This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

babylon search bar virus

1 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

hello
i have run the otl scan
here are the results:
thank you!

OTL logfile created on: 28/09/2012 11:06:48 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\dad\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.60 Gb Total Physical Memory | 2.51 Gb Available Physical Memory | 69.81% Memory free
7.20 Gb Paging File | 5.14 Gb Available in Paging File | 71.40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 579.12 Gb Total Space | 546.08 Gb Free Space | 94.30% Space Free | Partition Type: NTFS

Computer Name: DAD-TOSH | User Name: dad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\dad\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\ProgramData\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
PRC - C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)


========== Modules (No Company Name) ==========

MOD - c:\ProgramData\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
MOD - C:\ProgramData\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
MOD - C:\Program Files (x86)\Mozilla Firefox\mozjs.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (mfevtp) – C:\Windows\SysNative\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV:64bit: - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (McODS) – C:\Program Files\mcafee\virusscan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (McAWFwk) – c:\Program Files\mcafee\msc\McAWFwk.exe (McAfee, Inc.)
SRV:64bit: - (MSK80Service) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McProxy) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McOobeSv) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) – C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (TODDSrv) – C:\Windows\SysNative\TODDSrv.exe (TOSHIBA Corporation)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (GFNEXSrv) – C:\Windows\SysNative\GFNEXSrv.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Browser Manager) – C:\ProgramData\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.exe ()
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (0219811348825492mcinstcleanup) – C:\Windows\Temp\0219811348825492mcinst.exe (McAfee, Inc.)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (Partner Service) – C:\ProgramData\Partner\Partner.exe (Google Inc.)
SRV - (NAUpdate) – C:\Program Files (x86)\Nero\Update\NASvc.exe (Nero AG)
SRV - (sftvsa) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftvsa.exe (Microsoft Corporation)
SRV - (sftlist) – C:\Program Files (x86)\Microsoft Application Virtualization Client\sftlist.exe (Microsoft Corporation)
SRV - (TMachInfo) – C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (TemproMonitoringService) – C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe (Toshiba Europe GmbH)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (Fs_Rec) – C:\windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (mfehidk) – C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\Windows\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\Windows\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\Windows\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\Windows\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfenlfk) – C:\Windows\SysNative\drivers\mfenlfk.sys (McAfee, Inc.)
DRV:64bit: - (cfwids) – C:\Windows\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (amdxhc) – C:\Windows\SysNative\drivers\amdxhc.sys (Advanced Micro Devices, INC.)
DRV:64bit: - (amdhub30) – C:\Windows\SysNative\drivers\amdhub30.sys (Advanced Micro Devices, INC.)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (NBVol) – C:\Windows\SysNative\drivers\NBVol.sys (Nero AG)
DRV:64bit: - (NBVolUp) – C:\Windows\SysNative\drivers\NBVolUp.sys (Nero AG)
DRV:64bit: - (Sftvol) – C:\Windows\SysNative\drivers\Sftvollh.sys (Microsoft Corporation)
DRV:64bit: - (Sftplay) – C:\Windows\SysNative\drivers\Sftplaylh.sys (Microsoft Corporation)
DRV:64bit: - (Sftredir) – C:\Windows\SysNative\drivers\Sftredirlh.sys (Microsoft Corporation)
DRV:64bit: - (Sftfs) – C:\Windows\SysNative\drivers\Sftfslh.sys (Microsoft Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (RTL8192Ce) – C:\Windows\SysNative\drivers\rtl8192ce.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (PGEffect) – C:\Windows\SysNative\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (tdcmdpst) – C:\Windows\SysNative\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV:64bit: - (TVALZ) – C:\Windows\SysNative\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (TVALZFL) – C:\Windows\SysNative\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=ironp…p;cr=1507131091
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {16DB1BEF-D876-4650-BBD3-E43DA2B766B1}
IE:64bit: - HKLM\..\SearchScopes\{16DB1BEF-D876-4650-BBD3-E43DA2B766B1}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1507131091
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=ironp…p;cr=1507131091
IE - HKLM\..\SearchScopes,Backup.Old.DefaultScope = {16DB1BEF-D876-4650-BBD3-E43DA2B766B1}
IE - HKLM\..\SearchScopes,DefaultScope = {16DB1BEF-D876-4650-BBD3-E43DA2B766B1}
IE - HKLM\..\SearchScopes\{0FF1476E-CFFD-ECAB-23FF-1C75D9147DBF}: "URL" = http://www.google.com/search?sourceid=ie7&…mp;rlz=1I7TEUA;
IE - HKLM\..\SearchScopes\{16DB1BEF-D876-4650-BBD3-E43DA2B766B1}: "URL" = http://start.funmoods.com/results.php?f=4&…p;cr=1507131091

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Backup.Old.Start Page = http://search.babylon.com/?affID=114336&am;…0004c72b99c796d
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,BrowserMngr Start Page = http://search.babylon.com/?affID=114336&am;…0004c72b99c796d
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…A&bmod=TEUA
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.funmoods.com/?f=1&a=ironp…p;cr=1507131091
IE - HKCU\..\SearchScopes,Backup.Old.DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,BrowserMngrDefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes,DefaultScope = {0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}
IE - HKCU\..\SearchScopes\{0ECDF796-C2DC-4d79-A620-CCE0C0A66CC9}: "URL" = http://search.babylon.com/?q={searchTerms}…0004c72b99c796d
IE - HKCU\..\SearchScopes\{0FF1476E-CFFD-ECAB-23FF-1C75D9147DBF}: "URL" = http://search.babylon.com/?q={searchTerms}…0004c72b99c796d
IE - HKCU\..\SearchScopes\{16DB1BEF-D876-4650-BBD3-E43DA2B766B1}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7TEUA_enGB503
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF64_11_4_402_278.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Nero.com/KM: C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL (Nero AG)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/09/28 10:42:51 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/09/26 12:44:18 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{b64982b1-d112-42b5-b1e4-d3867c4533f8}: C:\ProgramData\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\FirefoxExtension [2012/09/26 11:53:51 | 000,000,000 | —D | M]

[2012/09/26 12:44:45 | 000,000,000 | —D | M] (No name found) – C:\Users\dad\AppData\Roaming\Mozilla\Extensions
[2012/09/28 01:04:44 | 000,000,000 | —D | M] (No name found) – C:\Users\dad\AppData\Roaming\Mozilla\Firefox\Profiles\dz5vh7u4.default-1348786683277\Extensions
[2012/09/26 12:44:18 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/09/06 02:27:05 | 000,266,720 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/06 02:26:22 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/09/06 02:26:22 | 000,002,253 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - homepage: http://www.google.com/ig/redirectdomain?br…A&bmod=TEUA
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://www.google.com/ig/redirectdomain?br…A&bmod=TEUA
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32_11_4_402_278.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\22.0.1229.79\pdf.dll
CHR - plugin: Babylon ToolBar (Enabled) = C:\Users\dad\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.8_0\BabylonChromeToolBar.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Java Deployment Toolkit 6.0.300.12 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java™ Platform SE 6 U30 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Nero Kwik Media Helper (Enabled) = C:\PROGRA~2\COMMON~1\Nero\BROWSE~1\NPBROW~1.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.50401.0\npctrl.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\progra~2\mcafee\msc\npmcsn~1.dll
CHR - Extension: Funmoods = C:\Users\dad\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbjciahceamgodcoidkjpchnokgfpphh\1.0_0\
CHR - Extension: SpeedDial = C:\Users\dad\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\4.0\
CHR - Extension: SpeedDial = C:\Users\dad\AppData\Local\Google\Chrome\User Data\Default\Extensions\cjpglkicenollcignonpgiafdgfeehoj\4.0_0\
CHR - Extension: Babylon Toolbar = C:\Users\dad\AppData\Local\Google\Chrome\User Data\Default\Extensions\dhkplhfnhceodhffomolpfigojocbpcb\1.8_0\

