Bcoats
Topic Starter
hello, I'm Brad, new registered member,
my laptop has been infected with the mystart incredibar virus.
I have followed your instructions and downloaded the program to help with removal of the mystart virus. I have both reports on notepad, one is copied. where do I post it?
OTL logfile created on: 7/6/2012 3:01:29 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Brad C\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.80 Gb Total Physical Memory | 1.06 Gb Available Physical Memory | 27.91% Memory free
7.60 Gb Paging File | 4.41 Gb Available in Paging File | 58.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 668.10 Gb Total Space | 591.32 Gb Free Space | 88.51% Space Free | Partition Type: NTFS
Drive D: | 30.24 Gb Total Space | 4.44 Gb Free Space | 14.69% Space Free | Partition Type: NTFS
Drive F: | 98.87 Mb Total Space | 83.72 Mb Free Space | 84.68% Space Free | Partition Type: FAT32
Computer Name: BRADC-BRADC-HP | User Name: Brad C | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Brad C\Downloads\OTL(1).exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe ()
PRC - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)
PRC - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe ()
PRC - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Software Informer\softinfo.exe (Informer Technologies, Inc.)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\iWin Games\iWinTrusted.exe (iWin Inc.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\zumodrive.exe (Zecter Inc.)
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
PRC - C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe (CyberLink)
PRC - C:\ProgramData\ClickfreeC02\UACProxy.exe (Storage Appliance Corp.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE ()
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Users\Brad C\AppData\Local\Temp\libsqlitejdbc-8626483191519883319.lib ()
MOD - C:\Users\Brad C\AppData\Local\Temp\WindowsAPI.dll2891894938722718749.lib ()
MOD - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\SiteSafety.dll ()
MOD - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxslt.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (Web Assistant Updater) – C:\Program Files\Web Assistant\ExtensionUpdaterService.exe ()
SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (HPClientSvc) – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company)
SRV:64bit: - (HPAuto) – C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe (Hewlett-Packard)
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (HP Wireless Assistant Service) – C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Application Updater) – C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (vToolbarUpdater11.1.0) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe ()
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (WajamUpdater) – C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe (Wajam)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (IMFservice) – C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (iWinTrusted) – C:\Program Files (x86)\iWin Games\iWinTrusted.exe (iWin Inc.)
SRV - (CLKMSVC10_C6F09094) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe (CyberLink)
SRV - (RoxioNow Service) – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
SRV - (CFUACProxy_clickfreec02) – C:\ProgramData\ClickfreeC02\UACProxy.exe (Storage Appliance Corp.)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (clwvd) – C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation)
DRV:64bit: - (intelkmd) – C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (SkyhawkeUSBLan) – C:\Windows\SysNative\drivers\btblan.sys (Belcarra Technologies)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (UrlFilter) – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\UrlFilter.sys (IObit.com)
DRV - (RegFilter) – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\RegFilter.sys (IObit.com)
DRV - (FileMonitor) – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys (IObit)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a;=iron2…p;cr=1561730916
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1561730916
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}: "URL" = http://rover.ebay.com/rover/1/711-111092-2…p;mfe=Notebooks
IE:64bit: - HKLM\..\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000.100…D-ED18B0B41582}
IE - HKLM\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1561730916
IE - HKLM\..\SearchScopes\{7624FE00-BB7A-93D1-4029-31A105F7D5E8}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2776682
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKLM\..\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}: "URL" = http://rover.ebay.com/rover/1/711-111092-2…p;mfe=Notebooks
IE - HKLM\..\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6…D-ED18B0B41582}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://isearch.avg.com/?cid={1D722B3C-363F…mp;d=2012-03-13 20:31:04&v;=11.0.0.9&sap;=hp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie9
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.avg.com/?cid={1D722B3C-363F…mp;d=2012-03-13 20:31:04&v;=11.1.0.7&sap;=hp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - No CLSID value found
IE - HKCU\..\URLSearchHook: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\6.0\iobitToolbarIE.dll (Spigot, Inc.)
IE - HKCU\..\URLSearchHook: {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - No CLSID value found
IE - HKCU\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\6.0\pdfforgeToolbarIE.dll (Spigot, Inc.)
IE - HKCU\..\URLSearchHook: {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files (x86)\Freeze.com\NetAssistant\NetAssistant.dll (W3i, LLC)
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{12DC6175-B360-2C25-BF0E-2B6E49ADC9F3}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKCU\..\SearchScopes\{2C71AFC4-9C4C-4E8C-9618-38EADA8DEF02}: "URL" = http://www.flickr.com/search/?q={searchTerms}
IE - HKCU\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKCU\..\SearchScopes\{66C011AB-F98E-4337-B30D-C800D299CE92}: "URL" = http://delicious.com/search?p={searchTerms}
IE - HKCU\..\SearchScopes\{67AFED21-EE04-4081-941E-3CB3CAD8C28E}: "URL" = http://search.yahoo.com/search?fr=chr-gree…p={searchTerms}
IE - HKCU\..\SearchScopes\{7624FE00-BB7A-93D1-4029-31A105F7D5E8}: "URL" = http://isearch.avg.com/search?cid={1D722B3…mp;d=2012-03-13 20:31:04&v;=10.0.0.7&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1561730916
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\..\SearchScopes\{9BDECC3C-C77D-4CFE-9448-B1BED69F6ADD}: "URL" = http://search.yahoo.com/search?fr=chr-gree…p={searchTerms}
IE - HKCU\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKCU\..\SearchScopes\{B8822D2B-48D0-421E-93B7-432835894155}: "URL" = http://www.google.com/search?q={searchTerm…1I7GGHP_enUS466
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb143/?searc…buqG4D&i;=26
IE - HKCU\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKCU\..\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}: "URL" = http://rover.ebay.com/rover/1/711-111092-2…p;mfe=Notebooks
IE - HKCU\..\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6…D-ED18B0B41582}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2012/05/24 09:09:17 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2012/05/24 09:09:17 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMyWebS.dll (MyWebSearch.com)
FF - HKLM\Software\MozillaPlugins\@photoproduct.rocketlife.com/RocketLife App Viewer;version=0.8: File not found
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Users\Brad C\AppData\Local\HuluDesktop\instances\0.9.14.1\nphdplg.dll (Hulu LLC)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Brad C\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Brad C\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Brad C\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2012/05/02 13:00:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2010/10/25 04:11:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{98e34367-8df7-42b4-837b-20b892ff0849}: C:\ProgramData\iWin Games\firefox [2011/09/04 17:28:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\11.1.0.7\ [2012/06/12 11:11:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/05/29 10:07:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012/05/02 13:00:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/05/24 09:05:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MyWebSearch\bar\1.bin [2012/07/06 10:06:16 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/01 21:22:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/23 10:01:36 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/01 21:22:50 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/23 10:01:36 | 000,000,000 | —D | M]
[2012/01/06 22:54:41 | 000,000,000 | —D | M] (No name found) – C:\Users\Brad C\AppData\Roaming\Mozilla\Extensions
[2011/05/06 10:03:58 | 000,000,000 | —D | M] (No name found) – C:\Users\Brad C\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/06 15:02:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions
[2012/06/14 15:43:29 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/06/13 20:11:55 | 000,000,000 | —D | M] (DVDVideoSoftTB) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012/06/06 15:03:59 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/05/24 09:09:35 | 000,000,000 | —D | M] (Page Speed) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2012/06/19 06:35:03 | 000,000,000 | —D | M] (My Web Search) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\[removed]
[2012/06/18 09:26:07 | 000,000,000 | —D | M] (WebRank Toolbar) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\[removed]
[2011/10/08 18:28:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Brad C\AppData\Roaming\Mozilla\SeaMonkey\Profiles\t9umotw0.default\extensions
[2012/06/11 14:48:57 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/06/11 14:48:57 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/07/01 21:22:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\distribution\extensions
[2012/07/01 21:22:50 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/12 11:10:58 | 000,003,766 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/05/16 17:08:48 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml.old
[2011/11/26 16:02:58 | 000,002,519 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
[2012/05/16 17:08:48 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Yahoo! (Enabled)
CHR - default_search_provider: search_url = http://search.yahoo.com/search?ei={inputEn…p={searchTerms}
CHR - default_search_provider: suggest_url = http://ff.search.yahoo.com/gossip?output=f…d={searchTerms}
CHR - Extension: WinZipBar = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgpnojibjokpoghebklhkdeijehkohhb\2.3.4.2_0\
CHR - Extension: FunDial = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\1.0.1_0\
CHR - Extension: Web Assistant = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.430_0\
CHR - Extension: Funmoods = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\1.5.1_0\
CHR - Extension: SweetIM for Facebook = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
CHR - Extension: SweetIM for Facebook = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\
CHR - Extension: AVG Safe Search = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\
CHR - Extension: Wajam = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\
CHR - Extension: Skype Click to Call = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.0.0.10201_0\
CHR - Extension: AVG Do Not Track = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: DVDVideoSoftTB = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\plmlpkfpkijnlijgalnjaacllnjmoamo\10.11.5.4_0\
CHR - Extension: WinZipBar = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgpnojibjokpoghebklhkdeijehkohhb\2.3.4.2_0\
CHR - Extension: FunDial = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\1.0.1_0\
CHR - Extension: Web Assistant = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.430_0\
CHR - Extension: Funmoods = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\1.5.1_0\
CHR - Extension: SweetIM for Facebook = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
CHR - Extension: SweetIM for Facebook = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\
CHR - Extension: AVG Safe Search = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\
CHR - Extension: Wajam = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\
CHR - Extension: Skype Click to Call = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.0.0.10201_0\
CHR - Extension: AVG Do Not Track = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: DVDVideoSoftTB = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\plmlpkfpkijnlijgalnjaacllnjmoamo\10.11.5.4_0\
O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension64.dll ()
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\6.0\iobitToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (ViewSource Class) - {2EF37A01-884F-11d5-AC99-B112050ECB4F} - C:\Program Files (x86)\Popup Free\HTMLEdit.dll (InfoWorks Technology Company)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (BrotherSoft Extreme Toolbar) - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
O2 - BHO: (Funmoods Helper Object) - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\PROGRA~2\Funmoods\1.5.23.22\bh\escort.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll File not found
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll (Wajam)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\6.0\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (NetAssistant) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files (x86)\Freeze.com\NetAssistant\NetAssistant.dll (W3i, LLC)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (no name) - !{41B62AD3-5D43-40D1-9D43-F3539C1DB452} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - !{95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - !{B922D405-6D13-4A2B-AE89-08A030DA4402} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\6.0\iobitToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BrotherSoft Extreme Toolbar) - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll File not found
O3 - HKLM\..\Toolbar: (Funmoods Toolbar) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\PROGRA~2\Funmoods\1.5.23.22\escorTlbr.dll File not found
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\6.0\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Corel File Shell Monitor] c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\CorelIOMonitor.exe File not found
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found
O4 - HKLM..\Run: [ROC_roc_dec12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [ZumoDrive] C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk ()
O4 - HKCU..\Run: [Allmyapps] C:\Program Files (x86)\Allmyapps\AllmyappsNotifier.exe (Allmyapps)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Brad C\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [MyWebSearch Email Plugin] C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found
O4 - HKCU..\Run: [Software Informer] C:\Program Files (x86)\Software Informer\softinfo.exe (Informer Technologies, Inc.)
O4 - HKCU..\Run: [ZumoDrive] C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk ()
O4 - Startup: C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2040B8F1-89EE-40CF-BFB8-C5213E9F4DF7}: DhcpNameServer = 10.0.0.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe) - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:64bit: - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll (Stardock)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{e08af094-1548-11e1-8b3f-f568c47f51ae}\Shell - "" = AutoRun
O33 - MountPoints2\{e08af094-1548-11e1-8b3f-f568c47f51ae}\Shell\AutoRun\command - "" = G:\StartClickFreeBackup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.tscc - C:\Windows\SysWOW64\tsccvid64.dll (TechSmith Corporation)
Drivers32: msacm.dvacm - c:\Program Files (x86)\Common Files\Ulead Systems\VIO\DVACM.acm (Corel TW Corp.)
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/07/06 14:12:45 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\James_Jordan-IM_Business_In_A_Box
[2012/07/06 11:54:14 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{90895736-A8E0-42D9-86DD-C65D217907DB}
[2012/07/06 11:54:03 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{1373FBAA-F462-4A3F-90DD-29BB80AB97FE}
[2012/07/05 10:16:59 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{E2A0B748-F5EC-4217-935F-A2ABBD3986C2}
[2012/07/05 10:16:48 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{928EFE15-82C8-4378-9AD9-9A0C2818CAEC}
[2012/07/05 10:13:43 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{7B2F270B-0974-4B9C-AC31-CEFF2A84BA5D}
[2012/07/04 11:48:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit Toolbar
[2012/07/04 11:48:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
[2012/07/04 11:48:22 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\IObit
[2012/07/04 11:48:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2012/07/04 11:47:11 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\IObitMalwareFighterPRO
[2012/07/04 04:58:11 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{06DB8F0B-1441-46E9-A225-004BA3AF432D}
[2012/07/04 04:58:00 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{B9956608-0B07-433A-9985-14F4F4814F8A}
[2012/07/03 14:09:56 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Corel Auto-Preserve
[2012/07/03 11:52:42 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{D7C6B135-E1F2-4EE9-8EF2-C43F0C443A3F}
[2012/07/03 11:52:31 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{0B0DD05E-62A9-48B4-8FE2-E91EB6E8E249}
[2012/07/03 10:01:14 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\CPS images
[2012/07/03 09:50:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Spigot
[2012/07/03 09:50:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\pdfforge Toolbar
[2012/07/03 09:50:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Application Updater
[2012/07/02 08:35:16 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{325F898A-A958-4492-AE41-C80BC195A431}
[2012/07/02 08:35:05 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{2BC30E3A-BD64-488B-AA0B-811FE094234D}
[2012/07/01 12:24:45 | 004,472,121 | —- | C] (CamStudio Open Source Dev Team ) – C:\Users\Brad C\Downloads\Documents\CamStudio_Setup_v2.6b_r294_(build_24Oct2010).exe
[2012/07/01 09:04:58 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{F9C03163-84BC-40A1-ACB2-9C57880B416D}
[2012/07/01 09:04:46 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{0498AD14-7FB3-4AD3-81A0-9631A658607B}
[2012/06/30 17:23:15 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\Email Newsletter BC Online
[2012/06/30 10:09:14 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\twitter
[2012/06/30 10:06:26 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\TweetAdder3
[2012/06/30 09:17:08 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{CEF5D77C-EE35-4855-92A8-504864818144}
[2012/06/30 09:16:57 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{79EC122A-5978-49BD-ADAC-30B630549F35}
[2012/06/29 12:40:19 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{AB8D0F03-5A15-4496-A14E-7A3E9FF66986}
[2012/06/29 12:40:07 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{5E02D64E-A25E-4D58-98BD-B7B8BC109282}
[2012/06/28 19:50:38 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{2133ED98-28AF-4F44-BBA4-784AEEE141E7}
[2012/06/28 19:50:27 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{6161CE72-A397-435E-BA5F-D3263ACD67E8}
[2012/06/28 10:39:13 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\BlogThemes_201109
[2012/06/28 09:41:35 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\CreateStunningVideoSlideshowsForFree_PLR
[2012/06/28 06:12:58 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{5D18960A-1A3A-41FB-BE01-599ED4EE0130}
[2012/06/28 06:12:47 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{498CA44B-5914-440A-9039-46EEA2EEDE97}
[2012/06/27 16:26:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Content Spin Bot
[2012/06/27 16:26:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\ContentSpinBot
[2012/06/27 11:54:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoSqPageGen
[2012/06/27 11:54:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoSqPageGen
[2012/06/27 11:42:21 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\ecovers
[2012/06/26 18:22:05 | 000,000,000 | R–D | C] – C:\Users\Brad C\Downloads\Documents\HP Photo Creations
[2012/06/26 18:22:05 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Visan
[2012/06/26 18:22:00 | 000,000,000 | —D | C] – C:\ProgramData\Visan
[2012/06/26 13:52:03 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{1BF78769-68B8-4779-826C-F0D3747947EE}
[2012/06/26 13:51:52 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{3F8F1BE2-DF2E-42D8-8D0D-4D2C902A48C9}
[2012/06/25 09:20:50 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{639F841D-9862-4AFD-8C0B-EF01D447FEE6}
[2012/06/25 09:20:39 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{350AF1CC-4B5A-40C0-8DD9-2D989A458A2C}
[2012/06/23 12:38:00 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{C16650F3-2D41-44A4-A432-F064B8D4B6F6}
[2012/06/23 12:37:49 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{87811A18-9580-44FA-871C-C23BEC21B040}
[2012/06/22 16:45:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/06/22 16:44:25 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2012/06/22 16:44:25 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2012/06/22 16:44:25 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2012/06/22 16:44:24 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2012/06/22 16:43:50 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/06/22 16:43:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2012/06/22 16:43:50 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/06/22 16:43:50 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2012/06/22 16:42:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2012/06/22 16:42:36 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2012/06/22 16:42:26 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/06/22 16:42:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2012/06/22 16:40:36 | 079,225,752 | —- | C] (Apple Inc.) – C:\Users\Brad C\iTunes64Setup.exe
[2012/06/22 15:53:52 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{3ED52322-4D8F-44EC-92B7-0771E77D8561}
[2012/06/22 15:53:41 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{5F8478C5-829D-4D59-95E6-D3805371A348}
[2012/06/21 12:03:03 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{337BEA95-4AFD-44AE-B751-FF6F202EB9F8}
[2012/06/21 12:02:51 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{7817663F-E0BB-4414-B02C-97D86A813263}
[2012/06/20 09:33:10 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{AC6951B2-192A-4A4B-B875-C44AF8781DEE}
[2012/06/20 09:33:00 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{76703886-F033-4F30-9160-4D2AF770E0E0}
[2012/06/19 13:59:56 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{623F1BF0-C5E4-4D07-B22D-F00BD7587500}
[2012/06/19 13:59:45 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{1031FD43-5931-494F-BB75-DE20F9D261E0}
[2012/06/19 06:29:23 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/19 06:29:23 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/19 06:29:23 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/19 06:28:58 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/19 06:28:58 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/19 06:28:58 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/19 06:28:41 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/19 06:28:41 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/06/18 20:12:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\MyWebSearch
[2012/06/18 06:59:05 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{39FF811A-3DDE-4AA4-97EC-A453EEC257D8}
[2012/06/16 20:15:58 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{5E42E006-51D6-4C61-A99D-6DD91894B772}
[2012/06/16 05:39:40 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\SuperSignUpSystem_Minisite
[2012/06/16 05:35:20 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Free_PLR_Products-dkas
[2012/06/16 05:10:39 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TweetDeck
[2012/06/16 05:10:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Twitter
[2012/06/16 05:03:45 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Business Links
[2012/06/16 05:02:56 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\MindValley
[2012/06/15 08:30:54 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{9E0A3BED-1FF5-4509-AA7C-B551BC2D4752}
[2012/06/14 17:29:28 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\nichebuilder
[2012/06/14 16:21:37 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\nichebuilder
[2012/06/14 15:55:25 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\ListGuerillaTraffic
[2012/06/14 15:53:42 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\Co_Registration_Explained
[2012/06/14 15:53:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Utilities
[2012/06/14 08:43:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs
[2012/06/14 08:43:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012/06/14 08:03:23 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\AVG
[2012/06/14 08:02:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2012/06/14 06:46:09 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{FA84CF08-8433-42C2-B303-544BA3E593B7}
[2012/06/14 06:45:58 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{CB8E4E87-95F5-43A6-9CB6-76374106D5BA}
[2012/06/13 20:16:35 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/06/13 20:16:34 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/06/13 20:16:34 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/06/13 20:16:34 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/06/13 20:16:33 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/06/13 20:16:33 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/06/13 20:16:32 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/06/13 20:16:32 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/06/13 20:16:31 | 002,311,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/06/13 20:16:31 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/06/13 20:16:31 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/06/13 20:16:31 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/06/13 20:16:30 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/06/13 20:15:41 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\DVDVideoSoft_Ltd
[2012/06/13 20:12:44 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\DVDVideoSoft
[2012/06/13 20:11:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\DVDVideoSoftTB
[2012/06/13 20:11:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
[2012/06/13 20:11:37 | 002,557,952 | —- | C] (Nokia Corporation and/or its subsidiary(-ies)) – C:\Windows\SysWow64\QtCore4.dll
[2012/06/13 20:11:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\DVDVideoSoft
[2012/06/13 20:11:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DVDVideoSoft
[2012/06/13 20:10:43 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\DVDVideoSoft
[2012/06/13 19:57:48 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/06/13 19:57:48 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/06/13 19:57:48 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2012/06/13 19:57:40 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/06/13 19:57:38 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/06/13 19:57:38 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/06/13 19:57:34 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2012/06/13 19:57:28 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/06/13 19:57:27 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/06/13 14:06:33 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\LibreOffice
[2012/06/13 14:04:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 3.4
[2012/06/13 14:03:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\LibreOffice 3.4
[2012/06/13 14:02:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free Offers from Freeze.com
[2012/06/13 14:02:12 | 000,000,000 | -HSD | C] – C:\Windows\SysWow64\AI_RecycleBin
[2012/06/13 14:02:11 | 000,000,000 | —D | C] – C:\ProgramData\W3i
[2012/06/13 14:02:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\W3i
[2012/06/13 14:02:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InstallIQ Updater
[2012/06/13 14:02:05 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NetAssistant
[2012/06/13 14:02:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Freeze.com
[2012/06/13 13:59:16 | 001,536,192 | —- | C] (W3i, LLC) – C:\Users\Brad C\Desktop\libreoffice.exe
[2012/06/13 13:54:11 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
[2012/06/13 13:54:07 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\Wajam
[2012/06/13 13:54:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Wajam
[2012/06/13 13:50:14 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\mobile
[2012/06/13 13:50:13 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\files
[2012/06/13 08:49:42 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Downloads bundled
[2012/06/13 07:19:09 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Kingsoft
[2012/06/13 07:19:09 | 000,000,000 | —D | C] – C:\ProgramData\Kingsoft
[2012/06/13 06:50:14 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\Macromedia
[2012/06/13 06:43:22 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{64F87F3C-E10D-467B-A5D5-1BDECABD5279}
[2012/06/13 06:43:10 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{663998F9-037B-441F-A275-BBD7A907ABE0}
[2012/06/12 16:49:10 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Apple Computer
[2012/06/12 11:11:00 | 000,000,000 | —D | C] – C:\Windows\SysWow64\cache
[2012/06/12 07:13:18 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{DE9F876E-4D46-4206-A3A5-4CBB091E4B40}
[2012/06/12 07:12:31 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{28824F43-59D7-43E1-832E-AAC5C0E9B96B}
[2012/06/11 16:47:23 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Screen Shots
[2012/06/11 16:28:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Tableau
[2012/06/11 15:29:59 | 000,000,000 | —D | C] – C:\Users\Brad C\LimitlessLeadGenerationGuideMRR
[2012/06/11 15:12:00 | 000,000,000 | —D | C] – C:\Users\Brad C\Tracing
[2012/06/11 15:06:52 | 000,000,000 | —D | C] – C:\ProgramData\SweetIM
[2012/06/11 15:06:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\SweetIM
[2012/06/11 15:06:25 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\pdfforge
[2012/06/11 15:06:22 | 000,065,024 | —- | C] (pdfforge GbR) – C:\Windows\SysNative\pdfcmon.dll
[2012/06/11 14:57:15 | 000,000,000 | -H-D | C] – C:\ProgramData\{A3A26C56-02C3-4F76-A033-12EE2FB52AE6}
[2012/06/11 14:57:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock
[2012/06/11 14:57:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Stardock
[2012/06/11 14:56:39 | 000,000,000 | –SD | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4
[2012/06/11 14:53:33 | 000,000,000 | —D | C] – C:\Users\Brad C\OpenOffice.org 3.4 (en-US) Installation Files
[2012/06/11 14:52:40 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling
[2012/06/11 14:52:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\LightScribe
[2012/06/11 14:49:31 | 000,000,000 | —D | C] – C:\9becf207da7d7dfef274f5c9
[2012/06/11 14:48:23 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2012/06/11 14:48:23 | 000,000,000 | —D | C] – C:\Users\Brad C\Skype
[2012/06/11 14:48:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2012/06/11 14:45:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/06/11 14:43:45 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2012/06/11 14:39:35 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Allmyapps
[2012/06/11 14:39:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Allmyapps
[2012/06/11 14:39:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Allmyapps
[2012/06/11 14:39:23 | 000,000,000 | —D | C] – C:\ProgramData\Allmyapps
[2012/06/11 14:38:57 | 003,534,288 | —- | C] (Allmyapps) – C:\Users\Brad C\Facebook_video_calling_Allmyapps_Setup.exe
[2012/06/11 06:36:27 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{38072749-59A0-48BC-868F-67C7C50F8993}
[2012/06/11 06:36:16 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{A4F8141A-4C4D-4493-A0F3-2F6EB5E3F69E}
[2012/06/10 16:13:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Creator
[2012/06/10 16:13:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\GPLGS
[2012/06/10 16:13:17 | 000,000,000 | —D | C] – C:\Program1
[2012/06/09 06:42:28 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Software Informer
[2012/06/09 06:42:28 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Software Informer
[2012/06/09 06:42:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Software Informer
[2012/06/09 06:42:04 | 000,000,000 | —D | C] – C:\ProgramData\A-PDF
[2012/06/09 06:42:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PPT To Flash Catalog Professional
[2012/06/09 06:41:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\PPT To Flash Catalog Professional
[2012/06/09 06:41:59 | 000,000,000 | —D | C] – C:\ProgramData\flipBook
[2012/06/09 06:41:42 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\PPTtoFlashCatalogPro
[2012/06/09 06:41:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\WebFormDesigner
[2012/06/09 06:40:53 | 000,000,000 | —D | C] – C:\Users\Brad C\WFDInstall
[2012/06/09 06:40:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\CamStudio
[2012/06/09 05:30:20 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{FEBE7E0A-3050-4A4E-9365-C00BF81FDDF4}
[2012/06/09 05:30:09 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{941FC528-AC8E-4933-93DD-683B40AFCB72}
[2012/06/08 08:09:51 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{AF132AE6-BBCF-4807-A4F4-28EF497119B9}
[2012/06/08 08:09:40 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{000E45A8-7676-4F86-A208-B04EEE3DF036}
[2012/06/08 07:29:49 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\Article Submission Helper
[2012/06/08 07:29:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\ASHelper
[2012/06/07 19:28:26 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{2E56102B-A738-4BFE-894E-E925B339AFF2}
[2012/06/07 19:28:15 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{79DF1C6B-F755-461E-B3F5-29A5CC9C4BEB}
[2012/06/07 14:42:22 | 000,000,000 | —D | C] – C:\Users\Brad C\.thumbnails
[2012/06/07 14:00:02 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\fontconfig
[2012/06/07 14:00:00 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\gegl-0.2
[2012/06/07 14:00:00 | 000,000,000 | —D | C] – C:\Users\Brad C\.gimp-2.8
[2012/06/07 13:58:36 | 000,000,000 | —D | C] – C:\Program Files\GIMP 2
[2012/06/07 05:29:29 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{4548D96F-40F1-428F-8B87-A63092F2A2C4}
[2012/06/07 05:29:18 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{2CA04E2A-9FA7-4C06-A45A-C5321522F517}
[2012/06/06 17:28:51 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{49963352-2D04-4BAF-B1EA-7539FC580A33}
[2012/06/06 17:28:40 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{E931F0B9-2B67-40B2-99FC-8C6C2DAFF57F}
[2012/05/24 09:30:33 | 017,152,712 | —- | C] (Mozilla) – C:\Users\Brad C\Firefox Setup 13.0b4.exe
[2012/05/16 07:50:55 | 000,516,136 | —- | C] (Bandoo Media Inc) – C:\Users\Brad C\iLividSetupV1.exe
[2012/05/09 16:17:58 | 000,809,288 | —- | C] (AirInstaller Inc.) – C:\Users\Brad C\setup.exe
[2012/05/08 13:17:02 | 004,472,121 | —- | C] (CamStudio Open Source Dev Team ) – C:\Users\Brad C\CamStudio_Setup_v2.6b_r294_(build_24Oct2010).exe
[2012/03/23 12:00:00 | 000,733,280 | —- | C] (Google Inc.) – C:\Users\Brad C\ChromeSetup.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/06 15:01:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2012/07/06 14:52:02 | 000,000,932 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000UA.job
[2012/07/06 14:52:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000UA.job
[2012/07/06 14:52:01 | 000,000,910 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000Core.job
[2012/07/06 14:37:49 | 000,000,193 | —- | M] () – C:\Windows\WORDPAD.INI
[2012/07/06 14:33:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/06 14:30:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/06 13:52:37 | 101,200,596 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/07/06 13:52:09 | 000,487,533 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/07/06 13:45:48 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/06 12:34:01 | 000,220,164 | —- | M] () – C:\Users\Brad C\Desktop\LoneWolfPassiveProfits.pdf
[2012/07/06 11:37:07 | 000,230,548 | —- | M] () – C:\Users\Brad C\Desktop\buildyouronlinemarketingplan.pdf
[2012/07/06 09:56:21 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/06 09:56:21 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/06 09:52:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000Core.job
[2012/07/06 09:49:29 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/06 09:48:53 | 000,000,354 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForBRADC-BRADC-HP$.job
[2012/07/06 09:48:40 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2012/07/04 11:48:27 | 000,001,180 | —- | M] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2012/07/04 05:01:49 | 000,569,220 | —- | M] () – C:\Users\Brad C\Desktop\freetrafficmarketingreport.pdf
[2012/07/04 04:43:30 | 000,001,682 | -HS- | M] () – C:\ProgramData\KGyGaAvL.sys
[2012/07/03 17:00:07 | 000,452,917 | —- | M] () – C:\Users\Brad C\Desktop\tw12345.png
[2012/07/03 16:35:07 | 000,310,273 | —- | M] () – C:\Users\Brad C\Desktop\twitterbackground1.jpg
[2012/07/03 14:59:23 | 000,304,310 | —- | M] () – C:\Users\Brad C\Desktop\Blogging-Toolkit-Suscriber-background1.jpg
[2012/07/02 13:16:46 | 002,348,119 | —- | M] () – C:\Users\Brad C\Desktop\blogandping.pdf
[2012/07/02 11:37:17 | 000,024,799 | —- | M] () – C:\Users\Brad C\Desktop\migraine diary.pdf
[2012/07/02 11:37:06 | 000,014,397 | —- | M] () – C:\Users\Brad C\Desktop\migraine diary.odt
[2012/07/02 10:51:54 | 000,084,459 | —- | M] () – C:\Users\Brad C\Desktop\paperbackstack(2).jpg
[2012/07/02 09:51:42 | 000,061,958 | —- | M] () – C:\Users\Brad C\Desktop\ringbinderlaying(1).jpg
[2012/07/02 09:35:39 | 000,024,999 | —- | M] () – C:\Users\Brad C\Desktop\migraineebook.odt
[2012/07/01 19:06:53 | 000,161,426 | —- | M] () – C:\Users\Brad C\Desktop\10 Tips for Success.pdf
[2012/07/01 19:06:48 | 000,100,017 | —- | M] () – C:\Users\Brad C\Desktop\10 Tips for Success.odt
[2012/07/01 18:49:43 | 000,066,799 | —- | M] () – C:\Users\Brad C\Desktop\paperbackstack(1).jpg
[2012/07/01 12:24:29 | 000,000,982 | —- | M] () – C:\Users\Public\Desktop\CamStudio-Recorder.lnk
[2012/07/01 12:23:44 | 000,015,228 | —- | M] () – C:\Users\Brad C\Desktop\Tips & Tricks to Make Money Online.odt
[2012/07/01 09:44:21 | 000,217,362 | —- | M] () – C:\Users\Brad C\Desktop\Internet Marketing.pdf
[2012/07/01 09:31:39 | 000,347,738 | —- | M] () – C:\Users\Brad C\Desktop\Automate Your Business.pdf
[2012/07/01 09:31:31 | 000,361,127 | —- | M] () – C:\Users\Brad C\Desktop\How To Drive Big Traffic.pdf
[2012/07/01 09:31:23 | 000,384,983 | —- | M] () – C:\Users\Brad C\Desktop\Secrets of the Winners.pdf
[2012/07/01 09:31:12 | 000,369,901 | —- | M] () – C:\Users\Brad C\Desktop\10 Twitter Tips.pdf
[2012/07/01 07:10:41 | 004,472,121 | —- | M] (CamStudio Open Source Dev Team ) – C:\Users\Brad C\Downloads\Documents\CamStudio_Setup_v2.6b_r294_(build_24Oct2010).exe
[2012/07/01 06:53:36 | 000,002,416 | —- | M] () – C:\Users\Brad C\Desktop\Google Chrome.lnk
[2012/06/30 16:44:45 | 072,261,231 | —- | M] () – C:\Users\Brad C\Desktop\TrafficVideosMRR.zip
[2012/06/30 16:05:34 | 001,609,904 | —- | M] () – C:\Users\Brad C\Desktop\the_essential_guide_to_internet_marketing.pdf
[2012/06/30 10:39:10 | 000,834,766 | —- | M] () – C:\Users\Brad C\Desktop\replace-your-job-with-an-internet-business.pdf
[2012/06/30 10:08:44 | 000,002,931 | —- | M] () – C:\Users\Brad C\Desktop\TweetDeck.lnk
[2012/06/30 09:29:58 | 000,187,600 | —- | M] () – C:\Users\Brad C\Desktop\treat-me-good-and-i-treat-you-good_wl29jfr100.pdf
[2012/06/30 09:09:54 | 000,000,336 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForBrad C.job
[2012/06/29 17:07:11 | 000,337,672 | —- | M] () – C:\Users\Brad C\Desktop\IMeye_report.pdf
[2012/06/28 13:08:00 | 000,105,944 | —- | M] () – C:\Users\Brad C\Desktop\Howtobecomesuccessfulinaffiliagemarketing.pdf
[2012/06/28 13:07:52 | 000,278,939 | —- | M] () – C:\Users\Brad C\Desktop\Successful Affiliate Strategies.pdf
[2012/06/28 11:35:16 | 000,002,181 | —- | M] () – C:\Users\Brad C\Desktop\bradleycoats.com.html
[2012/06/28 10:45:31 | 023,911,551 | —- | M] () – C:\Users\Brad C\Desktop\QuickBlogIndexing_PLR.zip
[2012/06/28 10:45:01 | 024,120,316 | —- | M] () – C:\Users\Brad C\Desktop\HowToSetDomainNameservers_PLR.zip
[2012/06/28 10:39:03 | 001,025,264 | —- | M] () – C:\Users\Brad C\Desktop\BlogThemes_201109.zip
[2012/06/28 09:50:05 | 000,173,688 | —- | M] () – C:\Users\Brad C\Desktop\tscc.exe
[2012/06/28 09:41:29 | 143,316,947 | —- | M] () – C:\Users\Brad C\Desktop\CreateStunningVideoSlideshowsForFree_PLR.zip
[2012/06/28 09:38:50 | 002,115,021 | —- | M] () – C:\Users\Brad C\Desktop\OnlineVideo2012_PLR.zip
[2012/06/28 06:59:21 | 000,178,428 | —- | M] () – C:\Users\Brad C\Desktop\All the traffic your website can handle.pdf
[2012/06/27 18:46:51 | 000,136,875 | —- | M] () – C:\Users\Brad C\Desktop\Listbuilding Old and New.odt
[2012/06/27 18:01:20 | 000,057,590 | —- | M] () – C:\Users\Brad C\Desktop\ringbinderlaying.jpg
[2012/06/27 17:43:39 | 000,029,513 | —- | M] () – C:\Users\Brad C\Desktop\Screen-Shot-2012-06-25-at-10.26.09-AM-400x184.png
[2012/06/27 17:21:04 | 000,083,618 | —- | M] () – C:\Users\Brad C\Desktop\paperbackstack.jpg
[2012/06/27 16:27:00 | 000,001,025 | —- | M] () – C:\Users\Public\Desktop\Content Spin Bot.lnk
[2012/06/27 11:54:46 | 000,001,536 | —- | M] () – C:\Users\Public\Desktop\videosqueeze.lnk
[2012/06/26 14:25:52 | 000,916,472 | —- | M] () – C:\Users\Brad C\Desktop\nstf_cheat_sheet.pdf
[2012/06/26 14:18:17 | 000,094,937 | —- | M] () – C:\Users\Brad C\Desktop\NSTF Video 1 Slides.pdf
[2012/06/25 16:37:19 | 000,716,038 | —- | M] () – C:\Users\Brad C\Downloads\Documents\Learn Affiliate Marketing Basics E-book.odt
[2012/06/23 16:40:45 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/23 16:40:45 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/22 16:59:19 | 000,002,533 | —- | M] () – C:\Users\Brad C\Desktop\Skype (2).lnk
[2012/06/22 16:45:02 | 000,001,790 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/06/22 16:41:13 | 079,225,752 | —- | M] (Apple Inc.) – C:\Users\Brad C\iTunes64Setup.exe
[2012/06/22 16:29:05 | 002,068,428 | —- | M] () – C:\Users\Brad C\Desktop\1kblueprintnewpdf.pdf
[2012/06/21 06:45:07 | 000,483,593 | —- | M] () – C:\Users\Brad C\Downloads\Documents\LAMB.png
[2012/06/20 16:16:23 | 004,976,920 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/16 06:03:59 | 000,001,515 | —- | M] () – C:\Users\Brad C\Desktop\TrafficGeneration-ecourse - Shortcut.lnk
[2012/06/15 13:03:55 | 000,305,178 | —- | M] () – C:\Users\Brad C\Desktop\BrandNewEbook.odt
[2012/06/14 15:53:08 | 000,002,107 | —- | M] () – C:\Users\Public\Desktop\Express Zip File Compression Software.lnk
[2012/06/14 15:20:50 | 000,727,381 | —- | M] () – C:\Users\Brad C\Desktop\3waystomineyourlist.pdf
[2012/06/14 15:20:47 | 000,062,105 | —- | M] () – C:\Users\Brad C\Desktop\squeeze.pdf
[2012/06/14 08:43:38 | 000,001,177 | —- | M] () – C:\Users\Public\Desktop\PhotoStage Slideshow Producer.lnk
[2012/06/14 08:02:19 | 000,001,149 | —- | M] () – C:\Users\Brad C\Desktop\AVG PC Tuneup 2011.lnk
[2012/06/13 20:26:42 | 000,797,466 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/13 20:26:42 | 000,662,870 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/13 20:26:42 | 000,122,408 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/13 18:26:20 | 000,001,220 | —- | M] () – C:\Users\Public\Desktop\Affiliate ID Manager Master Rebrander .lnk
[2012/06/13 14:04:34 | 000,001,182 | —- | M] () – C:\Users\Public\Desktop\LibreOffice 3.4.lnk
[2012/06/13 13:59:21 | 001,536,192 | —- | M] (W3i, LLC) – C:\Users\Brad C\Desktop\libreoffice.exe
[2012/06/13 13:50:14 | 000,032,280 | —- | M] () – C:\Users\Brad C\Downloads\Documents\demo.html
[2012/06/12 07:14:56 | 000,001,242 | —- | M] () – C:\Users\Brad C\Desktop\Paint.lnk
[2012/06/11 16:54:12 | 000,006,144 | —- | M] () – C:\Users\Brad C\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/06/11 16:29:05 | 000,001,307 | —- | M] () – C:\Users\Public\Desktop\Tableau Public 6.1.lnk
[2012/06/11 16:24:45 | 000,001,242 | —- | M] () – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk
[2012/06/11 15:30:07 | 000,001,554 | —- | M] () – C:\Users\Brad C\Desktop\LimitlessLeadGenerationGuide - Shortcut.lnk
[2012/06/11 15:17:38 | 000,011,264 | —- | M] () – C:\Users\Brad C\Downloads\Documents\NicheData.db
[2012/06/11 14:57:59 | 000,000,829 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/11 14:57:18 | 000,002,033 | —- | M] () – C:\Users\Brad C\Desktop\Customize Fences.lnk
[2012/06/11 14:52:43 | 000,002,044 | —- | M] () – C:\Users\Public\Desktop\LightScribe.lnk
[2012/06/11 14:48:23 | 000,002,533 | —- | M] () – C:\Users\Brad C\Desktop\Skype.lnk
[2012/06/11 14:45:22 | 000,001,014 | —- | M] () – C:\Users\Brad C\Desktop\Audacity.lnk
[2012/06/11 14:39:31 | 000,000,960 | —- | M] () – C:\Users\Public\Desktop\Allmyapps.lnk
[2012/06/11 14:39:00 | 003,534,288 | —- | M] (Allmyapps) – C:\Users\Brad C\Facebook_video_calling_Allmyapps_Setup.exe
[2012/06/11 14:13:51 | 000,002,464 | —- | M] () – C:\Users\Brad C\Traffic Overdrive - Shortcut.lnk
[2012/06/10 16:34:34 | 000,034,333 | —- | M] () – C:\Users\Brad C\Downloads\Documents\internetnewbiebusinessmodel.odt
[2012/06/10 16:13:13 | 000,302,425 | —- | M] () – C:\Users\Brad C\AppData\Local\funmoods-speeddial.crx
[2012/06/10 16:13:13 | 000,031,470 | —- | M] () – C:\Users\Brad C\AppData\Local\funmoods.crx
[2012/06/09 06:33:54 | 001,364,995 | —- | M] () – C:\Users\Brad C\setup20.exe
[2012/06/09 05:56:13 | 000,304,659 | —- | M] () – C:\Users\Brad C\Downloads\Documents\Free Web Tools.pdf
[2012/06/08 17:31:21 | 000,080,184 | —- | M] () – C:\Users\Brad C\13 Secrets.pdf
[2012/06/08 17:31:11 | 000,026,679 | —- | M] () – C:\Users\Brad C\Downloads\Documents\13 Secrets.odt
[2012/06/08 15:33:09 | 000,164,720 | —- | M] () – C:\Users\Brad C\Extremefreetips.pdf
[2012/06/08 07:29:46 | 000,000,890 | —- | M] () – C:\Users\Brad C\Desktop\ASHelper.lnk
[2012/06/07 14:43:32 | 000,002,802 | —- | M] () – C:\Users\Brad C\AppData\Local\recently-used.xbel
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/07/06 14:37:49 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2012/07/06 12:34:01 | 000,220,164 | —- | C] () – C:\Users\Brad C\Desktop\LoneWolfPassiveProfits.pdf
