This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Entire Windows Registery Damaged, possibly maleware and viruses [Solve

15 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello, I have a serous issue with my computer. I noticed that my avast firewall was disabled and the shields were all turned off in addition to that, it was shown that my license registration was expired. Many of the applications stopped running.

I contacted avast in regards to this issue and he remote connected to my pc and they told me that the license was not expired and that i have a serious issue with my windows registry being damaged completely. I asked them if i format my computer will that fix the issue, they said no. Because the registry on the windows platform is in critical state and a format will not fix it. He also shown me a few things that i had on my computer that compromise the security of my files, something called "iYogi Support Dock" which is basically a scam attempt to try and gather information from the user's pc.

I also wanted to note that i use this computer for bank account information and he mentioned that it would be a good idea if you told the tech providing service on your computer to use a software that protects the identity of your passwords and id's for all of your bank account and security information. Other software he mentioned that should be removed my pc is "CCcleaner", which i always though was a good software for cleaning your registry, but he mentions that no such software really exists. The other software is "Superanyspyware" which he mentioned should never be ran with avast and it cause a conflicting issue with my firewall. I just recently download superantispyware and CCcleaner so i can try and fix this problem.

I really do not know how i was able to get this type of infection, i do no that i download diamond tools software application and a certain game, and and i think they may of what caused this issue to happen. It came packaged with a software called "Updater by Sweetpacks" which was rerouting my URL and changing my default URL for my browser. The technician from avast was going to try and renew my license for my computer, i accessed my email address so he can download it, but mentioned that the .dat ext was not being recognized due to the corruption my OS was in. He told me they could fix it completely but it would cost me $168.00. I said i really wasn't into paying that much for it so this is why i bring this to your attention, i mentioned that i knew a good tech forum that may be able to fix the issue. The avast technician said its possible to fix if someone knows how to fix a damaged registry so that is why i am asking that you take a deep look into this problem and find out exactly what is going on and how to fix this. It worries me because the fact that "clean format" could not even fix the problem, ive never had anything really that serous before.

He also some how looked at my windows errors and shown alot of error codes in the registry, this may seem like a scam but i assure you its not. This person is a legitimate technician because I called the main avast contact for customer support.

Their was a few other things i wanted to jot down but was not able to because i got disconnected from the phone and he closed the remote connection, so hopefully this is enough information for you annylize the problem efficiently. This may be an issue that simple maleware and virus removal activity will not fix, he mentioned that someone has to know how to actually fix the registery of the platform of my OS but said its possible if you get the right technician.

I am going to send a log report file from DDS for now and you can look it over and let me know where to go from here, thanks!


DDS LOG REPORT


DDS (Ver_2012-11-20.01) - NTFS_AMD64
Internet Explorer: 9.0.8112.16464 BrowserJavaVersion: 10.17.2
Run by [removed] at 16:35:48 on 2013-04-03
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.7659.4465 [GMT -7:00]
.
AV: avast! Internet Security *Disabled/Outdated* {2B2D1395-420B-D5C9-657E-930FE358FC3C}
SP: avast! Internet Security *Disabled/Outdated* {904CF271-6431-DA47-5FCE-A87D98DFB681}
SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
FW: avast! Internet Security *Enabled* {131692B0-0864-D491-4E21-3A3A1D8BBB47}
.
============== Running Processes ===============
.
C:\Windows\system32\lsm.exe
C:\Windows\system32\svchost.exe -k DcomLaunch
C:\Windows\system32\svchost.exe -k RPCSS
C:\Windows\system32\atiesrxx.exe
C:\Windows\System32\svchost.exe -k LocalServiceNetworkRestricted
C:\Windows\System32\svchost.exe -k LocalSystemNetworkRestricted
C:\Windows\system32\svchost.exe -k LocalService
C:\Windows\system32\svchost.exe -k netsvcs
C:\Program Files\IDT\WDM\STacSV64.exe
C:\Windows\system32\atieclxx.exe
C:\Windows\system32\svchost.exe -k NetworkService
C:\Program Files\AVAST Software\Avast\afwServ.exe
C:\Windows\System32\spoolsv.exe
C:\Windows\system32\svchost.exe -k LocalServiceNoNetwork
C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE
C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
C:\Users\Jeff\AppData\Local\CrossLoop\CrossLoopService.exe
C:\Windows\system32\svchost.exe -k LocalServiceAndNoImpersonation
C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
C:\Windows\system32\svchost.exe -k imgsvc
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE
C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe
C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSvcM.exe
C:\Windows\system32\taskhost.exe
C:\Windows\system32\svchost.exe -k NetworkServiceNetworkRestricted
C:\Windows\system32\Dwm.exe
C:\Windows\System32\rundll32.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\IDT\WDM\sttray64.exe
C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar1.exe
C:\Program Files\Hewlett-Packard\HP LaunchBox\HPTaskBar2.exe
C:\Program Files\Canon\MyPrinter\BJMYPRT.EXE
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Windows\system32\taskeng.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Mal Updater 2\MalUpdater.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files\ONAIR\ONAIR.exe
C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
C:\Program Files\AVAST Software\Avast\AvastUI.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Users\Jeff\AppData\Roaming\Dropbox\bin\Dropbox.exe
C:\Windows\system32\SearchIndexer.exe
C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
C:\Program Files\Windows Media Player\wmpnetwk.exe
C:\Program Files (x86)\HP\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
C:\Windows\splwow64.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Canon\Solution Menu EX\CNSEUPDT.EXE
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Windows\System32\svchost.exe -k LocalServicePeerNet
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe
C:\Windows\System32\svchost.exe -k secsvcs
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe
C:\Windows\system32\wuauclt.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Microsoft Office\Office14\WINWORD.EXE
C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Program Files (x86)\Internet Explorer\iexplore.exe
C:\Windows\SysWOW64\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Jeff\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\system32\wbem\wmiprvse.exe
C:\Windows\System32\cscript.exe
.
============== Pseudo HJT Report ===============
.
uStart Page = hxxp://search.iyogi.com/
uURLSearchHooks: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
mWinlogon: Userinit = userinit.exe
BHO: &Yahoo! Toolbar Helper: {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
BHO: Adobe PDF Link Helper: {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
BHO: DivX Plus Web Player HTML5 : {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll
BHO: Canon Easy-WebPrint EX BHO: {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll
BHO: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll
BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
BHO: Java™ Plug-In SSV Helper: {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
BHO: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files (x86)\Microsoft Office\Office14\URLREDIR.DLL
BHO: Java™ Plug-In 2 SSV Helper: {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
BHO: HP Network Check Helper: {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
BHO: SingleInstance Class: {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll
TB: Yahoo! Toolbar: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll
TB: avast! WebRep: {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll
TB: Canon Easy-WebPrint EX: {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
EB: Canon Easy-WebPrint EX: {21347690-EC41-4F9A-8887-1F4AEE672439} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll
EB: : {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 -
EB: : {555D4D79-4BD2-4094-A395-CFC534424A05} - LocalServer32 -
uRun: [Google Update] "C:\Users\Jeff\AppData\Local\Google\Update\GoogleUpdate.exe" /c
uRun: [Mal Updater 2] C:\Program Files (x86)\Mal Updater 2\MalUpdater.exe
uRun: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /minimized /regrun
uRun: [ONAIR] C:\Program Files\ONAIR\ONAIR.exe
uRun: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe
uRun: [Bomgar_Cleanup_ZD463527019543] cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-00000000515CAF96" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD463527019543 /f
mRun: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
mRun: [HPQuickWebProxy] "C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe"
mRun: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
mRun: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
mRun: [BCSSync] "C:\Program Files (x86)\Microsoft Office\Office14\BCSSync.exe" /DelayServices
mRun: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
mRun: [avast] "C:\Program Files\AVAST Software\Avast\avastUI.exe" /nogui
mRun: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
mRun: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin
mRun: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\\isuspm.exe -scheduler
mRun: [HP Software Update] C:\Program Files (x86)\HP\HP Software Update\HPWuSchd2.exe
mRun: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe
mRun: [DivXUpdate] "C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe" /CHECKNOW
mRun: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
mRun: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE /logon
mRun: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe /FORCE
dRun: [Bomgar_Cleanup_ZD7101125413] cmd.exe /C rd /S /Q "C:\ProgramData\iyogi-scc-0000000050C671CB" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD7101125413 /f
StartupFolder: C:\Users\Jeff\AppData\Roaming\MICROS~1\Windows\STARTM~1\Programs\Startup\Dropbox.lnk - C:\Users\Jeff\AppData\Roaming\Dropbox\bin\Dropbox.exe
mPolicies-Explorer: NoActiveDesktop = dword:1
mPolicies-Explorer: NoActiveDesktopChanges = dword:1
mPolicies-System: ConsentPromptBehaviorAdmin = dword:5
mPolicies-System: ConsentPromptBehaviorUser = dword:3
mPolicies-System: EnableUIADesktopToggle = dword:0
mPolicies-System: SoftwareSASGeneration = dword:3
IE: E&xport to Microsoft Excel - C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
IE: Se&nd to OneNote - C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
IE: {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - {5F7B1267-94A9-47F5-98DB-E99415F33AEC} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
IE: {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
IE: {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll/204
TCP: NameServer = 192.168.0.1 205.171.2.65
TCP: Interfaces\{E374F5FE-C5BF-433D-9148-D474298D024F} : DHCPNameServer = 192.168.0.1 [removed]
TCP: Interfaces\{E374F5FE-C5BF-433D-9148-D474298D024F}\3456E647572797C496E6B603535333F5548545 : DHCPNameServer = 192.168.0.1 [removed]
TCP: Interfaces\{E374F5FE-C5BF-433D-9148-D474298D024F}\D697177756374763939343 : DHCPNameServer = 192.168.0.1 [removed]
TCP: Interfaces\{E374F5FE-C5BF-433D-9148-D474298D024F}\D697177756374763939343F5548545 : DHCPNameServer = 192.168.0.7
Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll
Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll
Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
SSODL: WebCheck -
SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files (x86)\Microsoft Office\Office14\GROOVEEX.DLL
mASetup: {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} - msiexec /fu {F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1} /qn
x64-BHO: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-BHO: SteadyVideoBHO Class: {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll
x64-BHO: Groove GFS Browser Helper: {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-BHO: Windows Live ID Sign-in Helper: {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
x64-BHO: Office Document Cache Handler: {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL
x64-TB: avast! WebRep: {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll
x64-Run: [SynTPEnh] C:\Program Files (x86)\Synaptics\SynTP\SynTPEnh.exe
x64-Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe
x64-Run: [SetDefault] C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe
x64-Run: [AdobeAAMUpdater-1.0] "C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
x64-Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe /logon
x64-IE: {2670000A-7350-4f3c-8081-5663EE0C6C49} - {48E73304-E1D6-4330-914C-F5F514E3486C} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dll
x64-IE: {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - {FFFDC614-B694-4AE6-AB38-5D6374584B52} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
x64-Filter: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
x64-Filter: video/mp4 - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Filter: video/x-flv - {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll
x64-Handler: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} -
x64-Handler: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} -
x64-SSODL: WebCheck -
x64-SEH: Groove GFS Stub Execution Hook - {B5A7F190-DDA6-4420-B3BA-52453494E6CD} - C:\Program Files\Microsoft Office\Office14\GROOVEEX.DLL
x64-mASetup: {6032497A-4479-462B-ADB8-A0A372BB9A23} - msiexec /fu {6032497A-4479-462B-ADB8-A0A372BB9A23} /qn
.
================= FIREFOX ===================
.
FF - ProfilePath - C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\9odu2h93.default\
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
FF - plugin: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
FF - plugin: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll
FF - plugin: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL
FF - plugin: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll
FF - plugin: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll
FF - plugin: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
FF - plugin: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrlui.dll
FF - plugin: C:\Program Files (x86)\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
FF - plugin: C:\Program Files (x86)\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
FF - plugin: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll
FF - plugin: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
FF - plugin: C:\Users\Jeff\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll
FF - plugin: C:\Windows\SysWOW64\npDeployJava1.dll
FF - plugin: C:\Windows\SysWOW64\npmproxy.dll
.
============= SERVICES / DRIVERS ===============
.
R0 amd_sata;amd_sata;C:\Windows\System32\drivers\amd_sata.sys [2011-6-17 79488]
R0 amd_xata;amd_xata;C:\Windows\System32\drivers\amd_xata.sys [2011-6-17 40064]
R0 aswKbd;aswKbd;C:\Windows\System32\drivers\aswKbd.sys [2012-8-5 22600]
R0 aswNdis;avast! Firewall NDIS Filter Service;C:\Windows\System32\drivers\aswNdis.sys [2012-8-5 12368]
R0 aswNdis2;avast! Firewall Core Firewall Service;C:\Windows\System32\drivers\aswNdis2.sys [2012-8-5 263096]
R0 aswRvrt;aswRvrt;C:\Windows\System32\drivers\aswRvrt.sys [2013-3-13 65336]
R0 PxHlpa64;PxHlpa64;C:\Windows\System32\drivers\PxHlpa64.sys [2012-8-24 56336]
R1 aswFW;avast! TDI Firewall driver;C:\Windows\System32\drivers\aswFW.sys [2012-8-5 127136]
R1 aswSnx;aswSnx;C:\Windows\System32\drivers\aswSnx.sys [2012-8-5 1025808]
R1 aswSP;aswSP;C:\Windows\System32\drivers\aswSP.sys [2012-8-5 377920]
R1 SASDIFSV;SASDIFSV;C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys [2011-7-22 14928]
R1 SASKUTIL;SASKUTIL;C:\Program Files\SUPERAntiSpyware\saskutil64.sys [2011-7-12 12368]
R2 !SASCORE;SAS Core Service;C:\Program Files\SUPERAntiSpyware\SASCore64.exe [2012-7-11 140672]
R2 ABBYY.Licensing.FineReader.Sprint.9.0;ABBYY FineReader 9.0 Sprint Licensing Service;C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe [2009-5-14 759048]
R2 AMD External Events Utility;AMD External Events Utility;C:\Windows\System32\atiesrxx.exe [2011-9-16 204288]
R2 AMD FUEL Service;AMD FUEL Service;C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe [2011-9-15 361984]
R2 aswFsBlk;aswFsBlk;C:\Windows\System32\drivers\aswFsBlk.sys [2012-8-5 33400]
R2 aswMonFlt;aswMonFlt;C:\Windows\System32\drivers\aswMonFlt.sys [2012-8-5 80816]
R2 avast! Firewall;avast! Firewall;C:\Program Files\AVAST Software\Avast\afwServ.exe [2013-3-13 136912]
R2 cpuz135;cpuz135;C:\Windows\System32\drivers\cpuz135_x64.sys [2012-8-5 23816]
R2 CrossLoopService;CrossLoop Service;C:\Users\Jeff\AppData\Local\CrossLoop\CrossLoopService.exe [2012-11-4 569072]
R2 HP Support Assistant Service;HP Support Assistant Service;C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe [2012-9-27 86528]
R2 HPAuto;HP Auto;C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe [2011-2-16 682040]
R2 HPClientSvc;HP Client Services;C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe [2010-10-11 346168]
R2 HPDrvMntSvc.exe;HP Quick Synchronization Service;C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe [2012-8-10 197536]
R2 HPWMISVC;HPWMISVC;C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe [2012-3-5 35200]
R2 IconMan_R;IconMan_R;C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe [2012-2-13 2424424]
R3 amdiox64;AMD IO Driver;C:\Windows\System32\drivers\amdiox64.sys [2012-2-13 46136]
R3 AtiHDAudioService;ATI Function Driver for HD Audio Service;C:\Windows\System32\drivers\AtihdW76.sys [2011-3-30 114704]
R3 clwvd;CyberLink WebCam Virtual Driver;C:\Windows\System32\drivers\clwvd.sys [2012-8-3 40432]
R3 netr28x;Ralink 802.11n Extensible Wireless Driver;C:\Windows\System32\drivers\netr28x.sys [2012-2-13 1860672]
R3 RSPCIESTOR;Realtek PCIE CardReader Driver;C:\Windows\System32\drivers\RtsPStor.sys [2012-2-13 339048]
R3 RTL8167;Realtek 8167 NT Driver;C:\Windows\System32\drivers\Rt64win7.sys [2012-2-13 539240]
R3 ScreamBAudioSvc;ScreamBee Audio;C:\Windows\System32\drivers\ScreamingBAudio64.sys [2012-7-31 38992]
R3 usbfilter;AMD USB Filter Driver;C:\Windows\System32\drivers\usbfilter.sys [2012-2-13 53376]
S2 avast! Antivirus;avast! Antivirus;C:\Program Files\AVAST Software\Avast\AvastSvc.exe [2013-3-13 45248]
S2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-3-18 130384]
S2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-3-18 138576]
S2 SkypeUpdate;Skype Updater;C:\Program Files (x86)\Skype\Updater\Updater.exe [2013-1-8 161536]
S3 aswVmm;aswVmm;C:\Windows\System32\drivers\aswVmm.sys [2013-3-13 178624]
S3 GamesAppService;GamesAppService;C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe [2010-10-12 206072]
S3 H5xUSB;Roxio GameCAP HD PRO;C:\Windows\System32\drivers\uth5x64.sys [2012-8-2 101632]
S3 hcwE5bda;Hauppauge Siena Video Capture;C:\Windows\System32\drivers\hcwE5bda.sys [2012-9-14 546480]
S3 RoxMediaDBGame1X;RoxMediaDBGame1X;C:\Program Files (x86)\Common Files\Roxio Shared\Game1X\SharedCOM\RoxMediaDBGame1X.exe [2012-8-2 1095824]
S3 SrvHsfHDA;SrvHsfHDA;C:\Windows\System32\drivers\VSTAZL6.SYS [2009-7-13 292864]
S3 SrvHsfV92;SrvHsfV92;C:\Windows\System32\drivers\VSTDPV6.SYS [2009-7-13 1485312]
S3 SrvHsfWinac;SrvHsfWinac;C:\Windows\System32\drivers\VSTCNXT6.SYS [2009-7-13 740864]
S3 SwitchBoard;Adobe SwitchBoard;C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-2-19 517096]
S3 TsUsbFlt;TsUsbFlt;C:\Windows\System32\drivers\TsUsbFlt.sys [2010-11-20 59392]
S3 TsUsbGD;Remote Desktop Generic USB Device;C:\Windows\System32\drivers\TsUsbGD.sys [2010-11-20 31232]
S3 tvnserver;TightVNC Server;C:\Users\Jeff\AppData\Local\CrossLoop\tvnserver.exe [2012-11-4 814080]
S3 WatAdminSvc;Windows Activation Technologies Service;C:\Windows\System32\Wat\WatAdminSvc.exe [2012-8-6 1255736]
S3 WDC_SAM;WD SCSI Pass Thru driver;C:\Windows\System32\drivers\wdcsam64.sys [2008-5-6 14464]
.
=============== Created Last 30 ================
.
2013-04-03 22:47:50 76232 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{06C9692B-8134-4A13-A526-408AC1015F55}\offreg.dll
2013-04-03 22:39:59 7680 —-a-w- C:\ProgramData\Z@!-0b4ddd20-6370-4583-8ce0-d7e64f9cc5cc.tmp
2013-04-03 22:39:59 7168 —-a-w- C:\ProgramData\Z@S!-0668b1b1-c835-4eda-8c21-5b35f8f22c64.tmp
2013-04-03 22:39:45 7168 —-a-w- C:\Users\Jeff\AppData\Local\Z@S!-27cc3793-4e25-4b40-943c-711d0fa80891.tmp
2013-04-03 22:39:44 7680 —-a-w- C:\Users\Jeff\AppData\Local\Z@!-992bf619-60e2-4b91-a83f-692375d67676.tmp
2013-04-03 09:35:05 ——– d—–w- C:\Users\Jeff\AppData\Roaming\Malwarebytes
2013-04-03 09:35:00 ——– d—–w- C:\ProgramData\Malwarebytes
2013-04-03 09:34:59 24176 —-a-w- C:\Windows\System32\drivers\mbam.sys
2013-04-03 09:34:59 ——– d—–w- C:\Program Files (x86)\Malwarebytes' Anti-Malware
2013-04-03 09:29:02 ——– d—–w- C:\Users\Jeff\AppData\Roaming\SUPERAntiSpyware.com
2013-04-03 09:28:57 ——– d—–w- C:\ProgramData\SUPERAntiSpyware.com
2013-04-03 09:28:57 ——– d—–w- C:\Program Files\SUPERAntiSpyware
2013-04-03 09:20:49 9311288 —-a-w- C:\ProgramData\Microsoft\Windows Defender\Definition Updates\{06C9692B-8134-4A13-A526-408AC1015F55}\mpengine.dll
2013-04-03 08:45:07 ——– d—–w- C:\Program Files (x86)\SweetIM
2013-04-03 08:44:21 ——– d—–w- C:\Program Files\Updater By SweetPacks
2013-04-03 08:41:11 ——– d—–w- C:\Users\Jeff\AppData\Roaming\DAEMON Tools Lite
2013-04-03 08:40:18 ——– d—–w- C:\ProgramData\DAEMON Tools Lite
2013-04-03 08:38:32 ——– d—–w- C:\age
2013-03-30 20:08:47 ——– d–h–w- C:\ProgramData\CanonIJScan
2013-03-28 10:19:23 ——– d—–w- C:\Users\Jeff\AppData\Roaming\OrphneDev
2013-03-28 10:19:23 ——– d—–w- C:\Users\Jeff\AppData\Local\OrphneDev
2013-03-25 22:20:29 316416 —-a-w- C:\Windows\SysWow64\CNC_B2L.dll
2013-03-25 22:20:29 102912 —-a-w- C:\Windows\SysWow64\CNC_B2U.dll
2013-03-25 22:20:28 15872 —-a-w- C:\Windows\SysWow64\CNHMCA.dll
2013-03-25 22:20:25 ——– d–h–w- C:\ProgramData\CanonIJFAX
2013-03-25 22:17:25 ——– d—–w- C:\Program Files\Canon
2013-03-25 22:16:17 99840 —-a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPPB2.DLL
2013-03-25 22:16:17 30208 —-a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPDB2.DLL
2013-03-25 22:16:17 30208 —-a-w- C:\Windows\System32\Spool\prtprocs\x64\1_CNMPDB2.DLL
2013-03-25 22:15:38 385024 —-a-w- C:\Windows\System32\CNMLMB2.DLL
2013-03-25 22:15:32 302592 —-a-w- C:\Windows\System32\CNCALB2.DLL
2013-03-25 22:15:23 256000 —-a-w- C:\Windows\System32\CNMIUB2.DLL
2013-03-25 22:06:52 39424 —-a-w- C:\Windows\System32\CNMN6UI.DLL
2013-03-25 22:06:52 363520 —-a-w- C:\Windows\SysWow64\CNMNPPM.DLL
2013-03-25 22:06:52 356864 —-a-w- C:\Windows\System32\CNMN6PPM.DLL
2013-03-18 10:10:55 95648 —-a-w- C:\Windows\SysWow64\WindowsAccessBridge-32.dll
2013-03-16 19:07:55 ——– d–h–w- C:\ProgramData\CanonIJEGV
2013-03-16 01:26:43 ——– d–h–w- C:\ProgramData\CanonIJSolutionMenuEX
2013-03-16 01:26:42 ——– d–h–w- C:\ProgramData\CanonIJEPPEX2
2013-03-16 01:26:42 ——– d–h–w- C:\ProgramData\CanonEPP
2013-03-16 01:18:43 ——– d—–w- C:\ProgramData\Canon IJ Network Tool
2013-03-16 01:18:35 323584 —-a-w- C:\Windows\SysWow64\CNC_ATL.dll
2013-03-16 01:18:35 114688 —-a-w- C:\Windows\SysWow64\CNC_ATU.dll
2013-03-16 01:13:58 ——– d—–w- C:\Program Files\Common Files\CANON
2013-03-16 01:13:50 ——– d—–w- C:\ProgramData\CanonIJWSpt
2013-03-16 01:09:35 98816 —-a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPPAT.DLL
2013-03-16 01:09:35 30208 —-a-w- C:\Windows\System32\Spool\prtprocs\x64\CNMPDAT.DLL
2013-03-16 01:09:20 385536 —-a-w- C:\Windows\System32\CNMLMAT.DLL
2013-03-16 01:09:07 256000 —-a-w- C:\Windows\System32\CNMIUAT.DLL
2013-03-16 01:08:28 ——– d—–w- C:\Windows\System32\STRING
2013-03-16 01:01:41 ——– d—–w- C:\Program Files (x86)\Canon
2013-03-13 21:34:27 65336 —-a-w- C:\Windows\System32\drivers\aswRvrt.sys
2013-03-13 21:34:27 178624 —-a-w- C:\Windows\System32\drivers\aswVmm.sys
.
==================== Find3M ====================
.
2013-03-18 10:10:47 861088 —-a-w- C:\Windows\SysWow64\npDeployJava1.dll
2013-03-18 10:10:47 782240 —-a-w- C:\Windows\SysWow64\deployJava1.dll
2013-03-13 17:51:56 73432 —-a-w- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
2013-03-13 17:51:56 693976 —-a-w- C:\Windows\SysWow64\FlashPlayerApp.exe
2013-03-06 22:33:21 70992 —-a-w- C:\Windows\System32\drivers\aswRdr2.sys
2013-03-06 22:33:21 1025808 —-a-w- C:\Windows\System32\drivers\aswSnx.sys
2013-03-06 22:33:20 80816 —-a-w- C:\Windows\System32\drivers\aswMonFlt.sys
2013-03-06 22:33:20 263096 —-a-w- C:\Windows\System32\drivers\aswNdis2.sys
2013-03-06 22:33:20 22600 —-a-w- C:\Windows\System32\drivers\aswKbd.sys
2013-03-06 22:33:20 127136 —-a-w- C:\Windows\System32\drivers\aswFW.sys
2013-03-06 22:32:51 41664 —-a-w- C:\Windows\avastSS.scr
2013-01-17 08:28:58 273840 —-a-w- C:\Windows\System32\MpSigStub.exe
2013-01-13 21:17:03 9728 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 21:17:02 2560 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 21:16:42 10752 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 21:12:46 3584 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 21:11:21 4096 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 21:11:08 5632 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 21:11:07 5632 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 21:11:07 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 21:11:07 3072 —ha-w- C:\Windows\SysWow64\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:35:31 9728 —ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
2013-01-13 20:35:31 2560 —ha-w- C:\Windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
2013-01-13 20:35:18 10752 —ha-w- C:\Windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
2013-01-13 20:32:07 3584 —ha-w- C:\Windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
2013-01-13 20:31:48 4096 —ha-w- C:\Windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
2013-01-13 20:31:41 5632 —ha-w- C:\Windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
2013-01-13 20:31:40 5632 —ha-w- C:\Windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
2013-01-13 20:31:40 3072 —ha-w- C:\Windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
2013-01-13 20:31:40 3072 —ha-w- C:\Windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
2013-01-13 20:31:00 1247744 —-a-w- C:\Windows\SysWow64\DWrite.dll
2013-01-13 20:22:22 1988096 —-a-w- C:\Windows\SysWow64\d3d10warp.dll
2013-01-13 20:20:31 293376 —-a-w- C:\Windows\SysWow64\dxgi.dll
2013-01-13 20:09:00 249856 —-a-w- C:\Windows\SysWow64\d3d10_1core.dll
2013-01-13 20:08:43 220160 —-a-w- C:\Windows\SysWow64\d3d10core.dll
2013-01-13 20:08:35 1504768 —-a-w- C:\Windows\SysWow64\d3d11.dll
2013-01-13 19:59:04 1643520 —-a-w- C:\Windows\System32\DWrite.dll
2013-01-13 19:58:28 1175552 —-a-w- C:\Windows\System32\FntCache.dll
2013-01-13 19:54:01 604160 —-a-w- C:\Windows\SysWow64\d3d10level9.dll
2013-01-13 19:53:58 207872 —-a-w- C:\Windows\SysWow64\WindowsCodecsExt.dll
2013-01-13 19:53:14 187392 —-a-w- C:\Windows\SysWow64\UIAnimation.dll
2013-01-13 19:51:30 2565120 —-a-w- C:\Windows\System32\d3d10warp.dll
2013-01-13 19:49:17 363008 —-a-w- C:\Windows\System32\dxgi.dll
2013-01-13 19:48:47 161792 —-a-w- C:\Windows\SysWow64\d3d10_1.dll
2013-01-13 19:46:25 1080832 —-a-w- C:\Windows\SysWow64\d3d10.dll
2013-01-13 19:43:21 1230336 —-a-w- C:\Windows\SysWow64\WindowsCodecs.dll
2013-01-13 19:38:39 333312 —-a-w- C:\Windows\System32\d3d10_1core.dll
2013-01-13 19:38:32 1887232 —-a-w- C:\Windows\System32\d3d11.dll
2013-01-13 19:38:21 296960 —-a-w- C:\Windows\System32\d3d10core.dll
2013-01-13 19:37:57 3419136 —-a-w- C:\Windows\SysWow64\d2d1.dll
2013-01-13 19:25:04 245248 —-a-w- C:\Windows\System32\WindowsCodecsExt.dll
2013-01-13 19:24:33 648192 —-a-w- C:\Windows\System32\d3d10level9.dll
2013-01-13 19:24:30 221184 —-a-w- C:\Windows\System32\UIAnimation.dll
2013-01-13 19:20:42 194560 —-a-w- C:\Windows\System32\d3d10_1.dll
2013-01-13 19:20:04 1238528 —-a-w- C:\Windows\System32\d3d10.dll
2013-01-13 19:15:40 1424384 —-a-w- C:\Windows\System32\WindowsCodecs.dll
2013-01-13 19:10:36 3928064 —-a-w- C:\Windows\System32\d2d1.dll
2013-01-13 19:02:06 417792 —-a-w- C:\Windows\SysWow64\WMPhoto.dll
2013-01-13 18:34:58 364544 —-a-w- C:\Windows\SysWow64\XpsGdiConverter.dll
2013-01-13 18:32:43 465920 —-a-w- C:\Windows\System32\WMPhoto.dll
2013-01-13 18:09:52 522752 —-a-w- C:\Windows\System32\XpsGdiConverter.dll
2013-01-13 17:26:42 1158144 —-a-w- C:\Windows\SysWow64\XpsPrint.dll
2013-01-13 17:05:09 1682432 —-a-w- C:\Windows\System32\XpsPrint.dll
2013-01-09 01:19:09 2312704 —-a-w- C:\Windows\System32\jscript9.dll
2013-01-09 01:12:03 1392128 —-a-w- C:\Windows\System32\wininet.dll
2013-01-09 01:11:06 1494528 —-a-w- C:\Windows\System32\inetcpl.cpl
2013-01-09 01:07:51 173056 —-a-w- C:\Windows\System32\ieUnatt.exe
2013-01-09 01:07:47 599040 —-a-w- C:\Windows\System32\vbscript.dll
2013-01-09 01:04:42 2382848 —-a-w- C:\Windows\System32\mshtml.tlb
2013-01-08 22:11:21 1800704 —-a-w- C:\Windows\SysWow64\jscript9.dll
2013-01-08 22:03:20 1129472 —-a-w- C:\Windows\SysWow64\wininet.dll
2013-01-08 22:03:12 1427968 —-a-w- C:\Windows\SysWow64\inetcpl.cpl
2013-01-08 21:59:02 142848 —-a-w- C:\Windows\SysWow64\ieUnatt.exe
2013-01-08 21:58:29 420864 —-a-w- C:\Windows\SysWow64\vbscript.dll
2013-01-08 21:56:23 2382848 —-a-w- C:\Windows\SysWow64\mshtml.tlb
2013-01-05 05:53:43 5553512 —-a-w- C:\Windows\System32\ntoskrnl.exe
2013-01-05 05:00:15 3967848 —-a-w- C:\Windows\SysWow64\ntkrnlpa.exe
2013-01-05 05:00:11 3913064 —-a-w- C:\Windows\SysWow64\ntoskrnl.exe
2013-01-04 06:11:21 2284544 —-a-w- C:\Windows\SysWow64\msmpeg2vdec.dll
2013-01-04 06:11:13 2776576 —-a-w- C:\Windows\System32\msmpeg2vdec.dll
2013-01-04 05:46:09 215040 —-a-w- C:\Windows\System32\winsrv.dll
2013-01-04 04:51:16 5120 —-a-w- C:\Windows\SysWow64\wow32.dll
2013-01-04 04:43:21 44032 —-a-w- C:\Windows\apppatch\acwow64.dll
2013-01-04 03:26:48 3153408 —-a-w- C:\Windows\System32\win32k.sys
2013-01-04 02:47:35 25600 —-a-w- C:\Windows\SysWow64\setup16.exe
2013-01-04 02:47:34 7680 —-a-w- C:\Windows\SysWow64\instnm.exe
2013-01-04 02:47:34 2048 —-a-w- C:\Windows\SysWow64\user.exe
2013-01-04 02:47:33 14336 —-a-w- C:\Windows\SysWow64\ntvdm64.dll
.
============= FINISH: 16:36:17.78 ===============

Attachments:

Hi jeff matthews,

This certainly does sound like a scam. About the only accurate information was not to use CCleaner the rest plays out like a classic "clean your computer for a fee" scam. Where did you get the conact information for Avast?

Since you've let an unknown person have access to your computer, I strongly suggest you change All of your passwords to any forums, financial institutes you deal with online. You may also want to closely watch any of your accounts for any suspicious activity.

Besides Avast being disabled where you experiencing any problems?

When should have your subscription to Avast expired?
I really don't think this was a scam unless the person at avast was scamming me which i don't think is the case, this is the contact information i used. This is the official legitimate avast website, some companies use remote connection as means to anylize your computer. Though i have been scammed before in the past with such type of activities but its usually them calling me on the phone and explain to me something is wrong with my pc so their for they got my attention and thats how they scam you to gain access to your pc.

This is the contact number and website i used.

http://www.avast.com/en-us/contacts

This is the remote connection URL that they used to remote connect to my pc.

http://gan.doubleclick.net/. I don't think it works right now because it only worked when they were taking to me on the phone. As soon as i get disconnected, they closed the remote connection on the spot.

These problems happened before i contacted avast, its the whole reason i was contacting avast in the first place was because my license expired and they specifically told me it doesn't expire until like June 2013. But i had many other issues as i stated above. Through the remote connection they anylized my pc and came to these conclusions that my registry was damaged. They checked a few charts that i was not even aware of that was part of windows 7, but it shown where their was alots of errors and like a graph that shows the health of the computer.

Anyways i really need to get this fixed, because my pc is having issues right now. I can't have a firewall that does not work, also the iyogee support dock application they were taking bout. I did a research on that online and it appears that is a scam attempt but i had that before i called avast.

Does my DDS report show any signs of infections or viruses, i know i did a scan of superantivirus and it found 20 infections, but it ran for like 5 hrs, so i stopped it. But i am not sure if that application is legitimate or not.

I also mentioned before that many of my applications in my services as the Representative pointed out when he was connected to my pc all stopped working and thats definitively not a good thing.
Ok wait a min wait a min. That gandouble click was wrong, i think that was something that was actually wrong with my computer that he was looking at or showing me.

This link is how he remote connected to me

http://ts.avast.com/en-us/

Its in the history of my IE explorer

It sounds pretty legitimate to me, if your not sure, can you please contact someone that might know. thanks!
Hi jeff matthews,

iYogi Support Dock

This was a support service that Avast did use in the past. I don't think they use it anymore when it became apparant that iYogi was more interested in selling premium support services rather than helping avast customers. You probably got this if you previously installed avast about a year or so ago.

If you are interested in reformatting the computer and reinstall the OS that will not be a problem. I don't know what the tech was trying to tell you but a format will remove the registry. The registry is part of windows so when windows goes so does all of it components. Besides a reformat will remove everything oon the drive.

Depending on your computer it may have a restore partition. This will put the computer back to the state it was shipped from the factory. Any personal data, programs, etc would be lost so you will need to ensure you have proper backups of anything you wan to keep.

Let me know how you want to procede.

Just a FYI. PlumChoice isn't a part of Avast but rather it's an independant fee for sevice that does support.
Yeah when i heard that even a format would not fixed my damaged registry, i was a bit suspicious of that. I have never heard of such a thing before. Maybe he was just trying to sell me his services. Even though it was not a scan and a legitimate company, i guess technicians will go to great lengths, even telling you a flat out lie to be able to sell you their services and fix your computer. Yeah i do have a restore partition i think on here, my laptop manufacturer specifically told me that a clean deleting of the partition table on windows 7 would cause my computer to not work any more because i would not have windows 7 installed on here and it came with windows 7 so the only way to restore it is to use the restore partition. Is their anyway to fix the problem with out formatting? Because honestly i had alot of different things set up on this pc to have it run just the way i like it, certain things like video codocs installed to be able to play those high quality 10p video's. It took me like a 10 page tutorial to set this up the right way with out having to use those codec packs that usually cause errors and BSOD crashes. I also had alot of passwords and user id's saved on this computer. I don't quite remember all of them. I have media servers and video capture modules that are configured just the right way to run through my router and that was a real pain setting all that up. But if this is the only way for me to fix my problem then i'll do it, its just going to be quite the work to be able to get my computer back and running with all of those software and configurations that i had before. Is this actually a virus issue, because you make it sound like its not, usually when i use show a DDS log the techs here can point out that their is obvously a virus or maleware on the machine, but you make it sound like its something more serous as a clean install is the only way to remove the problem, can you be more specific what exactly is going on with my machine and believe me if the only solution is to format or if its the best, then i will do it. But some how i have to back up all of the password id and bank information i used, i have loads of passwords and ID's i used on this machine that are important.
Hi jeff matthews,

IMO this tech was using scare tactics to sell you support.

Nothing jumps out from the DDS log. Please describe the symptoms you are experiencing.

Check to see if Avast did indeed expire.
  • right click the Avast icon
  • click about Avast
  • click the summary button
  • what is the expiration date? (you may need to click show details)

Let's get a better log at this machine.

Download aswMBR.exe to your desktop.

Double click the aswMBR.exe to run it. If asked to download Avast's database please do so.

Click the "Scan" button to start scan
[external image: Posted Image]

On completion of the scan click save log, save it to your desktop and post in your next reply
[external image: Posted Image]

There shall also be a file on your desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) folder. Please attach that zipped file in your next reply.

Next

Download OTL to your desktop.
  • Right click on OTL.exe and click "Run as Administrator" to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output make sure it is set to Standard Output
  • check the boc beside "scan all users"
  • Check the boxes beside LOP Check and Purity Check.
  • In the window under Custom Scans/Fixes copy and paste the following


    netsvcs
    %SYSTEMDRIVE%\*.*
    %systemroot%\Fonts\*.com
    %systemroot%\Fonts\*.dll
    %systemroot%\Fonts\*.ini
    %systemroot%\Fonts\*.ini2
    %systemroot%\Fonts\*.exe
    %systemroot%\system32\spool\prtprocs\w32x86\*.*
    %systemroot%\REPAIR\*.bak1
    %systemroot%\REPAIR\*.ini
    %systemroot%\system32\*.jpg
    %systemroot%\*.jpg
    %systemroot%\*.png
    %systemroot%\*.scr
    %systemroot%\*._sy
    %APPDATA%\Adobe\Update\*.*
    %ALLUSERSPROFILE%\Favorites\*.*
    %APPDATA%\Microsoft\*.*
    %PROGRAMFILES%\*.*
    %APPDATA%\Update\*.*
    %systemroot%\*. /mp /s
    CREATERESTOREPOINT
    %systemroot%\System32\config\*.sav
    %PROGRAMFILES%\bak. /s
    %systemroot%\system32\bak. /s
    %ALLUSERSPROFILE%\Start Menu\*.lîk /x
    %systemroot%\system32\config\systemprofile\*.dat /x
    %systemroot%\*.config
    %systemroot%\system32\*.db
    %PROGRAMFILES%\Internet Explorer\*.dat
    %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x
    %USERPROFILE%\Deskuop\*.exe
    %PROGRAMFILES%\Common Files\*.*
    %systemroot%\*.src
    %systemroot%\install\*.*
    %systemroot%\system32\DLL\*.*
    %systemroot%\system32\HelpFiles\*.*
    %systemroot%\system32\rundll\*.*
    %systemroot%\winn32\*.*
    %systemroot%\Java\*.*
    %systemroot%\system32\test\*.*
    %systemroot%\system32\Rundll32\*.*
    HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU
    HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    /md5start
    iexplore.*
    explorer.*
    winlogon.*
    dll
    zx.dll
    hlp.dat
    consrv.dll
    services.*
    /md5stop

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.

Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them all in.

Please post back with
  • aswMBR log
  • both OTL logs
Ok as far as symptoms, nothing that i really experience that is slowing down my computer. How ever i did have that issue with "Updater sweetpacks" That i saw the moment i opened up my browser and it started rerouting certain URLS's but its not doing it now so maybe its gone im not sure?

Superantispyware how ever found some like 30 infections but i am not sure if those are real or not. In fact i might just delete that superantispyware. The Iyogee Dock is still in my registry probably. I want to make sure i get rid of that. I did check my avast it said "expiration active" but it also said "0 days remaining" I checked my lisence file the moment i bought avast, and it clearly should not be over a year old , i so tried to install that lisencefile.lic into my avast and it says "unable to find file, the system can't specify the file" I also have that CCcleaner in my system as well that i used what is your take on that, do you think i should remove that?


I am pretty irritated at the fact that some one, a professional company would use deception and lies to try and get you purchase their product. In any case, like i said i searched my license file and i bought it in may 2012, that means it should expire next month and not now, it doesn't many any sense to me.


Here is my aswMBR log

It has a few errors in regards to trying to download the avast definitions.

aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-04-04 22:47:37
—————————–
22:47:37.405 OS Version: Windows x64 6.1.7601 Service Pack 1
22:47:37.405 Number of processors: 4 586 0x100
22:47:37.406 ComputerName: JEFF-HP UserName: Jeff
22:47:38.823 Initialize success
22:50:13.250 AVAST engine error: 2
22:50:23.296 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000073
22:50:23.301 Disk 0 Vendor: ST950032 0005 Size: 476940MB BusType: 11
22:50:23.420 Disk 0 MBR read successfully
22:50:23.426 Disk 0 MBR scan
22:50:23.433 Disk 0 Windows 7 default MBR code
22:50:23.451 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
22:50:23.457 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 451351 MB offset 409600
22:50:23.487 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 21325 MB offset 924776448
22:50:23.505 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 4063 MB offset 968450048
22:50:23.650 Disk 0 scanning C:\Windows\system32\drivers
22:50:32.991 Service scanning
22:50:55.497 Modules scanning
22:50:55.507 Disk 0 trace - called modules:
22:50:55.573 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
22:50:55.587 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007192060]
22:50:55.599 3 CLASSPNP.SYS[fffff8800195443f] -> nt!IofCallDriver -> [0xfffffa8006b7c590]
22:50:55.607 5 amd_xata.sys[fffff880010f9b3f] -> nt!IofCallDriver -> \Device\00000073[0xfffffa8006b79060]
22:50:55.613 Scan finished successfully
22:51:07.666 Disk 0 MBR has been saved successfully to "C:\Users\Jeff\Desktop\MBR.dat"
22:51:07.673 The log file has been saved successfully to "C:\Users\Jeff\Desktop\aswMBR.txt"

Here are the OTL logs

OTL logfile created on: 4/4/2013 11:07:03 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jeff\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.48 Gb Total Physical Memory | 4.42 Gb Available Physical Memory | 59.08% Memory free
14.96 Gb Paging File | 11.15 Gb Available in Paging File | 74.57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 440.77 Gb Total Space | 194.88 Gb Free Space | 44.21% Space Free | Partition Type: NTFS
Drive D: | 20.83 Gb Total Space | 2.25 Gb Free Space | 10.79% Space Free | Partition Type: NTFS
Drive E: | 3.96 Gb Total Space | 3.95 Gb Free Space | 99.77% Space Free | Partition Type: FAT32

Computer Name: JEFF-HP | User Name: Jeff | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/04/04 22:59:52 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Jeff\Desktop\OTL.exe
PRC - [2013/03/12 00:05:50 | 029,106,336 | —- | M] (Dropbox, Inc.) – C:\Users\Jeff\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013/03/06 15:32:44 | 004,767,304 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013/03/06 15:32:42 | 000,136,912 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2012/12/18 07:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/11/29 19:06:58 | 001,263,512 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2012/10/25 21:12:06 | 000,139,792 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2012/08/10 16:48:50 | 000,197,536 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
PRC - [2012/03/05 13:38:38 | 000,578,944 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
PRC - [2012/03/05 13:38:38 | 000,035,200 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
PRC - [2012/01/06 09:35:22 | 000,569,072 | —- | M] (CrossLoop) – C:\Users\Jeff\AppData\Local\CrossLoop\CrossLoopService.exe
PRC - [2011/10/07 19:10:48 | 000,169,528 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
PRC - [2011/09/27 11:44:20 | 000,439,440 | —- | M] (CANON INC.) – C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
PRC - [2011/08/19 14:48:44 | 000,379,960 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
PRC - [2011/08/04 14:44:24 | 000,593,032 | —- | M] (CANON INC.) – C:\Program Files (x86)\Canon\Solution Menu EX\CNSEUPDT.EXE
PRC - [2011/08/04 14:41:44 | 001,637,496 | —- | M] (CANON INC.) – C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
PRC - [2009/07/20 11:51:52 | 000,935,208 | —- | M] (Nero AG) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2009/05/14 18:07:14 | 000,759,048 | —- | M] (ABBYY) – C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
PRC - [2002/12/17 17:26:22 | 007,520,337 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe


========== Modules (No Company Name) ==========

MOD - [2013/03/21 15:50:33 | 000,390,096 | —- | M] () – C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\ppgooglenaclpluginchrome.dll
MOD - [2013/03/21 15:50:32 | 012,662,224 | —- | M] () – C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\PepperFlash\pepflashplayer.dll
MOD - [2013/03/21 15:50:31 | 004,050,896 | —- | M] () – C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\pdf.dll
MOD - [2013/03/21 15:49:41 | 000,598,480 | —- | M] () – C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\libglesv2.dll
MOD - [2013/03/21 15:49:40 | 000,124,368 | —- | M] () – C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\libegl.dll
MOD - [2013/03/21 15:49:38 | 001,606,096 | —- | M] () – C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\ffmpegsumo.dll
MOD - [2013/01/08 12:35:41 | 011,493,376 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2012/11/29 19:07:48 | 000,100,248 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2012/11/29 19:06:58 | 001,263,512 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2011/03/17 00:11:16 | 004,297,568 | —- | M] () – C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 15:45:26 | 008,801,120 | —- | M] () – C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll


========== Services (SafeList) ==========

SRV:64bit: - [2013/03/06 15:32:44 | 000,045,248 | —- | M] (AVAST Software) [Auto | Stopped] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV:64bit: - [2013/03/06 15:32:42 | 000,136,912 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\afwServ.exe – (avast! Firewall)
SRV:64bit: - [2012/07/11 11:54:58 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore64.exe – (!SASCORE)
SRV:64bit: - [2011/09/16 03:12:12 | 000,204,288 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:64bit: - [2011/09/15 15:15:44 | 000,361,984 | —- | M] (Advanced Micro Devices, Inc.) [Auto | Running] – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe – (AMD FUEL Service)
SRV:64bit: - [2011/09/08 06:42:28 | 000,305,152 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Program Files\IDT\WDM\stacsv64.exe – (STacSV)
SRV:64bit: - [2011/02/16 22:47:28 | 000,682,040 | —- | M] (Hewlett-Packard) [Auto | Running] – C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe – (HPAuto)
SRV:64bit: - [2010/10/11 02:48:14 | 000,346,168 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe – (HPClientSvc)
SRV:64bit: - [2009/07/13 18:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2013/03/13 10:51:57 | 000,253,656 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/03/07 07:30:44 | 000,115,608 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2013/01/08 13:53:48 | 000,161,536 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/12/18 07:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/09/27 12:55:16 | 000,086,528 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe – (HP Support Assistant Service)
SRV - [2012/08/10 16:48:50 | 000,197,536 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe – (HPDrvMntSvc.exe)
SRV - [2012/08/02 11:56:54 | 001,095,824 | —- | M] (Corel Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\Game1X\SharedCOM\RoxMediaDBGame1X.exe – (RoxMediaDBGame1X)
SRV - [2012/03/05 13:38:38 | 000,035,200 | —- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe – (HPWMISVC)
SRV - [2012/01/06 09:35:22 | 000,569,072 | —- | M] (CrossLoop) [Auto | Running] – C:\Users\Jeff\AppData\Local\CrossLoop\CrossLoopService.exe – (CrossLoopService)
SRV - [2011/08/29 11:02:22 | 002,424,424 | —- | M] (Realsil Microelectronics Inc.) [Auto | Running] – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe – (IconMan_R)
SRV - [2010/10/12 10:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2010/07/21 08:50:26 | 000,814,080 | —- | M] (GlavSoft LLC.) [On_Demand | Stopped] – C:\Users\Jeff\AppData\Local\CrossLoop\tvnserver.exe – (tvnserver)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 13:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2009/07/20 11:51:52 | 000,935,208 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0)
SRV - [2009/06/10 14:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/05/14 18:07:14 | 000,759,048 | —- | M] (ABBYY) [Auto | Running] – C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.FineReader.Sprint.9.0)
SRV - [2002/12/17 17:26:22 | 007,520,337 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe – (MSSQL$SONY_MEDIAMGR)
SRV - [2002/12/17 17:23:30 | 000,311,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE – (SQLAgent$SONY_MEDIAMGR)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/03/06 15:33:21 | 001,025,808 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\SysNative\drivers\aswSnx.sys – (aswSnx)
DRV:64bit: - [2013/03/06 15:33:21 | 000,377,920 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswSP.sys – (aswSP)
DRV:64bit: - [2013/03/06 15:33:21 | 000,178,624 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\aswVmm.sys – (aswVmm)
DRV:64bit: - [2013/03/06 15:33:21 | 000,070,992 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswRdr2.sys – (aswRdr)
DRV:64bit: - [2013/03/06 15:33:21 | 000,068,920 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswTdi.sys – (aswTdi)
DRV:64bit: - [2013/03/06 15:33:21 | 000,065,336 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswRvrt.sys – (aswRvrt)
DRV:64bit: - [2013/03/06 15:33:20 | 000,263,096 | —- | M] (AVAST Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis2.sys – (aswNdis2)
DRV:64bit: - [2013/03/06 15:33:20 | 000,127,136 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswFW.sys – (aswFW)
DRV:64bit: - [2013/03/06 15:33:20 | 000,080,816 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswMonFlt.sys – (aswMonFlt)
DRV:64bit: - [2013/03/06 15:33:20 | 000,033,400 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswFsBlk.sys – (aswFsBlk)
DRV:64bit: - [2013/03/06 15:33:20 | 000,022,600 | —- | M] (AVAST Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswKbd.sys – (aswKbd)
DRV:64bit: - [2012/08/15 06:16:06 | 000,546,480 | —- | M] (Hauppauge Computer Work, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcwE5bda.sys – (hcwE5bda)
DRV:64bit: - [2012/08/03 18:49:18 | 000,040,432 | —- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\clwvd.sys – (clwvd)
DRV:64bit: - [2012/08/02 11:18:08 | 000,101,632 | —- | M] (UT) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\uth5x64.sys – (H5xUSB)
DRV:64bit: - [2012/07/31 11:45:10 | 000,038,992 | —- | M] (Screaming Bee LLC) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\ScreamingBAudio64.sys – (ScreamBAudioSvc)
DRV:64bit: - [2012/07/10 03:01:00 | 000,056,336 | —- | M] (Corel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:64bit: - [2012/06/27 13:33:54 | 000,012,368 | —- | M] (ALWIL Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis.sys – (aswNdis)
DRV:64bit: - [2012/04/12 19:45:04 | 001,860,672 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\netr28x.sys – (netr28x)
DRV:64bit: - [2012/03/09 10:57:36 | 000,023,816 | —- | M] (CPUID) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\cpuz135_x64.sys – (cpuz135)
DRV:64bit: - [2012/02/29 23:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:64bit: - [2011/10/25 20:53:55 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:64bit: - [2011/10/25 20:53:55 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:64bit: - [2011/09/16 03:51:12 | 010,206,208 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:64bit: - [2011/09/16 02:38:42 | 000,317,952 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:64bit: - [2011/09/08 06:42:28 | 000,535,040 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\stwrt64.sys – (STHDA)
DRV:64bit: - [2011/08/29 11:02:28 | 000,339,048 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\RtsPStor.sys – (RSPCIESTOR)
DRV:64bit: - [2011/08/18 05:44:46 | 000,053,376 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\usbfilter.sys – (usbfilter)
DRV:64bit: - [2011/07/22 09:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:64bit: - [2011/07/21 20:01:14 | 001,448,496 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:64bit: - [2011/07/12 14:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:64bit: - [2011/06/17 04:08:26 | 000,040,064 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amd_xata.sys – (amd_xata)
DRV:64bit: - [2011/06/17 04:08:24 | 000,079,488 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amd_sata.sys – (amd_sata)
DRV:64bit: - [2011/06/10 15:34:52 | 000,539,240 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:64bit: - [2011/03/30 15:46:46 | 000,114,704 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtihdW76.sys – (AtiHDAudioService)
DRV:64bit: - [2010/11/20 20:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:64bit: - [2010/11/20 20:23:47 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:64bit: - [2010/11/20 20:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:64bit: - [2010/11/20 20:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:64bit: - [2010/02/18 10:18:24 | 000,046,136 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\amdiox64.sys – (amdiox64)
DRV:64bit: - [2009/07/13 18:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:64bit: - [2009/07/13 18:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:64bit: - [2009/07/13 18:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:64bit: - [2009/07/13 17:35:32 | 000,012,288 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\serscan.sys – (StillCam)
DRV:64bit: - [2009/06/10 14:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:64bit: - [2009/06/10 14:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:64bit: - [2009/06/10 14:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:64bit: - [2009/06/10 13:35:35 | 000,408,960 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\nvm62x64.sys – (NVENETFD)
DRV:64bit: - [2009/06/10 13:34:38 | 001,311,232 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:64bit: - [2009/06/10 13:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:64bit: - [2009/06/10 13:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:64bit: - [2009/06/10 13:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:64bit: - [2009/06/10 13:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:64bit: - [2008/05/06 16:06:00 | 000,014,464 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\wdcsam64.sys – (WDC_SAM)
DRV - [2009/07/13 18:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{4D7A8A72-5294-44C3-A010-B60E1A356E88}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11…w={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKLM\..\SearchScopes\{4D7A8A72-5294-44C3-A010-B60E1A356E88}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11…w={searchTerms}


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.iyogi.com/
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{4D7A8A72-5294-44C3-A010-B60E1A356E88}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{5AA0FB2F-45B5-4b28-8E51-261F7382C1A8}: "URL" = http://search.iyogi.com/search.html?hl=en&…q={searchTerms}
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11…w={searchTerms}
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files (x86)\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files (x86)\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Jeff\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Jeff\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/12/23 23:38:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/28 03:15:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

[2013/03/28 03:16:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Jeff\AppData\Roaming\Mozilla\Extensions
[2013/04/03 01:43:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\9odu2h93.default\extensions
[2013/04/03 01:43:46 | 000,195,574 | —- | M] () (No name found) – C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\9odu2h93.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
[2013/04/03 01:43:08 | 000,000,514 | —- | M] () – C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\9odu2h93.default\searchplugins\sweetim.xml
[2013/03/28 03:15:49 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/03/07 07:31:00 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013/03/07 07:30:20 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/03/07 07:30:20 | 000,002,086 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}
{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Jeff\AppData\Local\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Users\Jeff\AppData\Local\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\\npsitesafety.dll
CHR - plugin: Java™ Platform SE 7 U7 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Jeff\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: WOT = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.11_0\
CHR - Extension: Updater By SweetPacks = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.566_0\
CHR - Extension: AdBlock = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.61_0\
CHR - Extension: avast! WebRep = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\8.0.1483_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: WOT = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.11_0\
CHR - Extension: Updater By SweetPacks = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.566_0\
CHR - Extension: AdBlock = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.61_0\
CHR - Extension: avast! WebRep = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\8.0.1483_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\

Hosts file not found
O2:64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3:64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:64bit: - HKLM..\Run: [SetDefault] C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe (Hewlett-Packard Development Company, L.P.)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPQuickWebProxy] C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (CANON INC.)
O4 - HKLM..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\isuspm.exe (Flexera Software, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\.DEFAULT..\Run: [Bomgar_Cleanup_ZD7101125413] cmd.exe /C rd /S /Q "C:\ProgramData\iyogi-scc-0000000050C671CB" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD7101125413 /f File not found
O4 - HKU\S-1-5-18..\Run: [Bomgar_Cleanup_ZD7101125413] cmd.exe /C rd /S /Q "C:\ProgramData\iyogi-scc-0000000050C671CB" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD7101125413 /f File not found
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001..\Run: [Bomgar_Cleanup_ZD463527019543] cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-00000000515CAF96" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD463527019543 /f File not found
O4 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001..\Run: [Mal Updater 2] C:\Program Files (x86)\Mal Updater 2\MalUpdater.exe (eden.fm)
O4 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001..\Run: [ONAIR] C:\Program Files\ONAIR\ONAIR.exe (DJMASTER.COM)
O4 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Jeff\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 3
O7 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionAction = http://hp.digitalriver.com/DRHM/store?Acti…amp;keywords=%w
O7 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionName = Find Software on HP Download Store (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E374F5FE-C5BF-433D-9148-D474298D024F}: DhcpNameServer = 192.168.0.1 [removed]
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:64bit: - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18:64bit: - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{6b375e4c-4b0d-11e2-abc7-78e3b5677f68}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{6b375e4c-4b0d-11e2-abc7-78e3b5677f68}\Shell\phone\command - "" = G:\autorun.exe
O33 - MountPoints2\{8d737620-f5f8-11e1-be5e-78e3b5677f68}\Shell - "" = AutoRun
O33 - MountPoints2\{8d737620-f5f8-11e1-be5e-78e3b5677f68}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\G\Shell\phone\command - "" = G:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/04/04 23:00:21 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Jeff\Desktop\OTL.exe
[2013/04/04 22:47:31 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Jeff\Desktop\aswMBR.exe
[2013/04/03 16:23:56 | 000,688,992 | R— | C] (Swearware) – C:\Users\Jeff\Desktop\dds.com
[2013/04/03 02:35:05 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\Malwarebytes
[2013/04/03 02:35:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/04/03 02:35:00 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/04/03 02:34:59 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/04/03 02:34:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/04/03 02:29:02 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\SUPERAntiSpyware.com
[2013/04/03 02:29:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2013/04/03 02:28:57 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2013/04/03 02:28:57 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2013/04/03 01:45:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\SweetIM
[2013/04/03 01:44:21 | 000,000,000 | —D | C] – C:\Program Files\Updater By SweetPacks
[2013/04/03 01:41:11 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\DAEMON Tools Lite
[2013/04/03 01:40:18 | 000,000,000 | —D | C] – C:\ProgramData\DAEMON Tools Lite
[2013/04/03 01:38:32 | 000,000,000 | —D | C] – C:\age
[2013/03/31 18:38:18 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2013/03/30 13:08:47 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonIJScan
[2013/03/28 03:19:23 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\OrphneDev
[2013/03/28 03:19:23 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Local\OrphneDev
[2013/03/28 03:15:56 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\Mozilla
[2013/03/28 03:15:56 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Local\Mozilla
[2013/03/28 03:15:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2013/03/28 03:15:51 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2013/03/28 03:15:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/03/25 15:20:29 | 000,316,416 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNC_B2L.dll
[2013/03/25 15:20:29 | 000,102,912 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNC_B2U.dll
[2013/03/25 15:20:28 | 000,015,872 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNHMCA.dll
[2013/03/25 15:20:25 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonIJFAX
[2013/03/25 15:17:25 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2013/03/25 15:17:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX510 series Manual
[2013/03/25 15:16:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX510 series
[2013/03/25 15:15:38 | 000,385,024 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMLMB2.DLL
[2013/03/25 15:15:32 | 000,302,592 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNCALB2.DLL
[2013/03/25 15:15:23 | 000,256,000 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMIUB2.DLL
[2013/03/25 15:06:52 | 000,363,520 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNMNPPM.DLL
[2013/03/25 15:06:52 | 000,356,864 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMN6PPM.DLL
[2013/03/25 15:06:52 | 000,039,424 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMN6UI.DLL
[2013/03/24 14:28:04 | 000,000,000 | —D | C] – C:\Users\Public\Documents\YouCam
[2013/03/24 14:26:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\CyberLink
[2013/03/18 03:11:06 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/18 03:10:55 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/03/18 03:10:55 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/03/18 03:10:55 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/03/18 03:10:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2013/03/16 12:07:55 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonIJEGV
[2013/03/15 18:26:43 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonIJSolutionMenuEX
[2013/03/15 18:26:42 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonIJEPPEX2
[2013/03/15 18:26:42 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonEPP
[2013/03/15 18:26:41 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\Canon
[2013/03/15 18:18:43 | 000,000,000 | —D | C] – C:\ProgramData\Canon IJ Network Tool
[2013/03/15 18:18:35 | 000,323,584 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNC_ATL.dll
[2013/03/15 18:18:35 | 000,114,688 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNC_ATU.dll
[2013/03/15 18:18:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG5300 series User Registration
[2013/03/15 18:13:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\CANON
[2013/03/15 18:13:50 | 000,000,000 | —D | C] – C:\ProgramData\CanonIJWSpt
[2013/03/15 18:10:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
[2013/03/15 18:10:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG5300 series Manual
[2013/03/15 18:09:36 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonBJ
[2013/03/15 18:09:32 | 000,000,000 | -H-D | C] – C:\Windows\SysNative\CanonIJ Uninstaller Information
[2013/03/15 18:09:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG5300 series
[2013/03/15 18:09:20 | 000,385,536 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMLMAT.DLL
[2013/03/15 18:09:07 | 000,256,000 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMIUAT.DLL
[2013/03/15 18:08:52 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2013/03/15 18:08:28 | 000,000,000 | —D | C] – C:\Windows\SysNative\STRING
[2013/03/15 18:01:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Canon
[2 C:\Users\Jeff\AppData\Local\*.tmp files -> C:\Users\Jeff\AppData\Local\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Jeff\Documents\*.tmp files -> C:\Users\Jeff\Documents\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/04/04 22:59:52 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Jeff\Desktop\OTL.exe
[2013/04/04 22:57:53 | 000,000,616 | —- | M] () – C:\Users\Jeff\Desktop\MBR.dat.zip
[2013/04/04 22:51:07 | 000,000,512 | —- | M] () – C:\Users\Jeff\Desktop\MBR.dat
[2013/04/04 22:48:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/04/04 22:47:17 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Jeff\Desktop\aswMBR.exe
[2013/04/04 22:34:14 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/04/04 22:34:14 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/04/04 22:34:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3952182868-3481799418-86632157-1001UA.job
[2013/04/04 22:18:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/04/04 20:39:12 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3952182868-3481799418-86632157-1001Core.job
[2013/04/04 20:39:09 | 000,000,508 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 9edf46f8-117b-4316-8207-00d73e1f4f99.job
[2013/04/04 02:49:42 | 000,000,508 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 45900836-9099-4415-9664-708fec098603.job
[2013/04/03 16:22:42 | 000,688,992 | R— | M] (Swearware) – C:\Users\Jeff\Desktop\dds.com
[2013/04/03 03:11:25 | 1728,241,663 | -HS- | M] () – C:\hiberfil.sys
[2013/04/03 03:02:32 | 000,805,108 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/04/03 03:02:32 | 000,678,148 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/04/03 03:02:32 | 000,128,898 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/04/03 02:36:26 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/04/03 02:29:00 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2013/04/03 02:20:32 | 000,001,047 | —- | M] () – C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/04/03 02:20:23 | 000,001,013 | —- | M] () – C:\Users\Jeff\Desktop\Dropbox.lnk
[2013/04/01 20:17:02 | 000,087,592 | —- | M] () – C:\Users\Jeff\Desktop\gamelist Organized by hrs.rtf
[2013/03/29 18:31:15 | 000,002,358 | —- | M] () – C:\Users\Jeff\Desktop\Google Chrome.lnk
[2013/03/28 03:15:52 | 000,001,147 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/03/25 15:19:36 | 000,002,075 | —- | M] () – C:\Users\Public\Desktop\Canon Solution Menu EX.lnk
[2013/03/25 15:17:04 | 000,002,354 | —- | M] () – C:\Users\Public\Desktop\Canon MX510 series On-screen Manual.lnk
[2013/03/24 14:28:09 | 000,001,361 | —- | M] () – C:\Users\Public\Desktop\CyberLink YouCam.lnk
[2013/03/18 03:10:49 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/03/18 03:10:47 | 000,861,088 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/03/18 03:10:47 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/03/18 03:10:47 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/18 03:10:47 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/03/18 03:10:47 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/03/17 15:16:42 | 005,356,601 | —- | M] () – C:\Users\Jeff\Desktop\91355965Oo.gif
[2013/03/17 14:50:40 | 000,036,739 | —- | M] () – C:\Users\Jeff\Desktop\4bd17ae228cf30_full.jpg
[2013/03/17 14:48:59 | 000,053,947 | —- | M] () – C:\Users\Jeff\Desktop\14424.png
[2013/03/17 11:39:35 | 001,018,355 | —- | M] () – C:\Users\Jeff\Desktop\tumblr_miyb02G8r41rwv2mgo1_500.gif
[2013/03/16 13:53:59 | 000,190,553 | —- | M] () – C:\Users\Jeff\Desktop\adorama_RMA-signed.pdf
[2013/03/16 13:45:35 | 000,146,882 | —- | M] () – C:\Users\Jeff\Desktop\adorama_RMA (1).pdf
[2013/03/16 13:38:30 | 000,146,882 | —- | M] () – C:\Users\Jeff\Desktop\adorama_RMA.pdf
[2013/03/15 18:10:26 | 000,002,358 | —- | M] () – C:\Users\Public\Desktop\Canon MG5300 series On-screen Manual.lnk
[2013/03/13 14:36:41 | 000,000,328 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJeff.job
[2013/03/13 14:34:26 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/03/13 10:51:56 | 000,693,976 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/03/13 10:51:56 | 000,073,432 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/03/06 15:33:21 | 001,025,808 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2013/03/06 15:33:21 | 000,377,920 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2013/03/06 15:33:21 | 000,178,624 | —- | M] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/03/06 15:33:21 | 000,070,992 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2013/03/06 15:33:21 | 000,068,920 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2013/03/06 15:33:21 | 000,065,336 | —- | M] () – C:\Windows\SysNative\drivers\aswRvrt.sys
[2013/03/06 15:33:20 | 000,263,096 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2013/03/06 15:33:20 | 000,127,136 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2013/03/06 15:33:20 | 000,080,816 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2013/03/06 15:33:20 | 000,033,400 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2013/03/06 15:33:20 | 000,022,600 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswKbd.sys
[2013/03/06 15:32:51 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2013/03/06 15:32:22 | 000,287,840 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2013/03/06 01:51:07 | 000,000,340 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJEFF-HP$.job
[2 C:\Users\Jeff\AppData\Local\*.tmp files -> C:\Users\Jeff\AppData\Local\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Jeff\Documents\*.tmp files -> C:\Users\Jeff\Documents\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/04/04 22:57:50 | 000,000,616 | —- | C] () – C:\Users\Jeff\Desktop\MBR.dat.zip
[2013/04/04 22:51:07 | 000,000,512 | —- | C] () – C:\Users\Jeff\Desktop\MBR.dat
[2013/04/03 02:35:01 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/04/03 02:29:12 | 000,000,508 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 9edf46f8-117b-4316-8207-00d73e1f4f99.job
[2013/04/03 02:29:11 | 000,000,508 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 45900836-9099-4415-9664-708fec098603.job
[2013/04/03 02:29:00 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2013/03/28 03:15:52 | 000,001,159 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/03/28 03:15:52 | 000,001,147 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/03/25 15:20:29 | 000,069,376 | —- | C] () – C:\Windows\SysWow64\CNC175CD.TBL
[2013/03/25 15:17:04 | 000,002,354 | —- | C] () – C:\Users\Public\Desktop\Canon MX510 series On-screen Manual.lnk
[2013/03/24 14:28:09 | 000,001,361 | —- | C] () – C:\Users\Public\Desktop\CyberLink YouCam.lnk
[2013/03/17 15:16:41 | 005,356,601 | —- | C] () – C:\Users\Jeff\Desktop\91355965Oo.gif
[2013/03/17 14:50:37 | 000,036,739 | —- | C] () – C:\Users\Jeff\Desktop\4bd17ae228cf30_full.jpg
[2013/03/17 14:48:59 | 000,053,947 | —- | C] () – C:\Users\Jeff\Desktop\14424.png
[2013/03/17 11:39:35 | 001,018,355 | —- | C] () – C:\Users\Jeff\Desktop\tumblr_miyb02G8r41rwv2mgo1_500.gif
[2013/03/16 13:53:59 | 000,190,553 | —- | C] () – C:\Users\Jeff\Desktop\adorama_RMA-signed.pdf
[2013/03/16 13:45:35 | 000,146,882 | —- | C] () – C:\Users\Jeff\Desktop\adorama_RMA (1).pdf
[2013/03/16 13:38:30 | 000,146,882 | —- | C] () – C:\Users\Jeff\Desktop\adorama_RMA.pdf
[2013/03/15 18:18:35 | 000,068,096 | —- | C] () – C:\Windows\SysWow64\CNC1754D.TBL
[2013/03/15 18:13:50 | 000,002,075 | —- | C] () – C:\Users\Public\Desktop\Canon Solution Menu EX.lnk
[2013/03/15 18:10:26 | 000,002,358 | —- | C] () – C:\Users\Public\Desktop\Canon MG5300 series On-screen Manual.lnk
[2013/03/13 14:34:27 | 000,178,624 | —- | C] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/03/13 14:34:27 | 000,065,336 | —- | C] () – C:\Windows\SysNative\drivers\aswRvrt.sys
[2013/01/01 03:11:25 | 000,178,688 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2012/12/28 14:41:03 | 000,000,045 | —- | C] () – C:\Windows\WF-2540.ini
[2012/10/26 17:26:48 | 000,248,370 | —- | C] () – C:\Users\Jeff\AppData\Local\RAContactHistory.xml
[2012/09/14 15:30:32 | 000,004,662 | —- | C] () – C:\Windows\HCWPNP.INI
[2012/08/05 01:43:07 | 000,799,324 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/02/13 17:24:03 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/02/13 17:20:15 | 000,014,119 | —- | C] () – C:\Windows\SysWow64\RaCoInst.dat
[2011/09/15 15:24:42 | 000,056,832 | —- | C] () – C:\Windows\SysWow64\OpenVideo.dll
[2011/09/06 13:34:28 | 000,007,736 | —- | C] () – C:\Windows\hpDSTRES.DLL
[2011/07/21 19:59:02 | 000,066,856 | —- | C] () – C:\Windows\SysWow64\SynTPEnhPS.dll

========== ZeroAccess Check ==========

[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 22:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 21:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 18:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 20:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 18:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2012/09/26 14:29:04 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Audacity
[2013/03/30 13:08:46 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Canon
[2012/12/14 15:45:26 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\CometPlayer
[2013/04/03 02:28:09 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\DAEMON Tools Lite
[2013/04/03 03:12:57 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Dropbox
[2013/01/13 20:33:15 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Epson
[2012/11/27 19:05:50 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Jasc
[2012/12/28 14:41:08 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Leadertech
[2013/04/03 03:12:41 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Mal Updater
[2012/12/20 20:09:53 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\mjusbsp
[2013/03/28 03:19:23 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\OrphneDev
[2012/08/24 20:34:56 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\PACE Anti-Piracy
[2012/10/26 17:26:37 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\PeerNetworking
[2012/09/27 01:56:49 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Publish Providers
[2013/03/02 15:08:12 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Screaming Bee
[2012/09/27 01:56:33 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Sony
[2012/08/24 20:36:08 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/08/04 15:42:44 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Synaptics
[2012/12/28 22:49:27 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\TigerPlayer
[2012/10/23 14:38:22 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Windows Live Writer

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.* >
[2010/11/20 20:23:51 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2012/09/14 15:29:52 | 000,000,920 | —- | M] () – C:\hcwDriverInstall.txt
[2013/04/03 03:11:25 | 1728,241,663 | -HS- | M] () – C:\hiberfil.sys
[2013/04/03 03:11:26 | 3735,977,983 | -HS- | M] () – C:\pagefile.sys

< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont

< %systemroot%\Fonts\*.dll >

< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini

< %systemroot%\Fonts\*.ini2 >

< %systemroot%\Fonts\*.exe >

< %systemroot%\system32\spool\prtprocs\w32x86\*.* >

< %systemroot%\REPAIR\*.bak1 >

< %systemroot%\REPAIR\*.ini >

< %systemroot%\system32\*.jpg >

< %systemroot%\*.jpg >

< %systemroot%\*.png >

< %systemroot%\*.scr >
[2013/03/06 15:32:51 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/09/12 16:57:44 | 000,322,048 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

< %systemroot%\*._sy >

< %APPDATA%\Adobe\Update\*.* >

< %ALLUSERSPROFILE%\Favorites\*.* >

< %APPDATA%\Microsoft\*.* >

< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini

< %APPDATA%\Update\*.* >

< %systemroot%\*. /mp /s >

< %systemroot%\System32\config\*.sav >

< %PROGRAMFILES%\bak. /s >

< %systemroot%\system32\bak. /s >

< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >

< %systemroot%\system32\config\systemprofile\*.dat /x >

< %systemroot%\*.config >

< %systemroot%\system32\*.db >

< %PROGRAMFILES%\Internet Explorer\*.dat >

< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >

< %USERPROFILE%\Deskuop\*.exe >

< %PROGRAMFILES%\Common Files\*.* >

< %systemroot%\*.src >

< %systemroot%\install\*.* >

< %systemroot%\system32\DLL\*.* >

< %systemroot%\system32\HelpFiles\*.* >

< %systemroot%\system32\rundll\*.* >

< %systemroot%\winn32\*.* >

< %systemroot%\Java\*.* >

< %systemroot%\system32\test\*.* >

< %systemroot%\system32\Rundll32\*.* >

< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >

< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

< MD5 for: EXPLORER.ADML >
[2010/11/21 00:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml

< MD5 for: EXPLORER.ADMX >
[2009/06/10 13:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx

< MD5 for: EXPLORER.EXE >
[2011/10/25 20:44:27 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/10/25 20:44:27 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/10/25 20:44:27 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/10/25 20:44:27 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 20:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/10/25 20:44:27 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/10/25 20:44:27 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 20:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 00:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 00:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010/11/21 00:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010/11/21 00:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui

< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/04/04 22:59:57 | 000,027,802 | —- | M] () MD5=C96021A710717710F0724DB8D5BCCB2F – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf

< MD5 for: EXPLORER.ZIP >
[2009/06/03 21:15:06 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip

< MD5 for: IEXPLORE.EXE >
[2012/06/02 04:47:54 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2013/01/08 18:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Program Files\Internet Explorer\iexplore.exe
[2013/01/08 18:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012/11/13 19:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/06/28 22:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/08/24 00:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012/10/08 01:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2012/08/24 04:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012/06/02 02:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2012/10/08 05:29:46 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2012/08/24 03:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/06/28 19:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012/06/02 05:52:21 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2012/08/24 00:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2013/01/08 15:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/01/08 15:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2010/11/20 20:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2011/10/25 21:09:05 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012/06/28 18:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2012/11/15 20:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2012/06/02 01:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010/11/20 20:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2012/10/08 01:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2012/06/28 16:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2013/01/08 17:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 14:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2011/10/25 21:09:05 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2012/10/08 04:09:10 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012/11/13 19:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/11/14 00:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe

< MD5 for: IEXPLORE.EXE.MUI >
[2011/10/25 21:09:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011/10/25 21:09:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/10/25 21:09:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2011/10/25 21:09:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2009/07/13 19:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 19:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui

< MD5 for: SERVICES >
[2009/06/10 14:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.ASFX >
[2012/07/27 13:52:04 | 000,002,637 | —- | M] () MD5=016DFC4F3F133AE19338EECD1924886A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ro_RO\Services\Services.asfx
[2012/07/27 13:52:04 | 000,002,970 | —- | M] () MD5=05A68D76420994EF8DF33184BFA98E04 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\uk_UA\Services\Services.asfx
[2012/07/27 13:51:54 | 000,002,555 | —- | M] () MD5=272301585AC133486E70228DA27659AC – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\zh_TW\Services\Services.asfx
[2012/07/27 13:51:50 | 000,002,562 | —- | M] () MD5=27CE9BD3209B549BB776B8C877455A91 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\nb_NO\Services\Services.asfx
[2012/07/27 13:51:52 | 000,002,632 | —- | M] () MD5=2998A4AE8D0EF5122CCB985CF7E9D9D3 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ko_KR\Services\Services.asfx
[2012/07/27 13:51:52 | 000,002,545 | —- | M] () MD5=2EEC9DDBD0B4EE5F65532322C383938A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\zh_CN\Services\Services.asfx
[2012/07/27 13:51:56 | 000,002,629 | —- | M] () MD5=3A0082D76426A87FB4937D426C491C10 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\Services\Services.asfx
[2012/07/27 13:51:58 | 000,002,590 | —- | M] () MD5=448953BD0CF26CE03D9E7CC1A7B278BC – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\tr_TR\Services\Services.asfx
[2012/07/27 13:51:42 | 000,002,605 | —- | M] () MD5=5A2C5D0DA3EAAB2AA77F16947D0E14FF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\it_IT\Services\Services.asfx
[2012/07/27 13:51:56 | 000,002,679 | —- | M] () MD5=5DD2704563A6A79C466E44CD966B2655 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\hu_HU\Services\Services.asfx
[2012/07/27 13:51:40 | 000,002,711 | —- | M] () MD5=6B0E7B068BD530B8FCEBC04CC8844AA9 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ja_JP\Services\Services.asfx
[2012/07/27 13:52:02 | 000,002,582 | —- | M] () MD5=797FC263D59784AD1498560C34FA7DA1 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sl_SI\Services\Services.asfx
[2012/07/27 13:51:38 | 000,002,626 | —- | M] () MD5=8073B18DC740B965256CE0957E363AC5 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fr_FR\Services\Services.asfx
[2012/07/27 13:51:50 | 000,002,634 | —- | M] () MD5=912DD5C0C7C8D7572AD598414D56E24A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pt_BR\Services\Services.asfx
[2012/07/27 13:51:40 | 000,002,655 | —- | M] () MD5=ABFBB9D0398492D849690C344C1316BB – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\de_DE\Services\Services.asfx
[2012/07/27 13:52:06 | 000,002,638 | —- | M] () MD5=C2C37202B0E55877A64ADDBDE738284E – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sk_SK\Services\Services.asfx
[2012/07/27 13:51:56 | 000,002,589 | —- | M] () MD5=C313AD3602D4965A1918E86B9F3E84CF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Services\Services.asfx
[2012/07/27 13:52:06 | 000,002,609 | —- | M] () MD5=C7FA88C21103C70826F274A0E865AEDF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\Services\Services.asfx
[2012/07/27 13:52:08 | 000,002,576 | —- | M] () MD5=D27D52045EB6A2EE031F7D2EA0349BC3 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\Services\Services.asfx
[2012/07/27 13:51:46 | 000,002,560 | —- | M] () MD5=D5642B1BFE0A70231D14C11D3D3FD60D – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\Services\Services.asfx
[2012/07/27 13:52:00 | 000,002,588 | —- | M] () MD5=DB216743CDE75637621E2FD39431BBD4 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\hr_HR\Services\Services.asfx
[2012/07/27 13:51:44 | 000,002,620 | —- | M] () MD5=DCF7A8843832327386B81ABD189AC236 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\Services\Services.asfx
[2012/07/27 13:52:00 | 000,002,997 | —- | M] () MD5=DD3F4DAF426555D8D85FF4D7C5A04F37 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ru_RU\Services\Services.asfx
[2010/11/15 21:02:32 | 000,000,228 | R— | M] () MD5=E09422BE0C7636A7B63A1527C4C1372D – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx
[2012/07/27 13:51:48 | 000,002,599 | —- | M] () MD5=F09D769A94767C3C7E7015A5C6C99A39 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fi_FI\Services\Services.asfx
[2012/07/27 13:51:46 | 000,002,628 | —- | M] () MD5=F844D742DB53C7D671BF7ED6517414D1 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\nl_NL\Services\Services.asfx
[2012/07/27 13:51:44 | 000,002,582 | —- | M] () MD5=FED4BDA3B6A9EB9DB59C254D8C987495 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sv_SE\Services\Services.asfx

< MD5 for: SERVICES.ASFX1 >
[2010/11/15 21:02:32 | 000,000,228 | R— | M] () MD5=A7B7A4CC1A717292474115CD3A4AC121 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx1

< MD5 for: SERVICES.ASFX10 >
[2010/11/15 21:02:34 | 000,000,233 | R— | M] () MD5=3382FAB54FC906B0E40269D903A8D690 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx10

< MD5 for: SERVICES.ASFX11 >
[2010/11/15 21:02:26 | 000,000,227 | R— | M] () MD5=F36865AB3B9813962B7EDBE66FA1C28A – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx11

< MD5 for: SERVICES.ASFX12 >
[2010/11/15 21:02:30 | 000,000,225 | R— | M] () MD5=9287C7268CC0F37F1DDE18CEBB128685 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx12

< MD5 for: SERVICES.ASFX13 >
[2010/11/15 21:02:30 | 000,000,228 | R— | M] () MD5=95326C46AC2654AFF5C8543DFE22CCB3 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx13

< MD5 for: SERVICES.ASFX14 >
[2010/11/15 21:02:26 | 000,000,228 | R— | M] () MD5=14DA84ECAF57B5ADA36B9093FF04CF32 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx14

< MD5 for: SERVICES.ASFX15 >
[2010/11/15 21:02:26 | 000,000,231 | R— | M] () MD5=CF94F061685A38BABE0BBD463191EDE7 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx15

< MD5 for: SERVICES.ASFX16 >
[2010/11/15 21:02:34 | 000,000,232 | R— | M] () MD5=B6E63D87C73CED2D6B433C542C5C3965 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx16

< MD5 for: SERVICES.ASFX17 >
[2010/11/15 21:02:34 | 000,000,230 | R— | M] () MD5=545E97C4F4CEA743A8D86B685EE2EDBB – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx17

< MD5 for: SERVICES.ASFX18 >
[2010/11/15 21:02:24 | 000,000,230 | R— | M] () MD5=2577B66F38E0DEA25F328DA4A0FED322 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx18

< MD5 for: SERVICES.ASFX19 >
[2010/11/15 21:02:26 | 000,000,225 | R— | M] () MD5=0A27F1D6595A69800A43CDE155B1E4A0 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx19

< MD5 for: SERVICES.ASFX2 >
[2010/11/15 21:02:36 | 000,000,264 | R— | M] () MD5=0652D24D4E2799851A6DF1705E2BFFDA – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx2

< MD5 for: SERVICES.ASFX20 >
[2010/11/15 21:02:38 | 000,000,231 | R— | M] () MD5=C85F2519DC6AECF93F67AA613A320136 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx20

< MD5 for: SERVICES.ASFX21 >
[2010/11/15 21:02:26 | 000,000,231 | R— | M] () MD5=8C95C0528EA7049A1DFC7A7342461D75 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx21

< MD5 for: SERVICES.ASFX22 >
[2010/11/15 21:02:24 | 000,000,231 | R— | M] () MD5=9F2731666F5771CC5C1E4EEDC8FB8607 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx22

< MD5 for: SERVICES.ASFX23 >
[2010/11/15 21:02:26 | 000,000,225 | R— | M] () MD5=0E89BE53F56B22390CF61584B649CE01 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx23

< MD5 for: SERVICES.ASFX24 >
[2010/11/15 21:02:32 | 000,000,229 | R— | M] () MD5=E57594DB9B9D78AB4B53D34CAFEB8497 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx24

< MD5 for: SERVICES.ASFX25 >
[2010/11/15 21:02:36 | 000,000,232 | R— | M] () MD5=611CB9CC21D2DDAD711690671F70EF39 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx25

< MD5 for: SERVICES.ASFX3 >
[2010/11/15 21:02:34 | 000,000,229 | R— | M] () MD5=F9824728970AC8199BABDC9CBA5E038C – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx3

< MD5 for: SERVICES.ASFX4 >
[2010/11/15 21:02:26 | 000,000,226 | R— | M] () MD5=55EA57D90AE22BDF0132597EF0D7C9C7 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx4

< MD5 for: SERVICES.ASFX5 >
[2010/11/15 21:02:34 | 000,000,233 | R— | M] () MD5=846C265B751189E88B74F0155DB6B828 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx5

< MD5 for: SERVICES.ASFX6 >
[2010/11/15 21:02:36 | 000,000,231 | R— | M] () MD5=89BD37C4118540FD5AA8CDD0C24D6C0A – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx6

< MD5 for: SERVICES.ASFX7 >
[2010/11/15 21:02:34 | 000,000,245 | R— | M] () MD5=0B82FAB8FF5F988C5311DF1144A7D740 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx7

< MD5 for: SERVICES.ASFX8 >
[2010/11/15 21:02:34 | 000,000,231 | R— | M] () MD5=5226417D3C8206000A8983BDC1243075 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx8

< MD5 for: SERVICES.ASFX9 >
[2010/11/15 21:02:30 | 000,000,234 | R— | M] () MD5=EBD8D036504F2935675F5F432F076DBA – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx9

< MD5 for: SERVICES.CFG >
[2012/12/18 07:28:18 | 000,558,791 | —- | M] () MD5=A9983CC532F9B3FB1E87918D2313731D – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2010/11/15 21:02:22 | 000,032,633 | R— | M] () MD5=EA1C35DD541D60819D55482130BD585D – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/13 18:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 18:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 00:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010/11/21 00:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/13 21:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 13:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 13:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2010/11/21 00:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 13:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010/11/21 00:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 14:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010/11/21 00:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 13:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 00:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 14:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 13:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 13:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: WINLOGON.ADML >
[2010/11/21 00:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml

< MD5 for: WINLOGON.ADMX >
[2009/06/10 14:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx

< MD5 for: WINLOGON.EXE >
[2010/11/20 20:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 20:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 00:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/21 00:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui

< MD5 for: WINLOGON.EXE-B020DC41.PF >
[2013/04/04 17:23:54 | 000,038,320 | —- | M] () MD5=4E335D2E022CFFBC05F275C92105500A – C:\Windows\Prefetch\WINLOGON.EXE-B020DC41.pf

< MD5 for: WINLOGON.MFL >
[2010/11/21 00:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010/11/21 00:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl

< MD5 for: WINLOGON.MOF >
[2009/07/13 13:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 13:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof

========== Alternate Data Streams ==========

@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:8CE646EE

< End of report >





OTL Extras logfile created on: 4/4/2013 11:07:03 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jeff\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.48 Gb Total Physical Memory | 4.42 Gb Available Physical Memory | 59.08% Memory free
14.96 Gb Paging File | 11.15 Gb Available in Paging File | 74.57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 440.77 Gb Total Space | 194.88 Gb Free Space | 44.21% Space Free | Partition Type: NTFS
Drive D: | 20.83 Gb Total Space | 2.25 Gb Free Space | 10.79% Space Free | Partition Type: NTFS
Drive E: | 3.96 Gb Total Space | 3.95 Gb Free Space | 99.77% Space Free | Partition Type: FAT32

Computer Name: JEFF-HP | User Name: Jeff | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – C:\Program Files\Hewlett-Packard\HP Application Assistant\HPAA.exe %1 (Hewlett Packard Company)
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – C:\Program Files\Hewlett-Packard\HP Application Assistant\HPAA.exe %1 (Hewlett Packard Company)
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06B1CF0E-AC94-4B21-88A1-CD4767A9FA84}" = lport=138 | protocol=17 | dir=in | app=system |
"{0D372A54-3805-4D7D-904B-ABCBB36084FC}" = rport=138 | protocol=17 | dir=out | app=system |
"{2B0F0839-6636-44BF-87A0-5FC9554EABEB}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{430BB916-AD16-4737-8CCD-98E849781E40}" = lport=139 | protocol=6 | dir=in | app=system |
"{460D854D-E64A-45B3-BF3E-2321CEA09C71}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{50BDAF9D-23DF-4493-A59D-2FE2FF40B6EC}" = rport=139 | protocol=6 | dir=out | app=system |
"{5D547CBC-2D21-445F-9186-F4380F069AC3}" = rport=445 | protocol=6 | dir=out | app=system |
"{630AD83B-B455-4A1D-AE08-A91B55C07B12}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{65CB1E6C-FBF5-4CBE-8D21-943EFFC8EC7D}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{681A848B-DD8F-4C75-BB07-08EDBA5CDC38}" = lport=137 | protocol=17 | dir=in | app=system |
"{69D6FAEB-E6E0-4A02-9D68-B6F51948A677}" = rport=10243 | protocol=6 | dir=out | app=system |
"{6E871BD7-449B-4CD1-B092-9C36F13AEF0C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{750706F5-A477-4048-AB49-5CE108040F3E}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{85F85AB4-293D-4EC4-80C7-5CED35413C56}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{893FF24C-7462-46B1-A02C-76B8E5FE9453}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{91732C21-760D-48CD-B89E-3682F526AD5C}" = rport=1723 | protocol=6 | dir=out | app=system |
"{9EECB89A-AE5C-4C5B-BBDB-2940C0AF5A3D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9F00577E-7471-45B2-AE0A-7FFD1B55E2F6}" = rport=1701 | protocol=17 | dir=out | app=system |
"{AA1ED8FC-E148-4570-BBEF-1BB701117D9A}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{B7233669-B632-4FA8-A65F-F9D9018429D6}" = lport=1701 | protocol=17 | dir=in | app=system |
"{B913722C-7A44-4F88-BC40-ABAF83645C72}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
"{D4F7F83D-4B7B-41F5-97AF-175AD6A7EDAF}" = rport=137 | protocol=17 | dir=out | app=system |
"{D7CEC3F1-4F84-4667-9CD1-F47A31D8304A}" = lport=10243 | protocol=6 | dir=in | app=system |
"{D8747242-E959-413F-8E21-F65EB446EF72}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E85D6EB8-958A-42F4-9091-CAB6B94F709A}" = lport=445 | protocol=6 | dir=in | app=system |
"{EAD8F1DD-061D-416B-A099-7738A9A7B9B5}" = lport=1723 | protocol=6 | dir=in | app=system |
"{ECF31215-AFF8-438A-AD92-65B5DF89C68C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FAA1747F-17D2-483D-9EF6-B79F92705A88}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FCA73D0C-4E35-4C76-BEA9-61E4A175F481}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00437BD7-9FD8-4CFD-88A3-DAADD7445B10}" = protocol=6 | dir=in | app=c:\users\jeff\appdata\local\crossloop\vncviewer.exe |
"{05FA3F96-530B-40D2-8C32-9D4A40966473}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{06ABC84A-E8CA-4D96-960F-EC1252C64A75}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{0B340965-B733-4D97-98E9-D631B79D2DE6}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orb.exe |
"{0F951172-4096-41A0-B6E4-1B6273CE9F81}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orblauncher.exe |
"{0FDBDE5D-DACC-4D00-9466-1CC2FDE52364}" = protocol=6 | dir=in | app=f:\common\epsonnet setup\eneasyapp.exe |
"{127CDE0A-B0D0-4F1D-AD2D-73C01CCFA642}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbir.exe |
"{13EF10E2-A4C1-4B7B-B948-27A2169C8CC9}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\indivdrm.exe |
"{18A251DA-EE08-4FD3-BDC2-5BCEFE726697}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{19770E98-4DFA-445E-A5E9-7233A51ADFD8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1DCB2076-C48D-4F6A-AE0F-E9902637872E}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbsetupwizard.exe |
"{2D00C611-632C-4A91-9D31-F9129F22CCAE}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbsetup.exe |
"{2EF65036-4F00-42A6-8258-6D33D4BE9AFD}" = dir=in | app=c:\users\jeff\appdata\local\microsoft\skydrive\skydrive.exe |
"{2F4D06BF-D9B8-4FA2-AA19-49E6D6130F95}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbsetup.exe |
"{3212223F-4FEB-4C48-BD61-6DB9009F8A4A}" = dir=in | app=c:\users\jeff\appdata\local\temp\7zs6cb4\setup\hpznui40.exe |
"{40EB4CD2-ABFA-411D-9A8F-874071394CC0}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{40FA79A9-5057-4BD9-A577-ACF62FF62EC5}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orblauncher.exe |
"{45503374-AF13-4565-A37B-CA22F429F9A3}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\..\orb mini controller\bin\orbminicontroller.exe |
"{47DADCC0-1B65-4057-A747-84996D104358}" = protocol=47 | dir=in | app=system |
"{48789A82-57DD-46D7-9A3B-093C395599DB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{48A0B93A-6A52-42FD-A31A-9AAB44BB588C}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\..\orb mini controller\bin\orbminicontroller.exe |
"{4F57D974-ECC7-4342-935B-1BD65FCC989E}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{4F870272-F701-4C36-A0C2-EF16AD5D31E3}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{52B9B168-7FDD-4F30-9A5C-EAB1B40EB69D}" = protocol=6 | dir=in | app=c:\users\jeff\appdata\roaming\dropbox\bin\dropbox.exe |
"{5812C1F5-BCED-4B28-B8F2-3C367109285E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5CCBE87F-CC3F-4485-8EBE-FF09D50FF744}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbstreamerclient.exe |
"{5E349098-B93E-48FA-9F47-56E1A4FEC4EC}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbjetmanager.exe |
"{5EA01195-634E-4E2E-8C66-93CDB3A50DF3}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{62803026-FF3E-4510-8D41-6A1A18AEAA2F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6A456BC8-C7E3-444E-96C0-B2BBF774A110}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbchannelscan.exe |
"{80220CA3-226B-4C8E-A0E9-C9737B67C9B3}" = protocol=6 | dir=out | app=system |
"{80CB792C-20C7-466E-B23B-0A1DA8ECC70A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{810E3C31-6A2C-4873-B93F-54152FD8DEEE}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{8AA78212-4DAD-408C-AAC8-495C18563CED}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbstreamerclient.exe |
"{9002DD1E-9487-44D5-A91C-5EBCEEE9CEFC}" = protocol=17 | dir=in | app=c:\users\jeff\appdata\roaming\dropbox\bin\dropbox.exe |
"{931182AC-6139-4C81-AEE7-94F53F05F381}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{97306F16-8A76-4918-B509-BCD6B0D40049}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbsetupwizard.exe |
"{97833BB8-1D09-415D-9292-00593B618BEC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{978F5DA3-702A-44A8-9511-E888C9FA7E87}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{97E0DF9A-E03C-4F58-845C-77116D74BF68}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbir.exe |
"{9C7B38F1-8A4B-4EB0-B082-7F99C6CF3025}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbjetmanager.exe |
"{9C9B2A3C-EF3A-44EE-B92D-07DBDC5630E3}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpwarrantychecker.exe |
"{A56D6DDB-46EB-4E99-B14E-6CB4A020CA38}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{A9E1A035-A5D5-41F5-819B-BE70794EFAD0}" = protocol=47 | dir=out | app=system |
"{AC9C7A23-0FCE-4D79-818E-59C4FCC09B3A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B1813968-63F4-4718-B64E-CA4F123DE895}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\indivdrm.exe |
"{B1A5114D-12F6-4DA5-913B-149A4A834305}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{B6E5685D-0916-41E1-9FE3-75CECE93CBCF}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{BF37A58A-D161-4F1B-842E-5F584782F454}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbchannelscan.exe |
"{C1D25E84-3E6F-431B-A662-FB3CF5477E0F}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{CB94D45C-DDB5-4667-9339-F99BB0A72E8D}" = protocol=17 | dir=in | app=c:\users\jeff\appdata\local\crossloop\tvnserver.exe |
"{CC00A3D2-DCC8-42B1-B488-4FB5A803CC34}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D3ADD1DB-9D1C-43DA-AD1E-58C11F54535E}" = protocol=17 | dir=in | app=f:\common\epsonnet setup\eneasyapp.exe |
"{D8C10DA4-D33D-444C-A3CA-38CFA6E1EB84}" = protocol=17 | dir=in | app=c:\users\jeff\appdata\local\crossloop\vncviewer.exe |
"{DA10CA20-756C-4667-AB65-DDFB9B0454E4}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E05245F2-E5C6-4197-8912-C93A40EBA57A}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe |
"{E265F2F4-5AF8-4DB6-BF37-BB9BC742B284}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{E9AC709E-1B60-41BE-80B5-D2913F7907C7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E9F1AB9A-84B6-4B4B-A3BC-C30F120A84FE}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{F0F83576-2BC0-4BCF-AB2A-668D414EB915}" = protocol=6 | dir=in | app=c:\users\jeff\appdata\local\crossloop\tvnserver.exe |
"{FB49387B-4087-443F-8D91-6BEBAB54F903}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{FC4F862F-A99E-4E28-A2FF-E677BD0AC653}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{FDC31EF3-E2B7-4198-AE75-571A2C119941}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orb.exe |
"TCP Query User{2B32E27E-DFDE-4132-9202-ECE541025263}C:\users\jeff\appdata\local\crossloop\crossloopconnect.exe" = protocol=6 | dir=in | app=c:\users\jeff\appdata\local\crossloop\crossloopconnect.exe |
"TCP Query User{7C994FDB-ADA6-4520-861C-B822193F8AB8}C:\users\jeff\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\jeff\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{FA7A33DA-3BA6-453E-9E91-3CB17A8F4F27}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"TCP Query User{FBC01AA3-475C-48F3-A278-79246CBB1EE6}C:\Program Files (x86)\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"UDP Query User{09D2640B-2A01-4FBF-B109-0B1A4DEC324A}C:\Program Files (x86)\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"UDP Query User{31457E93-48B2-4CD9-8578-52D210D432F8}C:\users\jeff\appdata\local\crossloop\crossloopconnect.exe" = protocol=17 | dir=in | app=c:\users\jeff\appdata\local\crossloop\crossloopconnect.exe |
"UDP Query User{54BD4CF4-1ABF-4069-81B2-353F2C13CF4A}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"UDP Query User{5E422DF1-E560-4D55-9300-74413F8CCCA2}C:\users\jeff\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\jeff\appdata\roaming\dropbox\bin\dropbox.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{006716FE-DAB7-8EA8-99B6-04EB354AC3A8}" = AMD Media Foundation Decoders
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5300_series" = Canon MG5300 series MP Drivers
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX510_series" = Canon MX510 series MP Drivers
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services
"{288591DE-4151-4E8E-A698-C6EFF5DF00F9}" = HP Security Assistant
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6032497A-4479-462B-ADB8-A0A372BB9A23}" = HP Application Assistant
"{6ECDAC2F-12C1-E49B-448E-6002368967E0}" = AMD Steady Video Plug-In
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9795DCDC-45CB-8A98-4F01-8C4B37361BF5}" = AMD Fuel
"{9CAB2212-0732-4827-8EC4-61D8EF0AA65B}" = HP Launch Box
"{A21EA495-2B09-7E39-8C55-310D6DC7DB4C}" = ccc-utility64
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{C9608300-11F5-11E0-A64B-0013D3D69929}" = MSVCRT Redists
"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{CF780466-D74B-C6E7-7E61-0C4DCA614455}" = AMD Catalyst Install Manager
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6822EFD-3F7D-4B35-8845-757A26AEC8E2}" = Windows Live MIME IFilter
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.60.1
"EPSON WF-2540 Series" = EPSON WF-2540 Series Printer Uninstall
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"ONAIR_is1" = ONAIR 4.0.0.854
"SynTPDeinstKey" = Synaptics TouchPad Driver
"WinRAR archiver" = WinRAR 4.11 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{0497EAED-70DA-4BBE-BEB3-AF77FD8788EA}" = Adobe Premiere Pro CS5.5
"{06A62CCD-4953-88D6-104D-37C20CCA8140}" = CCC Help Greek
"{07E900C8-D1E3-4C24-AC9F-7FE3C1AE19A2}_is1" = Mal Updater 2.85
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0AD538F8-AE22-4448-71C5-2A321D3953A3}" = CCC Help Chinese Standard
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore
"{169FDBFF-6FA1-2A14-F5F0-EEA7C27C4AFE}" = AMD VISION Engine Control Center
"{174D5678-D941-433C-BD23-58A5C7B0D36D}" = Jasc Animation Shop 3
"{18272881-CFC0-434D-A975-E5BE44206AA0}" = Windows Live UX Platform Language Pack
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1AD2BBC8-8233-F193-6915-AEB19299EF69}" = CCC Help Dutch
"{1EA7C505-E6DA-4B85-9432-EBD3C70D510D}" = Windows Live Messenger
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2133CB3F-F891-4081-8681-FEE2B2419FF4}" = Orb Runtime libraries
"{23A3E560-069F-4CFC-8F6C-1B526EC735FC}" = Windows Live Writer Resources
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17
"{2DD84AB2-8BF4-49FA-9D62-E3F93D4F56FB}" = Roxio Game Capture HD PRO
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{35E81526-8A3E-FF8C-6E43-EBA7D40904CA}" = CCC Help Finnish
"{3677D4D8-E5E0-49FC-B86E-06541CF00BBE}" = opensource
"{3D5C7E0E-AEC0-40EB-99D3-C40469738040}" = HP Documentation
"{400C31E4-796F-4E86-8FDC-C3C4FACC6847}" = Junk Mail filter update
"{4653DA78-3DB2-4F38-A35D-675CA0AF49CA}" = ArcSoft ShowBiz
"{47AA42FD-0450-4CB4-ADAF-B6E770AA7B2F}" = Sony Media Manager 2.2
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1
"{53B17A98-5BF0-40BC-AAFF-850A357975AC}" = HP Quick Launch
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579BD527-0EED-20A8-B9F4-0244FBABB085}" = CCC Help German
"{5AF4B3C4-C393-48D7-AC7E-8E7615579548}" = Adobe AIR
"{5BABDA39-61CF-41EE-992D-4054B6649A9B}" = Movie Maker
"{5F187E71-93D7-4849-B5C2-1DD1747C81A7}" = Roxio CinePlayer Decoder Pack
"{600DFD49-D7C2-9DE4-4EEA-337083E72B1F}" = CCC Help Russian
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{69290A89-5CD6-42A2-BBD9-D1EE95A3E490}" = Roxio GameCAP HD PRO
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{6DE8EE45-09DE-3288-4635-DCFA87765D84}" = CCC Help Portuguese
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.1.1
"{6F89F8EB-16A2-E21F-A34C-CF6AB53EA7E1}" = CCC Help Hungarian
"{6FF4C560-A95B-42DE-83AD-62C8737115E9}" = Roxio Game Capture HD PRO
"{70854FE6-3BF1-4C69-94D0-BEB821102E34}" = Windows Live Mail
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App (HP Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{79A21AE8-0BF2-955D-7AC3-2AFD9430C199}" = CCC Help Czech
"{7B67B74C-6942-9F20-C05A-2870D600A6EB}" = CCC Help Italian
"{8279D3BD-3A54-A6F6-E8BE-C12FADDC1064}" = CCC Help Polish
"{86C40513-B5A4-476E-9EAB-EC118DCF4502}" = Windows Live Writer
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8D78F24E-3AA8-9D2A-3B28-CA240439B802}" = CCC Help Swedish
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT5390 802.11b/g/n WiFi Adapter
"{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9036f6df-feeb-4503-867e-8103d1cac110}" = Nero 9 Essentials
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{962CB079-85E6-405F-8704-1C62365AE46F}" = HP Software Framework
"{97C79BEC-43F7-4BD8-A6A7-85C0257E488A}" = Windows Live Writer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F4532D6-62F3-4B5B-AA47-979CFC7510F5}" = CCC Help Chinese Traditional
"{A7A7B78C-3EEE-5783-E2FB-218E4B40198E}" = CCC Help Spanish
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.6) MUI
"{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager
"{B0E3A46B-0629-BD31-EC2B-4C96DCF7F7BB}" = Catalyst Control Center Localization All
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B41441A0-A65C-CABF-4D1B-B1588E316F7D}" = CCC Help Korean
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B80D3EA9-A252-4AE5-AC51-81729F5C586F}" = Windows Live Mail
"{B894D068-A07A-96C8-A6CB-87C5EDB97C8E}" = Catalyst Control Center Graphics Previews Common
"{BB4FC2AD-DF12-4EE1-8AA7-2C0A26B5E2FB}" = HP QuickWeb
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BDD74598-1133-68FA-CD69-6FD442759CD4}" = CCC Help Thai
"{BEA1CE9A-93E0-E131-13DF-76441B6783E6}" = Catalyst Control Center InstallProxy
"{C034A6F9-6569-491B-B3BF-F5D15221A708}" = Windows Live Essentials
"{C0E6C680-7B1D-0EE9-0D6C-AF28765FB885}" = CCC Help Turkish
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C28DD992-5B7B-D195-6841-4EC57DF512BD}" = Adobe Story
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C7D23135-04B6-1A0C-E835-42AADD00EA1F}" = CCC Help Japanese
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{CA41C92C-BEA4-5C7B-6DDE-48C7E996FE72}" = CCC Help Norwegian
"{CB841B9A-4049-E21F-1E62-49AC742C1B81}" = CCC Help English
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1725D54-279A-40C5-A70D-23C1785DB920}_is1" = AoA Audio Extractor Platinum
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D2C146B1-948D-47EF-8387-5D1C6B980F7C}" = Windows Live Writer
"{D888F114-7537-4D48-AF03-5DA9C82D7540}" = Photo Common
"{D8BCE5B9-67CF-4F3F-93AE-3ACC754C72EB}" = HP Power Manager
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D947A225-8C23-4E52-866E-CF3967476BFC}" = Female Voice Pack
"{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
"{DBCD5E64-7379-4648-9444-8A6558DCB614}" = HP Recovery Manager
"{DE289787-7ECA-4BED-9D8C-99FAC407E3D6}" = MorphVOX Pro
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E12C4983-DA0E-7AFD-04E5-592EC5DF1974}" = CCC Help French
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E728441A-7820-4B1C-87C9-DE7BE37B2953}" = Download Navigator
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{E96CAA2A-0244-4A2A-8403-0C3C9534778B}" = ESU for Microsoft Windows 7 SP1
"{EC6BAAC5-F5E0-48D4-B4B6-7C654DD54086}" = Sony Vegas 7.0b
"{ED1BD69A-07E3-418C-91F1-D856582581BF}" = HP On Screen Display
"{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker
"{EE202411-2C26-49E8-9784-1BC1DBF7DE96}" = HP Support Assistant
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F2235E5E-7881-4293-9B6F-04B2609FBFF0}" = Windows Live Messenger
"{F30403FF-0146-4633-AAC5-D5CD5C50AE70}" = Catalyst Control Center - Branding
"{F500B5DC-CCCE-CC7F-B1D1-39139AE57676}" = CCC Help Danish
"{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}" = HP Setup
"{F761359C-9CED-45AE-9A51-9D6605CD55C4}" = Evernote v. 4.2.3
"{F9000000-0018-0000-0000-074957833700}" = ABBYY FineReader 9.0 Sprint
"{FC6C7107-7D72-41A1-A031-3CE751159BAB}" = Photo Gallery
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"7-Zip" = 7-Zip 4.32
"ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Audacity_is1" = Audacity 2.0.2
"avast" = avast! Internet Security
"Canon MG5300 series On-screen Manual" = Canon MG5300 series On-screen Manual
"Canon MG5300 series User Registration" = Canon MG5300 series User Registration
"Canon MX510 series On-screen Manual" = Canon MX510 series On-screen Manual
"Canon_IJ_Network_Scanner_Selector_EX" = Canon IJ Network Scanner Selector EX
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Story
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"CrossLoop_is1" = CrossLoop 2.82
"DivX Setup" = DivX Setup
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"FormatFactory" = FormatFactory 2.96
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"KLiteCodecPack_is1" = K-Lite Codec Pack 9.6.5 (Standard)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Mozilla Firefox 19.0.2 (x86 en-US)" = Mozilla Firefox 19.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 5.0" = Canon MP Navigator EX 5.0
"MP Navigator EX 5.1" = Canon MP Navigator EX 5.1
"MpcStar" = MpcStar 5.3
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Orb" = Orb
"Orb Mini Controller" = Orb Mini Controller
"Speed Dial Utility" = Canon Speed Dial Utility
"SpeedFan" = SpeedFan (remove only)
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"WTA-03eaf8a3-d4e4-4e74-81fa-9a750638440f" = Hoyle Card Games
"WTA-05baa083-98fc-4295-b0d6-ebbfde2cbaae" = Polar Bowler
"WTA-0e2af03a-115c-43b8-92cf-2e9894b75a09" = Final Drive Fury
"WTA-1013007a-e2ae-4478-a7ba-fcb5ef229d1d" = Blackhawk Striker 2
"WTA-21411c76-2cba-40b4-9f51-4d86a472e884" = Virtual Villagers 4 - The Tree of Life
"WTA-279cf681-1067-4bbb-94b5-f1157720c963" = FATE
"WTA-2f933c63-a5b8-4438-ba29-3b2167ffb329" = Letters from Nowhere 2
"WTA-38ca30e4-5ef4-48ec-b6c0-eac39d7622b2" = John Deere Drive Green
"WTA-4bd98dfa-b4b2-4568-b754-fd6fbebb6c77" = Plants vs. Zombies - Game of the Year
"WTA-596c1d88-c119-4aac-ac47-824dd7bd0092" = RollerCoaster Tycoon 3: Platinum
"WTA-7422e5c8-c1ba-4b5f-8d80-e66d5379244d" = Penguins!
"WTA-78d9a8fa-7918-4b63-b3df-c50fa13e91ad" = Luxor HD
"WTA-7be5810c-ea5e-4369-bb44-222ca40b37ca" = Bejeweled 3
"WTA-864f03ed-f2c1-4145-8110-d2725c4d5d3b" = Jewel Match 3
"WTA-89b4debd-166b-437d-bd18-2d6141046e35" = Jewel Quest Mysteries: The Seventh Gate Collector's Edition
"WTA-93ff1273-e0b2-48f8-b5b5-5df7ee75ec68" = Cradle of Rome 2
"WTA-9493dec6-a9ec-4c16-82aa-6bc1cb0b678c" = Torchlight
"WTA-a440874a-34ea-40fe-9af4-c9cdd81dea06" = Farm Frenzy
"WTA-b1d68def-d5bd-4f0b-9690-ead73acb9a11" = Dora's World Adventure
"WTA-b24b387f-0989-4b82-99bc-c30584401ee7" = Zuma's Revenge
"WTA-c1968821-c8ac-4459-812b-75906d5c143e" = Polar Golfer
"WTA-c2714556-d482-4680-bd2b-d17b8abe75ce" = Chuzzle Deluxe
"WTA-cdcdfb51-ac34-4f64-9069-95c4d07b8738" = Farmscapes
"WTA-e2531fc0-9b5d-42e4-ad84-b227f6e379da" = Mah Jong Medley
"WTA-f6945d06-5c82-4266-8a9f-b1a296130bdd" = The Treasures of Mystery Island: The Ghost Ship
"WTA-ff3a66bc-e702-4df5-87d2-62dbd4791335" = Poker Superstars III
"Yahoo! Companion" = Yahoo! Toolbar

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3952182868-3481799418-86632157-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"SkyDriveSetup.exe" = Microsoft SkyDrive

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 1/1/2013 6:13:45 AM | Computer Name = Jeff-HP | Source = Application Error | ID = 1005
Description = Windows cannot access the file for one of the following reasons: there
is a problem with the network connection, the disk that the file is stored on,
or the storage drivers installed on this computer; or the disk is missing. Windows
closed the program Media Player Classic - Home Cinema because of this error. Program:
Media Player Classic - Home Cinema File: The error value is listed in the Additional
Data section. User Action 1. Open the file again. This situation might be a temporary
problem that corrects itself when the program runs again. 2. If the file still cannot
be accessed and - It is on the network, your network administrator should verify
that there is not a problem with the network and that the server can be contacted.
-
It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the
disk is fully inserted into the computer. 3. Check and repair the file system by
running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click
OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem
persists, restore the file from a backup copy. 5. Determine whether other files
on the same disk can be opened. If not, the disk might be damaged. If it is a hard
disk, contact your administrator or computer hardware vendor for further assistance.

Additional
Data Error value: 00000000 Disk type: 0

Error - 1/4/2013 8:15:19 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image
of service ArcSoft Connect Daemon since QueryServiceConfig API failed System Error:
The
system cannot find the file specified. .

Error - 1/5/2013 2:33:01 AM | Computer Name = Jeff-HP | Source = Application Hang | ID = 1002
Description = The program MalUpdater.exe version 2.8.6.3754 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1a6c Start
Time: 01cdeb0c0cece6bd Termination Time: 26 Application Path: C:\Program Files (x86)\Mal
Updater 2\MalUpdater.exe Report Id: b83009c4-5701-11e2-bdff-78e3b5677f68

Error - 1/8/2013 2:49:45 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image
of service ArcSoft Connect Daemon since QueryServiceConfig API failed System Error:
The
system cannot find the file specified. .

Error - 1/8/2013 3:28:26 PM | Computer Name = Jeff-HP | Source = WinMgmt | ID = 10
Description =

Error - 1/11/2013 7:14:02 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-RestartManager | ID = 10006
Description = Application or service 'Windows Explorer' could not be shut down.

Error - 1/25/2013 1:47:25 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-RestartManager | ID = 10006
Description = Application or service 'Windows Search' could not be shut down.

Error - 1/25/2013 1:57:14 PM | Computer Name = Jeff-HP | Source = WinMgmt | ID = 10
Description =

Error - 2/15/2013 1:59:54 PM | Computer Name = Jeff-HP | Source = Application Hang | ID = 1002
Description = The program E_YARNIUE.EXE version 7.0.1.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 2454 Start
Time: 01ce0ba4d28e728f Termination Time: 11 Application Path: C:\Windows\system32\spool\DRIVERS\x64\3\E_YARNIUE.EXE

Report
Id:

Error - 2/18/2013 1:53:41 PM | Computer Name = Jeff-HP | Source = WinMgmt | ID = 10
Description =

[ Hewlett-Packard Events ]
Error - 12/2/2012 7:23:47 PM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 30 TargetSite: Void loadActiveCheckResult(Boolean)

Error - 12/10/2012 12:55:21 AM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 30 TargetSite: Void loadActiveCheckResult(Boolean)

Error - 12/10/2012 1:05:25 AM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 30 TargetSite: Void loadActiveCheckResult(Boolean)

Error - 12/10/2012 3:05:26 AM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 30 TargetSite: Void loadActiveCheckResult(Boolean)

Error - 12/17/2012 1:12:43 PM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 50 TargetSite: Void loadActiveCheckResult(Boolean)

Error - 12/23/2012 6:21:58 PM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 40 TargetSite: Void loadActiveCheckResult(Boolean)

Error - 12/23/2012 7:34:23 PM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 40 TargetSite: Void loadActiveCheckResult(Boolean)

Error - 12/23/2012 10:34:22 PM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 40 TargetSite: Void loadActiveCheckResult(Boolean)

Error - 12/30/2012 6:31:05 PM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 40 TargetSite: Void loadActiveCheckResult(Boolean)

Error - 1/1/2013 5:49:48 AM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 30 TargetSite: Void loadActiveCheckResult(Boolean)

[ HP Software Framework Events ]
Error - 10/26/2011 12:38:23 AM | Computer Name = 960EC8351I5AL | Source = CaslWmi | ID = 5
Description = 2011/10/25 21:38:23.032|00000BB0|Error |[CaslWmi]CommandPanelBrightness::GetCurrentPanelBrightnessFromOS{hpCasl.enRetur
nCode(CaslWmi.enPanelBrightnessDataType,ushort&)}|Exception
occurred in querying WMI for WmiMonitorBrightness: 'Not supported '

Error - 10/26/2011 12:38:25 AM | Computer Name = 960EC8351I5AL | Source = CaslWmi | ID = 5
Description = 2011/10/25 21:38:25.248|00000BB0|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 8/4/2012 6:40:46 PM | Computer Name = Jeff-HP | Source = CaslWmi | ID = 5
Description = 2012/08/04 15:40:46.394|00000E50|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 8/4/2012 6:40:53 PM | Computer Name = Jeff-HP | Source = CaslWmi | ID = 5
Description = 2012/08/04 15:40:53.668|00000E58|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 8/4/2012 10:38:02 PM | Computer Name = Jeff-HP | Source = CaslWmi | ID = 5
Description = 2012/08/04 19:38:02.136|00001364|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 8/5/2012 5:18:20 PM | Computer Name = Jeff-HP | Source = CaslWmi | ID = 5
Description = 2012/08/05 14:18:20.392|00000E2C|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 8/5/2012 5:21:15 PM | Computer Name = Jeff-HP | Source = CaslWmi | ID = 5
Description = 2012/08/05 14:21:15.909|00001698|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

Error - 8/5/2012 5:21:24 PM | Computer Name = Jeff-HP | Source = CaslWmi | ID = 5
Description = 2012/08/05 14:21:24.175|000017BC|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state

[ System Events ]
Error - 12/14/2012 11:12:37 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 12/14/2012 11:12:37 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 12/14/2012 11:48:19 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 12/15/2012 1:16:38 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 12/15/2012 1:16:41 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 12/15/2012 1:16:43 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 12/15/2012 1:16:50 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 12/15/2012 1:16:52 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 12/15/2012 1:16:52 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.

Error - 12/15/2012 1:17:03 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.


< End of report >

Attachments:

[external image: Posted Image]

As you can see their is no information oh who this licence belongs to, what the exp date is. That was never the case before i don't know whats going on maybe i can try and re download a new avast software and then try download the license file.lic and inserting it.
Hi jeff matthews,

I don't see any malware. There are a few things we can clean up later. For now let's see if you can get Avast up and running. Do not use any other tools or do any other scans.

This looks like you may have been hit with a glitch in one of Avast's latest VPS updates which caused much the same behaviour in some installs.

Please follow these instructions to preform a clean uninstall-reinstall.

Download aswClear to your Desktop.
Download the correct version of Avast
http://files.avast.com/iavs5x/avast_free_antivirus_setup.exe
http://files.avast.com/iavs5x/avast_pro_antivirus_setup.exe
http://files.avast.com/iavs5x/avast_intern…urity_setup.exe

Disconnect from the net
Uninstall Avast via control panel

  • Boot to Safe Mode.
    • Restart the computer.
    • As soon as BIOS is loaded begin tapping the F8 key until the Advanced Options menu appears.
    • Use the arrow keys to select the Safe mode with Networking menu item
    • Press Enter.
  • Run aswClear
  • In the Select Product to Uninstall dropdown choose the version of Avast that is on your system.
    [external image: Posted Image]
  • Press Uninstall
  • Once complete reboot your system to Normal Mode
  • Reinstall Avast
Try inserting your licence key.

Let me know how it goes.
Well it worked. Avast is up and running, all shields are active, shows my license subscription the way its supposed to be and how many days remaining I am very annoyed that a professional avast representative would not be able to figure this out. Hell this guy didn't even tell me how to insert the vast file into the software, thats common sense and ive always know how to do this. NO what this person did was show me a bunch of errors reports on my registry or the health of my pc, showing me that its in a critical state and then sent me the avast license file through email and shown me how to open it through the email. This was with a .bat ext. Anyone that remotely knows anything bout computers knows that you can't double click any extension to open it, its going to say "cannot find the file associated with this application" this is what he was showing me when he was remote connected to my machine. He was simply playing me for a fool. I asked him well don't you have to insert the file into avast and he told me "see it does not work, it says no application found" This guy should of been fired for trying to pull a fast one on me like that. Just to try and sell me his services because he didn't want to do his job the right way and fix my avast software.
Hi jeff matthews,

Good job!

Keep in mind that this Tech does not work directly for Avast. PlumChoice is a company that contracts support/help for various software companies. From your experience it looks like the employees also try to upsell services to the person that is seeking help. I'd speculate that there may be a bonus for selling a support package.

The problem with CCleaner is the option to "clean" the registry. Registry cleaners do nothing for the preformance of Windows they do however have a great protential to cause problems. See here.

Superantispyware logs tracking cookies. This IMO is a bit of over kill. If this is what it found when you ran the scan I don't think you are in any danger.

You also have MBAM installed. These 2 programs do the same thing. I suggest you uninstall SAS and keep MBAM.

You can also uninstall CCleaner I'll give you a better temp file cleaner when we are done.

Next, openOTL.exe
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
  • Do Not copy the word CODE
  • please note the fix starts with the :
:Services

:OTL
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.iyogi.com/
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{5AA0FB2F-45B5-4b28-8E51-261F7382C1A8}: "URL" = http://search.iyogi.com/search.html?hl=en&…q={searchTerms}

:Reg
[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"Bomgar_Cleanup_ZD7101125413"=-
[HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run]
"Bomgar_Cleanup_ZD7101125413"=-
[HKEY_USERS\S-1-5-21-3952182868-3481799418-86632157-1001\Software\Microsoft\Windows\CurrentVersion\Run]
"Bomgar_Cleanup_ZD463527019543"=-

:Files
C:\ProgramData\iyogi-scc-0000000050C671CB

:Commands
[emptytemp]
[createrestorepoint]

Then click the Run Fix button at the top
  • Let the program run unhindered
  • Please save the resulting log to be posted in your next reply.
Please post the OTL fix log.

Next

  • Please download AdwCleaner by Xplode onto your desktop.
  • Close all open programs and internet browsers.
  • Right Click the desktop icon and click "Run as Administrator" to run AdwCleaner.exe
  • Click on Search.
  • Please post the content of that logfile with your next answer.
  • You can find the logfile at C:\AdwCleaner[S1].txt as well.

Please post back with
  • OTL fix log
  • AdwCleaner log
Is the problem with iyogi still there?
Yeah i noticed that CCcleaning tries to update and clean my computer like every time i turn it on, its kind of annoying.

Here is my OTL log


All processes killed
========== SERVICES/DRIVERS ==========
========== OTL ==========
HKU\S-1-5-21-3952182868-3481799418-86632157-1001\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
Registry key HKEY_USERS\S-1-5-21-3952182868-3481799418-86632157-1001\Software\Microsoft\Internet Explorer\SearchScopes\{5AA0FB2F-45B5-4b28-8E51-261F7382C1A8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{5AA0FB2F-45B5-4b28-8E51-261F7382C1A8}\ not found.
========== REGISTRY ==========
Registry value HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run\\Bomgar_Cleanup_ZD7101125413 deleted successfully.
Registry value HKEY_USERS\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Run\\Bomgar_Cleanup_ZD7101125413 not found.
Registry value HKEY_USERS\S-1-5-21-3952182868-3481799418-86632157-1001\Software\Microsoft\Windows\CurrentVersion\Run\\Bomgar_Cleanup_ZD463527019543 not found.
========== FILES ==========
File\Folder C:\ProgramData\iyogi-scc-0000000050C671CB not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 57616 bytes

User: Default User

User: Jeff
->Temp folder emptied: 91493590 bytes
->Temporary Internet Files folder emptied: 91572563 bytes
->Java cache emptied: 4574847 bytes
->FireFox cache emptied: 2485188 bytes
->Google Chrome cache emptied: 359276159 bytes
->Flash cache emptied: 740 bytes

User: Public

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 41582280 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 67630 bytes
RecycleBin emptied: 31168715 bytes

Total Files Cleaned = 593.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 04062013_114312

Files\Folders moved on Reboot…
C:\Users\Jeff\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Users\Jeff\AppData\Local\Temp\~DF1C520274713E0E19.TMP not found!
C:\Users\Jeff\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{D014DD23-1D4C-4ED2-BD9C-4EF93DCDD533}.tmp moved successfully.
C:\Users\Jeff\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{08FEBB97-D206-4045-830E-558F81AAE609}.tmp moved successfully.
C:\Users\Jeff\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{3CF8493B-194F-4C04-A1E6-8E7EBCD1CD1D}.tmp moved successfully.
C:\Users\Jeff\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{7C140FF4-1081-4359-9FD2-3BAAF244B6E5}.tmp moved successfully.
File\Folder C:\Users\Jeff\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{B3257AA8-F29E-4240-8490-5122FD092E52}.tmp not found!
C:\Users\Jeff\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{C2FE1685-5984-4680-A206-D8238CFF2DF2}.tmp moved successfully.
File move failed. C:\Windows\temp\_avast_\Webshlock.txt scheduled to be moved on reboot.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…


ADW Cleaner log

# AdwCleaner v2.200 - Logfile created 04/06/2013 at 11:53:38
# Updated 02/04/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Jeff - JEFF-HP
# Boot Mode : Normal
# Running from : C:\Users\Jeff\Desktop\adwcleaner.exe
# Option [Search]


***** [Services] *****


***** [Files / Folders] *****

File Found : C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\9odu2h93.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
File Found : C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\9odu2h93.default\searchplugins\SweetIm.xml
File Found : C:\Users\Public\Desktop\eBay.lnk
Folder Found : C:\Program Files (x86)\AVG Secure Search
Folder Found : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Found : C:\Program Files (x86)\Common Files\spigot
Folder Found : C:\Program Files (x86)\SweetIM
Folder Found : C:\ProgramData\AVG Secure Search
Folder Found : C:\ProgramData\boost_interprocess
Folder Found : C:\ProgramData\InstallMate
Folder Found : C:\Users\Jeff\AppData\Local\AVG Secure Search
Folder Found : C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Folder Found : C:\Users\Jeff\AppData\LocalLow\AVG Secure Search
Folder Found : C:\Users\Jeff\AppData\LocalLow\boost_interprocess
Folder Found : C:\Users\Jeff\AppData\LocalLow\Search Settings

***** [Registry] *****

Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Found : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Found : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Found : HKU\S-1-5-21-3952182868-3481799418-86632157-1001\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Value Found : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Value Found : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16464

[OK] Registry is clean.

-\\ Mozilla Firefox v19.0.2 (en-US)

File : C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\9odu2h93.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v26.0.1410.43

File : C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [3669 octets] - [06/04/2013 11:53:38]

########## EOF - C:\AdwCleaner[R1].txt - [3729 octets] ##########


The folder of the iYogee Support dock still remains in the directory of my C drive, but their is nothing in the folder.

One more question i have to ask and this is just something that has been bugging me latly, is my "Youcame Device" which is what works my webcam, has stopped running some how and its having issues getting a video feedback on my computer, i can't use right now because of that problem, i tried turning on and off and still nothing. So i am not whats going on with that. It might have had something to do with all those processes when they stopped running.
Hi jeff matthews,

You can delete the Iyogi folder.

Perhaps uninstalling and reinstalling Youcame Device would correct it.


  • Close all open programs and internet browsers.
  • Right click on adwcleaner.exe and click "Tun as administrator" to run the tool.
  • Click on the Delete button.
  • A logfile will automatically open after the scan has finished.
Copy and paste the adwcleaner.txt report into your next reply.
I still have all those log files, like otl, dds, extra's aswmbr, you want me to just delete those off my desktop? Besides that everything seems to be ok with this machine i think. It looks like everything is clean.

I know we are not supposed to open another case until the current one is finished but i think this one is just bout finished so when we are done with this case, i have another computer i am working on has some major issues being able to log in to windows, anyways i posted the topic here

http://forums.whatthetech.com/index.php?showtopic=125914

So once we are done with the case you might take a look at that one, or someone else can if your don't have the time, it looks to be far worse then what i have judging by the logs.


Here is my log file for ADWcleaner

# AdwCleaner v2.200 - Logfile created 04/07/2013 at 11:38:59
# Updated 02/04/2013 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : Jeff - JEFF-HP
# Boot Mode : Normal
# Running from : C:\Users\Jeff\Desktop\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

File Deleted : C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\9odu2h93.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
File Deleted : C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\9odu2h93.default\searchplugins\SweetIm.xml
File Deleted : C:\Users\Public\Desktop\eBay.lnk
Folder Deleted : C:\Program Files (x86)\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Common Files\AVG Secure Search
Folder Deleted : C:\Program Files (x86)\Common Files\spigot
Folder Deleted : C:\Program Files (x86)\SweetIM
Folder Deleted : C:\ProgramData\AVG Secure Search
Folder Deleted : C:\ProgramData\boost_interprocess
Folder Deleted : C:\ProgramData\InstallMate
Folder Deleted : C:\Users\Jeff\AppData\Local\AVG Secure Search
Folder Deleted : C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd
Folder Deleted : C:\Users\Jeff\AppData\LocalLow\AVG Secure Search
Folder Deleted : C:\Users\Jeff\AppData\LocalLow\boost_interprocess
Folder Deleted : C:\Users\Jeff\AppData\LocalLow\Search Settings

***** [Registry] *****

Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Ext\PreApproved\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\CLSID\{EF99BD32-C1FB-11D2-892F-0090271D4F88}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Classes\Interface\{79FB5FC8-44B9-4AF5-BADD-CCE547F953E5}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Key Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{02478D38-C3F9-4EFB-9B51-7695ECA05670}
Key Deleted : HKLM\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2FA28606-DE77-4029-AF96-B231E3B8F827}
Value Deleted : HKCU\Software\Microsoft\Internet Explorer\URLSearchHooks [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]
Value Deleted : HKLM\SOFTWARE\Wow6432Node\Microsoft\Internet Explorer\Toolbar [{EF99BD32-C1FB-11D2-892F-0090271D4F88}]

***** [Internet Browsers] *****

-\\ Internet Explorer v9.0.8112.16470

[OK] Registry is clean.

-\\ Mozilla Firefox v19.0.2 (en-US)

File : C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\9odu2h93.default\prefs.js

[OK] File is clean.

-\\ Google Chrome v26.0.1410.43

File : C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Preferences

[OK] File is clean.

*************************

AdwCleaner[R1].txt - [3794 octets] - [06/04/2013 11:53:38]
AdwCleaner[S1].txt - [3638 octets] - [07/04/2013 11:38:59]

########## EOF - C:\AdwCleaner[S1].txt - [3698 octets] ##########

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI