FreyjaGoddess
Topic Starter
1. I have a slow internet and my connection drops a lot. My ISP suggested that I might have a virus. I have 3 computers to check.
Computer #1 is my most important computer as I work from home and need it for that. I will start with it.
OTL logfile created on: 03/01/2013 3:28:49 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karri\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
7.93 Gb Total Physical Memory | 2.99 Gb Available Physical Memory | 37.72% Memory free
16.07 Gb Paging File | 8.76 Gb Available in Paging File | 54.51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.59 Gb Total Space | 70.86 Gb Free Space | 30.47% Space Free | Partition Type: NTFS
Drive D: | 348.93 Gb Total Space | 92.10 Gb Free Space | 26.40% Space Free | Partition Type: NTFS
Drive J: | 295.02 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive N: | 3.79 Gb Total Space | 3.79 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive O: | 930.95 Gb Total Space | 813.57 Gb Free Space | 87.39% Space Free | Partition Type: FAT32
Computer Name: KARRI-PC | User Name: Karri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/01/03 15:28:41 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karri\Desktop\OTL.exe
PRC - [2012/12/20 13:13:01 | 000,541,760 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe
PRC - [2012/12/14 04:17:04 | 003,467,768 | —- | M] (TeamViewer GmbH) – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2012/12/14 04:17:03 | 009,876,472 | —- | M] (TeamViewer GmbH) – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
PRC - [2012/12/14 04:08:24 | 000,190,968 | —- | M] (TeamViewer GmbH) – C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
PRC - [2012/12/04 07:57:14 | 001,354,736 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Steam\Steam.exe
PRC - [2012/11/28 15:17:53 | 000,040,376 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Program Files (x86)\Citrix\GoToMeeting\1060\g2mstart.exe
PRC - [2012/11/28 15:17:53 | 000,040,376 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Program Files (x86)\Citrix\GoToMeeting\1060\g2mlauncher.exe
PRC - [2012/11/28 15:17:53 | 000,040,376 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Program Files (x86)\Citrix\GoToMeeting\1060\g2mcomm.exe
PRC - [2012/11/14 13:45:40 | 001,831,936 | —- | M] (Livedrive Internet Ltd) – C:\Program Files (x86)\Livedrive\Livedrive.exe
PRC - [2012/10/26 12:17:52 | 000,079,384 | —- | M] (Google) – C:\Users\Karri\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
PRC - [2012/10/10 21:23:42 | 001,258,856 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012/10/04 12:47:20 | 027,112,568 | —- | M] (ooVoo LLC) – C:\Program Files (x86)\ooVoo\ooVoo.exe
PRC - [2012/10/02 13:15:38 | 000,382,824 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012/09/28 20:44:54 | 012,105,344 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Lync\communicator.exe
PRC - [2012/08/30 15:16:16 | 000,310,920 | —- | M] (Pelmorex Media Inc.) – C:\Users\Karri\AppData\Local\The Weather Network\weathereye.exe
PRC - [2012/08/08 14:18:52 | 000,348,664 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012/07/27 15:51:28 | 001,498,552 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
PRC - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/17 17:45:12 | 000,079,872 | —- | M] (SanDisk Corporation) – C:\Users\Karri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2012/05/02 00:42:31 | 000,086,224 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012/05/01 23:34:37 | 000,110,032 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/08/19 04:26:50 | 000,450,848 | —- | M] (Logitech Inc.) – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
PRC - [2011/08/12 12:18:42 | 000,205,336 | —- | M] (Logitech Inc.) – C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2011/02/09 14:00:00 | 000,610,120 | R— | M] (WinZip Computing, S.L.) – C:\Program Files (x86)\WinZip\WZQKPICK.EXE
PRC - [2010/10/29 15:06:08 | 005,915,480 | —- | M] (Logitech Inc.) – C:\Program Files (x86)\Logitech\Vid HD\Vid.exe
PRC - [2009/05/15 06:35:52 | 000,935,208 | —- | M] (Nero AG) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2009/04/23 08:51:38 | 000,691,656 | —- | M] (DT Soft Ltd) – C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe
PRC - [2008/09/11 15:19:28 | 000,105,504 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdateService.exe
PRC - [2008/09/11 15:19:26 | 000,068,640 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdate.exe
PRC - [2008/09/11 15:19:14 | 000,179,232 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaMonitorService.exe
PRC - [2008/09/11 15:19:12 | 000,322,592 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaService.exe
PRC - [2008/08/01 14:30:28 | 000,501,760 | —- | M] () – C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe
PRC - [2008/07/29 16:53:00 | 000,500,784 | —- | M] (Egis Incorporated) – C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
PRC - [2008/07/29 16:52:56 | 000,454,704 | —- | M] (Egis inc.) – C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
PRC - [2008/07/20 16:45:06 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/07/20 16:45:06 | 000,182,808 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/06/23 12:12:52 | 000,174,616 | —- | M] (Intel Corporation) – C:\Program Files\Intel\AMT\LMS.exe
PRC - [2008/05/20 16:50:50 | 000,269,448 | —- | M] (CyberLink) – C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
========== Modules (No Company Name) ==========
MOD - [2012/12/20 13:13:10 | 000,647,168 | —- | M] () – C:\Program Files (x86)\Steam\sdl.dll
MOD - [2012/12/20 13:13:00 | 020,320,240 | —- | M] () – C:\Program Files (x86)\Steam\bin\libcef.dll
MOD - [2012/12/20 13:12:58 | 000,969,280 | —- | M] () – C:\Program Files (x86)\Steam\bin\chromehtml.dll
MOD - [2012/12/20 13:12:56 | 000,124,416 | —- | M] () – C:\Program Files (x86)\Steam\bin\avutil-51.dll
MOD - [2012/12/20 13:12:54 | 000,192,000 | —- | M] () – C:\Program Files (x86)\Steam\bin\avformat-53.dll
MOD - [2012/12/20 13:12:52 | 001,100,800 | —- | M] () – C:\Program Files (x86)\Steam\bin\avcodec-53.dll
MOD - [2012/12/04 20:15:15 | 012,456,040 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
MOD - [2012/12/04 20:15:15 | 000,460,904 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppgooglenaclpluginchrome.dll
MOD - [2012/12/04 20:15:14 | 004,008,040 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
MOD - [2012/12/04 20:14:29 | 000,587,880 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\libglesv2.dll
MOD - [2012/12/04 20:14:28 | 000,124,520 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\libegl.dll
MOD - [2012/12/04 20:14:21 | 000,157,304 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\avutil-51.dll
MOD - [2012/12/04 20:14:20 | 000,275,576 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\avformat-54.dll
MOD - [2012/12/04 20:14:19 | 002,168,952 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll
MOD - [2012/11/21 11:19:12 | 000,059,392 | —- | M] () – C:\Users\Karri\AppData\Local\Temp\{1d478740-1c26-43ed-9b9e-2f8938b03192}\Livedrive.Native.dll
MOD - [2012/11/18 09:00:54 | 000,998,400 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\d08cb6b1c4052e6f5a4e2452870d67d7\System.Management.ni.dll
MOD - [2012/11/18 09:00:04 | 001,840,640 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\7844c1ae91c8f584025756ad72e65176\System.Web.Services.ni.dll
MOD - [2012/11/18 08:59:55 | 001,116,672 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\6082261ca7c89e5c073a073fdd851572\System.DirectoryServices.ni.dll
MOD - [2012/11/18 08:59:55 | 000,627,200 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\850a371af19c00078a8cfbee763fb449\System.Transactions.ni.dll
MOD - [2012/11/18 08:59:54 | 000,627,712 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\1f0ff07c7fa3ef235a9e2b3b6a49db04\System.EnterpriseServices.ni.dll
MOD - [2012/11/18 08:59:50 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7f15d0cb7e4f87f86e425d5ffe7e8280\System.Configuration.ni.dll
MOD - [2012/11/18 08:46:58 | 005,450,752 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\741164a3e36f879b9f9e3ff176465127\System.Xml.ni.dll
MOD - [2012/11/18 08:46:46 | 012,433,920 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\22e554f2c4da53c07e4815a24e2d50e2\System.Windows.Forms.ni.dll
MOD - [2012/11/18 08:46:38 | 001,592,320 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2c6cd37f29fc76d6c2ed6bbed202d82c\System.Drawing.ni.dll
MOD - [2012/11/18 08:46:26 | 006,621,696 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\ee724aeea5f1b9d8a01fa6047fd2ef99\System.Data.ni.dll
MOD - [2012/11/18 08:45:49 | 007,976,960 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b2052acbbbba4f98585196872195e009\System.ni.dll
MOD - [2012/11/18 08:45:43 | 011,492,352 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7ad9c44df3b85848590e63f13fc59804\mscorlib.ni.dll
MOD - [2012/11/14 13:43:48 | 000,781,312 | —- | M] () – C:\Program Files (x86)\Livedrive\Livedrive.Localisation.dll
MOD - [2012/07/27 15:51:28 | 000,249,272 | —- | M] () – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\sqlite.dll
MOD - [2011/09/27 06:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 06:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/08/19 04:26:16 | 000,183,320 | —- | M] () – C:\Program Files (x86)\Common Files\LogiShrd\SharedBin\LvApi11.dll
MOD - [2011/08/12 12:18:56 | 000,342,552 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll
MOD - [2011/08/12 12:18:56 | 000,128,536 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
MOD - [2011/08/12 12:18:56 | 000,029,208 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
MOD - [2011/08/12 12:18:54 | 007,956,504 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll
MOD - [2011/08/12 12:18:54 | 002,145,304 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll
MOD - [2011/07/28 15:20:34 | 000,270,336 | —- | M] () – C:\Program Files (x86)\Livedrive\AlphaFS.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | —- | M] () – C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/29 15:02:38 | 000,751,616 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\vpxmd.dll
MOD - [2010/10/29 15:01:30 | 000,027,472 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\SDL.dll
MOD - [2010/10/20 15:45:26 | 008,801,120 | —- | M] () – C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2009/04/22 16:53:56 | 000,969,040 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtNetwork4.dll
MOD - [2009/04/09 18:04:56 | 002,141,008 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtCore4.dll
MOD - [2009/03/29 23:42:19 | 000,261,632 | —- | M] () – C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009/03/29 23:42:17 | 002,933,760 | —- | M] () – C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2009/03/03 17:18:08 | 000,138,064 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qjpeg4.dll
MOD - [2009/03/03 17:18:06 | 000,035,152 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qico4.dll
MOD - [2009/03/03 17:18:06 | 000,029,008 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qgif4.dll
MOD - [2009/03/03 17:17:46 | 011,311,952 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtWebKit4.dll
MOD - [2009/03/03 17:17:46 | 000,363,856 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtXml4.dll
MOD - [2009/03/03 17:17:44 | 000,200,016 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtSql4.dll
MOD - [2009/03/03 17:17:40 | 000,475,472 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtOpenGL4.dll
MOD - [2009/03/03 17:17:38 | 007,704,400 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtGui4.dll
MOD - [2009/03/03 17:17:32 | 000,291,664 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\phonon4.dll
MOD - [2008/08/01 14:30:28 | 000,501,760 | —- | M] () – C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe
MOD - [2008/04/28 08:49:18 | 000,002,560 | —- | M] () – C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTrayLOC.dll
MOD - [2007/07/11 12:27:24 | 000,400,896 | —- | M] () – C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQDEVCL.dll
MOD - [2007/06/24 15:14:52 | 000,029,696 | —- | M] () – C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMDLL.DLL
========== Services (SafeList) ==========
SRV:64bit: - [2012/10/14 23:20:08 | 000,026,760 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Dynamics CRM\Client\bin\CrmSqlStartupSvc.exe – (CrmSqlStartupSvc)
SRV:64bit: - [2010/02/02 18:03:04 | 000,015,768 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe – (c2wts)
SRV:64bit: - [2008/07/16 12:50:24 | 002,476,432 | —- | M] (Intel® Corporation) [Auto | Running] – C:\Program Files\Intel\inteldh\msm\MSM.exe – (ME Services Manager)
SRV:64bit: - [2008/07/16 12:44:02 | 000,068,496 | —- | M] (Intel® Corporation) [Auto | Running] – C:\Program Files\Intel\inteldh\common\IntelDHSvcMgr.exe – (Software Services Manager)
SRV:64bit: - [2008/06/23 12:12:52 | 000,174,616 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\AMT\LMS.exe – (LMS)
SRV:64bit: - [2008/06/02 08:25:40 | 000,024,576 | —- | M] () [Auto | Running] – C:\Program Files\Acer\Empowering Technology\Service\ETService.exe – (ETService)
SRV:64bit: - [2008/01/20 21:47:32 | 000,383,544 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/12/20 13:13:01 | 000,541,760 | —- | M] (Valve Corporation) [On_Demand | Running] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2012/12/19 08:28:50 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/12/14 04:17:04 | 003,467,768 | —- | M] (TeamViewer GmbH) [Auto | Running] – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe – (TeamViewer8)
SRV - [2012/12/05 16:29:30 | 000,115,168 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/11/14 13:48:28 | 000,210,144 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Livedrive\VSSService.exe – (LivedriveVSSService)
SRV - [2012/10/10 21:23:42 | 001,258,856 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe – (nvUpdatusService)
SRV - [2012/10/02 13:15:38 | 000,382,824 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe – (Stereo Service)
SRV - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/05/02 00:42:31 | 000,086,224 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2012/05/01 23:34:37 | 000,110,032 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2011/08/19 04:26:50 | 000,450,848 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe – (UMVPFSrv)
SRV - [2010/03/18 12:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/05/15 06:35:52 | 000,935,208 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0)
SRV - [2009/03/29 23:42:14 | 000,066,368 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2008/09/11 15:19:28 | 000,105,504 | —- | M] (CyberLink) [Auto | Running] – C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdateService.exe – (CyberLink Live Push Update Service)
SRV - [2008/09/11 15:19:14 | 000,179,232 | —- | M] (CyberLink) [Auto | Running] – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaMonitorService.exe – (CyberLink Live Monitor Service)
SRV - [2008/09/11 15:19:12 | 000,322,592 | —- | M] (CyberLink Corp.) [Auto | Running] – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaService.exe – (CyberLink Live Service)
SRV - [2008/07/29 16:53:00 | 000,500,784 | —- | M] (Egis Incorporated) [Auto | Running] – C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe – (eDataSecurity Service)
SRV - [2008/07/20 16:45:06 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON)
SRV - [2008/05/20 16:50:50 | 000,269,448 | —- | M] (CyberLink) [Auto | Running] – C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe – (Acer HomeMedia Connect Service)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/11/10 10:50:36 | 000,352,008 | —- | M] (EldoS Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\cbfs3.sys – (cbfs3)
DRV:64bit: - [2012/08/21 12:01:20 | 000,033,240 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2012/07/09 12:42:54 | 000,052,736 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2012/05/02 14:24:12 | 000,027,760 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\Windows\SysNative\DRIVERS\avkmgr.sys – (avkmgr)
DRV:64bit: - [2012/04/27 09:20:04 | 000,132,832 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\Windows\SysNative\DRIVERS\avipbb.sys – (avipbb)
DRV:64bit: - [2012/04/24 23:32:27 | 000,098,848 | —- | M] (Avira GmbH) [File_System | Auto | Running] – C:\Windows\SysNative\DRIVERS\avgntflt.sys – (avgntflt)
DRV:64bit: - [2012/02/29 08:52:46 | 000,016,384 | —- | M] (Microsoft Corporation) [Recognizer | System | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/08/19 04:27:30 | 004,869,024 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\lvuvc64.sys – (LVUVC64)
DRV:64bit: - [2011/08/19 04:27:30 | 000,351,136 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\lvrs64.sys – (LVRS64)
DRV:64bit: - [2009/11/20 14:26:50 | 000,031,232 | —- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\tap0901.sys – (tap0901)
DRV:64bit: - [2009/09/30 19:51:42 | 000,046,592 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\wpdusb.sys – (WpdUsb)
DRV:64bit: - [2009/08/06 11:52:34 | 000,871,408 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\sptd.sys – (sptd)
DRV:64bit: - [2009/05/09 00:14:20 | 000,015,752 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\NuidFltr.sys – (NuidFltr)
DRV:64bit: - [2008/08/13 21:18:54 | 008,029,792 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\igdkmd64.sys – (igfx)
DRV:64bit: - [2008/07/29 16:53:50 | 000,060,976 | —- | M] (Egis Incorporated) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\PSDVdisk.sys – (psdvdisk)
DRV:64bit: - [2008/07/29 16:53:50 | 000,021,040 | —- | M] (Egis Incorporated) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\PSDNServ.sys – (PSDNServ)
DRV:64bit: - [2008/07/29 16:53:48 | 000,022,064 | —- | M] (Egis Incorporated) [File_System | Boot | Running] – C:\Windows\SysNative\DRIVERS\psdfilter.sys – (PSDFilter)
DRV:64bit: - [2008/07/25 04:26:20 | 000,315,008 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\e1y60x64.sys – (e1yexpress)
DRV:64bit: - [2008/07/20 04:44:54 | 000,402,456 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\DRIVERS\iaStor.sys – (iaStor)
DRV:64bit: - [2008/07/14 19:20:42 | 000,126,464 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService)
DRV:64bit: - [2008/03/28 11:42:58 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\HECIx64.sys – (HECIx64)
DRV:64bit: - [2008/01/30 19:48:32 | 000,016,384 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2008/01/30 19:48:16 | 000,016,384 | —- | M] (NewTech Infosystems Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV - [2008/06/02 08:20:12 | 000,017,952 | —- | M] (Acer, Inc.) [Kernel | Auto | Running] – C:\Windows\SysWOW64\drivers\int15_64.sys – (int15)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACAW
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://global.acer.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: CFBFAE00-17A6-11D0-99CB-00C04FD64497} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACAW
IE - HKCU\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}
IE - HKCU\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.theweathernetwork.com/weather/caon0532"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_38: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\Karri\AppData\Local\Citrix\Plugins\79\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Karri\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Karri\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/05 16:29:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/12/05 16:29:26 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/05 16:29:30 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/12/05 16:29:26 | 000,000,000 | —D | M]
[2009/10/29 12:03:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Karri\AppData\Roaming\Mozilla\Extensions
[2009/10/29 12:03:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Karri\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/10/26 01:50:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Karri\AppData\Roaming\Mozilla\Firefox\Profiles\3rkyge3u.default\extensions
[2011/10/15 13:35:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Karri\AppData\Roaming\Mozilla\Firefox\Profiles\3rkyge3u.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/08/06 11:56:41 | 000,002,399 | —- | M] () – C:\Users\Karri\AppData\Roaming\Mozilla\Firefox\Profiles\3rkyge3u.default\searchplugins\daemon-search.xml
[2012/12/28 23:43:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/12/05 16:29:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/12/05 16:29:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/12/05 16:29:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012/12/28 23:43:40 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA}
[2012/12/05 16:29:30 | 000,262,112 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/28 20:39:06 | 000,031,872 | —- | M] () – C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
[2012/09/24 16:21:50 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/12/05 16:29:29 | 000,002,058 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage: http://www.theweathernetwork.com/weather/caon0532
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter}
CHR - homepage: http://www.theweathernetwork.com/weather/caon0532
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Java™ Platform SE 6 U32 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.320.5 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Karri\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Entanglement = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: AT_JamesWhite = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm\3\
CHR - Extension: AdBlock = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.54_0\
CHR - Extension: Poppit = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
O1 HOSTS File: ([2013/01/03 08:12:30 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll (Egis)
O2:64bit: - BHO: (BrowserHelper Class) - {EDF48A39-1442-463F-9F4E-F376A78D034A} - C:\Program Files (x86)\Livedrive\LivedriveExplorerExtensions.dll (Livedrive Internet Ltd)
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
O3:64bit: - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [Acer Empowering Technology Monitor] C:\Program Files\Acer\Empowering Technology\SysMonitor.exe ()
O4:64bit: - HKLM..\Run: [eDataSecurity Loader] C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe (Egis Incorporated)
O4:64bit: - HKLM..\Run: [EmpoweringTechnology] C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe boot File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelSWUpdateClient] C:\Program Files\Intel\inteldh\common\SWUpdateClient.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files (x86)\Acer\Acer Assist\launcher.exe ()
O4 - HKLM..\Run: [Acer Product Registration] C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe (Leader Technologies)
O4 - HKLM..\Run: [ACQTMOUSE] C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CLPushUpdate] C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdate.exe (CyberLink)
O4 - HKLM..\Run: [Communicator] C:\Program Files (x86)\Microsoft Lync\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DivXMediaServer] "C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" File not found
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [PCMMediaSharing] C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe ()
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKCU..\Run: [EADM] C:\Program Files (x86)\Origin\Origin.exe (Electronic Arts)
O4 - HKCU..\Run: [GoToMeeting] C:\Program Files (x86)\Citrix\GoToMeeting\1060\g2mstart.exe (Citrix Online, a division of Citrix Systems, Inc.)
