This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

MyStart Incredibar Virus

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello, I'm Brad, new registered member,

my laptop has been infected with the mystart incredibar virus.

I have followed your instructions and downloaded the program to help with removal of the mystart virus. I have both reports on notepad, one is copied. where do I post it?


OTL logfile created on: 7/6/2012 3:01:29 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Brad C\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 1.06 Gb Available Physical Memory | 27.91% Memory free
7.60 Gb Paging File | 4.41 Gb Available in Paging File | 58.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 668.10 Gb Total Space | 591.32 Gb Free Space | 88.51% Space Free | Partition Type: NTFS
Drive D: | 30.24 Gb Total Space | 4.44 Gb Free Space | 14.69% Space Free | Partition Type: NTFS
Drive F: | 98.87 Mb Total Space | 83.72 Mb Free Space | 84.68% Space Free | Partition Type: FAT32

Computer Name: BRADC-BRADC-HP | User Name: Brad C | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Brad C\Downloads\OTL(1).exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
PRC - C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe ()
PRC - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)
PRC - C:\Program Files\Web Assistant\ExtensionUpdaterService.exe ()
PRC - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.exe (OpenOffice.org)
PRC - C:\Program Files (x86)\OpenOffice.org 3\program\soffice.bin (OpenOffice.org)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Software Informer\softinfo.exe (Informer Technologies, Inc.)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\iWin Games\iWinTrusted.exe (iWin Inc.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\zumodrive.exe (Zecter Inc.)
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
PRC - C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
PRC - C:\Program Files (x86)\Hewlett-Packard\Media\Webcam\YCMMirage.exe (CyberLink)
PRC - C:\ProgramData\ClickfreeC02\UACProxy.exe (Storage Appliance Corp.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
PRC - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE ()
PRC - C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Modules (No Company Name) ==========

MOD - C:\Users\Brad C\AppData\Local\Temp\libsqlitejdbc-8626483191519883319.lib ()
MOD - C:\Users\Brad C\AppData\Local\Temp\WindowsAPI.dll2891894938722718749.lib ()
MOD - C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\SiteSafety.dll ()
MOD - C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxml2.dll ()
MOD - C:\Program Files (x86)\OpenOffice.org 3\program\libxslt.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\Virtualization Handler\OFFICEVIRT.EXE ()


========== Win32 Services (SafeList) ==========

SRV:64bit: - (Web Assistant Updater) – C:\Program Files\Web Assistant\ExtensionUpdaterService.exe ()
SRV:64bit: - (NisSrv) – c:\Program Files\Microsoft Security Client\Antimalware\NisSrv.exe (Microsoft Corporation)
SRV:64bit: - (MsMpSvc) – c:\Program Files\Microsoft Security Client\Antimalware\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona, Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (HPClientSvc) – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe (Hewlett-Packard Company)
SRV:64bit: - (HPAuto) – C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe (Hewlett-Packard)
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (HP Wireless Assistant Service) – C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWA_Service.exe (Hewlett-Packard Company)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors, Inc.)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (Application Updater) – C:\Program Files (x86)\Application Updater\ApplicationUpdater.exe (Spigot, Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (vToolbarUpdater11.1.0) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\11.1.0\ToolbarUpdater.exe ()
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (WajamUpdater) – C:\Program Files (x86)\Wajam\Updater\WajamUpdater.exe (Wajam)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (IMFservice) – C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Flexera Software, Inc.)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (HPDrvMntSvc.exe) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe (Hewlett-Packard Company)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (iWinTrusted) – C:\Program Files (x86)\iWin Games\iWinTrusted.exe (iWin Inc.)
SRV - (CLKMSVC10_C6F09094) – C:\Program Files (x86)\Hewlett-Packard\Media\DVD\Kernel\HDDVD\NavFilter\kmsvc.exe (CyberLink)
SRV - (RoxioNow Service) – C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe (Roxio)
SRV - (CFUACProxy_clickfreec02) – C:\ProgramData\ClickfreeC02\UACProxy.exe (Storage Appliance Corp.)
SRV - (GameConsoleService) – C:\Program Files (x86)\HP Games\HP Game Console\GameConsoleService.exe (WildTangent, Inc.)
SRV - (UNS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (PSI_SVC_2) – c:\Program Files (x86)\Common Files\Protexis\License Service\PsiService_2.exe (Protexis Inc.)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (YahooAUService) – C:\Program Files (x86)\Yahoo!\SoftwareUpdate\YahooAUService.exe (Yahoo! Inc.)


========== Driver Services (SafeList) ==========

DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (NisDrv) – C:\Windows\SysNative\drivers\NisDrvWFP.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\drivers\BCMWL664.SYS (Broadcom Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (clwvd) – C:\Windows\SysNative\drivers\clwvd.sys (CyberLink Corporation)
DRV:64bit: - (intelkmd) – C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (HECIx64) Intel® – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (SkyhawkeUSBLan) – C:\Windows\SysNative\drivers\btblan.sys (Belcarra Technologies)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) Intel® – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV - (UrlFilter) – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\UrlFilter.sys (IObit.com)
DRV - (RegFilter) – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\RegFilter.sys (IObit.com)
DRV - (FileMonitor) – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys (IObit)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a;=iron2…p;cr=1561730916
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1561730916
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}: "URL" = http://rover.ebay.com/rover/1/711-111092-2…p;mfe=Notebooks
IE:64bit: - HKLM\..\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.sweetim.com/?crg=3.1010000.100…D-ED18B0B41582}
IE - HKLM\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
IE - HKLM\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1561730916
IE - HKLM\..\SearchScopes\{7624FE00-BB7A-93D1-4029-31A105F7D5E8}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.conduit.com/ResultsExt.aspx?…;ctid=CT2776682
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKLM\..\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}: "URL" = http://rover.ebay.com/rover/1/711-111092-2…p;mfe=Notebooks
IE - HKLM\..\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6…D-ED18B0B41582}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://isearch.avg.com/?cid={1D722B3C-363F…mp;d=2012-03-13 20:31:04&v;=11.0.0.9&sap;=hp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.com/?fr=fp-yie9
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.avg.com/?cid={1D722B3C-363F…mp;d=2012-03-13 20:31:04&v;=11.1.0.7&sap;=hp
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.yahoo.com/
IE - HKCU\..\URLSearchHook: {00A6FAF6-072E-44cf-8957-5838F569A31D} - No CLSID value found
IE - HKCU\..\URLSearchHook: {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\6.0\iobitToolbarIE.dll (Spigot, Inc.)
IE - HKCU\..\URLSearchHook: {50fafaf0-70a9-419d-a109-fa4b4ffd4e37} - No CLSID value found
IE - HKCU\..\URLSearchHook: {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\6.0\pdfforgeToolbarIE.dll (Spigot, Inc.)
IE - HKCU\..\URLSearchHook: {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files (x86)\Freeze.com\NetAssistant\NetAssistant.dll (W3i, LLC)
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes,DefaultScope = {95B7759C-8C7F-4BF1-B163-73684A933233}
IE - HKCU\..\SearchScopes\{12DC6175-B360-2C25-BF0E-2B6E49ADC9F3}: "URL" = http://www.bing.com/search?q={searchTerms}…eferrer:source}
IE - HKCU\..\SearchScopes\{2C71AFC4-9C4C-4E8C-9618-38EADA8DEF02}: "URL" = http://www.flickr.com/search/?q={searchTerms}
IE - HKCU\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKCU\..\SearchScopes\{66C011AB-F98E-4337-B30D-C800D299CE92}: "URL" = http://delicious.com/search?p={searchTerms}
IE - HKCU\..\SearchScopes\{67AFED21-EE04-4081-941E-3CB3CAD8C28E}: "URL" = http://search.yahoo.com/search?fr=chr-gree…p={searchTerms}
IE - HKCU\..\SearchScopes\{7624FE00-BB7A-93D1-4029-31A105F7D5E8}: "URL" = http://isearch.avg.com/search?cid={1D722B3…mp;d=2012-03-13 20:31:04&v;=10.0.0.7&sap;=dsp&q;={searchTerms}
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1561730916
IE - HKCU\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}: "URL" = http://dts.search-results.com/sr?src=ieb&a;…q={searchTerms}
IE - HKCU\..\SearchScopes\{9BDECC3C-C77D-4CFE-9448-B1BED69F6ADD}: "URL" = http://search.yahoo.com/search?fr=chr-gree…p={searchTerms}
IE - HKCU\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKCU\..\SearchScopes\{B8822D2B-48D0-421E-93B7-432835894155}: "URL" = http://www.google.com/search?q={searchTerm…1I7GGHP_enUS466
IE - HKCU\..\SearchScopes\{CFF4DB9B-135F-47c0-9269-B4C6572FD61A}: "URL" = http://mystart.incredibar.com/mb143/?searc…buqG4D&i;=26
IE - HKCU\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKCU\..\SearchScopes\{d944bb61-2e34-4dbf-a683-47e505c587dc}: "URL" = http://rover.ebay.com/rover/1/711-111092-2…p;mfe=Notebooks
IE - HKCU\..\SearchScopes\{ec29edf6-ad3c-4e1c-a087-d6cb81400c43}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://search.sweetim.com/search.asp?src=6…D-ED18B0B41582}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_3_300_262.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2012/05/24 09:09:17 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_3_300_262.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\11.1.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/VirtualEarth3D,version=4.0: C:\Program Files (x86)\Virtual Earth 3D\ [2012/05/24 09:09:17 | 000,000,000 | —D | M]
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@mywebsearch.com/Plugin: C:\Program Files (x86)\MyWebSearch\bar\1.bin\NPMyWebS.dll (MyWebSearch.com)
FF - HKLM\Software\MozillaPlugins\@photoproduct.rocketlife.com/RocketLife App Viewer;version=0.8: File not found
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@hulu.com/Hulu Desktop: C:\Users\Brad C\AppData\Local\HuluDesktop\instances\0.9.14.1\nphdplg.dll (Hulu LLC)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Brad C\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll File not found
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Brad C\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Brad C\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

64bit-FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\PROGRAM FILES\WEB ASSISTANT\FIREFOX [2012/05/02 13:00:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\DigitalPersona\Bin\FirefoxExt\ [2010/10/25 04:11:42 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{98e34367-8df7-42b4-837b-20b892ff0849}: C:\ProgramData\iWin Games\firefox [2011/09/04 17:28:34 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\11.1.0.7\ [2012/06/12 11:11:02 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{1E73965B-8B48-48be-9C8D-68B920ABC1C4}: C:\Program Files (x86)\AVG\AVG2012\Firefox4\ [2012/05/29 10:07:01 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{336D0C35-8A85-403a-B9D2-65C292C39087}: C:\Program Files\Web Assistant\Firefox [2012/05/02 13:00:00 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/05/24 09:05:32 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\MyWebSearch\bar\1.bin [2012/07/06 10:06:16 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/01 21:22:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 14.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/23 10:01:36 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/01 21:22:50 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 14.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/05/23 10:01:36 | 000,000,000 | —D | M]

[2012/01/06 22:54:41 | 000,000,000 | —D | M] (No name found) – C:\Users\Brad C\AppData\Roaming\Mozilla\Extensions
[2011/05/06 10:03:58 | 000,000,000 | —D | M] (No name found) – C:\Users\Brad C\AppData\Roaming\Mozilla\Extensions\{3550f703-e582-4d05-9a08-453d09bdfdc6}
[2012/07/06 15:02:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions
[2012/06/14 15:43:29 | 000,000,000 | —D | M] (Yahoo! Toolbar) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\{635abd67-4fe9-1b23-4f01-e679fa7484c1}
[2012/06/13 20:11:55 | 000,000,000 | —D | M] (DVDVideoSoftTB) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\{872b5b88-9db5-4310-bdd0-ac189557e5f5}
[2012/06/06 15:03:59 | 000,000,000 | —D | M] (DownloadHelper) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\{b9db16a4-6edc-47ec-a1f4-b86292ed211d}
[2012/05/24 09:09:35 | 000,000,000 | —D | M] (Page Speed) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\{e3f6c2cc-d8db-498c-af6c-499fb211db97}
[2012/06/19 06:35:03 | 000,000,000 | —D | M] (My Web Search) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\[removed]
[2012/06/18 09:26:07 | 000,000,000 | —D | M] (WebRank Toolbar) – C:\Users\Brad C\AppData\Roaming\Mozilla\Firefox\Profiles\so4u9ll7.default\extensions\[removed]
[2011/10/08 18:28:06 | 000,000,000 | —D | M] (No name found) – C:\Users\Brad C\AppData\Roaming\Mozilla\SeaMonkey\Profiles\t9umotw0.default\extensions
[2012/06/11 14:48:57 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/06/11 14:48:57 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2012/07/01 21:22:50 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\distribution\extensions
[2012/07/01 21:22:50 | 000,136,672 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/06/12 11:10:58 | 000,003,766 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/05/16 17:08:48 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2010/01/01 03:00:00 | 000,002,252 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml.old
[2011/11/26 16:02:58 | 000,002,519 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\Search_Results.xml
[2012/05/16 17:08:48 | 000,002,040 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Yahoo! (Enabled)
CHR - default_search_provider: search_url = http://search.yahoo.com/search?ei={inputEn…p={searchTerms}
CHR - default_search_provider: suggest_url = http://ff.search.yahoo.com/gossip?output=f…d={searchTerms}
CHR - Extension: WinZipBar = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgpnojibjokpoghebklhkdeijehkohhb\2.3.4.2_0\
CHR - Extension: FunDial = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\1.0.1_0\
CHR - Extension: Web Assistant = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.430_0\
CHR - Extension: Funmoods = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\1.5.1_0\
CHR - Extension: SweetIM for Facebook = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
CHR - Extension: SweetIM for Facebook = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\
CHR - Extension: AVG Safe Search = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\
CHR - Extension: Wajam = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\
CHR - Extension: Skype Click to Call = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.0.0.10201_0\
CHR - Extension: AVG Do Not Track = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: DVDVideoSoftTB = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\plmlpkfpkijnlijgalnjaacllnjmoamo\10.11.5.4_0\
CHR - Extension: WinZipBar = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\cgpnojibjokpoghebklhkdeijehkohhb\2.3.4.2_0\
CHR - Extension: FunDial = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\1.0.1_0\
CHR - Extension: Web Assistant = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.430_0\
CHR - Extension: Funmoods = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdloijijlkoblmigdofommgnheckmaki\1.5.1_0\
CHR - Extension: SweetIM for Facebook = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\Copy of
CHR - Extension: SweetIM for Facebook = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jcdgjdiieiljkfkdcloehkohchhpekkn\1.0.0.0_0\
CHR - Extension: AVG Safe Search = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\12.0.0.2161_0\
CHR - Extension: Wajam = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpmbfleldcgkldadpdinhjjopdfpjfjp\1.24_0\
CHR - Extension: Skype Click to Call = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.0.0.10201_0\
CHR - Extension: AVG Do Not Track = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\ndibdjnfmopecpmkdieinmbadjfpblof\12.0.0.2166_0\
CHR - Extension: DVDVideoSoftTB = C:\Users\Brad C\AppData\Local\Google\Chrome\User Data\Default\Extensions\plmlpkfpkijnlijgalnjaacllnjmoamo\10.11.5.4_0\