O1 HOSTS File: ([2009/06/10 22:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20120926162535.dll (McAfee, Inc.)
O2:64bit: - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2 - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2 - BHO: (Funmoods Helper Object) - {75EBB0AA-4214-4CB4-90EC-E3E07ECD04F7} - C:\Program Files (x86)\Funmoods\1.5.23.22\bh\escort.dll (Funmoods BHO)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20120926162536.dll (McAfee, Inc.)
O2 - BHO: (Partner BHO Class) - {83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4} - C:\ProgramData\Partner\Partner.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Funmoods Toolbar) - {A4C272EC-ED9E-4ACE-A6F2-9558C7F29EF3} - C:\Program Files (x86)\Funmoods\1.5.23.22\escorTlbr.dll (Funmoods)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [] File not found
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [SRS Premium Sound HD] C:\Program Files\SRS Labs\SRS Control Panel\SRSPanel_64.exe (SRS Labs, Inc.)
O4:64bit: - HKLM..\Run: [TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [Toshiba Registration] C:\Program Files\TOSHIBA\Registration\ToshibaReminder.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [Toshiba TEMPRO] C:\Program Files (x86)\Toshiba TEMPRO\TemproTray.exe (Toshiba Europe GmbH)
O4:64bit: - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosVolRegulator] C:\Program Files\TOSHIBA\TosVolRegulator\TosVolRegulator.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4:64bit: - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [NBAgent] C:\Program Files (x86)\Nero\Nero 11\Nero BackItUp\NBAgent.exe (Nero AG)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [ToshibaServiceStation] C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe (TOSHIBA Corporation)
O4 - HKCU..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe (TOSHIBA)
O4 - Startup: C:\Users\dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (TOSHIBA Europe)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_30)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{5878A972-4ABE-4426-AC6F-361823F0D5E6}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
O18:64bit: - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18:64bit: - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O20 - AppInit_DLLs: (c:\progra~3\browse~1\22643~1.41\{16cdf~1\browse~1.dll) - c:\ProgramData\Browser Manager\2.2.643.41\{16cdff19-861d-48e3-a751-d99a27784753}\browsemngr.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\windows\SysWow64\iccvid.dll (Radius Inc.)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/09/28 10:50:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/09/28 03:36:39 | 000,000,000 | —D | C] – C:\windows\SysWow64\Wat
[2012/09/28 03:36:38 | 000,000,000 | —D | C] – C:\windows\SysNative\Wat
[2012/09/28 02:31:59 | 000,294,912 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\browserchoice.exe
[2012/09/28 02:00:31 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\mshtmled.dll
[2012/09/28 02:00:31 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\mshtmled.dll
[2012/09/28 02:00:29 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieui.dll
[2012/09/28 02:00:29 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\url.dll
[2012/09/28 02:00:29 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieui.dll
[2012/09/28 02:00:29 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ieUnatt.exe
[2012/09/28 02:00:29 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ieUnatt.exe
[2012/09/28 02:00:28 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\url.dll
[2012/09/28 02:00:27 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript9.dll
[2012/09/28 02:00:27 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\inetcpl.cpl
[2012/09/28 02:00:27 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\inetcpl.cpl
[2012/09/28 02:00:26 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msfeeds.dll
[2012/09/28 02:00:23 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\jscript.dll
[2012/09/28 02:00:23 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\vbscript.dll
[2012/09/28 02:00:22 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\jscript.dll
[2012/09/28 01:47:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Skype
[2012/09/28 01:47:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Skype
[2012/09/28 01:47:20 | 000,000,000 | R–D | C] – C:\Program Files (x86)\Skype
[2012/09/28 01:30:42 | 000,000,000 | -HSD | C] – C:\Config.Msi
[2012/09/28 01:28:27 | 000,081,408 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\imagehlp.dll
[2012/09/28 01:28:27 | 000,023,408 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\fs_rec.sys
[2012/09/28 01:28:26 | 000,220,672 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wintrust.dll
[2012/09/27 23:58:10 | 000,000,000 | —D | C] – C:\Users\dad\Desktop\Old Firefox Data-1
[2012/09/27 22:38:58 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\Malwarebytes
[2012/09/27 22:38:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/27 22:37:55 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2012/09/27 22:37:50 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\windows\SysNative\drivers\mbam.sys
[2012/09/27 22:37:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/09/27 22:14:05 | 000,000,000 | —D | C] – C:\Users\dad\Desktop\Old Firefox Data
[2012/09/27 21:43:53 | 000,000,000 | —D | C] – C:\Users\dad\P5JavaClientSettings
[2012/09/27 21:43:39 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Local\P5
[2012/09/27 21:43:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Betfair Poker
[2012/09/27 21:43:29 | 000,000,000 | —D | C] – C:\Betfair
[2012/09/27 17:41:56 | 000,077,906 | —- | C] (Lexmark International) – C:\windows\SysWow64\lxdxcfg.dll
[2012/09/27 17:41:55 | 000,065,536 | —- | C] (Lexmark International) – C:\windows\SysNative\lxdxcfg64.dll
[2012/09/27 08:22:19 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\netapi32.dll
[2012/09/27 08:22:19 | 000,059,392 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\browcli.dll
[2012/09/27 08:22:18 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\browcli.dll
[2012/09/27 08:21:41 | 001,544,704 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\DWrite.dll
[2012/09/27 08:21:35 | 000,503,808 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\srcore.dll
[2012/09/27 08:21:17 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\msxml3r.dll
[2012/09/27 08:21:17 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msxml3r.dll
[2012/09/27 08:20:40 | 000,041,472 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\RNDISMP.sys
[2012/09/27 08:20:33 | 000,574,464 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\d3d10level9.dll
[2012/09/27 08:20:20 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ncrypt.dll
[2012/09/27 08:20:11 | 000,376,688 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\netio.sys
[2012/09/27 08:20:10 | 000,288,624 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\drivers\FWPKCLNT.SYS
[2012/09/27 08:19:32 | 005,559,664 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\ntoskrnl.exe
[2012/09/27 08:19:30 | 003,913,072 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntoskrnl.exe
[2012/09/27 08:19:29 | 003,968,368 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\ntkrnlpa.exe
[2012/09/27 08:19:22 | 000,245,760 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\OxpsConverter.exe
[2012/09/27 08:17:33 | 000,956,928 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\localspl.dll
[2012/09/27 08:17:09 | 003,216,384 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\msi.dll
[2012/09/27 08:16:49 | 001,462,272 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\crypt32.dll
[2012/09/27 08:16:48 | 000,140,288 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\cryptnet.dll
[2012/09/27 08:10:30 | 000,805,376 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\cdosys.dll
[2012/09/27 08:10:25 | 001,133,568 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\cdosys.dll
[2012/09/26 17:20:24 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Local\Microsoft Games
[2012/09/26 13:55:44 | 000,000,000 | —D | C] – C:\ProgramData\VirtualizedApplications
[2012/09/26 12:58:26 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Local\Macromedia
[2012/09/26 12:53:11 | 000,000,000 | —D | C] – C:\Users\dad\Documents\iMacros
[2012/09/26 12:44:31 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\Mozilla
[2012/09/26 12:44:31 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Local\Mozilla
[2012/09/26 12:44:21 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2012/09/26 12:44:20 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2012/09/26 12:43:23 | 000,000,000 | —D | C] – C:\Program Files (x86)\Funmoods
[2012/09/26 11:54:17 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
[2012/09/26 11:54:15 | 000,000,000 | —D | C] – C:\rei
[2012/09/26 11:54:07 | 000,000,000 | —D | C] – C:\Program Files\Reimage
[2012/09/26 11:53:56 | 000,000,000 | —D | C] – C:\windows\SysWow64\Extensions
[2012/09/26 11:53:56 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Browser Manager
[2012/09/26 11:53:55 | 000,000,000 | —D | C] – C:\windows\SysWow64\searchplugins
[2012/09/26 11:53:48 | 000,000,000 | —D | C] – C:\ProgramData\Browser Manager
[2012/09/26 11:53:37 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/09/26 11:53:15 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\Babylon
[2012/09/26 11:53:15 | 000,000,000 | —D | C] – C:\ProgramData\Babylon
[2012/09/26 11:45:47 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\Google
[2012/09/26 11:45:45 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Local\Google
[2012/09/26 11:40:10 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Local\SoftGrid Client
[2012/09/26 11:40:08 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\SoftGrid Client
[2012/09/26 11:39:39 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office Starter (English)
[2012/09/26 11:38:14 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\DESIGNER
[2012/09/26 11:38:13 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Office
[2012/09/26 11:38:12 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Application Virtualization Client
[2012/09/26 11:37:17 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\TP
[2012/09/26 11:31:35 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\ATI
[2012/09/26 11:31:35 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Local\ATI
[2012/09/26 11:31:32 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\Toshiba
[2012/09/26 11:31:22 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Local\TOSHIBA
[2012/09/26 11:31:22 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Local\SRS Labs
[2012/09/26 11:30:53 | 000,000,000 | R–D | C] – C:\Users\dad\Searches
[2012/09/26 11:30:53 | 000,000,000 | R–D | C] – C:\Users\dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/09/26 11:30:52 | 000,000,000 | -H-D | C] – C:\Users\dad\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/09/26 11:30:41 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\Identities
[2012/09/26 11:30:36 | 000,000,000 | R–D | C] – C:\Users\dad\Contacts
[2012/09/26 11:30:03 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eBay
[2012/09/26 11:29:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Amazon
[2012/09/26 11:29:33 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\WinBatch
[2012/09/26 11:29:27 | 001,031,680 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\rdpcore.dll
[2012/09/26 11:29:26 | 000,826,880 | —- | C] (Microsoft Corporation) – C:\windows\SysWow64\rdpcore.dll
[2012/09/26 11:29:06 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Local\VirtualStore
[2012/09/26 11:28:57 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\Macromedia
[2012/09/26 11:28:53 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Local\Adobe
[2012/09/26 11:28:52 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\Adobe
[2012/09/26 11:23:49 | 002,622,464 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wucltux.dll
[2012/09/26 11:23:49 | 000,057,880 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wuauclt.exe
[2012/09/26 11:23:49 | 000,044,056 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wups2.dll
[2012/09/26 11:23:26 | 000,701,976 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wuapi.dll
[2012/09/26 11:23:26 | 000,099,840 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wudriver.dll
[2012/09/26 11:23:26 | 000,038,424 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wups.dll
[2012/09/26 11:23:12 | 000,186,752 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wuwebv.dll
[2012/09/26 11:23:12 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\windows\SysNative\wuapp.exe
[2012/09/26 11:21:30 | 000,000,000 | —D | C] – C:\ProgramData\ToshibaEurope
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\AppData\Local\Temporary Internet Files
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\Templates
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\Start Menu
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\SendTo
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\Recent
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\PrintHood
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\NetHood
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\Documents\My Videos
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\Documents\My Pictures
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\Documents\My Music
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\My Documents
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\Local Settings
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\AppData\Local\History
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\Cookies
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\Application Data
[2012/09/26 11:18:55 | 000,000,000 | -HSD | C] – C:\Users\dad\AppData\Local\Application Data
[2012/09/26 11:18:54 | 000,000,000 | –SD | C] – C:\Users\dad\AppData\Roaming\Microsoft
[2012/09/26 11:18:54 | 000,000,000 | R–D | C] – C:\Users\dad\Videos
[2012/09/26 11:18:54 | 000,000,000 | R–D | C] – C:\Users\dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/09/26 11:18:54 | 000,000,000 | R–D | C] – C:\Users\dad\Saved Games
[2012/09/26 11:18:54 | 000,000,000 | R–D | C] – C:\Users\dad\Pictures
[2012/09/26 11:18:54 | 000,000,000 | R–D | C] – C:\Users\dad\Music
[2012/09/26 11:18:54 | 000,000,000 | R–D | C] – C:\Users\dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/09/26 11:18:54 | 000,000,000 | R–D | C] – C:\Users\dad\Links
[2012/09/26 11:18:54 | 000,000,000 | R–D | C] – C:\Users\dad\Favorites
[2012/09/26 11:18:54 | 000,000,000 | R–D | C] – C:\Users\dad\Downloads
[2012/09/26 11:18:54 | 000,000,000 | R–D | C] – C:\Users\dad\Documents
[2012/09/26 11:18:54 | 000,000,000 | R–D | C] – C:\Users\dad\Desktop
[2012/09/26 11:18:54 | 000,000,000 | R–D | C] – C:\Users\dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/09/26 11:18:54 | 000,000,000 | -H-D | C] – C:\Users\dad\AppData
[2012/09/26 11:18:54 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Local\Temp
[2012/09/26 11:18:54 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Local\Microsoft
[2012/09/26 11:18:54 | 000,000,000 | —D | C] – C:\Users\dad\AppData\Roaming\Media Center Programs

