This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Starburn search [Solved]

23 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:21:06 PM, on 27/12/2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16457)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe
C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe
C:\WINDOWS\SysWOW64\Ctxfihlp.exe
C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe
C:\Program Files (x86)\HFN\Client\cutil.exe
C:\Windows\SysWOW64\CTXFISPI.EXE
C:\Users\Wayne\AppData\Roaming\SearchProtect\bin\cltmng.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/23
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://search.musicfrost.com
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
O4 - HKLM\..\Run: [mcui_exe] "C:\Program Files\McAfee.com\Agent\mcagent.exe" /runkey
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Garmin Lifetime Updater] C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe /StartMinimized
O4 - HKLM\..\Run: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe
O4 - HKCU\..\Run: [swg] "C:\Program Files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"
O4 - HKCU\..\Run: [HP Officejet 6600 (NET)] "C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe" -deviceID "CN23E291RT05RN:NW" -scfn "HP Officejet 6600 (NET)" -AutoStart 1
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - .DEFAULT User Startup: Dell Dock First Run.lnk = C:\Program Files\Dell\DellDock\DellDock.exe (User 'Default user')
O4 - Startup: Dell Dock.lnk = C:\Program Files\Dell\DellDock\DellDock.exe
O4 - Startup: Monitor Ink Alerts - HP Officejet 6600 (Network).lnk = ?
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Companion\companionlang.dll,-600 - {0000036B-C524-4050-81A0-243669A86B9F} - C:\Program Files (x86)\Windows Live\Companion\companioncore.dll
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: Garmin Communicator Plug-In - https://static.garmincdn.com/gcp/ie/4.0.4.0…xControl_32.CAB
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files%20(x86)/Mah%20Jong%20Medley/Images/stg_drm.ocx
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (YInstStarter Class) - C:\Program Files (x86)\Yahoo!\Common\yinsthelper.dll
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} (DellSystemLite.Scanner) - http://support.dell.com/systemprofiler/DellSystemLite.CAB
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} (Creative Software AutoUpdate Support Package 2) - http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} (Creative Software AutoUpdate 2) - http://ccfiles.creative.com/Web/softwareup…015/CTSUEng.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://ccfiles.creative.com/Web/softwareup…15118/CTPID.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter: application/x-mfe-ipt - {3EF5086B-5478-4598-A054-786C45D75692} - c:\PROGRA~2\mcafee\msc\mcsniepl.dll
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Active File Monitor V8 (AdobeActiveFileMonitor8.0) - Adobe Systems Incorporated - c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Search Protect by Conduit Updater (CltMngSvc) - Conduit - C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe
O23 - Service: Creative ALchemy AL6 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: Dock Login Service (DockLoginService) - Stardock Corporation - C:\Program Files\Dell\DellDock\DockLogin.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: HFN Client - HFN, Inc. - C:\Program Files (x86)\HFN\Client\srvc.exe
O23 - Service: Advanced Networking Service (hnmsvc) - Dell Inc. - c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe
O23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: McAfee Security Scan Component Host Service (McComponentHostService) - McAfee, Inc. - C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe
O23 - Service: McAfee Personal Firewall Service (McMPFSvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee VirusScan Announcer (McNaiAnn) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\Program Files\McAfee\VirusScan\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe
O23 - Service: McAfee Firewall Core Service (mfefire) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe
O23 - Service: McAfee Validation Trust Protection Service (mfevtp) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Rapport Management Service (RapportMgmtService) - Trusteer Ltd. - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe
O23 - Service: RoxMediaDB10 - Sonic Solutions - c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SessionLauncher - Unknown owner - c:\Users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe (file missing)
O23 - Service: SoftThinks Agent Service (SftService) - SoftThinks SAS - C:\Program Files (x86)\Dell DataSafe Local Backup\sftservice.EXE
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: stllssvr - MicroVision Development, Inc. - c:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

–
End of file - 14935 bytes
I am using Windows 7 home premium on a desktop. I downloaded Google Chrome and started getting used to it when Star burn took over. I searched for a fix and ended up here. I will appreciate any help —–Wayne
Hello ENYAW22,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

Please be advised, as I am still in training, all my replies to you will be checked for accuracy by one of our experts to ensure that I am giving you the best possible advice, this will be a team effort. This may cause a delay, but I will do my best to keep it as short as possible. Please bear with me, I will post back to you as soon as I can.
  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"
Hi ENYAW22,

Download OTL to your desktop.

Right click and select "Run as Administrator".
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
Next

Download aswMBR.exe and save it to your desktop.

Right click and select "Run as Administrator".
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
In your next post please provide the following:
  • OTL.txt
  • Extras.txt
  • aswMBR log
  • Describe how the computer is running/issues.
OTL Extras logfile created on: 12/29/2012 4:17:51 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Wayne\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

8.99 Gb Total Physical Memory | 7.04 Gb Available Physical Memory | 78.26% Memory free
17.98 Gb Paging File | 15.52 Gb Available in Paging File | 86.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.35 Gb Total Space | 782.52 Gb Free Space | 85.40% Space Free | Partition Type: NTFS