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension64.dll ()
O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssiea.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O2 - BHO: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\6.0\iobitToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (ViewSource Class) - {2EF37A01-884F-11d5-AC99-B112050ECB4F} - C:\Program Files (x86)\Popup Free\HTMLEdit.dll (InfoWorks Technology Company)
O2 - BHO: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Web Assistant) - {336D0C35-8A85-403a-B9D2-65C292C39087} - C:\Program Files\Web Assistant\Extension32.dll ()
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG2012\avgssie.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (BrotherSoft Extreme Toolbar) - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
O2 - BHO: (Funmoods Helper Object) - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\PROGRA~2\Funmoods\1.5.23.22\bh\escort.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll File not found
O2 - BHO: (Wajam) - {A7A6995D-6EE1-4FD1-A258-49395D5BF99C} - C:\Program Files (x86)\Wajam\IE\priam_bho.dll (Wajam)
O2 - BHO: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\6.0\pdfforgeToolbarIE.dll (Spigot, Inc.)
O2 - BHO: (NetAssistant) - {E38FA08E-F56A-4169-ABF5-5C71E3C153A1} - C:\Program Files (x86)\Freeze.com\NetAssistant\NetAssistant.dll (W3i, LLC)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn0\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (no name) - !{41B62AD3-5D43-40D1-9D43-F3539C1DB452} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - !{95B7759C-8C7F-4BF1-B163-73684A933233} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - !{B922D405-6D13-4A2B-AE89-08A030DA4402} - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (IObit Toolbar) - {0BDA0769-FD72-49F4-9266-E1FB004F4D8F} - C:\Program Files (x86)\IObit Toolbar\IE\6.0\iobitToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Conduit Engine) - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files (x86)\ConduitEngine\prxConduitEngine.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (BrotherSoft Extreme Toolbar) - {51a86bb3-6602-4c85-92a5-130ee4864f13} - C:\Program Files (x86)\BrotherSoft_Extreme\prxtbBrot.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (DVDVideoSoftTB Toolbar) - {872b5b88-9db5-4310-bdd0-ac189557e5f5} - C:\Program Files (x86)\DVDVideoSoftTB\prxtbDVDV.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\11.1.0.7\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Searchqu Toolbar) - {99079a25-328f-4bd4-be04-00955acaa0a7} - C:\PROGRA~2\WI3C8A~1\Datamngr\ToolBar\searchqudtx.dll File not found
O3 - HKLM\..\Toolbar: (Funmoods Toolbar) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\PROGRA~2\Funmoods\1.5.23.22\escorTlbr.dll File not found
O3 - HKLM\..\Toolbar: (pdfforge Toolbar) - {B922D405-6D13-4A2B-AE89-08A030DA4402} - C:\Program Files (x86)\pdfforge Toolbar\IE\6.0\pdfforgeToolbarIE.dll (Spigot, Inc.)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn1\yt.dll (Yahoo! Inc.)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [SmartMenu] C:\Program Files\Hewlett-Packard\HP MediaSmart\SmartMenu.exe ()
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [Corel File Shell Monitor] c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\CorelIOMonitor.exe File not found
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKLM..\Run: [MyWebSearch Email Plugin] C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found
O4 - HKLM..\Run: [ROC_roc_dec12] "C:\Program Files (x86)\AVG Secure Search\ROC_roc_dec12.exe" /PROMPT /CMPID=roc_dec12 File not found
O4 - HKLM..\Run: [SearchSettings] C:\Program Files (x86)\Common Files\Spigot\Search Settings\SearchSettings.exe (Spigot, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe (SweetIM Technologies Ltd.)
O4 - HKLM..\Run: [vProt] C:\Program Files (x86)\AVG Secure Search\vprot.exe ()
O4 - HKLM..\Run: [ZumoDrive] C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk ()
O4 - HKCU..\Run: [Allmyapps] C:\Program Files (x86)\Allmyapps\AllmyappsNotifier.exe (Allmyapps)
O4 - HKCU..\Run: [Facebook Update] C:\Users\Brad C\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKCU..\Run: [MyWebSearch Email Plugin] C:\PROGRA~2\MYWEBS~1\bar\1.bin\mwsoemon.exe File not found
O4 - HKCU..\Run: [Software Informer] C:\Program Files (x86)\Software Informer\softinfo.exe (Informer Technologies, Inc.)
O4 - HKCU..\Run: [ZumoDrive] C:\Program Files (x86)\Hewlett-Packard\HP CloudDrive\ZumoLauncher.lnk ()
O4 - Startup: C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk = C:\Program Files (x86)\OpenOffice.org 3\program\quickstart.exe ()
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 255
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_21)
O16:64bit: - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_31)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 10.0.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2040B8F1-89EE-40CF-BFB8-C5213E9F4DF7}: DhcpNameServer = 10.0.0.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\11.1.0\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe) - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O22:64bit: - SharedTaskScheduler: {1984DD45-52CF-49cd-AB77-18F378FEA264} - FencesShellExt - C:\Program Files (x86)\Stardock\Fences\FencesMenu64.dll (Stardock)
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{e08af094-1548-11e1-8b3f-f568c47f51ae}\Shell - "" = AutoRun
O33 - MountPoints2\{e08af094-1548-11e1-8b3f-f568c47f51ae}\Shell\AutoRun\command - "" = G:\StartClickFreeBackup.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (C:\PROGRA~2\AVG\AVG2012\avgrsa.exe /sync /restart)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.tscc - C:\Windows\SysWOW64\tsccvid64.dll (TechSmith Corporation)
Drivers32: msacm.dvacm - c:\Program Files (x86)\Common Files\Ulead Systems\VIO\DVACM.acm (Corel TW Corp.)
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.tscc - C:\Windows\SysWow64\tsccvid.dll (TechSmith Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/07/06 14:12:45 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\James_Jordan-IM_Business_In_A_Box
[2012/07/06 11:54:14 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{90895736-A8E0-42D9-86DD-C65D217907DB}
[2012/07/06 11:54:03 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{1373FBAA-F462-4A3F-90DD-29BB80AB97FE}
[2012/07/05 10:16:59 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{E2A0B748-F5EC-4217-935F-A2ABBD3986C2}
[2012/07/05 10:16:48 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{928EFE15-82C8-4378-9AD9-9A0C2818CAEC}
[2012/07/05 10:13:43 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{7B2F270B-0974-4B9C-AC31-CEFF2A84BA5D}
[2012/07/04 11:48:48 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit Toolbar
[2012/07/04 11:48:27 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
[2012/07/04 11:48:22 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\IObit
[2012/07/04 11:48:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\IObit
[2012/07/04 11:47:11 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\IObitMalwareFighterPRO
[2012/07/04 04:58:11 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{06DB8F0B-1441-46E9-A225-004BA3AF432D}
[2012/07/04 04:58:00 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{B9956608-0B07-433A-9985-14F4F4814F8A}
[2012/07/03 14:09:56 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Corel Auto-Preserve
[2012/07/03 11:52:42 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{D7C6B135-E1F2-4EE9-8EF2-C43F0C443A3F}
[2012/07/03 11:52:31 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{0B0DD05E-62A9-48B4-8FE2-E91EB6E8E249}
[2012/07/03 10:01:14 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\CPS images
[2012/07/03 09:50:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Spigot
[2012/07/03 09:50:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\pdfforge Toolbar
[2012/07/03 09:50:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\Application Updater
[2012/07/02 08:35:16 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{325F898A-A958-4492-AE41-C80BC195A431}
[2012/07/02 08:35:05 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{2BC30E3A-BD64-488B-AA0B-811FE094234D}
[2012/07/01 12:24:45 | 004,472,121 | —- | C] (CamStudio Open Source Dev Team ) – C:\Users\Brad C\Downloads\Documents\CamStudio_Setup_v2.6b_r294_(build_24Oct2010).exe
[2012/07/01 09:04:58 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{F9C03163-84BC-40A1-ACB2-9C57880B416D}
[2012/07/01 09:04:46 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{0498AD14-7FB3-4AD3-81A0-9631A658607B}
[2012/06/30 17:23:15 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\Email Newsletter BC Online
[2012/06/30 10:09:14 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\twitter
[2012/06/30 10:06:26 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\TweetAdder3
[2012/06/30 09:17:08 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{CEF5D77C-EE35-4855-92A8-504864818144}
[2012/06/30 09:16:57 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{79EC122A-5978-49BD-ADAC-30B630549F35}
[2012/06/29 12:40:19 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{AB8D0F03-5A15-4496-A14E-7A3E9FF66986}
[2012/06/29 12:40:07 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{5E02D64E-A25E-4D58-98BD-B7B8BC109282}
[2012/06/28 19:50:38 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{2133ED98-28AF-4F44-BBA4-784AEEE141E7}
[2012/06/28 19:50:27 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{6161CE72-A397-435E-BA5F-D3263ACD67E8}
[2012/06/28 10:39:13 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\BlogThemes_201109
[2012/06/28 09:41:35 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\CreateStunningVideoSlideshowsForFree_PLR
[2012/06/28 06:12:58 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{5D18960A-1A3A-41FB-BE01-599ED4EE0130}
[2012/06/28 06:12:47 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{498CA44B-5914-440A-9039-46EEA2EEDE97}
[2012/06/27 16:26:59 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Content Spin Bot
[2012/06/27 16:26:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\ContentSpinBot
[2012/06/27 11:54:44 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoSqPageGen
[2012/06/27 11:54:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\VideoSqPageGen
[2012/06/27 11:42:21 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\ecovers
[2012/06/26 18:22:05 | 000,000,000 | R–D | C] – C:\Users\Brad C\Downloads\Documents\HP Photo Creations
[2012/06/26 18:22:05 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Visan
[2012/06/26 18:22:00 | 000,000,000 | —D | C] – C:\ProgramData\Visan
[2012/06/26 13:52:03 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{1BF78769-68B8-4779-826C-F0D3747947EE}
[2012/06/26 13:51:52 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{3F8F1BE2-DF2E-42D8-8D0D-4D2C902A48C9}
[2012/06/25 09:20:50 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{639F841D-9862-4AFD-8C0B-EF01D447FEE6}
[2012/06/25 09:20:39 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{350AF1CC-4B5A-40C0-8DD9-2D989A458A2C}
[2012/06/23 12:38:00 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{C16650F3-2D41-44A4-A432-F064B8D4B6F6}
[2012/06/23 12:37:49 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{87811A18-9580-44FA-871C-C23BEC21B040}
[2012/06/22 16:45:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/06/22 16:44:25 | 000,126,312 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\GEARAspi64.dll
[2012/06/22 16:44:25 | 000,107,368 | —- | C] (GEAR Software Inc.) – C:\Windows\SysWow64\GEARAspi.dll
[2012/06/22 16:44:25 | 000,034,152 | —- | C] (GEAR Software Inc.) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2012/06/22 16:44:24 | 000,000,000 | —D | C] – C:\Windows\SysNative\DRVSTORE
[2012/06/22 16:43:50 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/06/22 16:43:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2012/06/22 16:43:50 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/06/22 16:43:50 | 000,000,000 | —D | C] – C:\ProgramData\{93E26451-CD9A-43A5-A2FA-C42392EA4001}
[2012/06/22 16:42:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Apple Software Update
[2012/06/22 16:42:36 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Apple
[2012/06/22 16:42:26 | 000,000,000 | —D | C] – C:\Program Files\Bonjour
[2012/06/22 16:42:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Bonjour
[2012/06/22 16:40:36 | 079,225,752 | —- | C] (Apple Inc.) – C:\Users\Brad C\iTunes64Setup.exe
[2012/06/22 15:53:52 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{3ED52322-4D8F-44EC-92B7-0771E77D8561}
[2012/06/22 15:53:41 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{5F8478C5-829D-4D59-95E6-D3805371A348}
[2012/06/21 12:03:03 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{337BEA95-4AFD-44AE-B751-FF6F202EB9F8}
[2012/06/21 12:02:51 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{7817663F-E0BB-4414-B02C-97D86A813263}
[2012/06/20 09:33:10 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{AC6951B2-192A-4A4B-B875-C44AF8781DEE}
[2012/06/20 09:33:00 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{76703886-F033-4F30-9160-4D2AF770E0E0}
[2012/06/19 13:59:56 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{623F1BF0-C5E4-4D07-B22D-F00BD7587500}
[2012/06/19 13:59:45 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{1031FD43-5931-494F-BB75-DE20F9D261E0}
[2012/06/19 06:29:23 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2012/06/19 06:29:23 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2012/06/19 06:29:23 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups2.dll
[2012/06/19 06:28:58 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2012/06/19 06:28:58 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2012/06/19 06:28:58 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wups.dll
[2012/06/19 06:28:41 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2012/06/19 06:28:41 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2012/06/18 20:12:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\MyWebSearch
[2012/06/18 06:59:05 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{39FF811A-3DDE-4AA4-97EC-A453EEC257D8}
[2012/06/16 20:15:58 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{5E42E006-51D6-4C61-A99D-6DD91894B772}
[2012/06/16 05:39:40 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\SuperSignUpSystem_Minisite
[2012/06/16 05:35:20 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Free_PLR_Products-dkas
[2012/06/16 05:10:39 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\TweetDeck
[2012/06/16 05:10:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Twitter
[2012/06/16 05:03:45 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Business Links
[2012/06/16 05:02:56 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\MindValley
[2012/06/15 08:30:54 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{9E0A3BED-1FF5-4509-AA7C-B551BC2D4752}
[2012/06/14 17:29:28 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\nichebuilder
[2012/06/14 16:21:37 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\nichebuilder
[2012/06/14 15:55:25 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\ListGuerillaTraffic
[2012/06/14 15:53:42 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\Co_Registration_Explained
[2012/06/14 15:53:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Utilities
[2012/06/14 08:43:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Video Related Programs
[2012/06/14 08:43:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\NCH Software Suite
[2012/06/14 08:03:23 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\AVG
[2012/06/14 08:02:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG PC Tuneup 2011
[2012/06/14 06:46:09 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{FA84CF08-8433-42C2-B303-544BA3E593B7}
[2012/06/14 06:45:58 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{CB8E4E87-95F5-43A6-9CB6-76374106D5BA}
[2012/06/13 20:16:35 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/06/13 20:16:34 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/06/13 20:16:34 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/06/13 20:16:34 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/06/13 20:16:33 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/06/13 20:16:33 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/06/13 20:16:32 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/06/13 20:16:32 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/06/13 20:16:31 | 002,311,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/06/13 20:16:31 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/06/13 20:16:31 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/06/13 20:16:31 | 000,716,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/06/13 20:16:30 | 000,818,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/06/13 20:15:41 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\DVDVideoSoft_Ltd
[2012/06/13 20:12:44 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\DVDVideoSoft
[2012/06/13 20:11:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\DVDVideoSoftTB
[2012/06/13 20:11:38 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVDVideoSoft
[2012/06/13 20:11:37 | 002,557,952 | —- | C] (Nokia Corporation and/or its subsidiary(-ies)) – C:\Windows\SysWow64\QtCore4.dll
[2012/06/13 20:11:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\DVDVideoSoft
[2012/06/13 20:11:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DVDVideoSoft
[2012/06/13 20:10:43 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\DVDVideoSoft
[2012/06/13 19:57:48 | 000,149,504 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorekmts.dll
[2012/06/13 19:57:48 | 000,077,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpwsx.dll
[2012/06/13 19:57:48 | 000,009,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdrmemptylst.exe
[2012/06/13 19:57:40 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2012/06/13 19:57:38 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntkrnlpa.exe
[2012/06/13 19:57:38 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntoskrnl.exe
[2012/06/13 19:57:34 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msi.dll
[2012/06/13 19:57:28 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2012/06/13 19:57:27 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2012/06/13 14:06:33 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\LibreOffice
[2012/06/13 14:04:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LibreOffice 3.4
[2012/06/13 14:03:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\LibreOffice 3.4
[2012/06/13 14:02:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Free Offers from Freeze.com
[2012/06/13 14:02:12 | 000,000,000 | -HSD | C] – C:\Windows\SysWow64\AI_RecycleBin
[2012/06/13 14:02:11 | 000,000,000 | —D | C] – C:\ProgramData\W3i
[2012/06/13 14:02:11 | 000,000,000 | —D | C] – C:\Program Files (x86)\W3i
[2012/06/13 14:02:11 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\InstallIQ Updater
[2012/06/13 14:02:05 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NetAssistant
[2012/06/13 14:02:05 | 000,000,000 | —D | C] – C:\Program Files (x86)\Freeze.com
[2012/06/13 13:59:16 | 001,536,192 | —- | C] (W3i, LLC) – C:\Users\Brad C\Desktop\libreoffice.exe
[2012/06/13 13:54:11 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Wajam
[2012/06/13 13:54:07 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\Wajam
[2012/06/13 13:54:06 | 000,000,000 | —D | C] – C:\Program Files (x86)\Wajam
[2012/06/13 13:50:14 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\mobile
[2012/06/13 13:50:13 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\files
[2012/06/13 08:49:42 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Downloads bundled
[2012/06/13 07:19:09 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Kingsoft
[2012/06/13 07:19:09 | 000,000,000 | —D | C] – C:\ProgramData\Kingsoft
[2012/06/13 06:50:14 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\Macromedia
[2012/06/13 06:43:22 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{64F87F3C-E10D-467B-A5D5-1BDECABD5279}
[2012/06/13 06:43:10 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{663998F9-037B-441F-A275-BBD7A907ABE0}
[2012/06/12 16:49:10 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Apple Computer
[2012/06/12 11:11:00 | 000,000,000 | —D | C] – C:\Windows\SysWow64\cache
[2012/06/12 07:13:18 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{DE9F876E-4D46-4206-A3A5-4CBB091E4B40}
[2012/06/12 07:12:31 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{28824F43-59D7-43E1-832E-AAC5C0E9B96B}
[2012/06/11 16:47:23 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Screen Shots
[2012/06/11 16:28:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Tableau
[2012/06/11 15:29:59 | 000,000,000 | —D | C] – C:\Users\Brad C\LimitlessLeadGenerationGuideMRR
[2012/06/11 15:12:00 | 000,000,000 | —D | C] – C:\Users\Brad C\Tracing
[2012/06/11 15:06:52 | 000,000,000 | —D | C] – C:\ProgramData\SweetIM
[2012/06/11 15:06:52 | 000,000,000 | —D | C] – C:\Program Files (x86)\SweetIM
[2012/06/11 15:06:25 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\pdfforge
[2012/06/11 15:06:22 | 000,065,024 | —- | C] (pdfforge GbR) – C:\Windows\SysNative\pdfcmon.dll
[2012/06/11 14:57:15 | 000,000,000 | -H-D | C] – C:\ProgramData\{A3A26C56-02C3-4F76-A033-12EE2FB52AE6}
[2012/06/11 14:57:13 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Stardock
[2012/06/11 14:57:13 | 000,000,000 | —D | C] – C:\Program Files (x86)\Stardock
[2012/06/11 14:56:39 | 000,000,000 | –SD | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4
[2012/06/11 14:53:33 | 000,000,000 | —D | C] – C:\Users\Brad C\OpenOffice.org 3.4 (en-US) Installation Files
[2012/06/11 14:52:40 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LightScribe Direct Disc Labeling
[2012/06/11 14:52:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\LightScribe
[2012/06/11 14:49:31 | 000,000,000 | —D | C] – C:\9becf207da7d7dfef274f5c9
[2012/06/11 14:48:23 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2012/06/11 14:48:23 | 000,000,000 | —D | C] – C:\Users\Brad C\Skype
[2012/06/11 14:48:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2012/06/11 14:45:08 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2012/06/11 14:43:45 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2012/06/11 14:39:35 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Allmyapps
[2012/06/11 14:39:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Allmyapps
[2012/06/11 14:39:30 | 000,000,000 | —D | C] – C:\Program Files (x86)\Allmyapps
[2012/06/11 14:39:23 | 000,000,000 | —D | C] – C:\ProgramData\Allmyapps
[2012/06/11 14:38:57 | 003,534,288 | —- | C] (Allmyapps) – C:\Users\Brad C\Facebook_video_calling_Allmyapps_Setup.exe
[2012/06/11 06:36:27 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{38072749-59A0-48BC-868F-67C7C50F8993}
[2012/06/11 06:36:16 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{A4F8141A-4C4D-4493-A0F3-2F6EB5E3F69E}
[2012/06/10 16:13:19 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF Creator
[2012/06/10 16:13:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\GPLGS
[2012/06/10 16:13:17 | 000,000,000 | —D | C] – C:\Program1
[2012/06/09 06:42:28 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\Software Informer
[2012/06/09 06:42:28 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Roaming\Software Informer
[2012/06/09 06:42:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Software Informer
[2012/06/09 06:42:04 | 000,000,000 | —D | C] – C:\ProgramData\A-PDF
[2012/06/09 06:42:02 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PPT To Flash Catalog Professional
[2012/06/09 06:41:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\PPT To Flash Catalog Professional
[2012/06/09 06:41:59 | 000,000,000 | —D | C] – C:\ProgramData\flipBook
[2012/06/09 06:41:42 | 000,000,000 | —D | C] – C:\Users\Brad C\Desktop\PPTtoFlashCatalogPro
[2012/06/09 06:41:08 | 000,000,000 | —D | C] – C:\Program Files (x86)\WebFormDesigner
[2012/06/09 06:40:53 | 000,000,000 | —D | C] – C:\Users\Brad C\WFDInstall
[2012/06/09 06:40:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\CamStudio
[2012/06/09 05:30:20 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{FEBE7E0A-3050-4A4E-9365-C00BF81FDDF4}
[2012/06/09 05:30:09 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{941FC528-AC8E-4933-93DD-683B40AFCB72}
[2012/06/08 08:09:51 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{AF132AE6-BBCF-4807-A4F4-28EF497119B9}
[2012/06/08 08:09:40 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{000E45A8-7676-4F86-A208-B04EEE3DF036}
[2012/06/08 07:29:49 | 000,000,000 | —D | C] – C:\Users\Brad C\Downloads\Documents\Article Submission Helper
[2012/06/08 07:29:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\ASHelper
[2012/06/07 19:28:26 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{2E56102B-A738-4BFE-894E-E925B339AFF2}
[2012/06/07 19:28:15 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{79DF1C6B-F755-461E-B3F5-29A5CC9C4BEB}
[2012/06/07 14:42:22 | 000,000,000 | —D | C] – C:\Users\Brad C\.thumbnails
[2012/06/07 14:00:02 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\fontconfig
[2012/06/07 14:00:00 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\gegl-0.2
[2012/06/07 14:00:00 | 000,000,000 | —D | C] – C:\Users\Brad C\.gimp-2.8
[2012/06/07 13:58:36 | 000,000,000 | —D | C] – C:\Program Files\GIMP 2
[2012/06/07 05:29:29 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{4548D96F-40F1-428F-8B87-A63092F2A2C4}
[2012/06/07 05:29:18 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{2CA04E2A-9FA7-4C06-A45A-C5321522F517}