O4 - HKCU..\Run: [Livedrive] C:\Program Files (x86)\Livedrive\Livedrive.exe (Livedrive Internet Ltd)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files (x86)\ooVoo\oovoo.exe (ooVoo LLC)
O4 - HKCU..\Run: [SansaDispatch] C:\Users\Karri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [WeatherEye] C:\Users\Karri\AppData\Local\The Weather Network\weathereye.exe (Pelmorex Media Inc.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aboriginallink.ca ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: aboriginallink.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: dynamics.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: live.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoftonline.com ([portal] https in Trusted sites)
O15 - HKCU\..Trusted Domains: outlook.com ([]http in Trusted sites)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} http://www.shockwave.com/content/trijinx/s…nx.1.0.0.86.cab (CPlayFirstTriJinxControl Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O16 - DPF: {CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3DF7249C-DC40-4434-8123-8375B94A51F0}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\intu-qt2008 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-qt2009 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-tt2010 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-tt2011 - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\intu-qt2008 {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files (x86)\QuickTax 2008\ic2008pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files (x86)\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files (x86)\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2011 {B3B5DAD9-E96D-45b4-B636-B6CF2F773DE1} - C:\Program Files (x86)\TurboTax 2011\ic2011pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysNative\CbFsMntNtf3.dll (EldoS Corporation)
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O22:64bit: - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\Windows\SysNative\CbFsMntNtf3.dll (EldoS Corporation)
O22 - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img16.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img16.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/24 10:26:00 | 000,000,740 | R— | M] () - J:\autorun.inf – [ UDF ]
O32 - Unable to obtain root file information for disk N:\
O32 - Unable to obtain root file information for disk O:\
O33 - MountPoints2\{a4b61a9e-df1e-11e1-aff1-00219761ce94}\Shell\AutoRun\command - "" = J:\fscommand\LS_Start_Launch.exe – [2010/05/10 13:00:11 | 000,151,040 | R— | M] ()
O33 - MountPoints2\{a4b61a9e-df1e-11e1-aff1-00219761ce94}\Shell\Launcher\command - "" = J:\Get_Started_with_LifeStudio.exe – [2010/05/10 13:00:13 | 003,478,888 | R— | M] (Adobe Systems, Inc.)
O33 - MountPoints2\{a4b61b3b-df1e-11e1-aff1-00219761ce94}\Shell\AutoRun\command - "" = N:\fscommand\LS_Start_Launch.exe
O33 - MountPoints2\{a4b61b3b-df1e-11e1-aff1-00219761ce94}\Shell\Launcher\command - "" = N:\Get_Started_with_LifeStudio.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/01/03 15:28:39 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Karri\Desktop\OTL.exe
[2013/01/03 08:16:20 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{3858D4CE-7BC8-4FE8-9F1E-F3F94A633EFD}
[2013/01/02 15:49:38 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\ooVoo Details
[2013/01/02 15:49:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ooVoo
[2013/01/02 15:49:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\ooVoo
[2013/01/02 15:39:54 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2013/01/02 15:39:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2013/01/02 15:25:53 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Yahoo!
[2013/01/02 15:17:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Yahoo!
[2013/01/02 15:16:04 | 000,439,704 | —- | C] (Yahoo! Inc.) – C:\Users\Karri\Desktop\msgr11us.exe
[2013/01/02 09:23:29 | 015,271,824 | —- | C] (Google Inc.) – C:\Users\Karri\Desktop\picasa39-setup.exe
[2013/01/02 08:12:35 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{10BF1A49-4693-4220-A360-114CA5DDC371}
[2013/01/01 10:41:28 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{86E62FE5-66DA-4681-AE2C-76E89E9BC9DD}
[2012/12/31 07:33:55 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{87035D76-36ED-4720-BF9B-830C39E20E79}
[2012/12/30 11:42:34 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{91A02224-9FFD-4884-8A5A-7F1D116DD04D}
[2012/12/28 23:43:35 | 000,157,680 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/12/28 23:43:35 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/12/28 23:43:35 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/12/28 18:58:45 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{184713FA-E986-4774-94A8-A2A93B6AD872}
[2012/12/23 09:17:29 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{0CB37340-0337-46FF-802E-71CB478313AD}
[2012/12/21 23:44:49 | 000,368,128 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2012/12/21 23:44:49 | 000,293,376 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2012/12/21 23:44:49 | 000,048,128 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2012/12/21 23:44:49 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2012/12/21 08:52:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/12/21 07:38:56 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{3FBDA6A9-2EFD-4BDB-A67E-2F015241502F}
[2012/12/20 08:04:19 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{A92265B7-2452-434A-9E9C-3A6977E6589B}
[2012/12/19 15:46:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/12/19 15:46:26 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/12/19 15:46:24 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/12/19 15:46:24 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2012/12/19 07:57:25 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{7AF64024-6B51-43B7-B313-07638ED02640}
[2012/12/14 13:18:51 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Regina Qu'Appelle Health Region
[2012/12/14 12:52:10 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Porcupine Health Unit
[2012/12/14 12:45:41 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Ontario Hospital Association
[2012/12/14 08:42:45 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Weather Network
[2012/12/14 08:42:41 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\The Weather Network
[2012/12/14 08:40:20 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{7069D2AB-F115-4928-B074-71ACB02FC834}
[2012/12/14 08:17:15 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\NVIDIA
[2012/12/13 15:04:37 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Timmins and District Hospital
[2012/12/13 14:59:30 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\North Bay Regional Health Centre
[2012/12/13 08:15:05 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{AF641A64-E0DF-4E17-92D3-BF9AC3E13389}
[2012/12/12 21:10:05 | 000,054,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdfLdr.sys
[2012/12/12 21:10:05 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wdfres.dll
[2012/12/12 21:10:03 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2012/12/12 21:10:03 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winusb.dll
[2012/12/12 21:10:02 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2012/12/12 21:10:02 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2012/12/12 21:10:02 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2012/12/12 21:09:16 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/12/12 21:09:16 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/12/12 21:09:16 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/12/12 21:09:15 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/12/12 21:09:15 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/12/12 21:09:15 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/12/12 21:09:15 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/12/12 21:09:15 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/12/12 21:09:15 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/12/12 21:09:14 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/12/12 21:09:14 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/12/12 21:09:14 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/12/12 21:09:13 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/12/12 21:09:13 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/12/12 21:09:13 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/12/12 16:03:15 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Atlantic Aboriginal health Research Program
[2012/12/12 14:18:55 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Health Sciences North - Sudbury
[2012/12/12 14:16:52 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Patient Voices Network
[2012/12/12 04:19:36 | 001,210,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012/12/12 04:19:29 | 000,477,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnet.dll
[2012/12/12 04:19:29 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnet.dll
[2012/12/12 04:19:29 | 000,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnathlp.dll
[2012/12/12 04:19:29 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnsvr.exe
[2012/12/12 04:19:29 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnsvr.exe
[2012/12/11 21:17:55 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{A122EF8E-C279-47A0-BF6B-64C219125E8A}
[2012/12/11 13:56:12 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Citrix
[2012/12/11 13:31:44 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Dilico
[2012/12/11 13:26:33 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\St. Joseph's Care Group
[2012/12/11 13:23:55 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Thunder Bay Community Economic Development Commission
[2012/12/11 13:14:39 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Confederation College
[2012/12/11 08:03:42 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{0CD10092-4D8A-4B3A-8161-1F0997E76605}
[2012/12/10 16:13:05 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Victoria General Hospital
[2012/12/10 15:54:56 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Concordia Hospital
[2012/12/10 15:28:35 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Seven Oaks General Hospital
[2012/12/10 15:15:41 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Norwest Community Health Centres
[2012/12/10 14:38:54 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\LogMeIn Rescue Applet
[2012/12/10 13:20:27 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Sault Area Hospital
[2012/12/10 13:10:20 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Thunder Bay Regional Health Sciences Centre
[2012/12/10 12:56:56 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Health Sciences Centre Winnipeg
[2012/12/10 07:55:58 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{A4C7EEF5-843F-4720-BD17-CDD942FA9120}
[2012/12/09 13:18:37 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{57AECE94-BF36-4E90-B2D7-1A5F166C5616}
[2012/12/07 09:58:45 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Northern Ontario School of Medicine (NOSM)
[2012/12/07 09:40:22 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Couchiching Family Health Team
[2012/12/07 08:10:59 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{1B7C379E-2F27-4C8B-9C7D-26384FDECA9E}
[2012/12/06 07:31:52 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{B4D454D9-8266-474A-B661-688CEE1665A5}
[2012/12/05 16:29:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/12/05 11:00:52 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Northern Health
[2012/12/05 11:00:35 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Opening Scripts
[2012/12/05 07:36:50 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{2C228139-8687-43F2-9088-E478BB61A606}
========== Files - Modified Within 30 Days ==========
[2013/01/03 15:29:11 | 000,025,854 | —- | M] () – C:\Users\Karri\Desktop\R110829104.20130102.pdf
[2013/01/03 15:28:41 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karri\Desktop\OTL.exe
[2013/01/03 15:27:59 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/03 15:20:22 | 000,002,559 | —- | M] () – C:\Users\Karri\Desktop\HiJackThis.lnk
[2013/01/03 14:39:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3989614313-289073978-4266361891-1000UA.job
[2013/01/03 14:15:29 | 000,201,281 | —- | M] () – C:\Users\Karri\Desktop\27292_10151363206356049_672386584_n.jpg
[2013/01/03 14:12:21 | 000,003,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/03 14:12:21 | 000,003,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/03 08:12:30 | 000,000,761 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/01/03 08:12:20 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/01/02 15:49:32 | 000,001,772 | —- | M] () – C:\Users\Public\Desktop\ooVoo.lnk
[2013/01/02 15:24:12 | 001,402,880 | —- | M] () – C:\Users\Karri\Desktop\HiJackThis.msi
[2013/01/02 15:23:40 | 000,004,824 | —- | M] () – C:\Windows\wininit.ini
[2013/01/02 15:16:34 | 000,439,704 | —- | M] (Yahoo! Inc.) – C:\Users\Karri\Desktop\msgr11us.exe
[2013/01/02 11:24:00 | 000,132,078 | —- | M] () – C:\Users\Karri\Desktop\Scandinavian.jpg
[2013/01/02 11:19:14 | 000,432,213 | —- | M] () – C:\Users\Karri\Desktop\Video call snapshot 48.png
[2013/01/02 09:25:01 | 000,000,969 | —- | M] () – C:\Users\Karri\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2013/01/02 09:25:01 | 000,000,945 | —- | M] () – C:\Users\Public\Desktop\Picasa 3.lnk
[2013/01/02 09:24:05 | 015,271,824 | —- | M] (Google Inc.) – C:\Users\Karri\Desktop\picasa39-setup.exe
[2012/12/31 21:39:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3989614313-289073978-4266361891-1000Core.job
[2012/12/22 13:58:20 | 000,092,623 | —- | M] () – C:\Users\Karri\Desktop\16800_10151343017346049_1636654817_n.jpg
[2012/12/22 08:29:40 | 000,393,856 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/12/21 14:36:44 | 000,051,335 | —- | M] () – C:\Users\Karri\Desktop\224562_10150266265914978_307550646_n.jpg
[2012/12/21 14:34:55 | 000,027,506 | —- | M] () – C:\Users\Karri\Desktop\17082_548427821850478_1374715143_n.jpg
[2012/12/21 08:52:23 | 000,000,905 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2012/12/19 15:46:48 | 000,001,698 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/12/19 11:15:11 | 000,001,001 | —- | M] () – C:\Users\Public\Desktop\TeamViewer 8.lnk
[2012/12/19 08:28:50 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/12/19 08:28:50 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/12/18 07:31:32 | 000,652,288 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/12/18 07:31:31 | 000,766,246 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/12/18 07:31:31 | 000,125,686 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/12/16 08:31:20 | 000,048,128 | —- | M] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2012/12/16 08:12:54 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2012/12/16 06:08:21 | 000,368,128 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2012/12/16 05:50:29 | 000,293,376 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2012/12/14 16:25:20 | 000,077,393 | —- | M] () – C:\Users\Karri\Desktop\oj-murders-tape-photographs__oPt.jpg
[2012/12/14 08:42:48 | 000,000,952 | —- | M] () – C:\Users\Karri\Desktop\The Weather Network.lnk
[2012/12/13 13:44:08 | 000,002,046 | —- | M] () – C:\Users\Karri\Desktop\Google Chrome.lnk
[2012/12/13 13:44:08 | 000,002,008 | —- | M] () – C:\Users\Karri\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/12/11 13:56:12 | 000,001,207 | —- | M] () – C:\Users\Karri\Desktop\GoToMeeting.lnk
[2012/12/07 16:06:43 | 000,000,466 | —- | M] () – C:\Users\Karri\Documents\ChatLog New Meeting 2012_12_07 16_06.rtf
[2012/12/07 15:08:36 | 005,406,957 | —- | M] () – C:\Users\Karri\Desktop\DSC01531.JPG
[2012/12/07 15:00:54 | 005,391,002 | —- | M] () – C:\Users\Karri\Desktop\DSC01505.JPG
[2012/12/07 15:00:30 | 005,038,827 | —- | M] () – C:\Users\Karri\Desktop\DSC01476.JPG
[2012/12/07 15:00:24 | 005,120,304 | —- | M] () – C:\Users\Karri\Desktop\DSC01475.JPG
[2012/12/07 14:59:34 | 005,157,162 | —- | M] () – C:\Users\Karri\Desktop\DSC01466.JPG
[2012/12/07 14:58:38 | 004,863,461 | —- | M] () – C:\Users\Karri\Desktop\DSC01464.JPG
[2012/12/07 11:21:09 | 708,422,035 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/12/07 09:15:02 | 005,410,422 | —- | M] () – C:\Users\Karri\Desktop\DSC01436.JPG
========== Files Created - No Company Name ==========
[2013/01/03 15:29:10 | 000,025,854 | —- | C] () – C:\Users\Karri\Desktop\R110829104.20130102.pdf
[2013/01/03 14:15:28 | 000,201,281 | —- | C] () – C:\Users\Karri\Desktop\27292_10151363206356049_672386584_n.jpg
[2013/01/02 15:49:32 | 000,001,772 | —- | C] () – C:\Users\Public\Desktop\ooVoo.lnk
[2013/01/02 15:39:54 | 000,002,559 | —- | C] () – C:\Users\Karri\Desktop\HiJackThis.lnk
[2013/01/02 15:24:05 | 001,402,880 | —- | C] () – C:\Users\Karri\Desktop\HiJackThis.msi
[2013/01/02 11:24:00 | 000,132,078 | —- | C] () – C:\Users\Karri\Desktop\Scandinavian.jpg
[2013/01/02 11:19:05 | 000,432,213 | —- | C] () – C:\Users\Karri\Desktop\Video call snapshot 48.png
[2012/12/22 13:58:20 | 000,092,623 | —- | C] () – C:\Users\Karri\Desktop\16800_10151343017346049_1636654817_n.jpg
[2012/12/21 14:36:43 | 000,051,335 | —- | C] () – C:\Users\Karri\Desktop\224562_10150266265914978_307550646_n.jpg
[2012/12/21 14:34:55 | 000,027,506 | —- | C] () – C:\Users\Karri\Desktop\17082_548427821850478_1374715143_n.jpg
[2012/12/21 08:52:23 | 000,000,905 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2012/12/19 07:59:00 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/14 16:25:20 | 000,077,393 | —- | C] () – C:\Users\Karri\Desktop\oj-murders-tape-photographs__oPt.jpg
[2012/12/14 08:42:48 | 000,000,952 | —- | C] () – C:\Users\Karri\Desktop\The Weather Network.lnk
[2012/12/12 21:10:08 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/12/12 21:10:08 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/12/11 13:56:12 | 000,001,207 | —- | C] () – C:\Users\Karri\Desktop\GoToMeeting.lnk
[2012/12/07 16:06:43 | 000,000,466 | —- | C] () – C:\Users\Karri\Documents\ChatLog New Meeting 2012_12_07 16_06.rtf
[2012/12/07 15:20:27 | 005,406,957 | —- | C] () – C:\Users\Karri\Desktop\DSC01531.JPG
[2012/12/07 15:19:09 | 005,391,002 | —- | C] () – C:\Users\Karri\Desktop\DSC01505.JPG
[2012/12/07 15:02:00 | 005,120,304 | —- | C] () – C:\Users\Karri\Desktop\DSC01475.JPG
[2012/12/07 15:01:37 | 005,038,827 | —- | C] () – C:\Users\Karri\Desktop\DSC01476.JPG
[2012/12/07 14:59:50 | 005,157,162 | —- | C] () – C:\Users\Karri\Desktop\DSC01466.JPG
[2012/12/07 14:59:11 | 004,863,461 | —- | C] () – C:\Users\Karri\Desktop\DSC01464.JPG
[2012/12/07 14:57:04 | 005,410,422 | —- | C] () – C:\Users\Karri\Desktop\DSC01436.JPG
[2012/12/06 10:57:24 | 000,001,013 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
[2012/12/06 10:57:24 | 000,001,001 | —- | C] () – C:\Users\Public\Desktop\TeamViewer 8.lnk
[2012/07/22 17:32:00 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2012/02/01 17:18:15 | 000,000,552 | —- | C] () – C:\Users\Karri\AppData\Local\d3d8caps.dat
[2011/12/30 21:49:42 | 000,000,680 | —- | C] () – C:\Users\Karri\AppData\Local\d3d9caps.dat
[2011/10/10 17:52:43 | 000,742,262 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/02 13:28:57 | 000,031,232 | —- | C] () – C:\Users\Karri\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/19 04:26:20 | 010,898,456 | —- | C] () – C:\Windows\SysWow64\LogiDPP.dll
[2011/08/19 04:26:20 | 000,336,408 | —- | C] () – C:\Windows\SysWow64\DevManagerCore.dll
[2011/08/19 04:26:20 | 000,104,472 | —- | C] () – C:\Windows\SysWow64\LogiDPPApp.exe
[2011/04/01 09:07:49 | 000,060,864 | —- | C] () – C:\Users\Karri\g2mdlhlpx.exe
[2011/03/19 12:17:47 | 000,004,824 | —- | C] () – C:\Windows\wininit.ini
[2010/03/12 21:00:58 | 000,000,760 | —- | C] () – C:\Users\Karri\AppData\Roaming\setup_ldm.iss
[2009/09/21 11:30:38 | 000,000,029 | —- | C] () – C:\Users\Karri\AppData\Roaming\default.rss
[2009/09/15 11:40:54 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/06/28 10:50:52 | 000,048,127 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/06/28 10:50:52 | 000,048,127 | —- | C] () – C:\ProgramData\nvModes.001
[2008/10/28 07:57:39 | 000,000,052 | —- | C] () – C:\ProgramData\CLSDefine.ini
========== ZeroAccess Check ==========
[2006/11/02 10:30:40 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 12:59:03 | 012,899,840 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 12:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/04/11 02:11:14 | 000,891,392 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 01:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2008/01/20 21:50:58 | 000,513,024 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Alternate Data Streams ==========
@Alternate Data Stream - 94 bytes -> C:\ProgramData\Temp:D5AA39DD
@Alternate Data Stream - 257 bytes -> C:\ProgramData\Temp:36608448
@Alternate Data Stream - 252 bytes -> C:\ProgramData\Temp:1E288DA3
@Alternate Data Stream - 251 bytes -> C:\ProgramData\Temp:AE289451
@Alternate Data Stream - 247 bytes -> C:\ProgramData\Temp:7D288858
@Alternate Data Stream - 247 bytes -> C:\ProgramData\Temp:0E61938B
@Alternate Data Stream - 242 bytes -> C:\ProgramData\Temp:FEE00EB9
@Alternate Data Stream - 237 bytes -> C:\ProgramData\Temp:2EB79F01
@Alternate Data Stream - 236 bytes -> C:\ProgramData\Temp:F2327E82
@Alternate Data Stream - 236 bytes -> C:\ProgramData\Temp:DE6EED8B
@Alternate Data Stream - 235 bytes -> C:\ProgramData\Temp:35629AE6
@Alternate Data Stream - 233 bytes -> C:\ProgramData\Temp:CEE4A457
@Alternate Data Stream - 230 bytes -> C:\ProgramData\Temp:08DB8D99
@Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:3B07E6F4
@Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:349E5B74
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:10D45FC3
@Alternate Data Stream - 224 bytes -> C:\ProgramData\Temp:4B244549
@Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:5AE33054
@Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:014BC3B4
@Alternate Data Stream - 221 bytes -> C:\ProgramData\Temp:3C0887BF
@Alternate Data Stream - 218 bytes -> C:\ProgramData\Temp:41884BBE
@Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:CB0FEE2B
@Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:38D2EA83
@Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:169E7AC5
@Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:A9ABA3FF
@Alternate Data Stream - 210 bytes -> C:\ProgramData\Temp:ED9B661E
@Alternate Data Stream - 196 bytes -> C:\ProgramData\Temp:3D36932D
@Alternate Data Stream - 152 bytes -> C:\ProgramData\Temp:6301CE40
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:2A8A3140
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:E9900C74
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:4B70A9FA
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:908A1B53
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:6E11933F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:1B3549F2
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:7BB584AA
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:274516E7
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:131C0EE9
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:3AC0ED43
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:C9BC8592
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:793F316E
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:92DB4653
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:8AB6C1D7
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:CFF6B3FF
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:490BCC52
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:DCA79AB3
@Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:2CED8825
@Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:FC60E0F8
@Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:861A898F
@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:580E04D8
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:4F636E25
< End of report >
OTL Extras logfile created on: 03/01/2013 3:28:49 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karri\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
7.93 Gb Total Physical Memory | 2.99 Gb Available Physical Memory | 37.72% Memory free
16.07 Gb Paging File | 8.76 Gb Available in Paging File | 54.51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.59 Gb Total Space | 70.86 Gb Free Space | 30.47% Space Free | Partition Type: NTFS
Drive D: | 348.93 Gb Total Space | 92.10 Gb Free Space | 26.40% Space Free | Partition Type: NTFS
Drive J: | 295.02 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive N: | 3.79 Gb Total Space | 3.79 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive O: | 930.95 Gb Total Space | 813.57 Gb Free Space | 87.39% Space Free | Partition Type: FAT32
Computer Name: KARRI-PC | User Name: Karri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = C9 C1 E4 2F 8B 3A CA 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0485F8E3-1A09-4024-BA7E-F98A6E3B67FB}" = rport=138 | protocol=17 | dir=out | app=system |
"{26EACD8C-7194-4F96-81ED-2154D5E90590}" = lport=2869 | protocol=6 | dir=in | app=system |
"{42D82151-1A35-4B9D-A760-559221DBBA4F}" = rport=137 | protocol=17 | dir=out | app=system |
"{438F3FCE-8893-48B9-A035-40554350B370}" = lport=139 | protocol=6 | dir=in | app=system |
"{50115D97-DB49-44CD-84E2-4DA4E2F2EEF9}" = lport=137 | protocol=17 | dir=in | app=system |
"{5AA76EEF-6B8E-438A-B21C-10FE61C8273E}" = rport=445 | protocol=6 | dir=out | app=system |
"{72723F71-5C72-4E2F-A8BB-1B2FACDB0B03}" = lport=138 | protocol=17 | dir=in | app=system |
"{7368AFD0-6C88-4905-BAB2-CC2F4BB6602B}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{8A9ABA56-F005-42CB-835A-680487CE04E1}" = lport=445 | protocol=6 | dir=in | app=system |
"{B1E53891-F0B7-4D8F-87CF-92D87825598A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{B8806828-0C3B-4515-8175-852416FE4373}" = rport=139 | protocol=6 | dir=out | app=system |
"{BCE834EC-BBCE-41BD-8EAE-8AD289A873AF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C73FCED9-8013-44F9-9592-8A54D7382EFF}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{D8416C81-AE7C-4BDA-9F38-50CB9711BFF2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{EA7FAF37-873E-474D-ACA0-61CFD228318E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{026A20FC-E75E-4AE5-A84F-3FB1E5C8E8FD}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{0D80A6FE-DF65-421F-9336-1A166CC05632}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\droplitz\cascade.exe |
"{143090E1-9C5F-41B5-9B2E-C1D71C44FB47}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotel dash\hoteldash.exe |
"{15586373-00E5-411F-BFF2-941CC4C64474}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\eufloria\eufloria.exe |
"{1A6A2C55-F5C3-49DA-95B9-70BBA78D5589}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{1CB745C2-A73C-42B2-ACA3-A3F7F2C3C15B}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia connect\kernel\dms\clmsserver.exe |
"{1D84E0DD-067E-4B7D-88CB-A6E2F48DD0A5}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{211AD758-F2EB-4C6B-867E-9E1B7A5A0437}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotel dash\hoteldash.exe |
"{25757D9E-3675-4F14-A555-A49B3425CE2B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{28280830-880C-44CF-8B73-76D37540F99B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzle chronicles\puzzlechronicles.exe |
"{2F4D3580-9E97-40D0-993E-04DADC4CE426}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{31084447-3FDA-4BC2-B9ED-916FEF2295CF}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{31DB2597-38D6-4A4E-AA8B-EF6C74DEF37B}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia connect\acer homemedia connect.exe |
"{33B49371-D92B-40D5-867C-05009872AB14}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{36BE2B08-E41C-430A-8CE3-BA072FB7BB18}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\zuma's revenge\zumasrevenge.exe |
"{3EA1A45A-B3BE-4B86-83A9-882D7631EB07}" = dir=in | app=c:\program files\microsoft lync\ucmapi64.exe |
"{41EB73A3-0B7B-4FE3-89F3-ABF7F7551415}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\luxor 5th passage\luxor - 5th passage.exe |
"{42D7C32D-AFB0-4E17-805C-D17ACCBF9B1F}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{437A62E9-5F86-447B-BC81-C06350379349}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{45E1E295-7947-4BC0-A7D5-1341E4C006DF}" = dir=in | app=c:\program files (x86)\acer arcade live\acer arcade live main page\acer arcade live.exe |
"{46319C9A-D991-4DF5-AAB0-75693DD14404}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{482E5199-DCBB-40E3-A1DB-BC2D27399AB0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{49DF5E5B-FAC5-4C46-A567-8DEC235647EC}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{4CD3CDE7-136E-4D80-8E17-BCA58F2A9160}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{4DE71902-F71D-485C-BFA2-FCFFC948878D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{50BCD8A0-DE73-4E01-8E42-A26440FEA07D}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clsomamonitorservice.exe |
"{5128F576-1743-46EE-BD62-15FD815E5D6F}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{53F1AE12-C085-4AF4-A1A3-3E0493DDE57C}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clsomaservice.exe |
"{59F76541-B1FB-4C81-A98D-9DFB3F36A7A7}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia trial creator\acer homemedia trial creator.exe |
"{5A4CD912-D98B-4752-8758-9CBEFF37B38C}" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{5A846A34-4E3D-4397-B499-EA651EAC799A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{5B53DBD0-CF30-4E48-A60A-B8F14A7338AB}" = dir=in | app=c:\program files (x86)\acer arcade live\acer slideshow dvd\acer slideshow dvd.exe |
"{5BFCE5AC-A1CF-4E02-945E-082F476C53AB}" = protocol=17 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{60908FE1-AD5A-44DE-973F-D1B56E4C95C4}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{63529CEB-A982-4D8F-B3D4-38798D235B97}" = dir=in | app=c:\program files (x86)\acer arcade live\acer dv magician\acer dv magician.exe |
"{6B53143B-FAF1-4826-A5C4-2D0D25E3B6B1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\eufloria\eufloria.exe |
"{6BF7994F-F161-4D37-BA52-9F2B7903F92D}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{6EF76C59-39D2-4E16-A3D9-FD112F09E4D5}" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{70DDDEC1-424F-4FB0-90AB-DC467AF2DE73}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{722B5250-5770-4A57-AA8A-77F2F3935D0C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\luxor 5th passage\luxor - 5th passage.exe |
"{7992BD87-E39E-4DF3-AE41-7CC61872FA91}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzlequest2\puzzlequest2.exe |
"{8B57FA11-FAAA-45D7-9CD0-779B67A0691F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\zuma's revenge\zumasrevenge.exe |
"{8F30AF37-993B-4183-9481-23345349D2E4}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{9AE2D478-D3BA-40C2-ADE9-3C8EBE115FAF}" = dir=in | app=c:\program files (x86)\acer arcade live\acer videomagician\acer videomagician.exe |
"{9EBA2EBE-1437-41D5-B5DD-D10C4459955A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"{A755F2BB-5391-4EC8-8CC9-2A6E28230F0D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A792D402-18C2-4584-9985-67947D43CBB4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe |
"{AB95C5A1-1EE1-4623-B8B8-AC3AD4717B59}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{AF57DC65-FE10-4F0E-87EB-850082FEC2A5}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{B4B4EF0A-F441-4C4E-9B49-E8DF65F3DC53}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{B7035FE8-3D41-48BC-83DB-3069996FDF15}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{BA977534-1A57-46A1-9D5C-E8CAF28DA686}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzle chronicles\puzzlechronicles.exe |
"{BAE33E54-2BEA-4488-AE6A-9184671ACDB0}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{BCB23F56-6620-45C9-97B1-743DA0A787D2}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clpushupdateservice.exe |
"{BDEE44E1-CC0F-418D-BDE1-F2A29A22B66A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{BE958C74-7849-4FC8-955D-53C4840F85DE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzlequest2\puzzlequest2.exe |
"{C0BCE171-BA08-4A8A-9468-CECD02E07F30}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe |
"{C30E81C8-6756-4A8E-A10A-75D500F199C8}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{C39E0424-540B-45DB-9A3E-A8D23D3A7630}" = dir=in | app=c:\program files (x86)\microsoft lync\communicator.exe |
"{C6E9C062-FDE1-4E8F-B5E9-E60EDAB60356}" = dir=in | app=c:\program files (x86)\acer arcade live\acer dvdivine\acer dvdivine.exe |
"{C77AB154-B16F-4739-AB97-294A1E700D8E}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{CE2A96E7-0A4E-4840-987F-8AE7692D4E66}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{CF6AFB91-9BB1-40CD-951F-7334F89F92D9}" = protocol=6 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{D2B0635A-BF7B-4CCD-9FF4-33A786BF9772}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{D7929809-9DB7-4971-BE00-795D130BB3DA}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{DBBFBF7F-6998-4EE7-8B1C-5D4F1298ED14}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia\acer homemedia.exe |
"{E21B7CAE-632B-4891-B03B-7FEC13816437}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{E38229C0-4738-44C9-BC16-E3B2760638D3}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{E890FBFF-A9A1-41D1-B7F6-DF8CD784C568}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{F3315C0F-CCAA-4FE6-B1C1-D1FC8116906E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fitness dash\fitnessdash.exe |
"{F44E840B-CA0A-494D-974E-F88DC2AE18E8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F4E391D2-9AD6-4A86-B632-A7B3D4DB1868}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{F5431383-35A1-4C6F-BC45-4A7AEF330988}" = dir=in | app=c:\program files (x86)\microsoft lync\ucmapi.exe |
"{F736369E-A09E-4770-82FA-EE01A02543D4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\droplitz\cascade.exe |
"{FB3D19E9-958E-43D1-9E96-A676CE39491A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fitness dash\fitnessdash.exe |
"{FD2FA6DC-FA5E-4EC9-8311-481D5157822B}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clhomemediaserver.exe |
"{FE228B95-329B-46E8-950B-70EE4F5B549E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"TCP Query User{1FD7F4E9-C63D-4CFD-89DE-0279CE61ACBA}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"TCP Query User{236DB553-2209-4978-BD98-DDA820C234FE}C:\program files (x86)\oovoo\oovoo.exe" = protocol=6 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"TCP Query User{385704E7-8985-4F92-8901-C6FE813E201A}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{B504721D-C368-4CB9-90EB-852F3C2212B7}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"TCP Query User{CE3E5FCD-7C89-492C-9C89-CCA6312E7DED}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"TCP Query User{E6899A08-551C-4CBB-8A09-8514A08C1D03}C:\program files (x86)\logitech\vid hd\vid.exe" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"UDP Query User{534508C2-EC9A-4B83-BE0C-780DD08D8D53}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"UDP Query User{5B1C0B5B-B3D2-46B4-9AAF-F334DD805AAF}C:\program files (x86)\logitech\vid hd\vid.exe" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"UDP Query User{9A50E594-A30A-4554-9667-ADB34FA275F8}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"UDP Query User{BF90CEB4-CD3C-49C5-8BDE-10B1040E2383}C:\program files (x86)\oovoo\oovoo.exe" = protocol=17 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"UDP Query User{CCA1448D-D510-44CC-953D-484C5605B7F5}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"UDP Query User{E121835F-7ABC-45F8-84AE-DAC397530DEB}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{0370E621-61D1-4199-82AF-8F21851FD194}" = i_instrumentation [removed]
"{072F206C-2F30-48C9-8ED0-3CDF4F612CB1}" = ME_Kit_Files_x64
"{0C524D20-1409-0050-8A9E-0C4C490E4E54}" = Microsoft Dynamics CRM 2011 for Microsoft Office Outlook
"{0C524DC1-1409-0050-8121-88490F4D5549}" = Microsoft Dynamics CRM 2011 English (United States) Language Pack
"{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D666E21-2924-4B94-9A33-D6136761ACAB}" = Intel® Remote Wake Technology 1.0.296.0
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86416014FF}" = Java™ 6 Update 14 (64-bit)
"{273799F6-BC76-46F1-95E1-EF05322C3A5F}" = i_msm 1.0.312.0
"{2BE51F94-8ED9-4B31-898C-01BFA71CC1DC}" = i_swupdate [removed]
"{4975D666-729A-46A5-8C80-1F022AD43543}" = Livedrive
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{52A7026F-476C-4E3B-A4C7-8FF7DAD65FEB}" = i_redistributables 1.0.45
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{70E8EBD5-78C9-4258-B20A-5098CCA000F0}" = Dolby Control Center
"{81BE0B17-563B-45D4-B198-5721E6C665CD}" = Microsoft Lync 2010
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{868EA922-5675-4E91-BDA6-BBD0F923C5EF}" = HP Officejet Pro All-In-One Series
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUSR_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.PROPLUSR_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 306.97
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{E20B2752-0909-4B28-B8A9-A9BE519CA1A1}" = Microsoft Online Services Sign-in Assistant
"{F39076D7-7168-44CD-A2C6-EBC1CDA7DC1C}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft CRM Client" = Microsoft Dynamics CRM 2011 for Microsoft Office Outlook
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"WinRAR archiver" = WinRAR 4.01 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D2F6F25-394B-4ACA-BC9C-1394E963C620}" = Intel® Remote Wake Technology [removed]
"{12CAA28E-56CA-4C3D-B3F2-7311540DD410}" = TurboTax 2011
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{131B84C2-5435-4993-9888-6C62D9AC755E}" = CyberLink Live
"{132888AE-EF67-41C5-BCA2-7D5D2488AB63}" = Acer HomeMedia Connect
"{13D85C14-2B85-419F-AC41-C7F21E68B25D}" = Acer eSettings Management
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{24AE6B5B-3D5A-488C-9224-1BEE11F75DD9}" = TurboTax 2010
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java™ 6 Update 38
"{28DA3304-9EC2-4097-BC64-B59A1958841F}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{41581EF5-45A7-11DA-9D78-000129760D75}" = Acer SlideShow DVD
"{43D16DA8-BF42-3C62-89D3-3AD47829DC2E}" = Google Talk Plugin
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}" = BPDSoftware_Ini
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5AE12194-3EAA-40DF-B2BF-FE1D6B78BBF4}" = Nero Vision
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{63e01893-1aef-40c9-b436-5817c1394f52}" = Nero 9 Trial
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6ad7d061-da98-4a17-8960-1ba830ff4861}" = Nero 9
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71828142-5A24-4BD0-97E7-976DA08CE6CF}" = The Sims™ 3 High-End Loft Stuff
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110113233}" = Bookworm Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11029123}" = Bricks of Egypt
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110322783}" = Big Kahuna Reef
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110411970}" = Chuzzle
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111324990}" = Kick N Rush
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111543617}" = Backspin Billiards
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111692950}" = Mahjongg Artifacts
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}" = Mystery Solitaire - Secret Island
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111872660}" = Diner Dash Flo on the Go
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112310577}" = Flip Words 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112531267}" = Chicken Invaders 3
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113009953}" = Turbo Pizza
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113080210}" = Azada
"{83BEEFB4-8C28-4F4F-8A9D-E0D1ADCE335B}" = The Sims Medieval
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8868D822-2CBA-46B2-A286-B400B6185769}" = 7500_7600_7700_Help
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F1B6239-FEA0-450A-A950-B05276CE177C}" = Acer Empowering Technology
"{8F968232-15C6-4872-84C2-9FCDAA1AEAB6}" = MPM
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = The Sims™ 3 Ambitions
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A875B56-A35C-46BA-A3AA-DF8D03EE9F2F}" = Nero ControlCenter
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{9e9fdde6-2c26-492a-85a0-05646b3f2795}" = NeroLiveGadget
"{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A495D4DC-4036-4914-9CB2-0FCF6A3166EF}" = L7500
"{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA0D2D5F-612B-45D3-8759-DA87206E5CC9}" = QuickTax 2008
"{AA4BF92B-2AAF-11DA-9D78-000129760D75}" = Acer HomeMedia
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B145EC69-66F5-11D8-9D75-000129760D75}" = Acer DVDivine
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B580C409-E16F-44FF-904D-3AE94E113BE0}" = Acer HomeMedia Trial Creator
"{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = The Sims™ 3 World Adventures
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C19B3EB6-B54C-3204-A4DF-88432E0C79F7}" = Microsoft ReportViewer 2010 Redistributable
"{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C1}" = WinZip 15.0
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{DEB9AEF7-3ADA-40a9-9C98-546D54FE9CBD}" = ProductContext
"{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}" = Nero Live
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{ECB9C58E-C565-4683-9599-B72290BD3B25}" = QuickTax 2009
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}" = Acer Arcade Live Main Page
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f1861f30-3419-44db-b2a1-c274825698b3}" = Nero Disc Copy Gadget
"{F6EFFB76-4A07-11DA-9D78-000129760D75}" = Acer DV Magician
"{F79A208D-D929-11D9-9D77-000129760D75}" = Acer VideoMagician
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Acer Assist" = Acer Assist
"Acer GameZone Console_is1" = Acer GameZone Console DTV 2.0.1.1
"Acer Registration" = Acer Registration
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"BFG-Be a King - Golden Empire" = Be a King: Golden Empire
"BFG-Be Richest!" = Be Richest!
"BFG-Bistro Boulevard" = Bistro Boulevard
"BFG-Boutique Boulevard" = Boutique Boulevard
"BFG-Build-a-lot - Fairy Tales" = Build-a-lot: Fairy Tales
"BFG-Build-a-lot - On Vacation" = Build-a-lot: On Vacation
"BFG-Build-a-Lot 4 - Power Source" = Build-a-Lot 4: Power Source
"BFGC" = Big Fish Games: Game Manager
"BFG-Campgrounds" = Campgrounds
"BFG-Casino Chaos" = Casino Chaos
"BFG-Chloe's Dream Resort" = Chloe's Dream Resort
"BFG-Club Paradise" = Club Paradise
"BFG-Cooking Dash 3 - Thrills and Spills" = Cooking Dash 3: Thrills and Spills
"BFG-Dancing Craze" = Dancing Craze
"BFG-DinerTown - Detective Agency" = DinerTown: Detective Agency
"BFG-Dress Up Rush" = Dress Up Rush
"BFG-Farm Frenzy 3" = Farm Frenzy 3
"BFG-Fiona Finch and the Finest Flowers" = Fiona Finch and the Finest Flowers
"BFG-First Class Flurry" = First Class Flurry
"BFG-Grave Mania - Undead Fever" = Grave Mania: Undead Fever
"BFG-Hotel Dash 2 - Lost Luxuries" = Hotel Dash 2: Lost Luxuries
"BFG-Island Tribe 2" = Island Tribe 2
"BFG-Jet Set Go" = Jet Set Go
"BFG-Jo's Dream - Organic Coffee" = Jo's Dream: Organic Coffee
"BFG-Juliette's Fashion Empire" = Juliette's Fashion Empire
"BFG-Katy and Bob - Way Back Home" = Katy and Bob: Way Back Home
"BFG-My Farm Life" = My Farm Life
"BFG-Northern Tale" = Northern Tale
"BFG-Pet Rush - Arround the World" = Pet Rush: Arround the World
"BFG-Princess Isabella - A Witch's Curse" = Princess Isabella: A Witch's Curse
"BFG-Rescue Frenzy" = Rescue Frenzy
"BFG-Roads of Rome III" = Roads of Rome III
"BFG-Royal Envoy 2 Collector's Edition" = Royal Envoy 2 Collector's Edition
"BFG-Sally's Studio Collector's Edition" = Sally's Studio Collector's Edition
"BFG-Shop-n-Spree - Shopping Paradise" = Shop-n-Spree: Shopping Paradise
"BFG-Soap Opera Dash" = Soap Opera Dash
"BFG-Spa Mania 2" = Spa Mania 2
"BFG-The Timebuilders - Pyramid Rising" = The Timebuilders: Pyramid Rising
"BFG-Virtual City 2 - Paradise Resort" = Virtual City 2: Paradise Resort
"BFG-Wedding Dash 2 - Rings Around the World" = Wedding Dash 2: Rings Around the World
"BFG-Wedding Dash 4-Ever" = Wedding Dash 4-Ever
"BFG-Wedding Salon" = Wedding Salon
"BFG-Youda Jewel Shop" = Youda Jewel Shop
"Comical_is1" = Comical 0.8
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{131B84C2-5435-4993-9888-6C62D9AC755E}" = CyberLink Live
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"Kobo" = Kobo
"Logitech Vid" = Logitech Vid HD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mouse Setting Software_is1" = Mouse Setting Software 4.0
"Mozilla Firefox 15.0 (x86 en-US)" = Mozilla Firefox 15.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"Origin" = Origin
"Picasa 3" = Picasa 3
"Royal Envoy Collector's Edition" = Royal Envoy Collector's Edition
"Runic Games Torchlight" = Torchlight
"Steam App 19020" = Puzzle Chronicles
"Steam App 200710" = Torchlight II
"Steam App 23120" = Droplitz
"Steam App 3620" = Zuma's Revenge
"Steam App 37340" = Fitness Dash
"Steam App 41210" = Eufloria
"Steam App 47540" = Puzzle Quest 2
"Steam App 49000" = Hotel Dash
"Steam App 60340" = LUXOR: 5th Passage
"Steam App 70400" = Recettear: An Item Shop's Tale
"Strat-O-Matic CD-ROM Ver16.00H" = Strat-O-Matic CD-ROM Ver16.00H
"TeamViewer 8" = TeamViewer 8
"VLC media player" = VLC media player 2.0.5
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"YTdetect" = Yahoo! Detect
"Zynga Toolbar" = Zynga Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"GoToMeeting" = GoToMeeting 5.4.0.1060
"Mozilla Firefox 17.0.1 (x86 en-US)" = Mozilla Firefox 17.0.1 (x86 en-US)
"Oracle Live Help On Demand - Agent Console - NNA CLPOC ORILLIA Karri Tougas (105652707)" = Oracle Live Help On Demand - Agent Console - NNA CLPOC ORILLIA Karri Tougas (105652707)
"Sansa Updater" = Sansa Updater
"The Weather Network" = The Weather Network
"uTorrent" = µTorrent
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 03/01/2013 1:20:57 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 1:30:59 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 1:35:59 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 1:46:01 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 1:51:01 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 2:01:02 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 2:16:06 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 2:21:06 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 2:36:09 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 2:42:14 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5981
Description = An error occurred retrieving data from the Microsoft CRM server for
processing pending Microsoft CRM e-mail messages. Verify that the current user
has appropriate permissions and server connectivity and try the action again. HR=0x80131501.
Context=. Function=CEmailBackgroundSend::Run. Line=332.
[ System Events ]
Error - 30/12/2012 12:41:35 PM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 30/12/2012 12:41:35 PM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 31/12/2012 8:34:34 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 31/12/2012 8:34:34 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 01/01/2013 11:40:16 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 01/01/2013 11:40:16 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 02/01/2013 9:12:52 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 02/01/2013 9:12:53 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 03/01/2013 9:14:00 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 03/01/2013 9:14:00 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
< End of report >
Computer #1 is my most important computer as I work from home and need it for that. I will start with it.
OTL logfile created on: 03/01/2013 3:28:49 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karri\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
7.93 Gb Total Physical Memory | 2.99 Gb Available Physical Memory | 37.72% Memory free
16.07 Gb Paging File | 8.76 Gb Available in Paging File | 54.51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.59 Gb Total Space | 70.86 Gb Free Space | 30.47% Space Free | Partition Type: NTFS
Drive D: | 348.93 Gb Total Space | 92.10 Gb Free Space | 26.40% Space Free | Partition Type: NTFS
Drive J: | 295.02 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive N: | 3.79 Gb Total Space | 3.79 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive O: | 930.95 Gb Total Space | 813.57 Gb Free Space | 87.39% Space Free | Partition Type: FAT32
Computer Name: KARRI-PC | User Name: Karri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/01/03 15:28:41 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karri\Desktop\OTL.exe
PRC - [2012/12/20 13:13:01 | 000,541,760 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe
PRC - [2012/12/14 04:17:04 | 003,467,768 | —- | M] (TeamViewer GmbH) – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
PRC - [2012/12/14 04:17:03 | 009,876,472 | —- | M] (TeamViewer GmbH) – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
PRC - [2012/12/14 04:08:24 | 000,190,968 | —- | M] (TeamViewer GmbH) – C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe
PRC - [2012/12/04 07:57:14 | 001,354,736 | —- | M] (Valve Corporation) – C:\Program Files (x86)\Steam\Steam.exe
PRC - [2012/11/28 15:17:53 | 000,040,376 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Program Files (x86)\Citrix\GoToMeeting\1060\g2mstart.exe
PRC - [2012/11/28 15:17:53 | 000,040,376 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Program Files (x86)\Citrix\GoToMeeting\1060\g2mlauncher.exe
PRC - [2012/11/28 15:17:53 | 000,040,376 | —- | M] (Citrix Online, a division of Citrix Systems, Inc.) – C:\Program Files (x86)\Citrix\GoToMeeting\1060\g2mcomm.exe
PRC - [2012/11/14 13:45:40 | 001,831,936 | —- | M] (Livedrive Internet Ltd) – C:\Program Files (x86)\Livedrive\Livedrive.exe
PRC - [2012/10/26 12:17:52 | 000,079,384 | —- | M] (Google) – C:\Users\Karri\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
PRC - [2012/10/10 21:23:42 | 001,258,856 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2012/10/04 12:47:20 | 027,112,568 | —- | M] (ooVoo LLC) – C:\Program Files (x86)\ooVoo\ooVoo.exe
PRC - [2012/10/02 13:15:38 | 000,382,824 | —- | M] (NVIDIA Corporation) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2012/09/28 20:44:54 | 012,105,344 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Microsoft Lync\communicator.exe
PRC - [2012/08/30 15:16:16 | 000,310,920 | —- | M] (Pelmorex Media Inc.) – C:\Users\Karri\AppData\Local\The Weather Network\weathereye.exe
PRC - [2012/08/08 14:18:52 | 000,348,664 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe
PRC - [2012/07/27 15:51:28 | 001,498,552 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AcroRd32.exe
PRC - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/17 17:45:12 | 000,079,872 | —- | M] (SanDisk Corporation) – C:\Users\Karri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe
PRC - [2012/05/02 00:42:31 | 000,086,224 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe
PRC - [2012/05/01 23:34:37 | 000,110,032 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe
PRC - [2011/08/19 04:26:50 | 000,450,848 | —- | M] (Logitech Inc.) – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe
PRC - [2011/08/12 12:18:42 | 000,205,336 | —- | M] (Logitech Inc.) – C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe
PRC - [2011/02/09 14:00:00 | 000,610,120 | R— | M] (WinZip Computing, S.L.) – C:\Program Files (x86)\WinZip\WZQKPICK.EXE
PRC - [2010/10/29 15:06:08 | 005,915,480 | —- | M] (Logitech Inc.) – C:\Program Files (x86)\Logitech\Vid HD\Vid.exe
PRC - [2009/05/15 06:35:52 | 000,935,208 | —- | M] (Nero AG) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2009/04/23 08:51:38 | 000,691,656 | —- | M] (DT Soft Ltd) – C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe
PRC - [2008/09/11 15:19:28 | 000,105,504 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdateService.exe
PRC - [2008/09/11 15:19:26 | 000,068,640 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdate.exe
PRC - [2008/09/11 15:19:14 | 000,179,232 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaMonitorService.exe
PRC - [2008/09/11 15:19:12 | 000,322,592 | —- | M] (CyberLink Corp.) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaService.exe
PRC - [2008/08/01 14:30:28 | 000,501,760 | —- | M] () – C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe
PRC - [2008/07/29 16:53:00 | 000,500,784 | —- | M] (Egis Incorporated) – C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe
PRC - [2008/07/29 16:52:56 | 000,454,704 | —- | M] (Egis inc.) – C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe
PRC - [2008/07/20 16:45:06 | 000,354,840 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe
PRC - [2008/07/20 16:45:06 | 000,182,808 | —- | M] (Intel Corporation) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe
PRC - [2008/06/23 12:12:52 | 000,174,616 | —- | M] (Intel Corporation) – C:\Program Files\Intel\AMT\LMS.exe
PRC - [2008/05/20 16:50:50 | 000,269,448 | —- | M] (CyberLink) – C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe
========== Modules (No Company Name) ==========
MOD - [2012/12/20 13:13:10 | 000,647,168 | —- | M] () – C:\Program Files (x86)\Steam\sdl.dll
MOD - [2012/12/20 13:13:00 | 020,320,240 | —- | M] () – C:\Program Files (x86)\Steam\bin\libcef.dll
MOD - [2012/12/20 13:12:58 | 000,969,280 | —- | M] () – C:\Program Files (x86)\Steam\bin\chromehtml.dll
MOD - [2012/12/20 13:12:56 | 000,124,416 | —- | M] () – C:\Program Files (x86)\Steam\bin\avutil-51.dll
MOD - [2012/12/20 13:12:54 | 000,192,000 | —- | M] () – C:\Program Files (x86)\Steam\bin\avformat-53.dll
MOD - [2012/12/20 13:12:52 | 001,100,800 | —- | M] () – C:\Program Files (x86)\Steam\bin\avcodec-53.dll
MOD - [2012/12/04 20:15:15 | 012,456,040 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\PepperFlash\pepflashplayer.dll
MOD - [2012/12/04 20:15:15 | 000,460,904 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppgooglenaclpluginchrome.dll
MOD - [2012/12/04 20:15:14 | 004,008,040 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
MOD - [2012/12/04 20:14:29 | 000,587,880 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\libglesv2.dll
MOD - [2012/12/04 20:14:28 | 000,124,520 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\libegl.dll
MOD - [2012/12/04 20:14:21 | 000,157,304 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\avutil-51.dll
MOD - [2012/12/04 20:14:20 | 000,275,576 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\avformat-54.dll
MOD - [2012/12/04 20:14:19 | 002,168,952 | —- | M] () – C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\avcodec-54.dll
MOD - [2012/11/21 11:19:12 | 000,059,392 | —- | M] () – C:\Users\Karri\AppData\Local\Temp\{1d478740-1c26-43ed-9b9e-2f8938b03192}\Livedrive.Native.dll
MOD - [2012/11/18 09:00:54 | 000,998,400 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Management\d08cb6b1c4052e6f5a4e2452870d67d7\System.Management.ni.dll
MOD - [2012/11/18 09:00:04 | 001,840,640 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\7844c1ae91c8f584025756ad72e65176\System.Web.Services.ni.dll
MOD - [2012/11/18 08:59:55 | 001,116,672 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.DirectorySer#\6082261ca7c89e5c073a073fdd851572\System.DirectoryServices.ni.dll
MOD - [2012/11/18 08:59:55 | 000,627,200 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\850a371af19c00078a8cfbee763fb449\System.Transactions.ni.dll
MOD - [2012/11/18 08:59:54 | 000,627,712 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\1f0ff07c7fa3ef235a9e2b3b6a49db04\System.EnterpriseServices.ni.dll
MOD - [2012/11/18 08:59:50 | 000,971,264 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\7f15d0cb7e4f87f86e425d5ffe7e8280\System.Configuration.ni.dll
MOD - [2012/11/18 08:46:58 | 005,450,752 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\741164a3e36f879b9f9e3ff176465127\System.Xml.ni.dll
MOD - [2012/11/18 08:46:46 | 012,433,920 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\22e554f2c4da53c07e4815a24e2d50e2\System.Windows.Forms.ni.dll
MOD - [2012/11/18 08:46:38 | 001,592,320 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\2c6cd37f29fc76d6c2ed6bbed202d82c\System.Drawing.ni.dll
MOD - [2012/11/18 08:46:26 | 006,621,696 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Data\ee724aeea5f1b9d8a01fa6047fd2ef99\System.Data.ni.dll
MOD - [2012/11/18 08:45:49 | 007,976,960 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\System\b2052acbbbba4f98585196872195e009\System.ni.dll
MOD - [2012/11/18 08:45:43 | 011,492,352 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7ad9c44df3b85848590e63f13fc59804\mscorlib.ni.dll
MOD - [2012/11/14 13:43:48 | 000,781,312 | —- | M] () – C:\Program Files (x86)\Livedrive\Livedrive.Localisation.dll
MOD - [2012/07/27 15:51:28 | 000,249,272 | —- | M] () – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\sqlite.dll
MOD - [2011/09/27 06:23:00 | 000,087,912 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 06:22:40 | 001,242,472 | —- | M] () – C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/08/19 04:26:16 | 000,183,320 | —- | M] () – C:\Program Files (x86)\Common Files\LogiShrd\SharedBin\LvApi11.dll
MOD - [2011/08/12 12:18:56 | 000,342,552 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll
MOD - [2011/08/12 12:18:56 | 000,128,536 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll
MOD - [2011/08/12 12:18:56 | 000,029,208 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll
MOD - [2011/08/12 12:18:54 | 007,956,504 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll
MOD - [2011/08/12 12:18:54 | 002,145,304 | —- | M] () – C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll
MOD - [2011/07/28 15:20:34 | 000,270,336 | —- | M] () – C:\Program Files (x86)\Livedrive\AlphaFS.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | —- | M] () – C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/29 15:02:38 | 000,751,616 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\vpxmd.dll
MOD - [2010/10/29 15:01:30 | 000,027,472 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\SDL.dll
MOD - [2010/10/20 15:45:26 | 008,801,120 | —- | M] () – C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
MOD - [2009/04/22 16:53:56 | 000,969,040 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtNetwork4.dll
MOD - [2009/04/09 18:04:56 | 002,141,008 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtCore4.dll
MOD - [2009/03/29 23:42:19 | 000,261,632 | —- | M] () – C:\Windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009/03/29 23:42:17 | 002,933,760 | —- | M] () – C:\Windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2009/03/03 17:18:08 | 000,138,064 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qjpeg4.dll
MOD - [2009/03/03 17:18:06 | 000,035,152 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qico4.dll
MOD - [2009/03/03 17:18:06 | 000,029,008 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qgif4.dll
MOD - [2009/03/03 17:17:46 | 011,311,952 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtWebKit4.dll
MOD - [2009/03/03 17:17:46 | 000,363,856 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtXml4.dll
MOD - [2009/03/03 17:17:44 | 000,200,016 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtSql4.dll
MOD - [2009/03/03 17:17:40 | 000,475,472 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtOpenGL4.dll
MOD - [2009/03/03 17:17:38 | 007,704,400 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\QtGui4.dll
MOD - [2009/03/03 17:17:32 | 000,291,664 | —- | M] () – C:\Program Files (x86)\Logitech\Vid HD\phonon4.dll
MOD - [2008/08/01 14:30:28 | 000,501,760 | —- | M] () – C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe
MOD - [2008/04/28 08:49:18 | 000,002,560 | —- | M] () – C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTrayLOC.dll
MOD - [2007/07/11 12:27:24 | 000,400,896 | —- | M] () – C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQDEVCL.dll
MOD - [2007/06/24 15:14:52 | 000,029,696 | —- | M] () – C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMDLL.DLL
========== Services (SafeList) ==========
SRV:64bit: - [2012/10/14 23:20:08 | 000,026,760 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Microsoft Dynamics CRM\Client\bin\CrmSqlStartupSvc.exe – (CrmSqlStartupSvc)
SRV:64bit: - [2010/02/02 18:03:04 | 000,015,768 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe – (c2wts)
SRV:64bit: - [2008/07/16 12:50:24 | 002,476,432 | —- | M] (Intel® Corporation) [Auto | Running] – C:\Program Files\Intel\inteldh\msm\MSM.exe – (ME Services Manager)
SRV:64bit: - [2008/07/16 12:44:02 | 000,068,496 | —- | M] (Intel® Corporation) [Auto | Running] – C:\Program Files\Intel\inteldh\common\IntelDHSvcMgr.exe – (Software Services Manager)
SRV:64bit: - [2008/06/23 12:12:52 | 000,174,616 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files\Intel\AMT\LMS.exe – (LMS)
SRV:64bit: - [2008/06/02 08:25:40 | 000,024,576 | —- | M] () [Auto | Running] – C:\Program Files\Acer\Empowering Technology\Service\ETService.exe – (ETService)
SRV:64bit: - [2008/01/20 21:47:32 | 000,383,544 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2012/12/20 13:13:01 | 000,541,760 | —- | M] (Valve Corporation) [On_Demand | Running] – C:\Program Files (x86)\Common Files\Steam\SteamService.exe – (Steam Client Service)
SRV - [2012/12/19 08:28:50 | 000,250,808 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2012/12/14 04:17:04 | 003,467,768 | —- | M] (TeamViewer GmbH) [Auto | Running] – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe – (TeamViewer8)
SRV - [2012/12/05 16:29:30 | 000,115,168 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2012/11/14 13:48:28 | 000,210,144 | —- | M] () [Auto | Running] – C:\Program Files (x86)\Livedrive\VSSService.exe – (LivedriveVSSService)
SRV - [2012/10/10 21:23:42 | 001,258,856 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe – (nvUpdatusService)
SRV - [2012/10/02 13:15:38 | 000,382,824 | —- | M] (NVIDIA Corporation) [Auto | Running] – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe – (Stereo Service)
SRV - [2012/07/27 15:51:26 | 000,063,960 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/07/13 12:28:36 | 000,160,944 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/05/02 00:42:31 | 000,086,224 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe – (AntiVirSchedulerService)
SRV - [2012/05/01 23:34:37 | 000,110,032 | —- | M] (Avira Operations GmbH & Co. KG) [Auto | Running] – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe – (AntiVirService)
SRV - [2011/08/19 04:26:50 | 000,450,848 | —- | M] (Logitech Inc.) [Auto | Running] – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe – (UMVPFSrv)
SRV - [2010/03/18 12:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2009/05/15 06:35:52 | 000,935,208 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0)
SRV - [2009/03/29 23:42:14 | 000,066,368 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2008/09/11 15:19:28 | 000,105,504 | —- | M] (CyberLink) [Auto | Running] – C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdateService.exe – (CyberLink Live Push Update Service)
SRV - [2008/09/11 15:19:14 | 000,179,232 | —- | M] (CyberLink) [Auto | Running] – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaMonitorService.exe – (CyberLink Live Monitor Service)
SRV - [2008/09/11 15:19:12 | 000,322,592 | —- | M] (CyberLink Corp.) [Auto | Running] – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaService.exe – (CyberLink Live Service)
SRV - [2008/07/29 16:53:00 | 000,500,784 | —- | M] (Egis Incorporated) [Auto | Running] – C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe – (eDataSecurity Service)
SRV - [2008/07/20 16:45:06 | 000,354,840 | —- | M] (Intel Corporation) [Auto | Running] – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe – (IAANTMON)
SRV - [2008/05/20 16:50:50 | 000,269,448 | —- | M] (CyberLink) [Auto | Running] – C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe – (Acer HomeMedia Connect Service)
========== Driver Services (SafeList) ==========
DRV:64bit: - [2012/11/10 10:50:36 | 000,352,008 | —- | M] (EldoS Corporation) [Kernel | System | Running] – C:\Windows\SysNative\drivers\cbfs3.sys – (cbfs3)
DRV:64bit: - [2012/08/21 12:01:20 | 000,033,240 | —- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys – (GEARAspiWDM)
DRV:64bit: - [2012/07/09 12:42:54 | 000,052,736 | —- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\Drivers\usbaapl64.sys – (USBAAPL64)
DRV:64bit: - [2012/05/02 14:24:12 | 000,027,760 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\Windows\SysNative\DRIVERS\avkmgr.sys – (avkmgr)
DRV:64bit: - [2012/04/27 09:20:04 | 000,132,832 | —- | M] (Avira GmbH) [Kernel | System | Running] – C:\Windows\SysNative\DRIVERS\avipbb.sys – (avipbb)
DRV:64bit: - [2012/04/24 23:32:27 | 000,098,848 | —- | M] (Avira GmbH) [File_System | Auto | Running] – C:\Windows\SysNative\DRIVERS\avgntflt.sys – (avgntflt)
DRV:64bit: - [2012/02/29 08:52:46 | 000,016,384 | —- | M] (Microsoft Corporation) [Recognizer | System | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/08/19 04:27:30 | 004,869,024 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\lvuvc64.sys – (LVUVC64)
DRV:64bit: - [2011/08/19 04:27:30 | 000,351,136 | —- | M] (Logitech Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\lvrs64.sys – (LVRS64)
DRV:64bit: - [2009/11/20 14:26:50 | 000,031,232 | —- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\tap0901.sys – (tap0901)
DRV:64bit: - [2009/09/30 19:51:42 | 000,046,592 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\wpdusb.sys – (WpdUsb)
DRV:64bit: - [2009/08/06 11:52:34 | 000,871,408 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\Drivers\sptd.sys – (sptd)
DRV:64bit: - [2009/05/09 00:14:20 | 000,015,752 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\NuidFltr.sys – (NuidFltr)
DRV:64bit: - [2008/08/13 21:18:54 | 008,029,792 | —- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\DRIVERS\igdkmd64.sys – (igfx)
DRV:64bit: - [2008/07/29 16:53:50 | 000,060,976 | —- | M] (Egis Incorporated) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\PSDVdisk.sys – (psdvdisk)
DRV:64bit: - [2008/07/29 16:53:50 | 000,021,040 | —- | M] (Egis Incorporated) [Kernel | Auto | Running] – C:\Windows\SysNative\DRIVERS\PSDNServ.sys – (PSDNServ)
DRV:64bit: - [2008/07/29 16:53:48 | 000,022,064 | —- | M] (Egis Incorporated) [File_System | Boot | Running] – C:\Windows\SysNative\DRIVERS\psdfilter.sys – (PSDFilter)
DRV:64bit: - [2008/07/25 04:26:20 | 000,315,008 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\e1y60x64.sys – (e1yexpress)
DRV:64bit: - [2008/07/20 04:44:54 | 000,402,456 | —- | M] (Intel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\DRIVERS\iaStor.sys – (iaStor)
DRV:64bit: - [2008/07/14 19:20:42 | 000,126,464 | —- | M] (Intel® Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\IntcHdmi.sys – (IntcHdmiAddService)
DRV:64bit: - [2008/03/28 11:42:58 | 000,056,344 | —- | M] (Intel Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\DRIVERS\HECIx64.sys – (HECIx64)
DRV:64bit: - [2008/01/30 19:48:32 | 000,016,384 | —- | M] (NewTech Infosystems, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\Drivers\NTIDrvr.sys – (NTIDrvr)
DRV:64bit: - [2008/01/30 19:48:16 | 000,016,384 | —- | M] (NewTech Infosystems Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\UBHelper.sys – (UBHelper)
DRV - [2008/06/02 08:20:12 | 000,017,952 | —- | M] (Acer, Inc.) [Kernel | Auto | Running] – C:\Windows\SysWOW64\drivers\int15_64.sys – (int15)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACAW
IE - HKLM\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://global.acer.com/ [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
IE - HKCU\..\URLSearchHook: CFBFAE00-17A6-11D0-99CB-00C04FD64497} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACAW
IE - HKCU\..\SearchScopes\{AD22EBAF-0D18-4fc7-90CC-5EA0ABBE9EB8}: "URL" = http://www.daemon-search.com/search/web?q={searchTerms}
IE - HKCU\..\SearchScopes\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}: "URL" = http://us.yhs.search.yahoo.com/avg/search?…p={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF - prefs.js..browser.startup.homepage: "http://www.theweathernetwork.com/weather/caon0532"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:17.0.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - user.js - File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_5_502_135.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_5_502_135.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=1.6.0_38: C:\Windows\SysWOW64\npdeployJava1.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\Karri\AppData\Local\Citrix\Plugins\79\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Karri\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Karri\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/05 16:29:30 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 15.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/12/05 16:29:26 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/12/05 16:29:30 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 17.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2012/12/05 16:29:26 | 000,000,000 | —D | M]
[2009/10/29 12:03:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Karri\AppData\Roaming\Mozilla\Extensions
[2009/10/29 12:03:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Karri\AppData\Roaming\Mozilla\Extensions\[removed]
[2012/10/26 01:50:20 | 000,000,000 | —D | M] (No name found) – C:\Users\Karri\AppData\Roaming\Mozilla\Firefox\Profiles\3rkyge3u.default\extensions
[2011/10/15 13:35:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Karri\AppData\Roaming\Mozilla\Firefox\Profiles\3rkyge3u.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2009/08/06 11:56:41 | 000,002,399 | —- | M] () – C:\Users\Karri\AppData\Roaming\Mozilla\Firefox\Profiles\3rkyge3u.default\searchplugins\daemon-search.xml
[2012/12/28 23:43:40 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2012/12/05 16:29:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2012/12/05 16:29:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2012/12/05 16:29:26 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2012/12/28 23:43:40 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA}
[2012/12/05 16:29:30 | 000,262,112 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2012/09/28 20:39:06 | 000,031,872 | —- | M] () – C:\Program Files (x86)\mozilla firefox\plugins\npMeetingJoinPluginOC.dll
[2012/09/24 16:21:50 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2012/12/05 16:29:29 | 000,002,058 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - homepage: http://www.theweathernetwork.com/weather/caon0532
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}sourceid=chrome&ie;={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl;={language}&q;={searchTerms}&sugkey;={google:suggestAPIKeyParameter}
CHR - homepage: http://www.theweathernetwork.com/weather/caon0532
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\pdf.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Karri\AppData\Local\Google\Chrome\Application\23.0.1271.97\gcswf32.dll
CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 8.0\Reader\Browser\nppdf32.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: 2007 Microsoft Office system (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\NPOFF12.DLL
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.1 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll
CHR - plugin: DivX VOD Helper Plug-in (Enabled) = C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
CHR - plugin: DivX Web Player (Enabled) = C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Java™ Platform SE 6 U32 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 6.0.320.5 (Enabled) = C:\Windows\SysWOW64\npdeployJava1.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Karri\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - Extension: Entanglement = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: AT_JamesWhite = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm\3\
CHR - Extension: AdBlock = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.54_0\
CHR - Extension: Poppit = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
O1 HOSTS File: ([2013/01/03 08:12:30 | 000,000,761 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll (Egis)
O2:64bit: - BHO: (BrowserHelper Class) - {EDF48A39-1442-463F-9F4E-F376A78D034A} - C:\Program Files (x86)\Livedrive\LivedriveExplorerExtensions.dll (Livedrive Internet Ltd)
O2 - BHO: (Lync Browser Helper) - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre6\bin\ssv.dll (Sun Microsystems, Inc.)
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
O3:64bit: - HKLM\..\Toolbar: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
O3:64bit: - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (DAEMON Tools Toolbar) - {32099AAC-C132-4136-9E9A-4E364A424E17} - C:\Program Files (x86)\DAEMON Tools Toolbar\DTToolbar64.dll File not found
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files (x86)\Zynga\tbZyn0.dll (Conduit Ltd.)
O4:64bit: - HKLM..\Run: [Acer Empowering Technology Monitor] C:\Program Files\Acer\Empowering Technology\SysMonitor.exe ()
O4:64bit: - HKLM..\Run: [eDataSecurity Loader] C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe (Egis Incorporated)
O4:64bit: - HKLM..\Run: [EmpoweringTechnology] C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe boot File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelSWUpdateClient] C:\Program Files\Intel\inteldh\common\SWUpdateClient.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files (x86)\Acer\Acer Assist\launcher.exe ()
O4 - HKLM..\Run: [Acer Product Registration] C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe (Leader Technologies)
O4 - HKLM..\Run: [ACQTMOUSE] C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CLPushUpdate] C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdate.exe (CyberLink)
O4 - HKLM..\Run: [Communicator] C:\Program Files (x86)\Microsoft Lync\communicator.exe (Microsoft Corporation)
O4 - HKLM..\Run: [DivXMediaServer] "C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe" File not found
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [PCMMediaSharing] C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe ()
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EA Core] "C:\Program Files (x86)\Electronic Arts\EADM\Core.exe" -silent File not found
O4 - HKCU..\Run: [EADM] C:\Program Files (x86)\Origin\Origin.exe (Electronic Arts)
O4 - HKCU..\Run: [GoToMeeting] C:\Program Files (x86)\Citrix\GoToMeeting\1060\g2mstart.exe (Citrix Online, a division of Citrix Systems, Inc.)
O4 - HKCU..\Run: [Livedrive] C:\Program Files (x86)\Livedrive\Livedrive.exe (Livedrive Internet Ltd)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [ooVoo.exe] C:\Program Files (x86)\ooVoo\oovoo.exe (ooVoo LLC)
O4 - HKCU..\Run: [SansaDispatch] C:\Users\Karri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [WeatherEye] C:\Users\Karri\AppData\Local\The Weather Network\weathereye.exe (Pelmorex Media Inc.)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - HKCU..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9 - Extra Button: Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : Lync add-on - {31D09BA0-12F5-4CCE-BE8A-2923E76605DA} - C:\Program Files (x86)\Microsoft Lync\OCHelper.dll (Microsoft Corporation)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: aboriginallink.ca ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: aboriginallink.com ([]http in Trusted sites)
O15 - HKCU\..Trusted Domains: dynamics.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: live.com ([]* in Trusted sites)
O15 - HKCU\..Trusted Domains: microsoftonline.com ([portal] https in Trusted sites)
O15 - HKCU\..Trusted Domains: outlook.com ([]http in Trusted sites)
O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-0016-0000-0014-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_14)
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} http://www.shockwave.com/content/trijinx/s…nx.1.0.0.86.cab (CPlayFirstTriJinxControl Object)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O16 - DPF: {CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-…indows-i586.cab (Java Plug-in 1.6.0_38)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3DF7249C-DC40-4434-8123-8375B94A51F0}: DhcpNameServer = 192.168.0.1
O18:64bit: - Protocol\Handler\intu-qt2008 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-qt2009 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-tt2010 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-tt2011 - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18 - Protocol\Handler\intu-qt2008 {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files (x86)\QuickTax 2008\ic2008pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files (x86)\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files (x86)\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2011 {B3B5DAD9-E96D-45b4-B636-B6CF2F773DE1} - C:\Program Files (x86)\TurboTax 2011\ic2011pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysNative\CbFsMntNtf3.dll (EldoS Corporation)
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O22:64bit: - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\Windows\SysNative\CbFsMntNtf3.dll (EldoS Corporation)
O22 - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img16.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img16.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/24 10:26:00 | 000,000,740 | R— | M] () - J:\autorun.inf – [ UDF ]
O32 - Unable to obtain root file information for disk N:\
O32 - Unable to obtain root file information for disk O:\
O33 - MountPoints2\{a4b61a9e-df1e-11e1-aff1-00219761ce94}\Shell\AutoRun\command - "" = J:\fscommand\LS_Start_Launch.exe – [2010/05/10 13:00:11 | 000,151,040 | R— | M] ()
O33 - MountPoints2\{a4b61a9e-df1e-11e1-aff1-00219761ce94}\Shell\Launcher\command - "" = J:\Get_Started_with_LifeStudio.exe – [2010/05/10 13:00:13 | 003,478,888 | R— | M] (Adobe Systems, Inc.)
O33 - MountPoints2\{a4b61b3b-df1e-11e1-aff1-00219761ce94}\Shell\AutoRun\command - "" = N:\fscommand\LS_Start_Launch.exe
O33 - MountPoints2\{a4b61b3b-df1e-11e1-aff1-00219761ce94}\Shell\Launcher\command - "" = N:\Get_Started_with_LifeStudio.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
========== Files/Folders - Created Within 30 Days ==========
[2013/01/03 15:28:39 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Karri\Desktop\OTL.exe
[2013/01/03 08:16:20 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{3858D4CE-7BC8-4FE8-9F1E-F3F94A633EFD}
[2013/01/02 15:49:38 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\ooVoo Details
[2013/01/02 15:49:31 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ooVoo
[2013/01/02 15:49:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\ooVoo
[2013/01/02 15:39:54 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2013/01/02 15:39:53 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2013/01/02 15:25:53 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Yahoo!
[2013/01/02 15:17:26 | 000,000,000 | —D | C] – C:\Program Files (x86)\Yahoo!
[2013/01/02 15:16:04 | 000,439,704 | —- | C] (Yahoo! Inc.) – C:\Users\Karri\Desktop\msgr11us.exe
[2013/01/02 09:23:29 | 015,271,824 | —- | C] (Google Inc.) – C:\Users\Karri\Desktop\picasa39-setup.exe
[2013/01/02 08:12:35 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{10BF1A49-4693-4220-A360-114CA5DDC371}
[2013/01/01 10:41:28 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{86E62FE5-66DA-4681-AE2C-76E89E9BC9DD}
[2012/12/31 07:33:55 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{87035D76-36ED-4720-BF9B-830C39E20E79}
[2012/12/30 11:42:34 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{91A02224-9FFD-4884-8A5A-7F1D116DD04D}
[2012/12/28 23:43:35 | 000,157,680 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaws.exe
[2012/12/28 23:43:35 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\javaw.exe
[2012/12/28 23:43:35 | 000,149,488 | —- | C] (Sun Microsystems, Inc.) – C:\Windows\SysWow64\java.exe
[2012/12/28 18:58:45 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{184713FA-E986-4774-94A8-A2A93B6AD872}
[2012/12/23 09:17:29 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{0CB37340-0337-46FF-802E-71CB478313AD}
[2012/12/21 23:44:49 | 000,368,128 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2012/12/21 23:44:49 | 000,293,376 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2012/12/21 23:44:49 | 000,048,128 | —- | C] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2012/12/21 23:44:49 | 000,034,304 | —- | C] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2012/12/21 08:52:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/12/21 07:38:56 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{3FBDA6A9-2EFD-4BDB-A67E-2F015241502F}
[2012/12/20 08:04:19 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{A92265B7-2452-434A-9E9C-3A6977E6589B}
[2012/12/19 15:46:48 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2012/12/19 15:46:26 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2012/12/19 15:46:24 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2012/12/19 15:46:24 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2012/12/19 07:57:25 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{7AF64024-6B51-43B7-B313-07638ED02640}
[2012/12/14 13:18:51 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Regina Qu'Appelle Health Region
[2012/12/14 12:52:10 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Porcupine Health Unit
[2012/12/14 12:45:41 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Ontario Hospital Association
[2012/12/14 08:42:45 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\The Weather Network
[2012/12/14 08:42:41 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\The Weather Network
[2012/12/14 08:40:20 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{7069D2AB-F115-4928-B074-71ACB02FC834}
[2012/12/14 08:17:15 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\NVIDIA
[2012/12/13 15:04:37 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Timmins and District Hospital
[2012/12/13 14:59:30 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\North Bay Regional Health Centre
[2012/12/13 08:15:05 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{AF641A64-E0DF-4E17-92D3-BF9AC3E13389}
[2012/12/12 21:10:05 | 000,054,376 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdfLdr.sys
[2012/12/12 21:10:05 | 000,009,728 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Wdfres.dll
[2012/12/12 21:10:03 | 000,194,048 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFPlatform.dll
[2012/12/12 21:10:03 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winusb.dll
[2012/12/12 21:10:02 | 000,744,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFx.dll
[2012/12/12 21:10:02 | 000,229,888 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFHost.exe
[2012/12/12 21:10:02 | 000,045,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUDFCoinstaller.dll
[2012/12/12 21:09:16 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2012/12/12 21:09:16 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2012/12/12 21:09:16 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2012/12/12 21:09:15 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2012/12/12 21:09:15 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2012/12/12 21:09:15 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2012/12/12 21:09:15 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2012/12/12 21:09:15 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2012/12/12 21:09:15 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2012/12/12 21:09:14 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2012/12/12 21:09:14 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2012/12/12 21:09:14 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2012/12/12 21:09:13 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2012/12/12 21:09:13 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2012/12/12 21:09:13 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2012/12/12 16:03:15 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Atlantic Aboriginal health Research Program
[2012/12/12 14:18:55 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Health Sciences North - Sudbury
[2012/12/12 14:16:52 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Patient Voices Network
[2012/12/12 04:19:36 | 001,210,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2012/12/12 04:19:29 | 000,477,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnet.dll
[2012/12/12 04:19:29 | 000,376,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnet.dll
[2012/12/12 04:19:29 | 000,068,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnathlp.dll
[2012/12/12 04:19:29 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dpnsvr.exe
[2012/12/12 04:19:29 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dpnsvr.exe
[2012/12/11 21:17:55 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{A122EF8E-C279-47A0-BF6B-64C219125E8A}
[2012/12/11 13:56:12 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Citrix
[2012/12/11 13:31:44 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Dilico
[2012/12/11 13:26:33 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\St. Joseph's Care Group
[2012/12/11 13:23:55 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Thunder Bay Community Economic Development Commission
[2012/12/11 13:14:39 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Confederation College
[2012/12/11 08:03:42 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{0CD10092-4D8A-4B3A-8161-1F0997E76605}
[2012/12/10 16:13:05 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Victoria General Hospital
[2012/12/10 15:54:56 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Concordia Hospital
[2012/12/10 15:28:35 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Seven Oaks General Hospital
[2012/12/10 15:15:41 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Norwest Community Health Centres
[2012/12/10 14:38:54 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\LogMeIn Rescue Applet
[2012/12/10 13:20:27 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Sault Area Hospital
[2012/12/10 13:10:20 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Thunder Bay Regional Health Sciences Centre
[2012/12/10 12:56:56 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Health Sciences Centre Winnipeg
[2012/12/10 07:55:58 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{A4C7EEF5-843F-4720-BD17-CDD942FA9120}
[2012/12/09 13:18:37 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{57AECE94-BF36-4E90-B2D7-1A5F166C5616}
[2012/12/07 09:58:45 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Northern Ontario School of Medicine (NOSM)
[2012/12/07 09:40:22 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Couchiching Family Health Team
[2012/12/07 08:10:59 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{1B7C379E-2F27-4C8B-9C7D-26384FDECA9E}
[2012/12/06 07:31:52 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{B4D454D9-8266-474A-B661-688CEE1665A5}
[2012/12/05 16:29:25 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2012/12/05 11:00:52 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Northern Health
[2012/12/05 11:00:35 | 000,000,000 | —D | C] – C:\Users\Karri\Desktop\Opening Scripts
[2012/12/05 07:36:50 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Local\{2C228139-8687-43F2-9088-E478BB61A606}
========== Files - Modified Within 30 Days ==========
[2013/01/03 15:29:11 | 000,025,854 | —- | M] () – C:\Users\Karri\Desktop\R110829104.20130102.pdf
[2013/01/03 15:28:41 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karri\Desktop\OTL.exe
[2013/01/03 15:27:59 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/01/03 15:20:22 | 000,002,559 | —- | M] () – C:\Users\Karri\Desktop\HiJackThis.lnk
[2013/01/03 14:39:00 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3989614313-289073978-4266361891-1000UA.job
[2013/01/03 14:15:29 | 000,201,281 | —- | M] () – C:\Users\Karri\Desktop\27292_10151363206356049_672386584_n.jpg
[2013/01/03 14:12:21 | 000,003,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/01/03 14:12:21 | 000,003,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/01/03 08:12:30 | 000,000,761 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/01/03 08:12:20 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/01/02 15:49:32 | 000,001,772 | —- | M] () – C:\Users\Public\Desktop\ooVoo.lnk
[2013/01/02 15:24:12 | 001,402,880 | —- | M] () – C:\Users\Karri\Desktop\HiJackThis.msi
[2013/01/02 15:23:40 | 000,004,824 | —- | M] () – C:\Windows\wininit.ini
[2013/01/02 15:16:34 | 000,439,704 | —- | M] (Yahoo! Inc.) – C:\Users\Karri\Desktop\msgr11us.exe
[2013/01/02 11:24:00 | 000,132,078 | —- | M] () – C:\Users\Karri\Desktop\Scandinavian.jpg
[2013/01/02 11:19:14 | 000,432,213 | —- | M] () – C:\Users\Karri\Desktop\Video call snapshot 48.png
[2013/01/02 09:25:01 | 000,000,969 | —- | M] () – C:\Users\Karri\Application Data\Microsoft\Internet Explorer\Quick Launch\Picasa 3.lnk
[2013/01/02 09:25:01 | 000,000,945 | —- | M] () – C:\Users\Public\Desktop\Picasa 3.lnk
[2013/01/02 09:24:05 | 015,271,824 | —- | M] (Google Inc.) – C:\Users\Karri\Desktop\picasa39-setup.exe
[2012/12/31 21:39:00 | 000,000,856 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3989614313-289073978-4266361891-1000Core.job
[2012/12/22 13:58:20 | 000,092,623 | —- | M] () – C:\Users\Karri\Desktop\16800_10151343017346049_1636654817_n.jpg
[2012/12/22 08:29:40 | 000,393,856 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2012/12/21 14:36:44 | 000,051,335 | —- | M] () – C:\Users\Karri\Desktop\224562_10150266265914978_307550646_n.jpg
[2012/12/21 14:34:55 | 000,027,506 | —- | M] () – C:\Users\Karri\Desktop\17082_548427821850478_1374715143_n.jpg
[2012/12/21 08:52:23 | 000,000,905 | —- | M] () – C:\Users\Public\Desktop\VLC media player.lnk
[2012/12/19 15:46:48 | 000,001,698 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2012/12/19 11:15:11 | 000,001,001 | —- | M] () – C:\Users\Public\Desktop\TeamViewer 8.lnk
[2012/12/19 08:28:50 | 000,697,272 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2012/12/19 08:28:50 | 000,073,656 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/12/18 07:31:32 | 000,652,288 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2012/12/18 07:31:31 | 000,766,246 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2012/12/18 07:31:31 | 000,125,686 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2012/12/16 08:31:20 | 000,048,128 | —- | M] (Adobe Systems) – C:\Windows\SysNative\atmlib.dll
[2012/12/16 08:12:54 | 000,034,304 | —- | M] (Adobe Systems) – C:\Windows\SysWow64\atmlib.dll
[2012/12/16 06:08:21 | 000,368,128 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysNative\atmfd.dll
[2012/12/16 05:50:29 | 000,293,376 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\atmfd.dll
[2012/12/14 16:25:20 | 000,077,393 | —- | M] () – C:\Users\Karri\Desktop\oj-murders-tape-photographs__oPt.jpg
[2012/12/14 08:42:48 | 000,000,952 | —- | M] () – C:\Users\Karri\Desktop\The Weather Network.lnk
[2012/12/13 13:44:08 | 000,002,046 | —- | M] () – C:\Users\Karri\Desktop\Google Chrome.lnk
[2012/12/13 13:44:08 | 000,002,008 | —- | M] () – C:\Users\Karri\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/12/11 13:56:12 | 000,001,207 | —- | M] () – C:\Users\Karri\Desktop\GoToMeeting.lnk
[2012/12/07 16:06:43 | 000,000,466 | —- | M] () – C:\Users\Karri\Documents\ChatLog New Meeting 2012_12_07 16_06.rtf
[2012/12/07 15:08:36 | 005,406,957 | —- | M] () – C:\Users\Karri\Desktop\DSC01531.JPG
[2012/12/07 15:00:54 | 005,391,002 | —- | M] () – C:\Users\Karri\Desktop\DSC01505.JPG
[2012/12/07 15:00:30 | 005,038,827 | —- | M] () – C:\Users\Karri\Desktop\DSC01476.JPG
[2012/12/07 15:00:24 | 005,120,304 | —- | M] () – C:\Users\Karri\Desktop\DSC01475.JPG
[2012/12/07 14:59:34 | 005,157,162 | —- | M] () – C:\Users\Karri\Desktop\DSC01466.JPG
[2012/12/07 14:58:38 | 004,863,461 | —- | M] () – C:\Users\Karri\Desktop\DSC01464.JPG
[2012/12/07 11:21:09 | 708,422,035 | —- | M] () – C:\Windows\MEMORY.DMP
[2012/12/07 09:15:02 | 005,410,422 | —- | M] () – C:\Users\Karri\Desktop\DSC01436.JPG
========== Files Created - No Company Name ==========
[2013/01/03 15:29:10 | 000,025,854 | —- | C] () – C:\Users\Karri\Desktop\R110829104.20130102.pdf
[2013/01/03 14:15:28 | 000,201,281 | —- | C] () – C:\Users\Karri\Desktop\27292_10151363206356049_672386584_n.jpg
[2013/01/02 15:49:32 | 000,001,772 | —- | C] () – C:\Users\Public\Desktop\ooVoo.lnk
[2013/01/02 15:39:54 | 000,002,559 | —- | C] () – C:\Users\Karri\Desktop\HiJackThis.lnk
[2013/01/02 15:24:05 | 001,402,880 | —- | C] () – C:\Users\Karri\Desktop\HiJackThis.msi
[2013/01/02 11:24:00 | 000,132,078 | —- | C] () – C:\Users\Karri\Desktop\Scandinavian.jpg
[2013/01/02 11:19:05 | 000,432,213 | —- | C] () – C:\Users\Karri\Desktop\Video call snapshot 48.png
[2012/12/22 13:58:20 | 000,092,623 | —- | C] () – C:\Users\Karri\Desktop\16800_10151343017346049_1636654817_n.jpg
[2012/12/21 14:36:43 | 000,051,335 | —- | C] () – C:\Users\Karri\Desktop\224562_10150266265914978_307550646_n.jpg
[2012/12/21 14:34:55 | 000,027,506 | —- | C] () – C:\Users\Karri\Desktop\17082_548427821850478_1374715143_n.jpg
[2012/12/21 08:52:23 | 000,000,905 | —- | C] () – C:\Users\Public\Desktop\VLC media player.lnk
[2012/12/19 07:59:00 | 000,000,830 | —- | C] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/12/14 16:25:20 | 000,077,393 | —- | C] () – C:\Users\Karri\Desktop\oj-murders-tape-photographs__oPt.jpg
[2012/12/14 08:42:48 | 000,000,952 | —- | C] () – C:\Users\Karri\Desktop\The Weather Network.lnk
[2012/12/12 21:10:08 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_User_01_11_00_Inbox_Critical.Wdf
[2012/12/12 21:10:08 | 000,000,003 | —- | C] () – C:\Windows\SysNative\drivers\MsftWdf_Kernel_01011_Inbox_Critical.Wdf
[2012/12/11 13:56:12 | 000,001,207 | —- | C] () – C:\Users\Karri\Desktop\GoToMeeting.lnk
[2012/12/07 16:06:43 | 000,000,466 | —- | C] () – C:\Users\Karri\Documents\ChatLog New Meeting 2012_12_07 16_06.rtf
[2012/12/07 15:20:27 | 005,406,957 | —- | C] () – C:\Users\Karri\Desktop\DSC01531.JPG
[2012/12/07 15:19:09 | 005,391,002 | —- | C] () – C:\Users\Karri\Desktop\DSC01505.JPG
[2012/12/07 15:02:00 | 005,120,304 | —- | C] () – C:\Users\Karri\Desktop\DSC01475.JPG
[2012/12/07 15:01:37 | 005,038,827 | —- | C] () – C:\Users\Karri\Desktop\DSC01476.JPG
[2012/12/07 14:59:50 | 005,157,162 | —- | C] () – C:\Users\Karri\Desktop\DSC01466.JPG
[2012/12/07 14:59:11 | 004,863,461 | —- | C] () – C:\Users\Karri\Desktop\DSC01464.JPG
[2012/12/07 14:57:04 | 005,410,422 | —- | C] () – C:\Users\Karri\Desktop\DSC01436.JPG
[2012/12/06 10:57:24 | 000,001,013 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 8.lnk
[2012/12/06 10:57:24 | 000,001,001 | —- | C] () – C:\Users\Public\Desktop\TeamViewer 8.lnk
[2012/07/22 17:32:00 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2012/02/01 17:18:15 | 000,000,552 | —- | C] () – C:\Users\Karri\AppData\Local\d3d8caps.dat
[2011/12/30 21:49:42 | 000,000,680 | —- | C] () – C:\Users\Karri\AppData\Local\d3d9caps.dat
[2011/10/10 17:52:43 | 000,742,262 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/02 13:28:57 | 000,031,232 | —- | C] () – C:\Users\Karri\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/08/19 04:26:20 | 010,898,456 | —- | C] () – C:\Windows\SysWow64\LogiDPP.dll
[2011/08/19 04:26:20 | 000,336,408 | —- | C] () – C:\Windows\SysWow64\DevManagerCore.dll
[2011/08/19 04:26:20 | 000,104,472 | —- | C] () – C:\Windows\SysWow64\LogiDPPApp.exe
[2011/04/01 09:07:49 | 000,060,864 | —- | C] () – C:\Users\Karri\g2mdlhlpx.exe
[2011/03/19 12:17:47 | 000,004,824 | —- | C] () – C:\Windows\wininit.ini
[2010/03/12 21:00:58 | 000,000,760 | —- | C] () – C:\Users\Karri\AppData\Roaming\setup_ldm.iss
[2009/09/21 11:30:38 | 000,000,029 | —- | C] () – C:\Users\Karri\AppData\Roaming\default.rss
[2009/09/15 11:40:54 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/06/28 10:50:52 | 000,048,127 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/06/28 10:50:52 | 000,048,127 | —- | C] () – C:\ProgramData\nvModes.001
[2008/10/28 07:57:39 | 000,000,052 | —- | C] () – C:\ProgramData\CLSDefine.ini
========== ZeroAccess Check ==========
[2006/11/02 10:30:40 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 12:59:03 | 012,899,840 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 12:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/04/11 02:11:14 | 000,891,392 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2009/04/11 01:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2008/01/20 21:50:58 | 000,513,024 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== Alternate Data Streams ==========
@Alternate Data Stream - 94 bytes -> C:\ProgramData\Temp:D5AA39DD
@Alternate Data Stream - 257 bytes -> C:\ProgramData\Temp:36608448
@Alternate Data Stream - 252 bytes -> C:\ProgramData\Temp:1E288DA3
@Alternate Data Stream - 251 bytes -> C:\ProgramData\Temp:AE289451
@Alternate Data Stream - 247 bytes -> C:\ProgramData\Temp:7D288858
@Alternate Data Stream - 247 bytes -> C:\ProgramData\Temp:0E61938B
@Alternate Data Stream - 242 bytes -> C:\ProgramData\Temp:FEE00EB9
@Alternate Data Stream - 237 bytes -> C:\ProgramData\Temp:2EB79F01
@Alternate Data Stream - 236 bytes -> C:\ProgramData\Temp:F2327E82
@Alternate Data Stream - 236 bytes -> C:\ProgramData\Temp:DE6EED8B
@Alternate Data Stream - 235 bytes -> C:\ProgramData\Temp:35629AE6
@Alternate Data Stream - 233 bytes -> C:\ProgramData\Temp:CEE4A457
@Alternate Data Stream - 230 bytes -> C:\ProgramData\Temp:08DB8D99
@Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:3B07E6F4
@Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:349E5B74
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:10D45FC3
@Alternate Data Stream - 224 bytes -> C:\ProgramData\Temp:4B244549
@Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:5AE33054
@Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:014BC3B4
@Alternate Data Stream - 221 bytes -> C:\ProgramData\Temp:3C0887BF
@Alternate Data Stream - 218 bytes -> C:\ProgramData\Temp:41884BBE
@Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:CB0FEE2B
@Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:38D2EA83
@Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:169E7AC5
@Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:A9ABA3FF
@Alternate Data Stream - 210 bytes -> C:\ProgramData\Temp:ED9B661E
@Alternate Data Stream - 196 bytes -> C:\ProgramData\Temp:3D36932D
@Alternate Data Stream - 152 bytes -> C:\ProgramData\Temp:6301CE40
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:2A8A3140
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:E9900C74
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:4B70A9FA
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:908A1B53
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:6E11933F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:1B3549F2
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:7BB584AA
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:274516E7
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:131C0EE9
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:3AC0ED43
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:C9BC8592
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:793F316E
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:92DB4653
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:8AB6C1D7
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:CFF6B3FF
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:490BCC52
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:DCA79AB3
@Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:2CED8825
@Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:FC60E0F8
@Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:861A898F
@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:580E04D8
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:4F636E25
< End of report >
OTL Extras logfile created on: 03/01/2013 3:28:49 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karri\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy
7.93 Gb Total Physical Memory | 2.99 Gb Available Physical Memory | 37.72% Memory free
16.07 Gb Paging File | 8.76 Gb Available in Paging File | 54.51% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.59 Gb Total Space | 70.86 Gb Free Space | 30.47% Space Free | Partition Type: NTFS
Drive D: | 348.93 Gb Total Space | 92.10 Gb Free Space | 26.40% Space Free | Partition Type: NTFS
Drive J: | 295.02 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive N: | 3.79 Gb Total Space | 3.79 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive O: | 930.95 Gb Total Space | 813.57 Gb Free Space | 87.39% Space Free | Partition Type: FAT32
Computer Name: KARRI-PC | User Name: Karri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = C9 C1 E4 2F 8B 3A CA 01 [binary data]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0485F8E3-1A09-4024-BA7E-F98A6E3B67FB}" = rport=138 | protocol=17 | dir=out | app=system |
"{26EACD8C-7194-4F96-81ED-2154D5E90590}" = lport=2869 | protocol=6 | dir=in | app=system |
"{42D82151-1A35-4B9D-A760-559221DBBA4F}" = rport=137 | protocol=17 | dir=out | app=system |
"{438F3FCE-8893-48B9-A035-40554350B370}" = lport=139 | protocol=6 | dir=in | app=system |
"{50115D97-DB49-44CD-84E2-4DA4E2F2EEF9}" = lport=137 | protocol=17 | dir=in | app=system |
"{5AA76EEF-6B8E-438A-B21C-10FE61C8273E}" = rport=445 | protocol=6 | dir=out | app=system |
"{72723F71-5C72-4E2F-A8BB-1B2FACDB0B03}" = lport=138 | protocol=17 | dir=in | app=system |
"{7368AFD0-6C88-4905-BAB2-CC2F4BB6602B}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{8A9ABA56-F005-42CB-835A-680487CE04E1}" = lport=445 | protocol=6 | dir=in | app=system |
"{B1E53891-F0B7-4D8F-87CF-92D87825598A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{B8806828-0C3B-4515-8175-852416FE4373}" = rport=139 | protocol=6 | dir=out | app=system |
"{BCE834EC-BBCE-41BD-8EAE-8AD289A873AF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C73FCED9-8013-44F9-9592-8A54D7382EFF}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{D8416C81-AE7C-4BDA-9F38-50CB9711BFF2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{EA7FAF37-873E-474D-ACA0-61CFD228318E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{026A20FC-E75E-4AE5-A84F-3FB1E5C8E8FD}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{0D80A6FE-DF65-421F-9336-1A166CC05632}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\droplitz\cascade.exe |
"{143090E1-9C5F-41B5-9B2E-C1D71C44FB47}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotel dash\hoteldash.exe |
"{15586373-00E5-411F-BFF2-941CC4C64474}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\eufloria\eufloria.exe |
"{1A6A2C55-F5C3-49DA-95B9-70BBA78D5589}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{1CB745C2-A73C-42B2-ACA3-A3F7F2C3C15B}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia connect\kernel\dms\clmsserver.exe |
"{1D84E0DD-067E-4B7D-88CB-A6E2F48DD0A5}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{211AD758-F2EB-4C6B-867E-9E1B7A5A0437}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotel dash\hoteldash.exe |
"{25757D9E-3675-4F14-A555-A49B3425CE2B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{28280830-880C-44CF-8B73-76D37540F99B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzle chronicles\puzzlechronicles.exe |
"{2F4D3580-9E97-40D0-993E-04DADC4CE426}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{31084447-3FDA-4BC2-B9ED-916FEF2295CF}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{31DB2597-38D6-4A4E-AA8B-EF6C74DEF37B}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia connect\acer homemedia connect.exe |
"{33B49371-D92B-40D5-867C-05009872AB14}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{36BE2B08-E41C-430A-8CE3-BA072FB7BB18}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\zuma's revenge\zumasrevenge.exe |
"{3EA1A45A-B3BE-4B86-83A9-882D7631EB07}" = dir=in | app=c:\program files\microsoft lync\ucmapi64.exe |
"{41EB73A3-0B7B-4FE3-89F3-ABF7F7551415}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\luxor 5th passage\luxor - 5th passage.exe |
"{42D7C32D-AFB0-4E17-805C-D17ACCBF9B1F}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{437A62E9-5F86-447B-BC81-C06350379349}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{45E1E295-7947-4BC0-A7D5-1341E4C006DF}" = dir=in | app=c:\program files (x86)\acer arcade live\acer arcade live main page\acer arcade live.exe |
"{46319C9A-D991-4DF5-AAB0-75693DD14404}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{482E5199-DCBB-40E3-A1DB-BC2D27399AB0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{49DF5E5B-FAC5-4C46-A567-8DEC235647EC}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{4CD3CDE7-136E-4D80-8E17-BCA58F2A9160}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{4DE71902-F71D-485C-BFA2-FCFFC948878D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{50BCD8A0-DE73-4E01-8E42-A26440FEA07D}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clsomamonitorservice.exe |
"{5128F576-1743-46EE-BD62-15FD815E5D6F}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{53F1AE12-C085-4AF4-A1A3-3E0493DDE57C}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clsomaservice.exe |
"{59F76541-B1FB-4C81-A98D-9DFB3F36A7A7}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia trial creator\acer homemedia trial creator.exe |
"{5A4CD912-D98B-4752-8758-9CBEFF37B38C}" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{5A846A34-4E3D-4397-B499-EA651EAC799A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{5B53DBD0-CF30-4E48-A60A-B8F14A7338AB}" = dir=in | app=c:\program files (x86)\acer arcade live\acer slideshow dvd\acer slideshow dvd.exe |
"{5BFCE5AC-A1CF-4E02-945E-082F476C53AB}" = protocol=17 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{60908FE1-AD5A-44DE-973F-D1B56E4C95C4}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{63529CEB-A982-4D8F-B3D4-38798D235B97}" = dir=in | app=c:\program files (x86)\acer arcade live\acer dv magician\acer dv magician.exe |
"{6B53143B-FAF1-4826-A5C4-2D0D25E3B6B1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\eufloria\eufloria.exe |
"{6BF7994F-F161-4D37-BA52-9F2B7903F92D}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{6EF76C59-39D2-4E16-A3D9-FD112F09E4D5}" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{70DDDEC1-424F-4FB0-90AB-DC467AF2DE73}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{722B5250-5770-4A57-AA8A-77F2F3935D0C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\luxor 5th passage\luxor - 5th passage.exe |
"{7992BD87-E39E-4DF3-AE41-7CC61872FA91}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzlequest2\puzzlequest2.exe |
"{8B57FA11-FAAA-45D7-9CD0-779B67A0691F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\zuma's revenge\zumasrevenge.exe |
"{8F30AF37-993B-4183-9481-23345349D2E4}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{9AE2D478-D3BA-40C2-ADE9-3C8EBE115FAF}" = dir=in | app=c:\program files (x86)\acer arcade live\acer videomagician\acer videomagician.exe |
"{9EBA2EBE-1437-41D5-B5DD-D10C4459955A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"{A755F2BB-5391-4EC8-8CC9-2A6E28230F0D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A792D402-18C2-4584-9985-67947D43CBB4}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe |
"{AB95C5A1-1EE1-4623-B8B8-AC3AD4717B59}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{AF57DC65-FE10-4F0E-87EB-850082FEC2A5}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{B4B4EF0A-F441-4C4E-9B49-E8DF65F3DC53}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{B7035FE8-3D41-48BC-83DB-3069996FDF15}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{BA977534-1A57-46A1-9D5C-E8CAF28DA686}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzle chronicles\puzzlechronicles.exe |
"{BAE33E54-2BEA-4488-AE6A-9184671ACDB0}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{BCB23F56-6620-45C9-97B1-743DA0A787D2}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clpushupdateservice.exe |
"{BDEE44E1-CC0F-418D-BDE1-F2A29A22B66A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{BE958C74-7849-4FC8-955D-53C4840F85DE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzlequest2\puzzlequest2.exe |
"{C0BCE171-BA08-4A8A-9468-CECD02E07F30}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe |
"{C30E81C8-6756-4A8E-A10A-75D500F199C8}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{C39E0424-540B-45DB-9A3E-A8D23D3A7630}" = dir=in | app=c:\program files (x86)\microsoft lync\communicator.exe |
"{C6E9C062-FDE1-4E8F-B5E9-E60EDAB60356}" = dir=in | app=c:\program files (x86)\acer arcade live\acer dvdivine\acer dvdivine.exe |
"{C77AB154-B16F-4739-AB97-294A1E700D8E}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{CE2A96E7-0A4E-4840-987F-8AE7692D4E66}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{CF6AFB91-9BB1-40CD-951F-7334F89F92D9}" = protocol=6 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{D2B0635A-BF7B-4CCD-9FF4-33A786BF9772}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{D7929809-9DB7-4971-BE00-795D130BB3DA}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{DBBFBF7F-6998-4EE7-8B1C-5D4F1298ED14}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia\acer homemedia.exe |
"{E21B7CAE-632B-4891-B03B-7FEC13816437}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{E38229C0-4738-44C9-BC16-E3B2760638D3}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{E890FBFF-A9A1-41D1-B7F6-DF8CD784C568}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{F3315C0F-CCAA-4FE6-B1C1-D1FC8116906E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fitness dash\fitnessdash.exe |
"{F44E840B-CA0A-494D-974E-F88DC2AE18E8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F4E391D2-9AD6-4A86-B632-A7B3D4DB1868}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{F5431383-35A1-4C6F-BC45-4A7AEF330988}" = dir=in | app=c:\program files (x86)\microsoft lync\ucmapi.exe |
"{F736369E-A09E-4770-82FA-EE01A02543D4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\droplitz\cascade.exe |
"{FB3D19E9-958E-43D1-9E96-A676CE39491A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fitness dash\fitnessdash.exe |
"{FD2FA6DC-FA5E-4EC9-8311-481D5157822B}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clhomemediaserver.exe |
"{FE228B95-329B-46E8-950B-70EE4F5B549E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"TCP Query User{1FD7F4E9-C63D-4CFD-89DE-0279CE61ACBA}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"TCP Query User{236DB553-2209-4978-BD98-DDA820C234FE}C:\program files (x86)\oovoo\oovoo.exe" = protocol=6 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"TCP Query User{385704E7-8985-4F92-8901-C6FE813E201A}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{B504721D-C368-4CB9-90EB-852F3C2212B7}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"TCP Query User{CE3E5FCD-7C89-492C-9C89-CCA6312E7DED}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"TCP Query User{E6899A08-551C-4CBB-8A09-8514A08C1D03}C:\program files (x86)\logitech\vid hd\vid.exe" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"UDP Query User{534508C2-EC9A-4B83-BE0C-780DD08D8D53}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"UDP Query User{5B1C0B5B-B3D2-46B4-9AAF-F334DD805AAF}C:\program files (x86)\logitech\vid hd\vid.exe" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"UDP Query User{9A50E594-A30A-4554-9667-ADB34FA275F8}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"UDP Query User{BF90CEB4-CD3C-49C5-8BDE-10B1040E2383}C:\program files (x86)\oovoo\oovoo.exe" = protocol=17 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"UDP Query User{CCA1448D-D510-44CC-953D-484C5605B7F5}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"UDP Query User{E121835F-7ABC-45F8-84AE-DAC397530DEB}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{0370E621-61D1-4199-82AF-8F21851FD194}" = i_instrumentation [removed]
"{072F206C-2F30-48C9-8ED0-3CDF4F612CB1}" = ME_Kit_Files_x64
"{0C524D20-1409-0050-8A9E-0C4C490E4E54}" = Microsoft Dynamics CRM 2011 for Microsoft Office Outlook
"{0C524DC1-1409-0050-8121-88490F4D5549}" = Microsoft Dynamics CRM 2011 English (United States) Language Pack
"{0E5D76AD-A3FB-48D5-8400-8903B10317D3}" = iTunes
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D666E21-2924-4B94-9A33-D6136761ACAB}" = Intel® Remote Wake Technology 1.0.296.0
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86416014FF}" = Java™ 6 Update 14 (64-bit)
"{273799F6-BC76-46F1-95E1-EF05322C3A5F}" = i_msm 1.0.312.0
"{2BE51F94-8ED9-4B31-898C-01BFA71CC1DC}" = i_swupdate [removed]
"{4975D666-729A-46A5-8C80-1F022AD43543}" = Livedrive
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{52A7026F-476C-4E3B-A4C7-8FF7DAD65FEB}" = i_redistributables 1.0.45
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{70E8EBD5-78C9-4258-B20A-5098CCA000F0}" = Dolby Control Center
"{81BE0B17-563B-45D4-B198-5721E6C665CD}" = Microsoft Lync 2010
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{868EA922-5675-4E91-BDA6-BBD0F923C5EF}" = HP Officejet Pro All-In-One Series
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUSR_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.PROPLUSR_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 306.97
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 306.97
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.10.8
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{D70884EA-E2CE-4539-91DB-4766CC1E5F5F}" = Apple Mobile Device Support
"{E20B2752-0909-4B28-B8A9-A9BE519CA1A1}" = Microsoft Online Services Sign-in Assistant
"{F39076D7-7168-44CD-A2C6-EBC1CDA7DC1C}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft CRM Client" = Microsoft Dynamics CRM 2011 for Microsoft Office Outlook
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"WinRAR archiver" = WinRAR 4.01 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D2F6F25-394B-4ACA-BC9C-1394E963C620}" = Intel® Remote Wake Technology [removed]
"{12CAA28E-56CA-4C3D-B3F2-7311540DD410}" = TurboTax 2011
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{131B84C2-5435-4993-9888-6C62D9AC755E}" = CyberLink Live
"{132888AE-EF67-41C5-BCA2-7D5D2488AB63}" = Acer HomeMedia Connect
"{13D85C14-2B85-419F-AC41-C7F21E68B25D}" = Acer eSettings Management
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{24AE6B5B-3D5A-488C-9224-1BEE11F75DD9}" = TurboTax 2010
"{26A24AE4-039D-4CA4-87B4-2F83216032FF}" = Java™ 6 Update 38
"{28DA3304-9EC2-4097-BC64-B59A1958841F}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{41581EF5-45A7-11DA-9D78-000129760D75}" = Acer SlideShow DVD
"{43D16DA8-BF42-3C62-89D3-3AD47829DC2E}" = Google Talk Plugin
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}" = BPDSoftware_Ini
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5AE12194-3EAA-40DF-B2BF-FE1D6B78BBF4}" = Nero Vision
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{63e01893-1aef-40c9-b436-5817c1394f52}" = Nero 9 Trial
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6ad7d061-da98-4a17-8960-1ba830ff4861}" = Nero 9
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71828142-5A24-4BD0-97E7-976DA08CE6CF}" = The Sims™ 3 High-End Loft Stuff
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110113233}" = Bookworm Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11029123}" = Bricks of Egypt
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110322783}" = Big Kahuna Reef
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110411970}" = Chuzzle
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111324990}" = Kick N Rush
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111543617}" = Backspin Billiards
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111692950}" = Mahjongg Artifacts
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}" = Mystery Solitaire - Secret Island
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111872660}" = Diner Dash Flo on the Go
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112310577}" = Flip Words 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112531267}" = Chicken Invaders 3
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113009953}" = Turbo Pizza
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113080210}" = Azada
"{83BEEFB4-8C28-4F4F-8A9D-E0D1ADCE335B}" = The Sims Medieval
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8868D822-2CBA-46B2-A286-B400B6185769}" = 7500_7600_7700_Help
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F1B6239-FEA0-450A-A950-B05276CE177C}" = Acer Empowering Technology
"{8F968232-15C6-4872-84C2-9FCDAA1AEAB6}" = MPM
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = The Sims™ 3 Ambitions
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A875B56-A35C-46BA-A3AA-DF8D03EE9F2F}" = Nero ControlCenter
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{9e9fdde6-2c26-492a-85a0-05646b3f2795}" = NeroLiveGadget
"{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A495D4DC-4036-4914-9CB2-0FCF6A3166EF}" = L7500
"{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA0D2D5F-612B-45D3-8759-DA87206E5CC9}" = QuickTax 2008
"{AA4BF92B-2AAF-11DA-9D78-000129760D75}" = Acer HomeMedia
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{B145EC69-66F5-11D8-9D75-000129760D75}" = Acer DVDivine
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B580C409-E16F-44FF-904D-3AE94E113BE0}" = Acer HomeMedia Trial Creator
"{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = The Sims™ 3 World Adventures
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C19B3EB6-B54C-3204-A4DF-88432E0C79F7}" = Microsoft ReportViewer 2010 Redistributable
"{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CCE825DB-347A-4004-A186-5F4A6FDD8547}" = Apple Application Support
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C1}" = WinZip 15.0
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{DEB9AEF7-3ADA-40a9-9C98-546D54FE9CBD}" = ProductContext
"{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}" = Nero Live
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{ECB9C58E-C565-4683-9599-B72290BD3B25}" = QuickTax 2009
"{EE7257A2-39A2-4D2F-9DAC-F9F25B8AE1D8}" = Skype™ 5.10
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}" = Acer Arcade Live Main Page
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f1861f30-3419-44db-b2a1-c274825698b3}" = Nero Disc Copy Gadget
"{F6EFFB76-4A07-11DA-9D78-000129760D75}" = Acer DV Magician
"{F79A208D-D929-11D9-9D77-000129760D75}" = Acer VideoMagician
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Acer Assist" = Acer Assist
"Acer GameZone Console_is1" = Acer GameZone Console DTV 2.0.1.1
"Acer Registration" = Acer Registration
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"BFG-Be a King - Golden Empire" = Be a King: Golden Empire
"BFG-Be Richest!" = Be Richest!
"BFG-Bistro Boulevard" = Bistro Boulevard
"BFG-Boutique Boulevard" = Boutique Boulevard
"BFG-Build-a-lot - Fairy Tales" = Build-a-lot: Fairy Tales
"BFG-Build-a-lot - On Vacation" = Build-a-lot: On Vacation
"BFG-Build-a-Lot 4 - Power Source" = Build-a-Lot 4: Power Source
"BFGC" = Big Fish Games: Game Manager
"BFG-Campgrounds" = Campgrounds
"BFG-Casino Chaos" = Casino Chaos
"BFG-Chloe's Dream Resort" = Chloe's Dream Resort
"BFG-Club Paradise" = Club Paradise
"BFG-Cooking Dash 3 - Thrills and Spills" = Cooking Dash 3: Thrills and Spills
"BFG-Dancing Craze" = Dancing Craze
"BFG-DinerTown - Detective Agency" = DinerTown: Detective Agency
"BFG-Dress Up Rush" = Dress Up Rush
"BFG-Farm Frenzy 3" = Farm Frenzy 3
"BFG-Fiona Finch and the Finest Flowers" = Fiona Finch and the Finest Flowers
"BFG-First Class Flurry" = First Class Flurry
"BFG-Grave Mania - Undead Fever" = Grave Mania: Undead Fever
"BFG-Hotel Dash 2 - Lost Luxuries" = Hotel Dash 2: Lost Luxuries
"BFG-Island Tribe 2" = Island Tribe 2
"BFG-Jet Set Go" = Jet Set Go
"BFG-Jo's Dream - Organic Coffee" = Jo's Dream: Organic Coffee
"BFG-Juliette's Fashion Empire" = Juliette's Fashion Empire
"BFG-Katy and Bob - Way Back Home" = Katy and Bob: Way Back Home
"BFG-My Farm Life" = My Farm Life
"BFG-Northern Tale" = Northern Tale
"BFG-Pet Rush - Arround the World" = Pet Rush: Arround the World
"BFG-Princess Isabella - A Witch's Curse" = Princess Isabella: A Witch's Curse
"BFG-Rescue Frenzy" = Rescue Frenzy
"BFG-Roads of Rome III" = Roads of Rome III
"BFG-Royal Envoy 2 Collector's Edition" = Royal Envoy 2 Collector's Edition
"BFG-Sally's Studio Collector's Edition" = Sally's Studio Collector's Edition
"BFG-Shop-n-Spree - Shopping Paradise" = Shop-n-Spree: Shopping Paradise
"BFG-Soap Opera Dash" = Soap Opera Dash
"BFG-Spa Mania 2" = Spa Mania 2
"BFG-The Timebuilders - Pyramid Rising" = The Timebuilders: Pyramid Rising
"BFG-Virtual City 2 - Paradise Resort" = Virtual City 2: Paradise Resort
"BFG-Wedding Dash 2 - Rings Around the World" = Wedding Dash 2: Rings Around the World
"BFG-Wedding Dash 4-Ever" = Wedding Dash 4-Ever
"BFG-Wedding Salon" = Wedding Salon
"BFG-Youda Jewel Shop" = Youda Jewel Shop
"Comical_is1" = Comical 0.8
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{131B84C2-5435-4993-9888-6C62D9AC755E}" = CyberLink Live
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"Kobo" = Kobo
"Logitech Vid" = Logitech Vid HD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes' Anti-Malware
"Mouse Setting Software_is1" = Mouse Setting Software 4.0
"Mozilla Firefox 15.0 (x86 en-US)" = Mozilla Firefox 15.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"Origin" = Origin
"Picasa 3" = Picasa 3
"Royal Envoy Collector's Edition" = Royal Envoy Collector's Edition
"Runic Games Torchlight" = Torchlight
"Steam App 19020" = Puzzle Chronicles
"Steam App 200710" = Torchlight II
"Steam App 23120" = Droplitz
"Steam App 3620" = Zuma's Revenge
"Steam App 37340" = Fitness Dash
"Steam App 41210" = Eufloria
"Steam App 47540" = Puzzle Quest 2
"Steam App 49000" = Hotel Dash
"Steam App 60340" = LUXOR: 5th Passage
"Steam App 70400" = Recettear: An Item Shop's Tale
"Strat-O-Matic CD-ROM Ver16.00H" = Strat-O-Matic CD-ROM Ver16.00H
"TeamViewer 8" = TeamViewer 8
"VLC media player" = VLC media player 2.0.5
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"YTdetect" = Yahoo! Detect
"Zynga Toolbar" = Zynga Toolbar
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
"GoToMeeting" = GoToMeeting 5.4.0.1060
"Mozilla Firefox 17.0.1 (x86 en-US)" = Mozilla Firefox 17.0.1 (x86 en-US)
"Oracle Live Help On Demand - Agent Console - NNA CLPOC ORILLIA Karri Tougas (105652707)" = Oracle Live Help On Demand - Agent Console - NNA CLPOC ORILLIA Karri Tougas (105652707)
"Sansa Updater" = Sansa Updater
"The Weather Network" = The Weather Network
"uTorrent" = µTorrent
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 03/01/2013 1:20:57 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 1:30:59 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 1:35:59 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 1:46:01 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 1:51:01 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 2:01:02 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 2:16:06 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 2:21:06 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 2:36:09 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5972
Description = An error occurred retrieving data from the Microsoft CRM server for
processing Microsoft CRM-related e-mail messages. Not all CRM-related e-mail messages
may be marked appropriately. Verify that the current user has appropriate permissions
and server connectivity and try the action again. HR=0x80131501. Context=. Function=CEmailTagger::Run.
Line=410.
Error - 03/01/2013 2:42:14 PM | Computer Name = Karri-PC | Source = MSCRMAddin | ID = 5981
Description = An error occurred retrieving data from the Microsoft CRM server for
processing pending Microsoft CRM e-mail messages. Verify that the current user
has appropriate permissions and server connectivity and try the action again. HR=0x80131501.
Context=. Function=CEmailBackgroundSend::Run. Line=332.
[ System Events ]
Error - 30/12/2012 12:41:35 PM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 30/12/2012 12:41:35 PM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 31/12/2012 8:34:34 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 31/12/2012 8:34:34 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 01/01/2013 11:40:16 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 01/01/2013 11:40:16 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 02/01/2013 9:12:52 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 02/01/2013 9:12:53 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 03/01/2013 9:14:00 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
Error - 03/01/2013 9:14:00 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =
< End of report >