Computer Name: WAYNE-PC | User Name: Wayne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"FirewallDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
"DoNotAllowExceptions" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0043D7C8-761D-47B1-BAD1-9DE3D640F27C}" = rport=445 | protocol=6 | dir=out | app=system |
"{00F5417B-7541-42EA-BC30-DC033660469A}" = lport=138 | protocol=17 | dir=in | app=system |
"{0E6C9179-46DA-4F02-B89F-D25864595CC3}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{0FB3EE70-756E-4480-90B6-CD87584A2C42}" = lport=2869 | protocol=6 | dir=in | app=system |
"{13FE04A3-24BF-43CC-B787-6051DDE6A636}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{145EEC03-BA2B-4B2A-9FBA-F3A34898086D}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{20B6D364-0B76-4DB4-9E3B-3B0505B66ACC}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{20C31CB0-55BD-40F5-9358-9AE0C7C5A4D9}" = rport=137 | protocol=17 | dir=out | app=system |
"{2346B26C-9097-424E-A74D-F90EACEA651D}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{24B101F9-A08D-4378-AB05-D4D017C326CE}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{3748DE91-6F92-4A73-B093-2103AAC99DBC}" = lport=2869 | protocol=6 | dir=in | app=system |
"{40BB4C16-F287-4C97-8492-72B57D71B64D}" = lport=4482 | protocol=6 | dir=in | name=blackberry desktop software music sync service data transfer |
"{5F8EAC7C-EF1D-4B2F-8EFA-2321E1DEC935}" = rport=138 | protocol=17 | dir=out | app=system |
"{62A6A017-C1C8-4194-AA19-8E2401763E59}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{6676C68E-75E5-4212-9D1F-DFD808126DBB}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{6F93621B-AF32-421B-A688-34F211236D08}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{7239A020-43D3-4311-BA34-5D8EB3B2CD51}" = rport=139 | protocol=6 | dir=out | app=system |
"{78B570CC-30E6-4672-9F15-5EBF1D8D2232}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{81AADCDB-2ECD-4970-B5EA-B07290EC697D}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software wireless music sync discovery |
"{84E842C3-521C-4F7A-ABAC-60548595EA5E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{8F6146DE-C895-4A5D-8C10-9F916310C9AC}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software music sync service data transfer |
"{97DF7858-C7B7-4E49-9223-88ECF03B3359}" = lport=4481 | protocol=6 | dir=in | name=blackberry desktop software wireless music sync data transfer |
"{98A0D484-99A2-4C41-8767-E84441EFF0DA}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{98EE5609-C254-44AA-A9C9-3E19B2E53B67}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{9D3ACF4D-9BCE-4CCB-9F42-6D9E65743033}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{B3B4B38E-2F70-4E81-9AB6-991F65C4515D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D04100DA-5DEA-4226-B66A-2AC82B3135C7}" = lport=10243 | protocol=6 | dir=in | app=system |
"{DE78BC80-B199-4EE4-ACFA-F755136DCED6}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{DF2D2527-1231-413D-9E03-8B83325DAD2A}" = lport=445 | protocol=6 | dir=in | app=system |
"{E49CE166-D767-44D8-AF8C-657F5D6BC6B5}" = lport=4482 | protocol=17 | dir=in | name=blackberry desktop software music sync service discovery |
"{E7A9D0FA-5052-4F30-AE29-B63EF76B3A43}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{ECD04252-05D7-49B1-9A6C-2EEE6D573FA6}" = lport=137 | protocol=17 | dir=in | app=system |
"{EF0DB6B2-6F75-4AC9-9E2B-0C4BE282620F}" = lport=139 | protocol=6 | dir=in | app=system |
"{F4D1CCEF-211B-4E19-AEDC-B86A5EAE28A6}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{F665EE32-E6BD-4C91-8145-67F6982C2F11}" = lport=4481 | protocol=17 | dir=in | name=blackberry desktop software music sync service discovery |
"{FCB78D96-CFCB-4E83-AEAA-44852C338DAA}" = rport=10243 | protocol=6 | dir=out | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0185B9FC-E7FB-4E4D-81CA-619C6B19A875}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{01CEA879-C51F-48B8-A7EC-C46A2B228FA5}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{030BF801-186D-4728-B2DA-884A658213AC}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{03180B14-33F2-4BB4-A547-0E2514B3B9ED}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{0626A11E-E08D-46B9-A043-9126E9C59908}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{06DA07A8-321B-4CB6-BC63-9C35D9D303D1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{07D74EB8-82FC-493F-B008-36AB710FBB24}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{0833608A-F310-4334-A182-9CB7E2834F97}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{08742917-FA35-46AD-BFBB-A3CBE5359A82}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{0A6608D9-E62F-4BDF-914C-F2224E3E51CE}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{0E743C9F-54EC-485B-8ED3-B08D2330F6E4}" = protocol=6 | dir=out | app=system |
"{0ECC670C-3B8E-4942-9ECF-61268FE50C34}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{10C63A64-7375-4FF2-8CE5-83416D024DE9}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{10E424E3-5D38-47AD-8DE4-4567FD80C168}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{123BE663-76E6-4C98-BC84-9FA81FC9EBF3}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{12D794E3-8D96-4E2D-9DD3-7E5E831DB6CC}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{146E9243-783D-4372-BEB1-99E6A0F9D7B3}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{159C33A8-A3DC-49FE-89BC-6482CEB6B65C}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{1662D92D-1D01-490A-865B-BD807998F921}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{16666FD4-BA66-4A82-80AF-322D608517C5}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{16C03672-5950-4B0A-A19D-6FC96838C8A2}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{17059B90-E922-4D13-89B3-0843E22CCBF2}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{1747D342-575E-4DAF-8A34-CA2E7BBA00E8}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{17F51850-A140-471F-B358-AFCFF942EFA6}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{18752A72-6EE2-4C58-B5B0-5B21669F6074}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{1AD432FA-A13C-4A26-BD98-E35EC33C929E}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{1C5826A4-A870-4B71-B000-DFAD08E6AC44}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{1D43E9A3-5160-4D85-AC6A-4B010B928EB0}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{1DDA1701-B8DD-4169-92B7-EAC43DCF46FB}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{1F23E587-C4D5-40EC-AFF1-6B954366C448}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{1F63212E-BC7C-4B2C-A87B-A3451F2B6D83}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\hpnetworkcommunicator.exe |
"{20705A8F-DD71-4980-8858-EE185B469A0A}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{23D717C1-281B-426C-9096-227D16666735}" = protocol=17 | dir=in | app=c:\program files (x86)\dell remote access\ezi_ra.exe |
"{23E6AD39-FBFF-49A5-9A70-C268E7E05E16}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{252164A8-C572-4933-A942-C3D1A9DEAA5B}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{25BEBC77-BB7F-41B4-9DD6-05EA5AC45C6A}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{27D3F4E5-36AE-43BB-ABE0-19DB95DC2E8F}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{28345FC9-AFDC-4927-ABE9-CA0E358A21B8}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{28D21EA3-E997-49E9-967A-CF0E9E1500EA}" = dir=in | app=c:\program files\hp\hp officejet 6600\bin\devicesetup.exe |
"{29110D3F-9C7B-4E43-9844-699832712128}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{29252E40-8ACA-4EF0-AC16-72A85A418797}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{29527CEE-85A0-444F-9AC1-4C4302C542BD}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{2A23FCB3-3526-4B45-A98A-FB4D74BD21FC}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{2A51C2B4-4749-41DF-98A3-D12E537B9E47}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{2C568003-0150-4AC1-BD7A-F90CDD203FDD}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{2C929A8C-9D21-4679-A730-9B1331D3EC21}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{2CF375E0-32BC-4A92-BBC2-23F20A586F18}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\dell\vlc\vlc.exe |
"{2CF5C88A-D6DB-4C32-958C-7BF537D6A1AF}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{2F131B37-BD95-429D-A816-2DBE10A04EFE}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{304D1261-2003-4C4C-9FB4-3F2B4D3E993D}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{308F6592-3B10-4127-B063-0E1DC270D2AF}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{31534284-D077-40E9-8C8C-7902BCAFA5B6}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{322EAFA6-614D-4EEA-A0C8-A0B728E283A2}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{32C59E49-45FC-4A05-8DF8-395B656AA7C2}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{32FA2434-3E99-4C04-849E-2488786C4D66}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{34AEAAE5-4D11-4332-BC80-78F75951B922}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{35700ABD-E6C5-4714-A8BA-AF6B86977BB5}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{3588C4FD-31B2-40BE-8134-6A820C659EB2}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{3600C0A8-B575-4FE4-BF4C-88D005C83365}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{3669335E-F581-429C-906B-6B2006F98279}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{38BE11D1-0E96-426B-A41F-9DEEB875E151}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{39F8B57B-124A-44DA-ACE2-A2C188C231CF}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{3A9109B9-4B5D-490B-A28A-1C198F8F72B4}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{3AD37A88-4BC9-4693-88F4-CE23195234EB}" = protocol=6 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{3EA32D27-6A8A-45F5-93F2-664F29B2C3C2}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{43089DA7-7E3E-4FB0-AF6F-841E473FE3A2}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\dell\advanced networking service\hnm_svc.exe |
"{43E67709-F46B-4123-9F3E-A2C0DBF100B1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{44864B9B-51EB-4287-B33D-2068B11C64F8}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{44A3866C-C530-481A-89D6-B3936A070707}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{44B57C48-22F6-4B4F-B212-A1A2A2A435B8}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{495E0149-3A9A-45A1-9580-7F0CCAE52E6E}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\dell\advanced networking service\hnm_svc.exe |
"{49E20BF8-C748-4898-9E68-7A7E8FD2EA84}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{4AECFDEA-C413-4257-928E-4118581F8119}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{4C12A34F-59B5-4AE7-9EC1-1A9356E133FF}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{4D072E96-7631-4535-85CD-3EEF3BAC9BF5}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{4E5013C8-66BD-44D0-860E-915D54EDFB05}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{4EC15F68-43F2-4683-AEC9-0B5E5CED3CE6}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{4ECD49BF-B831-4BCA-8E4C-3352187D7103}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{50176BD6-1743-458D-8210-2433C6E4E55C}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{503364C8-DDEC-4A53-821E-D5A23B45ECF2}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{5033D552-6741-47A4-A8BF-5854EE14BB12}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{516DF14B-7FCC-41B8-B836-18EB40A13E63}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{520B88AF-8F65-40D4-8179-7A62353A3DE1}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{53E647DF-F98F-46A1-A950-16844ADC790D}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{54544255-746B-4084-9FAE-FA3406362FF5}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{554F58BC-BA60-4E18-B635-DB6576236DA3}" = protocol=6 | dir=in | app=c:\program files (x86)\dell remote access\ezi_ra.exe |
"{579C23CB-FDDA-40CF-84DA-96580FF08574}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{58653129-384F-493A-AEFE-A9B898E5D923}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{593A0586-ED82-4230-8465-6593B1A911A4}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{5A767E7F-4830-49CC-9B51-9C13BFAF22D5}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{5AF311CF-15C1-40C4-BE88-353ED51F794D}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{5CADA2B7-233F-41BE-B7B7-FD506AF7D5C2}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{5ED00F27-C818-44E9-BC0C-C5BA31A4937E}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{632CCB32-69DA-4F96-82C0-79A9FC092806}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{64106BBB-E354-44BF-A6F2-C267C60C98AC}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{64F68422-B359-4221-AE4C-532665E889C1}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{661702EA-A039-4D2C-935D-8DE2A7A25C4D}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{66F6706E-1B40-437C-8F36-54498E91885B}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{692C9C56-3450-4841-9E0F-F0EB142DEAE1}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{6A32E8A6-8411-4038-B862-7F98C96614AE}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{6C0CC699-B9CE-4669-9008-8CED60770C67}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{6D2FAE46-E90E-4E7F-AD2E-86BD91DF2469}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6D30864D-B741-40C9-841E-96C0872ED872}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{6E9A2451-BEBF-4F50-897F-DF10D765D8AC}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{6EEBCF9B-A6C0-4075-863B-6D8371B68E9F}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{6EFCAC01-5C95-48B5-8469-4244FDED2C9D}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{6F80D0E1-90F9-4CC7-A676-9B13BD968E25}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{70C23D8A-6288-4BFD-95F9-E70FC9950AD4}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{70FF6038-8330-462C-B5BC-1F9836EFB45E}" = protocol=17 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{717AE277-ACAC-46EB-9236-497E0D57869D}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{7199CA33-798D-4F6D-92ED-ED032A36AB29}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{7490CA1B-F998-4AD4-AB38-AAD3655C1AC6}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe |
"{789D78C2-4D57-4C83-A530-3A72165855FB}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{79F53070-A75F-4682-945D-CD96F9960BAB}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{7B12D266-3A3E-4A9C-9C96-7C513B0459E5}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{7B6FC558-09BD-48DC-912D-3C64567209DA}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{7CC8A1AD-A7DA-4E44-A5F2-4901ABC840E3}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{7D6AE842-5851-407A-87FE-54EF221E4126}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{7DE0B7E2-CEDD-4854-AFA4-C9B8CA3726A2}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{7FC2D0C5-8FEC-4E48-AAD2-FFE1137A9503}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\pdvddxsrv.exe |
"{80697FA4-3CE7-422B-B242-EA5A46734695}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{827785A7-6C6F-4949-85D5-91B5B960B750}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{843D1200-5BF2-4376-A3DF-49FA1D211DED}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{84F6A7EC-1002-410F-859D-15E2DFCB35B8}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{85857990-BD01-40F6-8F88-6F582512665C}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{85934077-90F1-4FE9-BEA8-0946862B8503}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{85CCAFF7-EDFF-40C7-B297-6CE41BB7210A}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{881FD676-C0C7-4E23-AFA6-0866743612E7}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{88E02191-A0C6-417B-A9C9-EA7E1DBD088F}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{894AAB09-B16B-4040-BEA1-CE66504A7F96}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{8B939FFD-2563-4152-9F1D-7785F2993FB5}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{8D6E1537-78A6-429D-BB38-89173109A045}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{8E39F344-AA05-4645-92D3-2BE52B9D36C0}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{8EE486AD-8954-4F4B-A481-5F4C8CFA3FE1}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{8FC3B3D0-2087-4FBE-AF67-EA978757F307}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{911251CE-C059-4C0E-8944-EC7B55C99D05}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{91182D06-C33D-40C9-A30C-34F9C4BF9D85}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{952C9342-ACC0-4034-93B6-639BD43FD36E}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{95916816-F172-4CE8-9975-564F1C681012}" = protocol=17 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{95B729EF-67BC-4802-9AC8-813112D516CC}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{970E34FB-4E53-4CFC-8B11-55856CAAA130}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{97DF74B9-FBCD-4EA5-83A6-E2D46DC77BDF}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{984178A5-A031-4EBD-82A9-EF6A66A158CB}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{986096B1-73D6-4E40-94E2-91D92DBE3338}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{98C8940C-F64F-4733-BEFB-AB7E329E4F7B}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{992CC9E6-85D4-4C58-8EC0-3C526AAF16B0}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{9A016196-04DF-4281-85BE-9E29A92134F7}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{9A18B904-4AC1-4290-9B66-54C8217F3314}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9B0EC21F-9F20-4FC0-B87A-01FA465DFD42}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{9BD3036B-C7D5-4B2E-BA13-EC52C2A7E312}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{9DB5E000-6024-42FF-8876-1654086708D2}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{9ED542B2-E6EF-4CAF-A51E-A39312C42C8F}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{9F5C6CBF-90BA-4C40-9070-50A95F170C2B}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{A0DE0344-9BC5-4131-B355-74D559CC5E20}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{A11C8615-94D7-4EF7-88E9-A879F4B05937}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{A169A594-3646-45E1-8CBE-AB13FC1F524F}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{A1CCF99A-026B-4CE7-A36D-D26E5D0EBD7B}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{A24F4384-6CF7-4763-8709-3F34CEDD524D}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{A2E08C6F-A8DD-490C-AF3B-1061973F7720}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{A41E159C-6C5E-4ACA-B676-4506166CE734}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{A6273F22-C335-4EE6-B964-0CE656138791}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{A649EFA7-5C79-48A5-BD5C-77623181DCBC}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{A775E710-D315-4147-A1C9-2CB3197FDEB2}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{A79F3137-F0E8-4E0E-90C4-83650211FE65}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{A8BEE5F0-64A1-4F90-8608-13E31AEAFB79}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{A9E9F075-75D4-4565-83E0-349C14CEE5CE}" = dir=in | app=c:\program files (x86)\hfn\client\custicn.exe |
"{AC0474D9-9B8F-43EF-B26A-1A5D9EDEC4C9}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{ADCB01CD-C5BB-48DE-93BC-E7FEE0588439}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{AE1620E3-3B99-4595-BB89-F085E909C9DB}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{AE2C0BC7-AB18-4CC7-B30E-3CDA927F93EA}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{B038A3BC-9834-4D31-BE74-A3E2CF738B55}" = dir=in | app=c:\program files (x86)\hfn\client\capp.exe |
"{B1771A69-595E-4E23-AE2A-5E047506A509}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{B18A2B91-01F4-48E1-95EC-7AA35BCA8C51}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{B18D3B83-1E32-4601-820B-44EED7ACE7DC}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd dx\powerdvd.exe |
"{B2BEE3A5-BF8D-486E-9C74-7E78D9F79208}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{B54CB704-F676-4E1F-B865-DF34D3895A8B}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{B6BFA4E7-D115-4F31-99B9-5F3BE4364337}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{B9774872-9682-4B7B-BA48-CC6E3EF5352C}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{B9825543-B74B-43CB-983E-EBD5F291BE5C}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{B984D5A4-0B91-42EA-9247-8998835DCE72}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{B9EBA68E-129D-449D-81F7-14BDDCC5CC9F}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{BC17ADC7-9B6D-4CC3-A7A6-ADB997A5BDF7}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{BD6CDED9-81FB-455A-A521-FD33F6A99B34}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{BDACF8A0-03E1-4BE7-A66C-6B09BF21AD9E}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{BE3E9198-E285-4FC9-A55C-08B55C434CFE}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{BEA541BE-2609-4C14-A622-23FCEABA2A92}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{BF591DA9-A457-442A-932E-26BA525B7D35}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{C0C3B8A4-72F3-46CF-B6B2-5977968B18B6}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C1953F71-FA47-4535-AC67-E82B9620148B}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{C1A7B0DB-B53E-453B-8658-A3B6BAEA93EE}" = dir=in | app=c:\program files (x86)\hfn\client\tools\browser.exe |
"{C1DCA3D7-FB4E-43B8-BD8C-AEC1C82C106B}" = dir=in | app=c:\program files (x86)\hfn\client\capp.exe |
"{C23B35AC-DBA4-424D-8D1F-B1D6A2861FC6}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{C248194E-F0D3-4EE3-850C-4B5124DA2DCC}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{C291062B-CCF3-4BFB-8B1C-E8355D8E21E8}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{C42B1B5A-8DAC-4C6B-9748-37B3F5896CC4}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{C5E9FF03-8E37-4820-966B-867BEF3C947E}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{C725B53E-1E0F-4081-B08B-2F30DCC83CAF}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{C763A65F-DAF5-48F9-A474-D9B0A47B8A89}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{C8123F56-1016-4A3C-9E64-57FCEF514468}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{C8F1AB87-6A78-41F6-9D13-37E40A52E8AC}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{CAB2E27A-E7D5-4822-9216-628073C92D52}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{CAE68754-E523-4CCC-8703-B475A261DDAD}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{CD093C04-0765-4784-966F-E8A83AA670D9}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\dell\vlc\vlc.exe |
"{CE839D9C-8181-40BE-A820-A7B544827D1D}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{CEBED01B-234E-4F13-8B1F-AE9C33A05102}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{CEFAF312-E9FB-46B4-A1A4-803ED5E46E74}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{CF40560E-1F20-4BEF-8568-B2A03FB8DB9C}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{D055706D-FB63-4A16-A9AE-FE441F4243F0}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{D1011B2C-532F-4A63-856B-E152722D7B6B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{D4C0646D-9A02-4E55-9ECC-0BF76D350C8E}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{D5E1694C-1027-4D80-A838-BCF0C794C258}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{D6A5333A-0336-443A-A5B7-0F56214D8FA2}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{D6F9A8E3-482A-472D-9321-5464EE86BEBD}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{D9130AF9-D626-49AD-88C9-BF2A658A57B2}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{D9BF8BEC-F256-4D9C-A3DC-A5BD4657DD83}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{DA3A70FF-A3A3-4B04-921C-D290B4E18B6D}" = dir=in | app=c:\program files (x86)\hfn\client\custicn.exe |
"{DB0991EC-8A8A-41E6-98B0-714261549173}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{DC63BBB9-07A4-44A1-A573-A3A0025403B5}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{DD1034BC-40B3-4428-B4F0-BD2C51126CAA}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{DD524B59-8EBC-4DE2-8D6E-49F8A1B49B1A}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{DD6F208A-BAF5-4A84-A323-6AC446D276F1}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{E0006A35-1844-4091-A564-E28A5712A69D}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{E0152841-9C70-4C03-9580-C887502F9ECF}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{E15434F8-7C2A-466E-9789-6045E25B396D}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{E1C55461-26F1-412C-A1D8-94EACF02091B}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{E33F86F5-0C32-45A3-BC4A-C9A0E9DCC6D7}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{E35AB9A1-BAE6-4FD5-87B7-84D75769D11F}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{E380A813-6196-4371-898D-E4FA7390E768}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{E5687838-8DB0-469C-A509-DBE8BAD28A2D}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{E58B2D9E-3028-4BA6-880F-3632BEFC21AB}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{E5DA8766-69FF-4A4D-BC1E-67A420A0432B}" = protocol=6 | dir=in | app=c:\program files (x86)\research in motion\blackberry desktop\rim.desktop.exe |
"{E8B2DD37-1703-4786-93F3-C07A810A545A}" = dir=in | app=c:\program files (x86)\hfn\client\cutil.exe |
"{E97DD9A8-32E9-4D10-A6B8-FDB4B1D1F9CA}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{E999C29F-8099-4E80-98BB-321A76625B5A}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{EA13080B-1EE5-449D-823B-E29ACAB991B6}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{EA23E12A-A831-48B9-9F27-22EB2EAE27EE}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{EC0BDEA2-A77C-44C7-AFF6-4020729C38FD}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{ECB57195-A7C8-44D9-AB4F-CC219799B2BE}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{ED974A05-F612-4047-9C20-AB8C84A73490}" = dir=in | app=c:\program files (x86)\hfn\client\tools\browser.exe |
"{EDAFEFC9-1A0E-42A4-95E0-57D073D6D79A}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{F07E6E93-9A08-4095-9A7F-844203F588C1}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{F1ECCBA1-B04E-4B39-8924-9DCB768421C0}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |
"{F2ABE234-3616-4D2C-8102-353DD61421F5}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{F5067EA4-2AEC-45A5-969F-F4596DB9E529}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{F5D3AB60-54D1-49E5-8EEA-05B9467D49D0}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{F77F4478-4822-4238-82A6-DF1DDA1F1353}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{F885AA78-6AB3-4D75-878D-77A236A271F9}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F984697F-C1D0-46B7-90A7-F23C120B35B1}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{F98A7C00-EB70-494B-A844-9E48B7D3D41A}" = dir=in | app=c:\program files (x86)\hfn\client\dmidecode.exe |
"{FA1D8A97-6DEF-4981-9310-4B4894E51EDD}" = dir=in | app=c:\program files (x86)\hfn\client\srtct.exe |
"{FA4CF79C-E77B-4D7F-B713-0CFEC870F6A4}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{FA97C78A-E815-4A69-9823-D5F5619B73CE}" = dir=in | app=c:\program files (x86)\hfn\client\intfr.exe |
"{FA9DF517-D491-4696-97DB-A09E006C2607}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{FE8DC4D5-C7E2-42EB-96E9-B8D2B7BB3B04}" = dir=in | app=c:\program files (x86)\hfn\client\cust.exe |
"{FF4A64A1-E9A1-4FD8-9794-F3C817E3D4E3}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{FFE48BC3-69E1-499F-8B5D-82D0FB11C0C3}" = dir=in | app=c:\program files (x86)\hfn\client\srvc.exe |
"{FFF7986D-4021-4350-94C6-7392C4E56543}" = dir=in | app=c:\program files (x86)\hfn\client\rerun.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{02AD9D20-03D2-4DE0-8793-E8253026AD86}" = EMCGadgets64
"{1493B2AE-0261-47D2-B1AA-F4DAD0F6C48B}" = iTunes
"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{237D687E-9E50-4A30-B810-262764CC491B}" = Garmin Communicator Plugin x64
"{26A24AE4-039D-4CA4-87B4-2F86416017FF}" = Java™ 6 Update 17 (64-bit)
"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety
"{4BC310C4-B898-46E2-B5FB-B85A30AA7142}" = iCloud
"{550331CC-C34B-494F-BCDA-37CE4EF6E924}" = Garmin Communicator Plugin x64
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{60B2315F-680F-4EB3-B8DD-CCDC86A7CCAB}" = Roxio File Backup
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6DD01FF3-63CE-436B-96DB-61363EAA4EB8}" = MobileMe Control Panel
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7446FE8D-C1F9-4D42-AAAE-5DBCE58605A6}" = Apple Mobile Device Support
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8EBA8727-ADC2-477B-9D9A-1A1836BE4E05}" = Dell Edoc Viewer
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{AEC699FC-F916-46A0-B15E-70EF1534AE93}" = HP Officejet 6600 Basic Device Software
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{BFE972A5-DC62-03F9-F03E-8AC751DFE770}" = ccc-utility64
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DB9C43F7-0B0F-4E43-9E6B-F945C71C469E}" = VD64Inst
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{E60B7350-EA5F-41E0-9D6F-E508781E36D2}" = Dell Dock
"{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"98157A226B40B173301B0F53C8E98C47805D5152" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0)
"Creative OA002" = Monitor Webcam Driver (1.01.02.0804)
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{0228e555-4f9c-4e35-a3ec-b109a192b4c2}" = Google Gmail Notifier
"{03CEC5A3-648C-3E00-7CDB-C049B47A5EDC}" = CCC Help Spanish
"{051EF664-EB85-8320-1184-35136C6B0BEF}" = CCC Help Portuguese
"{055EE59D-217B-43A7-ABFF-507B966405D8}" = ATI Catalyst Control Center
"{0566E404-1FCB-16C4-C265-9415012650D5}" = CCC Help Korean
"{07BB25C3-55B6-303C-1E7C-2C528555014D}" = CCC Help Dutch
"{08E81ABD-79F7-49C2-881F-FD6CB0975693}" = Roxio Central Data
"{098122AB-C605-4853-B441-C0A4EB359B75}" = DirectXInstallService
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0ED7EE95-6A97-47AA-AD73-152C08A15B04}" = Dell DataSafe Local Backup
"{12BAA98C-F8DD-4BC9-BBE6-1C8463114197}" = BlackBerry Device Software Updater
"{1583FB9E-D1D7-A29B-F3D3-7D6B74D75128}" = Catalyst Control Center Graphics Previews Vista
"{17DFE37C-064E-4834-AD8F-A4B2B4DF68F8}" = Adobe Photoshop Elements 8.0
"{18E928DE-ABBA-4CEB-A9E4-205769B03FE8}" = Garmin BaseCamp
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1DD81E7D-0D28-4CEB-87B2-C041A4FCB215}" = Rapport
"{1EE6959C-49F2-5D45-A007-776A7A053043}" = CCC Help English
"{1F54DAFA-9261-4A62-B59D-6C9F26B48FE4}" = Roxio Central Tools
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20288888-A7AF-4B24-8AEB-398D20CD563C}" = Sound Blaster X-Fi
"{222E1C7F-5892-0015-BF94-914B7EBEB564}" = CCC Help Finnish
"{237CD223-1B9D-47E8-A76C-E478B83CCEA2}" = File Uploader
"{26A24AE4-039D-4CA4-87B4-2F83216034FF}" = Java™ 6 Update 37
"{28E82311-8616-11E1-BEB0-B8AC6F97B88E}" = Google Earth
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{30465B6C-B53F-49A1-9EBA-A3F187AD502E}" = Roxio Update Manager
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{38001EBD-D270-2BBC-CEAE-B88BDE197E16}" = CCC Help Russian
"{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}" = Garmin USB Drivers
"{4080C564-7174-4CE4-B0F3-2C75D6ECB134}" = BlackBerry Device Manager 6.0
"{415FA9AD-DA10-4ABE-97B6-5051D4795C90}" = HP FWUpdateEDO2
"{42E0794B-B4A6-CDB6-308F-04A5CA54B81E}" = CCC Help French
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4685A344-6718-4923-AA9D-158A0A2E1CFB}" = SmartSound Quicktracks for Premiere Elements 8.0
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4D919200-A01C-4873-BADE-BA68FFB9D237}" = Garmin nRoute - City Navigator North America v8
"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion
"{537BF16E-7412-448C-95D8-846E85A1D817}" = Roxio Easy CD and DVD Burning
"{599EAA99-BBA8-C8FF-C2EA-04D0C8FA6D89}" = Catalyst Control Center InstallProxy
"{5A06423A-210C-49FB-950E-CB0EB8C5CEC7}" = Roxio BackOnTrack
"{5DFB9027-0099-5816-8428-CF25B64B46C9}" = CCC Help Czech
"{5E3CFCA6-C95A-47CB-A822-7FA80D423AF2}" = MapSource
"{612B5D2E-8084-4102-91DE-24281E4EFB2C}" = Roxio Easy CD and DVD Burning
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{634CE363-2BB8-FF85-83C3-734699DFC570}" = CCC Help German
"{63EC2120-1742-4625-AA47-C6A8AEC9C64C}" = Apple Application Support
"{647BB978-2876-487B-9B0E-FDB73F0EA4A2}" = Garmin Communicator Plugin
"{6545416A-A60A-8DE4-3590-15F0662461DF}" = CCC Help Polish
"{6675CA7F-E51B-4F6A-99D4-F8F0124C6EAA}" = Roxio Express Labeler 3
"{6811CAA0-BF12-11D4-9EA1-0050BAE317E1}" = PowerDVD DX
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{73A4F29F-31AC-4EBD-AA1B-0CC5F18C8F83}" = Roxio Central Audio
"{75157F34-02C6-4831-BD66-3BC49E7A8394}" = BlackBerry Desktop Software 6.1
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{774A70C8-29CA-565A-FB84-01B408F119B2}" = CCC Help Chinese Standard
"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core
"{7DB9F1E5-9ACB-410D-A7DC-7A3D023CE045}" = Dell Getting Started Guide
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{844DA731-B8B0-4581-AF3C-5158CC16897E}" = BlackBerry v4.2.2 for the 8320 Series Wireless Handheld
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87441A59-5E64-4096-A170-14EFE67200C3}" = Picture Control Utility
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A9DE8C3-5B21-34EC-DE5D-BAFAB8D8C9D9}" = CCC Help Greek
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8D337F77-BE7F-41A2-A7CB-D5A63FD7049B}" = Sonic CinePlayer Decoder Pack
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_BASICR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_BASICR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_BASICR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_BASICR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_BASICR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_BASICR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_BASICR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_BASICR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_BASICR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_BASICR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_BASICR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0013-0000-0000-0000000FF1CE}" = Microsoft Office Basic 2007
"{91120000-0013-0000-0000-0000000FF1CE}_BASICR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91D1580F-35C5-8D29-144C-605E3568B3A5}" = Catalyst Control Center Graphics Full Existing
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95140000-007A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook Connector
"{958FD5FD-1F71-493B-CC6C-4922F3EA2356}" = CCC Help Danish
"{97B70991-5002-4241-8B0C-D74B8ADEB2B5}" = BlackBerry Desktop Software 7.1
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9AAD03E8-4F65-4DE2-8F6C-1B079C0C8521}" = Garmin Lifetime Updater
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9F308117-9B2F-45EB-9FAF-B59CD8339673}" = MapSource - Topo Canada v2
"{9FDFB9AE-B7A9-3481-E85C-08E7FA6D620B}" = Catalyst Control Center Graphics Full New
"{A0AD3E2F-427D-09F9-85FB-450E35A03046}" = CCC Help Hungarian
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A0E583D1-23F7-4C35-9620-B169D7715E4B}" = Adobe Premiere Elements 8.0
"{A0F584A7-B0C2-4D90-9580-15456B9CF63C}" = MapSource - Trip & Waypoint Manager v2
"{A1D31E2C-C7E1-2E6E-EAE9-0C3BAFB5B1F9}" = CCC Help Thai
"{A69D7B32-2BE9-42BF-B576-69B5E0FF7394}" = Catalyst Control Center - Branding
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9668246-FB70-4103-A1E3-66C9BC2EFB49}" = Dell DataSafe Local Backup - Support Software
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI
"{AC76BA86-7AD7-5464-3428-900000000004}" = Spelling Dictionaries Support For Adobe Reader 9
"{B2C07E85-76D6-DC01-48A9-7577AD95CD70}" = CCC Help Swedish
"{B6A26DE5-F2B5-4D58-9570-4FC760E00FCD}" = Roxio Central Copy
"{B91C2CFE-15D0-C863-963A-DFF09D2AE726}" = Catalyst Control Center Core Implementation
"{BACF2A73-2F91-9657-F9B5-10723A9B1E5B}" = CCC Help Italian
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C779648B-410E-4BBA-B75B-5815BCEFE71D}" = Safari
"{C818BA3A-226F-4ED0-9CEF-96A0DF300211}" = HP Officejet 6600 Help
"{C8694EE7-24F3-6593-FE50-00E575C79272}" = Skins
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{CDF7810C-10AB-7E95-ABC5-0D60C5761876}" = Catalyst Control Center Graphics Light
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CF3A3816-7E48-4556-8614-654377EDE1B5}" = BlackBerry App World Browser Plugin
"{CFF8B8E8-E086-4DE0-935F-FE22CAB54F80}" = Microsoft Search Enhancement Pack
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D5D35107-8CFE-5FFB-2D64-1CE29202493B}" = Catalyst Control Center Graphics Previews Common
"{D8D98FAB-17E7-A123-D654-6574E6187EE2}" = CCC Help Chinese Traditional
"{DAC44207-C17F-DAFA-CE5D-010AB94A38AB}" = CCC Help Norwegian
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E31C77D0-B0F0-318B-0A39-F57BF54D22AD}" = ccc-core-static
"{E9757890-7EC5-46C8-99AB-B00F07B6525C}" = Nikon Transfer
"{EA3CD5E7-0C84-2479-6490-B6228F87B174}" = CCC Help Japanese
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EC877639-07AB-495C-BFD1-D63AF9140810}" = Roxio Activation Module
"{ECEB9207-85FE-3004-CD20-5DAEE0F1D1E0}" = CCC Help Turkish
"{ED439A64-F018-4DD4-8BA5-328D85AB09AB}" = Roxio Central Core
"{F007CBCE-D714-4C0B-8CE9-9B0D78116468}" = ViewNX
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F18046C5-1C4E-4BE1-A3D6-A6F970E2E8E8}" = ArcSoft Panorama Maker 5
"{F66A31D9-7831-4FBA-BA02-C411C0047CC5}" = Dell Remote Access
"{F68AFC71-77CD-0B22-4C4F-C09097E058E9}" = Catalyst Control Center Localization All
"{FDB46DE7-9045-47BB-970A-3E4ED5369E03}" = EMC 10 Content
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop Elements 8.0" = Adobe Photoshop Elements 8.0
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"AudioCS" = Creative Audio Control Panel
"BASICR" = Microsoft Office Basic 2007
"Bejeweled 2" = Bejeweled 2
"BlackBerry_{4080C564-7174-4CE4-B0F3-2C75D6ECB134}" = BlackBerry Device Manager 6.0
"BlackBerry_Desktop" = BlackBerry Desktop Software 7.1
"Cisco Connect" = Cisco Connect
"Creative Software AutoUpdate" = Creative Software AutoUpdate
"Creative Sound Blaster Properties x64 Edition" = Creative Sound Blaster Properties x64 Edition
"Dolby Digital Live Pack" = Dolby Digital Live Pack
"Dream Chronicles - The Book of Air - Collector's Edition" = Dream Chronicles - The Book of Air - Collector's Edition
"Escape Whisper Valley" = Escape Whisper Valley
"Gardenscapes" = Gardenscapes
"HP Photo Creations" = HP Photo Creations
"InstallShield_{4685A344-6718-4923-AA9D-158A0A2E1CFB}" = SmartSound Quicktracks for Premiere Elements 8.0
"InstallShield_{9F308117-9B2F-45EB-9FAF-B59CD8339673}" = MapSource - Topo Canada v2
"InstallShield_{A0F584A7-B0C2-4D90-9580-15456B9CF63C}" = MapSource - Trip & Waypoint Manager v2
"Mah Jong Medley" = Mah Jong Medley
"McAfee Security Scan" = McAfee Security Scan Plus
"MSC" = McAfee SecurityCenter
"Mystery P.I. - The London Caper" = Mystery P.I. - The London Caper
"OpenAL" = OpenAL
"Plants vs. Zombies - Game of the Year Edition" = Plants vs. Zombies - Game of the Year Edition
"PremElem80" = Adobe Premiere Elements 8.0
"Rapport_msi" = Rapport
"SearchProtect" = Search Protect by conduit
"WinLiveSuite" = Windows Live Essentials
"Yahoo! Companion" = Yahoo! Toolbar
"Yahoo! Toolbar" = Yahoo! Toolbar
"YInstHelper" = Yahoo! Install Manager

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/15/2012 10:33:36 AM | Computer Name = Wayne-PC | Source = Windows Backup | ID = 4103
Description =

Error - 6/17/2012 10:00:02 PM | Computer Name = Wayne-PC | Source = Windows Backup | ID = 4103
Description =

Error - 6/24/2012 10:00:01 PM | Computer Name = Wayne-PC | Source = Windows Backup | ID = 4103
Description =

Error - 7/1/2012 10:00:01 PM | Computer Name = Wayne-PC | Source = Windows Backup | ID = 4103
Description =

Error - 7/8/2012 10:00:01 PM | Computer Name = Wayne-PC | Source = Windows Backup | ID = 4103
Description =

Error - 7/11/2012 12:28:19 PM | Computer Name = Wayne-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Explorer.EXE, version: 6.1.7601.17567,
time stamp: 0x4d672ee4 Faulting module name: ntdll.dll, version: 6.1.7601.17725,
time stamp: 0x4ec4aa8e Exception code: 0xc0000005 Fault offset: 0x00000000000532d0
Faulting
process id: 0xc84 Faulting application start time: 0x01cd5f81e3956372 Faulting application
path: C:\Windows\Explorer.EXE Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: 6bf13262-cb75-11e1-972d-a4badbf9f029

Error - 7/15/2012 10:00:01 PM | Computer Name = Wayne-PC | Source = Windows Backup | ID = 4103
Description =

Error - 7/23/2012 12:28:07 PM | Computer Name = Wayne-PC | Source = Windows Backup | ID = 4103
Description =

Error - 7/29/2012 10:00:02 PM | Computer Name = Wayne-PC | Source = Windows Backup | ID = 4103
Description =

Error - 8/5/2012 10:00:01 PM | Computer Name = Wayne-PC | Source = Windows Backup | ID = 4103
Description =

[ Dell Events ]
Error - 10/5/2010 1:34:18 AM | Computer Name = Wayne-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 10/5/2010 1:34:18 AM | Computer Name = Wayne-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 11/1/2010 2:00:48 PM | Computer Name = Wayne-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 11/1/2010 2:00:48 PM | Computer Name = Wayne-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 11/1/2010 2:40:58 PM | Computer Name = Wayne-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 11/1/2010 2:40:58 PM | Computer Name = Wayne-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

Error - 2/2/2011 10:47:45 AM | Computer Name = Wayne-PC | Source = DataSafe | ID = 17
Description = The process was interrupted before completion.

[ Media Center Events ]
Error - 12/29/2010 11:36:26 PM | Computer Name = Wayne-PC | Source = MCUpdate | ID = 0
Description = 7:36:22 PM - Error connecting to the internet. 7:36:22 PM - Unable
to contact server..

Error - 12/30/2010 8:16:19 AM | Computer Name = Wayne-PC | Source = MCUpdate | ID = 0
Description = 4:16:19 AM - Error connecting to the internet. 4:16:19 AM - Unable
to contact server..

Error - 12/30/2010 8:16:28 AM | Computer Name = Wayne-PC | Source = MCUpdate | ID = 0
Description = 4:16:24 AM - Error connecting to the internet. 4:16:24 AM - Unable
to contact server..

Error - 12/31/2010 8:05:12 AM | Computer Name = Wayne-PC | Source = MCUpdate | ID = 0
Description = 4:05:07 AM - Error connecting to the internet. 4:05:07 AM - Unable
to contact server..

Error - 12/31/2010 9:06:55 AM | Computer Name = Wayne-PC | Source = MCUpdate | ID = 0
Description = 5:06:51 AM - Error connecting to the internet. 5:06:51 AM - Unable
to contact server..

Error - 12/31/2010 10:08:37 AM | Computer Name = Wayne-PC | Source = MCUpdate | ID = 0
Description = 6:08:33 AM - Error connecting to the internet. 6:08:33 AM - Unable
to contact server..

Error - 12/31/2010 11:11:04 AM | Computer Name = Wayne-PC | Source = MCUpdate | ID = 0
Description = 7:11:00 AM - Error connecting to the internet. 7:11:00 AM - Unable
to contact server..

Error - 1/3/2011 8:42:13 AM | Computer Name = Wayne-PC | Source = MCUpdate | ID = 0
Description = 4:42:09 AM - Error connecting to the internet. 4:42:09 AM - Unable
to contact server..

Error - 1/3/2011 9:43:54 AM | Computer Name = Wayne-PC | Source = MCUpdate | ID = 0
Description = 5:43:50 AM - Error connecting to the internet. 5:43:50 AM - Unable
to contact server..

Error - 1/3/2011 10:45:36 AM | Computer Name = Wayne-PC | Source = MCUpdate | ID = 0
Description = 6:45:32 AM - Error connecting to the internet. 6:45:32 AM - Unable
to contact server..

[ System Events ]
Error - 12/21/2012 11:56:25 AM | Computer Name = Wayne-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RxFilter

Error - 12/21/2012 11:57:24 AM | Computer Name = Wayne-PC | Source = DCOM | ID = 10016
Description =

Error - 12/27/2012 4:55:18 PM | Computer Name = Wayne-PC | Source = Service Control Manager | ID = 7000
Description = The SessionLauncher service failed to start due to the following error:
%%2

Error - 12/27/2012 4:55:22 PM | Computer Name = Wayne-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RxFilter

Error - 12/27/2012 4:56:19 PM | Computer Name = Wayne-PC | Source = DCOM | ID = 10016
Description =

Error - 12/27/2012 8:12:12 PM | Computer Name = Wayne-PC | Source = Service Control Manager | ID = 7000
Description = The SASDIFSV service failed to start due to the following error: %%183

Error - 12/29/2012 4:47:23 PM | Computer Name = Wayne-PC | Source = EventLog | ID = 6008
Description = The previous system shutdown at 2:52:06 PM on ?28/?12/?2012 was unexpected.

Error - 12/29/2012 4:47:41 PM | Computer Name = Wayne-PC | Source = Service Control Manager | ID = 7000
Description = The SessionLauncher service failed to start due to the following error:
%%2

Error - 12/29/2012 4:47:52 PM | Computer Name = Wayne-PC | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
RxFilter

Error - 12/29/2012 4:48:47 PM | Computer Name = Wayne-PC | Source = DCOM | ID = 10016
Description =


< End of report >
OTL logfile created on: 12/29/2012 4:17:51 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Wayne\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

8.99 Gb Total Physical Memory | 7.04 Gb Available Physical Memory | 78.26% Memory free
17.98 Gb Paging File | 15.52 Gb Available in Paging File | 86.32% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.35 Gb Total Space | 782.52 Gb Free Space | 85.40% Space Free | Partition Type: NTFS

Computer Name: WAYNE-PC | User Name: Wayne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Wayne\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (Conduit)
PRC - C:\Program Files (x86)\SearchProtect\bin\cltmng.exe (Conduit)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\HFN\Client\srvc.exe (HFN, Inc.)
PRC - C:\Program Files (x86)\HFN\Client\cutil.exe (HFN, Inc.)
PRC - C:\Program Files (x86)\HFN\Client\cust.exe (HFN, Inc.)
PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe (Garmin)
PRC - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\WINDOWS\SysWOW64\Ctxfihlp.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\SysWOW64\CTxfispi.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\876b5ec452b8ffaadcbe7b7296de0709\System.ServiceModel.Routing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\7eeaa98a92b28ba3368a4b83da4e0d41\System.ServiceModel.Discovery.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\a824e0a83196df2336f9f6faed910bc6\System.ServiceModel.Activities.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel#\48ccfbe2b28f889dc78314cbe21b6dba\System.ServiceModel.Channels.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.ServiceModel\5273b47aa159f2aff854210c9f23a970\System.ServiceModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.IdentityModel\aaf1ee6452691a0129bfd4a982c1464c\System.IdentityModel.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Dura#\8a8d61b84948cb58f9cf0f32b630e16d\System.Runtime.DurableInstancing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Runtime.Seri#\b347108b7fd646ef7394352a242da23b\System.Runtime.Serialization.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\SMDiagnostics\69c443a8321bb072f9769fad6800d399\SMDiagnostics.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\23de8d00755205c37aa6795b0ce8a42d\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\2ac9ed65e7a7ccfcc1d4f4967540d993\System.Xml.Linq.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\c22857dbcce7e0320350436e80ec8ab1\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\78a485faba9584cfb1a5052a4cbe71e8\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\df5142941549ff71737438c85e565ab3\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\53121a27f94f7335e585384377fc538a\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\ccf3f783590b1747a3593b889bede2fb\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\a7cdf1caedee630b8440fb8e8657aca1\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\06db722a2ddebd960d907c2de6f1cfa7\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Configuration\c15c94b675becb485d940f8f0068dc5d\System.Configuration.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Security\471e9622a174c71be1b987575a92a1f6\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\ed7768172bbf30462bc554dee3911540\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\0bc033fa805a31e31dc462cfae365478\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\685f73e04393b5342bd1cebe701496ad\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\HFN\Client\trig000.dll ()
MOD - C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\39624\RapportMS.dll ()
MOD - C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\WINDOWS\SysWOW64\CtxfiRes.dll ()
MOD - C:\WINDOWS\SysWOW64\APOMngr.DLL ()


========== Services (SafeList) ==========

SRV:64bit: - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (mfevtp) – C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (MSK80Service) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) – C:\WINDOWS\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (CltMngSvc) – C:\Program Files (x86)\SearchProtect\bin\CltMngSvc.exe (Conduit)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (HFN Client) – C:\Program Files (x86)\HFN\Client\srvc.exe (HFN, Inc.)
SRV - (RapportMgmtService) – C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (AdobeActiveFileMonitor8.0) – c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (hnmsvc) – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
SRV - (RoxMediaDB10) – c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\RoxMediaDB10.exe (Sonic Solutions)
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) – c:\program files\dell support center\pcdsrvc_x64.pkms File not found
DRV:64bit: - (cfwids) – C:\WINDOWS\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\WINDOWS\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\WINDOWS\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfehidk) – C:\WINDOWS\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\WINDOWS\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\WINDOWS\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\WINDOWS\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (RdpVideoMiniport) – C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\WINDOWS\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (kbfilter) – C:\WINDOWS\SysNative\drivers\kbfilter.sys (Trend Micro Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\WINDOWS\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RapportKE64) – C:\WINDOWS\SysNative\drivers\RapportKE64.sys (Trusteer Ltd.)
DRV:64bit: - (HipShieldK) – C:\WINDOWS\SysNative\drivers\HipShieldK.sys (McAfee, Inc.)
DRV:64bit: - (grmnusb) – C:\WINDOWS\SysNative\drivers\grmnusb.sys (GARMIN Corp.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\WINDOWS\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (RimUsb) – C:\WINDOWS\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (RimVSerPort) – C:\WINDOWS\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (amdsata) – C:\WINDOWS\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\WINDOWS\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\WINDOWS\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (fssfltr) – C:\WINDOWS\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (ha20x22k) – C:\WINDOWS\SysNative\drivers\ha20x22k.sys (Creative Technology Ltd)
DRV:64bit: - (ha20x2k) – C:\WINDOWS\SysNative\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV:64bit: - (emupia) – C:\WINDOWS\SysNative\drivers\emupia2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctsfm2k) – C:\WINDOWS\SysNative\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctprxy2k) – C:\WINDOWS\SysNative\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV:64bit: - (ossrv) – C:\WINDOWS\SysNative\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV:64bit: - (ctaud2k) – C:\WINDOWS\SysNative\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctac32k) – C:\WINDOWS\SysNative\drivers\ctac32k.sys (Creative Technology Ltd)
DRV:64bit: - (CTEXFIFX.SYS) – C:\WINDOWS\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:64bit: - (CTEXFIFX) – C:\WINDOWS\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:64bit: - (CTHWIUT.SYS) – C:\WINDOWS\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CTHWIUT) – C:\WINDOWS\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CT20XUT.SYS) – C:\WINDOWS\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CT20XUT) – C:\WINDOWS\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:64bit: - (atikmdag) – C:\WINDOWS\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (FTDIBUS) – C:\WINDOWS\SysNative\drivers\ftdibus.sys (FTDI Ltd.)
DRV:64bit: - (FTSER2K) – C:\WINDOWS\SysNative\drivers\ftser2k.sys (FTDI Ltd.)
DRV:64bit: - (AtiHdmiService) – C:\WINDOWS\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (JRAID) – C:\WINDOWS\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (HCW85BDA) – C:\WINDOWS\SysNative\drivers\HCW85BDA.sys (Hauppauge Computer Works)
DRV:64bit: - (amdsbs) – C:\WINDOWS\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\WINDOWS\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\WINDOWS\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\WINDOWS\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\WINDOWS\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ROOTMODEM) – C:\WINDOWS\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) – C:\WINDOWS\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (Packet) – C:\WINDOWS\SysNative\drivers\packet.sys (SingleClick Systems)
DRV:64bit: - (ebdrv) – C:\WINDOWS\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\WINDOWS\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\WINDOWS\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\WINDOWS\SysNative\drivers\HCW85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\WINDOWS\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\WINDOWS\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (RTL8167) – C:\WINDOWS\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (OA002Vid) – C:\WINDOWS\SysNative\drivers\OA002Vid.sys (Creative Technology Ltd.)
DRV:64bit: - (OA002Ufd) – C:\WINDOWS\SysNative\drivers\OA002Ufd.sys (Creative Technology Ltd.)
DRV:64bit: - (OA002Afx) – C:\WINDOWS\SysNative\drivers\OA002Afx.sys (Creative Technology Ltd.)
DRV:64bit: - (WimFltr) – C:\WINDOWS\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (RapportCerberus_43926) – C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys ()
DRV - (RapportEI64) – C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys (Trusteer Ltd.)
DRV - (RapportPG64) – C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys (Trusteer Ltd.)
DRV - (WIMMount) – C:\WINDOWS\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (RxFilter) – C:\WINDOWS\SysWOW64\drivers\RxFilter.sys (Sonic Solutions)
DRV - (Packet) – C:\WINDOWS\SysWOW64\drivers\packet.sys (SingleClick Systems)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE:64bit: - HKLM\..\SearchScopes\{ED2F724C-8FEE-4F8A-87E6-10678B5D6E07}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/USCON/23
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/
IE - HKCU\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7ADFA_en
IE - HKCU\..\SearchScopes\{AB79D3B4-AEDB-428a-B504-BAC00521A1C7}: "URL" = http://search.musicfrost.com/results.php?q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rim.com/npappworld: C:\Program Files (x86)\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll ()
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files (x86)\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Wayne\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\WeatherBlink\bar\1.bin [2011/12/16 15:26:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/12/11 21:14:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\McAfee\MSK [2012/12/09 15:16:43 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - default_search_provider: MF Custom Search (Enabled)
CHR - default_search_provider: search_url = http://search.musicfrost.com/results.php?q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif\10.13.20.29_0\plugins/np-cwmp.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U37 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: BlackBerry AppWorld (Enabled) = C:\Program Files (x86)\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\Program Files (x86)\Yahoo!\Common\npyaxmpb.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Wayne\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: WhiteSmoke US New = C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif\10.13.20.29_0\

O1 HOSTS File: ([2009/06/10 13:00:26 | 000,000,824 | —- | M]) - C:\WINDOWS\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (no name) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No CLSID value found.
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120622003851.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Garmin Lifetime Updater] C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe (Garmin)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKLM..\Run: [SearchProtectAll] C:\Program Files (x86)\SearchProtect\bin\cltmng.exe (Conduit)
O4 - HKCU..\Run: [HP Officejet 6600 (NET)] C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - Startup: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O8:64bit: - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files%20(x86)/Mah%20Jong%20Medley/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwareup…015/CTSUEng.cab (Creative Software AutoUpdate 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15118/CTPID.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/4.0.4.0…xControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8 8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E1BCCB63-E486-4006-AD24-F329D7216AE6}: DhcpNameServer = 8.8.8.8 8.8.4.4
O18:64bit: - Protocol\Handler\gopher - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - (EXPLORER.EXE) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/12/29 16:14:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Wayne\Desktop\OTL.exe
[2012/12/29 12:52:24 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/12/27 15:24:00 | 000,066,360 | —- | C] (Trend Micro Inc.) – C:\Windows\SysNative\drivers\kbfilter.sys
[2012/12/27 15:24:00 | 000,066,360 | —- | C] (Trend Micro Inc.) – C:\kbfilter.sys
[2012/12/27 15:08:37 | 000,000,000 | —D | C] – C:\ProgramData\Trend Micro
[2012/12/27 15:06:22 | 000,000,000 | —D | C] – C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/12/27 15:06:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2012/12/27 15:05:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\SearchProtect
[2012/12/27 15:05:11 | 000,000,000 | —D | C] – C:\Users\Wayne\AppData\Roaming\SearchProtect
[2012/12/27 15:05:04 | 000,000,000 | —D | C] – C:\Users\Wayne\AppData\Roaming\Trend Micro
[2012/12/27 15:05:04 | 000,000,000 | —D | C] – C:\Users\Wayne\AppData\Local\CRE
[2012/12/27 15:03:53 | 000,000,000 | —D | C] – C:\Users\Wayne\AppData\Roaming\OpenCandy
[2012/12/27 13:47:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\MusicFrost
[2012/12/20 18:55:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Garmin GPS Plugin
[2012/12/20 16:12:49 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2012/12/20 16:12:49 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2012/12/20 16:12:49 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2012/12/20 16:12:48 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2012/12/20 16:12:48 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2012/12/20 16:12:46 | 004,916,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2012/12/20 16:12:46 | 003,174,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2012/12/20 16:12:46 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2012/12/20 16:12:46 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2012/12/20 16:12:46 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprt.exe
[2012/12/20 16:12:46 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2012/12/20 16:12:46 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2012/12/20 16:12:46 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2012/12/20 16:12:46 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpendp_winip.dll
[2012/12/20 16:12:46 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpendp_winip.dll
[2012/12/20 16:12:46 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TSWbPrxy.exe
[2012/12/20 16:12:46 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsRdpWebAccess.dll
[2012/12/20 16:12:46 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsRdpWebAccess.dll
[2012/12/20 16:12:46 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2012/12/20 16:12:46 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2012/12/20 16:12:46 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2012/12/20 16:12:46 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprtPS.dll
[2012/12/20 16:12:46 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wksprtPS.dll
[2012/12/20 16:12:45 | 005,773,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2012/12/20 16:12:18 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2012/12/20 16:12:18 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2012/12/20 16:12:17 | 000,367,616 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2012/12/20 16:12:17 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2012/12/20 16:12:00 | 001,448,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2012/12/20 16:12:00 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2012/12/20 16:11:55 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2012/12/20 16:11:55 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2012/12/18 11:32:01 | 000,000,000 | —D | C] – C:\Users\Wayne\Documents\Garmin maps
[2012/12/18 04:34:54 | 000,000,000 | —D | C] – C:\Users\Wayne\AppData\Local\Garmin
[2012/12/18 04:34:52 | 000,000,000 | —D | C] – C:\Users\Wayne\Documents\My Garmin
[2012/12/18 04:34:51 | 000,000,000 | —D | C] – C:\ProgramData\Garmin
[2012/12/18 04:34:45 | 000,000,000 | —D | C] – C:\Users\Wayne\AppData\Local\GARMIN_Corp
[2012/12/18 04:31:20 | 000,000,000 | —D | C] – C:\Users\Wayne\Documents\BaseCamp
[2012/12/17 12:24:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MapSource
[2012/12/17 12:24:32 | 000,000,000 | —D | C] – C:\Garmin
[2012/12/16 08:19:11 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2012/12/13 08:11:54 | 000,000,000 | —D | C] – C:\Program Files\Garmin GPS Plugin
[2012/12/13 08:11:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
[2012/12/13 08:11:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Garmin
[2012/12/12 03:00:55 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/12/12 03:00:54 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/12/12 03:00:54 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/12/12 03:00:54 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/12/12 03:00:54 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/12/12 03:00:54 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/12/12 03:00:54 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/12/12 03:00:54 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/12/12 03:00:53 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/12/12 03:00:53 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/12/12 03:00:53 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/12/12 03:00:53 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/12/12 03:00:52 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/12/12 03:00:52 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/12/12 03:00:52 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/12/12 02:29:05 | 001,161,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012/12/12 02:29:05 | 000,424,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012/12/12 02:29:05 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012/12/12 02:29:05 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012/12/12 02:29:03 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012/12/12 02:29:03 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012/12/12 02:29:03 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012/12/12 02:29:02 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012/12/12 02:29:02 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012/12/12 02:29:02 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012/12/12 02:29:02 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012/12/12 02:29:00 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012/12/12 02:28:59 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/12/12 02:28:58 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012/12/12 02:28:58 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012/12/12 02:28:58 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012/12/12 02:28:58 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012/12/12 02:28:57 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012/12/12 02:28:57 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012/12/12 02:28:57 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/12/12 02:28:57 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012/12/12 02:28:56 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012/12/12 02:28:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012/12/12 02:28:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012/12/12 02:28:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012/12/12 02:28:54 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012/12/12 02:28:54 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012/12/12 02:28:54 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012/12/12 02:28:53 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012/12/12 02:28:53 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012/12/12 02:28:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012/12/12 02:28:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012/12/12 02:28:52 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012/12/12 02:28:22 | 000,478,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnet.dll
[2012/12/12 02:28:22 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnet.dll

========== Files - Modified Within 30 Days ==========

[2012/12/29 16:14:05 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Wayne\Desktop\OTL.exe
[2012/12/29 15:38:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/12/29 12:55:35 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/29 12:55:35 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/29 12:52:18 | 000,730,512 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/12/29 12:47:50 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/12/29 12:47:09 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/12/29 12:46:54 | 2945,699,839 | -HS- | M] () – C:\hiberfil.sys
[2012/12/28 14:39:43 | 001,541,120 | —- | M] () – C:\Users\Wayne\Documents\contacts.pst
[2012/12/27 18:55:52 | 000,001,262 | —- | M] () – C:\Users\Wayne\Desktop\Internet Explorer.lnk
[2012/12/27 15:06:22 | 000,002,975 | —- | M] () – C:\Users\Wayne\Desktop\HiJackThis.lnk
[2012/12/27 15:05:54 | 000,000,009 | —- | M] () – C:\END
[2012/12/27 12:59:47 | 000,631,318 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/12/27 12:59:47 | 000,111,442 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/12/22 06:17:26 | 000,062,308 | —- | M] () – C:\Windows\SysNative\BMXStateBkp-{00000002-00000000-00000000-00001102-0000000B-00441102}.rfx
[2012/12/22 06:17:26 | 000,062,308 | —- | M] () – C:\Windows\SysNative\BMXState-{00000002-00000000-00000000-00001102-0000000B-00441102}.rfx
[2012/12/22 06:17:26 | 000,000,820 | —- | M] () – C:\Windows\SysNative\DVCState-{00000002-00000000-00000000-00001102-0000000B-00441102}.rfx
[2012/12/21 07:53:21 | 000,001,256 | —- | M] () – C:\Users\Wayne\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/12/20 16:14:46 | 000,345,728 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/12/18 14:14:47 | 000,078,820 | —- | M] () – C:\Users\Wayne\Documents\Untitled.gdb
[2012/12/18 11:10:52 | 000,000,020 | -H– | M] () – C:\ProgramData\PKP_DLdu.DAT
[2012/12/18 10:04:27 | 000,001,914 | —- | M] () – C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 6600 (Network).lnk
[2012/12/17 12:24:36 | 000,001,413 | —- | M] () – C:\Users\Public\Desktop\MapSource.lnk
[2012/12/16 09:11:22 | 000,046,080 | —- | M] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2012/12/16 06:45:03 | 000,367,616 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2012/12/16 06:13:28 | 000,295,424 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2012/12/16 06:13:20 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2012/12/13 08:29:53 | 002,354,511 | —- | M] () – C:\Users\Wayne\Documents\Nuvi 2595 manual.pdf
[2012/12/13 08:11:51 | 000,001,974 | —- | M] () – C:\Users\Public\Desktop\Garmin Lifetime Updater.lnk

========== Files Created - No Company Name ==========

[2012/12/27 18:55:52 | 000,001,262 | —- | C] () – C:\Users\Wayne\Desktop\Internet Explorer.lnk
[2012/12/27 15:24:00 | 000,007,693 | —- | C] () – C:\kbfilter.cat
[2012/12/27 15:24:00 | 000,002,605 | —- | C] () – C:\kbfilter.inf
[2012/12/27 15:24:00 | 000,000,098 | —- | C] () – C:\install.bat
[2012/12/27 15:24:00 | 000,000,081 | —- | C] () – C:\uninstall.bat
[2012/12/27 15:06:22 | 000,002,975 | —- | C] () – C:\Users\Wayne\Desktop\HiJackThis.lnk
[2012/12/27 15:04:21 | 000,000,009 | —- | C] () – C:\END
[2012/12/17 12:24:36 | 000,001,413 | —- | C] () – C:\Users\Public\Desktop\MapSource.lnk
[2012/12/13 08:29:53 | 002,354,511 | —- | C] () – C:\Users\Wayne\Documents\Nuvi 2595 manual.pdf
[2012/12/13 08:11:51 | 000,001,974 | —- | C] () – C:\Users\Public\Desktop\Garmin Lifetime Updater.lnk
[2012/08/20 17:25:40 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2012/05/25 04:57:19 | 000,000,000 | —- | C] () – C:\Users\Wayne\AppData\Local\rx_image32.Cache
[2011/12/16 16:14:59 | 000,162,304 | —- | C] () – C:\Windows\SysWow64\ztvunrar36.dll
[2011/12/16 16:14:59 | 000,153,088 | —- | C] () – C:\Windows\SysWow64\unrar3.dll
[2011/12/16 16:14:59 | 000,077,312 | —- | C] () – C:\Windows\SysWow64\ztvunace26.dll
[2011/12/16 16:14:59 | 000,075,264 | —- | C] () – C:\Windows\SysWow64\unacev2.dll
[2011/01/04 16:49:45 | 000,000,000 | —- | C] () – C:\Windows\ViewNX.INI
[2011/01/04 07:54:56 | 000,148,156 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011/01/03 12:00:08 | 000,734,810 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/12/30 08:05:55 | 000,000,268 | RH– | C] () – C:\Users\Wayne\AppData\Roaming\MIDI Patch Names
[2010/12/30 08:05:55 | 000,000,268 | RH– | C] () – C:\ProgramData\Master
[2010/12/30 08:05:55 | 000,000,020 | -H– | C] () – C:\ProgramData\PKP_DLdw.DAT
[2010/12/30 08:05:55 | 000,000,012 | RH– | C] () – C:\ProgramData\Organic
[2010/12/30 08:04:27 | 000,000,268 | RH– | C] () – C:\Users\Wayne\AppData\Roaming\MIDI Devices
[2010/12/30 08:04:27 | 000,000,268 | RH– | C] () – C:\ProgramData\Mail
[2010/12/30 08:04:27 | 000,000,020 | -H– | C] () – C:\ProgramData\PKP_DLdu.DAT
[2010/12/30 08:04:27 | 000,000,012 | RH– | C] () – C:\ProgramData\Nature
[2010/11/01 09:53:44 | 000,007,168 | —- | C] () – C:\Users\Wayne\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/12 05:50:41 | 000,000,017 | —- | C] () – C:\Users\Wayne\AppData\Local\resmon.resmoncfg
[2010/06/10 16:33:55 | 000,103,272 | —- | C] () – C:\Users\Wayne\GoToAssistDownloadHelper.exe

========== ZeroAccess Check ==========

[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\shell32.dll – [2012/06/08 21:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 20:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\wbem\fastprox.dll – [2009/07/13 17:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 04:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\wbem\wbemess.dll – [2009/07/13 17:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2010/11/28 21:12:13 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Awem
[2010/11/17 19:10:34 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Big Fish Games
[2010/08/27 09:32:17 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Boolat Games
[2010/11/23 14:16:52 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Casual Mechanics
[2011/01/11 18:50:25 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\cerasus.media
[2011/01/02 20:15:49 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\ERS G-Studio
[2010/11/28 13:50:34 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Fabulous Finds
[2011/01/02 21:27:18 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Friday's games
[2010/10/30 19:30:58 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\GameHouse
[2012/12/18 06:25:16 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\GARMIN
[2010/11/21 21:46:26 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Gold Casual Games
[2010/12/31 22:33:34 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\HitPoint Studios
[2010/11/23 14:30:05 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\LaJangada
[2010/08/27 12:42:26 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\MagicIndie
[2011/01/02 13:50:47 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\MasterThief
[2010/11/20 15:38:27 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Merscom
[2010/12/30 08:22:18 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Nikon
[2010/10/31 06:37:24 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\No Company Name
[2012/12/27 15:03:54 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\OpenCandy
[2011/05/26 11:01:44 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\PCDr
[2010/11/30 21:23:58 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\PlayFirst
[2010/08/27 21:01:39 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Playrix Entertainment
[2010/11/16 22:03:43 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\PoBros
[2010/10/12 06:39:25 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Registry Mechanic
[2010/11/01 09:53:35 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Research In Motion
[2012/12/27 15:10:39 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\SearchProtect
[2010/12/30 21:38:19 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\ShinyTales
[2011/01/13 20:30:06 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Silverback Productions
[2012/12/27 16:07:58 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Simply Super Software
[2011/01/20 11:02:00 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\SpinTop
[2010/11/21 20:45:55 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\SpinTop Games
[2011/01/08 15:32:45 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\TheFixerUpper
[2010/08/27 15:19:28 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\TitanicMystery
[2010/08/05 07:47:45 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Trusteer
[2010/06/13 05:48:54 | 000,000,000 | —D | M] – C:\Users\Wayne\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >
[2007/11/07 07:03:18 | 000,562,688 | —- | M] (Microsoft Corporation) – C:\install.exe

< MD5 for: EXPLORER.EXE >
[2010/04/01 23:58:02 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=00B0358734CAA32C39D181FE6916B178 – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe
[2011/02/25 22:23:14 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/25 21:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 17:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/25 21:51:13 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/30 21:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/25 21:33:07 | 002,614,784 | —- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\WINDOWS\explorer.exe
[2011/02/24 22:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/25 22:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 04:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2010/04/01 23:58:02 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=6D4F9E4B640B413C6F73414327484C80 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe
[2010/04/01 23:58:04 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/24 21:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\WINDOWS\SysWOW64\explorer.exe
[2011/02/24 21:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/30 22:34:59 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2010/04/01 23:58:04 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 05:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/30 22:38:38 | 002,870,272 | —- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2010/04/01 23:58:04 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 17:39:10 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/30 22:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2010/04/01 23:58:02 | 002,868,736 | —- | M] (Microsoft Corporation) MD5=CA17F8620815267DC838E30B68CB5052 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe
[2011/02/25 22:26:45 | 002,870,784 | —- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2010/04/01 23:58:04 | 002,868,224 | —- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 – C:\WINDOWS\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2010/04/01 23:58:02 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=FC89FACA0473641CB625EDA9277D0885 – C:\WINDOWS\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 17:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\WINDOWS\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\WINDOWS\SysWOW64\svchost.exe
[2009/07/13 17:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\WINDOWS\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\Windows\SysNative\svchost.exe
[2009/07/13 17:39:46 | 000,027,136 | —- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D – C:\WINDOWS\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\WINDOWS\SysWOW64\userinit.exe
[2010/11/20 04:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\WINDOWS\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 17:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\WINDOWS\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe
[2009/07/13 17:39:48 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=6F8F1376A13114CC10C0E69274F5A4DE – C:\WINDOWS\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_381dabbceb60feb2\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\Windows\SysNative\userinit.exe
[2010/11/20 05:25:24 | 000,030,720 | —- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 – C:\WINDOWS\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 05:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\WINDOWS\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 17:39:52 | 000,389,120 | —- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A – C:\WINDOWS\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2009/10/27 23:01:57 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\WINDOWS\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2009/10/27 22:24:40 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\WINDOWS\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: SAMSUNG HD103SJ
Partitions: 3
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 39.00MB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 15.00GB
Starting Offset: 41943040
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 916.00GB
Starting Offset: 16280190976
Hidden sectors: 0


========== Hard Links - Junction Points - Mount Points - Symbolic Links ==========
[C:\Windows\System32\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\System32\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\System32\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\System32\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\System32\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\System32\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\System32\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\System32\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\System32\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\System32\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\System32\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\System32\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\History] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History -> Junction
[C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Temporary Internet Files] -> C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Application Data] -> C:\Windows\system32\config\systemprofile\AppData\Roaming -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Cookies] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Music] -> C:\Windows\system32\config\systemprofile\Music -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Pictures] -> C:\Windows\system32\config\systemprofile\Pictures -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Documents\My Videos] -> C:\Windows\system32\config\systemprofile\Videos -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Local Settings] -> C:\Windows\system32\config\systemprofile\AppData\Local -> Junction
[C:\Windows\SysWOW64\config\systemprofile\My Documents] -> C:\Windows\system32\config\systemprofile\Documents -> Junction
[C:\Windows\SysWOW64\config\systemprofile\NetHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\PrintHood] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Recent] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent -> Junction
[C:\Windows\SysWOW64\config\systemprofile\SendTo] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Start Menu] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu -> Junction
[C:\Windows\SysWOW64\config\systemprofile\Templates] -> C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates -> Junction

========== Alternate Data Streams ==========

@Alternate Data Stream - 995 bytes -> C:\Users\Wayne\Documents\ING Direct.eml:OECustomProperty
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:BE7A0841
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:F4F4A435
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:71173EF9
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:569033D0
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:2032CC2B
@Alternate Data Stream - 837 bytes -> C:\Users\Wayne\Documents\Marina Operators Legal Liability.eml:OECustomProperty
@Alternate Data Stream - 64 bytes -> C:\Users\Wayne\Documents\problemepsychiatriquelepitou.mpeg:TOC.WMV
@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:7B70C2D6
@Alternate Data Stream - 155 bytes -> C:\ProgramData\TEMP:F568DD7B
@Alternate Data Stream - 154 bytes -> C:\ProgramData\TEMP:57DC3B52
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:BB8B6B1E
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:C48A983C
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:04FDFCF6
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:C60C6342
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:A21E43C2
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:4F63029C
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:21F1378A
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:CCC4018A
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:370A117C
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:AB957E48
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:708E3F13
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:56EE2CAF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:157D4840
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:A8C08E7E
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:D853F961
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:D751C674
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:35F7F01D
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:73C7924E
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:B30D9A49
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:BB61BFAF
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:CF6A6C8A
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:9AB15E7A
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:43A7A7AD
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:D3D507A6
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:D1BCFD4A
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:C447EE44
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:8D25608D
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:2D7D575C
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:987DED13
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:0441DB7A
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:9AF9C79E
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:12B6A5EC
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:E51234A9
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:B8761AAB
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:ADE2C1A6
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:F321F01E
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:D41AB8D0
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:90FD8AD5
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:50B14AA6
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:1ED30878
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:117354E5
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:F57D2F43
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:78AFAE94
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:4C6DC495
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:20767002
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:F0A3E54E
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:F28885DF
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:F216755A
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:E8B5993B
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:DB8ED159
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:98DFF516
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:83E716F0
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:304D2C3C
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:B618BFFE
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:178D4338
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:C6E49090
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:9B27D3A9
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:7B0B85D2
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:452C4003
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:3477DE06
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:ACECBBFF
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:74E00408
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:2D09AB80
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:14859C24
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:F1E651F6
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:4A7C296A
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:32A38B26
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:AC8ECED1
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:7C60A173
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:239CC213
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:4AC9B4B7
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:5D59B736
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:55EFEB27
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:2A6414DE
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:04107365
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:B3BAC02F
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:53747726
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:359163DE
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:CFF21EA7
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:C7F04040
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:8BB2EC84
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:7D271B34
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:41D53451
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:026B76F2
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:EB6CB455
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:A17AFE82
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:485A9313
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D35663D1
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:88E71AC6
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:77A023CE
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:3325D6E9
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:D68FBF6D
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:A2CEDFBB
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:A25C1F6E
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:5A99DEB7
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:38BFF11F
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:0AC32449
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:EFEF58CC
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:B7D0D9DB
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:16ED1DDB

< End of report >
aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2012-12-29 16:50:37 —————————– 16:50:37.566 OS Version: Windows x64 6.1.7601 Service Pack 1 16:50:37.566 Number of processors: 8 586 0x1A05 16:50:37.566 ComputerName: WAYNE-PC UserName: Wayne 16:50:38.517 Initialize success 16:52:29.231 AVAST engine defs: 12122901 16:52:36.422 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 16:52:36.422 Disk 0 Vendor: SAMSUNG_ 1AJ1 Size: 953869MB BusType: 3 16:52:36.422 Disk 0 MBR read successfully 16:52:36.422 Disk 0 MBR scan 16:52:36.438 Disk 0 Windows 7 default MBR code 16:52:36.438 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63 16:52:36.453 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15486 MB offset 81920 16:52:36.469 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 938342 MB offset 31797248 16:52:36.485 Disk 0 scanning C:\Windows\system32\drivers 16:52:46.016 Service scanning 16:53:04.955 Modules scanning 16:53:04.955 Disk 0 trace - called modules: 16:53:04.970 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 16:53:05.485 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008abf060] 16:53:05.485 3 CLASSPNP.SYS[fffff88001bcf43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8008734050] 16:53:51.833 AVAST engine scan C:\Windows 16:53:53.845 AVAST engine scan C:\Windows\system32 16:53:58.946 Disk 0 MBR has been saved successfully to "C:\Users\Wayne\Desktop\MBR.dat" 16:53:58.962 The log file has been saved successfully to "C:\Users\Wayne\Desktop\aswMBR.txt" aswMBR version 0.9.9.1707 Copyright© 2011 AVAST Software Run date: 2012-12-29 16:50:37 —————————– 16:50:37.566 OS Version: Windows x64 6.1.7601 Service Pack 1 16:50:37.566 Number of processors: 8 586 0x1A05 16:50:37.566 ComputerName: WAYNE-PC UserName: Wayne 16:50:38.517 Initialize success 16:52:29.231 AVAST engine defs: 12122901 16:52:36.422 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IAAStorageDevice-1 16:52:36.422 Disk 0 Vendor: SAMSUNG_ 1AJ1 Size: 953869MB BusType: 3 16:52:36.422 Disk 0 MBR read successfully 16:52:36.422 Disk 0 MBR scan 16:52:36.438 Disk 0 Windows 7 default MBR code 16:52:36.438 Disk 0 Partition 1 00 DE Dell Utility Dell 8.0 39 MB offset 63 16:52:36.453 Disk 0 Partition 2 80 (A) 07 HPFS/NTFS NTFS 15486 MB offset 81920 16:52:36.469 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 938342 MB offset 31797248 16:52:36.485 Disk 0 scanning C:\Windows\system32\drivers 16:52:46.016 Service scanning 16:53:04.955 Modules scanning 16:53:04.955 Disk 0 trace - called modules: 16:53:04.970 ntoskrnl.exe CLASSPNP.SYS disk.sys iaStor.sys hal.dll 16:53:05.485 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8008abf060] 16:53:05.485 3 CLASSPNP.SYS[fffff88001bcf43f] -> nt!IofCallDriver -> \Device\Ide\IAAStorageDevice-1[0xfffffa8008734050] 16:53:51.833 AVAST engine scan C:\Windows 16:53:53.845 AVAST engine scan C:\Windows\system32 16:53:58.946 Disk 0 MBR has been saved successfully to "C:\Users\Wayne\Desktop\MBR.dat" 16:53:58.962 The log file has been saved successfully to "C:\Users\Wayne\Desktop\aswMBR.txt" 16:56:39.720 AVAST engine scan C:\Windows\system32\drivers 16:56:51.451 AVAST engine scan C:\Users\Wayne 16:57:14.087 Disk 0 MBR has been saved successfully to "C:\Users\Wayne\Desktop\MBR.dat" 16:57:14.087 The log file has been saved successfully to "C:\Users\Wayne\Desktop\aswMBR.txt"
This seem so much more than I am used to that I dont even know if you are getting any of what I am sending . I uninstalled Google chrome the other day and my computer seems to be working better..Thank you so much for the help, Ilook forward to hearing from you
Hi ENYAW22,

You're doing fine. Please do not add or remove any programs unless specifically asked to do so. Changes to the system during the cleaning process might delay our progress. Also, post all logs requested in one post if they will fit.

= = = = = = = = = = = = = = = = = = = =

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • SearchProtect
Next

Download AdwCleaner to your desktop.

Right click and select "Run as Administrator".
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
Next

[external image: Posted Image] Please download Junkware Removal Tool to your desktop.
  • Shut down your protection software now to avoid potential conflicts.
  • Run the tool by double-clicking it. If you are using Windows Vista, 7, or 8; instead of double-clicking, right-mouse click JRT.exe and select "Run as Administrator".
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
Next

Refer to the ComboFix User's Guide

  • Download ComboFix from the following location:

    Link

    * IMPORTANT !!! Place ComboFix.exe on your Desktop
  • Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with ComboFix.
    You can get help on disabling your protection programs here
  • Double click on ComboFix.exe & follow the prompts.
  • Your desktop may go blank. This is normal. It will return when ComboFix is done. ComboFix may reboot your machine. This is normal.
  • When finished, it shall produce a log for you. Post that log in your next reply

    Note: Do not mouseclick combofix's window whilst it's running. That may cause it to stall.

    ———————————————————————————————
  • Ensure your AntiVirus and AntiSpyware applications are re-enabled.
    ———————————————————————————————
NOTE: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

In your next post please provide the following:
  • AdwCleaner log
  • JRT.txt
  • ComboFix.txt
  • How is the computer running at the moment?
Thanks again fo# AdwCleaner v2.104 - Logfile created 12/31/2012 at 08:13:25
# Updated 29/12/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Wayne - WAYNE-PC
# Boot Mode : Normal
# Running from : C:\Users\Wayne\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\END
Folder Deleted : C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif
Folder Deleted : C:\Users\Wayne\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Wayne\AppData\Roaming\OpenCandy

***** [Registry] *****

Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\SmartBar
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\Google\Chrome\Extensions\kfkcangbigakljkjeglcofaomihpejif
Key Deleted : HKCU\Software\Softonic
Key Deleted : HKLM\SOFTWARE\Classes\IMsiDe1egate.Application.1
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Google\Chrome\Extensions\kfkcangbigakljkjeglcofaomihpejif
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{BCFF5F55-6F44-11D2-86F8-00104B265ED5}

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16457

[OK] Registry is clean.

-\\ Google Chrome v [Unable to get version]

File : C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 4.3.2 (12.29.2012:3)
OS: Windows 7 Home Premium x64
Ran by [removed] on 31/12/2012 at 8:25:45.18
Blog: http://thisisudax.blogspot.com
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services



~~~ Registry Values

Successfully deleted: [Registry Value] hkey_current_user\software\microsoft\internet explorer\urlsearchhooks\\{ef99bd32-c1fb-11d2-892f-0090271d4f88}



~~~ Registry Keys

Successfully deleted: [Registry Key] hkey_classes_root\clsid\{02478d38-c3f9-4efb-9b51-7695eca05670}
Successfully deleted: [Registry Key] hkey_classes_root\clsid\{ef99bd32-c1fb-11d2-892f-0090271d4f88}
Successfully deleted: [Registry Key] hkey_current_user\software\microsoft\internet explorer\searchscopes\{ab79d3b4-aedb-428a-b504-bac00521a1c7}



~~~ Files

Successfully deleted: [File] C:\eula.1028.txt
Successfully deleted: [File] C:\eula.1031.txt
Successfully deleted: [File] C:\eula.1033.txt
Successfully deleted: [File] C:\eula.1036.txt
Successfully deleted: [File] C:\eula.1040.txt
Successfully deleted: [File] C:\eula.1041.txt
Successfully deleted: [File] C:\eula.1042.txt
Successfully deleted: [File] C:\eula.2052.txt
Successfully deleted: [File] C:\install.res.1028.dll
Successfully deleted: [File] C:\install.res.1031.dll
Successfully deleted: [File] C:\install.res.1033.dll
Successfully deleted: [File] C:\install.res.1036.dll
Successfully deleted: [File] C:\install.res.1040.dll
Successfully deleted: [File] C:\install.res.1041.dll
Successfully deleted: [File] C:\install.res.1042.dll
Successfully deleted: [File] C:\install.res.2052.dll
Successfully deleted: [File] C:\install.res.3082.dll



~~~ Folders



~~~ Event Viewer Logs were cleared

ComboFix 12-12-31.01 - Wayne 31/12/2012 9:03.1.8 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.2.1033.18.9207.7407 [GMT -8:00]
Running from: c:\users\[removed]\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {ADA629C7-7F48-5689-624A-3B76997E0892}
FW: McAfee Firewall *Disabled* {959DA8E2-3527-57D1-4915-924367AD4FE9}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {16C7C823-5972-5907-58FA-0004E2F9422F}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
C:\install.exe
c:\program files (x86)\WeatherBlink
c:\program files (x86)\WeatherBlink\bar\1.bin\CHROME.MANIFEST
c:\program files (x86)\WeatherBlink\bar\1.bin\chrome\gcffxtbr.jar
c:\program files (x86)\WeatherBlink\bar\1.bin\gcbar.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcbarsvc.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\gcdatact.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcdyn.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcfeedmg.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gchighin.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\gchtml.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gchtmlmu.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gchttpct.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcidle.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcimpipe.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\gcmedint.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\gcmlbtn.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcmsg.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcPlugin.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcradio.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcregfft.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcregiet.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcscript.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcskin.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcskplay.exe
c:\program files (x86)\WeatherBlink\bar\1.bin\gctpinst.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\gcuabtn.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\INSTALL.RDF
c:\program files (x86)\WeatherBlink\bar\1.bin\LOGO.BMP
c:\program files (x86)\WeatherBlink\bar\1.bin\NPgcStub.dll
c:\program files (x86)\WeatherBlink\bar\1.bin\T8RES.DLL
c:\program files (x86)\WeatherBlink\bar\IE9Mesg\COMMON.T8S
c:\program files (x86)\WeatherBlink\bar\Message\COMMON.T8S
c:\program files (x86)\WeatherBlink\bar\Settings\s_pid.dat
c:\program files (x86)\WeatherBlinkEI
c:\users\Wayne\GoToAssistDownloadHelper.exe
c:\users\Wayne\WINDOWS
.
.
((((((((((((((((((((((((( Files Created from 2012-11-28 to 2012-12-31 )))))))))))))))))))))))))))))))
.
.
2012-12-31 17:10 . 2012-12-31 17:10 ——– d—–w- c:\users\Default\AppData\Local\temp
2012-12-31 16:25 . 2012-12-31 16:25 ——– d—–w- c:\windows\ERUNT
2012-12-31 16:25 . 2012-12-31 16:25 ——– d—–w- C:\JRT
2012-12-31 16:08 . 2012-12-31 16:08 ——– d—–w- C:\components
2012-12-27 23:24 . 2012-08-23 02:59 66360 —-a-w- c:\windows\system32\drivers\kbfilter.sys
2012-12-27 23:24 . 2012-08-23 02:59 66360 —-a-w- C:\kbfilter.sys
2012-12-27 23:24 . 2012-08-23 02:59 98 —-a-w- C:\install.bat
2012-12-27 23:24 . 2012-08-23 02:59 81 —-a-w- C:\uninstall.bat
2012-12-27 23:08 . 2012-12-27 23:24 ——– d—–w- c:\programdata\Trend Micro
2012-12-27 23:06 . 2012-12-27 23:06 388096 —-a-r- c:\users\Wayne\AppData\Roaming\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2012-12-27 23:06 . 2012-12-27 23:06 ——– d—–w- c:\program files (x86)\Trend Micro
2012-12-27 23:05 . 2012-12-27 23:05 ——– d—–w- c:\users\Wayne\AppData\Roaming\Trend Micro
2012-12-27 23:05 . 2012-12-27 23:05 ——– d—–w- c:\users\Wayne\AppData\Local\CRE
2012-12-27 21:47 . 2012-12-27 23:28 ——– d—–w- c:\program files (x86)\MusicFrost
2012-12-21 02:55 . 2012-12-21 02:55 ——– d—–w- c:\program files (x86)\Garmin GPS Plugin
2012-12-21 00:11 . 2012-08-24 16:53 96768 —-a-w- c:\windows\SysWow64\sspicli.dll
2012-12-21 00:11 . 2012-05-04 11:00 366592 —-a-w- c:\windows\system32\qdvd.dll
2012-12-21 00:11 . 2012-05-04 09:59 514560 —-a-w- c:\windows\SysWow64\qdvd.dll
2012-12-18 12:34 . 2012-12-18 12:34 ——– d—–w- c:\users\Wayne\AppData\Local\Garmin
2012-12-18 12:34 . 2012-12-18 12:34 ——– d—–w- c:\programdata\Garmin
2012-12-18 12:34 . 2012-12-18 12:34 ——– d—–w- c:\users\Wayne\AppData\Local\GARMIN_Corp
2012-12-17 20:24 . 2012-12-18 14:15 ——– d—–w- C:\Garmin
2012-12-16 16:19 . 2012-12-16 16:19 ——– d—–w- c:\program files\DIFX
2012-12-13 16:11 . 2012-12-21 02:55 ——– d—–w- c:\program files\Garmin GPS Plugin
2012-12-13 16:11 . 2012-12-18 12:34 ——– d—–w- c:\program files (x86)\Garmin
2012-12-12 10:29 . 2012-11-09 05:45 2048 —-a-w- c:\windows\system32\tzres.dll
2012-12-12 10:28 . 2012-10-04 16:40 4096 —ha-w- c:\windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-12-12 11:02 . 2010-06-11 06:18 67413224 —-a-w- c:\windows\system32\MRT.exe
2012-11-09 14:40 . 2010-08-29 18:52 69672 —-a-w- c:\windows\system32\drivers\cfwids.sys
2012-11-09 14:37 . 2010-08-29 18:52 339776 —-a-w- c:\windows\system32\drivers\mfewfpk.sys
2012-11-09 14:36 . 2010-08-29 18:52 10288 —-a-w- c:\windows\system32\drivers\mfeclnk.sys
2012-11-09 14:36 . 2010-08-29 18:52 106112 —-a-w- c:\windows\system32\drivers\mferkdet.sys
2012-11-09 14:35 . 2010-08-29 18:52 771096 —-a-w- c:\windows\system32\drivers\mfehidk.sys
2012-11-09 14:34 . 2010-08-29 18:52 515528 —-a-w- c:\windows\system32\drivers\mfefirek.sys
2012-11-09 14:34 . 2010-08-29 18:52 309400 —-a-w- c:\windows\system32\drivers\mfeavfk.sys
2012-11-09 14:33 . 2010-08-29 18:52 178840 —-a-w- c:\windows\system32\drivers\mfeapfk.sys
2012-10-23 14:46 . 2012-10-23 14:46 696760 —-a-w- c:\windows\SysWow64\FlashPlayerApp.exe
2012-10-23 14:46 . 2011-09-26 12:32 73656 —-a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2012-10-16 08:38 . 2012-11-28 03:41 135168 —-a-w- c:\windows\apppatch\AppPatch64\AcXtrnal.dll
2012-10-16 08:38 . 2012-11-28 03:41 350208 —-a-w- c:\windows\apppatch\AppPatch64\AcLayers.dll
2012-10-16 07:39 . 2012-11-28 03:41 561664 —-a-w- c:\windows\apppatch\AcLayers.dll
2012-10-09 18:17 . 2012-11-16 07:23 55296 —-a-w- c:\windows\system32\dhcpcsvc6.dll
2012-10-09 18:17 . 2012-11-16 07:23 226816 —-a-w- c:\windows\system32\dhcpcore6.dll
2012-10-09 17:40 . 2012-11-16 07:23 44032 —-a-w- c:\windows\SysWow64\dhcpcsvc6.dll
2012-10-09 17:40 . 2012-11-16 07:23 193536 —-a-w- c:\windows\SysWow64\dhcpcore6.dll
2012-10-04 16:40 . 2012-12-12 10:29 44032 —-a-w- c:\windows\apppatch\acwow64.dll
2012-10-03 17:56 . 2012-11-16 07:22 1914248 —-a-w- c:\windows\system32\drivers\tcpip.sys
2012-10-03 17:44 . 2012-11-16 07:22 303104 —-a-w- c:\windows\system32\nlasvc.dll
2012-10-03 17:44 . 2012-11-16 07:22 70656 —-a-w- c:\windows\system32\nlaapi.dll
2012-10-03 17:44 . 2012-11-16 07:22 246272 —-a-w- c:\windows\system32\netcorehc.dll
2012-10-03 17:44 . 2012-11-16 07:22 18944 —-a-w- c:\windows\system32\netevent.dll
2012-10-03 17:44 . 2012-11-16 07:22 216576 —-a-w- c:\windows\system32\ncsi.dll
2012-10-03 17:42 . 2012-11-16 07:22 569344 —-a-w- c:\windows\system32\iphlpsvc.dll
2012-10-03 16:42 . 2012-11-16 07:22 175104 —-a-w- c:\windows\SysWow64\netcorehc.dll
2012-10-03 16:42 . 2012-11-16 07:22 18944 —-a-w- c:\windows\SysWow64\netevent.dll
2012-10-03 16:42 . 2012-11-16 07:22 156672 —-a-w- c:\windows\SysWow64\ncsi.dll
2012-10-03 16:07 . 2012-11-16 07:22 45568 —-a-w- c:\windows\system32\drivers\tcpipreg.sys
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"HP Officejet 6600 (NET)"="c:\program files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe" [2011-09-09 2676584]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-09-12 1535112]
"CTxfiHlp"="CTXFIHLP.EXE" [2010-07-07 24576]
"APSDaemon"="c:\program files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe" [2012-08-28 59280]
"RIMBBLaunchAgent.exe"="c:\program files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe" [2011-11-02 90448]
"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2012-04-19 421888]
"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2010-06-10 49208]
"iTunesHelper"="c:\program files (x86)\iTunes\iTunesHelper.exe" [2012-09-10 421776]
"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-09-17 254896]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-09-24 926896]
"Garmin Lifetime Updater"="c:\program files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe" [2012-06-04 1466760]
.
c:\users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-9-21 1316192]
Monitor Ink Alerts - HP Officejet 6600 (Network).lnk - c:\windows\system32\RunDll32.exe [2009-7-13 45568]
.
c:\users\Default User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\
Dell Dock First Run.lnk - c:\program files\Dell\DellDock\DellDock.exe [2009-9-21 1316192]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"EnableLUA"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MSIServer]
@="Service"
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\run-]
""=
"TrojanScanner"=c:\program files (x86)\Trojan Remover\Trjscan.exe /boot
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 SessionLauncher;SessionLauncher;c:\users\ADMINI~1\AppData\Local\Temp\DX9\SessionLauncher.exe [x]
R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2010-04-02 79360]
R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2010-04-02 79360]
R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-07 230488]
R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-07 95320]
R3 HipShieldK;McAfee Inc. HipShieldK;c:\windows\system32\drivers\HipShieldK.sys [2012-04-20 196440]
R3 kbfilter;kbfilter;c:\windows\system32\DRIVERS\kbfilter.sys [2012-08-23 66360]
R3 McComponentHostService;McAfee Security Scan Component Host Service;c:\program files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe [2010-01-15 227232]
R3 mferkdet;McAfee Inc. mferkdet;c:\windows\system32\drivers\mferkdet.sys [2012-11-09 106112]
R3 PCDSRVC{1E208CE0-FB7451FF-06020101}_0;PCDSRVC{1E208CE0-FB7451FF-06020101}_0 - PCDR Kernel Mode Service Helper Driver;c:\program files\dell support center\pcdsrvc_x64.pkms [x]
R3 RdpVideoMiniport;Remote Desktop Video Miniport Driver;c:\windows\system32\drivers\rdpvideominiport.sys [2012-08-23 19456]
R3 RoxMediaDB10;RoxMediaDB10;c:\program files (x86)\Common Files\Roxio Shared\10.0\SharedCOM\RoxMediaDB10.exe [2009-06-26 1124848]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2012-08-23 57856]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2012-02-15 52736]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-06-14 1255736]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-11-09 339776]
S0 PxHlpa64;PxHlpa64;c:\windows\System32\Drivers\PxHlpa64.sys [2009-07-09 55280]
S0 RapportKE64;RapportKE64;c:\windows\System32\Drivers\RapportKE64.sys [2012-07-30 101688]
S1 RapportCerberus_43926;RapportCerberus_43926;c:\programdata\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys [2012-10-30 505720]
S1 RapportEI64;RapportEI64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys [2012-07-30 55096]
S1 RapportPG64;RapportPG64;c:\program files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys [2012-07-30 297240]
S2 AdobeActiveFileMonitor8.0;Adobe Active File Monitor V8;c:\program files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe [2009-09-18 169312]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2009-12-10 202752]
S2 DockLoginService;Dock Login Service;c:\program files\Dell\DellDock\DockLogin.exe [2009-06-09 155648]
S2 HFN Client;HFN Client;c:\program files (x86)\HFN\Client\srvc.exe [2012-09-21 69456]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2012-08-31 201304]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-11-09 218320]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\program files\Common Files\McAfee\SystemCore\mfevtps.exe [2012-11-09 177680]
S2 RapportMgmtService;Rapport Management Service;c:\program files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe [2012-07-30 976728]
S2 SftService;SoftThinks Agent Service;c:\program files (x86)\Dell DataSafe Local Backup\sftservice.EXE [2010-08-20 689472]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-11-09 69672]
S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-07 230488]
S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-07 1445976]
S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-07 95320]
S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-07 1612888]
S3 HCW85BDA;Hauppauge WinTV 885 Video Capture;c:\windows\system32\drivers\HCW85BDA.sys [2009-07-15 1708800]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-11-09 515528]
S3 OA002Afx;Provides a software interface to control audio effects of OA002 camera.;c:\windows\system32\Drivers\OA002Afx.sys [2007-06-08 219544]
S3 OA002Ufd;Creative Camera OA002 Upper Filter Driver;c:\windows\system32\DRIVERS\OA002Ufd.sys [2008-06-03 168864]
S3 OA002Vid;Creative Camera OA002 Function Driver;c:\windows\system32\DRIVERS\OA002Vid.sys [2008-08-01 306560]
S3 RSUSBSTOR;RtsUStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUStor.sys [2009-06-05 216064]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2009-05-23 215040]
.
.
— Other Services/Drivers In Memory —
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-24 22:37]
.
2012-12-31 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2010-11-24 22:37]
.
.
——— X64 Entries ———–
.
.
——- Supplementary Scan ——-
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page = https://www.google.ca/
mLocal Page = c:\windows\SysWOW64\blank.htm
uInternet Settings,ProxyOverride = *.local
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Google Sidewiki… - c:\program files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html
TCP: DhcpNameServer = 8.8.8.8 8.8.4.4
DPF: Garmin Communicator Plug-In - hxxps://static.garmincdn.com/gcp/ie/4.0.4.0/GarminAxControl_32.CAB
DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} - hxxp://ccfiles.creative.com/Web/softwareupdate/su2/ocx/20015/CTSUEng.cab
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
.
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\PCDSRVC{1E208CE0-FB7451FF-06020101}_0]
"ImagePath"="\??\c:\program files\dell support center\pcdsrvc_x64.pkms"
.
——————— LOCKED REGISTRY KEYS ———————
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\system32\\Macromed\\Flash\\FlashUtil64_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil32_11_4_402_287_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{73C9DFA0-750D-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.11"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash32_11_4_402_287.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}]
@Denied: (A 2) (Everyone)
@="IFlashBroker5"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{6AE38AE0-750C-11E1-B0C4-0800200C9A66}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-12-31 09:12:15
ComboFix-quarantined-files.txt 2012-12-31 17:12
.
Pre-Run: 857,096,069,120 bytes free
Post-Run: 856,866,500,608 bytes free
.
- - End Of File - - EADAC3D739CA2497B384C7D7B9537C12




~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on 31/12/2012 at 8:32:32.57
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

*************************

AdwCleaner[R1].txt - [1658 octets] - [31/12/2012 08:12:09]
AdwCleaner[S1].txt - [1617 octets] - [31/12/2012 08:13:25]

########## EOF - C:\AdwCleaner[S1].txt - [1677 octets] ##########
r the help

The Computer seems to be working OK. I havent used it much lately as I am helping one of my kids move
Hi ENYAW22,

Please download Malwarebytes' Anti-Malware to your desktop.

  • Right click and select "Run as Administrator" mbam-setup.exe and follow the prompts to install the program.
  • At the end, be sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select Perform quick scan, then click Scan as shown below.

    [external image: Posted Image]

  • When the scan is complete, click OK, then Show Results to view the results.
  • Be sure that everything is checked, and click Remove Selected.
  • When completed, a log will open in Notepad. Please save it to a convenient location and post the results.
Next

Please run Eset Online Scanner

Administrator rights are required to run ESET Online Scanner
  • Place a check mark in the box YES, I accept the Terms Of Use
  • Click the Start button.
  • Now click the Install button.
  • Click Start. The scanner engine will initialize and update.
  • Do Not place a check mark in the box beside Remove found threats.
  • Click the Scan button. The scan will now run, please be patient.
  • When the scan finishes click the Details tab.
  • Copy and paste the contents of the C:\Program Files\ESET\log.txt into your next reply.
In your next post please provide the following:
  • MBAM log
  • ESET log.txt
  • How's the computer running?
I did as instructed with Malwarebytes and have a file. I couldnot find a way to run Eset as admin, but ran it all the way through. No files came up but it came back with a sign " no threats found" I hope this means I am fine——Wayne Malwarebytes Anti-Malware 1.70.0.1100 www.malwarebytes.org Database version: v2013.01.01.03 Windows 7 Service Pack 1 x64 NTFS Internet Explorer 9.0.8112.16421 Wayne :: WAYNE-PC [administrator] 01/01/2013 10:58:39 AM mbam-log-2013-01-01 (10-58-39).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 223888 Time elapsed: 4 minute(s), 36 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 0 (No malicious items detected) Files Detected: 0 (No malicious items detected) (end)
Hi ENYAW22,

One more scan to be sure we got everything.

Re-run OTL (it should be located on your desktop).

Windows Vista and Windows 7 users Right Click and select "Run as Administrator" on the icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. (No Extras.txt will be produced)
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
In your next post please provide the following:
  • OTL.txt
  • Any remaining issues?
Good morning OCD This is the file hope all is well——–Wayne

OTL logfile created on: 1/2/2013 10:48:47 AM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Wayne\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

8.99 Gb Total Physical Memory | 7.24 Gb Available Physical Memory | 80.58% Memory free
17.98 Gb Paging File | 15.66 Gb Available in Paging File | 87.08% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 916.35 Gb Total Space | 796.42 Gb Free Space | 86.91% Space Free | Partition Type: NTFS

Computer Name: WAYNE-PC | User Name: Wayne | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Wayne\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\HFN\Client\srvc.exe (HFN, Inc.)
PRC - C:\Program Files (x86)\HFN\Client\cutil.exe (HFN, Inc.)
PRC - C:\Program Files (x86)\HFN\Client\cust.exe (HFN, Inc.)
PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
PRC - C:\Program Files (x86)\Trusteer\Rapport\bin\RapportService.exe (Trusteer Ltd.)
PRC - C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe (Garmin)
PRC - C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
PRC - C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
PRC - C:\WINDOWS\SysWOW64\Ctxfihlp.exe (Creative Technology Ltd)
PRC - C:\WINDOWS\SysWOW64\CTxfispi.exe (Creative Technology Ltd)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
PRC - c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
PRC - c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
PRC - C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)


========== Modules (No Company Name) ==========

MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xaml\23de8d00755205c37aa6795b0ce8a42d\System.Xaml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml.Linq\2ac9ed65e7a7ccfcc1d4f4967540d993\System.Xml.Linq.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\c22857dbcce7e0320350436e80ec8ab1\PresentationFramework.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationCore\78a485faba9584cfb1a5052a4cbe71e8\PresentationCore.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\WindowsBase\df5142941549ff71737438c85e565ab3\WindowsBase.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\PresentationFramewo#\53121a27f94f7335e585384377fc538a\PresentationFramework.Aero.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\ccf3f783590b1747a3593b889bede2fb\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\a7cdf1caedee630b8440fb8e8657aca1\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\06db722a2ddebd960d907c2de6f1cfa7\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Security\471e9622a174c71be1b987575a92a1f6\System.Security.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\ed7768172bbf30462bc554dee3911540\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\0bc033fa805a31e31dc462cfae365478\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\685f73e04393b5342bd1cebe701496ad\mscorlib.ni.dll ()
MOD - C:\Program Files (x86)\HFN\Client\trig000.dll ()
MOD - C:\ProgramData\Trusteer\Rapport\store\exts\RapportMS\39624\RapportMS.dll ()
MOD - C:\Program Files (x86)\Trusteer\Rapport\bin\js32.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\WINDOWS\SysWOW64\CtxfiRes.dll ()
MOD - C:\WINDOWS\SysWOW64\APOMngr.DLL ()


========== Services (SafeList) ==========

SRV:64bit: - (McODS) – C:\Program Files\McAfee\VirusScan\mcods.exe (McAfee, Inc.)
SRV:64bit: - (mfevtp) – C:\Program Files\Common Files\McAfee\SystemCore\mfevtps.exe (McAfee, Inc.)
SRV:64bit: - (mfefire) – C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe ()
SRV:64bit: - (McShield) – C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe ()
SRV:64bit: - (MSK80Service) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McProxy) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNASvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McNaiAnn) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (mcmscsvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (McMPFSvc) – C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe (McAfee, Inc.)
SRV:64bit: - (wlcrasvc) – C:\Program Files\Windows Live\Mesh\wlcrasvc.exe (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) – C:\WINDOWS\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (DockLoginService) – C:\Program Files\Dell\DellDock\DockLogin.exe (Stardock Corporation)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (HFN Client) – C:\Program Files (x86)\HFN\Client\srvc.exe (HFN, Inc.)
SRV - (RapportMgmtService) – C:\Program Files (x86)\Trusteer\Rapport\bin\RapportMgmtService.exe (Trusteer Ltd.)
SRV - (SftService) – C:\Program Files (x86)\Dell DataSafe Local Backup\SftService.exe (SoftThinks SAS)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (Creative ALchemy AL6 Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe (Creative Labs)
SRV - (Creative Audio Engine Licensing Service) – C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe (Creative Labs)
SRV - (clr_optimization_v4.0.30319_32) – C:\WINDOWS\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (ACDaemon) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (CTAudSvcService) – C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe (Creative Technology Ltd)
SRV - (McComponentHostService) – C:\Program Files (x86)\McAfee Security Scan\2.0.181\McCHSvc.exe (McAfee, Inc.)
SRV - (AdobeActiveFileMonitor8.0) – c:\Program Files (x86)\Adobe\Elements Organizer 8.0\PhotoshopElementsFileAgent.exe (Adobe Systems Incorporated)
SRV - (hnmsvc) – c:\Program Files (x86)\Common Files\Dell\Advanced Networking Service\hnm_svc.exe (Dell Inc.)
SRV - (RoxMediaDB10) – c:\Program Files (x86)\Common Files\Roxio Shared\10.0\SharedCom\RoxMediaDB10.exe (Sonic Solutions)
SRV - (clr_optimization_v2.0.50727_32) – C:\WINDOWS\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (IAANTMON) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)


========== Driver Services (SafeList) ==========

DRV:64bit: - (PCDSRVC{1E208CE0-FB7451FF-06020101}_0) – c:\program files\dell support center\pcdsrvc_x64.pkms File not found
DRV:64bit: - (cfwids) – C:\WINDOWS\SysNative\drivers\cfwids.sys (McAfee, Inc.)
DRV:64bit: - (mfewfpk) – C:\WINDOWS\SysNative\drivers\mfewfpk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdet) – C:\WINDOWS\SysNative\drivers\mferkdet.sys (McAfee, Inc.)
DRV:64bit: - (mfehidk) – C:\WINDOWS\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (mfefirek) – C:\WINDOWS\SysNative\drivers\mfefirek.sys (McAfee, Inc.)
DRV:64bit: - (mfeavfk) – C:\WINDOWS\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfeapfk) – C:\WINDOWS\SysNative\drivers\mfeapfk.sys (McAfee, Inc.)
DRV:64bit: - (RdpVideoMiniport) – C:\WINDOWS\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\WINDOWS\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (kbfilter) – C:\WINDOWS\SysNative\drivers\kbfilter.sys (Trend Micro Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\WINDOWS\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (RapportKE64) – C:\WINDOWS\SysNative\drivers\RapportKE64.sys (Trusteer Ltd.)
DRV:64bit: - (HipShieldK) – C:\WINDOWS\SysNative\drivers\HipShieldK.sys (McAfee, Inc.)
DRV:64bit: - (grmnusb) – C:\WINDOWS\SysNative\drivers\grmnusb.sys (GARMIN Corp.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\WINDOWS\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (RimUsb) – C:\WINDOWS\SysNative\drivers\RimUsb_AMD64.sys (Research In Motion Limited)
DRV:64bit: - (RimVSerPort) – C:\WINDOWS\SysNative\drivers\RimSerial_AMD64.sys (Research in Motion Ltd)
DRV:64bit: - (amdsata) – C:\WINDOWS\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\WINDOWS\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\WINDOWS\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (fssfltr) – C:\WINDOWS\SysNative\drivers\fssfltr.sys (Microsoft Corporation)
DRV:64bit: - (ha20x22k) – C:\WINDOWS\SysNative\drivers\ha20x22k.sys (Creative Technology Ltd)
DRV:64bit: - (ha20x2k) – C:\WINDOWS\SysNative\drivers\ha20x2k.sys (Creative Technology Ltd)
DRV:64bit: - (emupia) – C:\WINDOWS\SysNative\drivers\emupia2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctsfm2k) – C:\WINDOWS\SysNative\drivers\ctsfm2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctprxy2k) – C:\WINDOWS\SysNative\drivers\ctprxy2k.sys (Creative Technology Ltd)
DRV:64bit: - (ossrv) – C:\WINDOWS\SysNative\drivers\ctoss2k.sys (Creative Technology Ltd.)
DRV:64bit: - (ctaud2k) – C:\WINDOWS\SysNative\drivers\ctaud2k.sys (Creative Technology Ltd)
DRV:64bit: - (ctac32k) – C:\WINDOWS\SysNative\drivers\ctac32k.sys (Creative Technology Ltd)
DRV:64bit: - (CTEXFIFX.SYS) – C:\WINDOWS\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:64bit: - (CTEXFIFX) – C:\WINDOWS\SysNative\drivers\CTEXFIFX.sys (Creative Technology Ltd.)
DRV:64bit: - (CTHWIUT.SYS) – C:\WINDOWS\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CTHWIUT) – C:\WINDOWS\SysNative\drivers\CTHWIUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CT20XUT.SYS) – C:\WINDOWS\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:64bit: - (CT20XUT) – C:\WINDOWS\SysNative\drivers\CT20XUT.sys (Creative Technology Ltd.)
DRV:64bit: - (atikmdag) – C:\WINDOWS\SysNative\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV:64bit: - (FTDIBUS) – C:\WINDOWS\SysNative\drivers\ftdibus.sys (FTDI Ltd.)
DRV:64bit: - (FTSER2K) – C:\WINDOWS\SysNative\drivers\ftser2k.sys (FTDI Ltd.)
DRV:64bit: - (AtiHdmiService) – C:\WINDOWS\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (JRAID) – C:\WINDOWS\SysNative\drivers\jraid.sys (JMicron Technology Corp.)
DRV:64bit: - (HCW85BDA) – C:\WINDOWS\SysNative\drivers\HCW85BDA.sys (Hauppauge Computer Works)
DRV:64bit: - (amdsbs) – C:\WINDOWS\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\WINDOWS\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\WINDOWS\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\WINDOWS\SysNative\drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\WINDOWS\SysNative\drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (ROOTMODEM) – C:\WINDOWS\SysNative\drivers\rootmdm.sys (Microsoft Corporation)
DRV:64bit: - (PxHlpa64) – C:\WINDOWS\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (Packet) – C:\WINDOWS\SysNative\drivers\packet.sys (SingleClick Systems)
DRV:64bit: - (ebdrv) – C:\WINDOWS\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\WINDOWS\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\WINDOWS\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\WINDOWS\SysNative\drivers\HCW85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (iaStor) – C:\WINDOWS\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RSUSBSTOR) – C:\WINDOWS\SysNative\drivers\RtsUStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (RTL8167) – C:\WINDOWS\SysNative\drivers\Rt64win7.sys (Realtek )
DRV:64bit: - (OA002Vid) – C:\WINDOWS\SysNative\drivers\OA002Vid.sys (Creative Technology Ltd.)
DRV:64bit: - (OA002Ufd) – C:\WINDOWS\SysNative\drivers\OA002Ufd.sys (Creative Technology Ltd.)
DRV:64bit: - (OA002Afx) – C:\WINDOWS\SysNative\drivers\OA002Afx.sys (Creative Technology Ltd.)
DRV:64bit: - (WimFltr) – C:\WINDOWS\SysNative\drivers\WimFltr.sys (Microsoft Corporation)
DRV - (RapportCerberus_43926) – C:\ProgramData\Trusteer\Rapport\store\exts\RapportCerberus\43926\RapportCerberus64_43926.sys ()
DRV - (RapportEI64) – C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportEI64.sys (Trusteer Ltd.)
DRV - (RapportPG64) – C:\Program Files (x86)\Trusteer\Rapport\bin\x64\RapportPG64.sys (Trusteer Ltd.)
DRV - (WIMMount) – C:\WINDOWS\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (RxFilter) – C:\WINDOWS\SysWOW64\drivers\RxFilter.sys (Sonic Solutions)
DRV - (Packet) – C:\WINDOWS\SysWOW64\drivers\packet.sys (SingleClick Systems)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…mp;sourceid=ie7
IE:64bit: - HKLM\..\SearchScopes\{ED2F724C-8FEE-4F8A-87E6-10678B5D6E07}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = https://www.google.ca/
IE - HKCU\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={searchTerm…;rlz=1I7ADFA_en
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director\np32dsw_1168638.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_37: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL ()
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rim.com/npappworld: C:\Program Files (x86)\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll ()
FF - HKLM\Software\MozillaPlugins\@RIM.com/WebSLLauncher,version=1.0: C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\[removed]/YahooActiveXPluginBridge;version=1.0.0.1: C:\Program Files (x86)\Yahoo!\Common\npyaxmpb.dll (Yahoo! Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Wayne\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files (x86)\WeatherBlink\bar\1.bin
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/12/11 21:14:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\McAfee\MSK [2012/12/09 15:16:43 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - homepage: http://www.google.com
CHR - default_search_provider: MF Custom Search (Enabled)
CHR - default_search_provider: search_url = http://search.musicfrost.com/results.php?q={searchTerms}
CHR - default_search_provider: suggest_url =
CHR - homepage: http://www.google.com
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Conduit Chrome Plugin (Enabled) = C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif\10.13.20.29_0\plugins/ConduitChromeApiPlugin.dll
CHR - plugin: Conduit Radio Plugin (Enabled) = C:\Users\Wayne\AppData\Local\Google\Chrome\User Data\Default\Extensions\kfkcangbigakljkjeglcofaomihpejif\10.13.20.29_0\plugins/np-cwmp.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: RIM Handheld Application Loader (Enabled) = C:\Program Files (x86)\Common Files\Research In Motion\BBWebSLLauncher\NPWebSLLauncher.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 6 U37 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: BlackBerry AppWorld (Enabled) = C:\Program Files (x86)\Research In Motion Limited\BlackBerry App World Browser Plugin\npappworld.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Yahoo! activeX Plug-in Bridge (Enabled) = C:\Program Files (x86)\Yahoo!\Common\npyaxmpb.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Unity Player (Enabled) = C:\Users\Wayne\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Java Deployment Toolkit 6.0.370.6 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: McAfee SecurityCenter (Enabled) = c:\PROGRA~2\mcafee\msc\NPMCSN~1.DLL
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll

O1 HOSTS File: ([2012/12/31 09:10:27 | 000,000,027 | —- | M]) - C:\WINDOWS\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (no name) - {27B4851A-3207-45A2-B947-BE8AFE6163AB} - No CLSID value found.
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\McAfee\SystemCore\ScriptSn.20120622003851.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd)
O4 - HKLM..\Run: [Garmin Lifetime Updater] C:\Program Files (x86)\Garmin\Lifetime Updater\GarminLifetime.exe (Garmin)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [RIMBBLaunchAgent.exe] C:\Program Files (x86)\Common Files\Research In Motion\USB Drivers\RIMBBLaunchAgent.exe (Research In Motion Limited)
O4 - HKCU..\Run: [HP Officejet 6600 (NET)] C:\Program Files\HP\HP Officejet 6600\Bin\ScanToPCActivationApp.exe (Hewlett-Packard Co.)
O4 - HKLM..\RunOnce: [Malwarebytes Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - Startup: C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dell Dock.lnk = File not found
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O8 - Extra context menu item: Google Sidewiki… - res://C:\Program Files (x86)\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_7461B1589E8B4FB7.dll/cmsidewiki.html File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Reg Error: Key error.)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files%20(x86)/Mah%20Jong%20Medley/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} C:\Program Files (x86)\Yahoo!\Common\yinsthelper.dll (YInstStarter Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {C1F8FC10-E5DB-4112-9DBF-6C3FF728D4E3} http://support.dell.com/systemprofiler/DellSystemLite.CAB (DellSystemLite.Scanner)
O16 - DPF: {CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_37)
O16 - DPF: {D4B68B83-8710-488B-A692-D74B50BA558E} http://ccfiles.creative.com/Web/softwareup…13/CTPIDPDE.cab (Creative Software AutoUpdate Support Package 2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {E705A591-DA3C-4228-B0D5-A356DBA42FBF} http://ccfiles.creative.com/Web/softwareup…015/CTSUEng.cab (Creative Software AutoUpdate 2)
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareup…15118/CTPID.cab (Creative Software AutoUpdate Support Package)
O16 - DPF: Garmin Communicator Plug-In https://static.garmincdn.com/gcp/ie/4.0.4.0…xControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 8.8.8.8 8.8.4.4
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E1BCCB63-E486-4006-AD24-F329D7216AE6}: DhcpNameServer = 8.8.8.8 8.8.4.4
O18:64bit: - Protocol\Handler\gopher - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\McAfee\MSC\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\MSC\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\WINDOWS\SysWOW64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/01/01 20:02:14 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2013/01/01 11:09:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2013/01/01 10:55:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/01/01 10:55:49 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/01/01 10:55:49 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/01/01 10:49:00 | 010,156,344 | —- | C] (Malwarebytes Corporation ) – C:\Users\Wayne\Desktop\mbam-setup-1.70.0.1100.exe
[2012/12/31 09:18:27 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2012/12/31 09:12:16 | 000,000,000 | —D | C] – C:\Windows\temp
[2012/12/31 09:02:08 | 000,518,144 | —- | C] (SteelWerX) – C:\Windows\SWREG.exe
[2012/12/31 09:02:08 | 000,406,528 | —- | C] (SteelWerX) – C:\Windows\SWSC.exe
[2012/12/31 09:02:08 | 000,060,416 | —- | C] (NirSoft) – C:\Windows\NIRCMD.exe
[2012/12/31 09:01:58 | 000,000,000 | —D | C] – C:\Qoobox
[2012/12/31 09:01:49 | 000,000,000 | —D | C] – C:\Windows\erdnt
[2012/12/31 08:57:47 | 005,016,388 | R— | C] (Swearware) – C:\Users\Wayne\Desktop\ComboFix.exe
[2012/12/31 08:25:43 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2012/12/31 08:25:37 | 000,000,000 | —D | C] – C:\JRT
[2012/12/31 08:25:14 | 000,497,009 | —- | C] (Oleg N. Scherbakov) – C:\Users\Wayne\Desktop\JRT.exe
[2012/12/31 08:08:26 | 000,000,000 | —D | C] – C:\components
[2012/12/29 16:49:54 | 004,732,416 | —- | C] (AVAST Software) – C:\Users\Wayne\Desktop\aswMBR.exe
[2012/12/29 16:14:03 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Wayne\Desktop\OTL.exe
[2012/12/27 15:24:00 | 000,066,360 | —- | C] (Trend Micro Inc.) – C:\Windows\SysNative\drivers\kbfilter.sys
[2012/12/27 15:24:00 | 000,066,360 | —- | C] (Trend Micro Inc.) – C:\kbfilter.sys
[2012/12/27 15:08:37 | 000,000,000 | —D | C] – C:\ProgramData\Trend Micro
[2012/12/27 15:06:22 | 000,000,000 | —D | C] – C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2012/12/27 15:06:18 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2012/12/27 15:05:04 | 000,000,000 | —D | C] – C:\Users\Wayne\AppData\Roaming\Trend Micro
[2012/12/27 15:05:04 | 000,000,000 | —D | C] – C:\Users\Wayne\AppData\Local\CRE
[2012/12/27 13:47:40 | 000,000,000 | —D | C] – C:\Program Files (x86)\MusicFrost
[2012/12/20 18:55:28 | 000,000,000 | —D | C] – C:\Program Files (x86)\Garmin GPS Plugin
[2012/12/20 16:12:49 | 000,015,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RdpGroupPolicyExtension.dll
[2012/12/20 16:12:49 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2012/12/20 16:12:49 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2012/12/20 16:12:48 | 000,057,856 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2012/12/20 16:12:48 | 000,019,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
[2012/12/20 16:12:46 | 004,916,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstscax.dll
[2012/12/20 16:12:46 | 003,174,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpcorets.dll
[2012/12/20 16:12:46 | 001,123,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstsc.exe
[2012/12/20 16:12:46 | 001,048,064 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mstsc.exe
[2012/12/20 16:12:46 | 000,384,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprt.exe
[2012/12/20 16:12:46 | 000,322,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\aaclient.dll
[2012/12/20 16:12:46 | 000,269,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\aaclient.dll
[2012/12/20 16:12:46 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpudd.dll
[2012/12/20 16:12:46 | 000,228,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rdpendp_winip.dll
[2012/12/20 16:12:46 | 000,192,000 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\rdpendp_winip.dll
[2012/12/20 16:12:46 | 000,062,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TSWbPrxy.exe
[2012/12/20 16:12:46 | 000,054,272 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MsRdpWebAccess.dll
[2012/12/20 16:12:46 | 000,046,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MsRdpWebAccess.dll
[2012/12/20 16:12:46 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tsgqec.dll
[2012/12/20 16:12:46 | 000,043,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2012/12/20 16:12:46 | 000,037,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tsgqec.dll
[2012/12/20 16:12:46 | 000,018,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wksprtPS.dll
[2012/12/20 16:12:46 | 000,016,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wksprtPS.dll
[2012/12/20 16:12:45 | 005,773,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mstscax.dll
[2012/12/20 16:12:18 | 000,046,080 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2012/12/20 16:12:18 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2012/12/20 16:12:17 | 000,367,616 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2012/12/20 16:12:17 | 000,295,424 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2012/12/20 16:12:00 | 001,448,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\lsasrv.dll
[2012/12/20 16:12:00 | 000,307,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ncrypt.dll
[2012/12/20 16:11:55 | 000,514,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qdvd.dll
[2012/12/20 16:11:55 | 000,366,592 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qdvd.dll
[2012/12/18 11:32:01 | 000,000,000 | —D | C] – C:\Users\Wayne\Documents\Garmin maps
[2012/12/18 04:34:54 | 000,000,000 | —D | C] – C:\Users\Wayne\AppData\Local\Garmin
[2012/12/18 04:34:52 | 000,000,000 | —D | C] – C:\Users\Wayne\Documents\My Garmin
[2012/12/18 04:34:51 | 000,000,000 | —D | C] – C:\ProgramData\Garmin
[2012/12/18 04:34:45 | 000,000,000 | —D | C] – C:\Users\Wayne\AppData\Local\GARMIN_Corp
[2012/12/18 04:31:20 | 000,000,000 | —D | C] – C:\Users\Wayne\Documents\BaseCamp
[2012/12/17 12:24:33 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\MapSource
[2012/12/17 12:24:32 | 000,000,000 | —D | C] – C:\Garmin
[2012/12/16 08:19:11 | 000,000,000 | —D | C] – C:\Program Files\DIFX
[2012/12/13 08:11:54 | 000,000,000 | —D | C] – C:\Program Files\Garmin GPS Plugin
[2012/12/13 08:11:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Garmin
[2012/12/13 08:11:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\Garmin
[2012/12/12 03:00:55 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/12/12 03:00:54 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/12/12 03:00:54 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/12/12 03:00:54 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/12/12 03:00:54 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/12/12 03:00:54 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/12/12 03:00:54 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/12/12 03:00:54 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/12/12 03:00:53 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/12/12 03:00:53 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/12/12 03:00:53 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/12/12 03:00:53 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/12/12 03:00:52 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/12/12 03:00:52 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/12/12 03:00:52 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/12/12 02:29:05 | 001,161,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012/12/12 02:29:05 | 000,424,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\KernelBase.dll
[2012/12/12 02:29:05 | 000,338,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2012/12/12 02:29:05 | 000,215,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winsrv.dll
[2012/12/12 02:29:03 | 000,362,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64win.dll
[2012/12/12 02:29:03 | 000,243,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2012/12/12 02:29:03 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2012/12/12 02:29:02 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2012/12/12 02:29:02 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2012/12/12 02:29:02 | 000,013,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64cpu.dll
[2012/12/12 02:29:02 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2012/12/12 02:29:00 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2012/12/12 02:28:59 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/12/12 02:28:58 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-file-l1-1-0.dll
[2012/12/12 02:28:58 | 000,005,120 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-file-l1-1-0.dll
[2012/12/12 02:28:58 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processthreads-l1-1-0.dll
[2012/12/12 02:28:58 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-heap-l1-1-0.dll
[2012/12/12 02:28:57 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-security-base-l1-1-0.dll
[2012/12/12 02:28:57 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-threadpool-l1-1-0.dll
[2012/12/12 02:28:57 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-sysinfo-l1-1-0.dll
[2012/12/12 02:28:57 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-synch-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-xstate-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-util-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-string-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-string-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-rtlsupport-l1-1-0.dll
[2012/12/12 02:28:57 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-profile-l1-1-0.dll
[2012/12/12 02:28:56 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processthreads-l1-1-0.dll
[2012/12/12 02:28:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-misc-l1-1-0.dll
[2012/12/12 02:28:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localregistry-l1-1-0.dll
[2012/12/12 02:28:56 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localregistry-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-processenvironment-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-namedpipe-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-misc-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-memory-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-memory-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/12/12 02:28:56 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-profile-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-libraryloader-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-interlocked-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-io-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-io-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-interlocked-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-handle-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-handle-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-fibers-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-fibers-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-errorhandling-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-delayload-l1-1-0.dll
[2012/12/12 02:28:55 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-delayload-l1-1-0.dll
[2012/12/12 02:28:54 | 000,006,144 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-security-base-l1-1-0.dll
[2012/12/12 02:28:54 | 000,004,608 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-threadpool-l1-1-0.dll
[2012/12/12 02:28:54 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-synch-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-xstate-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-heap-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-debug-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-debug-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-datetime-l1-1-0.dll
[2012/12/12 02:28:54 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-datetime-l1-1-0.dll
[2012/12/12 02:28:53 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
[2012/12/12 02:28:53 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-localization-l1-1-0.dll
[2012/12/12 02:28:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
[2012/12/12 02:28:53 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\Windows\SysNative\api-ms-win-core-console-l1-1-0.dll
[2012/12/12 02:28:52 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2012/12/12 02:28:22 | 000,478,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnet.dll
[2012/12/12 02:28:22 | 000,376,832 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnet.dll

========== Files - Modified Within 30 Days ==========

[2013/01/02 10:38:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/01/02 03:38:00 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/01/01 10:55:54 | 000,001,115 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/01/01 10:54:30 | 010,156,344 | —- | M] (Malwarebytes Corporation ) – C:\Users\Wayne\Desktop\mbam-setup-1.70.0.1100.exe
[2012/12/31 09:24:36 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/12/31 09:24:36 | 000,014,240 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/12/31 09:18:33 | 000,001,914 | —- | M] () – C:\Users\Wayne\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Monitor Ink Alerts - HP Officejet 6600 (Network).lnk
[2012/12/31 09:16:11 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2012/12/31 09:16:01 | 2945,699,839 | -HS- | M] () – C:\hiberfil.sys
[2012/12/31 09:15:18 | 000,062,308 | —- | M] () – C:\Windows\SysNative\BMXStateBkp-{00000002-00000000-00000000-00001102-0000000B-00441102}.rfx
[2012/12/31 09:15:18 | 000,062,308 | —- | M] () – C:\Windows\SysNative\BMXState-{00000002-00000000-00000000-00001102-0000000B-00441102}.rfx
[2012/12/31 09:15:18 | 000,000,820 | —- | M] () – C:\Windows\SysNative\DVCState-{00000002-00000000-00000000-00001102-0000000B-00441102}.rfx
[2012/12/31 09:10:27 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2012/12/31 08:57:47 | 005,016,388 | R— | M] (Swearware) – C:\Users\Wayne\Desktop\ComboFix.exe
[2012/12/31 08:25:14 | 000,497,009 | —- | M] (Oleg N. Scherbakov) – C:\Users\Wayne\Desktop\JRT.exe
[2012/12/31 08:21:14 | 000,730,512 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/12/31 08:21:14 | 000,631,318 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/12/31 08:21:14 | 000,111,442 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/12/31 08:11:13 | 000,551,997 | —- | M] () – C:\Users\Wayne\Desktop\adwcleaner.exe
[2012/12/29 16:59:11 | 000,000,572 | —- | M] () – C:\Users\Wayne\Desktop\MBR.zip
[2012/12/29 16:59:11 | 000,000,572 | —- | M] () – C:\Users\Wayne\Desktop\MBR - Copy.zip
[2012/12/29 16:57:14 | 000,000,512 | —- | M] () – C:\Users\Wayne\Desktop\MBR.dat
[2012/12/29 16:50:26 | 004,732,416 | —- | M] (AVAST Software) – C:\Users\Wayne\Desktop\aswMBR.exe
[2012/12/29 16:14:05 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Wayne\Desktop\OTL.exe
[2012/12/28 14:39:43 | 001,541,120 | —- | M] () – C:\Users\Wayne\Documents\contacts.pst
[2012/12/27 18:55:52 | 000,001,262 | —- | M] () – C:\Users\Wayne\Desktop\Internet Explorer.lnk
[2012/12/27 15:06:22 | 000,002,975 | —- | M] () – C:\Users\Wayne\Desktop\HiJackThis.lnk
[2012/12/21 07:53:21 | 000,001,256 | —- | M] () – C:\Users\Wayne\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/12/20 16:14:46 | 000,345,728 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/12/18 14:14:47 | 000,078,820 | —- | M] () – C:\Users\Wayne\Documents\Untitled.gdb
[2012/12/18 11:10:52 | 000,000,020 | -H– | M] () – C:\ProgramData\PKP_DLdu.DAT
[2012/12/17 12:24:36 | 000,001,413 | —- | M] () – C:\Users\Public\Desktop\MapSource.lnk
[2012/12/16 09:11:22 | 000,046,080 | —- | M] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2012/12/16 06:45:03 | 000,367,616 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2012/12/16 06:13:28 | 000,295,424 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2012/12/16 06:13:20 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2012/12/14 16:49:28 | 000,024,176 | —- | M] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2012/12/13 08:29:53 | 002,354,511 | —- | M] () – C:\Users\Wayne\Documents\Nuvi 2595 manual.pdf
[2012/12/13 08:11:51 | 000,001,974 | —- | M] () – C:\Users\Public\Desktop\Garmin Lifetime Updater.lnk

========== Files Created - No Company Name ==========

[2013/01/01 10:55:54 | 000,001,115 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/12/31 09:02:08 | 000,256,000 | —- | C] () – C:\Windows\PEV.exe
[2012/12/31 09:02:08 | 000,208,896 | —- | C] () – C:\Windows\MBR.exe
[2012/12/31 09:02:08 | 000,098,816 | —- | C] () – C:\Windows\sed.exe
[2012/12/31 09:02:08 | 000,080,412 | —- | C] () – C:\Windows\grep.exe
[2012/12/31 09:02:08 | 000,068,096 | —- | C] () – C:\Windows\zip.exe
[2012/12/31 08:11:05 | 000,551,997 | —- | C] () – C:\Users\Wayne\Desktop\adwcleaner.exe
[2012/12/29 17:06:57 | 000,000,572 | —- | C] () – C:\Users\Wayne\Desktop\MBR - Copy.zip
[2012/12/29 16:59:11 | 000,000,572 | —- | C] () – C:\Users\Wayne\Desktop\MBR.zip
[2012/12/29 16:53:58 | 000,000,512 | —- | C] () – C:\Users\Wayne\Desktop\MBR.dat
[2012/12/27 18:55:52 | 000,001,262 | —- | C] () – C:\Users\Wayne\Desktop\Internet Explorer.lnk
[2012/12/27 15:24:00 | 000,007,693 | —- | C] () – C:\kbfilter.cat
[2012/12/27 15:24:00 | 000,002,605 | —- | C] () – C:\kbfilter.inf
[2012/12/27 15:24:00 | 000,000,098 | —- | C] () – C:\install.bat
[2012/12/27 15:24:00 | 000,000,081 | —- | C] () – C:\uninstall.bat
[2012/12/27 15:06:22 | 000,002,975 | —- | C] () – C:\Users\Wayne\Desktop\HiJackThis.lnk
[2012/12/17 12:24:36 | 000,001,413 | —- | C] () – C:\Users\Public\Desktop\MapSource.lnk
[2012/12/13 08:29:53 | 002,354,511 | —- | C] () – C:\Users\Wayne\Documents\Nuvi 2595 manual.pdf
[2012/12/13 08:11:51 | 000,001,974 | —- | C] () – C:\Users\Public\Desktop\Garmin Lifetime Updater.lnk
[2012/08/20 17:25:40 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2012/05/25 04:57:19 | 000,000,000 | —- | C] () – C:\Users\Wayne\AppData\Local\rx_image32.Cache
[2011/12/16 16:14:59 | 000,162,304 | —- | C] () – C:\Windows\SysWow64\ztvunrar36.dll
[2011/12/16 16:14:59 | 000,153,088 | —- | C] () – C:\Windows\SysWow64\unrar3.dll
[2011/12/16 16:14:59 | 000,077,312 | —- | C] () – C:\Windows\SysWow64\ztvunace26.dll
[2011/12/16 16:14:59 | 000,075,264 | —- | C] () – C:\Windows\SysWow64\unacev2.dll
[2011/01/04 16:49:45 | 000,000,000 | —- | C] () – C:\Windows\ViewNX.INI
[2011/01/04 07:54:56 | 000,148,156 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2011/01/03 12:00:08 | 000,734,810 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2010/12/30 08:05:55 | 000,000,268 | RH– | C] () – C:\Users\Wayne\AppData\Roaming\MIDI Patch Names
[2010/12/30 08:05:55 | 000,000,268 | RH– | C] () – C:\ProgramData\Master
[2010/12/30 08:05:55 | 000,000,020 | -H– | C] () – C:\ProgramData\PKP_DLdw.DAT
[2010/12/30 08:05:55 | 000,000,012 | RH– | C] () – C:\ProgramData\Organic
[2010/12/30 08:04:27 | 000,000,268 | RH– | C] () – C:\Users\Wayne\AppData\Roaming\MIDI Devices
[2010/12/30 08:04:27 | 000,000,268 | RH– | C] () – C:\ProgramData\Mail
[2010/12/30 08:04:27 | 000,000,020 | -H– | C] () – C:\ProgramData\PKP_DLdu.DAT
[2010/12/30 08:04:27 | 000,000,012 | RH– | C] () – C:\ProgramData\Nature
[2010/11/01 09:53:44 | 000,007,168 | —- | C] () – C:\Users\Wayne\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/10/12 05:50:41 | 000,000,017 | —- | C] () – C:\Users\Wayne\AppData\Local\resmon.resmoncfg

========== ZeroAccess Check ==========

[2009/07/13 20:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\shell32.dll – [2012/06/08 21:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 20:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\wbem\fastprox.dll – [2009/07/13 17:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 04:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\WINDOWS\SysNative\wbem\wbemess.dll – [2009/07/13 17:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Alternate Data Streams ==========

@Alternate Data Stream - 995 bytes -> C:\Users\Wayne\Documents\ING Direct.eml:OECustomProperty
@Alternate Data Stream - 99 bytes -> C:\ProgramData\TEMP:BE7A0841
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:F4F4A435
@Alternate Data Stream - 98 bytes -> C:\ProgramData\TEMP:71173EF9
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:569033D0
@Alternate Data Stream - 94 bytes -> C:\ProgramData\TEMP:2032CC2B
@Alternate Data Stream - 837 bytes -> C:\Users\Wayne\Documents\Marina Operators Legal Liability.eml:OECustomProperty
@Alternate Data Stream - 64 bytes -> C:\Users\Wayne\Documents\problemepsychiatriquelepitou.mpeg:TOC.WMV
@Alternate Data Stream - 168 bytes -> C:\ProgramData\TEMP:7B70C2D6
@Alternate Data Stream - 155 bytes -> C:\ProgramData\TEMP:F568DD7B
@Alternate Data Stream - 154 bytes -> C:\ProgramData\TEMP:57DC3B52
@Alternate Data Stream - 149 bytes -> C:\ProgramData\TEMP:BB8B6B1E
@Alternate Data Stream - 142 bytes -> C:\ProgramData\TEMP:C48A983C
@Alternate Data Stream - 141 bytes -> C:\ProgramData\TEMP:04FDFCF6
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:C60C6342
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:A21E43C2
@Alternate Data Stream - 140 bytes -> C:\ProgramData\TEMP:4F63029C
@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:21F1378A
@Alternate Data Stream - 137 bytes -> C:\ProgramData\TEMP:CCC4018A
@Alternate Data Stream - 136 bytes -> C:\ProgramData\TEMP:370A117C
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:AB957E48
@Alternate Data Stream - 135 bytes -> C:\ProgramData\TEMP:708E3F13
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:56EE2CAF
@Alternate Data Stream - 134 bytes -> C:\ProgramData\TEMP:157D4840
@Alternate Data Stream - 132 bytes -> C:\ProgramData\TEMP:A8C08E7E
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:D853F961
@Alternate Data Stream - 131 bytes -> C:\ProgramData\TEMP:D751C674
@Alternate Data Stream - 130 bytes -> C:\ProgramData\TEMP:35F7F01D
@Alternate Data Stream - 129 bytes -> C:\ProgramData\TEMP:73C7924E
@Alternate Data Stream - 128 bytes -> C:\ProgramData\TEMP:B30D9A49
@Alternate Data Stream - 127 bytes -> C:\ProgramData\TEMP:BB61BFAF
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:CF6A6C8A
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:9AB15E7A
@Alternate Data Stream - 125 bytes -> C:\ProgramData\TEMP:43A7A7AD
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:D3D507A6
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:D1BCFD4A
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:C447EE44
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:8D25608D
@Alternate Data Stream - 124 bytes -> C:\ProgramData\TEMP:2D7D575C
@Alternate Data Stream - 123 bytes -> C:\ProgramData\TEMP:987DED13
@Alternate Data Stream - 122 bytes -> C:\ProgramData\TEMP:0441DB7A
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:9AF9C79E
@Alternate Data Stream - 121 bytes -> C:\ProgramData\TEMP:12B6A5EC
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:E51234A9
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:B8761AAB
@Alternate Data Stream - 120 bytes -> C:\ProgramData\TEMP:ADE2C1A6
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:F321F01E
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:D41AB8D0
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:90FD8AD5
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:50B14AA6
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:1ED30878
@Alternate Data Stream - 119 bytes -> C:\ProgramData\TEMP:117354E5
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:F57D2F43
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:78AFAE94
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:4C6DC495
@Alternate Data Stream - 118 bytes -> C:\ProgramData\TEMP:20767002
@Alternate Data Stream - 117 bytes -> C:\ProgramData\TEMP:F0A3E54E
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:F28885DF
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:F216755A
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:E8B5993B
@Alternate Data Stream - 116 bytes -> C:\ProgramData\TEMP:DB8ED159
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:98DFF516
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:83E716F0
@Alternate Data Stream - 115 bytes -> C:\ProgramData\TEMP:304D2C3C
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:B618BFFE
@Alternate Data Stream - 114 bytes -> C:\ProgramData\TEMP:178D4338
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:C6E49090
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:9B27D3A9
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:7B0B85D2
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:452C4003
@Alternate Data Stream - 113 bytes -> C:\ProgramData\TEMP:3477DE06
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:ACECBBFF
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:74E00408
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:2D09AB80
@Alternate Data Stream - 112 bytes -> C:\ProgramData\TEMP:14859C24
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:F1E651F6
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:4A7C296A
@Alternate Data Stream - 111 bytes -> C:\ProgramData\TEMP:32A38B26
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:AC8ECED1
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:7C60A173
@Alternate Data Stream - 110 bytes -> C:\ProgramData\TEMP:239CC213
@Alternate Data Stream - 109 bytes -> C:\ProgramData\TEMP:4AC9B4B7
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:5D59B736
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:55EFEB27
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:2A6414DE
@Alternate Data Stream - 108 bytes -> C:\ProgramData\TEMP:04107365
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:B3BAC02F
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:53747726
@Alternate Data Stream - 107 bytes -> C:\ProgramData\TEMP:359163DE
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:CFF21EA7
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:C7F04040
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:8BB2EC84
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:7D271B34
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:41D53451
@Alternate Data Stream - 106 bytes -> C:\ProgramData\TEMP:026B76F2
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:EB6CB455
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:A17AFE82
@Alternate Data Stream - 105 bytes -> C:\ProgramData\TEMP:485A9313
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D35663D1
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:D1B5B4F1
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:88E71AC6
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:77A023CE
@Alternate Data Stream - 104 bytes -> C:\ProgramData\TEMP:3325D6E9
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:D68FBF6D
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:A2CEDFBB
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:A25C1F6E
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:5A99DEB7
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:38BFF11F
@Alternate Data Stream - 101 bytes -> C:\ProgramData\TEMP:0AC32449
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:EFEF58CC
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:B7D0D9DB
@Alternate Data Stream - 100 bytes -> C:\ProgramData\TEMP:16ED1DDB

< End of report >

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI