Ok as far as symptoms, nothing that i really experience that is slowing down my computer. How ever i did have that issue with "Updater sweetpacks" That i saw the moment i opened up my browser and it started rerouting certain URLS's but its not doing it now so maybe its gone im not sure?
Superantispyware how ever found some like 30 infections but i am not sure if those are real or not. In fact i might just delete that superantispyware. The Iyogee Dock is still in my registry probably. I want to make sure i get rid of that. I did check my avast it said "expiration active" but it also said "0 days remaining" I checked my lisence file the moment i bought avast, and it clearly should not be over a year old , i so tried to install that lisencefile.lic into my avast and it says "unable to find file, the system can't specify the file" I also have that CCcleaner in my system as well that i used what is your take on that, do you think i should remove that?
I am pretty irritated at the fact that some one, a professional company would use deception and lies to try and get you purchase their product. In any case, like i said i searched my license file and i bought it in may 2012, that means it should expire next month and not now, it doesn't many any sense to me.
Here is my aswMBR log
It has a few errors in regards to trying to download the avast definitions.
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software
Run date: 2013-04-04 22:47:37
—————————–
22:47:37.405 OS Version: Windows x64 6.1.7601 Service Pack 1
22:47:37.405 Number of processors: 4 586 0x100
22:47:37.406 ComputerName: JEFF-HP UserName: Jeff
22:47:38.823 Initialize success
22:50:13.250 AVAST engine error: 2
22:50:23.296 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\00000073
22:50:23.301 Disk 0 Vendor: ST950032 0005 Size: 476940MB BusType: 11
22:50:23.420 Disk 0 MBR read successfully
22:50:23.426 Disk 0 MBR scan
22:50:23.433 Disk 0 Windows 7 default MBR code
22:50:23.451 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 199 MB offset 2048
22:50:23.457 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 451351 MB offset 409600
22:50:23.487 Disk 0 Partition 3 00 07 HPFS/NTFS NTFS 21325 MB offset 924776448
22:50:23.505 Disk 0 Partition 4 00 0C FAT32 LBA MSDOS5.0 4063 MB offset 968450048
22:50:23.650 Disk 0 scanning C:\Windows\system32\drivers
22:50:32.991 Service scanning
22:50:55.497 Modules scanning
22:50:55.507 Disk 0 trace - called modules:
22:50:55.573 ntoskrnl.exe CLASSPNP.SYS disk.sys amd_xata.sys storport.sys hal.dll amd_sata.sys
22:50:55.587 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0xfffffa8007192060]
22:50:55.599 3 CLASSPNP.SYS[fffff8800195443f] -> nt!IofCallDriver -> [0xfffffa8006b7c590]
22:50:55.607 5 amd_xata.sys[fffff880010f9b3f] -> nt!IofCallDriver -> \Device\00000073[0xfffffa8006b79060]
22:50:55.613 Scan finished successfully
22:51:07.666 Disk 0 MBR has been saved successfully to "C:\Users\Jeff\Desktop\MBR.dat"
22:51:07.673 The log file has been saved successfully to "C:\Users\Jeff\Desktop\aswMBR.txt"
Here are the OTL logs
OTL logfile created on: 4/4/2013 11:07:03 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jeff\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.48 Gb Total Physical Memory | 4.42 Gb Available Physical Memory | 59.08% Memory free
14.96 Gb Paging File | 11.15 Gb Available in Paging File | 74.57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 440.77 Gb Total Space | 194.88 Gb Free Space | 44.21% Space Free | Partition Type: NTFS
Drive D: | 20.83 Gb Total Space | 2.25 Gb Free Space | 10.79% Space Free | Partition Type: NTFS
Drive E: | 3.96 Gb Total Space | 3.95 Gb Free Space | 99.77% Space Free | Partition Type: FAT32
Computer Name: JEFF-HP | User Name: Jeff | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - [2013/04/04 22:59:52 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Jeff\Desktop\OTL.exe
PRC - [2013/03/12 00:05:50 | 029,106,336 | —- | M] (Dropbox, Inc.) – C:\Users\Jeff\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013/03/06 15:32:44 | 004,767,304 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\AvastUI.exe
PRC - [2013/03/06 15:32:42 | 000,136,912 | —- | M] (AVAST Software) – C:\Program Files\AVAST Software\Avast\afwServ.exe
PRC - [2012/12/18 07:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/11/29 19:06:58 | 001,263,512 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
PRC - [2012/10/25 21:12:06 | 000,139,792 | —- | M] (CyberLink) – C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
PRC - [2012/08/10 16:48:50 | 000,197,536 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe
PRC - [2012/03/05 13:38:38 | 000,578,944 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
PRC - [2012/03/05 13:38:38 | 000,035,200 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
PRC - [2012/01/06 09:35:22 | 000,569,072 | —- | M] (CrossLoop) – C:\Users\Jeff\AppData\Local\CrossLoop\CrossLoopService.exe
PRC - [2011/10/07 19:10:48 | 000,169,528 | —- | M] (Hewlett-Packard Company) – C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe
PRC - [2011/09/27 11:44:20 | 000,439,440 | —- | M] (CANON INC.) – C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe
PRC - [2011/08/19 14:48:44 | 000,379,960 | —- | M] (Hewlett-Packard Development Company, L.P.) – C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe
PRC - [2011/08/04 14:44:24 | 000,593,032 | —- | M] (CANON INC.) – C:\Program Files (x86)\Canon\Solution Menu EX\CNSEUPDT.EXE
PRC - [2011/08/04 14:41:44 | 001,637,496 | —- | M] (CANON INC.) – C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE
PRC - [2009/07/20 11:51:52 | 000,935,208 | —- | M] (Nero AG) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe
PRC - [2009/05/14 18:07:14 | 000,759,048 | —- | M] (ABBYY) – C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
PRC - [2002/12/17 17:26:22 | 007,520,337 | —- | M] (Microsoft Corporation) – C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe
========== Modules (No Company Name) ==========
MOD - [2013/03/21 15:50:33 | 000,390,096 | —- | M] () – C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\ppgooglenaclpluginchrome.dll
MOD - [2013/03/21 15:50:32 | 012,662,224 | —- | M] () – C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\PepperFlash\pepflashplayer.dll
MOD - [2013/03/21 15:50:31 | 004,050,896 | —- | M] () – C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\pdf.dll
MOD - [2013/03/21 15:49:41 | 000,598,480 | —- | M] () – C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\libglesv2.dll
MOD - [2013/03/21 15:49:40 | 000,124,368 | —- | M] () – C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\libegl.dll
MOD - [2013/03/21 15:49:38 | 001,606,096 | —- | M] () – C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\ffmpegsumo.dll
MOD - [2013/01/08 12:35:41 | 011,493,376 | —- | M] () – C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2012/11/29 19:07:48 | 000,100,248 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdateCheck.dll
MOD - [2012/11/29 19:06:58 | 001,263,512 | —- | M] () – C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe
MOD - [2011/03/17 00:11:16 | 004,297,568 | —- | M] () – C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/10/20 15:45:26 | 008,801,120 | —- | M] () – C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll
========== Services (SafeList) ==========
SRV:
64bit: - [2013/03/06 15:32:44 | 000,045,248 | —- | M] (AVAST Software) [Auto | Stopped] – C:\Program Files\AVAST Software\Avast\AvastSvc.exe – (avast! Antivirus)
SRV:
64bit: - [2013/03/06 15:32:42 | 000,136,912 | —- | M] (AVAST Software) [Auto | Running] – C:\Program Files\AVAST Software\Avast\afwServ.exe – (avast! Firewall)
SRV:
64bit: - [2012/07/11 11:54:58 | 000,140,672 | —- | M] (SUPERAntiSpyware.com) [Auto | Running] – C:\Program Files\SUPERAntiSpyware\SASCore64.exe – (!SASCORE)
SRV:
64bit: - [2011/09/16 03:12:12 | 000,204,288 | —- | M] (AMD) [Auto | Running] – C:\Windows\SysNative\atiesrxx.exe – (AMD External Events Utility)
SRV:
64bit: - [2011/09/15 15:15:44 | 000,361,984 | —- | M] (Advanced Micro Devices, Inc.) [Auto | Running] – C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe – (AMD FUEL Service)
SRV:
64bit: - [2011/09/08 06:42:28 | 000,305,152 | —- | M] (IDT, Inc.) [Auto | Running] – C:\Program Files\IDT\WDM\stacsv64.exe – (STacSV)
SRV:
64bit: - [2011/02/16 22:47:28 | 000,682,040 | —- | M] (Hewlett-Packard) [Auto | Running] – C:\Program Files\Hewlett-Packard\HP Auto\HPAuto.exe – (HPAuto)
SRV:
64bit: - [2010/10/11 02:48:14 | 000,346,168 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe – (HPClientSvc)
SRV:
64bit: - [2009/07/13 18:41:27 | 001,011,712 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2013/03/13 10:51:57 | 000,253,656 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/03/07 07:30:44 | 000,115,608 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2013/01/08 13:53:48 | 000,161,536 | R— | M] (Skype Technologies) [Auto | Stopped] – C:\Program Files (x86)\Skype\Updater\Updater.exe – (SkypeUpdate)
SRV - [2012/12/18 07:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2012/09/27 12:55:16 | 000,086,528 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe – (HP Support Assistant Service)
SRV - [2012/08/10 16:48:50 | 000,197,536 | —- | M] (Hewlett-Packard Company) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\Shared\HPDrvMntSvc.exe – (HPDrvMntSvc.exe)
SRV - [2012/08/02 11:56:54 | 001,095,824 | —- | M] (Corel Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Roxio Shared\Game1X\SharedCOM\RoxMediaDBGame1X.exe – (RoxMediaDBGame1X)
SRV - [2012/03/05 13:38:38 | 000,035,200 | —- | M] (Hewlett-Packard Development Company, L.P.) [Auto | Running] – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe – (HPWMISVC)
SRV - [2012/01/06 09:35:22 | 000,569,072 | —- | M] (CrossLoop) [Auto | Running] – C:\Users\Jeff\AppData\Local\CrossLoop\CrossLoopService.exe – (CrossLoopService)
SRV - [2011/08/29 11:02:22 | 002,424,424 | —- | M] (Realsil Microelectronics Inc.) [Auto | Running] – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe – (IconMan_R)
SRV - [2010/10/12 10:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2010/07/21 08:50:26 | 000,814,080 | —- | M] (GlavSoft LLC.) [On_Demand | Stopped] – C:\Users\Jeff\AppData\Local\CrossLoop\tvnserver.exe – (tvnserver)
SRV - [2010/03/18 13:16:28 | 000,130,384 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe – (clr_optimization_v4.0.30319_32)
SRV - [2010/02/19 13:37:14 | 000,517,096 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe – (SwitchBoard)
SRV - [2009/07/20 11:51:52 | 000,935,208 | —- | M] (Nero AG) [Auto | Running] – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe – (Nero BackItUp Scheduler 4.0)
SRV - [2009/06/10 14:23:09 | 000,066,384 | —- | M] (Microsoft Corporation) [Disabled | Stopped] – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe – (clr_optimization_v2.0.50727_32)
SRV - [2009/05/14 18:07:14 | 000,759,048 | —- | M] (ABBYY) [Auto | Running] – C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe – (ABBYY.Licensing.FineReader.Sprint.9.0)
SRV - [2002/12/17 17:26:22 | 007,520,337 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlservr.exe – (MSSQL$SONY_MEDIAMGR)
SRV - [2002/12/17 17:23:30 | 000,311,872 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files (x86)\Sony\Shared Plug-Ins\Media Manager\MSSQL$SONY_MEDIAMGR\Binn\sqlagent.EXE – (SQLAgent$SONY_MEDIAMGR)
========== Driver Services (SafeList) ==========
DRV:
64bit: - [2013/03/06 15:33:21 | 001,025,808 | —- | M] (AVAST Software) [File_System | System | Running] – C:\Windows\SysNative\drivers\aswSnx.sys – (aswSnx)
DRV:
64bit: - [2013/03/06 15:33:21 | 000,377,920 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswSP.sys – (aswSP)
DRV:
64bit: - [2013/03/06 15:33:21 | 000,178,624 | —- | M] () [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\aswVmm.sys – (aswVmm)
DRV:
64bit: - [2013/03/06 15:33:21 | 000,070,992 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswRdr2.sys – (aswRdr)
DRV:
64bit: - [2013/03/06 15:33:21 | 000,068,920 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswTdi.sys – (aswTdi)
DRV:
64bit: - [2013/03/06 15:33:21 | 000,065,336 | —- | M] () [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswRvrt.sys – (aswRvrt)
DRV:
64bit: - [2013/03/06 15:33:20 | 000,263,096 | —- | M] (AVAST Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis2.sys – (aswNdis2)
DRV:
64bit: - [2013/03/06 15:33:20 | 000,127,136 | —- | M] (AVAST Software) [Kernel | System | Running] – C:\Windows\SysNative\drivers\aswFW.sys – (aswFW)
DRV:
64bit: - [2013/03/06 15:33:20 | 000,080,816 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswMonFlt.sys – (aswMonFlt)
DRV:
64bit: - [2013/03/06 15:33:20 | 000,033,400 | —- | M] (AVAST Software) [File_System | Auto | Running] – C:\Windows\SysNative\drivers\aswFsBlk.sys – (aswFsBlk)
DRV:
64bit: - [2013/03/06 15:33:20 | 000,022,600 | —- | M] (AVAST Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswKbd.sys – (aswKbd)
DRV:
64bit: - [2012/08/15 06:16:06 | 000,546,480 | —- | M] (Hauppauge Computer Work, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcwE5bda.sys – (hcwE5bda)
DRV:
64bit: - [2012/08/03 18:49:18 | 000,040,432 | —- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\clwvd.sys – (clwvd)
DRV:
64bit: - [2012/08/02 11:18:08 | 000,101,632 | —- | M] (UT) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\uth5x64.sys – (H5xUSB)
DRV:
64bit: - [2012/07/31 11:45:10 | 000,038,992 | —- | M] (Screaming Bee LLC) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\ScreamingBAudio64.sys – (ScreamBAudioSvc)
DRV:
64bit: - [2012/07/10 03:01:00 | 000,056,336 | —- | M] (Corel Corporation) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\PxHlpa64.sys – (PxHlpa64)
DRV:
64bit: - [2012/06/27 13:33:54 | 000,012,368 | —- | M] (ALWIL Software) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\aswNdis.sys – (aswNdis)
DRV:
64bit: - [2012/04/12 19:45:04 | 001,860,672 | —- | M] (Ralink Technology, Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\netr28x.sys – (netr28x)
DRV:
64bit: - [2012/03/09 10:57:36 | 000,023,816 | —- | M] (CPUID) [Kernel | Auto | Running] – C:\Windows\SysNative\drivers\cpuz135_x64.sys – (cpuz135)
DRV:
64bit: - [2012/02/29 23:46:16 | 000,023,408 | —- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] – C:\Windows\SysNative\drivers\fs_rec.sys – (Fs_Rec)
DRV:
64bit: - [2011/10/25 20:53:55 | 000,107,904 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsata.sys – (amdsata)
DRV:
64bit: - [2011/10/25 20:53:55 | 000,027,008 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amdxata.sys – (amdxata)
DRV:
64bit: - [2011/09/16 03:51:12 | 010,206,208 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmdag.sys – (amdkmdag)
DRV:
64bit: - [2011/09/16 02:38:42 | 000,317,952 | —- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\atikmpag.sys – (amdkmdap)
DRV:
64bit: - [2011/09/08 06:42:28 | 000,535,040 | —- | M] (IDT, Inc.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\stwrt64.sys – (STHDA)
DRV:
64bit: - [2011/08/29 11:02:28 | 000,339,048 | —- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\RtsPStor.sys – (RSPCIESTOR)
DRV:
64bit: - [2011/08/18 05:44:46 | 000,053,376 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\usbfilter.sys – (usbfilter)
DRV:
64bit: - [2011/07/22 09:26:56 | 000,014,928 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys – (SASDIFSV)
DRV:
64bit: - [2011/07/21 20:01:14 | 001,448,496 | —- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\SynTP.sys – (SynTP)
DRV:
64bit: - [2011/07/12 14:55:18 | 000,012,368 | —- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] – C:\Program Files\SUPERAntiSpyware\saskutil64.sys – (SASKUTIL)
DRV:
64bit: - [2011/06/17 04:08:26 | 000,040,064 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amd_xata.sys – (amd_xata)
DRV:
64bit: - [2011/06/17 04:08:24 | 000,079,488 | —- | M] (Advanced Micro Devices) [Kernel | Boot | Running] – C:\Windows\SysNative\drivers\amd_sata.sys – (amd_sata)
DRV:
64bit: - [2011/06/10 15:34:52 | 000,539,240 | —- | M] (Realtek ) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\Rt64win7.sys – (RTL8167)
DRV:
64bit: - [2011/03/30 15:46:46 | 000,114,704 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\AtihdW76.sys – (AtiHDAudioService)
DRV:
64bit: - [2010/11/20 20:24:33 | 000,059,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV:
64bit: - [2010/11/20 20:23:47 | 000,109,056 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\sdbus.sys – (sdbus)
DRV:
64bit: - [2010/11/20 20:23:47 | 000,078,720 | —- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\HpSAMD.sys – (HpSAMD)
DRV:
64bit: - [2010/11/20 20:23:47 | 000,031,232 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\TsUsbGD.sys – (TsUsbGD)
DRV:
64bit: - [2010/02/18 10:18:24 | 000,046,136 | —- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] – C:\Windows\SysNative\drivers\amdiox64.sys – (amdiox64)
DRV:
64bit: - [2009/07/13 18:52:20 | 000,194,128 | —- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\amdsbs.sys – (amdsbs)
DRV:
64bit: - [2009/07/13 18:48:04 | 000,065,600 | —- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\lsi_sas2.sys – (LSI_SAS2)
DRV:
64bit: - [2009/07/13 18:45:55 | 000,024,656 | —- | M] (Promise Technology) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\stexstor.sys – (stexstor)
DRV:
64bit: - [2009/07/13 17:35:32 | 000,012,288 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\serscan.sys – (StillCam)
DRV:
64bit: - [2009/06/10 14:01:11 | 001,485,312 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTDPV6.SYS – (SrvHsfV92)
DRV:
64bit: - [2009/06/10 14:01:11 | 000,740,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTCNXT6.SYS – (SrvHsfWinac)
DRV:
64bit: - [2009/06/10 14:01:11 | 000,292,864 | —- | M] (Conexant Systems, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\VSTAZL6.SYS – (SrvHsfHDA)
DRV:
64bit: - [2009/06/10 13:35:35 | 000,408,960 | —- | M] (NVIDIA Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\nvm62x64.sys – (NVENETFD)
DRV:
64bit: - [2009/06/10 13:34:38 | 001,311,232 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\BCMWL664.SYS – (BCM43XX)
DRV:
64bit: - [2009/06/10 13:34:33 | 003,286,016 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\evbda.sys – (ebdrv)
DRV:
64bit: - [2009/06/10 13:34:28 | 000,468,480 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\bxvbda.sys – (b06bdrv)
DRV:
64bit: - [2009/06/10 13:34:23 | 000,270,848 | —- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\b57nd60a.sys – (b57nd60a)
DRV:
64bit: - [2009/06/10 13:31:59 | 000,031,232 | —- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\hcw85cir.sys – (hcw85cir)
DRV:
64bit: - [2008/05/06 16:06:00 | 000,014,464 | —- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] – C:\Windows\SysNative\drivers\wdcsam64.sys – (WDC_SAM)
DRV - [2009/07/13 18:19:10 | 000,019,008 | —- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] – C:\Windows\SysWOW64\drivers\wimmount.sys – (WIMMount)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE:
64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:
64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE:
64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE:
64bit: - HKLM\..\SearchScopes\{4D7A8A72-5294-44C3-A010-B60E1A356E88}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE:
64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE:
64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE:
64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11…w={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT/1
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKLM\..\SearchScopes\{4D7A8A72-5294-44C3-A010-B60E1A356E88}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11…w={searchTerms}
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.iyogi.com/
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\URLSearchHook: {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{4D7A8A72-5294-44C3-A010-B60E1A356E88}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{5AA0FB2F-45B5-4b28-8E51-261F7382C1A8}: "URL" =
http://search.iyogi.com/search.html?hl=en&…q={searchTerms}
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia.org/wiki/Special:Searc…h={searchTerms}
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-30572-11…w={searchTerms}
IE - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ==========
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:19.0.2
FF - user.js - File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~3\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@canon.com/EPPEX: C:\Program Files (x86)\Canon\Easy-PhotoPrint EX\NPEZFFPI.DLL (CANON INC.)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX, LLC)
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX VOD Helper,version=1.0.0: C:\Program Files (x86)\DivX\DivX OVS Helper\npovshelper.dll (DivX, LLC.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=16.4.3505.0912: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=6.0.11.2571: C:\Program Files (x86)\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpjplug;version=6.0.12.1739: C:\Program Files (x86)\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nsJSRealPlayerPlugin;version=: File not found
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Jeff\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Jeff\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{23fcfd51-4958-4f00-80a3-ae97e717ed8b}: C:\Program Files (x86)\DivX\DivX Plus Web Player\firefox\DivXHTML5 [2012/12/23 23:38:59 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/03/28 03:15:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 19.0.2\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins
[2013/03/28 03:16:04 | 000,000,000 | —D | M] (No name found) – C:\Users\Jeff\AppData\Roaming\Mozilla\Extensions
[2013/04/03 01:43:46 | 000,000,000 | —D | M] (No name found) – C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\9odu2h93.default\extensions
[2013/04/03 01:43:46 | 000,195,574 | —- | M] () (No name found) – C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\9odu2h93.default\extensions\{EEE6C361-6118-11DC-9C72-001320C79847}.xpi
[2013/04/03 01:43:08 | 000,000,514 | —- | M] () – C:\Users\Jeff\AppData\Roaming\Mozilla\Firefox\Profiles\9odu2h93.default\searchplugins\sweetim.xml
[2013/03/28 03:15:49 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/03/07 07:31:00 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2013/03/07 07:30:20 | 000,002,465 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2013/03/07 07:30:20 | 000,002,086 | —- | M] () – C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{g
oogle:assistedQueryStats}{google:searchFieldtrialParameter}{google:searchClient}
{
google:sourceId}{google:instantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Jeff\AppData\Local\Google\Chrome\Application\22.0.1229.79\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\system32\Macromed\Flash\NPSWF32.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Jeff\AppData\Local\Google\Chrome\Application\26.0.1410.43\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Users\Jeff\AppData\Local\Google\Chrome\Application\plugins\npMozCouponPrinter.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\12.2.6\\npsitesafety.dll
CHR - plugin: Java™ Platform SE 7 U7 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.70.11 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: RealPlayer™ G2 LiveConnect-Enabled Plug-In (32-bit) (Enabled) = C:\Program Files (x86)\MpcStar\Codecs\Real\browser\plugins\nppl3260.dll
CHR - plugin: RealPlayer Version Plugin (Enabled) = C:\Program Files (x86)\MpcStar\Codecs\Real\browser\plugins\nprpjplug.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Jeff\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - Extension: WOT = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.11_0\
CHR - Extension: Updater By SweetPacks = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.566_0\
CHR - Extension: AdBlock = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.61_0\
CHR - Extension: avast! WebRep = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\8.0.1483_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
CHR - Extension: WOT = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.11_0\
CHR - Extension: Updater By SweetPacks = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlnembnfbcpjnepmfjmngjenhhajpdfd\2.0.0.566_0\
CHR - Extension: AdBlock = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.5.61_0\
CHR - Extension: avast! WebRep = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\icmlaeflemplmjndnaapfdbbnpncnbda\8.0.1483_0\
CHR - Extension: DivX Plus Web Player HTML5 \u003Cvideo\u003E = C:\Users\Jeff\AppData\Local\Google\Chrome\User Data\Default\Extensions\nneajnkjbffgblleaoojgaacokifdkhm\2.1.2.145_0\
Hosts file not found
O2:
64bit: - BHO: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:
64bit: - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2 - BHO: (&Yahoo;! Toolbar Helper) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O2 - BHO: (DivX Plus Web Player HTML5 ) - {326E768D-4182-46FD-9C16-1449A49795F4} - C:\Program Files (x86)\DivX\DivX Plus Web Player\ie\DivXHTML5\DivXHTML5.dll (DivX, LLC)
O2 - BHO: (Canon Easy-WebPrint EX BHO) - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexbho.dll (CANON INC.)
O2 - BHO: (SteadyVideoBHO Class) - {6C680BAE-655C-4E3D-8FC4-E6A520C3D928} - C:\Program Files (x86)\AMD\SteadyVideo\SteadyVideo.dll (Advanced Micro Devices)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O2 - BHO: (SingleInstance Class) - {FDAD4DA1-61A2-4FD8-9C17-86F7AC245081} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\YTSingleInstance.dll (Yahoo! Inc)
O3:
64bit: - HKLM\..\Toolbar: (avast! WebRep) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Canon Easy-WebPrint EX) - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files (x86)\Canon\Easy-WebPrint EX\ewpexhlp.dll (CANON INC.)
O3 - HKLM\..\Toolbar: (avast! WebRep) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (Yahoo! Toolbar) - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files (x86)\Yahoo!\Companion\Installs\cpn\yt.dll (Yahoo! Inc.)
O3 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\..\Toolbar\WebBrowser: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O4:
64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:
64bit: - HKLM..\Run: [CanonMyPrinter] C:\Program Files\Canon\MyPrinter\BJMyPrt.exe (CANON INC.)
O4:
64bit: - HKLM..\Run: [SetDefault] C:\Program Files\Hewlett-Packard\HP LaunchBox\SetDefault.exe (Hewlett-Packard Development Company, L.P.)
O4:
64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeCS5.5ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS5.5ServiceManager\CS5.5ServiceManager.exe" -launchedbylogin File not found
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [CanonSolutionMenuEx] C:\Program Files (x86)\Canon\Solution Menu EX\CNSEMAIN.EXE (CANON INC.)
O4 - HKLM..\Run: [DivXMediaServer] C:\Program Files (x86)\DivX\DivX Media Server\DivXMediaServer.exe ()
O4 - HKLM..\Run: [DivXUpdate] C:\Program Files (x86)\DivX\DivX Update\DivXUpdate.exe ()
O4 - HKLM..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPOSD] C:\Program Files (x86)\Hewlett-Packard\HP On Screen Display\HPOSD.exe (Hewlett-Packard Development Company, L.P.)
O4 - HKLM..\Run: [HPQuickWebProxy] C:\Program Files (x86)\Hewlett-Packard\HP QuickWeb\hpqwutils.exe (Hewlett-Packard Company)
O4 - HKLM..\Run: [IJNetworkScannerSelectorEX] C:\Program Files (x86)\Canon\IJ Network Scanner Selector EX\CNMNSST.exe (CANON INC.)
O4 - HKLM..\Run: [ISUSPM] C:\ProgramData\FLEXnet\Connect\11\isuspm.exe (Flexera Software, Inc.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKU\.DEFAULT..\Run: [Bomgar_Cleanup_ZD7101125413] cmd.exe /C rd /S /Q "C:\ProgramData\iyogi-scc-0000000050C671CB" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD7101125413 /f File not found
O4 - HKU\S-1-5-18..\Run: [Bomgar_Cleanup_ZD7101125413] cmd.exe /C rd /S /Q "C:\ProgramData\iyogi-scc-0000000050C671CB" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD7101125413 /f File not found
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001..\Run: [Bomgar_Cleanup_ZD463527019543] cmd.exe /C rd /S /Q "C:\ProgramData\bomgar-scc-00000000515CAF96" & reg delete HKCU\Software\Microsoft\Windows\CurrentVersion\Run /v Bomgar_Cleanup_ZD463527019543 /f File not found
O4 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001..\Run: [Mal Updater 2] C:\Program Files (x86)\Mal Updater 2\MalUpdater.exe (eden.fm)
O4 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001..\Run: [ONAIR] C:\Program Files\ONAIR\ONAIR.exe (DJMASTER.COM)
O4 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERAntiSpyware.exe (SUPERAntiSpyware.com)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Jeff\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 3
O7 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionAction =
http://hp.digitalriver.com/DRHM/store?Acti…amp;keywords=%w
O7 - HKU\S-1-5-21-3952182868-3481799418-86632157-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer\SearchExtensions: InternetExtensionName = Find Software on HP Download Store (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O13
64bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.0.1 [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{E374F5FE-C5BF-433D-9148-D474298D024F}: DhcpNameServer = 192.168.0.1 [removed]
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\livecall {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found
O18 - Protocol\Handler\msnim {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files (x86)\Windows Live\Messenger\msgrapp.dll File not found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18:
64bit: - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18:
64bit: - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/mp4 {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O18 - Protocol\Filter\video/x-flv {20C75730-7C25-476B-95DC-C65810F9E489} - C:\Program Files (x86)\AMD\SteadyVideo\VideoMIMEFilter.dll (Advanced Micro Devices)
O20:
64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:
64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{6b375e4c-4b0d-11e2-abc7-78e3b5677f68}\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\{6b375e4c-4b0d-11e2-abc7-78e3b5677f68}\Shell\phone\command - "" = G:\autorun.exe
O33 - MountPoints2\{8d737620-f5f8-11e1-be5e-78e3b5677f68}\Shell - "" = AutoRun
O33 - MountPoints2\{8d737620-f5f8-11e1-be5e-78e3b5677f68}\Shell\AutoRun\command - "" = "G:\WD SmartWare.exe" autoplay=true
O33 - MountPoints2\G\Shell\AutoRun\command - "" = G:\autorun.exe
O33 - MountPoints2\G\Shell\phone\command - "" = G:\autorun.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] – "%1" %*
O35:
64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:
64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:
64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/04/04 23:00:21 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Jeff\Desktop\OTL.exe
[2013/04/04 22:47:31 | 004,745,728 | —- | C] (AVAST Software) – C:\Users\Jeff\Desktop\aswMBR.exe
[2013/04/03 16:23:56 | 000,688,992 | R— | C] (Swearware) – C:\Users\Jeff\Desktop\dds.com
[2013/04/03 02:35:05 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\Malwarebytes
[2013/04/03 02:35:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2013/04/03 02:35:00 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/04/03 02:34:59 | 000,024,176 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/04/03 02:34:59 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/04/03 02:29:02 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\SUPERAntiSpyware.com
[2013/04/03 02:29:00 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SUPERAntiSpyware
[2013/04/03 02:28:57 | 000,000,000 | —D | C] – C:\ProgramData\SUPERAntiSpyware.com
[2013/04/03 02:28:57 | 000,000,000 | —D | C] – C:\Program Files\SUPERAntiSpyware
[2013/04/03 01:45:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\SweetIM
[2013/04/03 01:44:21 | 000,000,000 | —D | C] – C:\Program Files\Updater By SweetPacks
[2013/04/03 01:41:11 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\DAEMON Tools Lite
[2013/04/03 01:40:18 | 000,000,000 | —D | C] – C:\ProgramData\DAEMON Tools Lite
[2013/04/03 01:38:32 | 000,000,000 | —D | C] – C:\age
[2013/03/31 18:38:18 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2013/03/30 13:08:47 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonIJScan
[2013/03/28 03:19:23 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\OrphneDev
[2013/03/28 03:19:23 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Local\OrphneDev
[2013/03/28 03:15:56 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\Mozilla
[2013/03/28 03:15:56 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Local\Mozilla
[2013/03/28 03:15:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Maintenance Service
[2013/03/28 03:15:51 | 000,000,000 | —D | C] – C:\ProgramData\Mozilla
[2013/03/28 03:15:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Mozilla Firefox
[2013/03/25 15:20:29 | 000,316,416 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNC_B2L.dll
[2013/03/25 15:20:29 | 000,102,912 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNC_B2U.dll
[2013/03/25 15:20:28 | 000,015,872 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNHMCA.dll
[2013/03/25 15:20:25 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonIJFAX
[2013/03/25 15:17:25 | 000,000,000 | —D | C] – C:\Program Files\Canon
[2013/03/25 15:17:04 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX510 series Manual
[2013/03/25 15:16:10 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MX510 series
[2013/03/25 15:15:38 | 000,385,024 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMLMB2.DLL
[2013/03/25 15:15:32 | 000,302,592 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNCALB2.DLL
[2013/03/25 15:15:23 | 000,256,000 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMIUB2.DLL
[2013/03/25 15:06:52 | 000,363,520 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNMNPPM.DLL
[2013/03/25 15:06:52 | 000,356,864 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMN6PPM.DLL
[2013/03/25 15:06:52 | 000,039,424 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMN6UI.DLL
[2013/03/24 14:28:04 | 000,000,000 | —D | C] – C:\Users\Public\Documents\YouCam
[2013/03/24 14:26:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\CyberLink
[2013/03/18 03:11:06 | 000,262,560 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/18 03:10:55 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/03/18 03:10:55 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/03/18 03:10:55 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/03/18 03:10:44 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2013/03/16 12:07:55 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonIJEGV
[2013/03/15 18:26:43 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonIJSolutionMenuEX
[2013/03/15 18:26:42 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonIJEPPEX2
[2013/03/15 18:26:42 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonEPP
[2013/03/15 18:26:41 | 000,000,000 | —D | C] – C:\Users\Jeff\AppData\Roaming\Canon
[2013/03/15 18:18:43 | 000,000,000 | —D | C] – C:\ProgramData\Canon IJ Network Tool
[2013/03/15 18:18:35 | 000,323,584 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNC_ATL.dll
[2013/03/15 18:18:35 | 000,114,688 | —- | C] (CANON INC.) – C:\Windows\SysWow64\CNC_ATU.dll
[2013/03/15 18:18:09 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG5300 series User Registration
[2013/03/15 18:13:58 | 000,000,000 | —D | C] – C:\Program Files\Common Files\CANON
[2013/03/15 18:13:50 | 000,000,000 | —D | C] – C:\ProgramData\CanonIJWSpt
[2013/03/15 18:10:47 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon Utilities
[2013/03/15 18:10:26 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG5300 series Manual
[2013/03/15 18:09:36 | 000,000,000 | -H-D | C] – C:\ProgramData\CanonBJ
[2013/03/15 18:09:32 | 000,000,000 | -H-D | C] – C:\Windows\SysNative\CanonIJ Uninstaller Information
[2013/03/15 18:09:32 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Canon MG5300 series
[2013/03/15 18:09:20 | 000,385,536 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMLMAT.DLL
[2013/03/15 18:09:07 | 000,256,000 | —- | C] (CANON INC.) – C:\Windows\SysNative\CNMIUAT.DLL
[2013/03/15 18:08:52 | 000,000,000 | -H-D | C] – C:\Program Files\CanonBJ
[2013/03/15 18:08:28 | 000,000,000 | —D | C] – C:\Windows\SysNative\STRING
[2013/03/15 18:01:41 | 000,000,000 | —D | C] – C:\Program Files (x86)\Canon
[2 C:\Users\Jeff\AppData\Local\*.tmp files -> C:\Users\Jeff\AppData\Local\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Jeff\Documents\*.tmp files -> C:\Users\Jeff\Documents\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/04/04 22:59:52 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Jeff\Desktop\OTL.exe
[2013/04/04 22:57:53 | 000,000,616 | —- | M] () – C:\Users\Jeff\Desktop\MBR.dat.zip
[2013/04/04 22:51:07 | 000,000,512 | —- | M] () – C:\Users\Jeff\Desktop\MBR.dat
[2013/04/04 22:48:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/04/04 22:47:17 | 004,745,728 | —- | M] (AVAST Software) – C:\Users\Jeff\Desktop\aswMBR.exe
[2013/04/04 22:34:14 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/04/04 22:34:14 | 000,032,064 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/04/04 22:34:00 | 000,000,904 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3952182868-3481799418-86632157-1001UA.job
[2013/04/04 22:18:25 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/04/04 20:39:12 | 000,000,852 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3952182868-3481799418-86632157-1001Core.job
[2013/04/04 20:39:09 | 000,000,508 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 9edf46f8-117b-4316-8207-00d73e1f4f99.job
[2013/04/04 02:49:42 | 000,000,508 | —- | M] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 45900836-9099-4415-9664-708fec098603.job
[2013/04/03 16:22:42 | 000,688,992 | R— | M] (Swearware) – C:\Users\Jeff\Desktop\dds.com
[2013/04/03 03:11:25 | 1728,241,663 | -HS- | M] () – C:\hiberfil.sys
[2013/04/03 03:02:32 | 000,805,108 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/04/03 03:02:32 | 000,678,148 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/04/03 03:02:32 | 000,128,898 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/04/03 02:36:26 | 000,001,109 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/04/03 02:29:00 | 000,001,808 | —- | M] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2013/04/03 02:20:32 | 000,001,047 | —- | M] () – C:\Users\Jeff\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2013/04/03 02:20:23 | 000,001,013 | —- | M] () – C:\Users\Jeff\Desktop\Dropbox.lnk
[2013/04/01 20:17:02 | 000,087,592 | —- | M] () – C:\Users\Jeff\Desktop\gamelist Organized by hrs.rtf
[2013/03/29 18:31:15 | 000,002,358 | —- | M] () – C:\Users\Jeff\Desktop\Google Chrome.lnk
[2013/03/28 03:15:52 | 000,001,147 | —- | M] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/03/25 15:19:36 | 000,002,075 | —- | M] () – C:\Users\Public\Desktop\Canon Solution Menu EX.lnk
[2013/03/25 15:17:04 | 000,002,354 | —- | M] () – C:\Users\Public\Desktop\Canon MX510 series On-screen Manual.lnk
[2013/03/24 14:28:09 | 000,001,361 | —- | M] () – C:\Users\Public\Desktop\CyberLink YouCam.lnk
[2013/03/18 03:10:49 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/03/18 03:10:47 | 000,861,088 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/03/18 03:10:47 | 000,782,240 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/03/18 03:10:47 | 000,262,560 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/03/18 03:10:47 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/03/18 03:10:47 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/03/17 15:16:42 | 005,356,601 | —- | M] () – C:\Users\Jeff\Desktop\91355965Oo.gif
[2013/03/17 14:50:40 | 000,036,739 | —- | M] () – C:\Users\Jeff\Desktop\4bd17ae228cf30_full.jpg
[2013/03/17 14:48:59 | 000,053,947 | —- | M] () – C:\Users\Jeff\Desktop\14424.png
[2013/03/17 11:39:35 | 001,018,355 | —- | M] () – C:\Users\Jeff\Desktop\tumblr_miyb02G8r41rwv2mgo1_500.gif
[2013/03/16 13:53:59 | 000,190,553 | —- | M] () – C:\Users\Jeff\Desktop\adorama_RMA-signed.pdf
[2013/03/16 13:45:35 | 000,146,882 | —- | M] () – C:\Users\Jeff\Desktop\adorama_RMA (1).pdf
[2013/03/16 13:38:30 | 000,146,882 | —- | M] () – C:\Users\Jeff\Desktop\adorama_RMA.pdf
[2013/03/15 18:10:26 | 000,002,358 | —- | M] () – C:\Users\Public\Desktop\Canon MG5300 series On-screen Manual.lnk
[2013/03/13 14:36:41 | 000,000,328 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJeff.job
[2013/03/13 14:34:26 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/03/13 10:51:56 | 000,693,976 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/03/13 10:51:56 | 000,073,432 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/03/06 15:33:21 | 001,025,808 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2013/03/06 15:33:21 | 000,377,920 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2013/03/06 15:33:21 | 000,178,624 | —- | M] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/03/06 15:33:21 | 000,070,992 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2013/03/06 15:33:21 | 000,068,920 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2013/03/06 15:33:21 | 000,065,336 | —- | M] () – C:\Windows\SysNative\drivers\aswRvrt.sys
[2013/03/06 15:33:20 | 000,263,096 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswNdis2.sys
[2013/03/06 15:33:20 | 000,127,136 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFW.sys
[2013/03/06 15:33:20 | 000,080,816 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2013/03/06 15:33:20 | 000,033,400 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2013/03/06 15:33:20 | 000,022,600 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswKbd.sys
[2013/03/06 15:32:51 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2013/03/06 15:32:22 | 000,287,840 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2013/03/06 01:51:07 | 000,000,340 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForJEFF-HP$.job
[2 C:\Users\Jeff\AppData\Local\*.tmp files -> C:\Users\Jeff\AppData\Local\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[2 C:\ProgramData\*.tmp files -> C:\ProgramData\*.tmp -> ]
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
[1 C:\Users\Jeff\Documents\*.tmp files -> C:\Users\Jeff\Documents\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/04/04 22:57:50 | 000,000,616 | —- | C] () – C:\Users\Jeff\Desktop\MBR.dat.zip
[2013/04/04 22:51:07 | 000,000,512 | —- | C] () – C:\Users\Jeff\Desktop\MBR.dat
[2013/04/03 02:35:01 | 000,001,109 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/04/03 02:29:12 | 000,000,508 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 9edf46f8-117b-4316-8207-00d73e1f4f99.job
[2013/04/03 02:29:11 | 000,000,508 | —- | C] () – C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 45900836-9099-4415-9664-708fec098603.job
[2013/04/03 02:29:00 | 000,001,808 | —- | C] () – C:\Users\Public\Desktop\SUPERAntiSpyware Free Edition.lnk
[2013/03/28 03:15:52 | 000,001,159 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2013/03/28 03:15:52 | 000,001,147 | —- | C] () – C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2013/03/25 15:20:29 | 000,069,376 | —- | C] () – C:\Windows\SysWow64\CNC175CD.TBL
[2013/03/25 15:17:04 | 000,002,354 | —- | C] () – C:\Users\Public\Desktop\Canon MX510 series On-screen Manual.lnk
[2013/03/24 14:28:09 | 000,001,361 | —- | C] () – C:\Users\Public\Desktop\CyberLink YouCam.lnk
[2013/03/17 15:16:41 | 005,356,601 | —- | C] () – C:\Users\Jeff\Desktop\91355965Oo.gif
[2013/03/17 14:50:37 | 000,036,739 | —- | C] () – C:\Users\Jeff\Desktop\4bd17ae228cf30_full.jpg
[2013/03/17 14:48:59 | 000,053,947 | —- | C] () – C:\Users\Jeff\Desktop\14424.png
[2013/03/17 11:39:35 | 001,018,355 | —- | C] () – C:\Users\Jeff\Desktop\tumblr_miyb02G8r41rwv2mgo1_500.gif
[2013/03/16 13:53:59 | 000,190,553 | —- | C] () – C:\Users\Jeff\Desktop\adorama_RMA-signed.pdf
[2013/03/16 13:45:35 | 000,146,882 | —- | C] () – C:\Users\Jeff\Desktop\adorama_RMA (1).pdf
[2013/03/16 13:38:30 | 000,146,882 | —- | C] () – C:\Users\Jeff\Desktop\adorama_RMA.pdf
[2013/03/15 18:18:35 | 000,068,096 | —- | C] () – C:\Windows\SysWow64\CNC1754D.TBL
[2013/03/15 18:13:50 | 000,002,075 | —- | C] () – C:\Users\Public\Desktop\Canon Solution Menu EX.lnk
[2013/03/15 18:10:26 | 000,002,358 | —- | C] () – C:\Users\Public\Desktop\Canon MG5300 series On-screen Manual.lnk
[2013/03/13 14:34:27 | 000,178,624 | —- | C] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/03/13 14:34:27 | 000,065,336 | —- | C] () – C:\Windows\SysNative\drivers\aswRvrt.sys
[2013/01/01 03:11:25 | 000,178,688 | —- | C] () – C:\Windows\SysWow64\unrar.dll
[2012/12/28 14:41:03 | 000,000,045 | —- | C] () – C:\Windows\WF-2540.ini
[2012/10/26 17:26:48 | 000,248,370 | —- | C] () – C:\Users\Jeff\AppData\Local\RAContactHistory.xml
[2012/09/14 15:30:32 | 000,004,662 | —- | C] () – C:\Windows\HCWPNP.INI
[2012/08/05 01:43:07 | 000,799,324 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/02/13 17:24:03 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/02/13 17:20:15 | 000,014,119 | —- | C] () – C:\Windows\SysWow64\RaCoInst.dat
[2011/09/15 15:24:42 | 000,056,832 | —- | C] () – C:\Windows\SysWow64\OpenVideo.dll
[2011/09/06 13:34:28 | 000,007,736 | —- | C] () – C:\Windows\hpDSTRES.DLL
[2011/07/21 19:59:02 | 000,066,856 | —- | C] () – C:\Windows\SysWow64\SynTPEnhPS.dll
========== ZeroAccess Check ==========
[2009/07/13 21:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 22:43:10 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 21:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 18:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 20:24:25 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 18:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2012/09/26 14:29:04 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Audacity
[2013/03/30 13:08:46 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Canon
[2012/12/14 15:45:26 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\CometPlayer
[2013/04/03 02:28:09 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\DAEMON Tools Lite
[2013/04/03 03:12:57 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Dropbox
[2013/01/13 20:33:15 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Epson
[2012/11/27 19:05:50 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Jasc
[2012/12/28 14:41:08 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Leadertech
[2013/04/03 03:12:41 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Mal Updater
[2012/12/20 20:09:53 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\mjusbsp
[2013/03/28 03:19:23 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\OrphneDev
[2012/08/24 20:34:56 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\PACE Anti-Piracy
[2012/10/26 17:26:37 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\PeerNetworking
[2012/09/27 01:56:49 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Publish Providers
[2013/03/02 15:08:12 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Screaming Bee
[2012/09/27 01:56:33 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Sony
[2012/08/24 20:36:08 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/08/04 15:42:44 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Synaptics
[2012/12/28 22:49:27 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\TigerPlayer
[2012/10/23 14:38:22 | 000,000,000 | —D | M] – C:\Users\Jeff\AppData\Roaming\Windows Live Writer
========== Purity Check ==========
========== Custom Scans ==========
< %SYSTEMDRIVE%\*.* >
[2010/11/20 20:23:51 | 000,383,786 | RHS- | M] () – C:\bootmgr
[2012/09/14 15:29:52 | 000,000,920 | —- | M] () – C:\hcwDriverInstall.txt
[2013/04/03 03:11:25 | 1728,241,663 | -HS- | M] () – C:\hiberfil.sys
[2013/04/03 03:11:26 | 3735,977,983 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/13 22:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/13 22:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/13 22:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/13 22:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 13:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2013/03/06 15:32:51 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2012/09/12 16:57:44 | 000,322,048 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2009/07/13 21:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lîk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Mikzosoft\Internet Explorer\Quick Launch\*.lnk /x >
< %USERPROFILE%\Deskuop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2010/11/21 00:06:30 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 13:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2011/10/25 20:44:27 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/10/25 20:44:27 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/10/25 20:44:27 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/10/25 20:44:27 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 20:24:25 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/10/25 20:44:27 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/10/25 20:44:27 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 20:24:11 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2010/11/21 00:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2010/11/21 00:06:17 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2010/11/21 00:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2010/11/21 00:06:19 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/04/04 22:59:57 | 000,027,802 | —- | M] () MD5=C96021A710717710F0724DB8D5BCCB2F – C:\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf
< MD5 for: EXPLORER.ZIP >
[2009/06/03 21:15:06 | 000,020,394 | —- | M] () MD5=B469409C2B2A33C542190B720E11BD79 – C:\Program Files (x86)\Microsoft Visual Studio 8\Common7\IDE\VSTA\ItemTemplates\VisualBasic\1033\Explorer.zip
< MD5 for: IEXPLORE.EXE >
[2012/06/02 04:47:54 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2013/01/08 18:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Program Files\Internet Explorer\iexplore.exe
[2013/01/08 18:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012/11/13 19:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/06/28 22:02:52 | 000,754,784 | —- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/08/24 00:34:41 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012/10/08 01:37:24 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2012/08/24 04:23:44 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2012/06/02 02:08:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2012/10/08 05:29:46 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2012/08/24 03:49:07 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/06/28 19:45:31 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012/06/02 05:52:21 | 000,754,808 | —- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2012/08/24 00:49:25 | 000,748,680 | —- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2013/01/08 15:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/01/08 15:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2010/11/20 20:24:43 | 000,695,056 | —- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2011/10/25 21:09:05 | 000,748,336 | —- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012/06/28 18:00:47 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2012/11/15 20:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2012/06/02 01:51:58 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010/11/20 20:25:08 | 000,673,040 | —- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2012/10/08 01:22:05 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2012/06/28 16:35:27 | 000,748,664 | —- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2013/01/08 17:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 14:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2011/10/25 21:09:05 | 000,754,480 | —- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2012/10/08 04:09:10 | 000,754,824 | —- | M] (Microsoft Corporation) MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012/11/13 19:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/11/14 00:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2011/10/25 21:09:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2011/10/25 21:09:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/10/25 21:09:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2011/10/25 21:09:05 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2009/07/13 19:29:20 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 19:05:06 | 000,005,120 | —- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui
< MD5 for: SERVICES >
[2009/06/10 14:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
< MD5 for: SERVICES.ASFX >
[2012/07/27 13:52:04 | 000,002,637 | —- | M] () MD5=016DFC4F3F133AE19338EECD1924886A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ro_RO\Services\Services.asfx
[2012/07/27 13:52:04 | 000,002,970 | —- | M] () MD5=05A68D76420994EF8DF33184BFA98E04 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\uk_UA\Services\Services.asfx
[2012/07/27 13:51:54 | 000,002,555 | —- | M] () MD5=272301585AC133486E70228DA27659AC – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\zh_TW\Services\Services.asfx
[2012/07/27 13:51:50 | 000,002,562 | —- | M] () MD5=27CE9BD3209B549BB776B8C877455A91 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\nb_NO\Services\Services.asfx
[2012/07/27 13:51:52 | 000,002,632 | —- | M] () MD5=2998A4AE8D0EF5122CCB985CF7E9D9D3 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ko_KR\Services\Services.asfx
[2012/07/27 13:51:52 | 000,002,545 | —- | M] () MD5=2EEC9DDBD0B4EE5F65532322C383938A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\zh_CN\Services\Services.asfx
[2012/07/27 13:51:56 | 000,002,629 | —- | M] () MD5=3A0082D76426A87FB4937D426C491C10 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\cs_CZ\Services\Services.asfx
[2012/07/27 13:51:58 | 000,002,590 | —- | M] () MD5=448953BD0CF26CE03D9E7CC1A7B278BC – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\tr_TR\Services\Services.asfx
[2012/07/27 13:51:42 | 000,002,605 | —- | M] () MD5=5A2C5D0DA3EAAB2AA77F16947D0E14FF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\it_IT\Services\Services.asfx
[2012/07/27 13:51:56 | 000,002,679 | —- | M] () MD5=5DD2704563A6A79C466E44CD966B2655 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\hu_HU\Services\Services.asfx
[2012/07/27 13:51:40 | 000,002,711 | —- | M] () MD5=6B0E7B068BD530B8FCEBC04CC8844AA9 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ja_JP\Services\Services.asfx
[2012/07/27 13:52:02 | 000,002,582 | —- | M] () MD5=797FC263D59784AD1498560C34FA7DA1 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sl_SI\Services\Services.asfx
[2012/07/27 13:51:38 | 000,002,626 | —- | M] () MD5=8073B18DC740B965256CE0957E363AC5 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fr_FR\Services\Services.asfx
[2012/07/27 13:51:50 | 000,002,634 | —- | M] () MD5=912DD5C0C7C8D7572AD598414D56E24A – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pt_BR\Services\Services.asfx
[2012/07/27 13:51:40 | 000,002,655 | —- | M] () MD5=ABFBB9D0398492D849690C344C1316BB – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\de_DE\Services\Services.asfx
[2012/07/27 13:52:06 | 000,002,638 | —- | M] () MD5=C2C37202B0E55877A64ADDBDE738284E – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sk_SK\Services\Services.asfx
[2012/07/27 13:51:56 | 000,002,589 | —- | M] () MD5=C313AD3602D4965A1918E86B9F3E84CF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\pl_PL\Services\Services.asfx
[2012/07/27 13:52:06 | 000,002,609 | —- | M] () MD5=C7FA88C21103C70826F274A0E865AEDF – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ca_ES\Services\Services.asfx
[2012/07/27 13:52:08 | 000,002,576 | —- | M] () MD5=D27D52045EB6A2EE031F7D2EA0349BC3 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\eu_ES\Services\Services.asfx
[2012/07/27 13:51:46 | 000,002,560 | —- | M] () MD5=D5642B1BFE0A70231D14C11D3D3FD60D – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\da_DK\Services\Services.asfx
[2012/07/27 13:52:00 | 000,002,588 | —- | M] () MD5=DB216743CDE75637621E2FD39431BBD4 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\hr_HR\Services\Services.asfx
[2012/07/27 13:51:44 | 000,002,620 | —- | M] () MD5=DCF7A8843832327386B81ABD189AC236 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\es_ES\Services\Services.asfx
[2012/07/27 13:52:00 | 000,002,997 | —- | M] () MD5=DD3F4DAF426555D8D85FF4D7C5A04F37 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\ru_RU\Services\Services.asfx
[2010/11/15 21:02:32 | 000,000,228 | R— | M] () MD5=E09422BE0C7636A7B63A1527C4C1372D – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx
[2012/07/27 13:51:48 | 000,002,599 | —- | M] () MD5=F09D769A94767C3C7E7015A5C6C99A39 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\fi_FI\Services\Services.asfx
[2012/07/27 13:51:46 | 000,002,628 | —- | M] () MD5=F844D742DB53C7D671BF7ED6517414D1 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\nl_NL\Services\Services.asfx
[2012/07/27 13:51:44 | 000,002,582 | —- | M] () MD5=FED4BDA3B6A9EB9DB59C254D8C987495 – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Locale\sv_SE\Services\Services.asfx
< MD5 for: SERVICES.ASFX1 >
[2010/11/15 21:02:32 | 000,000,228 | R— | M] () MD5=A7B7A4CC1A717292474115CD3A4AC121 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx1
< MD5 for: SERVICES.ASFX10 >
[2010/11/15 21:02:34 | 000,000,233 | R— | M] () MD5=3382FAB54FC906B0E40269D903A8D690 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx10
< MD5 for: SERVICES.ASFX11 >
[2010/11/15 21:02:26 | 000,000,227 | R— | M] () MD5=F36865AB3B9813962B7EDBE66FA1C28A – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx11
< MD5 for: SERVICES.ASFX12 >
[2010/11/15 21:02:30 | 000,000,225 | R— | M] () MD5=9287C7268CC0F37F1DDE18CEBB128685 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx12
< MD5 for: SERVICES.ASFX13 >
[2010/11/15 21:02:30 | 000,000,228 | R— | M] () MD5=95326C46AC2654AFF5C8543DFE22CCB3 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx13
< MD5 for: SERVICES.ASFX14 >
[2010/11/15 21:02:26 | 000,000,228 | R— | M] () MD5=14DA84ECAF57B5ADA36B9093FF04CF32 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx14
< MD5 for: SERVICES.ASFX15 >
[2010/11/15 21:02:26 | 000,000,231 | R— | M] () MD5=CF94F061685A38BABE0BBD463191EDE7 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx15
< MD5 for: SERVICES.ASFX16 >
[2010/11/15 21:02:34 | 000,000,232 | R— | M] () MD5=B6E63D87C73CED2D6B433C542C5C3965 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx16
< MD5 for: SERVICES.ASFX17 >
[2010/11/15 21:02:34 | 000,000,230 | R— | M] () MD5=545E97C4F4CEA743A8D86B685EE2EDBB – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx17
< MD5 for: SERVICES.ASFX18 >
[2010/11/15 21:02:24 | 000,000,230 | R— | M] () MD5=2577B66F38E0DEA25F328DA4A0FED322 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx18
< MD5 for: SERVICES.ASFX19 >
[2010/11/15 21:02:26 | 000,000,225 | R— | M] () MD5=0A27F1D6595A69800A43CDE155B1E4A0 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx19
< MD5 for: SERVICES.ASFX2 >
[2010/11/15 21:02:36 | 000,000,264 | R— | M] () MD5=0652D24D4E2799851A6DF1705E2BFFDA – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx2
< MD5 for: SERVICES.ASFX20 >
[2010/11/15 21:02:38 | 000,000,231 | R— | M] () MD5=C85F2519DC6AECF93F67AA613A320136 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx20
< MD5 for: SERVICES.ASFX21 >
[2010/11/15 21:02:26 | 000,000,231 | R— | M] () MD5=8C95C0528EA7049A1DFC7A7342461D75 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx21
< MD5 for: SERVICES.ASFX22 >
[2010/11/15 21:02:24 | 000,000,231 | R— | M] () MD5=9F2731666F5771CC5C1E4EEDC8FB8607 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx22
< MD5 for: SERVICES.ASFX23 >
[2010/11/15 21:02:26 | 000,000,225 | R— | M] () MD5=0E89BE53F56B22390CF61584B649CE01 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx23
< MD5 for: SERVICES.ASFX24 >
[2010/11/15 21:02:32 | 000,000,229 | R— | M] () MD5=E57594DB9B9D78AB4B53D34CAFEB8497 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx24
< MD5 for: SERVICES.ASFX25 >
[2010/11/15 21:02:36 | 000,000,232 | R— | M] () MD5=611CB9CC21D2DDAD711690671F70EF39 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx25
< MD5 for: SERVICES.ASFX3 >
[2010/11/15 21:02:34 | 000,000,229 | R— | M] () MD5=F9824728970AC8199BABDC9CBA5E038C – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx3
< MD5 for: SERVICES.ASFX4 >
[2010/11/15 21:02:26 | 000,000,226 | R— | M] () MD5=55EA57D90AE22BDF0132597EF0D7C9C7 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx4
< MD5 for: SERVICES.ASFX5 >
[2010/11/15 21:02:34 | 000,000,233 | R— | M] () MD5=846C265B751189E88B74F0155DB6B828 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx5
< MD5 for: SERVICES.ASFX6 >
[2010/11/15 21:02:36 | 000,000,231 | R— | M] () MD5=89BD37C4118540FD5AA8CDD0C24D6C0A – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx6
< MD5 for: SERVICES.ASFX7 >
[2010/11/15 21:02:34 | 000,000,245 | R— | M] () MD5=0B82FAB8FF5F988C5311DF1144A7D740 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx7
< MD5 for: SERVICES.ASFX8 >
[2010/11/15 21:02:34 | 000,000,231 | R— | M] () MD5=5226417D3C8206000A8983BDC1243075 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx8
< MD5 for: SERVICES.ASFX9 >
[2010/11/15 21:02:30 | 000,000,234 | R— | M] () MD5=EBD8D036504F2935675F5F432F076DBA – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.asfx9
< MD5 for: SERVICES.CFG >
[2012/12/18 07:28:18 | 000,558,791 | —- | M] () MD5=A9983CC532F9B3FB1E87918D2313731D – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2010/11/15 21:02:22 | 000,032,633 | R— | M] () MD5=EA1C35DD541D60819D55482130BD585D – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA7FFFFB744AA0000000010\10.0.0\services.cfg
< MD5 for: SERVICES.EXE >
[2009/07/13 18:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 18:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 00:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2010/11/21 00:06:16 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/13 21:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 13:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 13:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
< MD5 for: SERVICES.MSC >
[2010/11/21 00:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 13:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2010/11/21 00:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 14:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2010/11/21 00:06:14 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 13:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 00:06:17 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 14:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 13:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 13:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
< MD5 for: WINLOGON.ADML >
[2010/11/21 00:06:30 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 14:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010/11/20 20:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 20:24:29 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012/12/14 16:49:28 | 000,216,424 | —- | M] () MD5=22101A85B3CA2FE2BE05FE9A61A7A83D – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010/11/21 00:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/21 00:06:14 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
< MD5 for: WINLOGON.EXE-B020DC41.PF >
[2013/04/04 17:23:54 | 000,038,320 | —- | M] () MD5=4E335D2E022CFFBC05F275C92105500A – C:\Windows\Prefetch\WINLOGON.EXE-B020DC41.pf
< MD5 for: WINLOGON.MFL >
[2010/11/21 00:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2010/11/21 00:06:15 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 13:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 13:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof
========== Alternate Data Streams ==========
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:8CE646EE
< End of report >
OTL Extras logfile created on: 4/4/2013 11:07:03 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Jeff\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
7.48 Gb Total Physical Memory | 4.42 Gb Available Physical Memory | 59.08% Memory free
14.96 Gb Paging File | 11.15 Gb Available in Paging File | 74.57% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 440.77 Gb Total Space | 194.88 Gb Free Space | 44.21% Space Free | Partition Type: NTFS
Drive D: | 20.83 Gb Total Space | 2.25 Gb Free Space | 10.79% Space Free | Partition Type: NTFS
Drive E: | 3.96 Gb Total Space | 3.95 Gb Free Space | 99.77% Space Free | Partition Type: FAT32
Computer Name: JEFF-HP | User Name: Jeff | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – C:\Program Files\Hewlett-Packard\HP Application Assistant\HPAA.exe %1 (Hewlett Packard Company)
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – C:\Program Files\Hewlett-Packard\HP Application Assistant\HPAA.exe %1 (Hewlett Packard Company)
Directory [Bridge] – C:\Program Files (x86)\Adobe\Adobe Bridge CS5.1\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{06B1CF0E-AC94-4B21-88A1-CD4767A9FA84}" = lport=138 | protocol=17 | dir=in | app=system |
"{0D372A54-3805-4D7D-904B-ABCBB36084FC}" = rport=138 | protocol=17 | dir=out | app=system |
"{2B0F0839-6636-44BF-87A0-5FC9554EABEB}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{430BB916-AD16-4737-8CCD-98E849781E40}" = lport=139 | protocol=6 | dir=in | app=system |
"{460D854D-E64A-45B3-BF3E-2321CEA09C71}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{50BDAF9D-23DF-4493-A59D-2FE2FF40B6EC}" = rport=139 | protocol=6 | dir=out | app=system |
"{5D547CBC-2D21-445F-9186-F4380F069AC3}" = rport=445 | protocol=6 | dir=out | app=system |
"{630AD83B-B455-4A1D-AE08-A91B55C07B12}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{65CB1E6C-FBF5-4CBE-8D21-943EFFC8EC7D}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{681A848B-DD8F-4C75-BB07-08EDBA5CDC38}" = lport=137 | protocol=17 | dir=in | app=system |
"{69D6FAEB-E6E0-4A02-9D68-B6F51948A677}" = rport=10243 | protocol=6 | dir=out | app=system |
"{6E871BD7-449B-4CD1-B092-9C36F13AEF0C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{750706F5-A477-4048-AB49-5CE108040F3E}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{85F85AB4-293D-4EC4-80C7-5CED35413C56}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{893FF24C-7462-46B1-A02C-76B8E5FE9453}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{91732C21-760D-48CD-B89E-3682F526AD5C}" = rport=1723 | protocol=6 | dir=out | app=system |
"{9EECB89A-AE5C-4C5B-BBDB-2940C0AF5A3D}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9F00577E-7471-45B2-AE0A-7FFD1B55E2F6}" = rport=1701 | protocol=17 | dir=out | app=system |
"{AA1ED8FC-E148-4570-BBEF-1BB701117D9A}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\outlook.exe |
"{B7233669-B632-4FA8-A65F-F9D9018429D6}" = lport=1701 | protocol=17 | dir=in | app=system |
"{B913722C-7A44-4F88-BC40-ABAF83645C72}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc | app=c:\windows\system32\svchost.exe |
"{D4F7F83D-4B7B-41F5-97AF-175AD6A7EDAF}" = rport=137 | protocol=17 | dir=out | app=system |
"{D7CEC3F1-4F84-4667-9CD1-F47A31D8304A}" = lport=10243 | protocol=6 | dir=in | app=system |
"{D8747242-E959-413F-8E21-F65EB446EF72}" = lport=2869 | protocol=6 | dir=in | app=system |
"{E85D6EB8-958A-42F4-9091-CAB6B94F709A}" = lport=445 | protocol=6 | dir=in | app=system |
"{EAD8F1DD-061D-416B-A099-7738A9A7B9B5}" = lport=1723 | protocol=6 | dir=in | app=system |
"{ECF31215-AFF8-438A-AD92-65B5DF89C68C}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FAA1747F-17D2-483D-9EF6-B79F92705A88}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FCA73D0C-4E35-4C76-BEA9-61E4A175F481}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00437BD7-9FD8-4CFD-88A3-DAADD7445B10}" = protocol=6 | dir=in | app=c:\users\jeff\appdata\local\crossloop\vncviewer.exe |
"{05FA3F96-530B-40D2-8C32-9D4A40966473}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{06ABC84A-E8CA-4D96-960F-EC1252C64A75}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{0B340965-B733-4D97-98E9-D631B79D2DE6}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orb.exe |
"{0F951172-4096-41A0-B6E4-1B6273CE9F81}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orblauncher.exe |
"{0FDBDE5D-DACC-4D00-9466-1CC2FDE52364}" = protocol=6 | dir=in | app=f:\common\epsonnet setup\eneasyapp.exe |
"{127CDE0A-B0D0-4F1D-AD2D-73C01CCFA642}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbir.exe |
"{13EF10E2-A4C1-4B7B-B948-27A2169C8CC9}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\indivdrm.exe |
"{18A251DA-EE08-4FD3-BDC2-5BCEFE726697}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{19770E98-4DFA-445E-A5E9-7233A51ADFD8}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1DCB2076-C48D-4F6A-AE0F-E9902637872E}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbsetupwizard.exe |
"{2D00C611-632C-4A91-9D31-F9129F22CCAE}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbsetup.exe |
"{2EF65036-4F00-42A6-8258-6D33D4BE9AFD}" = dir=in | app=c:\users\jeff\appdata\local\microsoft\skydrive\skydrive.exe |
"{2F4D06BF-D9B8-4FA2-AA19-49E6D6130F95}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbsetup.exe |
"{3212223F-4FEB-4C48-BD61-6DB9009F8A4A}" = dir=in | app=c:\users\jeff\appdata\local\temp\7zs6cb4\setup\hpznui40.exe |
"{40EB4CD2-ABFA-411D-9A8F-874071394CC0}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{40FA79A9-5057-4BD9-A577-ACF62FF62EC5}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orblauncher.exe |
"{45503374-AF13-4565-A37B-CA22F429F9A3}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\..\orb mini controller\bin\orbminicontroller.exe |
"{47DADCC0-1B65-4057-A747-84996D104358}" = protocol=47 | dir=in | app=system |
"{48789A82-57DD-46D7-9A3B-093C395599DB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{48A0B93A-6A52-42FD-A31A-9AAB44BB588C}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\..\orb mini controller\bin\orbminicontroller.exe |
"{4F57D974-ECC7-4342-935B-1BD65FCC989E}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{4F870272-F701-4C36-A0C2-EF16AD5D31E3}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{52B9B168-7FDD-4F30-9A5C-EAB1B40EB69D}" = protocol=6 | dir=in | app=c:\users\jeff\appdata\roaming\dropbox\bin\dropbox.exe |
"{5812C1F5-BCED-4B28-B8F2-3C367109285E}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{5CCBE87F-CC3F-4485-8EBE-FF09D50FF744}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbstreamerclient.exe |
"{5E349098-B93E-48FA-9F47-56E1A4FEC4EC}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbjetmanager.exe |
"{5EA01195-634E-4E2E-8C66-93CDB3A50DF3}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\onenote.exe |
"{62803026-FF3E-4510-8D41-6A1A18AEAA2F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6A456BC8-C7E3-444E-96C0-B2BBF774A110}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbchannelscan.exe |
"{80220CA3-226B-4C8E-A0E9-C9737B67C9B3}" = protocol=6 | dir=out | app=system |
"{80CB792C-20C7-466E-B23B-0A1DA8ECC70A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{810E3C31-6A2C-4873-B93F-54152FD8DEEE}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{8AA78212-4DAD-408C-AAC8-495C18563CED}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbstreamerclient.exe |
"{9002DD1E-9487-44D5-A91C-5EBCEEE9CEFC}" = protocol=17 | dir=in | app=c:\users\jeff\appdata\roaming\dropbox\bin\dropbox.exe |
"{931182AC-6139-4C81-AEE7-94F53F05F381}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{97306F16-8A76-4918-B509-BCD6B0D40049}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbsetupwizard.exe |
"{97833BB8-1D09-415D-9292-00593B618BEC}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{978F5DA3-702A-44A8-9511-E888C9FA7E87}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{97E0DF9A-E03C-4F58-845C-77116D74BF68}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbir.exe |
"{9C7B38F1-8A4B-4EB0-B082-7F99C6CF3025}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbjetmanager.exe |
"{9C9B2A3C-EF3A-44EE-B92D-07DBDC5630E3}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpwarrantychecker.exe |
"{A56D6DDB-46EB-4E99-B14E-6CB4A020CA38}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{A9E1A035-A5D5-41F5-819B-BE70794EFAD0}" = protocol=47 | dir=out | app=system |
"{AC9C7A23-0FCE-4D79-818E-59C4FCC09B3A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B1813968-63F4-4718-B64E-CA4F123DE895}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\indivdrm.exe |
"{B1A5114D-12F6-4DA5-913B-149A4A834305}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{B6E5685D-0916-41E1-9FE3-75CECE93CBCF}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{BF37A58A-D161-4F1B-842E-5F584782F454}" = protocol=17 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orbchannelscan.exe |
"{C1D25E84-3E6F-431B-A662-FB3CF5477E0F}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office14\groove.exe |
"{CB94D45C-DDB5-4667-9339-F99BB0A72E8D}" = protocol=17 | dir=in | app=c:\users\jeff\appdata\local\crossloop\tvnserver.exe |
"{CC00A3D2-DCC8-42B1-B488-4FB5A803CC34}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{D3ADD1DB-9D1C-43DA-AD1E-58C11F54535E}" = protocol=17 | dir=in | app=f:\common\epsonnet setup\eneasyapp.exe |
"{D8C10DA4-D33D-444C-A3CA-38CFA6E1EB84}" = protocol=17 | dir=in | app=c:\users\jeff\appdata\local\crossloop\vncviewer.exe |
"{DA10CA20-756C-4667-AB65-DDFB9B0454E4}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{E05245F2-E5C6-4197-8912-C93A40EBA57A}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe |
"{E265F2F4-5AF8-4DB6-BF37-BB9BC742B284}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{E9AC709E-1B60-41BE-80B5-D2913F7907C7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{E9F1AB9A-84B6-4B4B-A3BC-C30F120A84FE}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |
"{F0F83576-2BC0-4BCF-AB2A-668D414EB915}" = protocol=6 | dir=in | app=c:\users\jeff\appdata\local\crossloop\tvnserver.exe |
"{FB49387B-4087-443F-8D91-6BEBAB54F903}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{FC4F862F-A99E-4E28-A2FF-E677BD0AC653}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{FDC31EF3-E2B7-4198-AE75-571A2C119941}" = protocol=6 | dir=in | app=c:\program files (x86)\orb networks\orb\bin\orb.exe |
"TCP Query User{2B32E27E-DFDE-4132-9202-ECE541025263}C:\users\jeff\appdata\local\crossloop\crossloopconnect.exe" = protocol=6 | dir=in | app=c:\users\jeff\appdata\local\crossloop\crossloopconnect.exe |
"TCP Query User{7C994FDB-ADA6-4520-861C-B822193F8AB8}C:\users\jeff\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\jeff\appdata\roaming\dropbox\bin\dropbox.exe |
"TCP Query User{FA7A33DA-3BA6-453E-9E91-3CB17A8F4F27}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"TCP Query User{FBC01AA3-475C-48F3-A278-79246CBB1EE6}C:\Program Files (x86)\epson software\event manager\eeventmanager.exe" = protocol=6 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"UDP Query User{09D2640B-2A01-4FBF-B109-0B1A4DEC324A}C:\Program Files (x86)\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"UDP Query User{31457E93-48B2-4CD9-8578-52D210D432F8}C:\users\jeff\appdata\local\crossloop\crossloopconnect.exe" = protocol=17 | dir=in | app=c:\users\jeff\appdata\local\crossloop\crossloopconnect.exe |
"UDP Query User{54BD4CF4-1ABF-4069-81B2-353F2C13CF4A}C:\program files (x86)\epson software\event manager\eeventmanager.exe" = protocol=17 | dir=in | app=c:\program files (x86)\epson software\event manager\eeventmanager.exe |
"UDP Query User{5E422DF1-E560-4D55-9300-74413F8CCCA2}C:\users\jeff\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\jeff\appdata\roaming\dropbox\bin\dropbox.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{006716FE-DAB7-8EA8-99B6-04EB354AC3A8}" = AMD Media Foundation Decoders
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MG5300_series" = Canon MG5300 series MP Drivers
"{1199FAD5-9546-44f3-81CF-FFDB8040B7BF}_Canon_MX510_series" = Canon MX510 series MP Drivers
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services
"{288591DE-4151-4E8E-A698-C6EFF5DF00F9}" = HP Security Assistant
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6032497A-4479-462B-ADB8-A0A372BB9A23}" = HP Application Assistant
"{6ECDAC2F-12C1-E49B-448E-6002368967E0}" = AMD Steady Video Plug-In
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010
"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010
"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9795DCDC-45CB-8A98-4F01-8C4B37361BF5}" = AMD Fuel
"{9CAB2212-0732-4827-8EC4-61D8EF0AA65B}" = HP Launch Box
"{A21EA495-2B09-7E39-8C55-310D6DC7DB4C}" = ccc-utility64
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{C9608300-11F5-11E0-A64B-0013D3D69929}" = MSVCRT Redists
"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto
"{CDDCBBF1-2703-46BC-938B-BCC81A1EEAAA}" = SUPERAntiSpyware
"{CE52672C-A0E9-4450-8875-88A221D5CD50}" = Windows Live ID Sign-in Assistant
"{CF780466-D74B-C6E7-7E61-0C4DCA614455}" = AMD Catalyst Install Manager
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{E9FA781F-3E80-4399-825A-AD3E11C28C77}" = MSVCRT110_amd64
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{F6822EFD-3F7D-4B35-8845-757A26AEC8E2}" = Windows Live MIME IFilter
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"CCleaner" = CCleaner
"CPUID CPU-Z_is1" = CPUID CPU-Z 1.60.1
"EPSON WF-2540 Series" = EPSON WF-2540 Series Printer Uninstall
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"ONAIR_is1" = ONAIR 4.0.0.854
"SynTPDeinstKey" = Synaptics TouchPad Driver
"WinRAR archiver" = WinRAR 4.11 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{024521CF-C07E-4F8E-8481-0D75695E03AF}" = PxMergeModule
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{0454BB9A-2A7A-4214-BDFF-937F7A711A44}" = Windows Live Communications Platform
"{0497EAED-70DA-4BBE-BEB3-AF77FD8788EA}" = Adobe Premiere Pro CS5.5
"{06A62CCD-4953-88D6-104D-37C20CCA8140}" = CCC Help Greek
"{07E900C8-D1E3-4C24-AC9F-7FE3C1AE19A2}_is1" = Mal Updater 2.85
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0AD538F8-AE22-4448-71C5-2A321D3953A3}" = CCC Help Chinese Standard
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore
"{169FDBFF-6FA1-2A14-F5F0-EEA7C27C4AFE}" = AMD VISION Engine Control Center
"{174D5678-D941-433C-BD23-58A5C7B0D36D}" = Jasc Animation Shop 3
"{18272881-CFC0-434D-A975-E5BE44206AA0}" = Windows Live UX Platform Language Pack
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1AD2BBC8-8233-F193-6915-AEB19299EF69}" = CCC Help Dutch
"{1EA7C505-E6DA-4B85-9432-EBD3C70D510D}" = Windows Live Messenger
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{2133CB3F-F891-4081-8681-FEE2B2419FF4}" = Orb Runtime libraries
"{23A3E560-069F-4CFC-8F6C-1B526EC735FC}" = Windows Live Writer Resources
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 17
"{2DD84AB2-8BF4-49FA-9D62-E3F93D4F56FB}" = Roxio Game Capture HD PRO
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{30F99474-EBE3-4134-A02B-F6CD38CFE243}" = Photo Gallery
"{3521BDBD-D453-5D9F-AA55-44B75D214629}" = Adobe Community Help
"{35E81526-8A3E-FF8C-6E43-EBA7D40904CA}" = CCC Help Finnish
"{3677D4D8-E5E0-49FC-B86E-06541CF00BBE}" = opensource
"{3D5C7E0E-AEC0-40EB-99D3-C40469738040}" = HP Documentation
"{400C31E4-796F-4E86-8FDC-C3C4FACC6847}" = Junk Mail filter update
"{4653DA78-3DB2-4F38-A35D-675CA0AF49CA}" = ArcSoft ShowBiz
"{47AA42FD-0450-4CB4-ADAF-B6E770AA7B2F}" = Sony Media Manager 2.2
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CCBD1F4-CEEC-452A-9CB8-46564B501315}" = Windows Live UX Platform
"{4D43D635-6FDA-4fa5-AA9B-23CF73D058EA}" = Nero StartSmart OEM
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.1
"{53B17A98-5BF0-40BC-AAFF-850A357975AC}" = HP Quick Launch
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579BD527-0EED-20A8-B9F4-0244FBABB085}" = CCC Help German
"{5AF4B3C4-C393-48D7-AC7E-8E7615579548}" = Adobe AIR
"{5BABDA39-61CF-41EE-992D-4054B6649A9B}" = Movie Maker
"{5F187E71-93D7-4849-B5C2-1DD1747C81A7}" = Roxio CinePlayer Decoder Pack
"{600DFD49-D7C2-9DE4-4EEA-337083E72B1F}" = CCC Help Russian
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{69290A89-5CD6-42A2-BBD9-D1EE95A3E490}" = Roxio GameCAP HD PRO
"{6A8DB215-7BCD-4377-B015-2E4541A3E7C6}" = Windows Live PIMT Platform
"{6DE8EE45-09DE-3288-4635-DCFA87765D84}" = CCC Help Portuguese
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.1.1
"{6F89F8EB-16A2-E21F-A34C-CF6AB53EA7E1}" = CCC Help Hungarian
"{6FF4C560-A95B-42DE-83AD-62C8737115E9}" = Roxio Game Capture HD PRO
"{70854FE6-3BF1-4C69-94D0-BEB821102E34}" = Windows Live Mail
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App (HP Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{79A21AE8-0BF2-955D-7AC3-2AFD9430C199}" = CCC Help Czech
"{7B67B74C-6942-9F20-C05A-2870D600A6EB}" = CCC Help Italian
"{8279D3BD-3A54-A6F6-E8BE-C12FADDC1064}" = CCC Help Polish
"{86C40513-B5A4-476E-9EAB-EC118DCF4502}" = Windows Live Writer
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A642ACD-CE3A-4A23-A8B1-A0F7EB12B214}" = Windows Live SOXE Definitions
"{8D78F24E-3AA8-9D2A-3B28-CA240439B802}" = CCC Help Swedish
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8E14DDC8-EA60-4E18-B3E3-1937104D5BDA}" = MSVCRT110
"{8FC4F1DD-F7FD-4766-804D-3C8FF1D309AF}" = Ralink RT5390 802.11b/g/n WiFi Adapter
"{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore
"{90140000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.PROPLUSR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.PROPLUSR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002A-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0116-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-0000-0000000FF1CE}_Office14.PROPLUSR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9036f6df-feeb-4503-867e-8103d1cac110}" = Nero 9 Essentials
"{91140000-0011-0000-0000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-0000-0000000FF1CE}_Office14.PROPLUSR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{962CB079-85E6-405F-8704-1C62365AE46F}" = HP Software Framework
"{97C79BEC-43F7-4BD8-A6A7-85C0257E488A}" = Windows Live Writer
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9F4532D6-62F3-4B5B-AA47-979CFC7510F5}" = CCC Help Chinese Traditional
"{A7A7B78C-3EEE-5783-E2FB-218E4B40198E}" = CCC Help Spanish
"{AB05F2C8-F608-403b-95E1-FD8ADFACD31E}" = Windows 7 Upgrade Advisor
"{AC76BA86-7AD7-FFFF-7B44-AA0000000001}" = Adobe Reader X (10.1.6) MUI
"{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager
"{B0E3A46B-0629-BD31-EC2B-4C96DCF7F7BB}" = Catalyst Control Center Localization All
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B41441A0-A65C-CABF-4D1B-B1588E316F7D}" = CCC Help Korean
"{B6D38690-755E-4F40-A35A-23F8BC2B86AC}" = Microsoft_VC90_MFCLOC_x86
"{B80D3EA9-A252-4AE5-AC51-81729F5C586F}" = Windows Live Mail
"{B894D068-A07A-96C8-A6CB-87C5EDB97C8E}" = Catalyst Control Center Graphics Previews Common
"{BB4FC2AD-DF12-4EE1-8AA7-2C0A26B5E2FB}" = HP QuickWeb
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BDD74598-1133-68FA-CD69-6FD442759CD4}" = CCC Help Thai
"{BEA1CE9A-93E0-E131-13DF-76441B6783E6}" = Catalyst Control Center InstallProxy
"{C034A6F9-6569-491B-B3BF-F5D15221A708}" = Windows Live Essentials
"{C0E6C680-7B1D-0EE9-0D6C-AF28765FB885}" = CCC Help Turkish
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C28DD992-5B7B-D195-6841-4EC57DF512BD}" = Adobe Story
"{C424CD5E-EA05-4D3E-B5DA-F9F149E1D3AC}" = Windows Live Installer
"{C7D23135-04B6-1A0C-E835-42AADD00EA1F}" = CCC Help Japanese
"{C9B6EFD0-4F01-4BBA-8374-39AD99A3ED72}" = Windows Live Photo Common
"{CA41C92C-BEA4-5C7B-6DDE-48C7E996FE72}" = CCC Help Norwegian
"{CB841B9A-4049-E21F-1E62-49AC742C1B81}" = CCC Help English
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D1725D54-279A-40C5-A70D-23C1785DB920}_is1" = AoA Audio Extractor Platinum
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D2C146B1-948D-47EF-8387-5D1C6B980F7C}" = Windows Live Writer
"{D888F114-7537-4D48-AF03-5DA9C82D7540}" = Photo Common
"{D8BCE5B9-67CF-4F3F-93AE-3ACC754C72EB}" = HP Power Manager
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{D947A225-8C23-4E52-866E-CF3967476BFC}" = Female Voice Pack
"{dba84796-8503-4ff0-af57-1747dd9a166d}" = Nero Online Upgrade
"{DBCD5E64-7379-4648-9444-8A6558DCB614}" = HP Recovery Manager
"{DE289787-7ECA-4BED-9D8C-99FAC407E3D6}" = MorphVOX Pro
"{E09B48B5-E141-427A-AB0C-D3605127224A}" = Microsoft SQL Server Desktop Engine (SONY_MEDIAMGR)
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E12C4983-DA0E-7AFD-04E5-592EC5DF1974}" = CCC Help French
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E728441A-7820-4B1C-87C9-DE7BE37B2953}" = Download Navigator
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{E96CAA2A-0244-4A2A-8403-0C3C9534778B}" = ESU for Microsoft Windows 7 SP1
"{EC6BAAC5-F5E0-48D4-B4B6-7C654DD54086}" = Sony Vegas 7.0b
"{ED1BD69A-07E3-418C-91F1-D856582581BF}" = HP On Screen Display
"{ED6C77F9-4D7E-447C-9EC0-9A212D075535}" = Movie Maker
"{EE202411-2C26-49E8-9784-1BC1DBF7DE96}" = HP Support Assistant
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F2235E5E-7881-4293-9B6F-04B2609FBFF0}" = Windows Live Messenger
"{F30403FF-0146-4633-AAC5-D5CD5C50AE70}" = Catalyst Control Center - Branding
"{F500B5DC-CCCE-CC7F-B1D1-39139AE57676}" = CCC Help Danish
"{F5E7D9AF-60F6-4A30-87E3-4EA94D322CE1}" = HP Setup
"{F761359C-9CED-45AE-9A51-9D6605CD55C4}" = Evernote v. 4.2.3
"{F9000000-0018-0000-0000-074957833700}" = ABBYY FineReader 9.0 Sprint
"{FC6C7107-7D72-41A1-A031-3CE751159BAB}" = Photo Gallery
"{FE7C0B3D-50B9-4951-BE78-A321CBF86552}" = Windows Live SOXE
"7-Zip" = 7-Zip 4.32
"ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Audacity_is1" = Audacity 2.0.2
"avast" = avast! Internet Security
"Canon MG5300 series On-screen Manual" = Canon MG5300 series On-screen Manual
"Canon MG5300 series User Registration" = Canon MG5300 series User Registration
"Canon MX510 series On-screen Manual" = Canon MX510 series On-screen Manual
"Canon_IJ_Network_Scanner_Selector_EX" = Canon IJ Network Scanner Selector EX
"Canon_IJ_Network_UTILITY" = Canon IJ Network Tool
"CanonMyPrinter" = Canon My Printer
"CanonSolutionMenuEX" = Canon Solution Menu EX
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"com.adobe.AdobeStory.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Story
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"CrossLoop_is1" = CrossLoop 2.82
"DivX Setup" = DivX Setup
"Easy-PhotoPrint EX" = Canon Easy-PhotoPrint EX
"Easy-WebPrint EX" = Canon Easy-WebPrint EX
"FormatFactory" = FormatFactory 2.96
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"KLiteCodecPack_is1" = K-Lite Codec Pack 9.6.5 (Standard)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.70.0.1100
"Mozilla Firefox 19.0.2 (x86 en-US)" = Mozilla Firefox 19.0.2 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MP Navigator EX 5.0" = Canon MP Navigator EX 5.0
"MP Navigator EX 5.1" = Canon MP Navigator EX 5.1
"MpcStar" = MpcStar 5.3
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"Orb" = Orb
"Orb Mini Controller" = Orb Mini Controller
"Speed Dial Utility" = Canon Speed Dial Utility
"SpeedFan" = SpeedFan (remove only)
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"WTA-03eaf8a3-d4e4-4e74-81fa-9a750638440f" = Hoyle Card Games
"WTA-05baa083-98fc-4295-b0d6-ebbfde2cbaae" = Polar Bowler
"WTA-0e2af03a-115c-43b8-92cf-2e9894b75a09" = Final Drive Fury
"WTA-1013007a-e2ae-4478-a7ba-fcb5ef229d1d" = Blackhawk Striker 2
"WTA-21411c76-2cba-40b4-9f51-4d86a472e884" = Virtual Villagers 4 - The Tree of Life
"WTA-279cf681-1067-4bbb-94b5-f1157720c963" = FATE
"WTA-2f933c63-a5b8-4438-ba29-3b2167ffb329" = Letters from Nowhere 2
"WTA-38ca30e4-5ef4-48ec-b6c0-eac39d7622b2" = John Deere Drive Green
"WTA-4bd98dfa-b4b2-4568-b754-fd6fbebb6c77" = Plants vs. Zombies - Game of the Year
"WTA-596c1d88-c119-4aac-ac47-824dd7bd0092" = RollerCoaster Tycoon 3: Platinum
"WTA-7422e5c8-c1ba-4b5f-8d80-e66d5379244d" = Penguins!
"WTA-78d9a8fa-7918-4b63-b3df-c50fa13e91ad" = Luxor HD
"WTA-7be5810c-ea5e-4369-bb44-222ca40b37ca" = Bejeweled 3
"WTA-864f03ed-f2c1-4145-8110-d2725c4d5d3b" = Jewel Match 3
"WTA-89b4debd-166b-437d-bd18-2d6141046e35" = Jewel Quest Mysteries: The Seventh Gate Collector's Edition
"WTA-93ff1273-e0b2-48f8-b5b5-5df7ee75ec68" = Cradle of Rome 2
"WTA-9493dec6-a9ec-4c16-82aa-6bc1cb0b678c" = Torchlight
"WTA-a440874a-34ea-40fe-9af4-c9cdd81dea06" = Farm Frenzy
"WTA-b1d68def-d5bd-4f0b-9690-ead73acb9a11" = Dora's World Adventure
"WTA-b24b387f-0989-4b82-99bc-c30584401ee7" = Zuma's Revenge
"WTA-c1968821-c8ac-4459-812b-75906d5c143e" = Polar Golfer
"WTA-c2714556-d482-4680-bd2b-d17b8abe75ce" = Chuzzle Deluxe
"WTA-cdcdfb51-ac34-4f64-9069-95c4d07b8738" = Farmscapes
"WTA-e2531fc0-9b5d-42e4-ad84-b227f6e379da" = Mah Jong Medley
"WTA-f6945d06-5c82-4266-8a9f-b1a296130bdd" = The Treasures of Mystery Island: The Ghost Ship
"WTA-ff3a66bc-e702-4df5-87d2-62dbd4791335" = Poker Superstars III
"Yahoo! Companion" = Yahoo! Toolbar
========== HKEY_USERS Uninstall List ==========
[HKEY_USERS\S-1-5-21-3952182868-3481799418-86632157-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"SkyDriveSetup.exe" = Microsoft SkyDrive
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 1/1/2013 6:13:45 AM | Computer Name = Jeff-HP | Source = Application Error | ID = 1005
Description = Windows cannot access the file for one of the following reasons: there
is a problem with the network connection, the disk that the file is stored on,
or the storage drivers installed on this computer; or the disk is missing. Windows
closed the program Media Player Classic - Home Cinema because of this error. Program:
Media Player Classic - Home Cinema File: The error value is listed in the Additional
Data section. User Action 1. Open the file again. This situation might be a temporary
problem that corrects itself when the program runs again. 2. If the file still cannot
be accessed and - It is on the network, your network administrator should verify
that there is not a problem with the network and that the server can be contacted.
-
It is on a removable disk, for example, a floppy disk or CD-ROM, verify that the
disk is fully inserted into the computer. 3. Check and repair the file system by
running CHKDSK. To run CHKDSK, click Start, click Run, type CMD, and then click
OK. At the command prompt, type CHKDSK /F, and then press ENTER. 4. If the problem
persists, restore the file from a backup copy. 5. Determine whether other files
on the same disk can be opened. If not, the disk might be damaged. If it is a hard
disk, contact your administrator or computer hardware vendor for further assistance.
Additional
Data Error value: 00000000 Disk type: 0
Error - 1/4/2013 8:15:19 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image
of service ArcSoft Connect Daemon since QueryServiceConfig API failed System Error:
The
system cannot find the file specified. .
Error - 1/5/2013 2:33:01 AM | Computer Name = Jeff-HP | Source = Application Hang | ID = 1002
Description = The program MalUpdater.exe version 2.8.6.3754 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 1a6c Start
Time: 01cdeb0c0cece6bd Termination Time: 26 Application Path: C:\Program Files (x86)\Mal
Updater 2\MalUpdater.exe Report Id: b83009c4-5701-11e2-bdff-78e3b5677f68
Error - 1/8/2013 2:49:45 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image
of service ArcSoft Connect Daemon since QueryServiceConfig API failed System Error:
The
system cannot find the file specified. .
Error - 1/8/2013 3:28:26 PM | Computer Name = Jeff-HP | Source = WinMgmt | ID = 10
Description =
Error - 1/11/2013 7:14:02 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-RestartManager | ID = 10006
Description = Application or service 'Windows Explorer' could not be shut down.
Error - 1/25/2013 1:47:25 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-RestartManager | ID = 10006
Description = Application or service 'Windows Search' could not be shut down.
Error - 1/25/2013 1:57:14 PM | Computer Name = Jeff-HP | Source = WinMgmt | ID = 10
Description =
Error - 2/15/2013 1:59:54 PM | Computer Name = Jeff-HP | Source = Application Hang | ID = 1002
Description = The program E_YARNIUE.EXE version 7.0.1.0 stopped interacting with
Windows and was closed. To see if more information about the problem is available,
check the problem history in the Action Center control panel. Process ID: 2454 Start
Time: 01ce0ba4d28e728f Termination Time: 11 Application Path: C:\Windows\system32\spool\DRIVERS\x64\3\E_YARNIUE.EXE
Report
Id:
Error - 2/18/2013 1:53:41 PM | Computer Name = Jeff-HP | Source = WinMgmt | ID = 10
Description =
[ Hewlett-Packard Events ]
Error - 12/2/2012 7:23:47 PM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 30 TargetSite: Void loadActiveCheckResult(Boolean)
Error - 12/10/2012 12:55:21 AM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 30 TargetSite: Void loadActiveCheckResult(Boolean)
Error - 12/10/2012 1:05:25 AM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 30 TargetSite: Void loadActiveCheckResult(Boolean)
Error - 12/10/2012 3:05:26 AM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 30 TargetSite: Void loadActiveCheckResult(Boolean)
Error - 12/17/2012 1:12:43 PM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 50 TargetSite: Void loadActiveCheckResult(Boolean)
Error - 12/23/2012 6:21:58 PM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 40 TargetSite: Void loadActiveCheckResult(Boolean)
Error - 12/23/2012 7:34:23 PM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 40 TargetSite: Void loadActiveCheckResult(Boolean)
Error - 12/23/2012 10:34:22 PM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 40 TargetSite: Void loadActiveCheckResult(Boolean)
Error - 12/30/2012 6:31:05 PM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 40 TargetSite: Void loadActiveCheckResult(Boolean)
Error - 1/1/2013 5:49:48 AM | Computer Name = Jeff-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckRes
ult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
7658 Ram Utilization: 30 TargetSite: Void loadActiveCheckResult(Boolean)
[ HP Software Framework Events ]
Error - 10/26/2011 12:38:23 AM | Computer Name = 960EC8351I5AL | Source = CaslWmi | ID = 5
Description = 2011/10/25 21:38:23.032|00000BB0|Error |[CaslWmi]CommandPanelBrightness::GetCurrentPanelBrightnessFromOS{hpCasl.enRetur
nCode(CaslWmi.enPanelBrightnessDataType,ushort&)}|Exception
occurred in querying WMI for WmiMonitorBrightness: 'Not supported '
Error - 10/26/2011 12:38:25 AM | Computer Name = 960EC8351I5AL | Source = CaslWmi | ID = 5
Description = 2011/10/25 21:38:25.248|00000BB0|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state
Error - 8/4/2012 6:40:46 PM | Computer Name = Jeff-HP | Source = CaslWmi | ID = 5
Description = 2012/08/04 15:40:46.394|00000E50|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state
Error - 8/4/2012 6:40:53 PM | Computer Name = Jeff-HP | Source = CaslWmi | ID = 5
Description = 2012/08/04 15:40:53.668|00000E58|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state
Error - 8/4/2012 10:38:02 PM | Computer Name = Jeff-HP | Source = CaslWmi | ID = 5
Description = 2012/08/04 19:38:02.136|00001364|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state
Error - 8/5/2012 5:18:20 PM | Computer Name = Jeff-HP | Source = CaslWmi | ID = 5
Description = 2012/08/05 14:18:20.392|00000E2C|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state
Error - 8/5/2012 5:21:15 PM | Computer Name = Jeff-HP | Source = CaslWmi | ID = 5
Description = 2012/08/05 14:21:15.909|00001698|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state
Error - 8/5/2012 5:21:24 PM | Computer Name = Jeff-HP | Source = CaslWmi | ID = 5
Description = 2012/08/05 14:21:24.175|000017BC|Error |[CaslWmi]CommandFolio::A{hpCasl.enReturnCode(int&)}|Error
0xe_BIOS_INVALID_COMMAND_TYPE from BIOS WMI call Read/2Eh while getting Folio state
[ System Events ]
Error - 12/14/2012 11:12:37 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.
Error - 12/14/2012 11:12:37 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.
Error - 12/14/2012 11:48:19 PM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.
Error - 12/15/2012 1:16:38 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.
Error - 12/15/2012 1:16:41 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.
Error - 12/15/2012 1:16:43 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.
Error - 12/15/2012 1:16:50 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.
Error - 12/15/2012 1:16:52 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.
Error - 12/15/2012 1:16:52 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.
Error - 12/15/2012 1:17:03 AM | Computer Name = Jeff-HP | Source = Microsoft-Windows-DNS-Client | ID = 1012
Description = There was an error while attempting to read the local hosts file.
< End of report >