[2012/06/06 17:28:51 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{49963352-2D04-4BAF-B1EA-7539FC580A33}
[2012/06/06 17:28:40 | 000,000,000 | —D | C] – C:\Users\Brad C\AppData\Local\{E931F0B9-2B67-40B2-99FC-8C6C2DAFF57F}
[2012/05/24 09:30:33 | 017,152,712 | —- | C] (Mozilla) – C:\Users\Brad C\Firefox Setup 13.0b4.exe
[2012/05/16 07:50:55 | 000,516,136 | —- | C] (Bandoo Media Inc) – C:\Users\Brad C\iLividSetupV1.exe
[2012/05/09 16:17:58 | 000,809,288 | —- | C] (AirInstaller Inc.) – C:\Users\Brad C\setup.exe
[2012/05/08 13:17:02 | 004,472,121 | —- | C] (CamStudio Open Source Dev Team ) – C:\Users\Brad C\CamStudio_Setup_v2.6b_r294_(build_24Oct2010).exe
[2012/03/23 12:00:00 | 000,733,280 | —- | C] (Google Inc.) – C:\Users\Brad C\ChromeSetup.exe
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/06 15:01:00 | 000,000,340 | —- | M] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2012/07/06 14:52:02 | 000,000,932 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000UA.job
[2012/07/06 14:52:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000UA.job
[2012/07/06 14:52:01 | 000,000,910 | —- | M] () – C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000Core.job
[2012/07/06 14:37:49 | 000,000,193 | —- | M] () – C:\Windows\WORDPAD.INI
[2012/07/06 14:33:00 | 000,000,898 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/07/06 14:30:01 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/07/06 13:52:37 | 101,200,596 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2012/07/06 13:52:09 | 000,487,533 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2012/07/06 13:45:48 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/07/06 12:34:01 | 000,220,164 | —- | M] () – C:\Users\Brad C\Desktop\LoneWolfPassiveProfits.pdf
[2012/07/06 11:37:07 | 000,230,548 | —- | M] () – C:\Users\Brad C\Desktop\buildyouronlinemarketingplan.pdf
[2012/07/06 09:56:21 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/07/06 09:56:21 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/07/06 09:52:00 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000Core.job
[2012/07/06 09:49:29 | 000,000,894 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/07/06 09:48:53 | 000,000,354 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForBRADC-BRADC-HP$.job
[2012/07/06 09:48:40 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2012/07/04 11:48:27 | 000,001,180 | —- | M] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2012/07/04 05:01:49 | 000,569,220 | —- | M] () – C:\Users\Brad C\Desktop\freetrafficmarketingreport.pdf
[2012/07/04 04:43:30 | 000,001,682 | -HS- | M] () – C:\ProgramData\KGyGaAvL.sys
[2012/07/03 17:00:07 | 000,452,917 | —- | M] () – C:\Users\Brad C\Desktop\tw12345.png
[2012/07/03 16:35:07 | 000,310,273 | —- | M] () – C:\Users\Brad C\Desktop\twitterbackground1.jpg
[2012/07/03 14:59:23 | 000,304,310 | —- | M] () – C:\Users\Brad C\Desktop\Blogging-Toolkit-Suscriber-background1.jpg
[2012/07/02 13:16:46 | 002,348,119 | —- | M] () – C:\Users\Brad C\Desktop\blogandping.pdf
[2012/07/02 11:37:17 | 000,024,799 | —- | M] () – C:\Users\Brad C\Desktop\migraine diary.pdf
[2012/07/02 11:37:06 | 000,014,397 | —- | M] () – C:\Users\Brad C\Desktop\migraine diary.odt
[2012/07/02 10:51:54 | 000,084,459 | —- | M] () – C:\Users\Brad C\Desktop\paperbackstack(2).jpg
[2012/07/02 09:51:42 | 000,061,958 | —- | M] () – C:\Users\Brad C\Desktop\ringbinderlaying(1).jpg
[2012/07/02 09:35:39 | 000,024,999 | —- | M] () – C:\Users\Brad C\Desktop\migraineebook.odt
[2012/07/01 19:06:53 | 000,161,426 | —- | M] () – C:\Users\Brad C\Desktop\10 Tips for Success.pdf
[2012/07/01 19:06:48 | 000,100,017 | —- | M] () – C:\Users\Brad C\Desktop\10 Tips for Success.odt
[2012/07/01 18:49:43 | 000,066,799 | —- | M] () – C:\Users\Brad C\Desktop\paperbackstack(1).jpg
[2012/07/01 12:24:29 | 000,000,982 | —- | M] () – C:\Users\Public\Desktop\CamStudio-Recorder.lnk
[2012/07/01 12:23:44 | 000,015,228 | —- | M] () – C:\Users\Brad C\Desktop\Tips & Tricks to Make Money Online.odt
[2012/07/01 09:44:21 | 000,217,362 | —- | M] () – C:\Users\Brad C\Desktop\Internet Marketing.pdf
[2012/07/01 09:31:39 | 000,347,738 | —- | M] () – C:\Users\Brad C\Desktop\Automate Your Business.pdf
[2012/07/01 09:31:31 | 000,361,127 | —- | M] () – C:\Users\Brad C\Desktop\How To Drive Big Traffic.pdf
[2012/07/01 09:31:23 | 000,384,983 | —- | M] () – C:\Users\Brad C\Desktop\Secrets of the Winners.pdf
[2012/07/01 09:31:12 | 000,369,901 | —- | M] () – C:\Users\Brad C\Desktop\10 Twitter Tips.pdf
[2012/07/01 07:10:41 | 004,472,121 | —- | M] (CamStudio Open Source Dev Team ) – C:\Users\Brad C\Downloads\Documents\CamStudio_Setup_v2.6b_r294_(build_24Oct2010).exe
[2012/07/01 06:53:36 | 000,002,416 | —- | M] () – C:\Users\Brad C\Desktop\Google Chrome.lnk
[2012/06/30 16:44:45 | 072,261,231 | —- | M] () – C:\Users\Brad C\Desktop\TrafficVideosMRR.zip
[2012/06/30 16:05:34 | 001,609,904 | —- | M] () – C:\Users\Brad C\Desktop\the_essential_guide_to_internet_marketing.pdf
[2012/06/30 10:39:10 | 000,834,766 | —- | M] () – C:\Users\Brad C\Desktop\replace-your-job-with-an-internet-business.pdf
[2012/06/30 10:08:44 | 000,002,931 | —- | M] () – C:\Users\Brad C\Desktop\TweetDeck.lnk
[2012/06/30 09:29:58 | 000,187,600 | —- | M] () – C:\Users\Brad C\Desktop\treat-me-good-and-i-treat-you-good_wl29jfr100.pdf
[2012/06/30 09:09:54 | 000,000,336 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForBrad C.job
[2012/06/29 17:07:11 | 000,337,672 | —- | M] () – C:\Users\Brad C\Desktop\IMeye_report.pdf
[2012/06/28 13:08:00 | 000,105,944 | —- | M] () – C:\Users\Brad C\Desktop\Howtobecomesuccessfulinaffiliagemarketing.pdf
[2012/06/28 13:07:52 | 000,278,939 | —- | M] () – C:\Users\Brad C\Desktop\Successful Affiliate Strategies.pdf
[2012/06/28 11:35:16 | 000,002,181 | —- | M] () – C:\Users\Brad C\Desktop\bradleycoats.com.html
[2012/06/28 10:45:31 | 023,911,551 | —- | M] () – C:\Users\Brad C\Desktop\QuickBlogIndexing_PLR.zip
[2012/06/28 10:45:01 | 024,120,316 | —- | M] () – C:\Users\Brad C\Desktop\HowToSetDomainNameservers_PLR.zip
[2012/06/28 10:39:03 | 001,025,264 | —- | M] () – C:\Users\Brad C\Desktop\BlogThemes_201109.zip
[2012/06/28 09:50:05 | 000,173,688 | —- | M] () – C:\Users\Brad C\Desktop\tscc.exe
[2012/06/28 09:41:29 | 143,316,947 | —- | M] () – C:\Users\Brad C\Desktop\CreateStunningVideoSlideshowsForFree_PLR.zip
[2012/06/28 09:38:50 | 002,115,021 | —- | M] () – C:\Users\Brad C\Desktop\OnlineVideo2012_PLR.zip
[2012/06/28 06:59:21 | 000,178,428 | —- | M] () – C:\Users\Brad C\Desktop\All the traffic your website can handle.pdf
[2012/06/27 18:46:51 | 000,136,875 | —- | M] () – C:\Users\Brad C\Desktop\Listbuilding Old and New.odt
[2012/06/27 18:01:20 | 000,057,590 | —- | M] () – C:\Users\Brad C\Desktop\ringbinderlaying.jpg
[2012/06/27 17:43:39 | 000,029,513 | —- | M] () – C:\Users\Brad C\Desktop\Screen-Shot-2012-06-25-at-10.26.09-AM-400x184.png
[2012/06/27 17:21:04 | 000,083,618 | —- | M] () – C:\Users\Brad C\Desktop\paperbackstack.jpg
[2012/06/27 16:27:00 | 000,001,025 | —- | M] () – C:\Users\Public\Desktop\Content Spin Bot.lnk
[2012/06/27 11:54:46 | 000,001,536 | —- | M] () – C:\Users\Public\Desktop\videosqueeze.lnk
[2012/06/26 14:25:52 | 000,916,472 | —- | M] () – C:\Users\Brad C\Desktop\nstf_cheat_sheet.pdf
[2012/06/26 14:18:17 | 000,094,937 | —- | M] () – C:\Users\Brad C\Desktop\NSTF Video 1 Slides.pdf
[2012/06/25 16:37:19 | 000,716,038 | —- | M] () – C:\Users\Brad C\Downloads\Documents\Learn Affiliate Marketing Basics E-book.odt
[2012/06/23 16:40:45 | 000,426,184 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/06/23 16:40:45 | 000,070,344 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/06/22 16:59:19 | 000,002,533 | —- | M] () – C:\Users\Brad C\Desktop\Skype (2).lnk
[2012/06/22 16:45:02 | 000,001,790 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/06/22 16:41:13 | 079,225,752 | —- | M] (Apple Inc.) – C:\Users\Brad C\iTunes64Setup.exe
[2012/06/22 16:29:05 | 002,068,428 | —- | M] () – C:\Users\Brad C\Desktop\1kblueprintnewpdf.pdf
[2012/06/21 06:45:07 | 000,483,593 | —- | M] () – C:\Users\Brad C\Downloads\Documents\LAMB.png
[2012/06/20 16:16:23 | 004,976,920 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/06/16 06:03:59 | 000,001,515 | —- | M] () – C:\Users\Brad C\Desktop\TrafficGeneration-ecourse - Shortcut.lnk
[2012/06/15 13:03:55 | 000,305,178 | —- | M] () – C:\Users\Brad C\Desktop\BrandNewEbook.odt
[2012/06/14 15:53:08 | 000,002,107 | —- | M] () – C:\Users\Public\Desktop\Express Zip File Compression Software.lnk
[2012/06/14 15:20:50 | 000,727,381 | —- | M] () – C:\Users\Brad C\Desktop\3waystomineyourlist.pdf
[2012/06/14 15:20:47 | 000,062,105 | —- | M] () – C:\Users\Brad C\Desktop\squeeze.pdf
[2012/06/14 08:43:38 | 000,001,177 | —- | M] () – C:\Users\Public\Desktop\PhotoStage Slideshow Producer.lnk
[2012/06/14 08:02:19 | 000,001,149 | —- | M] () – C:\Users\Brad C\Desktop\AVG PC Tuneup 2011.lnk
[2012/06/13 20:26:42 | 000,797,466 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/06/13 20:26:42 | 000,662,870 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/06/13 20:26:42 | 000,122,408 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/06/13 18:26:20 | 000,001,220 | —- | M] () – C:\Users\Public\Desktop\Affiliate ID Manager Master Rebrander .lnk
[2012/06/13 14:04:34 | 000,001,182 | —- | M] () – C:\Users\Public\Desktop\LibreOffice 3.4.lnk
[2012/06/13 13:59:21 | 001,536,192 | —- | M] (W3i, LLC) – C:\Users\Brad C\Desktop\libreoffice.exe
[2012/06/13 13:50:14 | 000,032,280 | —- | M] () – C:\Users\Brad C\Downloads\Documents\demo.html
[2012/06/12 07:14:56 | 000,001,242 | —- | M] () – C:\Users\Brad C\Desktop\Paint.lnk
[2012/06/11 16:54:12 | 000,006,144 | —- | M] () – C:\Users\Brad C\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/06/11 16:29:05 | 000,001,307 | —- | M] () – C:\Users\Public\Desktop\Tableau Public 6.1.lnk
[2012/06/11 16:24:45 | 000,001,242 | —- | M] () – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk
[2012/06/11 15:30:07 | 000,001,554 | —- | M] () – C:\Users\Brad C\Desktop\LimitlessLeadGenerationGuide - Shortcut.lnk
[2012/06/11 15:17:38 | 000,011,264 | —- | M] () – C:\Users\Brad C\Downloads\Documents\NicheData.db
[2012/06/11 14:57:59 | 000,000,829 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/11 14:57:18 | 000,002,033 | —- | M] () – C:\Users\Brad C\Desktop\Customize Fences.lnk
[2012/06/11 14:52:43 | 000,002,044 | —- | M] () – C:\Users\Public\Desktop\LightScribe.lnk
[2012/06/11 14:48:23 | 000,002,533 | —- | M] () – C:\Users\Brad C\Desktop\Skype.lnk
[2012/06/11 14:45:22 | 000,001,014 | —- | M] () – C:\Users\Brad C\Desktop\Audacity.lnk
[2012/06/11 14:39:31 | 000,000,960 | —- | M] () – C:\Users\Public\Desktop\Allmyapps.lnk
[2012/06/11 14:39:00 | 003,534,288 | —- | M] (Allmyapps) – C:\Users\Brad C\Facebook_video_calling_Allmyapps_Setup.exe
[2012/06/11 14:13:51 | 000,002,464 | —- | M] () – C:\Users\Brad C\Traffic Overdrive - Shortcut.lnk
[2012/06/10 16:34:34 | 000,034,333 | —- | M] () – C:\Users\Brad C\Downloads\Documents\internetnewbiebusinessmodel.odt
[2012/06/10 16:13:13 | 000,302,425 | —- | M] () – C:\Users\Brad C\AppData\Local\funmoods-speeddial.crx
[2012/06/10 16:13:13 | 000,031,470 | —- | M] () – C:\Users\Brad C\AppData\Local\funmoods.crx
[2012/06/09 06:33:54 | 001,364,995 | —- | M] () – C:\Users\Brad C\setup20.exe
[2012/06/09 05:56:13 | 000,304,659 | —- | M] () – C:\Users\Brad C\Downloads\Documents\Free Web Tools.pdf
[2012/06/08 17:31:21 | 000,080,184 | —- | M] () – C:\Users\Brad C\13 Secrets.pdf
[2012/06/08 17:31:11 | 000,026,679 | —- | M] () – C:\Users\Brad C\Downloads\Documents\13 Secrets.odt
[2012/06/08 15:33:09 | 000,164,720 | —- | M] () – C:\Users\Brad C\Extremefreetips.pdf
[2012/06/08 07:29:46 | 000,000,890 | —- | M] () – C:\Users\Brad C\Desktop\ASHelper.lnk
[2012/06/07 14:43:32 | 000,002,802 | —- | M] () – C:\Users\Brad C\AppData\Local\recently-used.xbel
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/06 14:37:49 | 000,000,193 | —- | C] () – C:\Windows\WORDPAD.INI
[2012/07/06 12:34:01 | 000,220,164 | —- | C] () – C:\Users\Brad C\Desktop\LoneWolfPassiveProfits.pdf
[2012/07/06 11:37:07 | 000,230,548 | —- | C] () – C:\Users\Brad C\Desktop\buildyouronlinemarketingplan.pdf
[2012/07/04 11:48:27 | 000,001,180 | —- | C] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2012/07/04 05:01:49 | 000,569,220 | —- | C] () – C:\Users\Brad C\Desktop\freetrafficmarketingreport.pdf
[2012/07/03 17:00:06 | 000,452,917 | —- | C] () – C:\Users\Brad C\Desktop\tw12345.png
[2012/07/03 16:35:07 | 000,310,273 | —- | C] () – C:\Users\Brad C\Desktop\twitterbackground1.jpg
[2012/07/03 13:34:53 | 000,304,310 | —- | C] () – C:\Users\Brad C\Desktop\Blogging-Toolkit-Suscriber-background1.jpg
[2012/07/02 13:16:46 | 002,348,119 | —- | C] () – C:\Users\Brad C\Desktop\blogandping.pdf
[2012/07/02 11:37:15 | 000,024,799 | —- | C] () – C:\Users\Brad C\Desktop\migraine diary.pdf
[2012/07/02 11:37:04 | 000,014,397 | —- | C] () – C:\Users\Brad C\Desktop\migraine diary.odt
[2012/07/02 10:51:54 | 000,084,459 | —- | C] () – C:\Users\Brad C\Desktop\paperbackstack(2).jpg
[2012/07/02 09:51:41 | 000,061,958 | —- | C] () – C:\Users\Brad C\Desktop\ringbinderlaying(1).jpg
[2012/07/02 09:35:37 | 000,024,999 | —- | C] () – C:\Users\Brad C\Desktop\migraineebook.odt
[2012/07/01 19:06:52 | 000,161,426 | —- | C] () – C:\Users\Brad C\Desktop\10 Tips for Success.pdf
[2012/07/01 18:49:43 | 000,066,799 | —- | C] () – C:\Users\Brad C\Desktop\paperbackstack(1).jpg
[2012/07/01 18:25:59 | 000,100,017 | —- | C] () – C:\Users\Brad C\Desktop\10 Tips for Success.odt
[2012/07/01 12:24:29 | 000,000,982 | —- | C] () – C:\Users\Public\Desktop\CamStudio-Recorder.lnk
[2012/07/01 12:23:42 | 000,015,228 | —- | C] () – C:\Users\Brad C\Desktop\Tips & Tricks to Make Money Online.odt
[2012/07/01 09:44:21 | 000,217,362 | —- | C] () – C:\Users\Brad C\Desktop\Internet Marketing.pdf
[2012/07/01 09:31:39 | 000,347,738 | —- | C] () – C:\Users\Brad C\Desktop\Automate Your Business.pdf
[2012/07/01 09:31:31 | 000,361,127 | —- | C] () – C:\Users\Brad C\Desktop\How To Drive Big Traffic.pdf
[2012/07/01 09:31:23 | 000,384,983 | —- | C] () – C:\Users\Brad C\Desktop\Secrets of the Winners.pdf
[2012/07/01 09:31:12 | 000,369,901 | —- | C] () – C:\Users\Brad C\Desktop\10 Twitter Tips.pdf
[2012/06/30 16:43:42 | 072,261,231 | —- | C] () – C:\Users\Brad C\Desktop\TrafficVideosMRR.zip
[2012/06/30 16:05:33 | 001,609,904 | —- | C] () – C:\Users\Brad C\Desktop\the_essential_guide_to_internet_marketing.pdf
[2012/06/30 10:39:09 | 000,834,766 | —- | C] () – C:\Users\Brad C\Desktop\replace-your-job-with-an-internet-business.pdf
[2012/06/30 09:29:57 | 000,187,600 | —- | C] () – C:\Users\Brad C\Desktop\treat-me-good-and-i-treat-you-good_wl29jfr100.pdf
[2012/06/29 17:07:11 | 000,337,672 | —- | C] () – C:\Users\Brad C\Desktop\IMeye_report.pdf
[2012/06/28 13:08:00 | 000,105,944 | —- | C] () – C:\Users\Brad C\Desktop\Howtobecomesuccessfulinaffiliagemarketing.pdf
[2012/06/28 13:07:51 | 000,278,939 | —- | C] () – C:\Users\Brad C\Desktop\Successful Affiliate Strategies.pdf
[2012/06/28 11:17:16 | 000,002,181 | —- | C] () – C:\Users\Brad C\Desktop\bradleycoats.com.html
[2012/06/28 10:45:18 | 023,911,551 | —- | C] () – C:\Users\Brad C\Desktop\QuickBlogIndexing_PLR.zip
[2012/06/28 10:44:45 | 024,120,316 | —- | C] () – C:\Users\Brad C\Desktop\HowToSetDomainNameservers_PLR.zip
[2012/06/28 10:39:02 | 001,025,264 | —- | C] () – C:\Users\Brad C\Desktop\BlogThemes_201109.zip
[2012/06/28 09:50:04 | 000,173,688 | —- | C] () – C:\Users\Brad C\Desktop\tscc.exe
[2012/06/28 09:39:28 | 143,316,947 | —- | C] () – C:\Users\Brad C\Desktop\CreateStunningVideoSlideshowsForFree_PLR.zip
[2012/06/28 09:38:48 | 002,115,021 | —- | C] () – C:\Users\Brad C\Desktop\OnlineVideo2012_PLR.zip
[2012/06/28 06:59:19 | 000,178,428 | —- | C] () – C:\Users\Brad C\Desktop\All the traffic your website can handle.pdf
[2012/06/27 18:46:49 | 000,136,875 | —- | C] () – C:\Users\Brad C\Desktop\Listbuilding Old and New.odt
[2012/06/27 18:01:19 | 000,057,590 | —- | C] () – C:\Users\Brad C\Desktop\ringbinderlaying.jpg
[2012/06/27 17:43:37 | 000,029,513 | —- | C] () – C:\Users\Brad C\Desktop\Screen-Shot-2012-06-25-at-10.26.09-AM-400x184.png
[2012/06/27 17:21:04 | 000,083,618 | —- | C] () – C:\Users\Brad C\Desktop\paperbackstack.jpg
[2012/06/27 16:27:00 | 000,001,025 | —- | C] () – C:\Users\Public\Desktop\Content Spin Bot.lnk
[2012/06/27 11:54:46 | 000,001,536 | —- | C] () – C:\Users\Public\Desktop\videosqueeze.lnk
[2012/06/26 18:22:01 | 000,000,340 | —- | C] () – C:\Windows\tasks\HP Photo Creations Communicator.job
[2012/06/26 14:25:51 | 000,916,472 | —- | C] () – C:\Users\Brad C\Desktop\nstf_cheat_sheet.pdf
[2012/06/26 14:18:17 | 000,094,937 | —- | C] () – C:\Users\Brad C\Desktop\NSTF Video 1 Slides.pdf
[2012/06/22 16:59:19 | 000,002,533 | —- | C] () – C:\Users\Brad C\Desktop\Skype (2).lnk
[2012/06/22 16:45:02 | 000,001,790 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/06/22 16:29:05 | 002,068,428 | —- | C] () – C:\Users\Brad C\Desktop\1kblueprintnewpdf.pdf
[2012/06/21 07:29:21 | 000,716,038 | —- | C] () – C:\Users\Brad C\Downloads\Documents\Learn Affiliate Marketing Basics E-book.odt
[2012/06/21 06:45:07 | 000,483,593 | —- | C] () – C:\Users\Brad C\Downloads\Documents\LAMB.png
[2012/06/16 05:10:39 | 000,002,931 | —- | C] () – C:\Users\Brad C\Desktop\TweetDeck.lnk
[2012/06/15 13:03:51 | 000,305,178 | —- | C] () – C:\Users\Brad C\Desktop\BrandNewEbook.odt
[2012/06/15 11:46:30 | 000,175,648 | —- | C] () – C:\Users\Brad C\Downloads\Documents\List Building for Beginners.pdf
[2012/06/14 16:27:39 | 001,548,484 | —- | C] () – C:\Users\Brad C\Desktop\nlb.exe
[2012/06/14 15:53:08 | 000,002,107 | —- | C] () – C:\Users\Public\Desktop\Express Zip File Compression Software.lnk
[2012/06/14 15:53:08 | 000,001,893 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Express Zip File Compression Software.lnk
[2012/06/14 15:20:50 | 000,727,381 | —- | C] () – C:\Users\Brad C\Desktop\3waystomineyourlist.pdf
[2012/06/14 15:20:47 | 000,062,105 | —- | C] () – C:\Users\Brad C\Desktop\squeeze.pdf
[2012/06/14 08:43:38 | 000,001,177 | —- | C] () – C:\Users\Public\Desktop\PhotoStage Slideshow Producer.lnk
[2012/06/14 08:43:37 | 000,001,189 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoStage Slideshow Producer.lnk
[2012/06/14 08:02:19 | 000,001,149 | —- | C] () – C:\Users\Brad C\Desktop\AVG PC Tuneup 2011.lnk
[2012/06/13 18:26:20 | 000,001,220 | —- | C] () – C:\Users\Public\Desktop\Affiliate ID Manager Master Rebrander .lnk
[2012/06/13 14:04:34 | 000,001,182 | —- | C] () – C:\Users\Public\Desktop\LibreOffice 3.4.lnk
[2012/06/13 13:50:14 | 000,032,280 | —- | C] () – C:\Users\Brad C\Downloads\Documents\demo.html
[2012/06/13 13:50:13 | 000,391,434 | —- | C] () – C:\Users\Brad C\Downloads\Documents\book.swf
[2012/06/12 07:14:56 | 000,001,242 | —- | C] () – C:\Users\Brad C\Desktop\Paint.lnk
[2012/06/11 16:29:05 | 000,001,319 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Tableau Public 6.1.lnk
[2012/06/11 16:29:05 | 000,001,307 | —- | C] () – C:\Users\Public\Desktop\Tableau Public 6.1.lnk
[2012/06/11 16:26:24 | 000,001,515 | —- | C] () – C:\Users\Brad C\Desktop\TrafficGeneration-ecourse - Shortcut.lnk
[2012/06/11 16:24:45 | 000,001,242 | —- | C] () – C:\Users\Brad C\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.4.lnk
[2012/06/11 15:30:07 | 000,001,554 | —- | C] () – C:\Users\Brad C\Desktop\LimitlessLeadGenerationGuide - Shortcut.lnk
[2012/06/11 15:17:38 | 000,011,264 | —- | C] () – C:\Users\Brad C\Downloads\Documents\NicheData.db
[2012/06/11 14:57:59 | 000,000,829 | —- | C] () – C:\Users\Public\Desktop\CCleaner.lnk
[2012/06/11 14:57:18 | 000,002,033 | —- | C] () – C:\Users\Brad C\Desktop\Customize Fences.lnk
[2012/06/11 14:52:43 | 000,002,044 | —- | C] () – C:\Users\Public\Desktop\LightScribe.lnk
[2012/06/11 14:48:23 | 000,002,533 | —- | C] () – C:\Users\Brad C\Desktop\Skype.lnk
[2012/06/11 14:45:22 | 000,001,026 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk
[2012/06/11 14:45:22 | 000,001,014 | —- | C] () – C:\Users\Brad C\Desktop\Audacity.lnk
[2012/06/11 14:39:31 | 000,000,960 | —- | C] () – C:\Users\Public\Desktop\Allmyapps.lnk
[2012/06/10 16:34:32 | 000,034,333 | —- | C] () – C:\Users\Brad C\Downloads\Documents\internetnewbiebusinessmodel.odt
[2012/06/10 16:13:22 | 000,302,425 | —- | C] () – C:\Users\Brad C\AppData\Local\funmoods-speeddial.crx
[2012/06/10 16:13:18 | 000,087,552 | —- | C] () – C:\Windows\SysNative\custmon64i.dll
[2012/06/10 16:13:18 | 000,031,470 | —- | C] () – C:\Users\Brad C\AppData\Local\funmoods.crx
[2012/06/09 06:33:52 | 001,364,995 | —- | C] () – C:\Users\Brad C\setup20.exe
[2012/06/09 05:56:13 | 000,304,659 | —- | C] () – C:\Users\Brad C\Downloads\Documents\Free Web Tools.pdf
[2012/06/08 17:31:19 | 000,080,184 | —- | C] () – C:\Users\Brad C\13 Secrets.pdf
[2012/06/08 17:31:09 | 000,026,679 | —- | C] () – C:\Users\Brad C\Downloads\Documents\13 Secrets.odt
[2012/06/08 15:33:06 | 000,164,720 | —- | C] () – C:\Users\Brad C\Extremefreetips.pdf
[2012/06/08 07:29:46 | 000,000,890 | —- | C] () – C:\Users\Brad C\Desktop\ASHelper.lnk
[2012/06/07 14:43:32 | 000,002,802 | —- | C] () – C:\Users\Brad C\AppData\Local\recently-used.xbel
[2012/06/07 13:59:27 | 000,000,899 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GIMP 2.lnk
[2012/05/24 09:31:26 | 000,001,056 | —- | C] () – C:\Users\Brad C\Mozilla Firefox.lnk
[2012/05/11 15:08:19 | 000,002,212 | —- | C] () – C:\Users\Brad C\WinZip.lnk
[2012/05/09 17:10:02 | 000,001,074 | —- | C] () – C:\Users\Brad C\Free Download Manager.lnk
[2012/05/02 13:48:11 | 000,001,467 | —- | C] () – C:\Users\Brad C\my affiliate marketing course - Shortcut.lnk
[2012/05/02 12:08:16 | 000,001,873 | —- | C] () – C:\Users\Brad C\01 - Affiliate Marketer's Handbook - Shortcut.lnk
[2012/05/02 11:44:13 | 000,001,500 | —- | C] () – C:\Users\Brad C\Super Affiliate Secrets Exposed!.lnk
[2012/05/01 17:14:51 | 000,009,585 | —- | C] () – C:\Users\Brad C\workinprogress.jpg
[2012/05/01 16:55:19 | 000,072,527 | —- | C] () – C:\Users\Brad C\images3.png
[2012/05/01 15:08:20 | 000,136,688 | —- | C] () – C:\Users\Brad C\Outsourcing-Strategies.pdf
[2012/04/30 14:52:01 | 000,176,198 | —- | C] () – C:\Users\Brad C\Weight loss for a Healthier Lifestyle.pdf
[2012/04/30 14:02:19 | 000,109,445 | —- | C] () – C:\Users\Brad C\Weight loss for a Healthier Lifestyle.odt
[2012/04/30 12:50:31 | 000,003,272 | —- | C] () – C:\Users\Brad C\Ebook - Shortcut.lnk
[2012/04/29 13:26:21 | 000,001,981 | —- | C] () – C:\Users\Brad C\socrates - Shortcut.lnk
[2012/04/29 10:36:24 | 000,358,835 | —- | C] () – C:\Users\Brad C\free-header-image-2.psd
[2012/04/28 21:49:18 | 000,011,614 | —- | C] () – C:\Users\Brad C\new opt in form.html
[2012/04/28 10:39:17 | 000,070,251 | —- | C] () – C:\Users\Brad C\QuickHealthyWeightLoss.odt
[2012/04/25 17:43:20 | 000,001,131 | —- | C] () – C:\Users\Brad C\Thinspiration.html
[2012/04/24 19:40:56 | 000,002,293 | —- | C] () – C:\Users\Brad C\Foods_That_Kill_Fat_mg - Shortcut.lnk
[2012/04/24 19:37:36 | 000,002,410 | —- | C] () – C:\Users\Brad C\how-to-knock-20-years-off-your-body - Shortcut.lnk
[2012/04/24 16:48:49 | 000,624,374 | —- | C] () – C:\Users\Brad C\7figuresuccessformulatrafficguide.pdf
[2012/04/24 10:56:49 | 000,001,614 | —- | C] () – C:\Users\Brad C\Worlds-Shortest-Viral-Book.pdf
[2012/04/24 10:37:57 | 000,282,283 | —- | C] () – C:\Users\Brad C\Ultimate-ClickBank.pdf
[2012/04/23 17:13:07 | 000,006,140 | —- | C] () – C:\Users\Brad C\Image1.png
[2012/04/23 14:35:46 | 000,002,464 | —- | C] () – C:\Users\Brad C\Traffic Overdrive - Shortcut.lnk
[2012/04/22 21:03:02 | 000,001,701 | —- | C] () – C:\Users\Brad C\TrafficExplosion - Shortcut.lnk
[2012/04/21 17:19:31 | 000,000,132 | —- | C] () – C:\Users\Brad C\AppData\Roaming\Adobe PNG Format CS6 Prefs
[2012/04/15 13:12:00 | 000,001,792 | —- | C] () – C:\Users\Brad C\Newsletter - Shortcut.lnk
[2012/04/12 10:21:27 | 000,001,315 | —- | C] () – C:\Users\Brad C\The Weather Channel App.lnk
[2012/04/08 09:25:44 | 000,001,738 | —- | C] () – C:\Users\Brad C\feuxjo - Shortcut.lnk
[2012/01/22 17:22:12 | 000,001,017 | —- | C] () – C:\Program Files (x86)\Commission Streamer.lnk
[2012/01/22 17:22:12 | 000,000,967 | —- | C] () – C:\Program Files (x86)\Update Commission Streamer.lnk
[2012/01/04 18:16:43 | 000,000,015 | —- | C] () – C:\Windows\cfwin.ini
[2012/01/04 18:16:41 | 000,000,110 | —- | C] () – C:\Windows\cfwinlib.ini
[2011/11/23 23:37:29 | 000,742,442 | —- | C] () – C:\Windows\XHeader Uninstaller.exe
[2011/09/11 16:47:13 | 000,024,209 | —- | C] () – C:\Users\Brad C\AppData\Roaming\UserTile.png
[2011/08/29 13:47:42 | 000,538,222 | —- | C] () – C:\Users\Brad C\NonStopViralTraffic.pdf
[2011/05/24 18:58:23 | 000,006,144 | —- | C] () – C:\Users\Brad C\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/05/24 18:57:56 | 000,001,682 | -HS- | C] () – C:\ProgramData\KGyGaAvL.sys
[2011/05/13 11:16:11 | 000,001,854 | —- | C] () – C:\Users\Brad C\AppData\Roaming\GhostObjGAFix.xml
[2011/04/18 07:49:36 | 000,777,312 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/03/29 05:46:58 | 000,414,113 | —- | C] () – C:\Users\Brad C\Turbo_Traffic_ebook.pdf
[2010/10/25 03:47:34 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2010/10/25 03:38:46 | 000,002,857 | —- | C] () – C:\Windows\SysWow64\atipblup.dat
[2010/10/25 03:37:37 | 000,000,299 | —- | C] () – C:\Windows\SysWow64\RStoneLog2.ini
[2010/10/25 03:37:37 | 000,000,240 | —- | C] () – C:\Windows\SysWow64\RStoneLog.ini
[2010/10/16 14:42:34 | 000,000,188 | —- | C] () – C:\Windows\SysWow64\HPWA.ini
[2010/09/21 12:30:44 | 000,007,736 | —- | C] () – C:\Windows\hpDSTRES.DLL
[2010/07/28 17:08:46 | 000,127,868 | —- | C] () – C:\Windows\SysWow64\igcompkrng575.bin
[2010/07/28 17:08:44 | 000,104,796 | —- | C] () – C:\Windows\SysWow64\igfcg575m.bin
[2010/07/28 17:08:42 | 000,870,560 | —- | C] () – C:\Windows\SysWow64\igkrng575.bin
[2010/07/28 16:14:38 | 000,208,896 | —- | C] () – C:\Windows\SysWow64\iglhsip32.dll
[2010/07/28 16:14:38 | 000,143,360 | —- | C] () – C:\Windows\SysWow64\iglhcp32.dll

========== LOP Check ==========

[2012/01/17 19:17:39 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Affilorama
[2012/06/11 14:39:45 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Allmyapps
[2011/08/17 11:40:52 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Archon Media
[2012/06/04 08:24:38 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Audacity
[2011/09/28 19:22:22 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Avanquest
[2012/06/14 08:37:29 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\AVG
[2012/03/13 20:31:53 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\AVG2012
[2012/05/09 17:09:28 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Babylon
[2011/11/16 16:25:28 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\CoffeeCup Software
[2011/11/21 17:12:07 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\com.fastcashcommissions.fasttrafficmagnet
[2011/11/21 12:50:44 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\com.fastcashcommissions.fasttrafficsniper
[2012/03/14 08:14:48 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\CommissionMultiplier
[2011/04/16 11:03:25 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\DigitalPersona
[2012/06/13 20:12:28 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\DVDVideoSoft
[2011/10/05 09:26:26 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Easy Click Commissions
[2012/03/23 15:29:11 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\eGames
[2012/02/15 01:48:00 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\FileZilla
[2011/11/04 17:06:58 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\GetRightToGo
[2011/11/22 02:32:06 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\IBP
[2011/11/15 15:37:31 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\IncomeGenesis
[2012/07/04 11:48:22 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\IObit
[2012/05/24 09:09:29 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\IrfanView
[2011/09/18 18:22:23 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Keyword Strategy Studio Pro
[2012/06/19 06:32:27 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Kingsoft
[2011/10/10 00:15:20 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\KompoZer
[2012/06/13 14:06:33 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\LibreOffice
[2011/11/23 19:24:08 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\MAGIX
[2011/05/13 11:17:55 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1
[2011/09/25 19:05:10 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Nitro PDF
[2011/10/24 20:45:39 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Nvu
[2011/09/25 19:03:53 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\OpenCandy
[2011/05/08 22:20:27 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\OpenOffice.org
[2012/05/21 15:22:02 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\PCTools
[2012/03/31 21:57:59 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\PDAppFlex
[2012/06/11 15:06:26 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\pdfforge
[2011/10/15 21:25:44 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\PrimoPDF
[2011/12/30 16:56:43 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\SlimBrowser
[2012/07/05 15:34:52 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\SoftGrid Client
[2012/07/06 09:53:21 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Software Informer
[2011/04/16 11:09:33 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Stardock
[2012/05/23 08:32:26 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\TestApp
[2011/11/29 13:04:02 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\ThumbsPlus
[2011/05/06 10:03:58 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Thunderbird
[2011/04/18 07:59:30 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\TP
[2012/06/06 14:23:07 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Traffic Travis v4
[2012/01/26 19:48:28 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\TrafficInitiator-Air
[2012/06/30 10:07:18 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\TweetAdder3
[2011/11/14 17:45:29 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\ubot
[2012/04/22 11:09:48 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Ulead Systems
[2012/06/26 18:22:05 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Visan
[2011/10/30 22:41:10 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\WildTangent
[2011/05/16 12:45:17 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\Windows Live Writer
[2012/07/06 09:49:51 | 000,000,000 | —D | M] – C:\Users\Brad C\AppData\Roaming\ZumoDrive
[2012/07/06 14:52:01 | 000,000,910 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000Core.job
[2012/07/06 14:52:02 | 000,000,932 | —- | M] () – C:\Windows\Tasks\FacebookUpdateTaskUserS-1-5-21-2672231064-770767239-3119844742-1000UA.job
[2012/07/04 20:03:09 | 000,032,612 | —- | M] () – C:\Windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2012/05/23 08:13:04 | 000,014,253 | —- | M] () – C:\alotserviceruntime.log
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2008/04/11 10:07:18 | 000,003,820 | —- | M] () – C:\eula.1028.txt
[2008/04/11 10:07:18 | 000,015,428 | —- | M] () – C:\eula.1031.txt
[2008/04/11 10:07:18 | 000,010,058 | —- | M] () – C:\eula.1033.txt
[2008/04/11 10:07:18 | 000,012,246 | —- | M] () – C:\eula.1036.txt
[2008/04/11 10:07:18 | 000,013,912 | —- | M] () – C:\eula.1040.txt
[2008/04/11 10:07:18 | 000,005,868 | —- | M] () – C:\eula.1041.txt
[2008/04/11 10:07:18 | 000,005,970 | —- | M] () – C:\eula.1042.txt
[2008/04/11 10:07:18 | 000,010,134 | —- | M] () – C:\eula.1049.txt
[2008/04/11 10:07:18 | 000,003,814 | —- | M] () – C:\eula.2052.txt
[2008/04/11 10:07:18 | 000,012,936 | —- | M] () – C:\eula.3082.txt
[2008/04/11 10:07:18 | 000,001,110 | —- | M] () – C:\globdata.ini
[2012/07/06 09:48:40 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2008/04/11 08:03:48 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe
[2008/04/11 10:07:18 | 000,000,843 | —- | M] () – C:\install.ini
[2008/04/11 08:03:48 | 000,076,304 | —- | M] (Microsoft Corporation) – C:\install.res.1028.dll
[2008/04/11 08:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.1031.dll
[2008/04/11 08:03:48 | 000,091,152 | —- | M] (Microsoft Corporation) – C:\install.res.1033.dll
[2008/04/11 08:03:48 | 000,097,296 | —- | M] (Microsoft Corporation) – C:\install.res.1036.dll
[2008/04/11 08:03:48 | 000,095,248 | —- | M] (Microsoft Corporation) – C:\install.res.1040.dll
[2008/04/11 08:03:48 | 000,081,424 | —- | M] (Microsoft Corporation) – C:\install.res.1041.dll
[2008/04/11 08:03:48 | 000,079,888 | —- | M] (Microsoft Corporation) – C:\install.res.1042.dll
[2008/04/11 10:09:24 | 000,093,200 | —- | M] (Microsoft Corporation) – C:\install.res.1049.dll
[2008/04/11 08:03:48 | 000,075,792 | —- | M] (Microsoft Corporation) – C:\install.res.2052.dll
[2008/04/11 08:03:48 | 000,096,272 | —- | M] (Microsoft Corporation) – C:\install.res.3082.dll
[2012/05/23 08:13:04 | 000,020,374 | —- | M] () – C:\INSTALLHELPER.LOG
[2012/07/06 09:48:40 | 4083,007,488 | -HS- | M] () – C:\pagefile.sys
[2012/05/02 13:00:07 | 000,000,448 | —- | M] () – C:\user.js
[2008/04/11 10:07:18 | 000,005,686 | —- | M] () – C:\vcredist.bmp
[2008/04/11 10:09:38 | 003,797,292 | —- | M] () – C:\VC_RED.cab
[2008/04/11 10:11:40 | 000,233,472 | —- | M] () – C:\VC_RED.MSI

< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2012/03/08 18:37:20 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >
[2011/07/03 19:13:07 | 000,001,718 | -HS- | M] () – C:\Users\Brad C\AppData\Roaming\Microsoft\LastFlashConfig.wfc

< %PROGRAMFILES%\*.* >
[2012/01/22 17:22:12 | 000,001,017 | —- | M] () – C:\Program Files (x86)\Commission Streamer.lnk
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
[2012/01/22 17:22:12 | 000,000,967 | —- | M] () – C:\Program Files (x86)\Update Commission Streamer.lnk

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2011/04/28 17:51:32 | 000,000,221 | -HS- | M] () – C:\Users\Brad C\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >
[2010/09/03 19:13:42 | 000,277,600 | —- | M] (CyberLink Corp.) – C:\Users\Brad C\Desktop\HPMediaSmartWebcam.exe
[2012/06/13 13:59:21 | 001,536,192 | —- | M] (W3i, LLC) – C:\Users\Brad C\Desktop\libreoffice.exe
[2006/03/29 19:37:40 | 001,548,484 | —- | M] () – C:\Users\Brad C\Desktop\nlb.exe
[2012/06/28 09:50:05 | 000,173,688 | —- | M] () – C:\Users\Brad C\Desktop\tscc.exe

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

========== Alternate Data Streams ==========

@Alternate Data Stream - 98 bytes -> C:\ProgramData\Temp:DFC5A2B2
@Alternate Data Stream - 144 bytes -> C:\ProgramData\Temp:F49E02D5
@Alternate Data Stream - 139 bytes -> C:\ProgramData\Temp:0B4227B4
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:F73EA84D
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:F1CBBAF0
@Alternate Data Stream - 127 bytes -> C:\ProgramData\Temp:430C6D84
@Alternate Data Stream - 121 bytes -> C:\ProgramData\Temp:82111599
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:CFF654D3
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:B9A60C8F

< End of report >






OTL Extras logfile created on: 7/6/2012 3:01:29 PM - Run 1
OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Brad C\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

3.80 Gb Total Physical Memory | 1.06 Gb Available Physical Memory | 27.91% Memory free
7.60 Gb Paging File | 4.41 Gb Available in Paging File | 58.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 668.10 Gb Total Space | 591.32 Gb Free Space | 88.51% Space Free | Partition Type: NTFS
Drive D: | 30.24 Gb Total Space | 4.44 Gb Free Space | 14.69% Space Free | Partition Type: NTFS
Drive F: | 98.87 Mb Total Space | 83.72 Mb Free Space | 84.68% Space Free | Partition Type: FAT32

Computer Name: BRADC-BRADC-HP | User Name: Brad C | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Reg Error: Key error.] – Reg Error: Key error. File not found

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\PROGRA~2\COFFEE~1\coffee.exe" "%1" (CoffeeCup Software)
htmlfile [open] – Reg Error: Key error.
htmlfile [opennew] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [Browse with Corel PaintShop Photo Pro X3] – "c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\Corel Paint Shop Pro Photo.exe" "%L" (Corel, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Key error.