[2012/07/06 11:37:07 | 000,230,548 | —- | C] () – C:\Users\Brad C\Desktop\buildyouronlinemarketingplan.pdf
[2012/07/04 11:48:27 | 000,001,180 | —- | C] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2012/07/04 05:01:49 | 000,569,220 | —- | C] () – C:\Users\Brad C\Desktop\freetrafficmarketingreport.pdf
[2012/07/03 17:00:06 | 000,452,917 | —- | C] () – C:\Users\Brad C\Desktop\tw12345.png
[2012/07/03 16:35:07 | 000,310,273 | —- | C] () – C:\Users\Brad C\Desktop\twitterbackground1.jpg
[2012/07/03 13:34:53 | 000,304,310 | —- | C] () – C:\Users\Brad C\Desktop\Blogging-Toolkit-Suscriber-background1.jpg
[2012/07/02 13:16:46 | 002,348,119 | —- | C] () – C:\Users\Brad C\Desktop\blogandping.pdf
[2012/07/02 11:37:15 | 000,024,799 | —- | C] () – C:\Users\Brad C\Desktop\migraine diary.pdf
[2012/07/02 11:37:04 | 000,014,397 | —- | C] () – C:\Users\Brad C\Desktop\migraine diary.odt
[2012/07/02 10:51:54 | 000,084,459 | —- | C] () – C:\Users\Brad C\Desktop\paperbackstack(2).jpg
[2012/07/02 09:51:41 | 000,061,958 | —- | C] () – C:\Users\Brad C\Desktop\ringbinderlaying(1).jpg
[2012/07/02 09:35:37 | 000,024,999 | —- | C] () – C:\Users\Brad C\Desktop\migraineebook.odt
[2012/07/01 19:06:52 | 000,161,426 | —- | C] () – C:\Users\Brad C\Desktop\10 Tips for Success.pdf
[2012/07/01 18:49:43 | 000,066,799 | —- | C] () – C:\Users\Brad C\Desktop\paperbackstack(1).jpg
[2012/07/01 18:25:59 | 000,100,017 | —- | C] () – C:\Users\Brad C\Desktop\10 Tips for Success.odt
[2012/07/01 12:24:29 | 000,000,982 | —- | C] () – C:\Users\Public\Desktop\CamStudio-Recorder.lnk
[2012/07/01 12:23:42 | 000,015,228 | —- | C] () – C:\Users\Brad C\Desktop\Tips & Tricks to Make Money Online.odt
[2012/07/01 09:44:21 | 000,217,362 | —- | C] () – C:\Users\Brad C\Desktop\Internet Marketing.pdf
[2012/07/01 09:31:39 | 000,347,738 | —- | C] () – C:\Users\Brad C\Desktop\Automate Your Business.pdf
[2012/07/01 09:31:31 | 000,361,127 | —- | C] () – C:\Users\Brad C\Desktop\How To Drive Big Traffic.pdf
[2012/07/01 09:31:23 | 000,384,983 | —- | C] () – C:\Users\Brad C\Desktop\Secrets of the Winners.pdf
[2012/07/01 09:31:12 | 000,369,901 | —- | C] () – C:\Users\Brad C\Desktop\10 Twitter Tips.pdf
[2012/06/30 16:43:42 | 072,261,231 | —- | C] () – C:\Users\Brad C\Desktop\TrafficVideosMRR.zip
[2012/06/30 16:05:33 | 001,609,904 | —- | C] () – C:\Users\Brad C\Desktop\the_essential_guide_to_internet_marketing.pdf
[2012/06/30 10:39:09 | 000,834,766 | —- | C] () – C:\Users\Brad C\Desktop\replace-your-job-with-an-internet-business.pdf
[2012/06/30 09:29:57 | 000,187,600 | —- | C] () – C:\Users\Brad C\Desktop\treat-me-good-and-i-treat-you-good_wl29jfr100.pdf
[2012/06/29 17:07:11 | 000,337,672 | —- | C] () – C:\Users\Brad C\Desktop\IMeye_report.pdf
[2012/06/28 13:08:00 | 000,105,944 | —- | C] () – C:\Users\Brad C\Desktop\Howtobecomesuccessfulinaffiliagemarketing.pdf
[2012/06/28 13:07:51 | 000,278,939 | —- | C] () – C:\Users\Brad C\Desktop\Successful Affiliate Strategies.pdf
[2012/06/28 11:17:16 | 000,002,181 | —- | C] () – C:\Users\Brad C\Desktop\bradleycoats.com.html
[2012/06/28 10:45:18 | 023,911,551 | —- | C] () – C:\Users\Brad C\Desktop\QuickBlogIndexing_PLR.zip
[2012/06/28 10:44:45 | 024,120,316 | —- | C] () – C:\Users\Brad C\Desktop\HowToSetDomainNameservers_PLR.zip
[2012/06/28 10:39:02 | 001,025,264 | —- | C] () – C:\Users\Brad C\Desktop\BlogThemes_201109.zip
[2012/06/28 09:50:04 | 000,173,688 | —- | C] () – C:\Users\Brad C\Desktop\tscc.exe
[2012/06/28 09:39:28 | 143,316,947 | —- | C] () – C:\Users\Brad C\Desktop\CreateStunningVideoSlideshowsForFree_PLR.zip
[2012/06/28 09:38:48 | 002,115,021 | —- | C] () – C:\Users\Brad C\Desktop\OnlineVideo2012_PLR.zip
[2012/06/28 06:59:19 | 000,178,428 | —- | C] () – C:\Users\Brad C\Desktop\All the traffic your website can handle.pdf
[2012/06/27 18:46:49 | 000,136,875 | —- | C] () – C:\Users\Brad C\Desktop\Listbuilding Old and New.odt
[2012/06/27 18:01:19 | 000,057,590 | —- | C] () – C:\Users\Brad C\Desktop\ringbinderlaying.jpg
[2012/06/27 17:43:37 | 000,029,513 | —- | C] () – C:\Users\Brad C\Desktop\Screen-Shot-2012-06-25-at-10.26.09-AM-400x184.png
[2012/06/27 17:21:04 | 000,083,618 | —- | C] () – C:\Users\Brad C\Desktop\paperbackstack.jpg
[2012/06/27 16:27:00 | 000,001,025 | —- | C] () – C:\Users\Public\Desktop\Content Spin Bot.lnk
[2012/06/27 11:54:46 | 000,001,536 | —- | C] () – C:\Users\Public\Desktop\videosqueeze.lnk
[2012/06/26 18:22:01 | 000,000,340 | —- | C] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2012/06/26 14:25:51 | 000,916,472 | —- | C] () – C:\Users\Brad C\Desktop\nstf_cheat_sheet.pdf
[2012/06/26 14:18:17 | 000,094,937 | —- | C] () – C:\Users\Brad C\Desktop\NSTF Video 1 Slides.pdf
[2012/06/22 16:59:19 | 000,002,533 | —- | C] () – C:\Users\Brad C\Desktop\Skype (2).lnk
[2012/06/22 16:45:02 | 000,001,790 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/06/22 16:29:05 | 002,068,428 | —- | C] () – C:\Users\Brad C\Desktop\1kblueprintnewpdf.pdf
[2012/06/21 07:29:21 | 000,716,038 | —- | C] () – C:\Users\Brad C\Downloads\Documents\Learn Affiliate Marketing Basics E-book.odt
[2012/06/21 06:45:07 | 000,483,593 | —- | C] () – C:\Users\Brad C\Downloads\Documents\LAMB.png
[2012/06/16 05:10:39 | 000,002,931 | —- | C] () – C:\Users\Brad C\Desktop\TweetDeck.lnk
[2012/06/15 13:03:51 | 000,305,178 | —- | C] () – C:\Users\Brad C\Desktop\BrandNewEbook.odt
[2012/06/15 11:46:30 | 000,175,648 | —- | C] () – C:\Users\Brad C\Downloads\Documents\List Building for Beginners.pdf
[2012/06/14 16:27:39 | 001,548,484 | —- | C] () – C:\Users\Brad C\Desktop\nlb.exe
[2012/06/14 15:53:08 | 000,002,107 | —- | C] () – C:\Users\Public\Desktop\Express Zip File Compression Software.lnk
[2012/06/14 15:53:08 | 000,001,893 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Zip File Compression Software.lnk
[2012/06/14 15:20:50 | 000,727,381 | —- | C] () – C:\Users\Brad C\Desktop\3waystomineyourlist.pdf
[2012/06/14 15:20:47 | 000,062,105 | —- | C] () – C:\Users\Brad C\Desktop\squeeze.pdf
[2012/06/14 08:43:38 | 000,001,177 | —- | C] () – C:\Users\Public\Desktop\PhotoStage Slideshow Producer.lnk
[2012/06/14 08:43:37 | 000,001,189 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoStage Slideshow Producer.lnk
[2012/06/14 08:02:19 | 000,001,149 | —- | C] () – C:\Users\Brad C\Desktop\AVG PC Tuneup 2011.lnk
[2012/06/13 18:26:20 | 000,001,220 | —- | C] () – C:\Users\Public\Desktop\Affiliate ID Manager Master Rebrander .lnk
[2012/06/13 14:04:34 | 000,001,182 | —- | C] () – C:\Users\Public\Desktop\LibreOffice 3.4.lnk
[2012/06/13 13:50:14 | 000,032,280 | —- | C] () – C:\Users\Brad C\Downloads\Documents\demo.html
[2012/06/13 13:50:13 | 000,391,434 | —- | C] () – C:\Users\Brad C\Downloads\Documents\book.swf
[2012/06/12 07:14:56 | 000,001,242 | —- | C] () – C:\Users\Brad C\Desktop\Paint.lnk
[2012/06/11 16:29:05 | 000,001,319 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tableau Public 6.1.lnk
[2012/06/11 16:29:05 | 000,001,307 | —- | C] () – C:\Users\Public\Desktop\Tableau Public 6.1.lnk
[2012/06/11 16:26:24 | 000,001,515 | —- | C] () – C:\Users\Brad C\Desktop\TrafficGeneration-ecourse - Shortcut.lnk
[2012/06/11 16:24:45 | 000,001,242 | —- | C] () – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk
[2012/06/11 15:30:07 | 000,001,554 | —- | C] () – C:\Users\Brad C\Desktop\LimitlessLeadGenerationGuide - Shortcut.lnk
[2012/06/11 15:17:38 | 000,011,264 | —- | C] () – C:\Users\Brad C\Downloads\Documents\NicheData.db
[2012/06/11 14:57:59 | 000,000,829 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/11 14:57:18 | 000,002,033 | —- | C] () – C:\Users\Brad C\Desktop\Customize Fences.lnk
[2012/06/11 14:52:43 | 000,002,044 | —- | C] () – C:\Users\Public\Desktop\LightScribe.lnk
[2012/06/11 14:48:23 | 000,002,533 | —- | C] () – C:\Users\Brad C\Desktop\Skype.lnk
[2012/06/11 14:45:22 | 000,001,026 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2012/06/11 14:45:22 | 000,001,014 | —- | C] () – C:\Users\Brad C\Desktop\Audacity.lnk
[2012/06/11 14:39:31 | 000,000,960 | —- | C] () – C:\Users\Public\Desktop\Allmyapps.lnk
[2012/06/10 16:34:32 | 000,034,333 | —- | C] () – C:\Users\Brad C\Downloads\Documents\internetnewbiebusinessmodel.odt
[2012/06/10 16:13:22 | 000,302,425 | —- | C] () – C:\Users\Brad C\AppData\Local\funmoods-speeddial.crx
[2012/06/10 16:13:18 | 000,087,552 | —- | C] () – C:\Windows\SysNative\custmon64i.dll
[2012/06/10 16:13:18 | 000,031,470 | —- | C] () – C:\Users\Brad C\AppData\Local\funmoods.crx
[2012/06/09 06:33:52 | 001,364,995 | —- | C] () – C:\Users\Brad C\setup20.exe
[2012/06/09 05:56:13 | 000,304,659 | —- | C] () – C:\Users\Brad C\Downloads\Documents\Free Web Tools.pdf
[2012/06/08 17:31:19 | 000,080,184 | —- | C] () – C:\Users\Brad C\13 Secrets.pdf
[2012/06/08 17:31:09 | 000,026,679 | —- | C] () – C:\Users\Brad C\Downloads\Documents\13 Secrets.odt
[2012/06/08 15:33:06 | 000,164,720 | —- | C] () – C:\Users\Brad C\Extremefreetips.pdf
[2012/06/08 07:29:46 | 000,000,890 | —- | C] () – C:\Users\Brad C\Desktop\ASHelper.lnk
[2012/06/07 14:43:32 | 000,002,802 | —- | C] () – C:\Users\Brad C\AppData\Local\recently-used.xbel
[2012/06/07 13:59:27 | 000,000,899 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
[2012/05/24 09:31:26 | 000,001,056 | —- | C] () – C:\Users\Brad C\Mozilla Firefox.lnk
[2012/05/11 15:08:19 | 000,002,212 | —- | C] () – C:\Users\Brad C\WinZip.lnk
[2012/05/09 17:10:02 | 000,001,074 | —- | C] () – C:\Users\Brad C\Free Download Manager.lnk
[2012/05/02 13:48:11 | 000,001,467 | —- | C] () – C:\Users\Brad C\my affiliate marketing course - Shortcut.lnk
[2012/05/02 12:08:16 | 000,001,873 | —- | C] () – C:\Users\Brad C\01 - Affiliate Marketer's Handbook - Shortcut.lnk
[2012/05/02 11:44:13 | 000,001,500 | —- | C] () – C:\Users\Brad C\Super Affiliate Secrets Exposed!.lnk
[2012/05/01 17:14:51 | 000,009,585 | —- | C] () – C:\Users\Brad C\workinprogress.jpg
[2012/05/01 16:55:19 | 000,072,527 | —- | C] () – C:\Users\Brad C\images3.png
[2012/05/01 15:08:20 | 000,136,688 | —- | C] () – C:\Users\Brad C\Outsourcing-Strategies.pdf
[2012/04/30 14:52:01 | 000,176,198 | —- | C] () – C:\Users\Brad C\Weight loss for a Healthier Lifestyle.pdf
[2012/04/30 14:02:19 | 000,109,445 | —- | C] () – C:\Users\Brad C\Weight loss for a Healthier Lifestyle.odt
[2012/04/30 12:50:31 | 000,003,272 | —- | C] () – C:\Users\Brad C\Ebook - Shortcut.lnk
[2012/04/29 13:26:21 | 000,001,981 | —- | C] () – C:\Users\Brad C\socrates - Shortcut.lnk
[2012/04/29 10:36:24 | 000,358,835 | —- | C] () – C:\Users\Brad C\free-header-image-2.psd
[2012/04/28 21:49:18 | 000,011,614 | —- | C] () – C:\Users\Brad C\new opt in form.html
[2012/04/28 10:39:17 | 000,070,251 | —- | C] () – C:\Users\Brad C\QuickHealthyWeightLoss.odt
[2012/04/25 17:43:20 | 000,001,131 | —- | C] () – C:\Users\Brad C\Thinspiration.html
[2012/04/24 19:40:56 | 000,002,293 | —- | C] () – C:\Users\Brad C\Foods_That_Kill_Fat_mg - Shortcut.lnk
[2012/04/24 19:37:36 | 000,002,410 | —- | C] () – C:\Users\Brad C\how-to-knock-20-years-off-your-body - Shortcut.lnk
[2012/04/24 16:48:49 | 000,624,374 | —- | C] () – C:\Users\Brad C\7figuresuccessformulatrafficguide.pdf
[2012/04/24 10:56:49 | 000,001,614 | —- | C] () – C:\Users\Brad C\Worlds-Shortest-Viral-Book.pdf
[2012/04/24 10:37:57 | 000,282,283 | —- | C] () – C:\Users\Brad C\Ultimate-ClickBank.pdf
[2012/04/23 17:13:07 | 000,006,140 | —- | C] () – C:\Users\Brad C\Image1.png
[2012/04/23 14:35:46 | 000,002,464 | —- | C] () – C:\Users\Brad C\Traffic Overdrive - Shortcut.lnk
[2012/04/22 21:03:02 | 000,001,701 | —- | C] () – C:\Users\Brad C\TrafficExplosion - Shortcut.lnk
[2012/04/21 17:19:31 | 000,000,132 | —- | C] () – C:\Users\Brad C\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2012/04/15 13:12:00 | 000,001,792 | —- | C] () – C:\Users\Brad C\Newsletter - Shortcut.lnk
[2012/04/12 10:21:27 | 000,001,315 | —- | C] () – C:\Users\Brad C\The Weather Channel App.lnk
[2012/04/08 09:25:44 | 000,001,738 | —- | C] () – C:\Users\Brad C\feuxjo - Shortcut.lnk
[2012/01/22 17:22:12 | 000,001,017 | —- | C] () – C:\Program Files (x86)\Commission Streamer.lnk
[2012/01/22 17:22:12 | 000,000,967 | —- | C] () – C:\Program Files (x86)\Update Commission Streamer.lnk
[2012/01/04 18:16:43 | 000,000,015 | —- | C] () – C:\Windows\cfwin.ini
[2012/01/04 18:16:41 | 000,000,110 | —- | C] () – C:\Windows\cfwinlib.ini
[2011/11/23 23:37:29 | 000,742,442 | —- | C] () – C:\Windows\XHeader Uninstaller.exe
[2011/09/11 16:47:13 | 000,024,209 | —- | C] () – C:\Users\Brad C\AppData\Roaming\UserTile.png
[2011/08/29 13:47:42 | 000,538,222 | —- | C] () – C:\Users\Brad C\NonStopViralTraffic.pdf
[2011/05/24 18:58:23 | 000,006,144 | —- | C] () – C:\Users\Brad C\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/24 18:57:56 | 000,001,682 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2011/05/13 11:16:11 | 000,001,854 | —- | C] () – C:\Users\Brad C\AppData\Roaming\GhostObjGAFix.xml
[2011/04/18 07:49:36 | 000,777,312 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/03/29 05:46:58 | 000,414,113 | —- | C] () – C:\Users\Brad C\Turbo_Traffic_ebook.pdf
[2010/10/25 03:47:34 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/10/25 03:38:46 | 000,002,857 | —- | C] () – C:\Windows\SysWow64\atipblup.dat
[2010/10/25 03:37:37 | 000,000,299 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini
[2010/10/25 03:37:37 | 000,000,240 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini
[2010/10/16 14:42:34 | 000,000,188 | —- | C] () – C:\Windows\SysWow64\HPWA.ini
[2010/09/21 12:30:44 | 000,007,736 | —- | C] () – C:\Windows\hpDSTRES.DLL
[2010/07/28 17:08:46 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2010/07/28 17:08:44 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2010/07/28 17:08:42 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2010/07/28 16:14:38 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/07/28 16:14:38 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
========== LOP Check ==========
[2012/01/17 19:17:39 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Affilorama
[2012/06/11 14:39:45 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Allmyapps
[2011/08/17 11:40:52 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Archon Media
[2012/06/04 08:24:38 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Audacity
[2011/09/28 19:22:22 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Avanquest
[2012/06/14 08:37:29 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\AVG
[2012/03/13 20:31:53 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\AVG2012
[2012/05/09 17:09:28 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Babylon
[2011/11/16 16:25:28 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\CoffeeCup Software
[2011/11/21 17:12:07 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\com.fastcashcommissions.fasttrafficmagnet
[2011/11/21 12:50:44 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\com.fastcashcommissions.fasttrafficsniper
[2012/03/14 08:14:48 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\CommissionMultiplier
[2011/04/16 11:03:25 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\DigitalPersona
[2012/06/13 20:12:28 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\DVDVideoSoft
[2011/10/05 09:26:26 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Easy Click Commissions
[2012/03/23 15:29:11 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\eGames
[2012/02/15 01:48:00 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\FileZilla
[2011/11/04 17:06:58 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\GetRightToGo
[2011/11/22 02:32:06 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\IBP
[2011/11/15 15:37:31 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\IncomeGenesis
[2012/07/04 11:48:22 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\IObit
[2012/05/24 09:09:29 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\IrfanView
[2011/09/18 18:22:23 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Keyword Strategy Studio Pro
[2012/06/19 06:32:27 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Kingsoft
[2011/10/10 00:15:20 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\KompoZer
[2012/06/13 14:06:33 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\LibreOffice
[2011/11/23 19:24:08 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\MAGIX
[2011/05/13 11:17:55 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2011/09/25 19:05:10 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Nitro PDF
[2011/10/24 20:45:39 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Nvu
[2011/09/25 19:03:53 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\OpenCandy
[2011/05/08 22:20:27 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\OpenOffice.org
[2012/05/21 15:22:02 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\PCTools
[2012/03/31 21:57:59 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\PDAppFlex
[2012/06/11 15:06:26 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\pdfforge
[2011/10/15 21:25:44 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\PrimoPDF
[2011/12/30 16:56:43 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\SlimBrowser
[2012/07/05 15:34:52 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\SoftGrid Client
[2012/07/06 09:53:21 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Software Informer
[2011/04/16 11:09:33 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Stardock
[2012/05/23 08:32:26 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\TestApp
[2011/11/29 13:04:02 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\ThumbsPlus
[2011/05/06 10:03:58 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Thunderbird
[2011/04/18 07:59:30 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\TP
[2012/06/06 14:23:07 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Traffic Travis v4
[2012/01/26 19:48:28 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\TrafficInitiator-Air
[2012/06/30 10:07:18 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\TweetAdder3
[2011/11/14 17:45:29 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\ubot
[2012/04/22 11:09:48 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Ulead Systems
[2012/06/26 18:22:05 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Visan
[2011/10/30 22:41:10 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\WildTangent
[2011/05/16 12:45:17 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Windows Live Writer
[2012/07/06 09:49:51 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\ZumoDrive
[2012/07/06 14:52:01 | 000,000,910 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000Core.job
[2012/07/06 14:52:02 | 000,000,932 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000UA.job
[2012/07/04 20:03:09 | 000,032,612 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/05/23 08:13:04 | 000,014,253 | —- | M] () – C:\alotserviceruntime.log
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2008/04/11 10:07:18 | 000,003,820 | —- | M] () – C:\eula.1028.txt
[2008/04/11 10:07:18 | 000,015,428 | —- | M] () – C:\eula.1031.txt
[2008/04/11 10:07:18 | 000,010,058 | —- | M] () – C:\eula.1033.txt
[2008/04/11 10:07:18 | 000,012,246 | —- | M] () – C:\eula.1036.txt
[2008/04/11 10:07:18 | 000,013,912 | —- | M] () – C:\eula.1040.txt
[2008/04/11 10:07:18 | 000,005,868 | —- | M] () – C:\eula.1041.txt
[2008/04/11 10:07:18 | 000,005,970 | —- | M] () – C:\eula.1042.txt
[2008/04/11 10:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2008/04/11 10:07:18 | 000,003,814 | —- | M] () – C:\eula.2052.txt
[2008/04/11 10:07:18 | 000,012,936 | —- | M] () – C:\eula.3082.txt
[2008/04/11 10:07:18 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/07/06 09:48:40 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2008/04/11 08:03:48 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2008/04/11 10:07:18 | 000,000,843 | —- | M] () – C:\install.ini
[2008/04/11 08:03:48 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 08:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 08:03:48 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 08:03:48 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 08:03:48 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 08:03:48 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 08:03:48 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 10:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 08:03:48 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 08:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2012/05/23 08:13:04 | 000,020,374 | —- | M] () – C:\INSTALLHELPER.LOG
[2012/07/06 09:48:40 | 4083,007,488 | -HS- | M] () – C:\pagefile.sys
[2012/05/02 13:00:07 | 000,000,448 | —- | M] () – C:\user.js
[2008/04/11 10:07:18 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2008/04/11 10:09:38 | 003,797,292 | —- | M] () – C:\VC_RED.cab
[2008/04/11 10:11:40 | 000,233,472 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2011/07/03 19:13:07 | 000,001,718 | -HS- | M] () – C:\Users\Brad C\AppData\Roaming\Microsoft\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2012/01/22 17:22:12 | 000,001,017 | —- | M] () – C:\Program Files (x86)\Commission Streamer.lnk
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
[2012/01/22 17:22:12 | 000,000,967 | —- | M] () – C:\Program Files (x86)\Update Commission Streamer.lnk
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/28 17:51:32 | 000,000,221 | -HS- | M] () – C:\Users\Brad C\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/09/03 19:13:42 | 000,277,600 | —- | M] (CyberLink Corp.) – C:\Users\Brad C\Desktop\HPMediaSmartWebcam.exe
[2012/06/13 13:59:21 | 001,536,192 | —- | M] (W3i, LLC) – C:\Users\Brad C\Desktop\libreoffice.exe
[2006/03/29 19:37:40 | 001,548,484 | —- | M] () – C:\Users\Brad C\Desktop\nlb.exe
[2012/06/28 09:50:05 | 000,173,688 | —- | M] () – C:\Users\Brad C\Desktop\tscc.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 98 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:F49E02D5
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:F73EA84D
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:F1CBBAF0
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:82111599
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:CFF654D3
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:B9A60C8F
< End of report >
OTL Extras logfile created on: 7/6/2012 3:01:29 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Brad C\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.80 Gb Total Physical Memory | 1.06 Gb Available Physical Memory | 27.91% Memory free
7.60 Gb Paging File | 4.41 Gb Available in Paging File | 58.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 668.10 Gb Total Space | 591.32 Gb Free Space | 88.51% Space Free | Partition Type: NTFS
Drive D: | 30.24 Gb Total Space | 4.44 Gb Free Space | 14.69% Space Free | Partition Type: NTFS
Drive F: | 98.87 Mb Total Space | 83.72 Mb Free Space | 84.68% Space Free | Partition Type: FAT32
Computer Name: BRADC-BRADC-HP | User Name: Brad C | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\PROGRA~2\COFFEE~1\coffee.exe" "%1" (CoffeeCup Software)
htmlfile [open] – Reg Error: Key error.
htmlfile [opennew] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [Browse with Corel PaintShop Photo Pro X3] – "c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\Corel Paint Shop Pro Photo.exe" "%L" (Corel, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Key error.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\PROGRA~2\COFFEE~1\coffee.exe" "%1" (CoffeeCup Software)
htmlfile [open] – Reg Error: Key error.
htmlfile [opennew] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [Browse with Corel PaintShop Photo Pro X3] – "c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\Corel Paint Shop Pro Photo.exe" "%L" (Corel, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Key error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{19597BB1-4C0D-445A-91E1-A50CEA98B102}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{1F4CBAFA-3407-420F-8577-4BD6C4C9C530}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{26BA617B-D372-4473-815F-5D294A60C9E4}" = lport=10243 | protocol=6 | dir=in | app=system |
"{2E58C59E-2C52-4EA9-AA23-9364DC7C6227}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{319E2D5C-7E1C-47AC-B8CA-A2C4543308DE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{344E1A98-D8B6-4300-AFB7-A172CC2B4FBB}" = lport=139 | protocol=6 | dir=in | app=system |
"{366B0C0D-D690-42C8-B52F-EF01FBC334F0}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{412921DD-17B7-4F79-ADDE-74165E45AD98}" = rport=137 | protocol=17 | dir=out | app=system |
"{428BF949-CC40-4252-ACAC-1FDB4D4B8E97}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{43AE201E-9DBB-4184-A757-0C6E7A309338}" = lport=445 | protocol=6 | dir=in | app=system |
"{5D5AB864-43EA-491E-BD2F-14EF9ECDB28F}" = lport=2799 | protocol=6 | dir=in | name=altova license metering port (tcp) |
"{6494BEDF-E1E7-4CAC-80F6-91342FC56560}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8281A89D-CD03-4988-8799-EC7A98A7C90E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{89BEDD83-4877-466F-8DAA-1726A7A1671A}" = rport=10243 | protocol=6 | dir=out | app=system |
"{92FDEE2A-92DC-49AE-B436-4CFBD91329E2}" = rport=139 | protocol=6 | dir=out | app=system |
"{95243C02-2C73-43A8-A777-7ED0619423F8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{96E08991-D28E-410D-B0A9-E6AC78F2EFCF}" = rport=138 | protocol=17 | dir=out | app=system |
"{97A93E76-29F3-4DF6-8348-548170552FFD}" = lport=2799 | protocol=17 | dir=in | name=altova license metering port (udp) |
"{9A56A1B6-BB51-4497-89F4-92EDED8B430E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A6882FBF-BF5A-4391-8D57-059F307A71D4}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{A9C5D378-6D36-49E6-8C83-EAA493DB4078}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B1A52194-F8ED-4EED-90F4-D0C50EDDC59A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B5EFCC30-E476-47ED-A727-5E91AF28380D}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{BB5ED2DF-59CB-4F3F-850B-BEA79109F96A}" = rport=445 | protocol=6 | dir=out | app=system |
"{C1FE3830-9F8F-44CA-9373-67E40607A113}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{D55BA07D-29B2-4EBE-8BEB-7E7674FA0944}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DAF32865-72FB-4A15-9A7B-DE6E5BE2ED7A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EBB0BA4A-2A0C-48A9-9042-D4C7C38357C3}" = lport=138 | protocol=17 | dir=in | app=system |
"{EC77558A-171B-462B-9624-DB0D8FF6FBF8}" = lport=137 | protocol=17 | dir=in | app=system |
"{EE83D38A-96D7-4164-A7E5-02BACBE9E466}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{F30BD097-9D87-4EEA-A04B-878D2DA6FDDD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F3AE84C8-1979-48B7-BB1E-136DD0C71A0C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FE8FC3AA-2DEC-4AFA-8EF1-8378C0CCF29D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FECF0628-975B-4D0F-A12D-8DE72106F3D9}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FF417F25-FFD0-403A-A03F-7831E64ABB9E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{012DB1E2-5BA9-48C4-98A9-C5E53480BCD8}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{02AB7CF2-4A1D-419E-88AA-20BA15FE570B}" = protocol=6 | dir=out | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe |
"{0A6644DF-32A6-4747-83F5-DD46018DEA73}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{167A3DB7-4866-4AB8-B7E0-8C80573A42F4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{17708663-162E-4E56-8ED7-F436A3077995}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{17DF2CA4-CABA-4AD1-A513-85C29F4F2905}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{18C54DAA-BB5D-4CBE-9F12-791C37386797}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{1B11BAB2-F8E5-4DBC-81D0-581E009B2C87}" = dir=in | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe |
"{1D870A5D-29D8-4834-8BF6-5D07EEFF13FC}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{2920D607-598A-4159-B2EC-3214BE2342A0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2B39A564-FF92-44C2-96F9-FA53B6D3F52E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2E2B96FD-90E4-4931-B027-AB21AA103E54}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{2E96BD0B-CA71-4A9E-AD7A-45C2F6793941}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{2F9AE797-02AE-4F50-89C4-B1A2A5223D76}" = protocol=6 | dir=out | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe |
"{30F1D8D0-6E0B-4F3C-99E7-36CCCA75C71B}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{31524F41-F598-4380-BC00-34A7E42475BC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{347D1738-E9C0-49B7-B29C-45A8D832CA53}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{3935C2B5-BB4B-40E7-B269-A50B0A84B201}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{3BFEE9BE-3E92-47AA-B7BA-CF3BC8BFC2BB}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{4269FF99-AA02-4EEB-A8BF-0E34CCD17B47}" = protocol=17 | dir=in | app=c:\program files (x86)\iwin games\iwingames.exe |
"{44DB90D1-904D-4754-B3E5-C4B7A0D57281}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{466A8946-F8EA-4EB7-9BF0-F129F4350050}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{47566C82-2438-4578-A55F-6BA764066056}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4EAB3CBE-F91F-4702-8858-2287F7F8B198}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{4F5D8B0B-158B-4ED2-848B-208B5C97D209}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{51E4E683-0820-43A4-93EA-7D46D864ABD4}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\photo\hpmediasmartphoto.exe |
"{531E4EA2-A739-42F8-8776-83D60AA614FF}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr8.exe |
"{56F5FD59-1693-4BF9-AB37-ECFE2F8C9E00}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\music\hptouchsmartmusic.exe |
"{57BBD81D-A081-4604-8374-7BD56FC3E0D3}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{64ED9658-9646-45AF-98FC-112236C13822}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{67585892-4DF5-48D3-A6BD-7D735B9DF7EC}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{6E0F85E1-E81D-41F5-89FE-49D94D313B00}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{6FC9FA5E-FE7C-4E12-9610-8D5EDC07FCCE}" = protocol=17 | dir=in | app=c:\program files (x86)\iwin games\webupdater.exe |
"{76205CB0-ACA0-459A-9B59-4D09B9B85C55}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{7953EEAE-92E7-4C92-8F36-8CB75F3EB5A2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7E056D9E-D868-4520-9A57-E82968D5CA43}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\video\hpmediasmartvideo.exe |
"{8C76CFBF-3952-40F6-BB9D-0C5B3193E39B}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{8D8B90D0-7A85-4F10-B0E4-D9385C487418}" = protocol=6 | dir=out | app=system |
"{8F7862A6-090A-448C-81B4-624FA64A5EBA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9B48BD76-01D4-4C6A-A0AB-CF8C88E8BCC0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A0F6D422-E7D9-4AFB-80A0-A2646D582C0A}" = protocol=6 | dir=in | app=c:\program files (x86)\iwin games\iwingames.exe |
"{A2DE498D-2AB9-4DE7-9D94-27038E4E7A69}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{ABF9F627-0D4F-43A2-8160-8C2228671038}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B03CFFCD-DF1A-48C0-BDE6-213895C33FEA}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{B462EBAB-194E-41E1-8634-24AB30D11704}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{BE7B332F-312E-49AE-966B-97D2F3B71796}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{C6EBCCC0-FF46-43E7-AE70-061C05849E6B}" = protocol=17 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |
"{C7269815-5F46-44B2-B2CB-E078725479C6}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{C85A73FD-9AFD-462C-859B-268B4A2ED22F}" = dir=out | app=c:\program files (x86)\hewlett-packard\hp clouddrive\zumodrive.exe |
"{CCBDC39A-76DE-4CA8-9022-F918AC526E54}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{D1E2A091-61CF-4326-B5C0-434C71461B19}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp clouddrive\zumodrive.exe |
"{D6FCFC6A-F902-4CA8-B292-914A279818E3}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{DB9C4F97-0A5F-43B7-9D9E-03ABE7E3BE78}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{EFA5ECC5-EFF9-4F3E-9CDF-300C7DB58C8E}" = dir=in | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe |
"{F1219C65-6FDF-4C7B-B60D-AB2344BACE0B}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{F373AB66-9210-45CB-9DDA-00A04BC764A1}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{F75699BF-D34D-4F52-BF63-F1BEA2F1B471}" = protocol=6 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |
"{FB3B073D-7014-42A4-B4FE-76AC0EBC9CC0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{FD021AE2-D32D-48A3-BD03-47F1E55FC42A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FE5055FE-A593-422A-A51B-ED57F06A6BCE}" = protocol=6 | dir=in | app=c:\program files (x86)\iwin games\webupdater.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{09BDCC02-80F2-4EFB-8F1B-A807D2C38E31}" = HP MediaSmart Movies and TV
"{10CD364B-FFCC-48BE-B469-B9622A033075}" = Fences
"{13DCC2C7-454D-42F0-A892-E0E9A5DE4E67}" = HP Wireless Assistant
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F86416021FF}" = Java™ 6 Update 21 (64-bit)
"{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services
"{336D0C35-8A85-403a-B9D2-65C292C39087}_is1" = Web Assistant 2.0.0.430
"{3C8159DD-1890-4625-A5B2-E3D8D78D4486}" = AVG 2012
"{426FAE9F-7373-496E-A215-9DB7EF4398CF}" = Validity Sensors DDK
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5BF97E02-2F6A-412A-BB4D-B6E2DC65FCA7}" = HP SimplePass Identity Protection
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
"{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}" = Bing Maps 3D
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
"{857B32C1-7C87-40B5-B2A5-D06F49B80002}" = AVG 2012
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A04108F4-71E9-FD90-D73D-2058DF6987F4}" = ATI Catalyst Install Manager
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BE6725F2-6D15-477C-86C6-4522B8569D62}" = HP MediaSmart SmartMenu
"{C84FFB07-C687-45CF-91C8-868DB8D8C8CD}" = HP 3D DriveGuard
"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6246243-CF06-4E40-8A37-C3B537695C36}" = Share64
"{FED4086D-51A8-E88C-1CF9-BA21A50470EE}" = ccc-utility64
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"AVG" = AVG 2012
"Broadcom 802.11 Wireless LAN Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CCleaner" = CCleaner
"GIMP-2_is1" = GIMP 2.8.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"PDF Creator" = PDF Creator
"SynTPDeinstKey" = Synaptics Pointing Device Driver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{D1AEB5DB-04FA-489D-94EF-8600898B93EE}" = Corel PaintShop Photo Pro X3
"_{F072CA07-A781-45E4-9975-C033A73019CF}" = Corel VideoStudio Pro X3
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{00FB9AA8-5FFF-DDCE-DA2E-530994B59217}" = CCC Help Finnish
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{045C16AD-B2E5-43D0-BB51-2F1987D91038}" = HP Documentation
"{05BA3547-6C5C-7D39-4D23-DB5E61D8DD79}" = Income Genesis
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0965F857-DAAD-4F93-8054-0E2EC3C8C5B0}" = SweetIM for Messenger 3.6
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0EDEB615-1A60-425E-8306-0E10519C7B55}" = RoxioNow Player
"{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1991D8C3-8354-2228-401C-D3D105CA2AC4}" = CCC Help Chinese Traditional
"{19B9DAD6-5E6E-4B80-8EFE-314B5638D6D4}" = Xara 3D Maker 7
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1E6E990A-728D-4700-9B0A-2CA541C93A12}" = Catalyst Control Center - Branding
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2A738B10-A5C9-4525-8198-5B99C66E0A56}" = My Ebook Library
"{2D8539EE-3F50-94DB-2605-047B33558C70}" = CCC Help Thai
"{2EA3D6B2-157E-4112-A3AB-BF17E16661C3}" = HP MediaSmart/TouchSmart Netflix
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2FA75B40-17C9-4D22-88CA-80A5D52FAB13}" = LightScribe System Software
"{2FF2BBBA-341C-4F36-AB55-7398184733CE}" = CCC Help Italian
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{30296046-9CEB-4E8F-86BA-668155D123B3}_is1" = Spin Writer Pro version 1.0
"{31EEA563-3544-4EA1-8773-BCBF83F9627A}" = HP Software Framework
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33C8C01E-4787-482B-9D2C-AB8221FCC01D}" = IObit Toolbar v6.0
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{3B834B54-EC4B-48E2-BFC6-03FF5DA06F62}" = Adobe Shockwave Player 11.5
"{3DA41E54-9526-40C0-8456-66B09379DFCC}" = PaintShop Photo Pro X3 Registration Incentive
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{4717BD4A-E16A-41E9-B0D8-0BD931DAED96}" = CommentKahuna
"{491ADA37-04EE-2ECE-9F86-DDC0106047AC}" = Times Reader
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup
"{51071D66-D034-4239-94E0-723FCA10B6FE}" = OpenOffice.org 3.4
"{53469506-A37E-4314-A9D9-38724EC23A75}" = HP Setup
"{5410C77F-B22F-61FE-7D93-0BEDBC959FF3}" = PX Profile Update
"{5719D840-C30E-7DD3-C746-00B3A5C9BD6B}" = CCC Help Korean
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{5EDE7E1A-E386-BB8B-CD77-3B5AF9A8D80B}" = CCC Help Greek
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{670E7FFC-95FF-C425-BD00-91C120352C4B}" = CCC Help Turkish
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A396792-1CA6-E9E5-9844-512238F70C95}" = CCC Help Swedish
"{6B879152-071A-36B4-0F97-37B05552FA05}" = Fast Traffic Sniper
"{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"{6DC6392C-4D8C-D21E-A0DD-750BD76627F6}" = CCC Help Chinese Standard
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.2.0
"{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}" = HP Support Assistant
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74796D37-75F9-C430-CC1D-FCE8371D5EB3}" = CCC Help English
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7AB01508-C2B2-43C8-8B44-514801E7CCC9}" = Jing
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{7FBDEEDA-ECDB-A348-0FBC-41AD5D852B36}" = Catalyst Control Center Localization All
"{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}" = Rosetta Stone Version 3
"{819BD919-5B78-5D29-27AD-765778772B7C}" = Market Samurai
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83E55279-CE70-407F-B34D-EAE0D9C6372B}_is1" = eCover Software Pro
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{8AC3E7BB-F819-379B-3F81-255904B67A8A}" = CCC Help Czech
"{8B4B2F59-1C81-4389-9605-BA273957C24D}_is1" = Content Spin Bot version 1.0
"{8C696008-029B-BBA7-9CD3-45596A069D96}" = CCC Help Polish
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}" = InstallIQ Updater
"{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{91892B48-4503-D842-59A0-842F70503843}" = CCC Help Portuguese
"{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{946B0558-3E7B-D27B-2E95-3A2E99BCB826}" = Catalyst Control Center Graphics Previews Common
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{96B3C2A3-ADD6-4E63-89D3-1E3AC115D3FA}" = pdfforge Toolbar v6.0
"{9902DD1A-58CD-EE2D-1401-EF1D07D3D353}" = CCC Help Japanese
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BBEE625-F639-CB19-6447-98B25FF975DD}" = Traffic Launch Pad
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A44E3886-B7E7-ABA4-57C7-B423992CB536}" = Catalyst Control Center InstallProxy
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAD4E5A4-68CD-7957-81EF-8B50DBA5E939}" = CCC Help Danish
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{AE8289AB-E18C-36E6-BF9B-99557D9F7517}" = Catalyst Control Center Graphics Previews Vista
"{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager
"{B3E2EB86-2EDB-061B-0DDC-58EDBCAEC4A0}" = ASHelper
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B719C82F-A3AC-ED37-3E2A-947E5A7BA214}" = CCC Help Hungarian
"{B75726EF-847A-6965-0CBF-234BE30604D3}" = Fast Traffic Magnet
"{B92F4DE0-CAFE-404F-B907-19D872CFFD5C}" = Commission Streamer
"{BB1C717E-376C-4AA1-8940-81BFC38D9778}" = HP Quick Launch
"{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}" = Energy Star Digital Logo
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C5AC39F1-001D-4338-84C6-35109525588A}" = TweetDeck
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C792A75A-2A1F-4991-9B85-291745478A79}" = NetAssistant
"{C7AAB32A-AA73-ECFD-4F43-F41CFA2CD540}" = ccc-core-static
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFEAD106-F7EB-46B9-8E38-7C86C91F610E}" = CommissionMultiplier
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"{D1612A3D-0DCC-4055-BB6A-0036F31158A0}" = Setup
"{D1AEB5DB-04FA-489D-94EF-8600898B93EE}" = ICA
"{D1F80EFD-A032-4E8E-A367-70C44AD4DCE0}" = ISCOM
"{D3538C4C-8DAF-88CD-55B0-CBF12DECF5A6}" = CCC Help Spanish
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D445BE82-2ADA-423D-9CB5-DDFC48E5F6A9}" = Tableau Public 6.1
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D57588F6-2D35-42B5-5C96-4FC3EB3EF7CE}" = CCC Help Russian
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver
"{DA4BF4BE-3CDC-43B5-BBDA-DDDA73103111}" = Corel PaintShop Photo Pro X3
"{DBE31207-21B1-5688-450E-9B958643FD2C}" = CCC Help Norwegian
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DCD941B6-F2E7-4FAF-B102-F7D4DE5FF99A}" = IPM_PSP_Pro
"{DCF1928A-FC01-48E7-A7E6-4651D42EF6A1}" = PSPPRO_DCRAW
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE311B9A-4C1D-C746-264E-DB2A5C6DD2ED}" = CCC Help French
"{DF8B9311-ADE7-4EDE-B121-326CAA3D225D}" = PSPPContent
"{DFC63A26-1EF4-A666-BE94-1DF7351DA7BE}" = CCC Help Dutch
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EECD8A88-0030-48F1-9898-882EC02D0353}" = Pin Point Pro 1.0
"{F069C491-69E6-4D9B-9A0C-B7894A1FA97C}" = Setup
"{F072CA07-A781-45E4-9975-C033A73019CF}" = ICA
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F206FEC3-F5DD-43FD-A8CF-9C46B8A6A92C}" = VSPro
"{F4E9851F-765E-40B7-9859-237C2724E62C}" = DeviceIO
"{F6A76E9C-C299-4CFA-AD2A-57FE9DD68B70}" = Contents
"{F8423392-2296-4748-9B66-344432459632}" = PureHD
"{F909BD3C-8684-4ACF-B7C3-33F4F9F901B7}" = Share
"{F95C8C1F-25BB-44EC-A7E6-5C17ABC6BC71}" = VIO
"{FB0B6DDD-DF3E-4CD6-927C-724AB854E322}" = VSClassic
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"{FBBCD35F-930F-9B68-7A80-A668A68FE86A}" = CCC Help German
"{FD67D9F3-FED6-4A2E-9D6C-8C8C44DEF8FF}" = IPM_VS_Pro
"{FD9C31B6-F572-414D-81E3-89368C97A125}_is1" = CamStudio OSS Desktop Recorder
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE661711-E392-4B3F-A4A7-02C747C09134}" = ISCOM
"7-Zip" = 7-Zip 9.20
"AA-BestAffiliatePrograms_is1" = Best Affiliate Programs v2.6
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Affiliate ID Manager Master Rebrander_is1" = Affiliate ID Manager Master Rebrander - Version No.1
"Allmyapps" = Allmyapps
"ashelper.ASHelper.46130C60F2252FA5A4446077F84AA968F38F8488.1" = ASHelper
"Atlantis Quest" = Atlantis Quest (remove only)
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
"Audacity_is1" = Audacity 2.0
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe
"BrotherSoft_Extreme Toolbar" = BrotherSoft Extreme Toolbar
"CamStudio" = CamStudio
"CoffeeCup HTML Editor" = CoffeeCup HTML Editor
"com.fastcashcommissions.fasttrafficmagnet" = Fast Traffic Magnet
"com.fastcashcommissions.fasttrafficsniper" = Fast Traffic Sniper
"com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1" = Times Reader
"Commission Activator 1.00" = Commission Activator 1.00
"conduitEngine" = Conduit Engine
"Content Magnet Article Extractor_is1" = Content Magnet Article Extractor 1.0
"CoverFactory 2.50_is1" = CoverFactory 2.50
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"ExpressZip" = Express Zip File Compression Software
"Fences" = Fences
"Fences Pro" = Fences Pro
"FileZilla Client" = FileZilla Client 3.5.3
"Free Screen Video Recorder_is1" = Free Screen Video Recorder version 2.5.22.508
"Free-Web-Buttons.com" = Free-Web-Buttons.com
"GREENSAMBA32-bit Windows executable" = GreenSamba
"HP Photo Creations" = HP Photo Creations
"IncomeGenesis" = Income Genesis
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"IObit Malware Fighter_is1" = IObit Malware Fighter
"IrfanView" = IrfanView (remove only)
"Jewel Quest Mysteries: Curse of the Emerald Tear" = Jewel Quest Mysteries: Curse of the Emerald Tear (remove only)
"Jewel Quest: Heritage" = Jewel Quest: Heritage (remove only)
"John Evans Banner Creator_is1" = John Evans Banner Creator v2.01
"Keyword Pad_is1" = Keyword Pad v1.0.112706
"LADSPA_plugins-win_is1" = LADSPA_plugins-win-0.4.15
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"LibreOffice" = LibreOffice 3.4
"MAGIX_MSI_Xara3D7" = Xara 3D Maker 7
"MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1" = Market Samurai
"Mozilla Firefox 14.0 (x86 en-US)" = Mozilla Firefox 14.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"My HP Game Console" = HP Game Console
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"PhotoStage" = PhotoStage Slideshow Producer
"Popup Free" = Popup Free (remove only)
"PPT To Flash Catalog Professional_is1" = PPT To Flash Catalog Professional
"SkyCaddieDesktop" = SkyCaddie Desktop
"Software Informer_is1" = Software Informer 1.1
"Solitaire Master 3" = Solitaire Master 3
"The Weather Channel App" = The Weather Channel App
"The Weather Channel Desktop 6" = The Weather Channel Desktop 6
"TheDeanReportCloaker_is1" = TheDeanReportCloaker
"Traffic Travis 4.1 Setup Wizard_is1" = Traffic Travis 4.1.0
"TrafficInitiator-Air" = Traffic Launch Pad
"Video_0" = Video Squeeze Page Generator 1.1
"Wajam" = Wajam
"WebFormDesigner" = WebFormDesigner
"WildTangent hp Master Uninstall" = HP Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
"Wisdom-soft Set up ScreenHunter 5.1 Pro" = Wisdom-soft Set up ScreenHunter 5.1 Pro
"Wizard Land" = Wizard Land (remove only)
"WT087328" = Blackhawk Striker 2
"WT087330" = Bounce Symphony
"WT087335" = Build-a-lot 2
"WT087343" = Dora's World Adventure
"WT087360" = Escape Rosecliff Island
"WT087361" = FATE
"WT087362" = Final Drive Nitro
"WT087372" = Heroes of Hellas 2 - Olympia
"WT087379" = Jewel Quest Solitaire 2
"WT087394" = Penguins!
"WT087395" = Poker Superstars III
"WT087396" = Polar Bowler
"WT087397" = Polar Golfer
"WT087414" = Virtual Families
"WT087415" = Wheel of Fortune 2
"WT087428" = Bejeweled 2 Deluxe
"WT087453" = Chuzzle Deluxe
"WT087501" = Plants vs. Zombies
"WT087533" = Zuma Deluxe
"WT087536" = Diner Dash 2 Restaurant Rescue
"WT089299" = Mystery P.I. - The London Caper
"WT089307" = Virtual Villagers 4 - The Tree of Life
"WT089308" = Blasterball 3
"WT089328" = Farm Frenzy
"WT089359" = Cake Mania
"WT089362" = Agatha Christie - Peril at End House
"XHeader" = XHeader
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update
"ZumoDrive" = HP CloudDrive
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"43D873A11E3E6E1C1E31A5977B81928A57E00AD6" = eBay Excel Add-in
"Funmoods Web Search" = Funmoods Web Search
"Google Chrome" = Google Chrome
"HuluDesktop" = Hulu Desktop
"NetAssistant 3.8.3" = Freeze.com NetAssistant
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 4/18/2012 8:41:02 AM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/18/2012 7:26:58 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/20/2012 11:09:43 AM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/21/2012 5:53:03 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/22/2012 11:57:47 AM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/22/2012 5:54:46 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/22/2012 6:46:26 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/23/2012 1:53:46 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/23/2012 8:03:55 PM | Computer Name = BradC-BradC-HP | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "c:\program files\microsoft
security client\MSESysprep.dll".Error in manifest or policy file "c:\program files\microsoft
security client\MSESysprep.dll" on line 10. The element imaging appears as a child
of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by
this version of Windows.
Error - 4/24/2012 11:34:41 AM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
[ Hewlett-Packard Events ]
Error - 6/10/2011 9:52:26 AM | Computer Name = BradC-BradC-HP | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\061110085217.xml
File not created by asset agent
Error - 9/23/2011 9:48:58 AM | Computer Name = BradC-BradC-HP | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\091123084855.xml
File not created by asset agent
Error - 1/7/2012 12:11:39 AM | Computer Name = BradC-BradC-HP | Source = HPSFMsgr.exe | ID = 4000
Description = HP Error ID: -2147221164 at System.RuntimeTypeHandle.CreateInstance(RuntimeType
type, Boolean publicOnly, Boolean noCheck, Boolean& canBeCached, RuntimeMethodHandle&
ctor, Boolean& bNeedSecurityCheck) at System.RuntimeType.CreateInstanceSlow(Boolean
publicOnly, Boolean fillCache) at System.RuntimeType.CreateInstanceImpl(Boolean
publicOnly, Boolean skipVisibilityChecks, Boolean fillCache) at System.Activator.CreateInstance(Type
type, Boolean nonPublic) at HPSA_Messenger.MessengerCom.TrayDeskBand.isTaskbarDisplayed()
StackTrace:
at System.RuntimeTypeHandle.CreateInstance(RuntimeType type, Boolean publicOnly,
Boolean noCheck, Boolean& canBeCached, RuntimeMethodHandle& ctor, Boolean& bNeedSecurityCheck)
at System.RuntimeType.CreateInstanceSlow(Boolean publicOnly, Boolean fillCache)
at System.RuntimeType.CreateInstanceImpl(Boolean publicOnly, Boolean skipVisibilityChecks,
Boolean fillCache) at System.Activator.CreateInstance(Type type, Boolean nonPublic)
at HPSA_Messenger.MessengerCom.TrayDeskBand.isTaskbarDisplayed() Source: mscorlib
Name:
HPSFMsgr.exe Version: 01.00.00.00 Path: C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe Format: en-US RAM: 3893 Ram
Utilization: 30 TargetSite: System.Object CreateInstance(System.RuntimeType, Boolean,
Boolean, Boolean ByRef, System.RuntimeMethodHandle ByRef, Boolean ByRef)
Error - 3/30/2012 8:11:44 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =
Error - 3/30/2012 8:11:44 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =
Error - 3/30/2012 8:12:03 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =
Error - 3/30/2012 8:12:03 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =
Error - 3/31/2012 9:41:34 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =
Error - 4/14/2012 1:21:10 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =
Error - 6/13/2012 6:38:07 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description = HP Error ID: -2146233087 Server stack trace: at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs, TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs) at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessag
e
methodCall, ProxyOperationRuntime operation) at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage
message) Exception rethrown at [0] Message: The server did not provide a meaningful
reply; this might be caused by a contract mismatch, a premature session shutdown
or an internal server error. StackTrace: Server stack trace: at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs, TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs) at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessag
e
methodCall, ProxyOperationRuntime operation) at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage
message) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at HP.SupportFramework.Communicator.MessengerComm.IMessengerCommunicator.UpdateTime
r()
at HP.SupportAssistant.UI.MessengerCommunication.sendTimerUpdate() Source: mscorlib
Name:
HPSF.exe Version: 06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support
Framework\HPSF.exe Format: en-US RAM: 3893 Ram Utilization: 50 TargetSite: Void HandleReturnMessage(System.Runtime.Remoting.Messaging.IMessage,
System.Runtime.Remoting.Messaging.IMessage)
[ HP Wireless Assistant Events ]
Error - 4/16/2011 12:01:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:02:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:03:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:04:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:05:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:06:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:07:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:08:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:09:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:10:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
[ System Events ]
Error - 7/4/2012 5:15:50 PM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7023
Description = The Microsoft Antimalware Service service terminated with the following
error: %%-2147017840
Error - 7/4/2012 9:03:13 PM | Computer Name = BradC-BradC-HP | Source = Microsoft Antimalware | ID = 5101
Description = %%860 grace period has expired. Protection against viruses, spyware,
and other potentially unwanted software is disabled. Expiration Reason: %%873 Expiration
Date (UTC): ?7/?5/?2012 1:03:13 AM Error Code: 0x80092003 Error Description: An error
occurred while reading or writing to a file.
Error - 7/4/2012 9:03:24 PM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7000
Description = The My Web Search Service service failed to start due to the following
error: %%2
Error - 7/4/2012 9:04:03 PM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7023
Description = The Microsoft Antimalware Service service terminated with the following
error: %%-2147017840
Error - 7/5/2012 10:40:17 AM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7000
Description = The My Web Search Service service failed to start due to the following
error: %%2
Error - 7/5/2012 10:40:20 AM | Computer Name = BradC-BradC-HP | Source = Microsoft Antimalware | ID = 5101
Description = %%860 grace period has expired. Protection against viruses, spyware,
and other potentially unwanted software is disabled. Expiration Reason: %%873 Expiration
Date (UTC): ?7/?5/?2012 2:40:20 PM Error Code: 0x80092003 Error Description: An error
occurred while reading or writing to a file.
Error - 7/5/2012 10:40:58 AM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7023
Description = The Microsoft Antimalware Service service terminated with the following
error: %%-2147017840
Error - 7/6/2012 10:48:58 AM | Computer Name = BradC-BradC-HP | Source = Microsoft Antimalware | ID = 5101
Description = %%860 grace period has expired. Protection against viruses, spyware,
and other potentially unwanted software is disabled. Expiration Reason: %%873 Expiration
Date (UTC): ?7/?6/?2012 2:48:58 PM Error Code: 0x80092003 Error Description: An error
occurred while reading or writing to a file.
Error - 7/6/2012 10:48:58 AM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7000
Description = The My Web Search Service service failed to start due to the following
error: %%2
Error - 7/6/2012 10:49:33 AM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7023
Description = The Microsoft Antimalware Service service terminated with the following
error: %%-2147017840
< End of report >
my laptop has been infected with the mystart incredibar virus.
I have followed your instructions and downloaded the program to help with removal of the mystart virus. I have both reports on notepad, one is copied. where do I post it?
OTL logfile created on: 7/6/2012 3:01:29 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Brad C\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.80 Gb Total Physical Memory | 1.06 Gb Available Physical Memory | 27.91% Memory free
7.60 Gb Paging File | 4.41 Gb Available in Paging File | 58.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 668.10 Gb Total Space | 591.32 Gb Free Space | 88.51% Space Free | Partition Type: NTFS
Drive D: | 30.24 Gb Total Space | 4.44 Gb Free Space | 14.69% Space Free | Partition Type: NTFS
Drive F: | 98.87 Mb Total Space | 83.72 Mb Free Space | 84.68% Space Free | Partition Type: FAT32
Computer Name: BRADC-BRADC-HP | User Name: Brad C | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Brad C\Downloads\OTL(1).exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe ()
PRC - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)
PRC - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe ()
PRC - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Software Informer\softinfo.exe (Informer Technologies, Inc.)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\iWin Games\iWinTrusted.exe (iWin Inc.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\zumodrive.exe (Zecter Inc.)
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
PRC - C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe (CyberLink)
PRC - C:\ProgramData\ClickfreeC02\UACProxy.exe (Storage Appliance Corp.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE ()
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Modules (No Company Name) ==========
MOD - C:\Users\Brad C\AppData\Local\Temp\libsqlitejdbc-8626483191519883319.lib ()
MOD - C:\Users\Brad C\AppData\Local\Temp\WindowsAPI.dll2891894938722718749.lib ()
MOD - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\SiteSafety.dll ()
MOD - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxslt.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE ()
========== Win32 Services (SafeList) ==========
SRV:64bit: - (Web Assistant Updater) – C:\Program Files\Web Assistant\ExtensionUpdaterService.exe ()
SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (HPClientSvc) – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company)
SRV:64bit: - (HPAuto) – C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe (Hewlett-Packard)
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (HP Wireless Assistant Service) – C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Application Updater) – C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (vToolbarUpdater11.1.0) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe ()
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (WajamUpdater) – C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe (Wajam)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (IMFservice) – C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (iWinTrusted) – C:\Program Files (x86)\iWin Games\iWinTrusted.exe (iWin Inc.)
SRV - (CLKMSVC10_C6F09094) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe (CyberLink)
SRV - (RoxioNow Service) – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
SRV - (CFUACProxy_clickfreec02) – C:\ProgramData\ClickfreeC02\UACProxy.exe (Storage Appliance Corp.)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (clwvd) – C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation)
DRV:64bit: - (intelkmd) – C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (SkyhawkeUSBLan) – C:\Windows\SysNative\drivers\btblan.sys (Belcarra Technologies)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (UrlFilter) – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\UrlFilter.sys (IObit.com)
DRV - (RegFilter) – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\RegFilter.sys (IObit.com)
DRV - (FileMonitor) – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys (IObit)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a;=iron2…p;cr=1561730916
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1561730916
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}: "URL" = http://rover.ebay.com/rover/1/711-111092-2…p;mfe=Notebooks
IE:64bit: - HKLM\..\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000.100…D-ED18B0B41582}
IE - HKLM\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1561730916
IE - HKLM\..\SearchScopes\{7624FE00-BB7A-93D1-4029-31A105F7D5E8}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2776682
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKLM\..\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}: "URL" = http://rover.ebay.com/rover/1/711-111092-2…p;mfe=Notebooks
IE - HKLM\..\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6…D-ED18B0B41582}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://isearch.avg.com/?cid={1D722B3C-363F…mp;d=2012-03-13 20:31:04&v;=11.0.0.9&sap;=hp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie9
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.avg.com/?cid={1D722B3C-363F…mp;d=2012-03-13 20:31:04&v;=11.1.0.7&sap;=hp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - No CLSID value found
IE - HKCU\..\URLSearchHook: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\6.0\iobitToolbarIE.dll (Spigot, Inc.)
IE - HKCU\..\URLSearchHook: {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - No CLSID value found
IE - HKCU\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\6.0\pdfforgeToolbarIE.dll (Spigot, Inc.)
IE - HKCU\..\URLSearchHook: {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files (x86)\Freeze.com\NetAssistant\NetAssistant.dll (W3i, LLC)
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{12DC6175-B360-2C25-BF0E-2B6E49ADC9F3}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKCU\..\SearchScopes\{2C71AFC4-9C4C-4E8C-9618-38EADA8DEF02}: "URL" = http://www.flickr.com/search/?q={searchTerms}
IE - HKCU\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKCU\..\SearchScopes\{66C011AB-F98E-4337-B30D-C800D299CE92}: "URL" = http://delicious.com/search?p={searchTerms}
IE - HKCU\..\SearchScopes\{67AFED21-EE04-4081-941E-3CB3CAD8C28E}: "URL" = http://search.yahoo.com/search?fr=chr-gree…p={searchTerms}
IE - HKCU\..\SearchScopes\{7624FE00-BB7A-93D1-4029-31A105F7D5E8}: "URL" = http://isearch.avg.com/search?cid={1D722B3…mp;d=2012-03-13 20:31:04&v;=10.0.0.7&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1561730916
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\..\SearchScopes\{9BDECC3C-C77D-4CFE-9448-B1BED69F6ADD}: "URL" = http://search.yahoo.com/search?fr=chr-gree…p={searchTerms}
IE - HKCU\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKCU\..\SearchScopes\{B8822D2B-48D0-421E-93B7-432835894155}: "URL" = http://www.google.com/search?q={searchTerm…1I7GGHP_enUS466
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb143/?searc…buqG4D&i;=26
IE - HKCU\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKCU\..\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}: "URL" = http://rover.ebay.com/rover/1/711-111092-2…p;mfe=Notebooks
IE - HKCU\..\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6…D-ED18B0B41582}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2012/05/24 09:09:17 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2012/05/24 09:09:17 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMyWebS.dll (MyWebSearch.com)
FF - HKLM\Software\MozillaPlugins\@photoproduct.rocketlife.com/RocketLife App Viewer;version=0.8: File not found
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Users\Brad C\AppData\Local\HuluDesktop\instances\0.9.14.1\nphdplg.dll (Hulu LLC)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Brad C\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Brad C\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Brad C\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2012/05/02 13:00:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2010/10/25 04:11:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{98e34367-8df7-42b4-837b-20b892ff0849}: C:\ProgramData\iWin Games\firefox [2011/09/04 17:28:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\11.1.0.7\ [2012/06/12 11:11:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/05/29 10:07:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012/05/02 13:00:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/05/24 09:05:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MyWebSearch\bar\1.bin [2012/07/06 10:06:16 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/01 21:22:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/23 10:01:36 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/01 21:22:50 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/23 10:01:36 | 000,000,000 | —D | M]
[2012/01/06 22:54:41 | 000,000,000 | —D | M] (No name found) – C:\Users\Brad C\AppData\Roaming\Mozilla\Extensions
[2011/05/06 10:03:58 | 000,000,000 | —D | M] (No name found) – C:\Users\Brad C\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/06 15:02:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions
[2012/06/14 15:43:29 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/06/13 20:11:55 | 000,000,000 | —D | M] (DVDVideoSoftTB) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012/06/06 15:03:59 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/05/24 09:09:35 | 000,000,000 | —D | M] (Page Speed) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2012/06/19 06:35:03 | 000,000,000 | —D | M] (My Web Search) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\[removed]
[2012/06/18 09:26:07 | 000,000,000 | —D | M] (WebRank Toolbar) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\[removed]
[2011/10/08 18:28:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Brad C\AppData\Roaming\Mozilla\SeaMonkey\Profiles\t9umotw0.default\extensions
[2012/06/11 14:48:57 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/06/11 14:48:57 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/07/01 21:22:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\distribution\extensions
[2012/07/01 21:22:50 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/12 11:10:58 | 000,003,766 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/05/16 17:08:48 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml.old
[2011/11/26 16:02:58 | 000,002,519 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
[2012/05/16 17:08:48 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Yahoo! (Enabled)
CHR - default_search_provider: search_url = http://search.yahoo.com/search?ei={inputEn…p={searchTerms}
CHR - default_search_provider: suggest_url = http://ff.search.yahoo.com/gossip?output=f…d={searchTerms}
CHR - Extension: WinZipBar = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgpnojibjokpoghebklhkdeijehkohhb\2.3.4.2_0\
CHR - Extension: FunDial = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\1.0.1_0\
CHR - Extension: Web Assistant = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.430_0\
CHR - Extension: Funmoods = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\1.5.1_0\
CHR - Extension: SweetIM for Facebook = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
CHR - Extension: SweetIM for Facebook = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\
CHR - Extension: AVG Safe Search = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\
CHR - Extension: Wajam = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\
CHR - Extension: Skype Click to Call = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.0.0.10201_0\
CHR - Extension: AVG Do Not Track = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: DVDVideoSoftTB = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\plmlpkfpkijnlijgalnjaacllnjmoamo\10.11.5.4_0\
CHR - Extension: WinZipBar = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgpnojibjokpoghebklhkdeijehkohhb\2.3.4.2_0\
CHR - Extension: FunDial = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\1.0.1_0\
CHR - Extension: Web Assistant = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.430_0\
CHR - Extension: Funmoods = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\1.5.1_0\
CHR - Extension: SweetIM for Facebook = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
CHR - Extension: SweetIM for Facebook = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\
CHR - Extension: AVG Safe Search = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\
CHR - Extension: Wajam = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\
CHR - Extension: Skype Click to Call = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.0.0.10201_0\
CHR - Extension: AVG Do Not Track = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: DVDVideoSoftTB = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\plmlpkfpkijnlijgalnjaacllnjmoamo\10.11.5.4_0\
O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension64.dll ()
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\6.0\iobitToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (ViewSource Class) - {2EF37A01-884F-11d5-AC99-B112050ECB4F} - C:\Program Files (x86)\Popup Free\HTMLEdit.dll (InfoWorks Technology Company)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (BrotherSoft Extreme Toolbar) - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
O2 - BHO: (Funmoods Helper Object) - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\PROGRA~2\Funmoods\1.5.23.22\bh\escort.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll File not found
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll (Wajam)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\6.0\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (NetAssistant) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files (x86)\Freeze.com\NetAssistant\NetAssistant.dll (W3i, LLC)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (no name) - !{41B62AD3-5D43-40D1-9D43-F3539C1DB452} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - !{95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - !{B922D405-6D13-4A2B-AE89-08A030DA4402} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\6.0\iobitToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BrotherSoft Extreme Toolbar) - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll File not found
O3 - HKLM\..\Toolbar: (Funmoods Toolbar) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\PROGRA~2\Funmoods\1.5.23.22\escorTlbr.dll File not found
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\6.0\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Corel File Shell Monitor] c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\CorelIOMonitor.exe File not found
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found
O4 - HKLM..\Run: [ROC_roc_dec12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [ZumoDrive] C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk ()
O4 - HKCU..\Run: [Allmyapps] C:\Program Files (x86)\Allmyapps\AllmyappsNotifier.exe (Allmyapps)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Brad C\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [MyWebSearch Email Plugin] C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found
O4 - HKCU..\Run: [Software Informer] C:\Program Files (x86)\Software Informer\softinfo.exe (Informer Technologies, Inc.)
O4 - HKCU..\Run: [ZumoDrive] C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk ()
O4 - Startup: C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2040B8F1-89EE-40CF-BFB8-C5213E9F4DF7}: DhcpNameServer = 10.0.0.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe) - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:64bit: - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll (Stardock)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{e08af094-1548-11e1-8b3f-f568c47f51ae}\Shell - "" = AutoRun
O33 - MountPoints2\{e08af094-1548-11e1-8b3f-f568c47f51ae}\Shell\AutoRun\command - "" = G:\StartClickFreeBackup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.tscc - C:\Windows\SysWOW64\tsccvid64.dll (TechSmith Corporation)
Drivers32: msacm.dvacm - c:\Program Files (x86)\Common Files\Ulead Systems\VIO\DVACM.acm (Corel TW Corp.)
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2012/07/06 14:12:45 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\James_Jordan-IM_Business_In_A_Box
[2012/07/06 11:54:14 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{90895736-A8E0-42D9-86DD-C65D217907DB}
[2012/07/06 11:54:03 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{1373FBAA-F462-4A3F-90DD-29BB80AB97FE}
[2012/07/05 10:16:59 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{E2A0B748-F5EC-4217-935F-A2ABBD3986C2}
[2012/07/05 10:16:48 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{928EFE15-82C8-4378-9AD9-9A0C2818CAEC}
[2012/07/05 10:13:43 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{7B2F270B-0974-4B9C-AC31-CEFF2A84BA5D}
[2012/07/04 11:48:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit Toolbar
[2012/07/04 11:48:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
[2012/07/04 11:48:22 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\IObit
[2012/07/04 11:48:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2012/07/04 11:47:11 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\IObitMalwareFighterPRO
[2012/07/04 04:58:11 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{06DB8F0B-1441-46E9-A225-004BA3AF432D}
[2012/07/04 04:58:00 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{B9956608-0B07-433A-9985-14F4F4814F8A}
[2012/07/03 14:09:56 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Corel Auto-Preserve
[2012/07/03 11:52:42 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{D7C6B135-E1F2-4EE9-8EF2-C43F0C443A3F}
[2012/07/03 11:52:31 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{0B0DD05E-62A9-48B4-8FE2-E91EB6E8E249}
[2012/07/03 10:01:14 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\CPS images
[2012/07/03 09:50:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Spigot
[2012/07/03 09:50:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\pdfforge Toolbar
[2012/07/03 09:50:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Application Updater
[2012/07/02 08:35:16 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{325F898A-A958-4492-AE41-C80BC195A431}
[2012/07/02 08:35:05 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{2BC30E3A-BD64-488B-AA0B-811FE094234D}
[2012/07/01 12:24:45 | 004,472,121 | —- | C] (CamStudio Open Source Dev Team ) – C:\Users\Brad C\Downloads\Documents\CamStudio_Setup_v2.6b_r294_(build_24Oct2010).exe
[2012/07/01 09:04:58 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{F9C03163-84BC-40A1-ACB2-9C57880B416D}
[2012/07/01 09:04:46 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{0498AD14-7FB3-4AD3-81A0-9631A658607B}
[2012/06/30 17:23:15 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\Email Newsletter BC Online
[2012/06/30 10:09:14 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\twitter
[2012/06/30 10:06:26 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\TweetAdder3
[2012/06/30 09:17:08 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{CEF5D77C-EE35-4855-92A8-504864818144}
[2012/06/30 09:16:57 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{79EC122A-5978-49BD-ADAC-30B630549F35}
[2012/06/29 12:40:19 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{AB8D0F03-5A15-4496-A14E-7A3E9FF66986}
[2012/06/29 12:40:07 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{5E02D64E-A25E-4D58-98BD-B7B8BC109282}
[2012/06/28 19:50:38 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{2133ED98-28AF-4F44-BBA4-784AEEE141E7}
[2012/06/28 19:50:27 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{6161CE72-A397-435E-BA5F-D3263ACD67E8}
[2012/06/28 10:39:13 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\BlogThemes_201109
[2012/06/28 09:41:35 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\CreateStunningVideoSlideshowsForFree_PLR
[2012/06/28 06:12:58 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{5D18960A-1A3A-41FB-BE01-599ED4EE0130}
[2012/06/28 06:12:47 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{498CA44B-5914-440A-9039-46EEA2EEDE97}
[2012/06/27 16:26:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Content Spin Bot
[2012/06/27 16:26:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\ContentSpinBot
[2012/06/27 11:54:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoSqPageGen
[2012/06/27 11:54:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoSqPageGen
[2012/06/27 11:42:21 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\ecovers
[2012/06/26 18:22:05 | 000,000,000 | R–D | C] – C:\Users\Brad C\Downloads\Documents\HP Photo Creations
[2012/06/26 18:22:05 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Visan
[2012/06/26 18:22:00 | 000,000,000 | —D | C] – C:\ProgramData\Visan
[2012/06/26 13:52:03 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{1BF78769-68B8-4779-826C-F0D3747947EE}
[2012/06/26 13:51:52 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{3F8F1BE2-DF2E-42D8-8D0D-4D2C902A48C9}
[2012/06/25 09:20:50 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{639F841D-9862-4AFD-8C0B-EF01D447FEE6}
[2012/06/25 09:20:39 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{350AF1CC-4B5A-40C0-8DD9-2D989A458A2C}
[2012/06/23 12:38:00 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{C16650F3-2D41-44A4-A432-F064B8D4B6F6}
[2012/06/23 12:37:49 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{87811A18-9580-44FA-871C-C23BEC21B040}
[2012/06/22 16:45:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/06/22 16:44:25 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2012/06/22 16:44:25 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2012/06/22 16:44:25 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2012/06/22 16:44:24 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2012/06/22 16:43:50 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/06/22 16:43:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2012/06/22 16:43:50 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/06/22 16:43:50 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2012/06/22 16:42:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2012/06/22 16:42:36 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2012/06/22 16:42:26 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/06/22 16:42:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2012/06/22 16:40:36 | 079,225,752 | —- | C] (Apple Inc.) – C:\Users\Brad C\iTunes64Setup.exe
[2012/06/22 15:53:52 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{3ED52322-4D8F-44EC-92B7-0771E77D8561}
[2012/06/22 15:53:41 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{5F8478C5-829D-4D59-95E6-D3805371A348}
[2012/06/21 12:03:03 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{337BEA95-4AFD-44AE-B751-FF6F202EB9F8}
[2012/06/21 12:02:51 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{7817663F-E0BB-4414-B02C-97D86A813263}
[2012/06/20 09:33:10 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{AC6951B2-192A-4A4B-B875-C44AF8781DEE}
[2012/06/20 09:33:00 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{76703886-F033-4F30-9160-4D2AF770E0E0}
[2012/06/19 13:59:56 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{623F1BF0-C5E4-4D07-B22D-F00BD7587500}
[2012/06/19 13:59:45 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{1031FD43-5931-494F-BB75-DE20F9D261E0}
[2012/06/19 06:29:23 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/19 06:29:23 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/19 06:29:23 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/19 06:28:58 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/19 06:28:58 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/19 06:28:58 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/19 06:28:41 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/19 06:28:41 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/06/18 20:12:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\MyWebSearch
[2012/06/18 06:59:05 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{39FF811A-3DDE-4AA4-97EC-A453EEC257D8}
[2012/06/16 20:15:58 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{5E42E006-51D6-4C61-A99D-6DD91894B772}
[2012/06/16 05:39:40 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\SuperSignUpSystem_Minisite
[2012/06/16 05:35:20 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Free_PLR_Products-dkas
[2012/06/16 05:10:39 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TweetDeck
[2012/06/16 05:10:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Twitter
[2012/06/16 05:03:45 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Business Links
[2012/06/16 05:02:56 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\MindValley
[2012/06/15 08:30:54 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{9E0A3BED-1FF5-4509-AA7C-B551BC2D4752}
[2012/06/14 17:29:28 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\nichebuilder
[2012/06/14 16:21:37 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\nichebuilder
[2012/06/14 15:55:25 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\ListGuerillaTraffic
[2012/06/14 15:53:42 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\Co_Registration_Explained
[2012/06/14 15:53:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Utilities
[2012/06/14 08:43:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs
[2012/06/14 08:43:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012/06/14 08:03:23 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\AVG
[2012/06/14 08:02:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2012/06/14 06:46:09 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{FA84CF08-8433-42C2-B303-544BA3E593B7}
[2012/06/14 06:45:58 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{CB8E4E87-95F5-43A6-9CB6-76374106D5BA}
[2012/06/13 20:16:35 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/06/13 20:16:34 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/06/13 20:16:34 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/06/13 20:16:34 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/06/13 20:16:33 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/06/13 20:16:33 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/06/13 20:16:32 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/06/13 20:16:32 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/06/13 20:16:31 | 002,311,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/06/13 20:16:31 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/06/13 20:16:31 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/06/13 20:16:31 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/06/13 20:16:30 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/06/13 20:15:41 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\DVDVideoSoft_Ltd
[2012/06/13 20:12:44 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\DVDVideoSoft
[2012/06/13 20:11:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\DVDVideoSoftTB
[2012/06/13 20:11:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
[2012/06/13 20:11:37 | 002,557,952 | —- | C] (Nokia Corporation and/or its subsidiary(-ies)) – C:\Windows\SysWow64\QtCore4.dll
[2012/06/13 20:11:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\DVDVideoSoft
[2012/06/13 20:11:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DVDVideoSoft
[2012/06/13 20:10:43 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\DVDVideoSoft
[2012/06/13 19:57:48 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/06/13 19:57:48 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/06/13 19:57:48 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2012/06/13 19:57:40 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/06/13 19:57:38 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/06/13 19:57:38 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/06/13 19:57:34 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2012/06/13 19:57:28 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/06/13 19:57:27 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/06/13 14:06:33 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\LibreOffice
[2012/06/13 14:04:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 3.4
[2012/06/13 14:03:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\LibreOffice 3.4
[2012/06/13 14:02:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free Offers from Freeze.com
[2012/06/13 14:02:12 | 000,000,000 | -HSD | C] – C:\Windows\SysWow64\AI_RecycleBin
[2012/06/13 14:02:11 | 000,000,000 | —D | C] – C:\ProgramData\W3i
[2012/06/13 14:02:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\W3i
[2012/06/13 14:02:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InstallIQ Updater
[2012/06/13 14:02:05 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NetAssistant
[2012/06/13 14:02:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Freeze.com
[2012/06/13 13:59:16 | 001,536,192 | —- | C] (W3i, LLC) – C:\Users\Brad C\Desktop\libreoffice.exe
[2012/06/13 13:54:11 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
[2012/06/13 13:54:07 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\Wajam
[2012/06/13 13:54:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Wajam
[2012/06/13 13:50:14 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\mobile
[2012/06/13 13:50:13 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\files
[2012/06/13 08:49:42 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Downloads bundled
[2012/06/13 07:19:09 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Kingsoft
[2012/06/13 07:19:09 | 000,000,000 | —D | C] – C:\ProgramData\Kingsoft
[2012/06/13 06:50:14 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\Macromedia
[2012/06/13 06:43:22 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{64F87F3C-E10D-467B-A5D5-1BDECABD5279}
[2012/06/13 06:43:10 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{663998F9-037B-441F-A275-BBD7A907ABE0}
[2012/06/12 16:49:10 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Apple Computer
[2012/06/12 11:11:00 | 000,000,000 | —D | C] – C:\Windows\SysWow64\cache
[2012/06/12 07:13:18 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{DE9F876E-4D46-4206-A3A5-4CBB091E4B40}
[2012/06/12 07:12:31 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{28824F43-59D7-43E1-832E-AAC5C0E9B96B}
[2012/06/11 16:47:23 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Screen Shots
[2012/06/11 16:28:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Tableau
[2012/06/11 15:29:59 | 000,000,000 | —D | C] – C:\Users\Brad C\LimitlessLeadGenerationGuideMRR
[2012/06/11 15:12:00 | 000,000,000 | —D | C] – C:\Users\Brad C\Tracing
[2012/06/11 15:06:52 | 000,000,000 | —D | C] – C:\ProgramData\SweetIM
[2012/06/11 15:06:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\SweetIM
[2012/06/11 15:06:25 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\pdfforge
[2012/06/11 15:06:22 | 000,065,024 | —- | C] (pdfforge GbR) – C:\Windows\SysNative\pdfcmon.dll
[2012/06/11 14:57:15 | 000,000,000 | -H-D | C] – C:\ProgramData\{A3A26C56-02C3-4F76-A033-12EE2FB52AE6}
[2012/06/11 14:57:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock
[2012/06/11 14:57:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Stardock
[2012/06/11 14:56:39 | 000,000,000 | –SD | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4
[2012/06/11 14:53:33 | 000,000,000 | —D | C] – C:\Users\Brad C\OpenOffice.org 3.4 (en-US) Installation Files
[2012/06/11 14:52:40 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling
[2012/06/11 14:52:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\LightScribe
[2012/06/11 14:49:31 | 000,000,000 | —D | C] – C:\9becf207da7d7dfef274f5c9
[2012/06/11 14:48:23 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2012/06/11 14:48:23 | 000,000,000 | —D | C] – C:\Users\Brad C\Skype
[2012/06/11 14:48:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2012/06/11 14:45:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/06/11 14:43:45 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2012/06/11 14:39:35 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Allmyapps
[2012/06/11 14:39:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Allmyapps
[2012/06/11 14:39:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Allmyapps
[2012/06/11 14:39:23 | 000,000,000 | —D | C] – C:\ProgramData\Allmyapps
[2012/06/11 14:38:57 | 003,534,288 | —- | C] (Allmyapps) – C:\Users\Brad C\Facebook_video_calling_Allmyapps_Setup.exe
[2012/06/11 06:36:27 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{38072749-59A0-48BC-868F-67C7C50F8993}
[2012/06/11 06:36:16 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{A4F8141A-4C4D-4493-A0F3-2F6EB5E3F69E}
[2012/06/10 16:13:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Creator
[2012/06/10 16:13:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\GPLGS
[2012/06/10 16:13:17 | 000,000,000 | —D | C] – C:\Program1
[2012/06/09 06:42:28 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Software Informer
[2012/06/09 06:42:28 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Software Informer
[2012/06/09 06:42:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Software Informer
[2012/06/09 06:42:04 | 000,000,000 | —D | C] – C:\ProgramData\A-PDF
[2012/06/09 06:42:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PPT To Flash Catalog Professional
[2012/06/09 06:41:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\PPT To Flash Catalog Professional
[2012/06/09 06:41:59 | 000,000,000 | —D | C] – C:\ProgramData\flipBook
[2012/06/09 06:41:42 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\PPTtoFlashCatalogPro
[2012/06/09 06:41:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\WebFormDesigner
[2012/06/09 06:40:53 | 000,000,000 | —D | C] – C:\Users\Brad C\WFDInstall
[2012/06/09 06:40:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\CamStudio
[2012/06/09 05:30:20 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{FEBE7E0A-3050-4A4E-9365-C00BF81FDDF4}
[2012/06/09 05:30:09 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{941FC528-AC8E-4933-93DD-683B40AFCB72}
[2012/06/08 08:09:51 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{AF132AE6-BBCF-4807-A4F4-28EF497119B9}
[2012/06/08 08:09:40 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{000E45A8-7676-4F86-A208-B04EEE3DF036}
[2012/06/08 07:29:49 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\Article Submission Helper
[2012/06/08 07:29:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\ASHelper
[2012/06/07 19:28:26 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{2E56102B-A738-4BFE-894E-E925B339AFF2}
[2012/06/07 19:28:15 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{79DF1C6B-F755-461E-B3F5-29A5CC9C4BEB}
[2012/06/07 14:42:22 | 000,000,000 | —D | C] – C:\Users\Brad C\.thumbnails
[2012/06/07 14:00:02 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\fontconfig
[2012/06/07 14:00:00 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\gegl-0.2
[2012/06/07 14:00:00 | 000,000,000 | —D | C] – C:\Users\Brad C\.gimp-2.8
[2012/06/07 13:58:36 | 000,000,000 | —D | C] – C:\Program Files\GIMP 2
[2012/06/07 05:29:29 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{4548D96F-40F1-428F-8B87-A63092F2A2C4}
[2012/06/07 05:29:18 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{2CA04E2A-9FA7-4C06-A45A-C5321522F517}
[2012/06/06 17:28:51 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{49963352-2D04-4BAF-B1EA-7539FC580A33}
[2012/06/06 17:28:40 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{E931F0B9-2B67-40B2-99FC-8C6C2DAFF57F}
[2012/05/24 09:30:33 | 017,152,712 | —- | C] (Mozilla) – C:\Users\Brad C\Firefox Setup 13.0b4.exe
[2012/05/16 07:50:55 | 000,516,136 | —- | C] (Bandoo Media Inc) – C:\Users\Brad C\iLividSetupV1.exe
[2012/05/09 16:17:58 | 000,809,288 | —- | C] (AirInstaller Inc.) – C:\Users\Brad C\setup.exe
[2012/05/08 13:17:02 | 004,472,121 | —- | C] (CamStudio Open Source Dev Team ) – C:\Users\Brad C\CamStudio_Setup_v2.6b_r294_(build_24Oct2010).exe
[2012/03/23 12:00:00 | 000,733,280 | —- | C] (Google Inc.) – C:\Users\Brad C\ChromeSetup.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2012/07/06 15:01:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2012/07/06 14:52:02 | 000,000,932 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000UA.job
[2012/07/06 14:52:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000UA.job
[2012/07/06 14:52:01 | 000,000,910 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000Core.job
[2012/07/06 14:37:49 | 000,000,193 | —- | M] () – C:\Windows\WORDPAD.INI
[2012/07/06 14:33:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/06 14:30:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/06 13:52:37 | 101,200,596 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/07/06 13:52:09 | 000,487,533 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/07/06 13:45:48 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/06 12:34:01 | 000,220,164 | —- | M] () – C:\Users\Brad C\Desktop\LoneWolfPassiveProfits.pdf
[2012/07/06 11:37:07 | 000,230,548 | —- | M] () – C:\Users\Brad C\Desktop\buildyouronlinemarketingplan.pdf
[2012/07/06 09:56:21 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/06 09:56:21 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/06 09:52:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000Core.job
[2012/07/06 09:49:29 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/06 09:48:53 | 000,000,354 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForBRADC-BRADC-HP$.job
[2012/07/06 09:48:40 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2012/07/04 11:48:27 | 000,001,180 | —- | M] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2012/07/04 05:01:49 | 000,569,220 | —- | M] () – C:\Users\Brad C\Desktop\freetrafficmarketingreport.pdf
[2012/07/04 04:43:30 | 000,001,682 | -HS- | M] () – C:\ProgramData\KGyGaAvL.sys
[2012/07/03 17:00:07 | 000,452,917 | —- | M] () – C:\Users\Brad C\Desktop\tw12345.png
[2012/07/03 16:35:07 | 000,310,273 | —- | M] () – C:\Users\Brad C\Desktop\twitterbackground1.jpg
[2012/07/03 14:59:23 | 000,304,310 | —- | M] () – C:\Users\Brad C\Desktop\Blogging-Toolkit-Suscriber-background1.jpg
[2012/07/02 13:16:46 | 002,348,119 | —- | M] () – C:\Users\Brad C\Desktop\blogandping.pdf
[2012/07/02 11:37:17 | 000,024,799 | —- | M] () – C:\Users\Brad C\Desktop\migraine diary.pdf
[2012/07/02 11:37:06 | 000,014,397 | —- | M] () – C:\Users\Brad C\Desktop\migraine diary.odt
[2012/07/02 10:51:54 | 000,084,459 | —- | M] () – C:\Users\Brad C\Desktop\paperbackstack(2).jpg
[2012/07/02 09:51:42 | 000,061,958 | —- | M] () – C:\Users\Brad C\Desktop\ringbinderlaying(1).jpg
[2012/07/02 09:35:39 | 000,024,999 | —- | M] () – C:\Users\Brad C\Desktop\migraineebook.odt
[2012/07/01 19:06:53 | 000,161,426 | —- | M] () – C:\Users\Brad C\Desktop\10 Tips for Success.pdf
[2012/07/01 19:06:48 | 000,100,017 | —- | M] () – C:\Users\Brad C\Desktop\10 Tips for Success.odt
[2012/07/01 18:49:43 | 000,066,799 | —- | M] () – C:\Users\Brad C\Desktop\paperbackstack(1).jpg
[2012/07/01 12:24:29 | 000,000,982 | —- | M] () – C:\Users\Public\Desktop\CamStudio-Recorder.lnk
[2012/07/01 12:23:44 | 000,015,228 | —- | M] () – C:\Users\Brad C\Desktop\Tips & Tricks to Make Money Online.odt
[2012/07/01 09:44:21 | 000,217,362 | —- | M] () – C:\Users\Brad C\Desktop\Internet Marketing.pdf
[2012/07/01 09:31:39 | 000,347,738 | —- | M] () – C:\Users\Brad C\Desktop\Automate Your Business.pdf
[2012/07/01 09:31:31 | 000,361,127 | —- | M] () – C:\Users\Brad C\Desktop\How To Drive Big Traffic.pdf
[2012/07/01 09:31:23 | 000,384,983 | —- | M] () – C:\Users\Brad C\Desktop\Secrets of the Winners.pdf
[2012/07/01 09:31:12 | 000,369,901 | —- | M] () – C:\Users\Brad C\Desktop\10 Twitter Tips.pdf
[2012/07/01 07:10:41 | 004,472,121 | —- | M] (CamStudio Open Source Dev Team ) – C:\Users\Brad C\Downloads\Documents\CamStudio_Setup_v2.6b_r294_(build_24Oct2010).exe
[2012/07/01 06:53:36 | 000,002,416 | —- | M] () – C:\Users\Brad C\Desktop\Google Chrome.lnk
[2012/06/30 16:44:45 | 072,261,231 | —- | M] () – C:\Users\Brad C\Desktop\TrafficVideosMRR.zip
[2012/06/30 16:05:34 | 001,609,904 | —- | M] () – C:\Users\Brad C\Desktop\the_essential_guide_to_internet_marketing.pdf
[2012/06/30 10:39:10 | 000,834,766 | —- | M] () – C:\Users\Brad C\Desktop\replace-your-job-with-an-internet-business.pdf
[2012/06/30 10:08:44 | 000,002,931 | —- | M] () – C:\Users\Brad C\Desktop\TweetDeck.lnk
[2012/06/30 09:29:58 | 000,187,600 | —- | M] () – C:\Users\Brad C\Desktop\treat-me-good-and-i-treat-you-good_wl29jfr100.pdf
[2012/06/30 09:09:54 | 000,000,336 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForBrad C.job
[2012/06/29 17:07:11 | 000,337,672 | —- | M] () – C:\Users\Brad C\Desktop\IMeye_report.pdf
[2012/06/28 13:08:00 | 000,105,944 | —- | M] () – C:\Users\Brad C\Desktop\Howtobecomesuccessfulinaffiliagemarketing.pdf
[2012/06/28 13:07:52 | 000,278,939 | —- | M] () – C:\Users\Brad C\Desktop\Successful Affiliate Strategies.pdf
[2012/06/28 11:35:16 | 000,002,181 | —- | M] () – C:\Users\Brad C\Desktop\bradleycoats.com.html
[2012/06/28 10:45:31 | 023,911,551 | —- | M] () – C:\Users\Brad C\Desktop\QuickBlogIndexing_PLR.zip
[2012/06/28 10:45:01 | 024,120,316 | —- | M] () – C:\Users\Brad C\Desktop\HowToSetDomainNameservers_PLR.zip
[2012/06/28 10:39:03 | 001,025,264 | —- | M] () – C:\Users\Brad C\Desktop\BlogThemes_201109.zip
[2012/06/28 09:50:05 | 000,173,688 | —- | M] () – C:\Users\Brad C\Desktop\tscc.exe
[2012/06/28 09:41:29 | 143,316,947 | —- | M] () – C:\Users\Brad C\Desktop\CreateStunningVideoSlideshowsForFree_PLR.zip
[2012/06/28 09:38:50 | 002,115,021 | —- | M] () – C:\Users\Brad C\Desktop\OnlineVideo2012_PLR.zip
[2012/06/28 06:59:21 | 000,178,428 | —- | M] () – C:\Users\Brad C\Desktop\All the traffic your website can handle.pdf
[2012/06/27 18:46:51 | 000,136,875 | —- | M] () – C:\Users\Brad C\Desktop\Listbuilding Old and New.odt
[2012/06/27 18:01:20 | 000,057,590 | —- | M] () – C:\Users\Brad C\Desktop\ringbinderlaying.jpg
[2012/06/27 17:43:39 | 000,029,513 | —- | M] () – C:\Users\Brad C\Desktop\Screen-Shot-2012-06-25-at-10.26.09-AM-400x184.png
[2012/06/27 17:21:04 | 000,083,618 | —- | M] () – C:\Users\Brad C\Desktop\paperbackstack.jpg
[2012/06/27 16:27:00 | 000,001,025 | —- | M] () – C:\Users\Public\Desktop\Content Spin Bot.lnk
[2012/06/27 11:54:46 | 000,001,536 | —- | M] () – C:\Users\Public\Desktop\videosqueeze.lnk
[2012/06/26 14:25:52 | 000,916,472 | —- | M] () – C:\Users\Brad C\Desktop\nstf_cheat_sheet.pdf
[2012/06/26 14:18:17 | 000,094,937 | —- | M] () – C:\Users\Brad C\Desktop\NSTF Video 1 Slides.pdf
[2012/06/25 16:37:19 | 000,716,038 | —- | M] () – C:\Users\Brad C\Downloads\Documents\Learn Affiliate Marketing Basics E-book.odt
[2012/06/23 16:40:45 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/23 16:40:45 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/22 16:59:19 | 000,002,533 | —- | M] () – C:\Users\Brad C\Desktop\Skype (2).lnk
[2012/06/22 16:45:02 | 000,001,790 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/06/22 16:41:13 | 079,225,752 | —- | M] (Apple Inc.) – C:\Users\Brad C\iTunes64Setup.exe
[2012/06/22 16:29:05 | 002,068,428 | —- | M] () – C:\Users\Brad C\Desktop\1kblueprintnewpdf.pdf
[2012/06/21 06:45:07 | 000,483,593 | —- | M] () – C:\Users\Brad C\Downloads\Documents\LAMB.png
[2012/06/20 16:16:23 | 004,976,920 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/16 06:03:59 | 000,001,515 | —- | M] () – C:\Users\Brad C\Desktop\TrafficGeneration-ecourse - Shortcut.lnk
[2012/06/15 13:03:55 | 000,305,178 | —- | M] () – C:\Users\Brad C\Desktop\BrandNewEbook.odt
[2012/06/14 15:53:08 | 000,002,107 | —- | M] () – C:\Users\Public\Desktop\Express Zip File Compression Software.lnk
[2012/06/14 15:20:50 | 000,727,381 | —- | M] () – C:\Users\Brad C\Desktop\3waystomineyourlist.pdf
[2012/06/14 15:20:47 | 000,062,105 | —- | M] () – C:\Users\Brad C\Desktop\squeeze.pdf
[2012/06/14 08:43:38 | 000,001,177 | —- | M] () – C:\Users\Public\Desktop\PhotoStage Slideshow Producer.lnk
[2012/06/14 08:02:19 | 000,001,149 | —- | M] () – C:\Users\Brad C\Desktop\AVG PC Tuneup 2011.lnk
[2012/06/13 20:26:42 | 000,797,466 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/13 20:26:42 | 000,662,870 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/13 20:26:42 | 000,122,408 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/13 18:26:20 | 000,001,220 | —- | M] () – C:\Users\Public\Desktop\Affiliate ID Manager Master Rebrander .lnk
[2012/06/13 14:04:34 | 000,001,182 | —- | M] () – C:\Users\Public\Desktop\LibreOffice 3.4.lnk
[2012/06/13 13:59:21 | 001,536,192 | —- | M] (W3i, LLC) – C:\Users\Brad C\Desktop\libreoffice.exe
[2012/06/13 13:50:14 | 000,032,280 | —- | M] () – C:\Users\Brad C\Downloads\Documents\demo.html
[2012/06/12 07:14:56 | 000,001,242 | —- | M] () – C:\Users\Brad C\Desktop\Paint.lnk
[2012/06/11 16:54:12 | 000,006,144 | —- | M] () – C:\Users\Brad C\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/06/11 16:29:05 | 000,001,307 | —- | M] () – C:\Users\Public\Desktop\Tableau Public 6.1.lnk
[2012/06/11 16:24:45 | 000,001,242 | —- | M] () – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk
[2012/06/11 15:30:07 | 000,001,554 | —- | M] () – C:\Users\Brad C\Desktop\LimitlessLeadGenerationGuide - Shortcut.lnk
[2012/06/11 15:17:38 | 000,011,264 | —- | M] () – C:\Users\Brad C\Downloads\Documents\NicheData.db
[2012/06/11 14:57:59 | 000,000,829 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/11 14:57:18 | 000,002,033 | —- | M] () – C:\Users\Brad C\Desktop\Customize Fences.lnk
[2012/06/11 14:52:43 | 000,002,044 | —- | M] () – C:\Users\Public\Desktop\LightScribe.lnk
[2012/06/11 14:48:23 | 000,002,533 | —- | M] () – C:\Users\Brad C\Desktop\Skype.lnk
[2012/06/11 14:45:22 | 000,001,014 | —- | M] () – C:\Users\Brad C\Desktop\Audacity.lnk
[2012/06/11 14:39:31 | 000,000,960 | —- | M] () – C:\Users\Public\Desktop\Allmyapps.lnk
[2012/06/11 14:39:00 | 003,534,288 | —- | M] (Allmyapps) – C:\Users\Brad C\Facebook_video_calling_Allmyapps_Setup.exe
[2012/06/11 14:13:51 | 000,002,464 | —- | M] () – C:\Users\Brad C\Traffic Overdrive - Shortcut.lnk
[2012/06/10 16:34:34 | 000,034,333 | —- | M] () – C:\Users\Brad C\Downloads\Documents\internetnewbiebusinessmodel.odt
[2012/06/10 16:13:13 | 000,302,425 | —- | M] () – C:\Users\Brad C\AppData\Local\funmoods-speeddial.crx
[2012/06/10 16:13:13 | 000,031,470 | —- | M] () – C:\Users\Brad C\AppData\Local\funmoods.crx
[2012/06/09 06:33:54 | 001,364,995 | —- | M] () – C:\Users\Brad C\setup20.exe
[2012/06/09 05:56:13 | 000,304,659 | —- | M] () – C:\Users\Brad C\Downloads\Documents\Free Web Tools.pdf
[2012/06/08 17:31:21 | 000,080,184 | —- | M] () – C:\Users\Brad C\13 Secrets.pdf
[2012/06/08 17:31:11 | 000,026,679 | —- | M] () – C:\Users\Brad C\Downloads\Documents\13 Secrets.odt
[2012/06/08 15:33:09 | 000,164,720 | —- | M] () – C:\Users\Brad C\Extremefreetips.pdf
[2012/06/08 07:29:46 | 000,000,890 | —- | M] () – C:\Users\Brad C\Desktop\ASHelper.lnk
[2012/06/07 14:43:32 | 000,002,802 | —- | M] () – C:\Users\Brad C\AppData\Local\recently-used.xbel
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2012/07/06 14:37:49 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2012/07/06 12:34:01 | 000,220,164 | —- | C] () – C:\Users\Brad C\Desktop\LoneWolfPassiveProfits.pdf
[2012/07/06 11:37:07 | 000,230,548 | —- | C] () – C:\Users\Brad C\Desktop\buildyouronlinemarketingplan.pdf
[2012/07/04 11:48:27 | 000,001,180 | —- | C] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2012/07/04 05:01:49 | 000,569,220 | —- | C] () – C:\Users\Brad C\Desktop\freetrafficmarketingreport.pdf
[2012/07/03 17:00:06 | 000,452,917 | —- | C] () – C:\Users\Brad C\Desktop\tw12345.png
[2012/07/03 16:35:07 | 000,310,273 | —- | C] () – C:\Users\Brad C\Desktop\twitterbackground1.jpg
[2012/07/03 13:34:53 | 000,304,310 | —- | C] () – C:\Users\Brad C\Desktop\Blogging-Toolkit-Suscriber-background1.jpg
[2012/07/02 13:16:46 | 002,348,119 | —- | C] () – C:\Users\Brad C\Desktop\blogandping.pdf
[2012/07/02 11:37:15 | 000,024,799 | —- | C] () – C:\Users\Brad C\Desktop\migraine diary.pdf
[2012/07/02 11:37:04 | 000,014,397 | —- | C] () – C:\Users\Brad C\Desktop\migraine diary.odt
[2012/07/02 10:51:54 | 000,084,459 | —- | C] () – C:\Users\Brad C\Desktop\paperbackstack(2).jpg
[2012/07/02 09:51:41 | 000,061,958 | —- | C] () – C:\Users\Brad C\Desktop\ringbinderlaying(1).jpg
[2012/07/02 09:35:37 | 000,024,999 | —- | C] () – C:\Users\Brad C\Desktop\migraineebook.odt
[2012/07/01 19:06:52 | 000,161,426 | —- | C] () – C:\Users\Brad C\Desktop\10 Tips for Success.pdf
[2012/07/01 18:49:43 | 000,066,799 | —- | C] () – C:\Users\Brad C\Desktop\paperbackstack(1).jpg
[2012/07/01 18:25:59 | 000,100,017 | —- | C] () – C:\Users\Brad C\Desktop\10 Tips for Success.odt
[2012/07/01 12:24:29 | 000,000,982 | —- | C] () – C:\Users\Public\Desktop\CamStudio-Recorder.lnk
[2012/07/01 12:23:42 | 000,015,228 | —- | C] () – C:\Users\Brad C\Desktop\Tips & Tricks to Make Money Online.odt
[2012/07/01 09:44:21 | 000,217,362 | —- | C] () – C:\Users\Brad C\Desktop\Internet Marketing.pdf
[2012/07/01 09:31:39 | 000,347,738 | —- | C] () – C:\Users\Brad C\Desktop\Automate Your Business.pdf
[2012/07/01 09:31:31 | 000,361,127 | —- | C] () – C:\Users\Brad C\Desktop\How To Drive Big Traffic.pdf
[2012/07/01 09:31:23 | 000,384,983 | —- | C] () – C:\Users\Brad C\Desktop\Secrets of the Winners.pdf
[2012/07/01 09:31:12 | 000,369,901 | —- | C] () – C:\Users\Brad C\Desktop\10 Twitter Tips.pdf
[2012/06/30 16:43:42 | 072,261,231 | —- | C] () – C:\Users\Brad C\Desktop\TrafficVideosMRR.zip
[2012/06/30 16:05:33 | 001,609,904 | —- | C] () – C:\Users\Brad C\Desktop\the_essential_guide_to_internet_marketing.pdf
[2012/06/30 10:39:09 | 000,834,766 | —- | C] () – C:\Users\Brad C\Desktop\replace-your-job-with-an-internet-business.pdf
[2012/06/30 09:29:57 | 000,187,600 | —- | C] () – C:\Users\Brad C\Desktop\treat-me-good-and-i-treat-you-good_wl29jfr100.pdf
[2012/06/29 17:07:11 | 000,337,672 | —- | C] () – C:\Users\Brad C\Desktop\IMeye_report.pdf
[2012/06/28 13:08:00 | 000,105,944 | —- | C] () – C:\Users\Brad C\Desktop\Howtobecomesuccessfulinaffiliagemarketing.pdf
[2012/06/28 13:07:51 | 000,278,939 | —- | C] () – C:\Users\Brad C\Desktop\Successful Affiliate Strategies.pdf
[2012/06/28 11:17:16 | 000,002,181 | —- | C] () – C:\Users\Brad C\Desktop\bradleycoats.com.html
[2012/06/28 10:45:18 | 023,911,551 | —- | C] () – C:\Users\Brad C\Desktop\QuickBlogIndexing_PLR.zip
[2012/06/28 10:44:45 | 024,120,316 | —- | C] () – C:\Users\Brad C\Desktop\HowToSetDomainNameservers_PLR.zip
[2012/06/28 10:39:02 | 001,025,264 | —- | C] () – C:\Users\Brad C\Desktop\BlogThemes_201109.zip
[2012/06/28 09:50:04 | 000,173,688 | —- | C] () – C:\Users\Brad C\Desktop\tscc.exe
[2012/06/28 09:39:28 | 143,316,947 | —- | C] () – C:\Users\Brad C\Desktop\CreateStunningVideoSlideshowsForFree_PLR.zip
[2012/06/28 09:38:48 | 002,115,021 | —- | C] () – C:\Users\Brad C\Desktop\OnlineVideo2012_PLR.zip
[2012/06/28 06:59:19 | 000,178,428 | —- | C] () – C:\Users\Brad C\Desktop\All the traffic your website can handle.pdf
[2012/06/27 18:46:49 | 000,136,875 | —- | C] () – C:\Users\Brad C\Desktop\Listbuilding Old and New.odt
[2012/06/27 18:01:19 | 000,057,590 | —- | C] () – C:\Users\Brad C\Desktop\ringbinderlaying.jpg
[2012/06/27 17:43:37 | 000,029,513 | —- | C] () – C:\Users\Brad C\Desktop\Screen-Shot-2012-06-25-at-10.26.09-AM-400x184.png
[2012/06/27 17:21:04 | 000,083,618 | —- | C] () – C:\Users\Brad C\Desktop\paperbackstack.jpg
[2012/06/27 16:27:00 | 000,001,025 | —- | C] () – C:\Users\Public\Desktop\Content Spin Bot.lnk
[2012/06/27 11:54:46 | 000,001,536 | —- | C] () – C:\Users\Public\Desktop\videosqueeze.lnk
[2012/06/26 18:22:01 | 000,000,340 | —- | C] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2012/06/26 14:25:51 | 000,916,472 | —- | C] () – C:\Users\Brad C\Desktop\nstf_cheat_sheet.pdf
[2012/06/26 14:18:17 | 000,094,937 | —- | C] () – C:\Users\Brad C\Desktop\NSTF Video 1 Slides.pdf
[2012/06/22 16:59:19 | 000,002,533 | —- | C] () – C:\Users\Brad C\Desktop\Skype (2).lnk
[2012/06/22 16:45:02 | 000,001,790 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/06/22 16:29:05 | 002,068,428 | —- | C] () – C:\Users\Brad C\Desktop\1kblueprintnewpdf.pdf
[2012/06/21 07:29:21 | 000,716,038 | —- | C] () – C:\Users\Brad C\Downloads\Documents\Learn Affiliate Marketing Basics E-book.odt
[2012/06/21 06:45:07 | 000,483,593 | —- | C] () – C:\Users\Brad C\Downloads\Documents\LAMB.png
[2012/06/16 05:10:39 | 000,002,931 | —- | C] () – C:\Users\Brad C\Desktop\TweetDeck.lnk
[2012/06/15 13:03:51 | 000,305,178 | —- | C] () – C:\Users\Brad C\Desktop\BrandNewEbook.odt
[2012/06/15 11:46:30 | 000,175,648 | —- | C] () – C:\Users\Brad C\Downloads\Documents\List Building for Beginners.pdf
[2012/06/14 16:27:39 | 001,548,484 | —- | C] () – C:\Users\Brad C\Desktop\nlb.exe
[2012/06/14 15:53:08 | 000,002,107 | —- | C] () – C:\Users\Public\Desktop\Express Zip File Compression Software.lnk
[2012/06/14 15:53:08 | 000,001,893 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Zip File Compression Software.lnk
[2012/06/14 15:20:50 | 000,727,381 | —- | C] () – C:\Users\Brad C\Desktop\3waystomineyourlist.pdf
[2012/06/14 15:20:47 | 000,062,105 | —- | C] () – C:\Users\Brad C\Desktop\squeeze.pdf
[2012/06/14 08:43:38 | 000,001,177 | —- | C] () – C:\Users\Public\Desktop\PhotoStage Slideshow Producer.lnk
[2012/06/14 08:43:37 | 000,001,189 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoStage Slideshow Producer.lnk
[2012/06/14 08:02:19 | 000,001,149 | —- | C] () – C:\Users\Brad C\Desktop\AVG PC Tuneup 2011.lnk
[2012/06/13 18:26:20 | 000,001,220 | —- | C] () – C:\Users\Public\Desktop\Affiliate ID Manager Master Rebrander .lnk
[2012/06/13 14:04:34 | 000,001,182 | —- | C] () – C:\Users\Public\Desktop\LibreOffice 3.4.lnk
[2012/06/13 13:50:14 | 000,032,280 | —- | C] () – C:\Users\Brad C\Downloads\Documents\demo.html
[2012/06/13 13:50:13 | 000,391,434 | —- | C] () – C:\Users\Brad C\Downloads\Documents\book.swf
[2012/06/12 07:14:56 | 000,001,242 | —- | C] () – C:\Users\Brad C\Desktop\Paint.lnk
[2012/06/11 16:29:05 | 000,001,319 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tableau Public 6.1.lnk
[2012/06/11 16:29:05 | 000,001,307 | —- | C] () – C:\Users\Public\Desktop\Tableau Public 6.1.lnk
[2012/06/11 16:26:24 | 000,001,515 | —- | C] () – C:\Users\Brad C\Desktop\TrafficGeneration-ecourse - Shortcut.lnk
[2012/06/11 16:24:45 | 000,001,242 | —- | C] () – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk
[2012/06/11 15:30:07 | 000,001,554 | —- | C] () – C:\Users\Brad C\Desktop\LimitlessLeadGenerationGuide - Shortcut.lnk
[2012/06/11 15:17:38 | 000,011,264 | —- | C] () – C:\Users\Brad C\Downloads\Documents\NicheData.db
[2012/06/11 14:57:59 | 000,000,829 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/11 14:57:18 | 000,002,033 | —- | C] () – C:\Users\Brad C\Desktop\Customize Fences.lnk
[2012/06/11 14:52:43 | 000,002,044 | —- | C] () – C:\Users\Public\Desktop\LightScribe.lnk
[2012/06/11 14:48:23 | 000,002,533 | —- | C] () – C:\Users\Brad C\Desktop\Skype.lnk
[2012/06/11 14:45:22 | 000,001,026 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2012/06/11 14:45:22 | 000,001,014 | —- | C] () – C:\Users\Brad C\Desktop\Audacity.lnk
[2012/06/11 14:39:31 | 000,000,960 | —- | C] () – C:\Users\Public\Desktop\Allmyapps.lnk
[2012/06/10 16:34:32 | 000,034,333 | —- | C] () – C:\Users\Brad C\Downloads\Documents\internetnewbiebusinessmodel.odt
[2012/06/10 16:13:22 | 000,302,425 | —- | C] () – C:\Users\Brad C\AppData\Local\funmoods-speeddial.crx
[2012/06/10 16:13:18 | 000,087,552 | —- | C] () – C:\Windows\SysNative\custmon64i.dll
[2012/06/10 16:13:18 | 000,031,470 | —- | C] () – C:\Users\Brad C\AppData\Local\funmoods.crx
[2012/06/09 06:33:52 | 001,364,995 | —- | C] () – C:\Users\Brad C\setup20.exe
[2012/06/09 05:56:13 | 000,304,659 | —- | C] () – C:\Users\Brad C\Downloads\Documents\Free Web Tools.pdf
[2012/06/08 17:31:19 | 000,080,184 | —- | C] () – C:\Users\Brad C\13 Secrets.pdf
[2012/06/08 17:31:09 | 000,026,679 | —- | C] () – C:\Users\Brad C\Downloads\Documents\13 Secrets.odt
[2012/06/08 15:33:06 | 000,164,720 | —- | C] () – C:\Users\Brad C\Extremefreetips.pdf
[2012/06/08 07:29:46 | 000,000,890 | —- | C] () – C:\Users\Brad C\Desktop\ASHelper.lnk
[2012/06/07 14:43:32 | 000,002,802 | —- | C] () – C:\Users\Brad C\AppData\Local\recently-used.xbel
[2012/06/07 13:59:27 | 000,000,899 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
[2012/05/24 09:31:26 | 000,001,056 | —- | C] () – C:\Users\Brad C\Mozilla Firefox.lnk
[2012/05/11 15:08:19 | 000,002,212 | —- | C] () – C:\Users\Brad C\WinZip.lnk
[2012/05/09 17:10:02 | 000,001,074 | —- | C] () – C:\Users\Brad C\Free Download Manager.lnk
[2012/05/02 13:48:11 | 000,001,467 | —- | C] () – C:\Users\Brad C\my affiliate marketing course - Shortcut.lnk
[2012/05/02 12:08:16 | 000,001,873 | —- | C] () – C:\Users\Brad C\01 - Affiliate Marketer's Handbook - Shortcut.lnk
[2012/05/02 11:44:13 | 000,001,500 | —- | C] () – C:\Users\Brad C\Super Affiliate Secrets Exposed!.lnk
[2012/05/01 17:14:51 | 000,009,585 | —- | C] () – C:\Users\Brad C\workinprogress.jpg
[2012/05/01 16:55:19 | 000,072,527 | —- | C] () – C:\Users\Brad C\images3.png
[2012/05/01 15:08:20 | 000,136,688 | —- | C] () – C:\Users\Brad C\Outsourcing-Strategies.pdf
[2012/04/30 14:52:01 | 000,176,198 | —- | C] () – C:\Users\Brad C\Weight loss for a Healthier Lifestyle.pdf
[2012/04/30 14:02:19 | 000,109,445 | —- | C] () – C:\Users\Brad C\Weight loss for a Healthier Lifestyle.odt
[2012/04/30 12:50:31 | 000,003,272 | —- | C] () – C:\Users\Brad C\Ebook - Shortcut.lnk
[2012/04/29 13:26:21 | 000,001,981 | —- | C] () – C:\Users\Brad C\socrates - Shortcut.lnk
[2012/04/29 10:36:24 | 000,358,835 | —- | C] () – C:\Users\Brad C\free-header-image-2.psd
[2012/04/28 21:49:18 | 000,011,614 | —- | C] () – C:\Users\Brad C\new opt in form.html
[2012/04/28 10:39:17 | 000,070,251 | —- | C] () – C:\Users\Brad C\QuickHealthyWeightLoss.odt
[2012/04/25 17:43:20 | 000,001,131 | —- | C] () – C:\Users\Brad C\Thinspiration.html
[2012/04/24 19:40:56 | 000,002,293 | —- | C] () – C:\Users\Brad C\Foods_That_Kill_Fat_mg - Shortcut.lnk
[2012/04/24 19:37:36 | 000,002,410 | —- | C] () – C:\Users\Brad C\how-to-knock-20-years-off-your-body - Shortcut.lnk
[2012/04/24 16:48:49 | 000,624,374 | —- | C] () – C:\Users\Brad C\7figuresuccessformulatrafficguide.pdf
[2012/04/24 10:56:49 | 000,001,614 | —- | C] () – C:\Users\Brad C\Worlds-Shortest-Viral-Book.pdf
[2012/04/24 10:37:57 | 000,282,283 | —- | C] () – C:\Users\Brad C\Ultimate-ClickBank.pdf
[2012/04/23 17:13:07 | 000,006,140 | —- | C] () – C:\Users\Brad C\Image1.png
[2012/04/23 14:35:46 | 000,002,464 | —- | C] () – C:\Users\Brad C\Traffic Overdrive - Shortcut.lnk
[2012/04/22 21:03:02 | 000,001,701 | —- | C] () – C:\Users\Brad C\TrafficExplosion - Shortcut.lnk
[2012/04/21 17:19:31 | 000,000,132 | —- | C] () – C:\Users\Brad C\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2012/04/15 13:12:00 | 000,001,792 | —- | C] () – C:\Users\Brad C\Newsletter - Shortcut.lnk
[2012/04/12 10:21:27 | 000,001,315 | —- | C] () – C:\Users\Brad C\The Weather Channel App.lnk
[2012/04/08 09:25:44 | 000,001,738 | —- | C] () – C:\Users\Brad C\feuxjo - Shortcut.lnk
[2012/01/22 17:22:12 | 000,001,017 | —- | C] () – C:\Program Files (x86)\Commission Streamer.lnk
[2012/01/22 17:22:12 | 000,000,967 | —- | C] () – C:\Program Files (x86)\Update Commission Streamer.lnk
[2012/01/04 18:16:43 | 000,000,015 | —- | C] () – C:\Windows\cfwin.ini
[2012/01/04 18:16:41 | 000,000,110 | —- | C] () – C:\Windows\cfwinlib.ini
[2011/11/23 23:37:29 | 000,742,442 | —- | C] () – C:\Windows\XHeader Uninstaller.exe
[2011/09/11 16:47:13 | 000,024,209 | —- | C] () – C:\Users\Brad C\AppData\Roaming\UserTile.png
[2011/08/29 13:47:42 | 000,538,222 | —- | C] () – C:\Users\Brad C\NonStopViralTraffic.pdf
[2011/05/24 18:58:23 | 000,006,144 | —- | C] () – C:\Users\Brad C\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/24 18:57:56 | 000,001,682 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2011/05/13 11:16:11 | 000,001,854 | —- | C] () – C:\Users\Brad C\AppData\Roaming\GhostObjGAFix.xml
[2011/04/18 07:49:36 | 000,777,312 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/03/29 05:46:58 | 000,414,113 | —- | C] () – C:\Users\Brad C\Turbo_Traffic_ebook.pdf
[2010/10/25 03:47:34 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/10/25 03:38:46 | 000,002,857 | —- | C] () – C:\Windows\SysWow64\atipblup.dat
[2010/10/25 03:37:37 | 000,000,299 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini
[2010/10/25 03:37:37 | 000,000,240 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini
[2010/10/16 14:42:34 | 000,000,188 | —- | C] () – C:\Windows\SysWow64\HPWA.ini
[2010/09/21 12:30:44 | 000,007,736 | —- | C] () – C:\Windows\hpDSTRES.DLL
[2010/07/28 17:08:46 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2010/07/28 17:08:44 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2010/07/28 17:08:42 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2010/07/28 16:14:38 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/07/28 16:14:38 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll
========== LOP Check ==========
[2012/01/17 19:17:39 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Affilorama
[2012/06/11 14:39:45 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Allmyapps
[2011/08/17 11:40:52 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Archon Media
[2012/06/04 08:24:38 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Audacity
[2011/09/28 19:22:22 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Avanquest
[2012/06/14 08:37:29 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\AVG
[2012/03/13 20:31:53 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\AVG2012
[2012/05/09 17:09:28 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Babylon
[2011/11/16 16:25:28 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\CoffeeCup Software
[2011/11/21 17:12:07 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\com.fastcashcommissions.fasttrafficmagnet
[2011/11/21 12:50:44 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\com.fastcashcommissions.fasttrafficsniper
[2012/03/14 08:14:48 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\CommissionMultiplier
[2011/04/16 11:03:25 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\DigitalPersona
[2012/06/13 20:12:28 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\DVDVideoSoft
[2011/10/05 09:26:26 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Easy Click Commissions
[2012/03/23 15:29:11 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\eGames
[2012/02/15 01:48:00 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\FileZilla
[2011/11/04 17:06:58 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\GetRightToGo
[2011/11/22 02:32:06 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\IBP
[2011/11/15 15:37:31 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\IncomeGenesis
[2012/07/04 11:48:22 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\IObit
[2012/05/24 09:09:29 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\IrfanView
[2011/09/18 18:22:23 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Keyword Strategy Studio Pro
[2012/06/19 06:32:27 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Kingsoft
[2011/10/10 00:15:20 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\KompoZer
[2012/06/13 14:06:33 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\LibreOffice
[2011/11/23 19:24:08 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\MAGIX
[2011/05/13 11:17:55 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2011/09/25 19:05:10 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Nitro PDF
[2011/10/24 20:45:39 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Nvu
[2011/09/25 19:03:53 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\OpenCandy
[2011/05/08 22:20:27 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\OpenOffice.org
[2012/05/21 15:22:02 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\PCTools
[2012/03/31 21:57:59 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\PDAppFlex
[2012/06/11 15:06:26 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\pdfforge
[2011/10/15 21:25:44 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\PrimoPDF
[2011/12/30 16:56:43 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\SlimBrowser
[2012/07/05 15:34:52 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\SoftGrid Client
[2012/07/06 09:53:21 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Software Informer
[2011/04/16 11:09:33 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Stardock
[2012/05/23 08:32:26 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\TestApp
[2011/11/29 13:04:02 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\ThumbsPlus
[2011/05/06 10:03:58 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Thunderbird
[2011/04/18 07:59:30 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\TP
[2012/06/06 14:23:07 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Traffic Travis v4
[2012/01/26 19:48:28 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\TrafficInitiator-Air
[2012/06/30 10:07:18 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\TweetAdder3
[2011/11/14 17:45:29 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\ubot
[2012/04/22 11:09:48 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Ulead Systems
[2012/06/26 18:22:05 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Visan
[2011/10/30 22:41:10 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\WildTangent
[2011/05/16 12:45:17 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Windows Live Writer
[2012/07/06 09:49:51 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\ZumoDrive
[2012/07/06 14:52:01 | 000,000,910 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000Core.job
[2012/07/06 14:52:02 | 000,000,932 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000UA.job
[2012/07/04 20:03:09 | 000,032,612 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2012/05/23 08:13:04 | 000,014,253 | —- | M] () – C:\alotserviceruntime.log
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2008/04/11 10:07:18 | 000,003,820 | —- | M] () – C:\eula.1028.txt
[2008/04/11 10:07:18 | 000,015,428 | —- | M] () – C:\eula.1031.txt
[2008/04/11 10:07:18 | 000,010,058 | —- | M] () – C:\eula.1033.txt
[2008/04/11 10:07:18 | 000,012,246 | —- | M] () – C:\eula.1036.txt
[2008/04/11 10:07:18 | 000,013,912 | —- | M] () – C:\eula.1040.txt
[2008/04/11 10:07:18 | 000,005,868 | —- | M] () – C:\eula.1041.txt
[2008/04/11 10:07:18 | 000,005,970 | —- | M] () – C:\eula.1042.txt
[2008/04/11 10:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2008/04/11 10:07:18 | 000,003,814 | —- | M] () – C:\eula.2052.txt
[2008/04/11 10:07:18 | 000,012,936 | —- | M] () – C:\eula.3082.txt
[2008/04/11 10:07:18 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/07/06 09:48:40 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2008/04/11 08:03:48 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2008/04/11 10:07:18 | 000,000,843 | —- | M] () – C:\install.ini
[2008/04/11 08:03:48 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 08:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 08:03:48 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 08:03:48 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 08:03:48 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 08:03:48 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 08:03:48 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 10:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 08:03:48 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 08:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2012/05/23 08:13:04 | 000,020,374 | —- | M] () – C:\INSTALLHELPER.LOG
[2012/07/06 09:48:40 | 4083,007,488 | -HS- | M] () – C:\pagefile.sys
[2012/05/02 13:00:07 | 000,000,448 | —- | M] () – C:\user.js
[2008/04/11 10:07:18 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2008/04/11 10:09:38 | 003,797,292 | —- | M] () – C:\VC_RED.cab
[2008/04/11 10:11:40 | 000,233,472 | —- | M] () – C:\VC_RED.MSI
< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2011/07/03 19:13:07 | 000,001,718 | -HS- | M] () – C:\Users\Brad C\AppData\Roaming\Microsoft\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2012/01/22 17:22:12 | 000,001,017 | —- | M] () – C:\Program Files (x86)\Commission Streamer.lnk
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
[2012/01/22 17:22:12 | 000,000,967 | —- | M] () – C:\Program Files (x86)\Update Commission Streamer.lnk
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/28 17:51:32 | 000,000,221 | -HS- | M] () – C:\Users\Brad C\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2010/09/03 19:13:42 | 000,277,600 | —- | M] (CyberLink Corp.) – C:\Users\Brad C\Desktop\HPMediaSmartWebcam.exe
[2012/06/13 13:59:21 | 001,536,192 | —- | M] (W3i, LLC) – C:\Users\Brad C\Desktop\libreoffice.exe
[2006/03/29 19:37:40 | 001,548,484 | —- | M] () – C:\Users\Brad C\Desktop\nlb.exe
[2012/06/28 09:50:05 | 000,173,688 | —- | M] () – C:\Users\Brad C\Desktop\tscc.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 98 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:F49E02D5
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:F73EA84D
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:F1CBBAF0
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:82111599
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:CFF654D3
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:B9A60C8F
< End of report >
OTL Extras logfile created on: 7/6/2012 3:01:29 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Brad C\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.80 Gb Total Physical Memory | 1.06 Gb Available Physical Memory | 27.91% Memory free
7.60 Gb Paging File | 4.41 Gb Available in Paging File | 58.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 668.10 Gb Total Space | 591.32 Gb Free Space | 88.51% Space Free | Partition Type: NTFS
Drive D: | 30.24 Gb Total Space | 4.44 Gb Free Space | 14.69% Space Free | Partition Type: NTFS
Drive F: | 98.87 Mb Total Space | 83.72 Mb Free Space | 84.68% Space Free | Partition Type: FAT32
Computer Name: BRADC-BRADC-HP | User Name: Brad C | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Reg Error: Key error.] – Reg Error: Key error. File not found
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\PROGRA~2\COFFEE~1\coffee.exe" "%1" (CoffeeCup Software)
htmlfile [open] – Reg Error: Key error.
htmlfile [opennew] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [Browse with Corel PaintShop Photo Pro X3] – "c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\Corel Paint Shop Pro Photo.exe" "%L" (Corel, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Key error.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\PROGRA~2\COFFEE~1\coffee.exe" "%1" (CoffeeCup Software)
htmlfile [open] – Reg Error: Key error.
htmlfile [opennew] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [Browse with Corel PaintShop Photo Pro X3] – "c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\Corel Paint Shop Pro Photo.exe" "%L" (Corel, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Key error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{19597BB1-4C0D-445A-91E1-A50CEA98B102}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{1F4CBAFA-3407-420F-8577-4BD6C4C9C530}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{26BA617B-D372-4473-815F-5D294A60C9E4}" = lport=10243 | protocol=6 | dir=in | app=system |
"{2E58C59E-2C52-4EA9-AA23-9364DC7C6227}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{319E2D5C-7E1C-47AC-B8CA-A2C4543308DE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{344E1A98-D8B6-4300-AFB7-A172CC2B4FBB}" = lport=139 | protocol=6 | dir=in | app=system |
"{366B0C0D-D690-42C8-B52F-EF01FBC334F0}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{412921DD-17B7-4F79-ADDE-74165E45AD98}" = rport=137 | protocol=17 | dir=out | app=system |
"{428BF949-CC40-4252-ACAC-1FDB4D4B8E97}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{43AE201E-9DBB-4184-A757-0C6E7A309338}" = lport=445 | protocol=6 | dir=in | app=system |
"{5D5AB864-43EA-491E-BD2F-14EF9ECDB28F}" = lport=2799 | protocol=6 | dir=in | name=altova license metering port (tcp) |
"{6494BEDF-E1E7-4CAC-80F6-91342FC56560}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8281A89D-CD03-4988-8799-EC7A98A7C90E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{89BEDD83-4877-466F-8DAA-1726A7A1671A}" = rport=10243 | protocol=6 | dir=out | app=system |
"{92FDEE2A-92DC-49AE-B436-4CFBD91329E2}" = rport=139 | protocol=6 | dir=out | app=system |
"{95243C02-2C73-43A8-A777-7ED0619423F8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{96E08991-D28E-410D-B0A9-E6AC78F2EFCF}" = rport=138 | protocol=17 | dir=out | app=system |
"{97A93E76-29F3-4DF6-8348-548170552FFD}" = lport=2799 | protocol=17 | dir=in | name=altova license metering port (udp) |
"{9A56A1B6-BB51-4497-89F4-92EDED8B430E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A6882FBF-BF5A-4391-8D57-059F307A71D4}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{A9C5D378-6D36-49E6-8C83-EAA493DB4078}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B1A52194-F8ED-4EED-90F4-D0C50EDDC59A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B5EFCC30-E476-47ED-A727-5E91AF28380D}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{BB5ED2DF-59CB-4F3F-850B-BEA79109F96A}" = rport=445 | protocol=6 | dir=out | app=system |
"{C1FE3830-9F8F-44CA-9373-67E40607A113}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{D55BA07D-29B2-4EBE-8BEB-7E7674FA0944}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DAF32865-72FB-4A15-9A7B-DE6E5BE2ED7A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EBB0BA4A-2A0C-48A9-9042-D4C7C38357C3}" = lport=138 | protocol=17 | dir=in | app=system |
"{EC77558A-171B-462B-9624-DB0D8FF6FBF8}" = lport=137 | protocol=17 | dir=in | app=system |
"{EE83D38A-96D7-4164-A7E5-02BACBE9E466}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{F30BD097-9D87-4EEA-A04B-878D2DA6FDDD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F3AE84C8-1979-48B7-BB1E-136DD0C71A0C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FE8FC3AA-2DEC-4AFA-8EF1-8378C0CCF29D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FECF0628-975B-4D0F-A12D-8DE72106F3D9}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FF417F25-FFD0-403A-A03F-7831E64ABB9E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{012DB1E2-5BA9-48C4-98A9-C5E53480BCD8}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{02AB7CF2-4A1D-419E-88AA-20BA15FE570B}" = protocol=6 | dir=out | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe |
"{0A6644DF-32A6-4747-83F5-DD46018DEA73}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{167A3DB7-4866-4AB8-B7E0-8C80573A42F4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{17708663-162E-4E56-8ED7-F436A3077995}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{17DF2CA4-CABA-4AD1-A513-85C29F4F2905}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{18C54DAA-BB5D-4CBE-9F12-791C37386797}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{1B11BAB2-F8E5-4DBC-81D0-581E009B2C87}" = dir=in | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe |
"{1D870A5D-29D8-4834-8BF6-5D07EEFF13FC}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{2920D607-598A-4159-B2EC-3214BE2342A0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2B39A564-FF92-44C2-96F9-FA53B6D3F52E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2E2B96FD-90E4-4931-B027-AB21AA103E54}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{2E96BD0B-CA71-4A9E-AD7A-45C2F6793941}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{2F9AE797-02AE-4F50-89C4-B1A2A5223D76}" = protocol=6 | dir=out | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe |
"{30F1D8D0-6E0B-4F3C-99E7-36CCCA75C71B}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{31524F41-F598-4380-BC00-34A7E42475BC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{347D1738-E9C0-49B7-B29C-45A8D832CA53}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{3935C2B5-BB4B-40E7-B269-A50B0A84B201}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{3BFEE9BE-3E92-47AA-B7BA-CF3BC8BFC2BB}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{4269FF99-AA02-4EEB-A8BF-0E34CCD17B47}" = protocol=17 | dir=in | app=c:\program files (x86)\iwin games\iwingames.exe |
"{44DB90D1-904D-4754-B3E5-C4B7A0D57281}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{466A8946-F8EA-4EB7-9BF0-F129F4350050}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{47566C82-2438-4578-A55F-6BA764066056}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4EAB3CBE-F91F-4702-8858-2287F7F8B198}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{4F5D8B0B-158B-4ED2-848B-208B5C97D209}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{51E4E683-0820-43A4-93EA-7D46D864ABD4}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\photo\hpmediasmartphoto.exe |
"{531E4EA2-A739-42F8-8776-83D60AA614FF}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr8.exe |
"{56F5FD59-1693-4BF9-AB37-ECFE2F8C9E00}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\music\hptouchsmartmusic.exe |
"{57BBD81D-A081-4604-8374-7BD56FC3E0D3}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{64ED9658-9646-45AF-98FC-112236C13822}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{67585892-4DF5-48D3-A6BD-7D735B9DF7EC}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{6E0F85E1-E81D-41F5-89FE-49D94D313B00}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{6FC9FA5E-FE7C-4E12-9610-8D5EDC07FCCE}" = protocol=17 | dir=in | app=c:\program files (x86)\iwin games\webupdater.exe |
"{76205CB0-ACA0-459A-9B59-4D09B9B85C55}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{7953EEAE-92E7-4C92-8F36-8CB75F3EB5A2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7E056D9E-D868-4520-9A57-E82968D5CA43}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\video\hpmediasmartvideo.exe |
"{8C76CFBF-3952-40F6-BB9D-0C5B3193E39B}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{8D8B90D0-7A85-4F10-B0E4-D9385C487418}" = protocol=6 | dir=out | app=system |
"{8F7862A6-090A-448C-81B4-624FA64A5EBA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9B48BD76-01D4-4C6A-A0AB-CF8C88E8BCC0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A0F6D422-E7D9-4AFB-80A0-A2646D582C0A}" = protocol=6 | dir=in | app=c:\program files (x86)\iwin games\iwingames.exe |
"{A2DE498D-2AB9-4DE7-9D94-27038E4E7A69}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{ABF9F627-0D4F-43A2-8160-8C2228671038}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B03CFFCD-DF1A-48C0-BDE6-213895C33FEA}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{B462EBAB-194E-41E1-8634-24AB30D11704}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{BE7B332F-312E-49AE-966B-97D2F3B71796}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{C6EBCCC0-FF46-43E7-AE70-061C05849E6B}" = protocol=17 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |
"{C7269815-5F46-44B2-B2CB-E078725479C6}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{C85A73FD-9AFD-462C-859B-268B4A2ED22F}" = dir=out | app=c:\program files (x86)\hewlett-packard\hp clouddrive\zumodrive.exe |
"{CCBDC39A-76DE-4CA8-9022-F918AC526E54}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{D1E2A091-61CF-4326-B5C0-434C71461B19}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp clouddrive\zumodrive.exe |
"{D6FCFC6A-F902-4CA8-B292-914A279818E3}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{DB9C4F97-0A5F-43B7-9D9E-03ABE7E3BE78}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{EFA5ECC5-EFF9-4F3E-9CDF-300C7DB58C8E}" = dir=in | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe |
"{F1219C65-6FDF-4C7B-B60D-AB2344BACE0B}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{F373AB66-9210-45CB-9DDA-00A04BC764A1}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{F75699BF-D34D-4F52-BF63-F1BEA2F1B471}" = protocol=6 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |
"{FB3B073D-7014-42A4-B4FE-76AC0EBC9CC0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{FD021AE2-D32D-48A3-BD03-47F1E55FC42A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FE5055FE-A593-422A-A51B-ED57F06A6BCE}" = protocol=6 | dir=in | app=c:\program files (x86)\iwin games\webupdater.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{09BDCC02-80F2-4EFB-8F1B-A807D2C38E31}" = HP MediaSmart Movies and TV
"{10CD364B-FFCC-48BE-B469-B9622A033075}" = Fences
"{13DCC2C7-454D-42F0-A892-E0E9A5DE4E67}" = HP Wireless Assistant
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F86416021FF}" = Java™ 6 Update 21 (64-bit)
"{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services
"{336D0C35-8A85-403a-B9D2-65C292C39087}_is1" = Web Assistant 2.0.0.430
"{3C8159DD-1890-4625-A5B2-E3D8D78D4486}" = AVG 2012
"{426FAE9F-7373-496E-A215-9DB7EF4398CF}" = Validity Sensors DDK
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5BF97E02-2F6A-412A-BB4D-B6E2DC65FCA7}" = HP SimplePass Identity Protection
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
"{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}" = Bing Maps 3D
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
"{857B32C1-7C87-40B5-B2A5-D06F49B80002}" = AVG 2012
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A04108F4-71E9-FD90-D73D-2058DF6987F4}" = ATI Catalyst Install Manager
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BE6725F2-6D15-477C-86C6-4522B8569D62}" = HP MediaSmart SmartMenu
"{C84FFB07-C687-45CF-91C8-868DB8D8C8CD}" = HP 3D DriveGuard
"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6246243-CF06-4E40-8A37-C3B537695C36}" = Share64
"{FED4086D-51A8-E88C-1CF9-BA21A50470EE}" = ccc-utility64
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"AVG" = AVG 2012
"Broadcom 802.11 Wireless LAN Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CCleaner" = CCleaner
"GIMP-2_is1" = GIMP 2.8.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"PDF Creator" = PDF Creator
"SynTPDeinstKey" = Synaptics Pointing Device Driver
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{D1AEB5DB-04FA-489D-94EF-8600898B93EE}" = Corel PaintShop Photo Pro X3
"_{F072CA07-A781-45E4-9975-C033A73019CF}" = Corel VideoStudio Pro X3
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{00FB9AA8-5FFF-DDCE-DA2E-530994B59217}" = CCC Help Finnish
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{045C16AD-B2E5-43D0-BB51-2F1987D91038}" = HP Documentation
"{05BA3547-6C5C-7D39-4D23-DB5E61D8DD79}" = Income Genesis
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0965F857-DAAD-4F93-8054-0E2EC3C8C5B0}" = SweetIM for Messenger 3.6
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0EDEB615-1A60-425E-8306-0E10519C7B55}" = RoxioNow Player
"{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1991D8C3-8354-2228-401C-D3D105CA2AC4}" = CCC Help Chinese Traditional
"{19B9DAD6-5E6E-4B80-8EFE-314B5638D6D4}" = Xara 3D Maker 7
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1E6E990A-728D-4700-9B0A-2CA541C93A12}" = Catalyst Control Center - Branding
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2A738B10-A5C9-4525-8198-5B99C66E0A56}" = My Ebook Library
"{2D8539EE-3F50-94DB-2605-047B33558C70}" = CCC Help Thai
"{2EA3D6B2-157E-4112-A3AB-BF17E16661C3}" = HP MediaSmart/TouchSmart Netflix
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2FA75B40-17C9-4D22-88CA-80A5D52FAB13}" = LightScribe System Software
"{2FF2BBBA-341C-4F36-AB55-7398184733CE}" = CCC Help Italian
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{30296046-9CEB-4E8F-86BA-668155D123B3}_is1" = Spin Writer Pro version 1.0
"{31EEA563-3544-4EA1-8773-BCBF83F9627A}" = HP Software Framework
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33C8C01E-4787-482B-9D2C-AB8221FCC01D}" = IObit Toolbar v6.0
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{3B834B54-EC4B-48E2-BFC6-03FF5DA06F62}" = Adobe Shockwave Player 11.5
"{3DA41E54-9526-40C0-8456-66B09379DFCC}" = PaintShop Photo Pro X3 Registration Incentive
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{4717BD4A-E16A-41E9-B0D8-0BD931DAED96}" = CommentKahuna
"{491ADA37-04EE-2ECE-9F86-DDC0106047AC}" = Times Reader
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup
"{51071D66-D034-4239-94E0-723FCA10B6FE}" = OpenOffice.org 3.4
"{53469506-A37E-4314-A9D9-38724EC23A75}" = HP Setup
"{5410C77F-B22F-61FE-7D93-0BEDBC959FF3}" = PX Profile Update
"{5719D840-C30E-7DD3-C746-00B3A5C9BD6B}" = CCC Help Korean
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{5EDE7E1A-E386-BB8B-CD77-3B5AF9A8D80B}" = CCC Help Greek
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{670E7FFC-95FF-C425-BD00-91C120352C4B}" = CCC Help Turkish
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A396792-1CA6-E9E5-9844-512238F70C95}" = CCC Help Swedish
"{6B879152-071A-36B4-0F97-37B05552FA05}" = Fast Traffic Sniper
"{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"{6DC6392C-4D8C-D21E-A0DD-750BD76627F6}" = CCC Help Chinese Standard
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.2.0
"{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}" = HP Support Assistant
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74796D37-75F9-C430-CC1D-FCE8371D5EB3}" = CCC Help English
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7AB01508-C2B2-43C8-8B44-514801E7CCC9}" = Jing
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{7FBDEEDA-ECDB-A348-0FBC-41AD5D852B36}" = Catalyst Control Center Localization All
"{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}" = Rosetta Stone Version 3
"{819BD919-5B78-5D29-27AD-765778772B7C}" = Market Samurai
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83E55279-CE70-407F-B34D-EAE0D9C6372B}_is1" = eCover Software Pro
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{8AC3E7BB-F819-379B-3F81-255904B67A8A}" = CCC Help Czech
"{8B4B2F59-1C81-4389-9605-BA273957C24D}_is1" = Content Spin Bot version 1.0
"{8C696008-029B-BBA7-9CD3-45596A069D96}" = CCC Help Polish
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}" = InstallIQ Updater
"{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{91892B48-4503-D842-59A0-842F70503843}" = CCC Help Portuguese
"{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{946B0558-3E7B-D27B-2E95-3A2E99BCB826}" = Catalyst Control Center Graphics Previews Common
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{96B3C2A3-ADD6-4E63-89D3-1E3AC115D3FA}" = pdfforge Toolbar v6.0
"{9902DD1A-58CD-EE2D-1401-EF1D07D3D353}" = CCC Help Japanese
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BBEE625-F639-CB19-6447-98B25FF975DD}" = Traffic Launch Pad
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A44E3886-B7E7-ABA4-57C7-B423992CB536}" = Catalyst Control Center InstallProxy
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAD4E5A4-68CD-7957-81EF-8B50DBA5E939}" = CCC Help Danish
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{AE8289AB-E18C-36E6-BF9B-99557D9F7517}" = Catalyst Control Center Graphics Previews Vista
"{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager
"{B3E2EB86-2EDB-061B-0DDC-58EDBCAEC4A0}" = ASHelper
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B719C82F-A3AC-ED37-3E2A-947E5A7BA214}" = CCC Help Hungarian
"{B75726EF-847A-6965-0CBF-234BE30604D3}" = Fast Traffic Magnet
"{B92F4DE0-CAFE-404F-B907-19D872CFFD5C}" = Commission Streamer
"{BB1C717E-376C-4AA1-8940-81BFC38D9778}" = HP Quick Launch
"{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}" = Energy Star Digital Logo
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C5AC39F1-001D-4338-84C6-35109525588A}" = TweetDeck
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C792A75A-2A1F-4991-9B85-291745478A79}" = NetAssistant
"{C7AAB32A-AA73-ECFD-4F43-F41CFA2CD540}" = ccc-core-static
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFEAD106-F7EB-46B9-8E38-7C86C91F610E}" = CommissionMultiplier
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"{D1612A3D-0DCC-4055-BB6A-0036F31158A0}" = Setup
"{D1AEB5DB-04FA-489D-94EF-8600898B93EE}" = ICA
"{D1F80EFD-A032-4E8E-A367-70C44AD4DCE0}" = ISCOM
"{D3538C4C-8DAF-88CD-55B0-CBF12DECF5A6}" = CCC Help Spanish
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D445BE82-2ADA-423D-9CB5-DDFC48E5F6A9}" = Tableau Public 6.1
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D57588F6-2D35-42B5-5C96-4FC3EB3EF7CE}" = CCC Help Russian
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver
"{DA4BF4BE-3CDC-43B5-BBDA-DDDA73103111}" = Corel PaintShop Photo Pro X3
"{DBE31207-21B1-5688-450E-9B958643FD2C}" = CCC Help Norwegian
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DCD941B6-F2E7-4FAF-B102-F7D4DE5FF99A}" = IPM_PSP_Pro
"{DCF1928A-FC01-48E7-A7E6-4651D42EF6A1}" = PSPPRO_DCRAW
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE311B9A-4C1D-C746-264E-DB2A5C6DD2ED}" = CCC Help French
"{DF8B9311-ADE7-4EDE-B121-326CAA3D225D}" = PSPPContent
"{DFC63A26-1EF4-A666-BE94-1DF7351DA7BE}" = CCC Help Dutch
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EECD8A88-0030-48F1-9898-882EC02D0353}" = Pin Point Pro 1.0
"{F069C491-69E6-4D9B-9A0C-B7894A1FA97C}" = Setup
"{F072CA07-A781-45E4-9975-C033A73019CF}" = ICA
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F206FEC3-F5DD-43FD-A8CF-9C46B8A6A92C}" = VSPro
"{F4E9851F-765E-40B7-9859-237C2724E62C}" = DeviceIO
"{F6A76E9C-C299-4CFA-AD2A-57FE9DD68B70}" = Contents
"{F8423392-2296-4748-9B66-344432459632}" = PureHD
"{F909BD3C-8684-4ACF-B7C3-33F4F9F901B7}" = Share
"{F95C8C1F-25BB-44EC-A7E6-5C17ABC6BC71}" = VIO
"{FB0B6DDD-DF3E-4CD6-927C-724AB854E322}" = VSClassic
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"{FBBCD35F-930F-9B68-7A80-A668A68FE86A}" = CCC Help German
"{FD67D9F3-FED6-4A2E-9D6C-8C8C44DEF8FF}" = IPM_VS_Pro
"{FD9C31B6-F572-414D-81E3-89368C97A125}_is1" = CamStudio OSS Desktop Recorder
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE661711-E392-4B3F-A4A7-02C747C09134}" = ISCOM
"7-Zip" = 7-Zip 9.20
"AA-BestAffiliatePrograms_is1" = Best Affiliate Programs v2.6
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Affiliate ID Manager Master Rebrander_is1" = Affiliate ID Manager Master Rebrander - Version No.1
"Allmyapps" = Allmyapps
"ashelper.ASHelper.46130C60F2252FA5A4446077F84AA968F38F8488.1" = ASHelper
"Atlantis Quest" = Atlantis Quest (remove only)
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
"Audacity_is1" = Audacity 2.0
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe
"BrotherSoft_Extreme Toolbar" = BrotherSoft Extreme Toolbar
"CamStudio" = CamStudio
"CoffeeCup HTML Editor" = CoffeeCup HTML Editor
"com.fastcashcommissions.fasttrafficmagnet" = Fast Traffic Magnet
"com.fastcashcommissions.fasttrafficsniper" = Fast Traffic Sniper
"com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1" = Times Reader
"Commission Activator 1.00" = Commission Activator 1.00
"conduitEngine" = Conduit Engine
"Content Magnet Article Extractor_is1" = Content Magnet Article Extractor 1.0
"CoverFactory 2.50_is1" = CoverFactory 2.50
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"ExpressZip" = Express Zip File Compression Software
"Fences" = Fences
"Fences Pro" = Fences Pro
"FileZilla Client" = FileZilla Client 3.5.3
"Free Screen Video Recorder_is1" = Free Screen Video Recorder version 2.5.22.508
"Free-Web-Buttons.com" = Free-Web-Buttons.com
"GREENSAMBA32-bit Windows executable" = GreenSamba
"HP Photo Creations" = HP Photo Creations
"IncomeGenesis" = Income Genesis
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"IObit Malware Fighter_is1" = IObit Malware Fighter
"IrfanView" = IrfanView (remove only)
"Jewel Quest Mysteries: Curse of the Emerald Tear" = Jewel Quest Mysteries: Curse of the Emerald Tear (remove only)
"Jewel Quest: Heritage" = Jewel Quest: Heritage (remove only)
"John Evans Banner Creator_is1" = John Evans Banner Creator v2.01
"Keyword Pad_is1" = Keyword Pad v1.0.112706
"LADSPA_plugins-win_is1" = LADSPA_plugins-win-0.4.15
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"LibreOffice" = LibreOffice 3.4
"MAGIX_MSI_Xara3D7" = Xara 3D Maker 7
"MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1" = Market Samurai
"Mozilla Firefox 14.0 (x86 en-US)" = Mozilla Firefox 14.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"My HP Game Console" = HP Game Console
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"PhotoStage" = PhotoStage Slideshow Producer
"Popup Free" = Popup Free (remove only)
"PPT To Flash Catalog Professional_is1" = PPT To Flash Catalog Professional
"SkyCaddieDesktop" = SkyCaddie Desktop
"Software Informer_is1" = Software Informer 1.1
"Solitaire Master 3" = Solitaire Master 3
"The Weather Channel App" = The Weather Channel App
"The Weather Channel Desktop 6" = The Weather Channel Desktop 6
"TheDeanReportCloaker_is1" = TheDeanReportCloaker
"Traffic Travis 4.1 Setup Wizard_is1" = Traffic Travis 4.1.0
"TrafficInitiator-Air" = Traffic Launch Pad
"Video_0" = Video Squeeze Page Generator 1.1
"Wajam" = Wajam
"WebFormDesigner" = WebFormDesigner
"WildTangent hp Master Uninstall" = HP Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
"Wisdom-soft Set up ScreenHunter 5.1 Pro" = Wisdom-soft Set up ScreenHunter 5.1 Pro
"Wizard Land" = Wizard Land (remove only)
"WT087328" = Blackhawk Striker 2
"WT087330" = Bounce Symphony
"WT087335" = Build-a-lot 2
"WT087343" = Dora's World Adventure
"WT087360" = Escape Rosecliff Island
"WT087361" = FATE
"WT087362" = Final Drive Nitro
"WT087372" = Heroes of Hellas 2 - Olympia
"WT087379" = Jewel Quest Solitaire 2
"WT087394" = Penguins!
"WT087395" = Poker Superstars III
"WT087396" = Polar Bowler
"WT087397" = Polar Golfer
"WT087414" = Virtual Families
"WT087415" = Wheel of Fortune 2
"WT087428" = Bejeweled 2 Deluxe
"WT087453" = Chuzzle Deluxe
"WT087501" = Plants vs. Zombies
"WT087533" = Zuma Deluxe
"WT087536" = Diner Dash 2 Restaurant Rescue
"WT089299" = Mystery P.I. - The London Caper
"WT089307" = Virtual Villagers 4 - The Tree of Life
"WT089308" = Blasterball 3
"WT089328" = Farm Frenzy
"WT089359" = Cake Mania
"WT089362" = Agatha Christie - Peril at End House
"XHeader" = XHeader
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update
"ZumoDrive" = HP CloudDrive
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"43D873A11E3E6E1C1E31A5977B81928A57E00AD6" = eBay Excel Add-in
"Funmoods Web Search" = Funmoods Web Search
"Google Chrome" = Google Chrome
"HuluDesktop" = Hulu Desktop
"NetAssistant 3.8.3" = Freeze.com NetAssistant
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 4/18/2012 8:41:02 AM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/18/2012 7:26:58 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/20/2012 11:09:43 AM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/21/2012 5:53:03 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/22/2012 11:57:47 AM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/22/2012 5:54:46 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/22/2012 6:46:26 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/23/2012 1:53:46 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
Error - 4/23/2012 8:03:55 PM | Computer Name = BradC-BradC-HP | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "c:\program files\microsoft
security client\MSESysprep.dll".Error in manifest or policy file "c:\program files\microsoft
security client\MSESysprep.dll" on line 10. The element imaging appears as a child
of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by
this version of Windows.
Error - 4/24/2012 11:34:41 AM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =
[ Hewlett-Packard Events ]
Error - 6/10/2011 9:52:26 AM | Computer Name = BradC-BradC-HP | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\061110085217.xml
File not created by asset agent
Error - 9/23/2011 9:48:58 AM | Computer Name = BradC-BradC-HP | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\091123084855.xml
File not created by asset agent
Error - 1/7/2012 12:11:39 AM | Computer Name = BradC-BradC-HP | Source = HPSFMsgr.exe | ID = 4000
Description = HP Error ID: -2147221164 at System.RuntimeTypeHandle.CreateInstance(RuntimeType
type, Boolean publicOnly, Boolean noCheck, Boolean& canBeCached, RuntimeMethodHandle&
ctor, Boolean& bNeedSecurityCheck) at System.RuntimeType.CreateInstanceSlow(Boolean
publicOnly, Boolean fillCache) at System.RuntimeType.CreateInstanceImpl(Boolean
publicOnly, Boolean skipVisibilityChecks, Boolean fillCache) at System.Activator.CreateInstance(Type
type, Boolean nonPublic) at HPSA_Messenger.MessengerCom.TrayDeskBand.isTaskbarDisplayed()
StackTrace:
at System.RuntimeTypeHandle.CreateInstance(RuntimeType type, Boolean publicOnly,
Boolean noCheck, Boolean& canBeCached, RuntimeMethodHandle& ctor, Boolean& bNeedSecurityCheck)
at System.RuntimeType.CreateInstanceSlow(Boolean publicOnly, Boolean fillCache)
at System.RuntimeType.CreateInstanceImpl(Boolean publicOnly, Boolean skipVisibilityChecks,
Boolean fillCache) at System.Activator.CreateInstance(Type type, Boolean nonPublic)
at HPSA_Messenger.MessengerCom.TrayDeskBand.isTaskbarDisplayed() Source: mscorlib
Name:
HPSFMsgr.exe Version: 01.00.00.00 Path: C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe Format: en-US RAM: 3893 Ram
Utilization: 30 TargetSite: System.Object CreateInstance(System.RuntimeType, Boolean,
Boolean, Boolean ByRef, System.RuntimeMethodHandle ByRef, Boolean ByRef)
Error - 3/30/2012 8:11:44 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =
Error - 3/30/2012 8:11:44 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =
Error - 3/30/2012 8:12:03 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =
Error - 3/30/2012 8:12:03 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =
Error - 3/31/2012 9:41:34 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =
Error - 4/14/2012 1:21:10 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =
Error - 6/13/2012 6:38:07 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description = HP Error ID: -2146233087 Server stack trace: at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs, TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs) at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessag
e
methodCall, ProxyOperationRuntime operation) at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage
message) Exception rethrown at [0] Message: The server did not provide a meaningful
reply; this might be caused by a contract mismatch, a premature session shutdown
or an internal server error. StackTrace: Server stack trace: at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs, TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs) at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessag
e
methodCall, ProxyOperationRuntime operation) at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage
message) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at HP.SupportFramework.Communicator.MessengerComm.IMessengerCommunicator.UpdateTime
r()
at HP.SupportAssistant.UI.MessengerCommunication.sendTimerUpdate() Source: mscorlib
Name:
HPSF.exe Version: 06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support
Framework\HPSF.exe Format: en-US RAM: 3893 Ram Utilization: 50 TargetSite: Void HandleReturnMessage(System.Runtime.Remoting.Messaging.IMessage,
System.Runtime.Remoting.Messaging.IMessage)
[ HP Wireless Assistant Events ]
Error - 4/16/2011 12:01:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:02:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:03:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:04:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:05:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:06:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:07:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:08:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:09:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 4/16/2011 12:10:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
[ System Events ]
Error - 7/4/2012 5:15:50 PM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7023
Description = The Microsoft Antimalware Service service terminated with the following
error: %%-2147017840
Error - 7/4/2012 9:03:13 PM | Computer Name = BradC-BradC-HP | Source = Microsoft Antimalware | ID = 5101
Description = %%860 grace period has expired. Protection against viruses, spyware,
and other potentially unwanted software is disabled. Expiration Reason: %%873 Expiration
Date (UTC): ?7/?5/?2012 1:03:13 AM Error Code: 0x80092003 Error Description: An error
occurred while reading or writing to a file.
Error - 7/4/2012 9:03:24 PM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7000
Description = The My Web Search Service service failed to start due to the following
error: %%2
Error - 7/4/2012 9:04:03 PM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7023
Description = The Microsoft Antimalware Service service terminated with the following
error: %%-2147017840
Error - 7/5/2012 10:40:17 AM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7000
Description = The My Web Search Service service failed to start due to the following
error: %%2
Error - 7/5/2012 10:40:20 AM | Computer Name = BradC-BradC-HP | Source = Microsoft Antimalware | ID = 5101
Description = %%860 grace period has expired. Protection against viruses, spyware,
and other potentially unwanted software is disabled. Expiration Reason: %%873 Expiration
Date (UTC): ?7/?5/?2012 2:40:20 PM Error Code: 0x80092003 Error Description: An error
occurred while reading or writing to a file.
Error - 7/5/2012 10:40:58 AM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7023
Description = The Microsoft Antimalware Service service terminated with the following
error: %%-2147017840
Error - 7/6/2012 10:48:58 AM | Computer Name = BradC-BradC-HP | Source = Microsoft Antimalware | ID = 5101
Description = %%860 grace period has expired. Protection against viruses, spyware,
and other potentially unwanted software is disabled. Expiration Reason: %%873 Expiration
Date (UTC): ?7/?6/?2012 2:48:58 PM Error Code: 0x80092003 Error Description: An error
occurred while reading or writing to a file.
Error - 7/6/2012 10:48:58 AM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7000
Description = The My Web Search Service service failed to start due to the following
error: %%2
Error - 7/6/2012 10:49:33 AM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7023
Description = The Microsoft Antimalware Service service terminated with the following
error: %%-2147017840
< End of report >