========== Files - Modified Within 30 Days ==========

[2012/09/28 10:57:05 | 000,000,912 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/28 10:53:07 | 000,024,400 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/28 10:53:07 | 000,024,400 | -H– | M] () – C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/28 10:51:46 | 000,727,182 | —- | M] () – C:\windows\SysNative\PerfStringBackup.INI
[2012/09/28 10:51:46 | 000,628,904 | —- | M] () – C:\windows\SysNative\perfh009.dat
[2012/09/28 10:51:46 | 000,110,798 | —- | M] () – C:\windows\SysNative\perfc009.dat
[2012/09/28 10:50:14 | 000,001,839 | —- | M] () – C:\Users\Public\Desktop\McAfee Internet Security.lnk
[2012/09/28 10:45:26 | 000,000,908 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/28 10:43:17 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2012/09/28 10:43:16 | 000,274,320 | —- | M] () – C:\windows\SysNative\FNTCACHE.DAT
[2012/09/28 10:42:56 | 2899,075,072 | -HS- | M] () – C:\hiberfil.sys
[2012/09/28 02:39:44 | 000,000,830 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2012/09/28 02:02:28 | 000,735,230 | —- | M] () – C:\windows\SysWow64\PerfStringBackup.INI
[2012/09/27 22:38:07 | 000,001,124 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/27 21:43:32 | 000,001,478 | —- | M] () – C:\Users\dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Betfair Poker.lnk
[2012/09/27 21:43:32 | 000,001,452 | —- | M] () – C:\Users\Public\Desktop\Betfair Poker.lnk
[2012/09/26 19:15:30 | 000,108,227 | —- | M] () – C:\windows\SysWow64\license.rtf
[2012/09/26 19:15:30 | 000,108,227 | —- | M] () – C:\windows\SysNative\license.rtf
[2012/09/26 17:20:23 | 000,001,272 | —- | M] () – C:\Users\dad\Desktop\Snipping Tool.lnk
[2012/09/26 12:56:02 | 000,696,240 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerApp.exe
[2012/09/26 12:56:02 | 000,073,136 | —- | M] (Adobe Systems Incorporated) – C:\windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/09/26 12:44:23 | 000,001,145 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/09/26 12:43:22 | 000,384,844 | —- | M] () – C:\Users\dad\AppData\Local\funmoods-speeddial.crx
[2012/09/26 12:43:22 | 000,031,465 | —- | M] () – C:\Users\dad\AppData\Local\funmoods.crx
[2012/09/26 11:55:10 | 000,000,286 | —- | M] () – C:\windows\reimage.ini
[2012/09/26 11:54:18 | 000,001,912 | —- | M] () – C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
[2012/09/26 11:53:42 | 000,000,315 | —- | M] () – C:\user.js
[2012/09/26 11:45:31 | 000,001,452 | —- | M] () – C:\Users\dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/09/26 11:30:12 | 000,001,884 | —- | M] () – C:\Users\Public\Desktop\Toshiba Warranty Registration.lnk
[2012/09/26 11:30:04 | 000,000,514 | —- | M] () – C:\Users\Public\Desktop\eBay.lnk
[2012/09/07 17:04:46 | 000,025,928 | —- | M] (Malwarebytes Corporation) – C:\windows\SysNative\drivers\mbam.sys