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – "C:\PROGRA~2\COFFEE~1\coffee.exe" "%1" (CoffeeCup Software)
htmlfile [open] – Reg Error: Key error.
htmlfile [opennew] – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] – Reg Error: Key error.
https [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Browse with &IrfanView;] – "C:\Program Files (x86)\IrfanView\i_view32.exe" "%1 /thumbs" (Irfan Skiljan)
Directory [Browse with Corel PaintShop Photo Pro X3] – "c:\Program Files (x86)\Corel\Corel PaintShop Photo Pro\X3\PSPClassic\Corel Paint Shop Pro Photo.exe" "%L" (Corel, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – Reg Error: Key error.
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Key error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{19597BB1-4C0D-445A-91E1-A50CEA98B102}" = lport=3702 | protocol=17 | dir=in | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{1F4CBAFA-3407-420F-8577-4BD6C4C9C530}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{26BA617B-D372-4473-815F-5D294A60C9E4}" = lport=10243 | protocol=6 | dir=in | app=system |
"{2E58C59E-2C52-4EA9-AA23-9364DC7C6227}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{319E2D5C-7E1C-47AC-B8CA-A2C4543308DE}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{344E1A98-D8B6-4300-AFB7-A172CC2B4FBB}" = lport=139 | protocol=6 | dir=in | app=system |
"{366B0C0D-D690-42C8-B52F-EF01FBC334F0}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{412921DD-17B7-4F79-ADDE-74165E45AD98}" = rport=137 | protocol=17 | dir=out | app=system |
"{428BF949-CC40-4252-ACAC-1FDB4D4B8E97}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{43AE201E-9DBB-4184-A757-0C6E7A309338}" = lport=445 | protocol=6 | dir=in | app=system |
"{5D5AB864-43EA-491E-BD2F-14EF9ECDB28F}" = lport=2799 | protocol=6 | dir=in | name=altova license metering port (tcp) |
"{6494BEDF-E1E7-4CAC-80F6-91342FC56560}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8281A89D-CD03-4988-8799-EC7A98A7C90E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{89BEDD83-4877-466F-8DAA-1726A7A1671A}" = rport=10243 | protocol=6 | dir=out | app=system |
"{92FDEE2A-92DC-49AE-B436-4CFBD91329E2}" = rport=139 | protocol=6 | dir=out | app=system |
"{95243C02-2C73-43A8-A777-7ED0619423F8}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{96E08991-D28E-410D-B0A9-E6AC78F2EFCF}" = rport=138 | protocol=17 | dir=out | app=system |
"{97A93E76-29F3-4DF6-8348-548170552FFD}" = lport=2799 | protocol=17 | dir=in | name=altova license metering port (udp) |
"{9A56A1B6-BB51-4497-89F4-92EDED8B430E}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A6882FBF-BF5A-4391-8D57-059F307A71D4}" = lport=3702 | protocol=17 | dir=in | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{A9C5D378-6D36-49E6-8C83-EAA493DB4078}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B1A52194-F8ED-4EED-90F4-D0C50EDDC59A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B5EFCC30-E476-47ED-A727-5E91AF28380D}" = rport=3702 | protocol=17 | dir=out | svc=fdrespub | app=%systemroot%\system32\svchost.exe |
"{BB5ED2DF-59CB-4F3F-850B-BEA79109F96A}" = rport=445 | protocol=6 | dir=out | app=system |
"{C1FE3830-9F8F-44CA-9373-67E40607A113}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{D55BA07D-29B2-4EBE-8BEB-7E7674FA0944}" = lport=2869 | protocol=6 | dir=in | app=system |
"{DAF32865-72FB-4A15-9A7B-DE6E5BE2ED7A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{EBB0BA4A-2A0C-48A9-9042-D4C7C38357C3}" = lport=138 | protocol=17 | dir=in | app=system |
"{EC77558A-171B-462B-9624-DB0D8FF6FBF8}" = lport=137 | protocol=17 | dir=in | app=system |
"{EE83D38A-96D7-4164-A7E5-02BACBE9E466}" = rport=3702 | protocol=17 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe |
"{F30BD097-9D87-4EEA-A04B-878D2DA6FDDD}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{F3AE84C8-1979-48B7-BB1E-136DD0C71A0C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FE8FC3AA-2DEC-4AFA-8EF1-8378C0CCF29D}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FECF0628-975B-4D0F-A12D-8DE72106F3D9}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FF417F25-FFD0-403A-A03F-7831E64ABB9E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{012DB1E2-5BA9-48C4-98A9-C5E53480BCD8}" = protocol=6 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{02AB7CF2-4A1D-419E-88AA-20BA15FE570B}" = protocol=6 | dir=out | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe |
"{0A6644DF-32A6-4747-83F5-DD46018DEA73}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{167A3DB7-4866-4AB8-B7E0-8C80573A42F4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{17708663-162E-4E56-8ED7-F436A3077995}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{17DF2CA4-CABA-4AD1-A513-85C29F4F2905}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{18C54DAA-BB5D-4CBE-9F12-791C37386797}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{1B11BAB2-F8E5-4DBC-81D0-581E009B2C87}" = dir=in | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\support\bin\win\rosettastoneltdservices.exe |
"{1D870A5D-29D8-4834-8BF6-5D07EEFF13FC}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe |
"{2920D607-598A-4159-B2EC-3214BE2342A0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{2B39A564-FF92-44C2-96F9-FA53B6D3F52E}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{2E2B96FD-90E4-4931-B027-AB21AA103E54}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{2E96BD0B-CA71-4A9E-AD7A-45C2F6793941}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{2F9AE797-02AE-4F50-89C4-B1A2A5223D76}" = protocol=6 | dir=out | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe |
"{30F1D8D0-6E0B-4F3C-99E7-36CCCA75C71B}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{31524F41-F598-4380-BC00-34A7E42475BC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{347D1738-E9C0-49B7-B29C-45A8D832CA53}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{3935C2B5-BB4B-40E7-B269-A50B0A84B201}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{3BFEE9BE-3E92-47AA-B7BA-CF3BC8BFC2BB}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{4269FF99-AA02-4EEB-A8BF-0E34CCD17B47}" = protocol=17 | dir=in | app=c:\program files (x86)\iwin games\iwingames.exe |
"{44DB90D1-904D-4754-B3E5-C4B7A0D57281}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{466A8946-F8EA-4EB7-9BF0-F129F4350050}" = protocol=17 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{47566C82-2438-4578-A55F-6BA764066056}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4EAB3CBE-F91F-4702-8858-2287F7F8B198}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{4F5D8B0B-158B-4ED2-848B-208B5C97D209}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{51E4E683-0820-43A4-93EA-7D46D864ABD4}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\photo\hpmediasmartphoto.exe |
"{531E4EA2-A739-42F8-8776-83D60AA614FF}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr8.exe |
"{56F5FD59-1693-4BF9-AB37-ECFE2F8C9E00}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\music\hptouchsmartmusic.exe |
"{57BBD81D-A081-4604-8374-7BD56FC3E0D3}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{64ED9658-9646-45AF-98FC-112236C13822}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{67585892-4DF5-48D3-A6BD-7D735B9DF7EC}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{6E0F85E1-E81D-41F5-89FE-49D94D313B00}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{6FC9FA5E-FE7C-4E12-9610-8D5EDC07FCCE}" = protocol=17 | dir=in | app=c:\program files (x86)\iwin games\webupdater.exe |
"{76205CB0-ACA0-459A-9B59-4D09B9B85C55}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{7953EEAE-92E7-4C92-8F36-8CB75F3EB5A2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{7E056D9E-D868-4520-9A57-E82968D5CA43}" = dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\video\hpmediasmartvideo.exe |
"{8C76CFBF-3952-40F6-BB9D-0C5B3193E39B}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{8D8B90D0-7A85-4F10-B0E4-D9385C487418}" = protocol=6 | dir=out | app=system |
"{8F7862A6-090A-448C-81B4-624FA64A5EBA}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9B48BD76-01D4-4C6A-A0AB-CF8C88E8BCC0}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A0F6D422-E7D9-4AFB-80A0-A2646D582C0A}" = protocol=6 | dir=in | app=c:\program files (x86)\iwin games\iwingames.exe |
"{A2DE498D-2AB9-4DE7-9D94-27038E4E7A69}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{ABF9F627-0D4F-43A2-8160-8C2228671038}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{B03CFFCD-DF1A-48C0-BDE6-213895C33FEA}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{B462EBAB-194E-41E1-8634-24AB30D11704}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{BE7B332F-312E-49AE-966B-97D2F3B71796}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{C6EBCCC0-FF46-43E7-AE70-061C05849E6B}" = protocol=17 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |
"{C7269815-5F46-44B2-B2CB-E078725479C6}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{C85A73FD-9AFD-462C-859B-268B4A2ED22F}" = dir=out | app=c:\program files (x86)\hewlett-packard\hp clouddrive\zumodrive.exe |
"{CCBDC39A-76DE-4CA8-9022-F918AC526E54}" = protocol=6 | dir=in | app=c:\program files (x86)\sweetim\communicator\sweetpacksupdatemanager.exe |
"{D1E2A091-61CF-4326-B5C0-434C71461B19}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp clouddrive\zumodrive.exe |
"{D6FCFC6A-F902-4CA8-B292-914A279818E3}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{DB9C4F97-0A5F-43B7-9D9E-03ABE7E3BE78}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgmfapx.exe |
"{EFA5ECC5-EFF9-4F3E-9CDF-300C7DB58C8E}" = dir=in | app=c:\program files (x86)\rosetta stone\rosetta stone version 3\rosettastoneversion3.exe |
"{F1219C65-6FDF-4C7B-B60D-AB2344BACE0B}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{F373AB66-9210-45CB-9DDA-00A04BC764A1}" = protocol=17 | dir=in | app=c:\windows\syswow64\msiexec.exe |
"{F75699BF-D34D-4F52-BF63-F1BEA2F1B471}" = protocol=6 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |
"{FB3B073D-7014-42A4-B4FE-76AC0EBC9CC0}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{FD021AE2-D32D-48A3-BD03-47F1E55FC42A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FE5055FE-A593-422A-A51B-ED57F06A6BCE}" = protocol=6 | dir=in | app=c:\program files (x86)\iwin games\webupdater.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{05BFB060-4F22-4710-B0A2-2801A1B606C5}" = Microsoft Antimalware
"{09BDCC02-80F2-4EFB-8F1B-A807D2C38E31}" = HP MediaSmart Movies and TV
"{10CD364B-FFCC-48BE-B469-B9622A033075}" = Fences
"{13DCC2C7-454D-42F0-A892-E0E9A5DE4E67}" = HP Wireless Assistant
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{26A24AE4-039D-4CA4-87B4-2F86416021FF}" = Java™ 6 Update 21 (64-bit)
"{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services
"{336D0C35-8A85-403a-B9D2-65C292C39087}_is1" = Web Assistant 2.0.0.430
"{3C8159DD-1890-4625-A5B2-E3D8D78D4486}" = AVG 2012
"{426FAE9F-7373-496E-A215-9DB7EF4398CF}" = Validity Sensors DDK
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5BF97E02-2F6A-412A-BB4D-B6E2DC65FCA7}" = HP SimplePass Identity Protection
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6A76BEAF-6D1F-4273-A79B-DA8410A2E56B}" = Apple Mobile Device Support
"{6ACE7F46-FACE-4125-AE86-672F4F2A6A28}" = Bing Maps 3D
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{840A3BAA-4C68-4581-9C7A-6F8D6CF531B9}" = iTunes
"{857B32C1-7C87-40B5-B2A5-D06F49B80002}" = AVG 2012
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A04108F4-71E9-FD90-D73D-2058DF6987F4}" = ATI Catalyst Install Manager
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BE6725F2-6D15-477C-86C6-4522B8569D62}" = HP MediaSmart SmartMenu
"{C84FFB07-C687-45CF-91C8-868DB8D8C8CD}" = HP 3D DriveGuard
"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6246243-CF06-4E40-8A37-C3B537695C36}" = Share64
"{FED4086D-51A8-E88C-1CF9-BA21A50470EE}" = ccc-utility64
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX 64-bit
"AVG" = AVG 2012
"Broadcom 802.11 Wireless LAN Adapter" = Broadcom 802.11 Wireless LAN Adapter
"CCleaner" = CCleaner
"GIMP-2_is1" = GIMP 2.8.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"PDF Creator" = PDF Creator
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"_{D1AEB5DB-04FA-489D-94EF-8600898B93EE}" = Corel PaintShop Photo Pro X3
"_{F072CA07-A781-45E4-9975-C033A73019CF}" = Corel VideoStudio Pro X3
"{0001B4FD-9EA3-4D90-A79E-FD14BA3AB01D}" = PDFCreator
"{00FB9AA8-5FFF-DDCE-DA2E-530994B59217}" = CCC Help Finnish
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{045C16AD-B2E5-43D0-BB51-2F1987D91038}" = HP Documentation
"{05BA3547-6C5C-7D39-4D23-DB5E61D8DD79}" = Income Genesis
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0965F857-DAAD-4F93-8054-0E2EC3C8C5B0}" = SweetIM for Messenger 3.6
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0EDEB615-1A60-425E-8306-0E10519C7B55}" = RoxioNow Player
"{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore
"{122ADF8C-DDA1-480C-9936-C88F2825B265}" = Apple Application Support
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{1991D8C3-8354-2228-401C-D3D105CA2AC4}" = CCC Help Chinese Traditional
"{19B9DAD6-5E6E-4B80-8EFE-314B5638D6D4}" = Xara 3D Maker 7
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1E6E990A-728D-4700-9B0A-2CA541C93A12}" = Catalyst Control Center - Branding
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2A738B10-A5C9-4525-8198-5B99C66E0A56}" = My Ebook Library
"{2D8539EE-3F50-94DB-2605-047B33558C70}" = CCC Help Thai
"{2EA3D6B2-157E-4112-A3AB-BF17E16661C3}" = HP MediaSmart/TouchSmart Netflix
"{2EA870FA-585F-4187-903D-CB9FFD21E2E0}" = DHTML Editing Component
"{2FA75B40-17C9-4D22-88CA-80A5D52FAB13}" = LightScribe System Software
"{2FF2BBBA-341C-4F36-AB55-7398184733CE}" = CCC Help Italian
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{30296046-9CEB-4E8F-86BA-668155D123B3}_is1" = Spin Writer Pro version 1.0
"{31EEA563-3544-4EA1-8773-BCBF83F9627A}" = HP Software Framework
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33C8C01E-4787-482B-9D2C-AB8221FCC01D}" = IObit Toolbar v6.0
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{3B834B54-EC4B-48E2-BFC6-03FF5DA06F62}" = Adobe Shockwave Player 11.5
"{3DA41E54-9526-40C0-8456-66B09379DFCC}" = PaintShop Photo Pro X3 Registration Incentive
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{4717BD4A-E16A-41E9-B0D8-0BD931DAED96}" = CommentKahuna
"{491ADA37-04EE-2ECE-9F86-DDC0106047AC}" = Times Reader
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{50316C0A-CC2A-460A-9EA5-F486E54AC17D}_is1" = AVG PC Tuneup
"{51071D66-D034-4239-94E0-723FCA10B6FE}" = OpenOffice.org 3.4
"{53469506-A37E-4314-A9D9-38724EC23A75}" = HP Setup
"{5410C77F-B22F-61FE-7D93-0BEDBC959FF3}" = PX Profile Update
"{5719D840-C30E-7DD3-C746-00B3A5C9BD6B}" = CCC Help Korean
"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411
"{5EDE7E1A-E386-BB8B-CD77-3B5AF9A8D80B}" = CCC Help Greek
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65CB4C08-C47B-4A7E-A6A4-50C06ADA5FC6}" = Adobe AIR
"{670E7FFC-95FF-C425-BD00-91C120352C4B}" = CCC Help Turkish
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A396792-1CA6-E9E5-9844-512238F70C95}" = CCC Help Swedish
"{6B879152-071A-36B4-0F97-37B05552FA05}" = Fast Traffic Sniper
"{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"{6DC6392C-4D8C-D21E-A0DD-750BD76627F6}" = CCC Help Chinese Standard
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.2.0
"{6F44AF95-3CDE-4513-AD3F-6D45F17BF324}" = HP Support Assistant
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74796D37-75F9-C430-CC1D-FCE8371D5EB3}" = CCC Help English
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7AB01508-C2B2-43C8-8B44-514801E7CCC9}" = Jing
"{7CAC6A44-C3DE-4153-ACA6-7524602C789E}" = Facebook Video Calling 1.2.0.159
"{7FBDEEDA-ECDB-A348-0FBC-41AD5D852B36}" = Catalyst Control Center Localization All
"{80F7CA44-F3A5-4853-8BA6-DDF57CD4F078}" = Rosetta Stone Version 3
"{819BD919-5B78-5D29-27AD-765778772B7C}" = Market Samurai
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83E55279-CE70-407F-B34D-EAE0D9C6372B}_is1" = eCover Software Pro
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{8AC3E7BB-F819-379B-3F81-255904B67A8A}" = CCC Help Czech
"{8B4B2F59-1C81-4389-9605-BA273957C24D}_is1" = Content Spin Bot version 1.0
"{8C696008-029B-BBA7-9CD3-45596A069D96}" = CCC Help Polish
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E1CB0F1-67BF-4052-AA23-FA22E94804C1}" = InstallIQ Updater
"{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{91892B48-4503-D842-59A0-842F70503843}" = CCC Help Portuguese
"{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{946B0558-3E7B-D27B-2E95-3A2E99BCB826}" = Catalyst Control Center Graphics Previews Common
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{96B3C2A3-ADD6-4E63-89D3-1E3AC115D3FA}" = pdfforge Toolbar v6.0
"{9902DD1A-58CD-EE2D-1401-EF1D07D3D353}" = CCC Help Japanese
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BBEE625-F639-CB19-6447-98B25FF975DD}" = Traffic Launch Pad
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A44E3886-B7E7-ABA4-57C7-B423992CB536}" = Catalyst Control Center InstallProxy
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAD4E5A4-68CD-7957-81EF-8B50DBA5E939}" = CCC Help Danish
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{AE8289AB-E18C-36E6-BF9B-99557D9F7517}" = Catalyst Control Center Graphics Previews Vista
"{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager
"{B3E2EB86-2EDB-061B-0DDC-58EDBCAEC4A0}" = ASHelper
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{B719C82F-A3AC-ED37-3E2A-947E5A7BA214}" = CCC Help Hungarian
"{B75726EF-847A-6965-0CBF-234BE30604D3}" = Fast Traffic Magnet
"{B92F4DE0-CAFE-404F-B907-19D872CFFD5C}" = Commission Streamer
"{BB1C717E-376C-4AA1-8940-81BFC38D9778}" = HP Quick Launch
"{BD1A34C9-4764-4F79-AE1F-112F8C89D3D4}" = Energy Star Digital Logo
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C5AC39F1-001D-4338-84C6-35109525588A}" = TweetDeck
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C792A75A-2A1F-4991-9B85-291745478A79}" = NetAssistant
"{C7AAB32A-AA73-ECFD-4F43-F41CFA2CD540}" = ccc-core-static
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CFEAD106-F7EB-46B9-8E38-7C86C91F610E}" = CommissionMultiplier
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"{D1612A3D-0DCC-4055-BB6A-0036F31158A0}" = Setup
"{D1AEB5DB-04FA-489D-94EF-8600898B93EE}" = ICA
"{D1F80EFD-A032-4E8E-A367-70C44AD4DCE0}" = ISCOM
"{D3538C4C-8DAF-88CD-55B0-CBF12DECF5A6}" = CCC Help Spanish
"{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D445BE82-2ADA-423D-9CB5-DDFC48E5F6A9}" = Tableau Public 6.1
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D57588F6-2D35-42B5-5C96-4FC3EB3EF7CE}" = CCC Help Russian
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver
"{DA4BF4BE-3CDC-43B5-BBDA-DDDA73103111}" = Corel PaintShop Photo Pro X3
"{DBE31207-21B1-5688-450E-9B958643FD2C}" = CCC Help Norwegian
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DCD941B6-F2E7-4FAF-B102-F7D4DE5FF99A}" = IPM_PSP_Pro
"{DCF1928A-FC01-48E7-A7E6-4651D42EF6A1}" = PSPPRO_DCRAW
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE311B9A-4C1D-C746-264E-DB2A5C6DD2ED}" = CCC Help French
"{DF8B9311-ADE7-4EDE-B121-326CAA3D225D}" = PSPPContent
"{DFC63A26-1EF4-A666-BE94-1DF7351DA7BE}" = CCC Help Dutch
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E38C00D0-A68B-4318-A8A6-F7D4B5B1DF0E}" = Windows Media Encoder 9 Series
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EECD8A88-0030-48F1-9898-882EC02D0353}" = Pin Point Pro 1.0
"{F069C491-69E6-4D9B-9A0C-B7894A1FA97C}" = Setup
"{F072CA07-A781-45E4-9975-C033A73019CF}" = ICA
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F206FEC3-F5DD-43FD-A8CF-9C46B8A6A92C}" = VSPro
"{F4E9851F-765E-40B7-9859-237C2724E62C}" = DeviceIO
"{F6A76E9C-C299-4CFA-AD2A-57FE9DD68B70}" = Contents
"{F8423392-2296-4748-9B66-344432459632}" = PureHD
"{F909BD3C-8684-4ACF-B7C3-33F4F9F901B7}" = Share
"{F95C8C1F-25BB-44EC-A7E6-5C17ABC6BC71}" = VIO
"{FB0B6DDD-DF3E-4CD6-927C-724AB854E322}" = VSClassic
"{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"{FBBCD35F-930F-9B68-7A80-A668A68FE86A}" = CCC Help German
"{FD67D9F3-FED6-4A2E-9D6C-8C8C44DEF8FF}" = IPM_VS_Pro
"{FD9C31B6-F572-414D-81E3-89368C97A125}_is1" = CamStudio OSS Desktop Recorder
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE661711-E392-4B3F-A4A7-02C747C09134}" = ISCOM
"7-Zip" = 7-Zip 9.20
"AA-BestAffiliatePrograms_is1" = Best Affiliate Programs v2.6
"Adobe AIR" = Adobe AIR
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Affiliate ID Manager Master Rebrander_is1" = Affiliate ID Manager Master Rebrander - Version No.1
"Allmyapps" = Allmyapps
"ashelper.ASHelper.46130C60F2252FA5A4446077F84AA968F38F8488.1" = ASHelper
"Atlantis Quest" = Atlantis Quest (remove only)
"Audacity 1.3 Beta (Unicode)_is1" = Audacity 1.3.13 (Unicode)
"Audacity_is1" = Audacity 2.0
"Bejeweled 2 Deluxe" = Bejeweled 2 Deluxe
"BrotherSoft_Extreme Toolbar" = BrotherSoft Extreme Toolbar
"CamStudio" = CamStudio
"CoffeeCup HTML Editor" = CoffeeCup HTML Editor
"com.fastcashcommissions.fasttrafficmagnet" = Fast Traffic Magnet
"com.fastcashcommissions.fasttrafficsniper" = Fast Traffic Sniper
"com.nyt.timesreader.78C54164786ADE80CB31E1C5D95607D0938C987A.1" = Times Reader
"Commission Activator 1.00" = Commission Activator 1.00
"conduitEngine" = Conduit Engine
"Content Magnet Article Extractor_is1" = Content Magnet Article Extractor 1.0
"CoverFactory 2.50_is1" = CoverFactory 2.50
"DVDVideoSoftTB Toolbar" = DVDVideoSoftTB Toolbar
"ExpressZip" = Express Zip File Compression Software
"Fences" = Fences
"Fences Pro" = Fences Pro
"FileZilla Client" = FileZilla Client 3.5.3
"Free Screen Video Recorder_is1" = Free Screen Video Recorder version 2.5.22.508
"Free-Web-Buttons.com" = Free-Web-Buttons.com
"GREENSAMBA32-bit Windows executable" = GreenSamba
"HP Photo Creations" = HP Photo Creations
"IncomeGenesis" = Income Genesis
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{6DAF8CDC-9B04-413B-A0F2-BCC13CF8A5BF}" = HP MediaSmart Photo
"InstallShield_{91A34181-9FAD-43AB-A35F-E7A8945B7E1C}" = HP MediaSmart Music
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{D12E3E7F-1B13-4933-A915-16C7DD37A095}" = HP MediaSmart Video
"InstallShield_{D36DD326-7280-11D8-97C8-000129760CBE}" = PhotoNow!
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"InstallShield_{FB4BB287-37F9-4E27-9C4D-2D3882E08EFF}" = DVD Menu Pack for HP MediaSmart Video
"IObit Malware Fighter_is1" = IObit Malware Fighter
"IrfanView" = IrfanView (remove only)
"Jewel Quest Mysteries: Curse of the Emerald Tear" = Jewel Quest Mysteries: Curse of the Emerald Tear (remove only)
"Jewel Quest: Heritage" = Jewel Quest: Heritage (remove only)
"John Evans Banner Creator_is1" = John Evans Banner Creator v2.01
"Keyword Pad_is1" = Keyword Pad v1.0.112706
"LADSPA_plugins-win_is1" = LADSPA_plugins-win-0.4.15
"LAME for Audacity_is1" = LAME v3.98.3 for Audacity
"LibreOffice" = LibreOffice 3.4
"MAGIX_MSI_Xara3D7" = Xara 3D Maker 7
"MarketSamurai.6E37012E1CBD7F47B14488FCC715944F3EBDCEDC.1" = Market Samurai
"Mozilla Firefox 14.0 (x86 en-US)" = Mozilla Firefox 14.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"My HP Game Console" = HP Game Console
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"PhotoStage" = PhotoStage Slideshow Producer
"Popup Free" = Popup Free (remove only)
"PPT To Flash Catalog Professional_is1" = PPT To Flash Catalog Professional
"SkyCaddieDesktop" = SkyCaddie Desktop
"Software Informer_is1" = Software Informer 1.1
"Solitaire Master 3" = Solitaire Master 3
"The Weather Channel App" = The Weather Channel App
"The Weather Channel Desktop 6" = The Weather Channel Desktop 6
"TheDeanReportCloaker_is1" = TheDeanReportCloaker
"Traffic Travis 4.1 Setup Wizard_is1" = Traffic Travis 4.1.0
"TrafficInitiator-Air" = Traffic Launch Pad
"Video_0" = Video Squeeze Page Generator 1.1
"Wajam" = Wajam
"WebFormDesigner" = WebFormDesigner
"WildTangent hp Master Uninstall" = HP Games
"Windows Media Encoder 9" = Windows Media Encoder 9 Series
"WinLiveSuite" = Windows Live Essentials
"Wisdom-soft Set up ScreenHunter 5.1 Pro" = Wisdom-soft Set up ScreenHunter 5.1 Pro
"Wizard Land" = Wizard Land (remove only)
"WT087328" = Blackhawk Striker 2
"WT087330" = Bounce Symphony
"WT087335" = Build-a-lot 2
"WT087343" = Dora's World Adventure
"WT087360" = Escape Rosecliff Island
"WT087361" = FATE
"WT087362" = Final Drive Nitro
"WT087372" = Heroes of Hellas 2 - Olympia
"WT087379" = Jewel Quest Solitaire 2
"WT087394" = Penguins!
"WT087395" = Poker Superstars III
"WT087396" = Polar Bowler
"WT087397" = Polar Golfer
"WT087414" = Virtual Families
"WT087415" = Wheel of Fortune 2
"WT087428" = Bejeweled 2 Deluxe
"WT087453" = Chuzzle Deluxe
"WT087501" = Plants vs. Zombies
"WT087533" = Zuma Deluxe
"WT087536" = Diner Dash 2 Restaurant Rescue
"WT089299" = Mystery P.I. - The London Caper
"WT089307" = Virtual Villagers 4 - The Tree of Life
"WT089308" = Blasterball 3
"WT089328" = Farm Frenzy
"WT089359" = Cake Mania
"WT089362" = Agatha Christie - Peril at End House
"XHeader" = XHeader
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Software Update" = Yahoo! Software Update
"ZumoDrive" = HP CloudDrive

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"43D873A11E3E6E1C1E31A5977B81928A57E00AD6" = eBay Excel Add-in
"Funmoods Web Search" = Funmoods Web Search
"Google Chrome" = Google Chrome
"HuluDesktop" = Hulu Desktop
"NetAssistant 3.8.3" = Freeze.com NetAssistant

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 4/18/2012 8:41:02 AM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 4/18/2012 7:26:58 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 4/20/2012 11:09:43 AM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 4/21/2012 5:53:03 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 4/22/2012 11:57:47 AM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 4/22/2012 5:54:46 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 4/22/2012 6:46:26 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 4/23/2012 1:53:46 PM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =

Error - 4/23/2012 8:03:55 PM | Computer Name = BradC-BradC-HP | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "c:\program files\microsoft
security client\MSESysprep.dll".Error in manifest or policy file "c:\program files\microsoft
security client\MSESysprep.dll" on line 10. The element imaging appears as a child
of element urn:schemas-microsoft-com:asm.v1^assembly which is not supported by
this version of Windows.

Error - 4/24/2012 11:34:41 AM | Computer Name = BradC-BradC-HP | Source = Customer Experience Improvement Program | ID = 1008
Description =

[ Hewlett-Packard Events ]
Error - 6/10/2011 9:52:26 AM | Computer Name = BradC-BradC-HP | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\061110085217.xml
File not created by asset agent

Error - 9/23/2011 9:48:58 AM | Computer Name = BradC-BradC-HP | Source = Hewlett-Packard | ID = 0
Description = AAProcessExited() C:\ProgramData\Hewlett-Packard\HP Support Framework\Telemetry\091123084855.xml
File not created by asset agent

Error - 1/7/2012 12:11:39 AM | Computer Name = BradC-BradC-HP | Source = HPSFMsgr.exe | ID = 4000
Description = HP Error ID: -2147221164 at System.RuntimeTypeHandle.CreateInstance(RuntimeType
type, Boolean publicOnly, Boolean noCheck, Boolean& canBeCached, RuntimeMethodHandle&
ctor, Boolean& bNeedSecurityCheck) at System.RuntimeType.CreateInstanceSlow(Boolean
publicOnly, Boolean fillCache) at System.RuntimeType.CreateInstanceImpl(Boolean
publicOnly, Boolean skipVisibilityChecks, Boolean fillCache) at System.Activator.CreateInstance(Type
type, Boolean nonPublic) at HPSA_Messenger.MessengerCom.TrayDeskBand.isTaskbarDisplayed()
StackTrace:
at System.RuntimeTypeHandle.CreateInstance(RuntimeType type, Boolean publicOnly,
Boolean noCheck, Boolean& canBeCached, RuntimeMethodHandle& ctor, Boolean& bNeedSecurityCheck)

at System.RuntimeType.CreateInstanceSlow(Boolean publicOnly, Boolean fillCache)

at System.RuntimeType.CreateInstanceImpl(Boolean publicOnly, Boolean skipVisibilityChecks,
Boolean fillCache) at System.Activator.CreateInstance(Type type, Boolean nonPublic)

at HPSA_Messenger.MessengerCom.TrayDeskBand.isTaskbarDisplayed() Source: mscorlib

Name:
HPSFMsgr.exe Version: 01.00.00.00 Path: C:\Program Files (x86)\Hewlett-Packard\HP
Support Framework\Resources\HPSFMessenger\HPSFMsgr.exe Format: en-US RAM: 3893 Ram
Utilization: 30 TargetSite: System.Object CreateInstance(System.RuntimeType, Boolean,
Boolean, Boolean ByRef, System.RuntimeMethodHandle ByRef, Boolean ByRef)

Error - 3/30/2012 8:11:44 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =

Error - 3/30/2012 8:11:44 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =

Error - 3/30/2012 8:12:03 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =

Error - 3/30/2012 8:12:03 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =

Error - 3/31/2012 9:41:34 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =

Error - 4/14/2012 1:21:10 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description =

Error - 6/13/2012 6:38:07 PM | Computer Name = BradC-BradC-HP | Source = HPSF.exe | ID = 4000
Description = HP Error ID: -2146233087 Server stack trace: at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs, TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs) at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessag
e
methodCall, ProxyOperationRuntime operation) at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage
message) Exception rethrown at [0] Message: The server did not provide a meaningful
reply; this might be caused by a contract mismatch, a premature session shutdown
or an internal server error. StackTrace: Server stack trace: at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs, TimeSpan timeout) at System.ServiceModel.Channels.ServiceChannel.Call(String
action, Boolean oneway, ProxyOperationRuntime operation, Object[] ins, Object[]
outs) at System.ServiceModel.Channels.ServiceChannelProxy.InvokeService(IMethodCallMessag
e
methodCall, ProxyOperationRuntime operation) at System.ServiceModel.Channels.ServiceChannelProxy.Invoke(IMessage
message) Exception rethrown at [0]: at System.Runtime.Remoting.Proxies.RealProxy.HandleReturnMessage(IMessage
reqMsg, IMessage retMsg) at System.Runtime.Remoting.Proxies.RealProxy.PrivateInvoke(MessageData&
msgData, Int32 type) at HP.SupportFramework.Communicator.MessengerComm.IMessengerCommunicator.UpdateTime
r()

at HP.SupportAssistant.UI.MessengerCommunication.sendTimerUpdate() Source: mscorlib

Name:
HPSF.exe Version: 06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support
Framework\HPSF.exe Format: en-US RAM: 3893 Ram Utilization: 50 TargetSite: Void HandleReturnMessage(System.Runtime.Remoting.Messaging.IMessage,
System.Runtime.Remoting.Messaging.IMessage)

[ HP Wireless Assistant Events ]
Error - 4/16/2011 12:01:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/16/2011 12:02:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/16/2011 12:03:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/16/2011 12:04:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/16/2011 12:05:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/16/2011 12:06:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/16/2011 12:07:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/16/2011 12:08:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/16/2011 12:09:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

Error - 4/16/2011 12:10:35 PM | Computer Name = BradC-BradC-HP | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The RPC server is unavailable.
(Exception from HRESULT: 0x800706BA) at System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()

[ System Events ]
Error - 7/4/2012 5:15:50 PM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7023
Description = The Microsoft Antimalware Service service terminated with the following
error: %%-2147017840

Error - 7/4/2012 9:03:13 PM | Computer Name = BradC-BradC-HP | Source = Microsoft Antimalware | ID = 5101
Description = %%860 grace period has expired. Protection against viruses, spyware,
and other potentially unwanted software is disabled. Expiration Reason: %%873 Expiration
Date (UTC): ?7/?5/?2012 1:03:13 AM Error Code: 0x80092003 Error Description: An error
occurred while reading or writing to a file.

Error - 7/4/2012 9:03:24 PM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7000
Description = The My Web Search Service service failed to start due to the following
error: %%2

Error - 7/4/2012 9:04:03 PM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7023
Description = The Microsoft Antimalware Service service terminated with the following
error: %%-2147017840

Error - 7/5/2012 10:40:17 AM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7000
Description = The My Web Search Service service failed to start due to the following
error: %%2

Error - 7/5/2012 10:40:20 AM | Computer Name = BradC-BradC-HP | Source = Microsoft Antimalware | ID = 5101
Description = %%860 grace period has expired. Protection against viruses, spyware,
and other potentially unwanted software is disabled. Expiration Reason: %%873 Expiration
Date (UTC): ?7/?5/?2012 2:40:20 PM Error Code: 0x80092003 Error Description: An error
occurred while reading or writing to a file.

Error - 7/5/2012 10:40:58 AM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7023
Description = The Microsoft Antimalware Service service terminated with the following
error: %%-2147017840

Error - 7/6/2012 10:48:58 AM | Computer Name = BradC-BradC-HP | Source = Microsoft Antimalware | ID = 5101
Description = %%860 grace period has expired. Protection against viruses, spyware,
and other potentially unwanted software is disabled. Expiration Reason: %%873 Expiration
Date (UTC): ?7/?6/?2012 2:48:58 PM Error Code: 0x80092003 Error Description: An error
occurred while reading or writing to a file.

Error - 7/6/2012 10:48:58 AM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7000
Description = The My Web Search Service service failed to start due to the following
error: %%2

Error - 7/6/2012 10:49:33 AM | Computer Name = BradC-BradC-HP | Source = Service Control Manager | ID = 7023
Description = The Microsoft Antimalware Service service terminated with the following
error: %%-2147017840


< End of report >
Hello Bcoats and :welcome:

My name is JonTom

  • Malware Logs can sometimes take a lot of time to research and interpret.
  • Please be patient while I try to assist with your problem. If at any time you do not understand what is required, please ask for further explanation.
  • Please note that there is no "Quick Fix" to modern malware infections and we may need to use several different approaches to get your system clean.
  • Read every reply you receive carefully and thoroughly before carrying out the instructions. You may also find it helpful to print out the instructions you receive, as in some instances you may have to disconnect your computer from the Internet.
  • PLEASE NOTE: If you do not reply after 3 days your thread will be closed.

I have both reports on notepad, one is copied. where do I post it?

Your OTL logs are a great start, but I would also like to see a log generated from the following tool before we begin:


  • aswMBR


  • Download aswMBR.exe to your desktop.
  • Double click the aswMBR.exe to run it.
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click the "Scan" button to start scan.

[external image: Posted Image]

  • On completion of the scan click save log, save it to your desktop and post in your next reply.

[external image: Posted Image]

Please post the aswMBR log in your next reply.
Due to lack of response, this topic is now closed. If you are the topic starter and need this topic reopened, please PM a staff member (include the address of this thread in your request). Everyone else please start a new topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI