-9829-B6EEA55AE3A5}" = Microsoft Visual C++ 2005 Express Edition - ENU
"{AC76BA86-7AD7-1033-7B44-A81200000003}" = Adobe Reader 8.1.2
"{AE0259D4-7A01-4E47-BBAF-2604D03DF07C}" = LoJack Factory Installer
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Toolbars
"{B8DBED1E-8BC3-4d08-B94A-F9D7D88E9BBF}" = HPSSupply
"{B9DB4C76-01A4-46D5-8910-F7AA6376DBAF}" = NVIDIA PhysX
"{BAD0FA60-09CF-4411-AE6A-C2844C8812FA}" = HP Photosmart Essential 2.5
"{BCB4C18A-ACA6-4383-8688-E19933A705DD}" = Microsoft SOAP Toolkit 3.0
"{BD64AF4A-8C80-4152-AD77-FCDDF05208AB}" = Microsoft Sync Framework Services Native v1.0 (x86)
"{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}" = QuickTime
"{C3592426-531E-4110-911D-BFECE2CE284C}" = osu!
"{C4124E95-5061-4776-8D5D-E3D931C778E1}" = Microsoft VC9 runtime libraries
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{c6922d7f-c698-4d9e-9671-8b3de04d1511}" = DJ_AIO_03_F2200_Software_Min
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"{CCB9B81A-167F-4832-B305-D2A0430840B3}" = WebReg
"{D1E5870E-E3E5-4475-98A6-ADD614524ADF}" = ATK Media
"{D2E0F0CC-6BE0-490b-B08B-9267083E34C9}" = MarketResearch
"{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
"{D3D54F3E-C5C3-443D-978F-87A72E5616E8}" = ATK Generic Function Service
"{D99A8E3A-AE5A-4692-8B19-6F16D454E240}" = Destination Component
"{D9D754A1-EAC5-406C-A28B-C49B1E846711}" = Windows Live Essentials
"{db18dc72-cd20-4801-be82-f5d2caeec4d7}" = DJ_AIO_03_F2200_Software
"{DC905847-D537-427F-BF91-47CC7ACCDE58}" = ASUS FancyStart
"{DE10AB76-4756-4913-BE25-55D1C1051F9A}" = WinFlash
"{E08DC77E-D09A-4e36-8067-D6DBBCC5F8DC}" = VideoToolkit01
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E657B243-9AD4-4ECC-BE81-4CCF8D667FD0}" = ASUS Live Update
"{E6B87DC4-2B3D-4483-ADFF-E483BF718991}" = OpenOffice.org 3.1
"{e97a9fd7-2fa1-4474-820d-3f8893a5b78a}" = F2200
"{EC8BD21F-0CA0-4BBF-97D9-4A52B30041A1}" = ASUS Virtual Camera
"{eca3039b-e429-420f-bd5e-7dec0683fc32}" = DJ_AIO_03_F2200_ProductContext
"{EEF985E8-8B36-4230-B174-117A2381C17F}" = LogMeIn Hamachi
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F204E2B3-225D-419D-A5DE-3F97E8ADDD1B}" = Geek Squad 24 Hour Computer Support
"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable
"{F42CD69D-E393-47c8-B2CD-B139C4ADA9A8}" = Copy
"{F69E83CF-B440-43F8-89E6-6EA80712109B}" = Windows Live Communications Platform
"{F73A5B18-EB75-4B2C-B32D-9457576E2417}" = Windows Live Photo Gallery
"{F7FC9307-374E-4017-8E9D-DE1154780480}" = System Requirements Lab for Intel
"{FDD810CA-D5E3-40E9-AB7B-36440B0D41EF}" = Windows Live Sync
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"AIM_7" = AIM 7
"ALSee_is1" = ALSee
"ALUpdate_is1" = ALTools Update
"Asus_Camera_ScreenSaver" = Asus_Camera_ScreenSaver
"AutoHotkey" = AutoHotkey 1.0.48.05
"avast" = avast! Free Antivirus
"Call of Pripyat Complete_is1" = Call of Pripyat Complete v1.0.1
"Comical_is1" = Comical 0.8
"DragonUnPACKer5_is1" = Dragon UnPACKer 5
"Driver Cleaner Pro" = DH Driver Cleaner Professional Edition
"Fallout Collection" = Fallout Collection
"Fallout Mod Manager_is1" = Fallout Mod Manager 0.9.15
"Fraps" = Fraps (remove only)
"Game Booster_is1" = Game Booster
"HaaliMkx" = Haali Media Splitter
"HijackThis" = HijackThis 2.0.2
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = CyberLink Power2Go
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{AE0259D4-7A01-4E47-BBAF-2604D03DF07C}" = LoJack Factory Installer
"InstallShield_{C21D5524-A970-42FA-AC8A-59B8C7CDCA31}" = QuickTime
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = CyberLink PowerDirector
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = CyberLink PhotoNow
"LogMeIn Hamachi" = LogMeIn Hamachi
"MagicDisc 2.7.106" = MagicDisc 2.7.106
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Matroska Pack" = Matroska Pack
"Microsoft Visual C++ 2005 Express Edition - ENU" = Microsoft Visual C++ 2005 Express Edition - ENU
"mIRC" = mIRC
"Mozilla Firefox 4.0.1 (x86 en-US)" = Mozilla Firefox 4.0.1 (x86 en-US)
"Mumble" = Mumble and Murmur
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"PunkBusterSvc" = PunkBuster Services
"RealPlayer 12.0" = RealPlayer
"RivaTuner" = RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition
"ShockwaveFlash" = Adobe Flash Player 9 ActiveX
"Smart Defrag 2_is1" = Smart Defrag 2
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"SpywareBlaster_is1" = SpywareBlaster 4.4
"StarCraft II" = StarCraft II
"Steam App 105600" = Terraria
"Steam App 12910" = Audiosurf Demo
"Steam App 17020" = Global Agenda
"Steam App 18500" = Defense Grid: The Awakening
"Steam App 20500" = Red Faction: Guerrilla
"Steam App 20540" = Company of Heroes: Tales of Valor
"Steam App 20920" = The Witcher 2
"Steam App 20930" = The Witcher 2: Bonus Content
"Steam App 310" = Team Fortress 2 Dedicated Server
"Steam App 32370" = Star Wars: Knights of The Old Republic
"Steam App 35140" = Batman: Arkham Asylum GOTY Edition
"Steam App 3590" = Plants vs. Zombies: Game of the Year
"Steam App 3900" = Sid Meier's Civilization IV
"Steam App 40800" = Super Meat Boy
"Steam App 440" = Team Fortress 2
"Steam App 4560" = Company of Heroes
"Steam App 45740" = Dead Rising 2
"Steam App 550" = Left 4 Dead 2
"Steam App 620" = Portal 2
"Steam App 6980" = Thief: Deadly Shadows
"Steam App 8190" = Just Cause 2
"Steam App 8800" = Sid Meier's Civilization IV: Beyond the Sword
"Steam App 99900" = Spiral Knights
"SUPER ©" = SUPER © Version 2009.bld.36 (June 10, 2009)
"SystemRequirementsLab" = System Requirements Lab
"The Witcher - Scabbard Mod_is1" = Scabbar Mod ver 1.03
"TreeSize Free_is1" = TreeSize Free V2.5
"Unofficial Oblivion Patch_is1" = Unofficial Oblivion Patch v3.2.0
"uTorrent" = µTorrent
"ViewpointMediaPlayer" = Viewpoint Media Player
"VLC media player" = VLC media player 1.0.1
"Winamp" = Winamp
"Winamp Toolbar" = Winamp Toolbar
"WinLiveSuite_Wave3" = Windows Live Essentials
"WinPatrol" = WinPatrol 2009
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"3495513a08ab089c" = tMod
"Winamp Detect" = Winamp Detector Plug-in
========== Last 10 Event Log Errors ==========
[ Antivirus Events ]
Error - 1/27/2011 8:34:22 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:22 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:23 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:23 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:23 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:23 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:24 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:26 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:26 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
Error - 1/27/2011 8:34:27 PM | Computer Name = CHA-PC | Source = avast! | ID = 33554522
Description =
[ Application Events ]
Error - 1/10/2011 9:15:51 AM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/10/2011 1:57:35 PM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/10/2011 6:26:37 PM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/10/2011 11:43:56 PM | Computer Name = CHA-PC | Source = Application Error | ID = 1000
Description = Faulting application Skype.exe, version 5.1.0.104, time stamp 0x4d21d204,
faulting module virtualCamera.ax, version 0.0.0.0, time stamp 0x4933ab74, exception
code 0xc0000005, fault offset 0x000088e7, process id 0x10a8, application start time
0x01cbb1417e72c961.
Error - 1/11/2011 9:20:15 AM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/12/2011 9:13:43 AM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/12/2011 3:56:30 PM | Computer Name = CHA-PC | Source = Winlogon | ID = 4005
Description = The Windows logon process has unexpectedly terminated.
Error - 1/12/2011 3:59:49 PM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/13/2011 9:20:23 AM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
Error - 1/13/2011 1:44:05 PM | Computer Name = CHA-PC | Source = WinMgmt | ID = 10
Description =
[ Media Center Events ]
Error - 10/3/2009 11:32:04 PM | Computer Name = CHA-PC | Source = ehRecvr | ID = 4
Description =
[ System Events ]
Error - 6/21/2011 6:09:06 PM | Computer Name = CHA-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 4:50:55 PM on 6/21/2011 was unexpected.
Error - 6/21/2011 6:13:17 PM | Computer Name = CHA-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 5:10:04 PM on 6/21/2011 was unexpected.
Error - 6/21/2011 6:13:31 PM | Computer Name = CHA-PC | Source = DCOM | ID = 10005
Description =
Error - 6/21/2011 6:13:42 PM | Computer Name = CHA-PC | Source = DCOM | ID = 10005
Description =
Error - 6/21/2011 6:13:48 PM | Computer Name = CHA-PC | Source = DCOM | ID = 10005
Description =
Error - 6/21/2011 6:13:58 PM | Computer Name = CHA-PC | Source = Service Control Manager | ID = 7001
Description =
Error - 6/21/2011 6:13:58 PM | Computer Name = CHA-PC | Source = Service Control Manager | ID = 7026
Description =
Error - 6/21/2011 6:13:58 PM | Computer Name = CHA-PC | Source = DCOM | ID = 10005
Description =
Error - 6/21/2011 8:09:03 PM | Computer Name = CHA-PC | Source = DCOM | ID = 10005
Description =
Error - 6/21/2011 8:32:37 PM | Computer Name = CHA-PC | Source = DCOM | ID = 10005
Description =
< End of report >
HiJack This Log; done in safe mode, with networking support. If it is really important I can try to get one in normal mode… I should be able to get it and save it before it freezes up.
I guess I have an old version, but I can't get the new one in Safe Mode it seems. To bypass the redirection, I've changed the version number directly below. If these are essentially worthless since it's not the newest version, I apologize.
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 7:25:06 PM, on 6/21/2011
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v8.00 (8.00.6001.19088)
Boot mode: Safe mode with network support
Running processes:
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gamefaqs.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = http=127.0.0.1:18810
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Winamp Toolbar Loader - {25CEE8EC-5730-41bc-8B58-22DDC8AB8C20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: SkypeIEPluginBHO - {AE805869-2E5C-4ED4-8F7B-F1F7851A4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: &Windows; Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
O3 - Toolbar: Winamp Toolbar - {EBF2BA02-9094-4c5a-858B-BB198F3D8DE2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
O4 - HKLM\..\Run: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
O4 - HKLM\..\Run: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
O4 - HKLM\..\Run: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
O4 - HKLM\..\Run: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
O4 - HKLM\..\Run: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
O4 - HKLM\..\Run: [ADSMTray] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
O4 - HKLM\..\Run: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
O4 - HKLM\..\Run: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
O4 - HKLM\..\Run: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe
O4 - HKLM\..\Run: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
O4 - HKLM\..\Run: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [UpdatePDRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" –auto-start
O4 - HKLM\..\Run: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
O4 - HKCU\..\Run: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US
O4 - Global Startup: FancyStart daemon.lnk = ?
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
O8 - Extra context menu item: &Winamp; Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog; This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra 'Tools' menuitem: Skype Plug-In - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O9 - Extra button: HP Smart Select - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O18 - Protocol: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: ADSM Service (ADSMService) - ASUSTek Computer Inc. - C:\Program Files\ASUS\ASUS Data Security Manager\ADSMSrv.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: ASLDR Service (ASLDRService) - Unknown owner - C:\Program Files (x86)\ASUS\ATK Hotkey\ASLDRSrv.exe
O23 - Service: ATKGFNEX Service (ATKGFNEXSrv) - Unknown owner - C:\Program Files\ATKGFNEX\GFNEXSrv.exe
O23 - Service: avast! Antivirus - AVAST Software - C:\Program Files\Alwil Software\Avast5\AvastSvc.exe
O23 - Service: Dragon Age: Origins - Content Updater (DAUpdaterSvc) - Unknown owner - c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe (file missing)
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: LogMeIn Hamachi 2.0 Tunneling Engine (Hamachi2Svc) - LogMeIn Inc. - C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files (x86)\CyberLink\Shared files\RichVideo.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
–
End of file - 10820 bytes
Again, this was an older version of HyjackThis. To bypass the redirection, I've changed the version number in the first line. If these are essentially worthless since it's not the newest version, I apologize.
DDS
.
DDS (Ver_11-03-05.01) - NTFS_AMD64 NETWORK
Run by [removed] at 20:18:00.73 on Tue 06/21/2011
Internet Explorer: 8.0.6001.19088 BrowserJavaVersion: 1.6.0_24
Microsoft® Windows Vista™ Home Premium 6.0.6002.2.1252.1.1033.18.4094.2742 [GMT -5:00]
.
AV: avast! Antivirus *Enabled/Updated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Antivirus *Enabled/Updated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
============== Running Processes ===============
.
C:\Windows\system32\wininit.exe
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k rpcss
C:\Windows\System32\svchost.exe -k secsvcs
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\system32\svchost.exe -k netsvcs
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k NetworkService
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Windows\Explorer.EXE
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Alwil Software\Avast5\AvastUI.exe
C:\Users\Chameleon\Downloads\OTL.exe
C:\Program Files (x86)\Mozilla Firefox\firefox.exe
C:\Program Files (x86)\Mozilla Firefox\plugin-container.exe
C:\Users\Chameleon\Downloads\dds.scr
C:\Windows\system32\wbem\wmiprvse.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://www.gamefaqs.com/
mStart Page = hxxp://www.google.com/ig/redirectdomain?brand=ASUS&bmod;=ASUS
uInternet Settings,ProxyServer = http=127.0.0.1:18810
BHO: Adobe PDF Reader Link Helper: {06849e9f-c8d7-4d59-b87d-784b7d6be0b3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
BHO: Winamp Toolbar Loader: {25cee8ec-5730-41bc-8b58-22ddc8ab8c20} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
BHO: RealPlayer Download and Record Plugin for Internet Explorer: {3049c3e9-b461-4bc5-8870-4c09146192ca} - C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
BHO: {5C255C8A-E604-49b4-9D64-90988571CECB} - No File
BHO: Search Helper: {6ebf7485-159f-4bff-a14f-b9e3aac4465b} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
BHO: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030d464-4c02-4abf-8ecc-5164760863c6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Skype Browser Helper: {ae805869-2e5c-4ed4-8f7b-f1f7851a4497} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
BHO: Java™ Plug-In 2 SSV Helper: {dbc80044-a445-435b-bc74-9c25c1c588a9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
BHO: Windows Live Toolbar Helper: {e15a8dc0-8516-42a1-81ea-dc94ec1acf10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
BHO: HP Smart BHO Class: {ffffffff-cf4e-4f2b-bdc2-0e72e116a856} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
TB: &Windows; Live Toolbar: {21fa44ef-376d-4d53-9b0f-8a89d3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
TB: Winamp Toolbar: {ebf2ba02-9094-4c5a-858b-bb198f3d8de2} - C:\Program Files (x86)\Winamp Toolbar\winamptb.dll
TB: avast! WebRep: {8e5e2654-ad2d-48bf-ac2d-d17f00898d06} - C:\Program Files\Alwil Software\Avast5\aswWebRepIE.dll
uRun: [Aim] "C:\Program Files (x86)\AIM\aim.exe" /d locale=en-US
mRun: [UpdateLBPShortCut] "C:\Program Files (x86)\CyberLink\LabelPrint\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\LabelPrint" UpdateWithCreateOnce "Software\CyberLink\LabelPrint\2.5"
mRun: [CLMLServer] "C:\Program Files (x86)\CyberLink\Power2Go\CLMLSvc.exe"
mRun: [UpdateP2GoShortCut] "C:\Program Files (x86)\CyberLink\Power2Go\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\Power2Go" UpdateWithCreateOnce "SOFTWARE\CyberLink\Power2Go\6.0"
mRun: [HControlUser] C:\Program Files (x86)\ASUS\ATK Hotkey\HControlUser.exe
mRun: [ATKOSD2] C:\Program Files (x86)\ASUS\ATKOSD2\ATKOSD2.exe
mRun: [ADSMTray] C:\Program Files\ASUS\ASUS Data Security Manager\ADSMTray.exe
mRun: [ACMON] C:\Program Files (x86)\ASUS\Splendid\ACMON.exe
mRun: [ATKMEDIA] C:\Program Files (x86)\ASUS\ATK Media\DMedia.exe
mRun: [ASUS Camera ScreenSaver] C:\Windows\AsScrProlog.exe
mRun: [ASUS Screen Saver Protector] C:\Windows\ASScrPro.exe
mRun: [WinPatrol] "C:\Program Files (x86)\BillP Studios\WinPatrol\winpatrol.exe" -expressboot
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [hpqSRMon] C:\Program Files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe
mRun: [UpdatePDRShortCut] "C:\Program Files (x86)\CyberLink\PowerDirector\MUITransfer\MUIStartMenu.exe" "C:\Program Files (x86)\CyberLink\PowerDirector" UpdateWithCreateOnce "Software\CyberLink\PowerDirector\8.0"
mRun: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
mRun: [Malwarebytes' Anti-Malware] "C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" /starttray
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [LogMeIn Hamachi Ui] "C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe" –auto-start
mRun: [TkBellExe] "c:\program files (x86)\real\realplayer\Update\realsched.exe" -osboot
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\FANCYS~1.LNK - C:\Windows\Installer\{DC905847-D537-427F-BF91-47CC7ACCDE58}\_DF3A81D17C478A2A6C60A5.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\HPDIGI~1.LNK - C:\Program Files (x86)\HP\Digital Imaging\bin\hpqtra08.exe
StartupFolder: C:\PROGRA~3\MICROS~1\Windows\STARTM~1\Programs\Startup\MAGICD~1.LNK - C:\Program Files (x86)\MagicDisc\MagicDisc.exe
mPolicies-explorer: BindDirectlyToPropertySetStorage = 0 (0x0)
mPolicies-system: EnableUIADesktopToggle = 0 (0x0)
IE: &Winamp; Search - C:\ProgramData\Winamp Toolbar\ieToolbar\resources\en-US\local\search.html
IE: E&xport; to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
IE: {DDE87865-83C5-48c4-8357-2F5B1AA84522} - {DDE87865-83C5-48c4-8357-2F5B1AA84522} - C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} - hxxp://java.sun.com/update/1.6.0/jinstall-1_6_0_24-windows-i586.cab
Handler: skype-ie-addon-data - {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
LSA: Notification Packages = scecli C:\Program Files\ASUS\ASUS Data Security Manager\ASPWDFLT
BHO-X64: Windows Live Family Safety Browser Helper Class: {4f3ed5cd-0726-42a9-87f5-d13f3d2976ac} - C:\Program Files\Windows Live\Family Safety\fssbho.dll
BHO-X64: Windows Live Family Safety Browser Helper - No File
BHO-X64: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
TB-X64: {21FA44EF-376D-4D53-9B0F-8A89D3229068} - No File
TB-X64: Winamp Toolbar: {EBF2BA02-9094-4C5A-858B-BB198F3D8DE2} -
mRun-x64: [DisableS3S4] c:\DisableS3S4.cmd
mRun-x64: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe
mRun-x64: [Skytel] C:\Program Files\Realtek\Audio\HDA\Skytel.exe
mRun-x64: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
mRun-x64: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
mRun-x64: [ProfilerU] C:\Program Files\Saitek\SD6\Software\ProfilerU.exe
mRun-x64: [SaiMfd] C:\Program Files\Saitek\SD6\Software\SaiMfd.exe
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\CHAMEL~1\AppData\Roaming\Mozilla\Firefox\Profiles\g0zx0yb8.default\
FF - prefs.js: browser.search.defaulturl - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrie7&query;=
FF - prefs.js: browser.search.selectedEngine - AIM Search
FF - prefs.js: browser.startup.homepage - hxxp://www.gamefaqs.com/
FF - prefs.js: keyword.URL - hxxp://slirsredirect.search.aol.com/slirs_http/sredir?sredir=2706&invocationType;=tb50fftrab&query;=
FF - prefs.js: network.proxy.type - 4
FF - plugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\Microsoft\Office Live\npOLW.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdeployJava1.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnu.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npdnupdater2.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npViewpoint.dll
FF - plugin: C:\Program Files (x86)\Mozilla Firefox\plugins\npwachk.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
FF - plugin: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
FF - plugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll
FF - plugin: C:\Program Files (x86)\Viewpoint\Viewpoint Media Player\npViewpoint.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprpchromebrowserrecordext.dll
FF - plugin: C:\ProgramData\Real\RealPlayer\BrowserRecordPlugin\MozillaPlugins\nprphtml5videoshim.dll
FF - plugin: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
.
—- FIREFOX POLICIES —-
FF - user.js: yahoo.homepage.dontask - true
FF - user.js: browser.sessionstore.resume_from_crash - false
FF - user.js: network.protocol-handler.warn-external.dnupdate - false
.
============= SERVICES / DRIVERS ===============
.
R0 SmartDefragDriver;SmartDefragDriver;C:\Windows\System32\drivers\SmartDefragDriver.sys [2011-6-13 18232]
R2 Hamachi2Svc;LogMeIn Hamachi 2.0 Tunneling Engine;C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe [2011-5-25 2275720]
R3 itecir;ITECIR Infrared Receiver;C:\Windows\System32\drivers\itecir.sys [2009-8-11 59392]
R3 NETw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;C:\Windows\System32\drivers\NETw5v64.sys [2008-8-28 4745216]
R3 SaiK0CFA;SaiK0CFA;C:\Windows\System32\drivers\SaiK0CFA.sys [2010-12-19 174600]
R3 SaiU0CFA;SaiU0CFA;C:\Windows\System32\drivers\SaiU0CFA.sys [2010-12-19 41352]
S1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2011-2-26 600920]
S1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2009-9-10 287576]
S2 ASMMAP64;ASMMAP64;C:\Program Files\ATKGFNEX\ASMMAP64.sys [2009-8-11 14904]
S2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2009-9-10 22360]
S2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2009-9-10 64344]
S2 avast! Antivirus;avast! Antivirus;C:\Program Files\Alwil Software\Avast5\AvastSvc.exe [2011-1-29 42184]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 cpuz135;cpuz135;C:\Windows\System32\drivers\cpuz135_x64.sys [2011-2-11 21992]
S2 FontCache;Windows Font Cache Service;C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation [2008-1-20 27648]
S2 MBAMService;MBAMService;C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2009-9-10 304464]
S2 Stereo Service;NVIDIA Stereoscopic 3D Driver Service;C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe [2011-1-7 378984]
S2 Viewpoint Manager Service;Viewpoint Manager Service;C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe [2009-9-10 24652]
S3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe –> c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [?]
S3 fssfltr;FssFltr;C:\Windows\System32\drivers\fssfltr.sys [2009-8-11 61792]
S3 fsssvc;Windows Live Family Safety;C:\Program Files (x86)\Windows Live\Family Safety\fsssvc.exe [2008-12-8 533344]
S3 MBAMProtector;MBAMProtector;C:\Windows\System32\drivers\mbam.sys [2009-9-10 24664]
S3 MotioninJoyXFilter;MotioninJoy Virtual Xinput device Filter Driver;C:\Windows\System32\drivers\MijXfilt.sys [2009-12-5 53248]
S3 PerfHost;Performance Counter DLL Host;C:\Windows\SysWOW64\perfhost.exe [2008-1-20 19968]
S3 Point64;Microsoft IntelliPoint Filter Driver;C:\Windows\System32\drivers\point64k.sys [2009-5-8 33160]
S3 RivaTuner64;RivaTuner64;C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2009-8-22 19952]
S3 WPFFontCache_v0400;Windows Presentation Foundation Font Cache 4.0.0.0;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe [2010-3-18 1020768]
S3 yukonx64;NDIS6.0 Miniport Driver for Marvell Yukon Ethernet Controller;C:\Windows\System32\drivers\yk60x64.sys [2006-11-2 273408]
S4 clr_optimization_v2.0.50727_64;Microsoft .NET Framework NGEN v2.0.50727_X64;C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe [2009-10-20 89920]
.
=============== File Associations ===============
.
JSEFile=C:\Windows\SysWOW64\WScript.exe "%1" %*
.
=============== Created Last 30 ================
.
2011-06-21 18:38:08 ——– d—–w- C:\_OTS
2011-06-21 18:25:04 ——– d—–w- C:\Users\CHAMEL~1\AppData\Local\temp
2011-06-21 18:15:43 ——– d-sh–w- C:\$RECYCLE.BIN
2011-06-21 17:46:50 98816 —-a-w- C:\Windows\sed.exe
2011-06-21 17:46:50 518144 —-a-w- C:\Windows\SWREG.exe
2011-06-21 17:46:50 256512 —-a-w- C:\Windows\PEV.exe
2011-06-21 17:46:50 208896 —-a-w- C:\Windows\MBR.exe
2011-06-19 04:38:33 ——– d—–w- C:\Users\CHAMEL~1\AppData\Roaming\TerrariaMod
2011-06-18 02:21:07 8718160 —-a-w- C:\PROGRA~3\Microsoft\Windows Defender\Definition Updates\{4B70ECE2-C3FB-4D54-A41A-2A725956ED5D}\mpengine.dll
2011-06-16 19:37:53 916480 —-a-w- C:\Windows\SysWow64\wininet.dll
2011-06-14 01:19:47 ——– d—–w- C:\Users\CHAMEL~1\AppData\Local\Apps
2011-06-14 01:19:46 ——– d—–w- C:\Users\CHAMEL~1\AppData\Local\Deployment
2011-06-14 01:19:28 ——– d—–w- C:\Program Files\Microsoft Synchronization Services
2011-06-14 01:19:28 ——– d—–w- C:\Program Files\Microsoft SQL Server Compact Edition
2011-06-14 01:18:55 ——– d—–w- C:\Program Files (x86)\Microsoft Synchronization Services
2011-06-13 21:50:14 ——– d—–w- C:\Users\CHAMEL~1\AppData\Roaming\IObit
2011-06-13 21:50:13 32648 —-a-w- C:\Windows\System32\SmartDefragBootTime.exe
2011-06-13 21:50:13 18232 —-a-w- C:\Windows\System32\drivers\SmartDefragDriver.sys
2011-06-13 21:49:35 ——– d—–w- C:\Program Files (x86)\IObit
2011-06-13 21:46:57 ——– d—–w- C:\PROGRA~3\IObit
2011-06-10 06:43:21 ——– d—–w- C:\PROGRA~3\Skype Extras
2011-06-10 04:23:34 ——– d—–w- C:\Users\CHAMEL~1\AppData\Roaming\TerrariaWorldViewer
2011-06-08 20:04:50 ——– d—–w- C:\Program Files (x86)\osu!
2011-06-08 20:03:38 ——– d—–w- C:\Users\CHAMEL~1\AppData\Roaming\Downloaded Installations
2011-06-06 22:28:16 ——– d—–w- C:\PROGRA~3\AIM
2011-06-06 22:28:03 ——– d—–w- C:\Program Files (x86)\AIM
2011-06-06 22:28:02 ——– d—–w- C:\Program Files (x86)\Common Files\Software Update Utility
2011-06-03 17:54:56 ——– d—–w- C:\Users\CHAMEL~1\AppData\Local\Real
2011-06-03 17:53:34 ——– d—–w- C:\Program Files (x86)\Common Files\xing shared
2011-06-03 17:46:09 ——– d—–w- C:\Users\CHAMEL~1\AppData\Local\Google
2011-05-30 18:06:47 33856 —ha-w- C:\Windows\System32\hamachi.sys
2011-05-30 18:06:21 ——– d—–w- C:\Program Files (x86)\LogMeIn Hamachi
.
==================== Find3M ====================
.
2011-06-21 18:09:16 45056 —-a-w- C:\Windows\System32\acovcnt.exe
2011-06-06 17:13:07 404640 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2011-06-03 17:51:58 499712 —-a-w- C:\Windows\SysWow64\msvcp71.dll
2011-06-03 17:51:58 348160 —-a-w- C:\Windows\SysWow64\msvcr71.dll
2011-05-28 06:28:00 1147904 —-a-w- C:\Windows\System32\wininet.dll
2011-05-28 06:24:04 56832 —-a-w- C:\Windows\System32\licmgr10.dll
2011-05-28 06:23:47 1538560 —-a-w- C:\Windows\System32\inetcpl.cpl
2011-05-28 06:23:30 132096 —-a-w- C:\Windows\System32\iesysprep.dll
2011-05-28 06:23:29 77312 —-a-w- C:\Windows\System32\iesetup.dll
2011-05-28 06:04:30 43520 —-a-w- C:\Windows\SysWow64\licmgr10.dll
2011-05-28 06:04:17 1469440 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2011-05-28 06:04:03 71680 —-a-w- C:\Windows\SysWow64\iesetup.dll
2011-05-28 06:04:03 109056 —-a-w- C:\Windows\SysWow64\iesysprep.dll
2011-05-28 05:33:37 479232 —-a-w- C:\Windows\System32\html.iec
2011-05-28 05:10:26 385024 —-a-w- C:\Windows\SysWow64\html.iec
2011-05-28 04:53:37 162816 —-a-w- C:\Windows\System32\ieUnatt.exe
2011-05-28 04:52:18 1638912 —-a-w- C:\Windows\System32\mshtml.tlb
2011-05-28 04:33:03 133632 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2011-05-28 04:31:44 1638912 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2011-05-18 13:56:59 2762752 —-a-w- C:\Windows\System32\win32k.sys
2011-05-10 12:10:59 40112 —-a-w- C:\Windows\avastSS.scr
2011-05-10 12:04:08 600920 —-a-w- C:\Windows\System32\drivers\aswSnx.sys
2011-05-10 11:59:48 64344 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2011-05-03 23:38:44 90112 —-a-w- C:\Windows\lol.launcher.exe
2011-05-03 23:38:43 90112 —-a-w- C:\Windows\lol.launcher.admin.exe
2011-05-02 17:16:14 739328 —-a-w- C:\Windows\SysWow64\inetcomm.dll
2011-05-02 17:13:21 975360 —-a-w- C:\Windows\System32\inetcomm.dll
2011-04-29 13:41:02 176128 —-a-w- C:\Windows\System32\drivers\srv2.sys
2011-04-29 13:40:56 145920 —-a-w- C:\Windows\System32\drivers\srvnet.sys
2011-04-29 13:39:34 275456 —-a-w- C:\Windows\System32\drivers\mrxsmb10.sys
2011-04-29 13:39:34 135680 —-a-w- C:\Windows\System32\drivers\mrxsmb.sys
2011-04-29 13:39:31 107008 —-a-w- C:\Windows\System32\drivers\mrxsmb20.sys
2011-04-21 14:20:24 405504 —-a-w- C:\Windows\System32\drivers\afd.sys
2011-04-14 15:14:19 97792 —-a-w- C:\Windows\System32\drivers\dfsc.sys
2011-04-09 23:55:44 15453336 —-a-w- C:\Windows\SysWow64\xlive.dll
2011-04-09 23:55:42 13642904 —-a-w- C:\Windows\SysWow64\xlivefnt.dll
2006-05-03 09:06:54 163328 –sh–r- C:\Windows\SysWOW64\flvDX.dll
2007-02-21 10:47:16 31232 –sh–r- C:\Windows\SysWOW64\msfDX.dll
2008-03-16 12:30:52 216064 –sh–r- C:\Windows\SysWOW64\nbDX.dll
.
============= FINISH: 20:18:51.50 ===============
Once again, thanks in advance for any help you have to offer.