========== Files Created - No Company Name ==========

[2012/09/27 22:38:07 | 000,001,124 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/27 21:43:32 | 000,001,478 | —- | C] () – C:\Users\dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Betfair Poker.lnk
[2012/09/27 21:43:32 | 000,001,452 | —- | C] () – C:\Users\Public\Desktop\Betfair Poker.lnk
[2012/09/27 17:41:57 | 000,782,336 | —- | C] () – C:\windows\SysWow64\lxdxdrs.dll
[2012/09/27 17:41:57 | 000,081,920 | —- | C] () – C:\windows\SysWow64\lxdxcaps.dll
[2012/09/27 17:41:57 | 000,069,632 | —- | C] () – C:\windows\SysWow64\lxdxcnv4.dll
[2012/09/27 17:41:56 | 001,024,512 | —- | C] () – C:\windows\SysNative\lxdxdrs64.dll
[2012/09/27 17:41:56 | 000,054,784 | —- | C] () – C:\windows\SysNative\lxdxcnv464.dll
[2012/09/27 17:41:56 | 000,025,600 | —- | C] () – C:\windows\SysNative\lxdxcaps64.dll
[2012/09/26 17:20:23 | 000,001,272 | —- | C] () – C:\Users\dad\Desktop\Snipping Tool.lnk
[2012/09/26 12:44:23 | 000,001,157 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2012/09/26 12:44:23 | 000,001,145 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/09/26 12:43:29 | 000,384,844 | —- | C] () – C:\Users\dad\AppData\Local\funmoods-speeddial.crx
[2012/09/26 12:43:27 | 000,031,465 | —- | C] () – C:\Users\dad\AppData\Local\funmoods.crx
[2012/09/26 11:54:53 | 000,000,286 | —- | C] () – C:\windows\reimage.ini
[2012/09/26 11:54:18 | 000,001,912 | —- | C] () – C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
[2012/09/26 11:53:41 | 000,000,315 | —- | C] () – C:\user.js
[2012/09/26 11:45:31 | 000,001,452 | —- | C] () – C:\Users\dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/09/26 11:38:35 | 000,735,230 | —- | C] () – C:\windows\SysWow64\PerfStringBackup.INI
[2012/09/26 11:30:56 | 000,001,458 | —- | C] () – C:\Users\dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/09/26 11:30:12 | 000,001,884 | —- | C] () – C:\Users\Public\Desktop\Toshiba Warranty Registration.lnk
[2012/09/26 11:30:04 | 000,000,514 | —- | C] () – C:\Users\Public\Desktop\eBay.lnk
[2012/09/26 11:18:54 | 000,001,258 | —- | C] () – C:\Users\dad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TRDCReminder.lnk
[2012/09/26 11:18:54 | 000,000,290 | —- | C] () – C:\Users\dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/09/26 11:18:54 | 000,000,272 | —- | C] () – C:\Users\dad\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/08/29 09:02:16 | 000,128,312 | —- | C] () – C:\windows\SysWow64\GFNEX.dll
[2012/08/29 08:55:26 | 000,451,072 | —- | C] () – C:\windows\SysWow64\ISSRemoveSP.exe
[2012/08/29 08:42:48 | 000,000,000 | —- | C] () – C:\windows\ativpsrm.bin
[2012/08/29 08:39:34 | 000,204,960 | —- | C] () – C:\windows\SysWow64\ativvsvl.dat
[2012/08/29 08:39:34 | 000,157,152 | —- | C] () – C:\windows\SysWow64\ativvsva.dat
[2012/08/29 08:39:34 | 000,003,917 | —- | C] () – C:\windows\SysWow64\atipblag.dat
[2012/03/06 20:59:00 | 000,059,904 | —- | C] () – C:\windows\SysWow64\OpenVideo.dll
[2012/03/06 20:58:52 | 000,054,784 | —- | C] () – C:\windows\SysWow64\OVDecode.dll

========== ZeroAccess Check ==========

[2009/07/14 05:55:00 | 000,000,227 | RHS- | M] () – C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/09 06:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 05:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/14 02:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/21 04:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/14 02:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/09/26 11:53:15 | 000,000,000 | —D | M] – C:\Users\dad\AppData\Roaming\Babylon
[2012/09/26 14:06:46 | 000,000,000 | —D | M] – C:\Users\dad\AppData\Roaming\SoftGrid Client
[2012/09/26 11:31:32 | 000,000,000 | —D | M] – C:\Users\dad\AppData\Roaming\Toshiba
[2012/09/26 11:40:23 | 000,000,000 | —D | M] – C:\Users\dad\AppData\Roaming\TP
[2012/09/26 11:29:33 | 000,000,000 | —D | M] – C:\Users\dad\AppData\Roaming\WinBatch

========== Purity Check ==========



========== Custom Scans ==========

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/11/21 08:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 21:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/02/26 06:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 07:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 07:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/21 04:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 06:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/21 04:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 08:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 08:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010/11/21 08:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010/11/21 08:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: IEXPLORE.EXE >
[2012/08/24 08:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2012/08/24 08:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012/08/24 12:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Program Files\Internet Explorer\iexplore.exe
[2012/08/24 12:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/08/24 11:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/08/24 08:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2010/11/21 04:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2012/04/09 02:15:41 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2010/11/21 04:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2012/04/09 02:15:37 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2012/04/09 02:17:45 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=0D0D3FBDCC9B60985C654ABB0159D79E – C:\Program Files\Internet Explorer\fi-FI\iexplore.exe.mui
[2012/04/09 02:17:45 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=0D0D3FBDCC9B60985C654ABB0159D79E – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_fi-fi_a5e791a3ad57af35\iexplore.exe.mui
[2012/04/09 02:15:39 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/04/09 02:15:39 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2012/04/09 02:16:45 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=1B6E8A273EC843E3FA1666B2411FCB06 – C:\Program Files (x86)\Internet Explorer\da-DK\iexplore.exe.mui
[2012/04/09 02:16:45 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=1B6E8A273EC843E3FA1666B2411FCB06 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_da-dk_6b396f2ffbc32d02\iexplore.exe.mui
[2012/04/09 02:17:45 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=3E974B0251FC913BEAE750D71C87B51B – C:\Program Files (x86)\Internet Explorer\fi-FI\iexplore.exe.mui
[2012/04/09 02:17:45 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=3E974B0251FC913BEAE750D71C87B51B – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_fi-fi_b03c3bf5e1b87130\iexplore.exe.mui
[2012/04/09 02:15:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2012/04/09 02:15:41 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2012/04/09 02:18:38 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=51F45B445FE49963B51B357E9EBD8928 – C:\Program Files (x86)\Internet Explorer\nb-NO\iexplore.exe.mui
[2012/04/09 02:18:38 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=51F45B445FE49963B51B357E9EBD8928 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_nb-no_cc22808574537f93\iexplore.exe.mui
[2012/04/09 02:19:38 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=83AECEB4AD4364B2A40EEF3F64362F3B – C:\Program Files (x86)\Internet Explorer\sv-SE\iexplore.exe.mui
[2012/04/09 02:19:38 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=83AECEB4AD4364B2A40EEF3F64362F3B – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_sv-se_f671dc8e34a59363\iexplore.exe.mui
[2012/04/09 02:16:45 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8A67D9DE18290636561144461BE88649 – C:\Program Files\Internet Explorer\da-DK\iexplore.exe.mui
[2012/04/09 02:16:45 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8A67D9DE18290636561144461BE88649 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_da-dk_60e4c4ddc7626b07\iexplore.exe.mui
[2009/07/14 03:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2012/04/09 02:18:38 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=CCF70AF9FEBE4923212B94182CA1EA84 – C:\Program Files\Internet Explorer\nb-NO\iexplore.exe.mui
[2012/04/09 02:18:38 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=CCF70AF9FEBE4923212B94182CA1EA84 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_nb-no_c1cdd6333ff2bd98\iexplore.exe.mui
[2012/04/09 02:19:37 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=EC718F3D3165C3484933D62ED0DC40E4 – C:\Program Files\Internet Explorer\sv-SE\iexplore.exe.mui
[2012/04/09 02:19:37 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=EC718F3D3165C3484933D62ED0DC40E4 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_sv-se_ec1d323c0044d168\iexplore.exe.mui
[2009/07/14 03:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 22:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.ASFX >
[2011/06/06 20:55:42 | 000,000,638 | —- | M] () MD5=197B3B6830C016740F873E56C3F9C9BD – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\Services\Services.asfx
[2011/06/06 20:55:40 | 000,000,613 | —- | M] () MD5=1C7E1663AE424309CB3F78D7541BECEB – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\hr_HR\Services\Services.asfx
[2011/06/06 20:55:34 | 000,000,610 | —- | M] () MD5=1F083E63820945BD3B0A1EC89DC337F3 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fi_FI\Services\Services.asfx
[2011/06/06 20:55:32 | 000,000,622 | —- | M] () MD5=227C5D88D93A46BAA21CF25428ECC9D9 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sv_SE\Services\Services.asfx
[2011/06/06 20:55:32 | 000,000,634 | —- | M] () MD5=2510B37D21D2D7451DA5B80A31D7C99C – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\Services\Services.asfx
[2011/06/06 20:55:40 | 000,000,640 | —- | M] () MD5=3D687325BB9CDD27A998D6CA1977D14A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ro_RO\Services\Services.asfx
[2011/06/06 20:55:36 | 000,000,623 | —- | M] () MD5=52ACBF140935AA1FB30604EF26B3479C – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\Services\Services.asfx
[2011/06/06 20:55:36 | 000,000,614 | —- | M] () MD5=5EC6989CA1C72DC926A4A8DB4C0B440D – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Services\Services.asfx
[2011/06/06 20:55:40 | 000,000,620 | —- | M] () MD5=5F22C5924E86C6EE6F824DE286612180 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sl_SI\Services\Services.asfx
[2011/06/06 20:55:40 | 000,000,701 | —- | M] () MD5=5F25C1E01D5365CB9548DEFAD0DA9521 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ru_RU\Services\Services.asfx
[2011/06/06 20:55:32 | 000,000,652 | —- | M] () MD5=7008C9B2FC0E047237AFED998171E9A9 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ja_JP\Services\Services.asfx
[2011/06/06 20:55:36 | 000,000,602 | —- | M] () MD5=807E858DB39D1DADD1A7CDA0EB195902 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\zh_CN\Services\Services.asfx
[2011/06/06 20:55:40 | 000,000,720 | —- | M] () MD5=84B28361A585B9D3A8EE54A1C30D6B11 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\uk_UA\Services\Services.asfx
[2011/06/06 20:55:36 | 000,000,606 | —- | M] () MD5=85ED839825A89D69775A00386106F9E0 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\zh_TW\Services\Services.asfx
[2011/06/06 20:55:34 | 000,000,599 | —- | M] () MD5=8CEF86FF4BBA687F844CDD2FBC9E2901 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\Services\Services.asfx
[2011/06/06 20:55:42 | 000,000,632 | —- | M] () MD5=9FA4734C677692C2F9EF2B5277D6A66E – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sk_SK\Services\Services.asfx
[2011/06/06 20:55:32 | 000,000,639 | —- | M] () MD5=ACB64CA3772E9660F72E9E4A6ABF595C – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fr_FR\Services\Services.asfx
[2011/06/06 20:55:34 | 000,000,662 | —- | M] () MD5=AE0C9C7B50D793C33D610A6E58C2897C – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ko_KR\Services\Services.asfx
[2011/06/06 20:55:34 | 000,000,610 | —- | M] () MD5=B9C20B8684DFBAC54EDED5B4B674CA9C – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\nb_NO\Services\Services.asfx
[2011/06/06 20:55:32 | 000,000,627 | —- | M] () MD5=C25DC0D9A0098C3677CBC8AACADA1472 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\de_DE\Services\Services.asfx
[2011/06/06 20:55:38 | 000,000,628 | —- | M] () MD5=C54E7077434A62D51661295A250C8504 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\hu_HU\Services\Services.asfx
[2011/06/06 20:55:34 | 000,000,627 | —- | M] () MD5=CAFB055D206C2CBB122959A241668296 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\nl_NL\Services\Services.asfx
[2011/06/06 20:55:40 | 000,000,607 | —- | M] () MD5=CEAFFF352B8A0C30C27972EE98C34780 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\tr_TR\Services\Services.asfx
[2011/06/06 20:55:32 | 000,000,614 | —- | M] () MD5=DCAF5E14A41328B2A5976377D7DDD969 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\it_IT\Services\Services.asfx
[2011/06/06 20:55:42 | 000,000,616 | —- | M] () MD5=DED22EDA27D78427FE48AE13E566C201 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\Services\Services.asfx
[2010/11/15 20:02:32 | 000,000,228 | R— | M] () MD5=E09422BE0C7636A7B63A1527C4C1372D – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx
[2011/06/06 20:55:34 | 000,000,636 | —- | M] () MD5=E1EA7707C24F5A84850D5659CA376594 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pt_BR\Services\Services.asfx

< MD5 for: SERVICES.ASFX1 >
[2010/11/15 20:02:32 | 000,000,228 | R— | M] () MD5=A7B7A4CC1A717292474115CD3A4AC121 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx1

< MD5 for: SERVICES.ASFX10 >
[2010/11/15 20:02:34 | 000,000,233 | R— | M] () MD5=3382FAB54FC906B0E40269D903A8D690 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx10

< MD5 for: SERVICES.ASFX11 >
[2010/11/15 20:02:26 | 000,000,227 | R— | M] () MD5=F36865AB3B9813962B7EDBE66FA1C28A – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx11

< MD5 for: SERVICES.ASFX12 >
[2010/11/15 20:02:30 | 000,000,225 | R— | M] () MD5=9287C7268CC0F37F1DDE18CEBB128685 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx12

< MD5 for: SERVICES.ASFX13 >
[2010/11/15 20:02:30 | 000,000,228 | R— | M] () MD5=95326C46AC2654AFF5C8543DFE22CCB3 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx13

< MD5 for: SERVICES.ASFX14 >
[2010/11/15 20:02:26 | 000,000,228 | R— | M] () MD5=14DA84ECAF57B5ADA36B9093FF04CF32 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx14

< MD5 for: SERVICES.ASFX15 >
[2010/11/15 20:02:26 | 000,000,231 | R— | M] () MD5=CF94F061685A38BABE0BBD463191EDE7 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx15

< MD5 for: SERVICES.ASFX16 >
[2010/11/15 20:02:34 | 000,000,232 | R— | M] () MD5=B6E63D87C73CED2D6B433C542C5C3965 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx16

< MD5 for: SERVICES.ASFX17 >
[2010/11/15 20:02:34 | 000,000,230 | R— | M] () MD5=545E97C4F4CEA743A8D86B685EE2EDBB – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx17

< MD5 for: SERVICES.ASFX18 >
[2010/11/15 20:02:24 | 000,000,230 | R— | M] () MD5=2577B66F38E0DEA25F328DA4A0FED322 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx18

< MD5 for: SERVICES.ASFX19 >
[2010/11/15 20:02:26 | 000,000,225 | R— | M] () MD5=0A27F1D6595A69800A43CDE155B1E4A0 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx19

< MD5 for: SERVICES.ASFX2 >
[2010/11/15 20:02:36 | 000,000,264 | R— | M] () MD5=0652D24D4E2799851A6DF1705E2BFFDA – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx2

< MD5 for: SERVICES.ASFX20 >
[2010/11/15 20:02:38 | 000,000,231 | R— | M] () MD5=C85F2519DC6AECF93F67AA613A320136 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx20

< MD5 for: SERVICES.ASFX21 >
[2010/11/15 20:02:26 | 000,000,231 | R— | M] () MD5=8C95C0528EA7049A1DFC7A7342461D75 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx21

< MD5 for: SERVICES.ASFX22 >
[2010/11/15 20:02:24 | 000,000,231 | R— | M] () MD5=9F2731666F5771CC5C1E4EEDC8FB8607 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx22

< MD5 for: SERVICES.ASFX23 >
[2010/11/15 20:02:26 | 000,000,225 | R— | M] () MD5=0E89BE53F56B22390CF61584B649CE01 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx23

< MD5 for: SERVICES.ASFX24 >
[2010/11/15 20:02:32 | 000,000,229 | R— | M] () MD5=E57594DB9B9D78AB4B53D34CAFEB8497 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx24

< MD5 for: SERVICES.ASFX25 >
[2010/11/15 20:02:36 | 000,000,232 | R— | M] () MD5=611CB9CC21D2DDAD711690671F70EF39 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx25

< MD5 for: SERVICES.ASFX3 >
[2010/11/15 20:02:34 | 000,000,229 | R— | M] () MD5=F9824728970AC8199BABDC9CBA5E038C – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx3

< MD5 for: SERVICES.ASFX4 >
[2010/11/15 20:02:26 | 000,000,226 | R— | M] () MD5=55EA57D90AE22BDF0132597EF0D7C9C7 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx4

< MD5 for: SERVICES.ASFX5 >
[2010/11/15 20:02:34 | 000,000,233 | R— | M] () MD5=846C265B751189E88B74F0155DB6B828 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx5

< MD5 for: SERVICES.ASFX6 >
[2010/11/15 20:02:36 | 000,000,231 | R— | M] () MD5=89BD37C4118540FD5AA8CDD0C24D6C0A – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx6

< MD5 for: SERVICES.ASFX7 >
[2010/11/15 20:02:34 | 000,000,245 | R— | M] () MD5=0B82FAB8FF5F988C5311DF1144A7D740 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx7

< MD5 for: SERVICES.ASFX8 >
[2010/11/15 20:02:34 | 000,000,231 | R— | M] () MD5=5226417D3C8206000A8983BDC1243075 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx8

< MD5 for: SERVICES.ASFX9 >
[2010/11/15 20:02:30 | 000,000,234 | R— | M] () MD5=EBD8D036504F2935675F5F432F076DBA – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx9

< MD5 for: SERVICES.CFG >
[2011/06/06 20:55:30 | 000,584,045 | —- | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2010/11/15 20:02:22 | 000,032,633 | R— | M] () MD5=EA1C35DD541D60819D55482130BD585D – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/14 02:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\windows\SysNative\services.exe
[2009/07/14 02:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 08:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\windows\SysNative\en-US\services.exe.mui
[2010/11/21 08:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 05:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 05:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 21:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\windows\SysNative\wbem\services.mof
[2009/06/10 21:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2010/11/21 08:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\windows\SysNative\en-US\services.msc
[2009/06/10 21:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\windows\SysNative\services.msc
[2010/11/21 08:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010/11/21 08:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 21:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 08:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 22:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 21:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 21:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2010/11/21 08:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 22:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/21 04:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\windows\SysNative\winlogon.exe
[2010/11/21 04:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012/09/07 17:04:42 | 000,218,696 | —- | M] () MD5=4E0D8C9F83B7FD82393F7D8CCC27E7AE – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 08:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\windows\SysNative\en-US\winlogon.exe.mui
[2010/11/21 08:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.MFL >
[2010/11/21 08:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\windows\SysNative\wbem\en-US\winlogon.mfl
[2010/11/21 08:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 21:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\windows\SysNative\wbem\winlogon.mof
[2009/07/13 21:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

< %SYSTEMDRIVE%\*.* >
[2010/11/21 04:23:51 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2012/04/09 11:04:17 | 000,008,192 | RHS- | M] () – C:\BOOTSECT.BAK
[2012/09/28 10:42:56 | 2899,075,072 | -HS- | M] () – C:\hiberfil.sys
[2012/09/28 10:42:56 | 3865,436,160 | -HS- | M] () – C:\pagefile.sys
[2012/09/26 11:53:42 | 000,000,315 | —- | M] () – C:\user.js

< %systemroot%\Fonts\*.com >
[2009/07/14 06:32:31 | 000,026,040 | —- | M] () – C:\windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 06:32:31 | 000,026,489 | —- | M] () – C:\windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 06:32:31 | 000,029,779 | —- | M] () – C:\windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 06:32:31 | 000,043,318 | —- | M] () – C:\windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 21:49:50 | 000,000,065 | —- | M] () – C:\windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2011/05/13 23:42:24 | 000,302,448 | —- | M] (Microsoft Corporation) – C:\windows\WLXPGSS.SCR

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/14 05:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/09/26 11:45:31 | 000,000,221 | -HS- | M] () – C:\Users\dad\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini

< %USERPROFILE%\Desktop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< %systemroot%\AppPatch\Custom\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< End of report >

and the extras:

OTL Extras logfile created on: 28/09/2012 11:06:48 - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\dad\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

3.60 Gb Total Physical Memory | 2.51 Gb Available Physical Memory | 69.81% Memory free
7.20 Gb Paging File | 5.14 Gb Available in Paging File | 71.40% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 579.12 Gb Total Space | 546.08 Gb Free Space | 94.30% Space Free | Partition Type: NTFS

Computer Name: DAD-TOSH | User Name: dad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\SysWow64\control.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [print] – rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{25EE326B-0668-4630-BADF-E5CDA71F1D1F}" = lport=445 | protocol=6 | dir=in | app=system |
"{2EE597A4-0A25-48BF-814A-1C55493727D9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{395D3855-23C5-4628-8D23-64D1975EB602}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{4747CFB4-372A-4775-AC56-DB3438DCD8F7}" = lport=138 | protocol=17 | dir=in | app=system |
"{474A7147-FD90-40BF-AA0A-5A04E992718F}" = rport=138 | protocol=17 | dir=out | app=system |
"{49742591-CD6B-4D3B-B4C9-EC0B661E3D69}" = rport=139 | protocol=6 | dir=out | app=system |
"{4C64784B-56F5-40C9-9AEB-6A3B5FED480B}" = lport=137 | protocol=17 | dir=in | app=system |
"{4C9911E6-DF55-4D7B-AAB3-C19C094EEA7F}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{55346363-C279-41B9-87C0-90AD8F1581D7}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{615428BE-F67A-43EC-B0CC-0FBBA488BE6E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{754A8A13-7190-4E1C-B1EB-613E2108E97D}" = lport=10243 | protocol=6 | dir=in | app=system |
"{771802C7-12B5-4976-92B5-B0D9C676F92C}" = rport=445 | protocol=6 | dir=out | app=system |
"{7D81EE36-E6EE-4228-BE97-6D2A31917CCD}" = rport=137 | protocol=17 | dir=out | app=system |
"{8C86301C-3DA1-4139-8A4F-2CF7900D2BBC}" = rport=10243 | protocol=6 | dir=out | app=system |
"{912FD028-732C-4C2A-A47D-2D52635EB1DE}" = lport=2869 | protocol=6 | dir=in | app=system |
"{97F43644-4E1D-4F9C-87C2-C10CC77F311C}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{9DC45090-1AEA-4AD0-8C9B-5C54FEECBA99}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A4B3B2C8-0EB1-4DD0-8962-E62AFBEACF94}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A59C6288-55FE-41EF-82AC-010574C7DB8C}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{AA192BDE-0E7E-4565-B1F6-C8AF8AF09B89}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D19BCE69-B010-4524-ADAF-D9874D7809C0}" = lport=139 | protocol=6 | dir=in | app=system |
"{E8EF462C-12D5-4D05-9BF0-DB1AC24C8A98}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{FF681F18-90D3-4254-B35B-67B774D6BC5C}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{032A1D47-4C0C-4ACD-8216-09A117A54329}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{1908963C-36C9-46AB-B2C6-250D7A90B443}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{23085E86-C0ED-4AF3-AE01-2CBC4B3E71D8}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2A9DAD8B-4D04-4FB6-8D03-ACEE26D8AD2C}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{46485CCF-5820-4B8D-838B-C1B5F83E4552}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{51F33392-F39F-4DA5-9D08-AE921CBE1CAC}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5EE80DB3-D39A-49B6-8C58-2BD196A9E7F3}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{62796503-5530-45ED-A5DB-DB2095B31FB4}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6BD5DEDA-9ABC-439E-AC33-AA5AB87FBA12}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7E2779F8-4B9F-4B4C-91DF-6AAA334AA360}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{80379378-8E43-4B40-BA3E-351E3483E7BC}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A7DD8789-B9A9-43BD-ADD7-F63B10FFB29C}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{B8D98C83-6DD4-4A9D-A871-C078616D5413}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{BAF082AA-42FA-4A6A-9E05-593BEEA15CFC}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{C1439749-3ABA-4DBA-8F70-932598379D24}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C2346B38-2050-4948-AC1E-5D5D21D7F81A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{C73AD6FB-C2D1-4B74-AE3C-44B578085A3B}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{C96888A9-FA6F-4EC2-80E3-ADB76EB5A98D}" = protocol=6 | dir=out | app=system |
"{D53873DE-DD7F-456B-A37B-049089621C5E}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{DD9ECCEF-A4CC-4276-BB81-77D157F2680B}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{E5378FDD-FF7F-4260-834E-72D2072ED655}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{EC498903-E151-4D64-ABA2-5DA881237887}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{ED768C41-1614-417C-8CF1-9CD10F859593}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{EF2F4572-190C-430D-8A6E-40B51797685D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{F6F6C939-02AF-4BF3-B743-0F7A645FCC5C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{1214F6C9-539C-4138-993F-E3717A7D46DC}" = ccc-utility64
"{1685AE50-97ED-485B-80F6-145071EE14B0}" = Windows Live Remote Service Resources
"{180C8888-50F1-426B-A9DC-AB83A1989C65}" = Windows Live Language Selector
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{2C1A6191-9804-4FDC-AB01-6F9183C91A13}" = Windows Live Remote Client Resources
"{3007FF9F-5B2C-41FF-8BFC-08BF25DB2681}" = Premium Sound HD
"{4C2E49C0-9276-4324-841D-774CCCE5DB48}" = Windows Live Remote Client Resources
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{57F2BD1C-14A3-4785-8E48-2075B96EB2DF}" = Windows Live Remote Service Resources
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5E015E15-F7AD-3379-523F-AD63C0CB9E71}" = AMD Steady Video Plug-In
"{63F96D8F-D32B-AABF-4DE1-F51FF391FFD6}" = AMD Catalyst Install Manager
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{7AEC844D-448A-455E-A34E-E1032196BBCD}" = Windows Live Remote Service Resources
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{850B8072-2EA7-4EDC-B930-7FE569495E76}" = Windows Live Remote Client Resources
"{90140000-006D-0409-1000-0000000FF1CE}" = Microsoft Office Click-to-Run 2010
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor
"{A060182D-CDBE-4AD6-B9B4-860B435D6CBD}" = Windows Live Remote Client Resources
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C9C56642-9AAB-4267-9454-36FF1CC59168}" = TOSHIBA eco Utility
"{CB4C3CFA-D65B-E90A-268A-E12C2415BA8A}" = AMD Media Foundation Decoders
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D600D357-5CB9-4DE9-8FD4-14E208BD1970}" = Nero Backup Drivers
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6CB2C5F-B2C1-4DF1-BF44-39D0DC06FE6F}" = Windows Live Remote Service Resources
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Reimage Repair" = Reimage Repair
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00884F14-05BD-4D8E-90E5-1ABF78948CA4}" = Windows Live Mesh
"{01E9B2FF-DAF4-4529-9CC9-2101625517C7}" = nero.prerequisites.msi
"{034DCAF9-96E7-4936-9A07-712F80B5181E}" = Nero RescueAgent 11
"{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"{07E75C8C-A1D8-5409-FE3D-52FE1A8B0521}" = CCC Help Czech
"{09B7C7EB-3140-4B5E-842F-9C79A7137139}" = Windows Live Mesh ActiveX-kontroll for eksterne tilkoblinger
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C975FCC-A06E-4CB6-8F54-A9B52CF37781}" = Windows Liven sähköposti
"{10186F1A-6A14-43DF-A404-F0105D09BB07}" = Windows Live Mail
"{110668B7-54C6-47C9-BAC4-1CE77F156AF5}" = Windows Live Mesh
"{11417707-1F72-4279-95A3-01E0B898BBF5}" = Windows Live Mesh
"{119826A8-4EF6-4BE5-A88B-D2D81FA7CEE2}" = TOSHIBA Supervisor Password
"{11D3EF85-63E1-4AE4-A7C1-9241BDB16B51}" = Nero ControlCenter 11
"{133D9D67-D475-4407-AC3C-D558087B2453}" = Windows Live Movie Maker
"{15D2D75C-9CB2-4efd-BAD7-B9B4CB4BC693}" = Browser Manager
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1A72337E-D126-4BAF-AC89-E6122DB71866}" = Windows Liven valokuvavalikoima
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{216DF734-6004-42C7-AFC9-A81DFD344BA8}" = Nero BurnRights 11
"{220C7F8C-929D-4F71-9DC7-F7A6823B38E4}" = Windows Live UX Platform Language Pack
"{2290A680-4083-410A-ADCC-7092C67FC052}" = TOSHIBA Online Product Information
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{24DF33E0-F924-4D0D-9B96-11F28F0D602D}" = Windows Live UX Platform Language Pack
"{25CD4B12-8CC5-433E-B723-C9CB41FA8C5A}" = Windows Live Writer
"{26A24AE4-039D-4CA4-87B4-2F83216030FF}" = Java™ 6 Update 30
"{2767CD98-909A-D778-937D-CB81C21EAB99}" = CCC Help Portuguese
"{28B9D2D8-4304-483F-AD71-51890A063A74}" = Windows Live Photo Common
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2E50E321-4747-4EB5-9ECB-BBC6C3AC0F31}" = Windows Live Writer Resources
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{2FD5D2C5-A7A1-4065-89BA-90542BF7CCD3}" = TOSHIBA Hardware Setup
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{36710AB4-FE33-3424-BD51-F4D0FDD36A6C}" = CCC Help Italian
"{376D59B1-42D9-4FA2-B6CC-E346B6BE14F5}" = ActiveX-kontroll för fjärranslutningar för Windows Live Mesh
"{3826784C-62B7-4F16-AEAD-2417BD34AFA7}" = Catalyst Control Center - Branding
"{39F95B0B-A0B7-4FA7-BB6C-197DA2546468}" = Windows Live Mesh
"{3C0A0BB2-7886-9B50-8BFC-CF35C1A167DA}" = CCC Help Greek
"{3D6D889E-42B9-76EB-F98A-D3BA7EDD4203}" = CCC Help Polish
"{429DF1A0-3610-4E9E-8ACE-3C8AC1BA8FCA}" = Windows Live Photo Gallery
"{461F6F0D-7173-4902-9604-AB1A29108AF2}" = TOSHIBA Places Icon Utility
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A04DB63-8F81-4EF4-9D09-61A2057EF419}" = Windows Live Essentials
"{4B744C85-DBB1-4038-B989-4721EB22C582}" = Windows Live Messenger
"{4CF6F287-5121-483C-A5A2-07BDE19D8B4E}" = Windows Live Meshin etäyhteyksien ActiveX-komponentti
"{4D2122D0-66F7-4A53-96FC-079C900B1CAF}" = Nero BurnRights 11 Help (CHM)
"{57220148-3B2B-412A-A2E0-82B9DF423696}" = Windows Live Mesh ActiveX-objekt til fjernforbindelser
"{575BEAAF-780C-9C16-8CEB-A079BD3BF8B9}" = CCC Help Spanish
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A212B2D-140D-46F4-B625-2D1CA5A00594}" = Nero 11 Kwik Themes Basic
"{5C2F5C1B-9732-4F81-8FBF-6711627DC508}" = Windows Live Fotogalleri
"{6140F12A-D2E4-A20E-6A6C-5ECFE15E5AD6}" = CCC Help Korean
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{69CAC24D-B1DC-4B97-A1BE-FE21843108FE}" = Windows Live Writer Resources
"{6A67578E-095B-4661-88F7-0B199CEC3371}" = Windows Live Messenger
"{6AB2427E-A18F-4809-9A12-29F5EBABBB3A}" = Nero BackItUp 11 Help (CHM)
"{6E4468BF-851F-F424-58E9-5F303888B685}" = AMD VISION Engine Control Center
"{6EF2BE2C-3121-48B7-B7A6-C56046B3A588}" = Windows Live Movie Maker
"{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}" = TOSHIBA Web Camera Application
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-toshiba" = WildTangent Games App (Toshiba Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{734104DE-C2BF-412F-BB97-FCCE1EC94229}" = Windows Live Writer Resources
"{73CF1B93-688F-64AD-0410-5B1A84AD4F7F}" = CCC Help Hungarian
"{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TOSHIBA Recovery Media Creator Reminder
"{7ADFA72D-2A9F-4DEC-80A5-2FAA27E23F0F}" = Windows Live Photo Common
"{7CAEC4DA-4319-0FBF-F6E3-E1DD9679C34F}" = CCC Help Japanese
"{827D3E4A-0186-48B7-9801-7D1E9DD40C07}" = Windows Live Essentials
"{834CABA9-7C88-08D6-8D33-01FD3A8D7371}" = CCC Help German
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{84D32999-98A5-39CF-17CD-B01E80E1591A}" = CCC Help Russian
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{885F1BCD-C344-4758-85BD-09640CF449A5}" = Windows Live Photo Gallery
"{8909CFA8-97BF-4077-AC0F-6925243FFE08}" = Windows Liven asennustyökalu
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8CF5D47D-27B7-49D6-A14F-10550B92749D}" = Windows Live UX Platform Language Pack
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90140011-0066-0409-0000-0000000FF1CE}" = Microsoft Office Starter 2010 - English
"{90FF4432-21B7-4AF6-BA6E-FB8C1FED9173}" = Toshiba Manuals
"{9193490D-5229-4FC4-9BB9-A6D63C09574A}" = High-Definition Video Playback
"{924B4D82-1B97-48EB-8F1E-55C4353C22DB}" = Windows Live Mail
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B1A5C6A-E065-B631-1D03-465BF3665818}" = CCC Help Swedish
"{9CB0414F-2582-CAF2-0AE4-2A681BF8303C}" = Catalyst Control Center Localization All
"{9CEB4227-51C8-B855-376C-42587F913042}" = CCC Help Norwegian
"{9D3D8C60-A55F-4fed-B2B9-173001290E16}" = Realtek WLAN Driver
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F7EDE99-6717-AEF7-1226-B555937D567A}" = CCC Help Finnish
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A59A8D2F-9C35-5913-8EAB-A10D4439023C}" = CCC Help Dutch
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{A9CDA593-60AF-12FA-48CD-3A022331A03D}" = CCC Help Chinese Standard
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB2BBC64-8AC8-4E66-BBF3-E22D5EACEECA}" = Nero BackItUp 11
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.0) MUI
"{B3169E94-0578-7DB6-E0A7-01017E62AF03}" = CCC Help Thai
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{B9B1BA7F-7E07-49DD-A713-5B397A5BB66B}" = Nero Kwik Media Help (CHM)
"{BD3C678F-26E2-E518-9032-331190C714C9}" = Catalyst Control Center Graphics Previews Common
"{BE814218-3919-4EA3-868A-2F60BC135CB4}" = Nero Kwik Media
"{BEBEE34D-84A2-4EDD-8BEA-96CC54371263}" = Nero Core Components 11
"{BFC47A0B-D487-4DF0-889E-D6D392DF31E0}" = Windows Live Messenger
"{C2A276E3-154E-44DC-AAF1-FFDD7FD30E35}" = TOSHIBA Assist
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C7A4F26F-F9B0-41B2-8659-99181108CDE3}" = TOSHIBA Media Controller
"{CCB9D143-C62F-A895-6828-F00E9235EC88}" = CCC Help French
"{CCE210DF-7EEF-4A76-A63C-3EB091FDB992}" = welcome
"{CD442136-9115-4236-9C14-278F6A9DCB3F}" = Windows Live Movie Maker
"{CD7CB1E6-267A-408F-877D-B532AD2C882E}" = Windows Live Photo Common
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF671BFE-6BA3-44E7-98C1-500D9C51D947}" = Windows Live Photo Gallery
"{CFE3F8A1-C282-403C-316E-DD6A24697190}" = CCC Help Chinese Traditional
"{D01CE99A-8802-483C-A79F-298B691EB432}" = Nero RescueAgent 11 Help (CHM)
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D0B568E0-742C-71BD-1ED5-8CE3A529A93E}" = CCC Help Danish
"{D2CBEFA4-F2D3-4E97-A171-8BFD6A31A5EC}" = Nero Express 11 Help (CHM)
"{D31169F2-CD71-4337-B783-3E53F29F4CAD}" = Windows Live Mail
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4D66270-9147-4BDF-9946-FCA2B303AA8F}" = Nero ControlCenter 11 Help (CHM)
"{DA29F644-2420-4448-8128-1331BE588999}" = Windows Live Writer
"{DB1208F4-B2FE-44E9-BFE6-8824DBD7891B}" = Windows Live Movie Maker
"{DCAB6BA7-6533-44BF-9235-E5BF33B7431C}" = Windows Live Writer
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E10AAE4A-98B8-420A-BD93-E0520C23D624}" = Nero Express 11
"{E55E7026-EF2A-4A17-AAA7-DB98EA3FD1B1}" = BabylonObjectInstaller
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E5DD4723-FE0B-436E-A815-DC23CF902A0B}" = Windows Live UX Platform Language Pack
"{E8524B28-3BBB-4763-AC83-0E83FE31C350}" = Windows Live Writer
"{E9D98402-21AB-4E9F-BF6B-47AF36EF7E97}" = Windows Live Writer Resources
"{ECCCC555-B691-4485-E291-B9E65C1A574B}" = CCC Help Turkish
"{ED4155E5-CE72-B1C2-D2DF-9AF277B5DA55}" = CCC Help English
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{F082CB11-4794-4259-99A1-D91BA762AD15}" = TOSHIBA TEMPRO
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0F9505B-3ACF-4158-9311-D0285136AA00}" = Windows Live Essentials
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F8635CF8-B797-4EFD-80BC-DE2D26C65D4F}" = Nero 11 Essentials
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FFFA0584-8E3D-4195-8283-CCA3AD73C746}" = Windows Live Messenger
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Betfair Poker_is1" = Betfair Poker 1.0.0
"funmoods" = Funmoods Web Search
"InstallShield_{066CFFF8-12BF-4390-A673-75F95EFF188E}" = TOSHIBA Value Added Package
"InstallShield_{6F3C8901-EBD3-470D-87F8-AC210F6E5E02}" = TOSHIBA Web Camera Application
"InstallShield_{773970F1-5EBA-4474-ADEE-1EA3B0A59492}" = TOSHIBA Recovery Media Creator Reminder
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.65.0.1400
"Mozilla Firefox 15.0.1 (x86 en-US)" = Mozilla Firefox 15.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MSC" = McAfee Internet Security
"Office14.Click2Run" = Microsoft Office Click-to-Run 2010
"WildTangent toshiba Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials
"WTA-0790a147-a665-4cb9-9b3b-a6f136b2d8f6" = Insaniquarium Deluxe
"WTA-19bc8509-984f-436e-91da-0e5ecfbcc467" = Virtual Villagers 4 - The Tree of Life
"WTA-3ad1b57d-a24f-416a-9ea2-a26e391b456c" = Plants vs. Zombies - Game of the Year
"WTA-53024613-eeb5-451c-b6a3-09184e98c986" = Aloha TriPeaks
"WTA-8e4de194-7a51-4c5a-baef-1cda3c6de7fe" = Agatha Christie - Death on the Nile
"WTA-92ba529c-9c63-43a2-b565-9ec3966d7495" = Mystery P.I. - The London Caper
"WTA-99626ea8-1a41-4008-b1b4-cbd333883123" = Polar Bowler
"WTA-c8c3fc2b-a076-4d5b-95f9-93c0a60305f4" = Cake Mania
"WTA-ce9aecbf-59fc-480b-8456-8328df366279" = Bejeweled 3
"WTA-d4d59cb9-0a29-4273-8d4b-9bf1ec944b3e" = Chuzzle Deluxe
"WTA-ece706df-26fb-4145-89b5-ac5c3f0cce76" = Jewel Quest Solitaire 2

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 26/09/2012 07:42:46 | Computer Name = dad-TOSH | Source = Application Error | ID = 1000
Description = Faulting application name: BabylonToolbarsrv.exe, version: 1.6.9.0,
time stamp: 0x5035f49f Faulting module name: unknown, version: 0.0.0.0, time stamp:
0x00000000 Exception code: 0xc0000005 Fault offset: 0x00580a18 Faulting process id:
0x1c9c Faulting application start time: 0x01cd9bdc0b1ca961 Faulting application path:
C:\Program Files (x86)\BabylonToolbar\BabylonToolbar\1.6.9.12\BabylonToolbarsrv.exe
Faulting
module path: unknown Report Id: 49f2c044-07cf-11e2-8574-4c72b99c796d

Error - 27/09/2012 20:43:09 | Computer Name = dad-TOSH | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 27/09/2012 21:16:26 | Computer Name = dad-TOSH | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 27/09/2012 22:05:36 | Computer Name = dad-TOSH | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 27/09/2012 22:06:43 | Computer Name = dad-TOSH | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 27/09/2012 22:24:51 | Computer Name = dad-TOSH | Source = MsiInstaller | ID = 11935
Description =

Error - 27/09/2012 22:36:52 | Computer Name = dad-TOSH | Source = .NET Runtime Optimization Service | ID = 1101
Description =

Error - 27/09/2012 22:37:27 | Computer Name = dad-TOSH | Source = .NET Runtime | ID = 1023
Description =

Error - 27/09/2012 22:37:28 | Computer Name = dad-TOSH | Source = Application Error | ID = 1000
Error - 27/09/2012 22:37:32 | Computer Name = dad-TOSH | Source = .NET Runtime Optimization
Service | ID = 1101

Description =
Error - 28/09/2012 05:43:42 | Computer Name = dad-TOSH | Source = WinMgmt | ID =
10

Description =

Error encountered while reading event logs.

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI