This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Machine running badly [Solved]

39 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Hello All;
I think I have a problem with my machine,
Please find my HJT LOG FILE BELOW

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:24:47 PM, on 5/8/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\windows\system32\taskhost.exe
C:\windows\system32\Dwm.exe
C:\windows\Explorer.EXE
C:\windows\system32\taskeng.exe
C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
C:\Program Files\TOSHIBA\TECO\TEco.exe
C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Program Files\HP\Digital Imaging\bin\HpqSRmon.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe
C:\Program Files\Discover\SOAN\DiscoverSOAN.exe
C:\Program Files\AVG Secure Search\vprot.exe
C:\Program Files\AVG\AVG2013\avgui.exe
C:\Program Files\Ask.com\Updater\Updater.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Synaptics\SynTP\SynTPHelper.exe
C:\Program Files\Real\RealPlayer\Update\realsched.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\SecureBackupShare\ComcastSecureBackupSharestat.exe
C:\Windows\System32\OBroker.exe
C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
C:\windows\system32\taskeng.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_6_602_180.exe
C:\windows\system32\Macromed\Flash\FlashPlayerPlugin_11_6_602_180.exe
C:\Program Files\Mozilla Firefox\plugin-container.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
C:\windows\system32\NOTEPAD.EXE
C:\Users\User\AppData\Local\Temp\HouseCall\housecall.bin
C:\windows\system32\taskhost.exe
C:\Users\User\Downloads\New folder\HiJackThis.exe
C:\windows\system32\SearchFilterHost.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.comcast.net/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: UrlSearchHook Class - {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll
R3 - URLSearchHook: (no name) - {A3BC75A2-1F87-4686-AA43-5347D756017C} - (no file)
O2 - BHO: Freecause Shopping BHO - {0095C290-A428-4BDD-B98C-E0A116F1C702} - C:\Program Files\Shop to Win 9\ShoppingBHO.dll
O2 - BHO: ALOT Toolbar Helper - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C:\Program Files\alot\bin\BHO\alotBHO.dll
O2 - BHO: PriceGong - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.1.0\PriceGongIE.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: RealNetworks Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - (no file)
O2 - BHO: Secure Online Account Numbers Helper - {435EAA86-D32B-484F-869C-53745FCB1642} - C:\Program Files\Discover\SOAN\DiscoverSOANHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Zynga - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\prxtbZyn0.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\15.0.0.2\AVG Secure Search_toolbar.dll
O2 - BHO: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O2 - BHO: DCA - {B49699FC-1665-4414-A1CB-C4A2A4A13EEC} - C:\Program Files\Common Files\FreeCause\DCA\dca-bho.dll
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O3 - Toolbar: ALOT Toolbar - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll
O3 - Toolbar: Zynga Toolbar - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\prxtbZyn0.dll
O3 - Toolbar: Secure Online Account Numbers - {A8C7C2CA-6DFD-4E16-8458-592361564D38} - C:\Program Files\Discover\SOAN\DiscoverSOANToolbar.dll
O3 - Toolbar: Search Toolbar - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll
O3 - Toolbar: AVG Security Toolbar - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\15.0.0.2\AVG Secure Search_toolbar.dll
O3 - Toolbar: Ask Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files\Google\Google Toolbar\GoogleToolbar_32.dll
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe
O4 - HKLM\..\Run: [SynTPEnh] %ProgramFiles%\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [TPwrMain] %ProgramFiles%\TOSHIBA\Power Saver\TPwrMain.EXE
O4 - HKLM\..\Run: [SmoothView] %ProgramFiles%\Toshiba\SmoothView\SmoothView.exe
O4 - HKLM\..\Run: [00TCrdMain] %ProgramFiles%\TOSHIBA\FlashCards\TCrdMain.exe
O4 - HKLM\..\Run: [TosWaitSrv] %ProgramFiles%\TOSHIBA\TPHM\TosWaitSrv.exe
O4 - HKLM\..\Run: [Teco] "%ProgramFiles%\TOSHIBA\TECO\Teco.exe" /r
O4 - HKLM\..\Run: [TWebCamera] "%ProgramFiles%\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe" autorun
O4 - HKLM\..\Run: [SmartFaceVWatcher] %ProgramFiles%\Toshiba\SmartFaceV\SmartFaceVWatcher.exe
O4 - HKLM\..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe
O4 - HKLM\..\Run: [hpqSRMon] C:\Program Files\HP\Digital Imaging\bin\hpqSRMon.exe
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKLM\..\Run: [Toshiba Online Backup] "C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe" /m
O4 - HKLM\..\Run: [Secure Online Account Numbers] C:\PROGRA~1\Discover\SOAN\DISCOV~1.EXE /dontopenmycards
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [vProt] "C:\Program Files\AVG Secure Search\vprot.exe"
O4 - HKLM\..\Run: [AVG_UI] "C:\Program Files\AVG\AVG2013\avgui.exe" /TRAYONLY
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [ApnUpdater] "C:\Program Files\Ask.com\Updater\Updater.exe"
O4 - HKLM\..\Run: [TkBellExe] "c:\program files\real\realplayer\Update\realsched.exe" -osboot
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [MyTOSHIBA] "C:\Program Files\TOSHIBA\My Toshiba\MyToshiba.exe" /AUTO
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Global Startup: Secure Backup and Share Status.lnk = C:\Program Files\SecureBackupShare\ComcastSecureBackupSharestat.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\windows\system32\GPhotos.scr/200
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MIF5BA~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIF5BA~1\Office12\REFIEBAR.DLL
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - (no file)
O18 - Protocol: viprotocol - {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.0.0\ViProtocol.dll
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\windows\system32\atiesrxx.exe
O23 - Service: ARcltsrv - Algorithmic Research Ltd. - C:\Program Files\ARX\ARX CryptoKit\utils\ARcltsrv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: AVG Security Toolbar Service - Unknown owner - C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe
O23 - Service: AVGIDSAgent - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgidsagent.exe
O23 - Service: AVG WatchDog (avgwd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG2013\avgwdsvc.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
O23 - Service: Comcast Secure Backup & Share Backup Service (ComcastSecureBackupSharebackup) - Secure Backup and Share - C:\Program Files\SecureBackupShare\ComcastSecureBackupSharebackup.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files\WildTangent Games\App\GamesAppService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Mozilla Maintenance Service (MozillaMaintenance) - Mozilla Foundation - C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe
O23 - Service: RealNetworks Downloader Resolver Service - Unknown owner - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
O23 - Service: RelevantKnowledge - TMRG, Inc. - C:\Program Files\RelevantKnowledge\rlservice.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - TOSHIBA Corporation - C:\Windows\system32\TODDSrv.exe
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: vToolbarUpdater15.0.0 - Unknown owner - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe
O23 - Service: XobniService - Xobni Corporation - C:\Program Files\Xobni\XobniService.exe

–
End of file - 13761 bytes

Thank You Marty
Hello MARTY1946,

My name is OCD. I would be more than happy to take a look at your log and help you with solving any malware problems you might have. Logs can take a while to research, so please be patient and know that I am working hard to get you a clean and functional system back in your hands. I'd be grateful if you would note the following:

  • I will be working on your Malware issues, this may or may not, solve other issues you have with your machine.
  • The fixes are specific to your problem and should only be used for the issues on this machine.
  • Please continue to review my answers until I tell you your machine appears to be clear. Absence of symptoms does not mean that everything is clear.
  • It's often worth reading through these instructions and printing them for ease of reference.
  • If you don't know or understand something, please don't hesitate to say or ask!! It's better to be sure and safe than sorry.
  • Please reply to this thread. Do not start a new topic.
IMPORTANT NOTE : Please do not delete, download or install anything unless instructed to do so.

DO NOT use any TOOLS such as Combofix or HijackThis fixes without supervision. Doing so could make your system inoperable and could require a full reinstall of your Operating System and losing all your programs and data.

Important Note for Vista and Windows 7 users:

These tools MUST be run from the executable.(.exe) every time you run them with Admin Rights (Right click, choose "Run as Administrator")

Please stay with this topic until I let you know that your system appears to be "All Clear"

I will reply with further instructions after I review your logs.

= = = = = = = = = = = = = = = = = = = =

Download AdwCleaner to your desktop.

Right click and select "Run as Administrator".
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply
- - - - - Next - - - - -

Download aswMBR.exe and save it to your desktop.

Right click and select "Run as Administrator".
  • When asked if you want to download Avast's virus definitions please select Yes.
  • Click Scan
  • Upon completion of the scan, click Save log and save it to your desktop, and post that log in your next reply for review. Note - do NOT attempt any Fix yet.
  • You will also notice another file created on the desktop named MBR.dat. Right click that file and select Send To>Compressed (zipped) file. Attach that zipped file in your next reply as well.
- - - - - Next - - - - -

Download OTL to your desktop.

Right click and select "Run as Administrator".
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true
    %USERPROFILE%\..|smtmp;true;true;true /FP
    %temp%\smtmp\*.* /s >
    BASESERVICES
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt.
    Note:These logs can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply. You may need two posts to fit them both in.
In your next post please provide the following:
  • AdwCleaner.txt
  • aswMBR.txt
  • attach MBR.zip
  • OTL.txt
  • Extras.txt
  • Describe what symptoms you are experiencing?
OTL logfile created on: 5/8/2013 7:21:12 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Downloads
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.37 Gb Available Physical Memory | 49.91% Memory free
5.49 Gb Paging File | 3.71 Gb Available in Paging File | 67.61% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.71 Gb Total Space | 235.88 Gb Free Space | 81.70% Space Free | Partition Type: NTFS

Computer Name: RICHARDGMARTIN | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2013/05/08 18:52:48 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\User\Downloads\OTL.exe
PRC - [2013/05/08 17:23:15 | 000,044,784 | —- | M] (MindSpark) – C:\Program Files\UtilityChest_49\bar\1.bin\49SrchMn.exe
PRC - [2013/05/08 17:23:15 | 000,042,504 | —- | M] (COMPANYVERS_NAME) – C:\Program Files\UtilityChest_49\bar\1.bin\49barsvc.exe
PRC - [2013/05/08 17:23:15 | 000,030,096 | —- | M] (VER_COMPANY_NAME) – C:\Program Files\UtilityChest_49\bar\1.bin\49brmon.exe
PRC - [2013/04/12 16:50:58 | 000,920,472 | —- | M] (Mozilla Corporation) – C:\Program Files\Mozilla Firefox\firefox.exe
PRC - [2013/03/31 08:49:08 | 000,295,512 | —- | M] (RealNetworks, Inc.) – C:\Program Files\Real\RealPlayer\Update\realsched.exe
PRC - [2013/03/19 08:19:22 | 001,219,248 | —- | M] () – C:\Program Files\AVG Secure Search\vprot.exe
PRC - [2013/03/19 08:19:22 | 000,990,896 | —- | M] () – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe
PRC - [2013/03/13 17:15:00 | 004,394,032 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2013\avgui.exe
PRC - [2013/03/13 10:35:17 | 001,822,424 | —- | M] (Adobe Systems, Inc.) – C:\Windows\System32\Macromed\Flash\FlashPlayerPlugin_11_6_602_180.exe
PRC - [2013/03/06 02:21:52 | 000,039,056 | —- | M] () – C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe
PRC - [2013/02/27 23:42:12 | 004,937,264 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2013\avgidsagent.exe
PRC - [2013/02/26 23:41:54 | 000,763,440 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2013\avgrsx.exe
PRC - [2013/02/19 04:02:02 | 000,282,624 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe
PRC - [2013/02/19 04:01:34 | 001,116,720 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2013\avgnsx.exe
PRC - [2013/02/19 04:00:58 | 000,448,560 | —- | M] (AVG Technologies CZ, s.r.o.) – C:\Program Files\AVG\AVG2013\avgcsrvx.exe
PRC - [2012/12/18 10:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/11/22 22:48:41 | 000,049,152 | —- | M] (Microsoft Corporation) – C:\Windows\System32\taskhost.exe
PRC - [2012/11/13 14:08:12 | 003,487,240 | —- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe
PRC - [2012/11/13 14:08:08 | 003,825,176 | —- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe
PRC - [2012/11/13 14:07:24 | 000,168,384 | —- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe
PRC - [2012/11/13 14:07:20 | 001,369,624 | —- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe
PRC - [2012/11/13 14:07:16 | 001,103,392 | —- | M] (Safer-Networking Ltd.) – C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe
PRC - [2012/10/17 01:46:34 | 001,573,576 | —- | M] (Ask) – C:\Program Files\Ask.com\Updater\Updater.exe
PRC - [2011/04/29 20:18:16 | 000,062,184 | —- | M] (Xobni Corporation) – C:\Program Files\Xobni\XobniService.exe
PRC - [2010/12/14 13:06:06 | 003,539,688 | —- | M] (Secure Backup and Share) – C:\Program Files\SecureBackupShare\ComcastSecureBackupSharestat.exe
PRC - [2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) – C:\Windows\explorer.exe
PRC - [2010/08/06 14:26:02 | 000,045,896 | —- | M] (Secure Backup and Share) – C:\Program Files\SecureBackupShare\ComcastSecureBackupSharebackup.exe
PRC - [2010/03/05 17:03:26 | 000,376,832 | —- | M] (Orbiscom Ltd. All rights reserved.) – C:\Program Files\Discover\SOAN\DiscoverSOAN.exe
PRC - [2010/03/05 17:02:02 | 000,145,920 | —- | M] (Orbiscom Ltd.) – C:\Windows\System32\OBroker.exe
PRC - [2010/01/15 12:22:24 | 000,965,976 | —- | M] () – C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe
PRC - [2009/12/22 11:21:26 | 000,116,672 | —- | M] (Algorithmic Research Ltd.) – C:\Program Files\ARX\ARX CryptoKit\utils\ARcltsrv.exe
PRC - [2009/08/21 12:29:40 | 000,464,224 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
PRC - [2009/08/21 12:29:20 | 000,476,512 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe
PRC - [2009/08/11 19:09:54 | 000,185,712 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\TECO\TecoService.exe
PRC - [2009/08/11 19:09:38 | 001,324,384 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\TECO\TEco.exe
PRC - [2009/08/11 14:37:50 | 002,446,648 | —- | M] (TOSHIBA CORPORATION.) – C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe
PRC - [2009/08/10 22:55:46 | 000,185,712 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe
PRC - [2009/08/06 20:05:18 | 000,583,024 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe
PRC - [2009/08/06 20:04:56 | 000,685,424 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
PRC - [2009/08/05 17:04:54 | 000,738,616 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe
PRC - [2009/08/03 21:16:50 | 001,021,272 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe
PRC - [2009/08/03 21:16:32 | 000,111,960 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
PRC - [2009/07/30 02:54:38 | 000,348,160 | —- | M] (AMD) – C:\Windows\System32\atieclxx.exe
PRC - [2009/07/30 02:54:10 | 000,176,128 | —- | M] (AMD) – C:\Windows\System32\atiesrxx.exe
PRC - [2009/07/28 23:26:42 | 000,062,848 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\TOSHIBA\ConfigFree\CFSwMgr.exe
PRC - [2009/07/28 18:43:04 | 000,128,344 | —- | M] (TOSHIBA Corporation) – C:\Windows\System32\TODDSrv.exe
PRC - [2009/07/28 17:00:10 | 000,460,088 | —- | M] (TOSHIBA Corporation) – C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe
PRC - [2009/07/13 18:24:00 | 000,304,496 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\TOSHIBA\ConfigFree\NDSTray.exe
PRC - [2009/03/10 21:51:20 | 000,046,448 | —- | M] (TOSHIBA CORPORATION) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe


========== Modules (No Company Name) ==========

MOD - [2013/04/12 16:50:57 | 003,133,336 | —- | M] () – C:\Program Files\Mozilla Firefox\mozjs.dll
MOD - [2013/03/19 08:19:22 | 001,219,248 | —- | M] () – C:\Program Files\AVG Secure Search\vprot.exe
MOD - [2013/03/19 08:19:22 | 000,157,360 | —- | M] () – C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.0.0\SiteSafety.dll
MOD - [2013/03/13 10:35:16 | 014,717,144 | —- | M] () – C:\Windows\System32\Macromed\Flash\NPSWF32_11_6_602_180.dll
MOD - [2013/02/15 09:58:37 | 000,593,408 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\XobniStatistics\7b10f464b28d133a5ed3a417b4dbbfe6\XobniStatistics.ni.dll
MOD - [2013/02/15 09:58:34 | 003,494,912 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\XobniFeeds\440dcdab9e30030678f807e559dd48c6\XobniFeeds.ni.dll
MOD - [2013/02/15 09:57:45 | 001,122,304 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\Xobni.XMapiAccessor\e7ca9a7adb751b9980257293731b710e\Xobni.XMapiAccessor.ni.dll
MOD - [2013/02/15 09:57:43 | 000,883,712 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\XobniGadgets\ec980e4092ebca8d12057cddcbdb0e54\XobniGadgets.ni.dll
MOD - [2013/02/15 09:57:42 | 000,593,408 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\XobniPluginAPI\35a6a04833fb8bb1aebff40432b49f1b\XobniPluginAPI.ni.dll
MOD - [2013/02/15 09:57:36 | 015,345,664 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\XobniCommon\88db8d27a69e411db497b4b1c6563438\XobniCommon.ni.dll
MOD - [2013/02/15 09:24:21 | 001,840,640 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\64cf6c356be66bb17c4667d6d8aa467b\System.Web.Services.ni.dll
MOD - [2013/02/15 09:24:19 | 011,833,344 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll
MOD - [2013/02/15 09:23:51 | 012,436,480 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll
MOD - [2013/01/10 10:07:49 | 001,028,608 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.In#\6f62c9035248cbba2dae864b3a39636d\Microsoft.Office.Interop.Outlook.ni.dll
MOD - [2013/01/10 10:07:49 | 000,043,520 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\stdole\e48a55170d389688bb93808fdfebf8f7\stdole.ni.dll
MOD - [2013/01/10 10:07:48 | 000,506,880 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\office\212651f618176161df02f2483d004843\office.ni.dll
MOD - [2013/01/10 10:07:46 | 000,366,080 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\Antlr3.Runtime\25f1ec4ec1c24503db6d29427e967537\Antlr3.Runtime.ni.dll
MOD - [2013/01/10 10:07:43 | 000,550,912 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\XobniResources\6314b5bd70644992ba08235bfd31c006\XobniResources.ni.dll
MOD - [2013/01/10 10:07:42 | 000,497,664 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SQLite\e83a0f67b05bfc2b76d16faa08fc4cf4\System.Data.SQLite.ni.dll
MOD - [2013/01/10 10:07:41 | 000,328,704 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\Interop.shdocvw\3ad1d64d639f730acc378f623ffdadb1\Interop.shdocvw.ni.dll
MOD - [2013/01/10 10:07:39 | 000,438,272 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\LinqBridge\2cb2f04ae448cd918ecc979a39c380e7\LinqBridge.ni.dll
MOD - [2013/01/10 10:07:39 | 000,029,184 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\XobniDataTransfer\70e04da165c0fb94e768a889113260d8\XobniDataTransfer.ni.dll
MOD - [2013/01/10 10:07:34 | 001,099,776 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\Newtonsoft.Json.Net#\6498a0a7f2597e15d9d53bc7b9be10ab\Newtonsoft.Json.Net20.ni.dll
MOD - [2013/01/10 10:06:12 | 001,051,136 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\302207b4fa3083899fd8ab4db98cecc5\System.Management.ni.dll
MOD - [2013/01/10 10:04:10 | 000,220,672 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\5baea82888a13fa558004b24e3b107cf\CustomMarshalers.ni.dll
MOD - [2013/01/10 09:33:12 | 000,771,584 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll
MOD - [2013/01/10 09:33:10 | 000,628,224 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\01c6cb58745f397c9b7ccf3ab7bfc9cd\System.EnterpriseServices.ni.dll
MOD - [2013/01/10 09:33:06 | 000,627,200 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\536d704e93ffec9b54e4a0312fb5b996\System.Transactions.ni.dll
MOD - [2013/01/10 09:33:04 | 006,611,456 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\dd20416f723ee13ffb4173ec1afc4ec4\System.Data.ni.dll
MOD - [2013/01/10 09:31:51 | 001,592,832 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll
MOD - [2013/01/10 09:31:05 | 005,453,312 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll
MOD - [2013/01/10 09:30:58 | 000,971,264 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll
MOD - [2013/01/10 09:30:56 | 007,989,760 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll
MOD - [2013/01/10 09:30:42 | 011,493,376 | —- | M] () – C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll
MOD - [2012/11/13 14:06:32 | 000,158,624 | —- | M] () – C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl
MOD - [2012/11/13 14:06:30 | 000,108,960 | —- | M] () – C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl
MOD - [2012/11/13 14:06:28 | 000,554,400 | —- | M] () – C:\Program Files\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl
MOD - [2012/11/13 14:06:28 | 000,528,288 | —- | M] () – C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl
MOD - [2012/11/13 14:06:28 | 000,416,160 | —- | M] () – C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl
MOD - [2011/10/05 04:52:30 | 000,756,048 | —- | M] () – C:\Program Files\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL
MOD - [2011/06/22 12:46:12 | 000,434,016 | —- | M] () – C:\Program Files\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll
MOD - [2011/05/11 07:04:31 | 000,904,704 | —- | M] () – C:\windows\assembly\GAC_32\System.Data.SQLite\1.0.66.0__db937bc2d44ff139\System.Data.SQLite.dll
MOD - [2011/05/11 07:04:31 | 000,516,096 | —- | M] () – C:\windows\assembly\GAC_32\Xobni.XMapiAccessor\2.0.1.13496__6298d2d1fcfb5d85\Xobni.XMapiAccessor.dll
MOD - [2011/05/11 07:04:31 | 000,480,256 | —- | M] () – C:\windows\assembly\GAC_32\ServerSync\2.0.1.13496__6298d2d1fcfb5d85\ServerSync.dll
MOD - [2011/05/11 07:04:31 | 000,224,256 | —- | M] () – C:\windows\assembly\GAC_32\Utilities\2.0.1.13496__6298d2d1fcfb5d85\Utilities.dll
MOD - [2011/05/11 07:04:30 | 000,003,072 | —- | M] () – C:\windows\assembly\GAC_MSIL\Extensibility\7.0.3300.0__6298d2d1fcfb5d85\Extensibility.dll
MOD - [2011/04/29 20:18:20 | 000,062,184 | —- | M] () – C:\Program Files\Xobni\XobniMainConnector.dll
MOD - [2011/04/29 20:17:58 | 000,045,056 | —- | M] () – C:\Program Files\Xobni\XobniFailsafeUpdateChecker.dll
MOD - [2011/04/29 20:15:36 | 000,004,608 | —- | M] () – C:\Program Files\Xobni\ManagedAggregator.dll
MOD - [2011/04/29 20:15:34 | 000,124,416 | —- | M] () – C:\Program Files\Xobni\WindowDriver.dll
MOD - [2010/11/04 21:58:05 | 002,927,616 | —- | M] () – C:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2010/11/04 21:57:39 | 000,069,120 | —- | M] () – C:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll
MOD - [2010/04/22 14:40:58 | 001,364,480 | —- | M] () – C:\Program Files\ARX\ARX CoSign Client\cosign.dll
MOD - [2010/03/05 16:59:44 | 000,071,680 | —- | M] () – C:\Program Files\Discover\SOAN\DiscoverSOAN.dll
MOD - [2010/01/15 12:22:34 | 000,012,608 | —- | M] () – C:\Program Files\Toshiba Online Backup\Toast.dll
MOD - [2010/01/15 12:22:24 | 000,965,976 | —- | M] () – C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe
MOD - [2010/01/15 12:22:22 | 000,275,784 | —- | M] () – C:\Program Files\Toshiba Online Backup\SdbShared.dll
MOD - [2009/10/16 07:55:13 | 001,736,704 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3497.38831__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll
MOD - [2009/10/16 07:55:13 | 000,950,272 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager2.Graphics.Dashboard\2.0.3497.38923__90ba9c70f846762e\CLI.Aspect.DisplaysManager2.Graphics.Dashboard.dll
MOD - [2009/10/16 07:55:13 | 000,782,336 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3497.38856__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll
MOD - [2009/10/16 07:55:13 | 000,573,440 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3497.38833__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll
MOD - [2009/10/16 07:55:13 | 000,491,520 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3497.38899__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll
MOD - [2009/10/16 07:55:13 | 000,409,600 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3497.38875__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll
MOD - [2009/10/16 07:55:13 | 000,393,216 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3497.38855__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll
MOD - [2009/10/16 07:55:13 | 000,339,968 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3497.38814__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll
MOD - [2009/10/16 07:55:13 | 000,331,776 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3497.38868__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll
MOD - [2009/10/16 07:55:13 | 000,315,392 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3497.38862__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll
MOD - [2009/10/16 07:55:13 | 000,307,200 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3497.38837__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll
MOD - [2009/10/16 07:55:13 | 000,204,800 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3497.38833__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll
MOD - [2009/10/16 07:55:13 | 000,196,608 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3497.38833__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll
MOD - [2009/10/16 07:55:13 | 000,118,784 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard\2.0.3497.38898__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.dll
MOD - [2009/10/16 07:55:13 | 000,094,208 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3497.38868__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll
MOD - [2009/10/16 07:55:13 | 000,094,208 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3497.38861__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll
MOD - [2009/10/16 07:55:13 | 000,081,920 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3497.38856__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll
MOD - [2009/10/16 07:55:13 | 000,077,824 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3497.38880__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll
MOD - [2009/10/16 07:55:13 | 000,073,728 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3497.38822__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll
MOD - [2009/10/16 07:55:13 | 000,065,536 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3497.38863__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll
MOD - [2009/10/16 07:55:13 | 000,061,440 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3497.38867__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll
MOD - [2009/10/16 07:55:13 | 000,061,440 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3497.38855__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll
MOD - [2009/10/16 07:55:13 | 000,045,056 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3497.38899__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll
MOD - [2009/10/16 07:55:13 | 000,045,056 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3497.38898__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll
MOD - [2009/10/16 07:55:13 | 000,040,960 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3497.38828__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll
MOD - [2009/10/16 07:55:13 | 000,040,960 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3497.38837__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll
MOD - [2009/10/16 07:55:13 | 000,036,864 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3497.38860__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll
MOD - [2009/10/16 07:55:13 | 000,036,864 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3497.38855__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll
MOD - [2009/10/16 07:55:13 | 000,032,768 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3497.38862__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll
MOD - [2009/10/16 07:55:13 | 000,020,480 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3497.38823__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll
MOD - [2009/10/16 07:55:12 | 000,270,336 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2009/10/16 07:55:12 | 000,106,496 | —- | M] () – C:\windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3497.38894__90ba9c70f846762e\MOM.Implementation.dll
MOD - [2009/10/16 07:55:12 | 000,098,304 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3428.28305__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,094,208 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3428.28298__90ba9c70f846762e\CLI.Foundation.dll
MOD - [2009/10/16 07:55:12 | 000,065,536 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3428.28316__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,053,248 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,053,248 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,053,248 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,049,152 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,045,056 | —- | M] () – C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll
MOD - [2009/10/16 07:55:12 | 000,045,056 | —- | M] () – C:\windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3497.38904__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll
MOD - [2009/10/16 07:55:12 | 000,040,960 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3428.28324__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,040,960 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,040,960 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3497.38856__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll
MOD - [2009/10/16 07:55:12 | 000,032,768 | —- | M] () – C:\windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3428.28296__90ba9c70f846762e\LOG.Foundation.dll
MOD - [2009/10/16 07:55:12 | 000,032,768 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3428.28309__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,028,672 | —- | M] () – C:\windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3428.28297__90ba9c70f846762e\NEWAEM.Foundation.dll
MOD - [2009/10/16 07:55:12 | 000,028,672 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3428.28354__90ba9c70f846762e\CLI.Foundation.XManifest.dll
MOD - [2009/10/16 07:55:12 | 000,028,672 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.3428.28323__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,028,672 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,028,672 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,028,672 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3428.28311__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,024,576 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3428.28304__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,024,576 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,020,480 | —- | M] () – C:\windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll
MOD - [2009/10/16 07:55:12 | 000,020,480 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,020,480 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3428.28302__90ba9c70f846762e\CLI.Component.Client.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,020,480 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,020,480 | —- | M] () – C:\windows\assembly\GAC_MSIL\APM.Foundation\2.0.3428.28310__90ba9c70f846762e\APM.Foundation.dll
MOD - [2009/10/16 07:55:12 | 000,020,480 | —- | M] () – C:\windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,020,480 | —- | M] () – C:\windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3428.28302__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,016,384 | —- | M] () – C:\windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3428.28310__90ba9c70f846762e\MOM.Foundation.dll
MOD - [2009/10/16 07:55:12 | 000,016,384 | —- | M] () – C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll
MOD - [2009/10/16 07:55:12 | 000,016,384 | —- | M] () – C:\windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3428.28324__90ba9c70f846762e\DEM.Graphics.dll
MOD - [2009/10/16 07:55:12 | 000,016,384 | —- | M] () – C:\windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll
MOD - [2009/10/16 07:55:12 | 000,016,384 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3428.28303__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,016,384 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,016,384 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,016,384 | —- | M] () – C:\windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Server.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,016,384 | —- | M] () – C:\windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,016,384 | —- | M] () – C:\windows\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3428.28329__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,016,384 | —- | M] () – C:\windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,016,384 | —- | M] () – C:\windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,016,384 | —- | M] () – C:\windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll
MOD - [2009/10/16 07:55:12 | 000,007,168 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3497.38810__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll
MOD - [2009/10/16 07:55:12 | 000,007,168 | —- | M] () – C:\windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll
MOD - [2009/10/16 07:55:11 | 001,212,416 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3497.38819__90ba9c70f846762e\CLI.Component.Dashboard.dll
MOD - [2009/10/16 07:55:11 | 000,405,504 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3497.38827__90ba9c70f846762e\CLI.Component.Wizard.dll
MOD - [2009/10/16 07:55:11 | 000,065,536 | —- | M] () – C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3497.38892__90ba9c70f846762e\LOG.Foundation.Implementation.dll
MOD - [2009/10/16 07:55:11 | 000,061,440 | —- | M] () – C:\windows\assembly\GAC_MSIL\APM.Server\2.0.3497.38811__90ba9c70f846762e\APM.Server.dll
MOD - [2009/10/16 07:55:11 | 000,057,344 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3497.38813__90ba9c70f846762e\CLI.Component.SkinFactory.dll
MOD - [2009/10/16 07:55:11 | 000,057,344 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3497.38812__90ba9c70f846762e\CLI.Component.Runtime.dll
MOD - [2009/10/16 07:55:11 | 000,045,056 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll
MOD - [2009/10/16 07:55:11 | 000,045,056 | —- | M] () – C:\windows\assembly\GAC_MSIL\AEM.Server\2.0.3497.38810__90ba9c70f846762e\AEM.Server.dll
MOD - [2009/10/16 07:55:11 | 000,040,960 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3428.28301__90ba9c70f846762e\CLI.Foundation.Private.dll
MOD - [2009/10/16 07:55:11 | 000,040,960 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll
MOD - [2009/10/16 07:55:11 | 000,036,864 | —- | M] () – C:\windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\LOG.Foundation.Private.dll
MOD - [2009/10/16 07:55:11 | 000,032,768 | —- | M] () – C:\windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll
MOD - [2009/10/16 07:55:11 | 000,024,576 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll
MOD - [2009/10/16 07:55:11 | 000,020,480 | —- | M] () – C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3428.28310__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll
MOD - [2009/10/16 07:55:11 | 000,020,480 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3428.28309__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll
MOD - [2009/10/16 07:55:11 | 000,020,480 | —- | M] () – C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3428.28316__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll
MOD - [2009/10/16 07:55:11 | 000,019,456 | —- | M] () – C:\windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3497.38893__90ba9c70f846762e\CCC.Implementation.dll
MOD - [2009/10/16 07:40:43 | 008,007,680 | —- | M] () – C:\windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll
MOD - [2009/08/03 21:17:24 | 000,079,192 | —- | M] () – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll
MOD - [2009/07/25 14:07:12 | 000,058,704 | —- | M] () – C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll
MOD - [2009/07/16 18:27:48 | 000,052,536 | —- | M] () – C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnZ.dll
MOD - [2009/07/16 18:27:44 | 007,263,544 | —- | M] () – C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll
MOD - [2009/06/22 18:38:40 | 000,015,160 | —- | M] () – C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll
MOD - [2009/06/10 17:23:19 | 000,261,632 | —- | M] () – C:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll
MOD - [2009/05/04 13:45:14 | 000,016,384 | R— | M] () – C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll
MOD - [2009/03/12 22:08:04 | 000,049,152 | —- | M] () – C:\Program Files\TOSHIBA\PCDiag\NotifyPCD.dll
MOD - [2009/02/26 14:46:56 | 000,064,344 | —- | M] () – C:\Program Files\Microsoft Office\Office12\ADDINS\ColleagueImport.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Running] – C:\Program Files\Spybot – (SDWSCService)
SRV - File not found [Auto | Running] – C:\Program Files\Spybot – (SDUpdateService)
SRV - File not found [Auto | Running] – C:\Program Files\Spybot – (SDScannerService)
SRV - File not found [Auto | Stopped] – C:\Program Files\RelevantKnowledge\rlservice.exe /service – (RelevantKnowledge)
SRV - [2013/05/08 17:23:15 | 000,042,504 | —- | M] (COMPANYVERS_NAME) [Auto | Running] – C:\Program Files\UtilityChest_49\bar\1.bin\49barsvc.exe – (UtilityChest_49Service)
SRV - [2013/04/12 16:50:57 | 000,115,608 | —- | M] (Mozilla Foundation) [On_Demand | Stopped] – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe – (MozillaMaintenance)
SRV - [2013/03/19 08:19:22 | 000,990,896 | —- | M] () [Auto | Running] – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe – (vToolbarUpdater15.0.0)
SRV - [2013/03/13 10:35:18 | 000,253,656 | —- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe – (AdobeFlashPlayerUpdateSvc)
SRV - [2013/03/06 02:21:52 | 000,039,056 | —- | M] () [Auto | Running] – C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe – (RealNetworks Downloader Resolver Service)
SRV - [2013/02/27 23:42:12 | 004,937,264 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2013\avgidsagent.exe – (AVGIDSAgent)
SRV - [2013/02/19 04:02:02 | 000,282,624 | —- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] – C:\Program Files\AVG\AVG2013\avgwdsvc.exe – (avgwd)
SRV - [2012/12/18 10:28:08 | 000,065,192 | —- | M] (Adobe Systems Incorporated) [Auto | Running] – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe – (AdobeARMservice)
SRV - [2011/07/26 10:16:02 | 001,025,352 | —- | M] () [On_Demand | Stopped] – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe – (AVG Security Toolbar Service)
SRV - [2011/04/29 20:18:16 | 000,062,184 | —- | M] (Xobni Corporation) [Auto | Running] – C:\Program Files\Xobni\XobniService.exe – (XobniService)
SRV - [2010/10/12 13:59:12 | 000,206,072 | —- | M] (WildTangent, Inc.) [On_Demand | Stopped] – C:\Program Files\WildTangent Games\App\GamesAppService.exe – (GamesAppService)
SRV - [2010/08/15 17:17:27 | 001,343,400 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\Wat\WatAdminSvc.exe – (WatAdminSvc)
SRV - [2010/08/06 14:26:02 | 000,045,896 | —- | M] (Secure Backup and Share) [Auto | Running] – C:\Program Files\SecureBackupShare\ComcastSecureBackupSharebackup.exe – (ComcastSecureBackupSharebackup)
SRV - [2010/02/10 12:39:34 | 000,085,096 | —- | M] (Autodesk) [On_Demand | Stopped] – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe – (Autodesk Licensing Service)
SRV - [2009/12/22 11:21:26 | 000,116,672 | —- | M] (Algorithmic Research Ltd.) [Auto | Running] – C:\Program Files\ARX\ARX CryptoKit\utils\ARcltsrv.exe – (ARcltsrv)
SRV - [2009/08/21 12:29:40 | 000,464,224 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe – (TosCoSrv)
SRV - [2009/08/17 13:48:42 | 000,051,512 | —- | M] (TOSHIBA Corporation) [On_Demand | Stopped] – C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe – (TMachInfo)
SRV - [2009/08/11 19:09:54 | 000,185,712 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Program Files\TOSHIBA\TECO\TecoService.exe – (TOSHIBA eco Utility Service)
SRV - [2009/08/10 22:55:46 | 000,185,712 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe – (cfWiMAXService)
SRV - [2009/08/06 20:04:56 | 000,685,424 | —- | M] (TOSHIBA Corporation) [On_Demand | Running] – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe – (TPCHSrv)
SRV - [2009/08/03 21:16:32 | 000,111,960 | —- | M] (TOSHIBA Corporation) [On_Demand | Running] – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe – (TOSHIBA HDD SSD Alert Service)
SRV - [2009/07/30 02:54:10 | 000,176,128 | —- | M] (AMD) [Auto | Running] – C:\Windows\System32\atiesrxx.exe – (AMD External Events Utility)
SRV - [2009/07/28 18:43:04 | 000,128,344 | —- | M] (TOSHIBA Corporation) [Auto | Running] – C:\Windows\System32\TODDSrv.exe – (TODDSrv)
SRV - [2009/07/13 21:16:13 | 000,025,088 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\sensrsvc.dll – (SensrSvc)
SRV - [2009/07/13 21:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2009/03/10 21:51:20 | 000,046,448 | —- | M] (TOSHIBA CORPORATION) [Auto | Running] – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe – (ConfigFree Service)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\RtsUCcid.sys – (USBCCID)
DRV - File not found [Kernel | On_Demand | Stopped] – system32\DRIVERS\Rts516xIR.sys – (RtsUIR)
DRV - File not found [Kernel | On_Demand | Stopped] – System32\Drivers\RtsUStor.sys – (RSUSBSTOR)
DRV - File not found [Kernel | On_Demand | Stopped] – C:\Users\User\AppData\Local\Temp\cpuz134\cpuz134_x32.sys – (cpuz134)
DRV - [2013/03/19 08:19:22 | 000,033,624 | —- | M] (AVG Technologies) [Kernel | System | Running] – C:\Windows\System32\drivers\avgtpx86.sys – (avgtp)
DRV - [2013/03/01 10:32:20 | 000,022,328 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\System32\drivers\avgidsshimx.sys – (AVGIDSShim)
DRV - [2013/02/26 23:40:46 | 000,208,184 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\System32\drivers\avgidsdriverx.sys – (AVGIDSDriver)
DRV - [2013/02/14 03:52:46 | 000,182,072 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\System32\drivers\avgtdix.sys – (Avgtdix)
DRV - [2013/02/08 04:37:58 | 000,096,568 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\Windows\System32\drivers\avgmfx86.sys – (Avgmfx86)
DRV - [2013/02/08 04:37:56 | 000,245,048 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] – C:\Windows\System32\drivers\avglogx.sys – (Avglogx)
DRV - [2013/02/08 04:37:52 | 000,060,216 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | Boot | Running] – C:\Windows\System32\drivers\avgidshx.sys – (AVGIDSHX)
DRV - [2013/02/08 04:37:44 | 000,170,808 | —- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] – C:\Windows\System32\drivers\avgldx86.sys – (Avgldx86)
DRV - [2013/02/08 04:37:40 | 000,039,224 | —- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] – C:\Windows\System32\drivers\avgrkx86.sys – (Avgrkx86)
DRV - [2010/12/14 13:05:58 | 000,054,776 | —- | M] (Mozy, Inc.) [File_System | System | Running] – C:\Windows\System32\drivers\ComcastSecureBackupShare.sys – (ComcastSecureBackupShareFilter)
DRV - [2010/11/20 06:24:41 | 000,052,224 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\TsUsbFlt.sys – (TsUsbFlt)
DRV - [2010/11/20 05:59:44 | 000,035,968 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\winusb.sys – (winusb)
DRV - [2009/08/28 01:19:22 | 000,859,136 | —- | M] (Realtek Semiconductor Corporation ) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\rtl8192se.sys – (rtl8192se)
DRV - [2009/07/30 20:45:56 | 000,022,912 | —- | M] (TOSHIBA Corporation.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\tdcmdpst.sys – (tdcmdpst)
DRV - [2009/07/30 15:06:30 | 004,994,560 | —- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\atikmdag.sys – (atikmdag)
DRV - [2009/07/24 18:57:06 | 000,275,536 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\System32\drivers\tos_sps32.sys – (tos_sps32)
DRV - [2009/07/14 18:28:42 | 000,023,512 | —- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] – C:\Windows\System32\drivers\TVALZ_O.SYS – (TVALZ)
DRV - [2009/07/13 19:52:10 | 000,014,336 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\vwifimp.sys – (vwifimp)
DRV - [2009/07/13 18:13:48 | 001,035,776 | —- | M] (LSI Corp) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\AGRSM.sys – (AgereSoftModem)
DRV - [2009/07/13 18:02:46 | 001,096,704 | —- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Stopped] – C:\Windows\System32\drivers\athr.sys – (athr)
DRV - [2009/07/07 11:53:06 | 000,007,680 | —- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\FwLnk.sys – (FwLnk)
DRV - [2009/06/22 20:04:58 | 000,024,064 | —- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\PGEffect.sys – (PGEffect)
DRV - [2009/06/19 22:31:08 | 000,012,920 | —- | M] (TOSHIBA Corporation) [Kernel | Auto | Running] – C:\Windows\System32\drivers\TVALZFL.sys – (TVALZFL)
DRV - [2009/05/21 14:24:44 | 000,021,392 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\dc3d.sys – (dc3d)
DRV - [2009/05/08 21:14:21 | 000,030,088 | —- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] – C:\Windows\System32\drivers\point32k.sys – (Point32)
DRV - [2009/05/05 03:30:28 | 000,014,392 | —- | M] (Advanced Micro Devices Inc.) [Kernel | Boot | Running] – C:\Windows\System32\drivers\AtiPcie.sys – (AtiPcie)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\URLSearchHook: {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\prxtbZyn0.dll (Conduit Ltd.)
IE - HKLM\..\SearchScopes,DefaultScope = {0EF3D5EE-B833-43EC-8265-E0B5C71D50AB}
IE - HKLM\..\SearchScopes\{0EF3D5EE-B833-43EC-8265-E0B5C71D50AB}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSNA

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…A&bmod=TSNA
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://home.mywebsearch.com/index.jhtml?n=…p;si=EL_UTUS_13
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.comcast.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {00000000-6E41-4FD3-8538-502F5495E5FC} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
IE - HKCU\..\URLSearchHook: {7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a} - No CLSID value found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0EF3D5EE-B833-43EC-8265-E0B5C71D50AB}
IE - HKCU\..\SearchScopes\{05727330-12A2-6573-6C66-81489A35331A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;form=ZGAIDF
IE - HKCU\..\SearchScopes\{0EF3D5EE-B833-43EC-8265-E0B5C71D50AB}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7TSNA_enUS360
IE - HKCU\..\SearchScopes\{171DEBEB-C3D4-40b7-AC73-056A5EBA4A7E}: "URL" = http://websearch.ask.com/redirect?client=i…E4-88A78CFB580F
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={CBDFB5B…mp;d=2012-10-08 13:09:47&v=14.2.0.1&pid=avg&sg=&sap=dsp&q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultengine: "Ask.com"
FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.defaultthis.engineName: "Elf 1 Customized Web Search"
FF - prefs.js..browser.search.defaulturl: "http://search.conduit.com/ResultsExt.aspx?ctid=CT2856415&SearchSource=3&q={searchTerms}"
FF - prefs.js..browser.search.order.1: "Ask.com"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://home.mywebsearch.com/index.jhtml?ptb=CFE800C2-9499-4604-B32A-5BCB1C14BDFE&n=77fcb7c1&p2=^ZO^xdm036^YY^us&si=EL_UTUS_13"
FF - prefs.js..extensions.enabledAddons: %7B3e0e7d2a-070f-4a47-b019-91fe5385ba79%7D:3.5.9
FF - prefs.js..extensions.enabledAddons: %7B7b13ec3e-999a-4b70-b9cb-2617b8323822%7D:3.18.0.7
FF - prefs.js..extensions.enabledAddons: avg%40toolbar:15.0.0.2
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: avg@igeared:6.103.018.001
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: discoversoan@orbiscom:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0
FF - prefs.js..extensions.enabledItems: {3e0e7d2a-070f-4a47-b019-91fe5385ba79}:3.1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24


FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files\Common Files\AVG Secure Search\SiteSafetyInstaller\15.0.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@MyOwnSuperhero.com/Plugin: C:\Program Files\MyOwnSuperhero\bar\2.bin\NPv3Stub.dll (MyOwnSuperhero)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@UtilityChest_49.com/Plugin: C:\Program Files\UtilityChest_49\bar\1.bin\NP49Stub.dll (MindSpark)
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.17: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.17: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@Webfetti.com/Plugin: C:\Program Files\Webfetti\bar\2.bin\NP7dStub.dll (Webfetti)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\14\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Webfetti\bar\2.bin [2011/08/18 12:29:58 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyOwnSuperhero\bar\2.bin [2011/08/17 09:32:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\discoversoan@orbiscom: C:\Program Files\Discover\SOAN [2010/12/24 13:53:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/03/31 08:50:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\15.0.0.2 [2013/03/19 08:20:47 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DAC3F861-B30D-40dd-9166-F4E75327FAC7}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/03/31 08:50:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\49ffxtbr@UtilityChest_49.com: C:\Program Files\UtilityChest_49\bar\1.bin [2013/05/08 17:23:20 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/04/12 16:50:58 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/04/12 16:50:49 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\{8A9386B4-E958-4c4c-ADF4-8F26DB3E4829}: C:\Program Files\PriceGong\2.1.0\FF [2010/07/14 04:23:44 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/04/12 16:50:58 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/04/12 16:50:49 | 000,000,000 | —D | M]

[2010/01/31 03:42:40 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\mozilla\Extensions
[2013/05/08 17:35:36 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\pk9h6b1c.default\extensions
[2012/08/31 23:24:30 | 000,000,000 | —D | M] (AddThis) – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2013/03/04 15:39:43 | 000,000,000 | —D | M] (Zynga Community Toolbar) – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{7b13ec3e-999a-4b70-b9cb-2617b8323822}
[2013/05/08 17:23:06 | 000,000,000 | —D | M] (Utility Chest) – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\49ffxtbr@UtilityChest_49.com
[2012/11/04 10:02:50 | 000,000,000 | —D | M] (Ask Toolbar) – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\[removed]
[2012/11/04 10:02:50 | 000,002,308 | —- | M] () – C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\pk9h6b1c.default\searchplugins\askcom.xml
[2010/12/27 18:00:44 | 000,001,919 | —- | M] () – C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\pk9h6b1c.default\searchplugins\bing-zugo.xml
[2010/12/01 18:22:54 | 000,000,913 | —- | M] () – C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\pk9h6b1c.default\searchplugins\conduit.xml
[2010/12/03 16:35:37 | 000,010,039 | —- | M] () – C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\pk9h6b1c.default\searchplugins\Webfetti.xml
[2013/04/12 16:50:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/04/12 16:50:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2013/04/12 16:50:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013/03/19 08:20:47 | 000,000,000 | —D | M] (AVG Security Toolbar) – C:\PROGRAMDATA\AVG SECURE SEARCH\FIREFOXEXT\15.0.0.2
[2013/04/12 16:50:58 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/12/26 09:51:03 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2009/11/19 18:16:28 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npCouponPrinter.dll
[2009/11/19 18:16:29 | 000,091,552 | —- | M] (Coupons, Inc.) – C:\Program Files\mozilla firefox\plugins\npMozCouponPrinter.dll
[2013/03/31 08:49:17 | 000,124,504 | —- | M] (RealPlayer) – C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2013/03/19 08:20:50 | 000,003,714 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\avg-secure-search.xml
[2012/10/21 16:43:46 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/02/27 19:53:32 | 000,002,086 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnhgoncokajlafhnhjmccgcmgggiehjm\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.3_0\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\jmfkcklnlgedgbglfkkgedjfmejoahla\10.0.0.1374_0\

O1 HOSTS File: ([2011/12/22 16:11:00 | 000,000,833 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (Search Assistant BHO) - {06e05b40-77fa-40b6-9077-ed1a7577b1ef} - C:\Program Files\UtilityChest_49\bar\1.bin\49SrcAs.dll (MindSpark)
O2 - BHO: (ALOT Toolbar Helper) - {14CEEAFF-96DD-4101-AE37-D5ECDC23C3F6} - C:\Program Files\alot\bin\BHO\alotBHO.dll (Vertro)
O2 - BHO: (PriceGongBHO Class) - {1631550F-191D-4826-B069-D9439253D926} - C:\Program Files\PriceGong\2.1.0\PriceGongIE.dll (PriceGong)
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Secure Online Account Numbers Helper) - {435EAA86-D32B-484F-869C-53745FCB1642} - C:\Program Files\Discover\SOAN\DiscoverSOANHelper.dll (Orbiscom Ltd. All rights reserved.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (Toolbar BHO) - {58f7b5ca-1162-42e8-8bbc-d543b4edd780} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\prxtbZyn0.dll (Conduit Ltd.)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\15.0.0.2\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O2 - BHO: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll (Vertro)
O3 - HKLM\..\Toolbar: (Zynga Toolbar) - {7b13ec3e-999a-4b70-b9cb-2617b8323822} - C:\Program Files\Zynga\prxtbZyn0.dll (Conduit Ltd.)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files\AVG Secure Search\15.0.0.2\AVG Secure Search_toolbar.dll ()
O3 - HKLM\..\Toolbar: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKLM\..\Toolbar: (Secure Online Account Numbers) - {A8C7C2CA-6DFD-4E16-8458-592361564D38} - C:\Program Files\Discover\SOAN\DiscoverSOANToolbar.dll (Orbiscom Ltd. All rights reserved.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Utility Chest) - {cf67755f-9265-449c-87cf-b945519e073b} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll (MindSpark)
O3 - HKLM\..\Toolbar: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Zynga Toolbar) - {7B13EC3E-999A-4B70-B9CB-2617B8323822} - C:\Program Files\Zynga\prxtbZyn0.dll (Conduit Ltd.)
O3 - HKCU\..\Toolbar\WebBrowser: (Search Toolbar) - {9D425283-D487-4337-BAB6-AB8354A81457} - C:\Program Files\Search Toolbar\SearchToolbar.dll ()
O3 - HKCU\..\Toolbar\WebBrowser: (Ask Toolbar) - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files\Ask.com\GenericAskToolbar.dll (Ask)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [ApnUpdater] C:\Program Files\Ask.com\Updater\Updater.exe (Ask)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [Secure Online Account Numbers] C:\Program Files\Discover\SOAN\DiscoverSOAN.exe (Orbiscom Ltd. All rights reserved.)
O4 - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Toshiba Online Backup] C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe ()
O4 - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKLM..\Run: [Utility Chest Search Scope Monitor] C:\Program Files\UtilityChest_49\bar\1.bin\49SrchMn.exe (MindSpark)
O4 - HKLM..\Run: [UtilityChest_49 Browser Plugin Loader] C:\Program Files\UtilityChest_49\bar\1.bin\49brmon.exe (VER_COMPANY_NAME)
O4 - HKLM..\Run: [vProt] C:\Program Files\AVG Secure Search\vprot.exe ()
O4 - HKCU..\Run: [MyTOSHIBA] C:\Program Files\TOSHIBA\My Toshiba\MyToshiba.exe (TOSHIBA)
O4 - HKCU..\Run: [Spybot-S&D Cleaning] C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg Error: Key error. File not found
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ABBFB7FF-852E-4FF6-9DC0-3A692906985E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CF438D8B-532B-4B7A-972C-707EF7287EFF}: DhcpNameServer = 75.75.76.76 75.75.75.75
O18 - Protocol\Handler\linkscanner - No CLSID value found
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files\Common Files\AVG Secure Search\ViProtocolInstaller\15.0.0\ViProtocol.dll ()
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/05/08 18:19:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
[2013/05/08 18:19:05 | 000,000,000 | —D | C] – C:\rei
[2013/05/08 18:19:00 | 000,000,000 | —D | C] – C:\Program Files\Reimage
[2013/05/08 17:23:20 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\UtilityChest_49
[2013/05/08 17:23:14 | 000,000,000 | —D | C] – C:\Program Files\UtilityChest_49
[2013/05/08 14:56:10 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/05/08 14:56:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/05/08 14:55:47 | 000,015,224 | —- | C] (Safer Networking Limited) – C:\windows\System32\sdnclean.exe
[2013/05/08 14:55:42 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy 2
[2013/05/08 14:55:04 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Programs
[2013/05/01 08:29:22 | 000,174,496 | —- | C] (Oracle Corporation) – C:\windows\System32\javaw.exe
[2013/05/01 08:29:22 | 000,174,496 | —- | C] (Oracle Corporation) – C:\windows\System32\java.exe
[2013/05/01 08:29:22 | 000,094,112 | —- | C] (Oracle Corporation) – C:\windows\System32\WindowsAccessBridge.dll
[2013/04/29 21:34:39 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\windows\System32\MsSpellCheckingFacility.exe
[2013/04/29 21:34:39 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\windows\System32\elshyph.dll
[2013/04/29 21:34:39 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\windows\System32\msls31.dll
[2013/04/29 21:34:39 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\windows\System32\RegisterIEPKEYs.exe
[2013/04/29 21:34:39 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\windows\System32\jsproxy.dll
[2013/04/29 21:34:38 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeeds.dll
[2013/04/29 21:34:38 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\windows\System32\msrating.dll
[2013/04/29 21:34:38 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\windows\System32\iexpress.exe
[2013/04/29 21:34:38 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\windows\System32\wextract.exe
[2013/04/29 21:34:38 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\windows\System32\inseng.dll
[2013/04/29 21:34:37 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2013/04/29 21:34:37 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieUnatt.exe
[2013/04/29 21:34:37 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\windows\System32\iepeers.dll
[2013/04/29 21:34:37 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\windows\System32\IEAdvpack.dll
[2013/04/29 21:34:37 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\windows\System32\pngfilt.dll
[2013/04/29 21:34:37 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedsbs.dll
[2013/04/29 21:34:37 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\windows\System32\imgutil.dll
[2013/04/29 21:34:37 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedssync.exe
[2013/04/29 21:34:36 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\windows\System32\jscript9.dll
[2013/04/29 21:34:36 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2013/04/29 21:34:36 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\windows\System32\iesysprep.dll
[2013/04/29 21:34:36 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\windows\System32\SetIEInstalledDate.exe
[2013/04/29 21:34:36 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtmler.dll
[2013/04/29 21:34:35 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\windows\System32\html.iec
[2013/04/29 21:34:35 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\windows\System32\dxtrans.dll
[2013/04/29 21:34:34 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\windows\System32\inetcpl.cpl
[2013/04/29 21:34:34 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dat
[2013/04/29 21:34:34 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtmlmedia.dll
[2013/04/29 21:34:34 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dll
[2013/04/29 21:34:34 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\windows\System32\dxtmsft.dll
[2013/04/29 21:34:34 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\windows\System32\iedkcs32.dll
[2013/04/29 21:34:34 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\windows\System32\url.dll
[2013/04/29 21:34:34 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\windows\System32\iesetup.dll
[2013/04/29 21:34:34 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\windows\System32\ie4uinit.exe
[2013/04/29 21:34:34 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\windows\System32\iernonce.dll
[2013/04/29 21:34:34 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\windows\System32\licmgr10.dll
[2013/04/29 21:33:06 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/29 21:33:06 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/29 21:33:06 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/29 21:33:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/29 21:33:05 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\windows\System32\msmpeg2vdec.dll
[2013/04/29 21:33:05 | 001,504,768 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d11.dll
[2013/04/29 21:33:05 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\windows\System32\DWrite.dll
[2013/04/29 21:33:05 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\windows\System32\XpsPrint.dll
[2013/04/29 21:33:05 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\windows\System32\WMPhoto.dll
[2013/04/29 21:33:05 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\windows\System32\XpsGdiConverter.dll
[2013/04/29 21:33:05 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10core.dll
[2013/04/29 21:33:05 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/29 21:33:05 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/29 21:33:04 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\windows\System32\d2d1.dll
[2013/04/29 21:33:04 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10warp.dll
[2013/04/29 21:33:04 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10.dll
[2013/04/29 21:33:04 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10level9.dll
[2013/04/29 21:33:04 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\windows\System32\dxgi.dll
[2013/04/29 21:33:04 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10_1core.dll
[2013/04/29 21:33:04 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\windows\System32\WindowsCodecsExt.dll
[2013/04/29 21:33:04 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\windows\System32\UIAnimation.dll
[2013/04/29 21:33:04 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10_1.dll
[2013/04/12 16:50:47 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/04/10 11:05:30 | 002,347,008 | —- | C] (Microsoft Corporation) – C:\windows\System32\win32k.sys
[2013/04/10 11:05:26 | 003,968,856 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntkrnlpa.exe
[2013/04/10 11:05:26 | 003,913,560 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntoskrnl.exe
[2013/04/10 11:05:25 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\windows\System32\csrsrv.dll
[2013/04/10 11:05:13 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\windows\System32\aaclient.dll
[2013/04/10 11:05:12 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\windows\System32\tsgqec.dll
[2011/05/11 07:00:10 | 006,533,152 | —- | C] (Xobni) – C:\Users\User\XobniSetup.exe
[2011/01/25 19:18:13 | 008,969,504 | —- | C] (Secure Backup and Share) – C:\ProgramData\TempComcastSecureBackupShare-update-94576f825cbee21cffeff81117efd21f.exe
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/08 19:25:00 | 000,000,886 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/08 18:42:37 | 000,015,792 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/08 18:42:37 | 000,015,792 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/08 18:35:34 | 000,000,830 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2013/05/08 18:34:20 | 000,000,882 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/08 18:33:51 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2013/05/08 18:33:43 | 2211,577,856 | -HS- | M] () – C:\hiberfil.sys
[2013/05/08 18:20:03 | 000,000,162 | —- | M] () – C:\windows\Reimage.ini
[2013/05/08 18:19:06 | 000,002,025 | —- | M] () – C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
[2013/05/08 16:16:17 | 000,001,586 | —- | M] () – C:\Users\User\Documents\cc_20130508_161612.reg
[2013/05/08 15:45:24 | 000,001,772 | —- | M] () – C:\windows\wininit.ini
[2013/05/08 14:56:02 | 000,002,090 | —- | M] () – C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/05/08 14:19:40 | 001,012,646 | —- | M] () – C:\Users\User\AppData\Local\census.cache
[2013/05/08 14:18:41 | 000,196,593 | —- | M] () – C:\Users\User\AppData\Local\ars.cache
[2013/05/08 14:00:25 | 000,000,036 | —- | M] () – C:\Users\User\AppData\Local\housecall.guid.cache
[2013/05/07 17:57:19 | 000,003,416 | —- | M] () – C:\windows\ComcastSecureBackupShare.blk
[2013/05/07 17:57:19 | 000,000,354 | —- | M] () – C:\windows\ComcastSecureBackupShare.flt
[2013/04/30 08:13:30 | 000,433,584 | —- | M] () – C:\windows\System32\FNTCACHE.DAT
[2013/04/29 21:34:39 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\windows\System32\MsSpellCheckingFacility.exe
[2013/04/29 21:34:39 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\windows\System32\elshyph.dll
[2013/04/29 21:34:39 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\windows\System32\msls31.dll
[2013/04/29 21:34:39 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\windows\System32\RegisterIEPKEYs.exe
[2013/04/29 21:34:39 | 000,039,424 | —- | M] (Microsoft Corporation) – C:\windows\System32\jsproxy.dll
[2013/04/29 21:34:38 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\windows\System32\msfeeds.dll
[2013/04/29 21:34:38 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\windows\System32\msrating.dll
[2013/04/29 21:34:38 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\windows\System32\iexpress.exe
[2013/04/29 21:34:38 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\windows\System32\wextract.exe
[2013/04/29 21:34:38 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\windows\System32\inseng.dll
[2013/04/29 21:34:37 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2013/04/29 21:34:37 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieUnatt.exe
[2013/04/29 21:34:37 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\windows\System32\iepeers.dll
[2013/04/29 21:34:37 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\windows\System32\IEAdvpack.dll
[2013/04/29 21:34:37 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\windows\System32\pngfilt.dll
[2013/04/29 21:34:37 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\windows\System32\msfeedsbs.dll
[2013/04/29 21:34:37 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\windows\System32\imgutil.dll
[2013/04/29 21:34:37 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\windows\System32\msfeedssync.exe
[2013/04/29 21:34:36 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\windows\System32\jscript9.dll
[2013/04/29 21:34:36 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2013/04/29 21:34:36 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\windows\System32\iesysprep.dll
[2013/04/29 21:34:36 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\windows\System32\SetIEInstalledDate.exe
[2013/04/29 21:34:36 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\windows\System32\mshtmler.dll
[2013/04/29 21:34:35 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\windows\System32\html.iec
[2013/04/29 21:34:35 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\windows\System32\dxtrans.dll
[2013/04/29 21:34:34 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\windows\System32\inetcpl.cpl
[2013/04/29 21:34:34 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dat
[2013/04/29 21:34:34 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\windows\System32\mshtmlmedia.dll
[2013/04/29 21:34:34 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dll
[2013/04/29 21:34:34 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\windows\System32\dxtmsft.dll
[2013/04/29 21:34:34 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\windows\System32\iedkcs32.dll
[2013/04/29 21:34:34 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\windows\System32\url.dll
[2013/04/29 21:34:34 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\windows\System32\iesetup.dll
[2013/04/29 21:34:34 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\windows\System32\ie4uinit.exe
[2013/04/29 21:34:34 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\windows\System32\iernonce.dll
[2013/04/29 21:34:34 | 000,025,185 | —- | M] () – C:\windows\System32\ieuinit.inf
[2013/04/29 21:34:34 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\windows\System32\licmgr10.dll
[2013/04/29 21:33:06 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/29 21:33:06 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/29 21:33:06 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/29 21:33:06 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/29 21:33:05 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\windows\System32\msmpeg2vdec.dll
[2013/04/29 21:33:05 | 001,504,768 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d11.dll
[2013/04/29 21:33:05 | 001,247,744 | —- | M] (Microsoft Corporation) – C:\windows\System32\DWrite.dll
[2013/04/29 21:33:05 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\windows\System32\XpsPrint.dll
[2013/04/29 21:33:05 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\windows\System32\WMPhoto.dll
[2013/04/29 21:33:05 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\windows\System32\XpsGdiConverter.dll
[2013/04/29 21:33:05 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10core.dll
[2013/04/29 21:33:05 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/29 21:33:05 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/29 21:33:04 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\windows\System32\d2d1.dll
[2013/04/29 21:33:04 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10warp.dll
[2013/04/29 21:33:04 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10.dll
[2013/04/29 21:33:04 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10level9.dll
[2013/04/29 21:33:04 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\windows\System32\dxgi.dll
[2013/04/29 21:33:04 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10_1core.dll
[2013/04/29 21:33:04 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\windows\System32\WindowsCodecsExt.dll
[2013/04/29 21:33:04 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\windows\System32\UIAnimation.dll
[2013/04/29 21:33:04 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10_1.dll
[2013/04/12 17:54:47 | 000,002,001 | —- | M] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/04/10 08:20:37 | 000,002,100 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/08 18:19:06 | 000,002,025 | —- | C] () – C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
[2013/05/08 18:18:39 | 000,000,162 | —- | C] () – C:\windows\Reimage.ini
[2013/05/08 16:16:15 | 000,001,586 | —- | C] () – C:\Users\User\Documents\cc_20130508_161612.reg
[2013/05/08 15:45:22 | 000,001,772 | —- | C] () – C:\windows\wininit.ini
[2013/05/08 14:56:02 | 000,002,102 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2013/05/08 14:56:02 | 000,002,090 | —- | C] () – C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/05/08 14:19:40 | 001,012,646 | —- | C] () – C:\Users\User\AppData\Local\census.cache
[2013/05/08 14:18:41 | 000,196,593 | —- | C] () – C:\Users\User\AppData\Local\ars.cache
[2013/05/08 14:00:25 | 000,000,036 | —- | C] () – C:\Users\User\AppData\Local\housecall.guid.cache
[2013/04/29 21:34:34 | 000,025,185 | —- | C] () – C:\windows\System32\ieuinit.inf
[2011/10/08 08:48:11 | 000,000,210 | —- | C] () – C:\Users\User\AppData\Roaming\wklnhst.dat
[2011/04/13 17:51:02 | 000,001,502 | —- | C] () – C:\Users\User\.recently-used.xbel
[2011/03/16 18:54:03 | 000,000,000 | —- | C] () – C:\Users\User\AppData\Local\prvlcl.dat
[2010/12/05 03:58:53 | 000,026,837 | —- | C] () – C:\Users\User\AppData\Roaming\Comma Separated Values (Windows).ADR
[2010/12/02 10:05:38 | 000,000,017 | —- | C] () – C:\Users\User\AppData\Local\resmon.resmoncfg
[2010/12/01 03:12:28 | 000,001,662 | —- | C] () – C:\Users\User\Windows Easy Transfer.lnk
[2010/12/01 03:12:28 | 000,000,706 | —- | C] () – C:\Users\User\autorun.inf

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/09/29 20:01:06 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Alawar Entertainment
[2010/12/28 23:27:29 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Amazonia
[2010/02/13 13:07:18 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Autodesk
[2012/10/19 08:46:03 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\AVG2013
[2012/01/13 17:48:15 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Boomzap
[2011/12/25 15:40:41 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Casual Arts
[2012/12/07 00:27:00 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Catalina Marketing Corp
[2011/12/31 18:01:54 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\EnchantedCavern2
[2012/01/04 18:03:08 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Friday's games
[2012/04/02 19:55:57 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\GameCards
[2011/04/13 17:51:02 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\gtk-2.0
[2011/10/09 17:47:44 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\iMaxGen
[2010/12/03 22:53:26 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\iWin
[2011/10/02 17:19:18 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Jewel Keepers Easter Island
[2012/08/19 15:15:27 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Jewel Match 3
[2012/02/06 20:30:10 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Mahjong LoT
[2010/07/14 05:06:48 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\OpenOffice.org
[2010/08/29 18:14:37 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Opera
[2010/12/27 14:58:43 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\PlayFirst
[2010/12/28 13:05:27 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Playrix Entertainment
[2012/04/16 21:18:29 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Pogo Games
[2011/09/09 20:30:50 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\PTV Game
[2012/01/13 18:09:02 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\ScreenSeven
[2011/10/08 08:48:13 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Template
[2010/01/31 16:52:04 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\TOSHIBA
[2012/10/08 13:10:10 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\TuneUp Software
[2011/04/06 14:57:38 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\Unity
[2010/07/14 04:25:09 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\WeatherBug
[2012/07/03 17:27:11 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\WildTangent
[2009/11/09 08:14:17 | 000,000,000 | —D | M] – C:\Users\User\AppData\Roaming\WinBatch

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_518afd35db100430\explorer.exe
[2009/10/31 01:45:39 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_51a66d6ddafc2ed1\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_53bc10fdd7fe87ca\explorer.exe
[2009/08/03 01:49:47 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_526619d4f3f142e6\explorer.exe
[2009/08/03 01:35:50 | 002,613,248 | —- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_51e07e31dad00878\explorer.exe
[2009/10/31 02:00:51 | 002,614,272 | —- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_52283b2af41f3691\explorer.exe
[2012/11/13 14:07:52 | 003,906,584 | —- | M] (Safer-Networking Ltd.) MD5=E4A0900CF535888DDD85B10040CA3E34 – C:\Program Files\Spybot - Search & Destroy 2\explorer.exe

< MD5 for: SERVICES.EXE >
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\System32\services.exe
[2009/07/13 21:14:36 | 000,259,072 | —- | M] (Microsoft Corporation) MD5=5F1B6A9C35D3D5CA72D6D6FDEF9747D6 – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_cf36168b2e9c967b\services.exe

< MD5 for: SVCHOST.EXE >
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\System32\svchost.exe
[2009/07/13 21:14:41 | 000,020,992 | —- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 08:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\System32\userinit.exe
[2010/11/20 08:17:48 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2009/07/13 21:14:43 | 000,026,112 | —- | M] (Microsoft Corporation) MD5=6DE80F60D7DE9CE6B8C2DDFDF79EF175 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7600.16385_none_dbff103933038d7c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/10/28 02:17:59 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=37CDB7E72EB66BA85A87CBE37E7F03FD – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_6fc699643622d177\winlogon.exe
[2009/10/28 01:52:08 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=3BABE6767C78FBF5FB8435FEED187F30 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_703394514f56f7c2\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\System32\winlogon.exe
[2010/11/20 08:17:54 | 000,286,720 | —- | M] (Microsoft Corporation) MD5=6D13E1406F50C66E2A95D97F22C47560 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_71ca6b0233339500\winlogon.exe
[2009/07/13 21:14:45 | 000,285,696 | —- | M] (Microsoft Corporation) MD5=8EC6A4AB12B8F3759E21F8E3A388F2CF – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_6f99573a36451166\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true >

< %USERPROFILE%\..|smtmp;true;true;true /FP >

< %temp%\smtmp\*.* /s > >

========== Base Services ==========
SRV - [2009/07/13 21:14:53 | 000,062,464 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\aelupsvc.dll – (AeLookupSvc)
SRV - [2010/11/20 08:18:03 | 000,047,104 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\appinfo.dll – (Appinfo)
SRV - [2009/07/13 21:14:11 | 000,059,392 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\alg.exe – (ALG)
SRV - [2010/11/20 08:20:58 | 000,585,728 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\qmgr.dll – (BITS)
SRV - [2010/11/20 08:18:06 | 000,494,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\BFE.DLL – (BFE)
SRV - [2011/11/17 01:29:50 | 000,022,528 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\lsass.exe – (KeyIso)
SRV - [2009/07/13 21:15:19 | 000,271,360 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\es.dll – (EventSystem)
SRV - [2012/07/04 17:14:34 | 000,102,912 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\browser.dll – (Browser)
SRV - [2012/06/02 00:36:29 | 000,140,288 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\cryptsvc.dll – (CryptSvc)
SRV - [2010/11/20 08:21:03 | 000,376,832 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\rpcss.dll – (DcomLaunch)
SRV - [2010/11/20 08:18:30 | 000,254,464 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\dhcpcore.dll – (Dhcp)
SRV - [2011/03/03 01:38:01 | 000,132,608 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\dnsrslvr.dll – (Dnscache)
SRV - [2009/07/13 21:15:13 | 000,098,304 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\eapsvc.dll – (EapHost)
SRV - [2009/07/13 21:15:24 | 000,049,152 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\hidserv.dll – (hidserv)
SRV - [2009/07/13 21:15:33 | 000,300,544 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\ipnathlp.dll – (SharedAccess)
SRV - [2010/11/20 08:19:23 | 000,350,208 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\IPSECSVC.DLL – (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV - [2009/07/13 21:16:15 | 000,313,856 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\swprv.dll – (swprv)
SRV - [2009/07/13 21:15:41 | 000,049,664 | —- | M] (Microsoft Corporation) [Auto | Stopped] – C:\Windows\System32\mmcss.dll – (MMCSS)
SRV - [2009/07/13 21:16:03 | 000,280,576 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\netman.dll – (Netman)
SRV - [2009/07/13 21:16:03 | 000,360,448 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\netprofm.dll – (netprofm)
SRV - [2010/11/20 08:20:30 | 000,242,688 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\nlasvc.dll – (NlaSvc)
SRV - [2009/07/13 21:16:11 | 000,019,456 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\nsisvc.dll – (nsi)
SRV - [2011/05/24 06:44:59 | 000,293,376 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\umpnpmgr.dll – (PlugPlay)
SRV - [2010/11/20 08:17:45 | 000,317,440 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\spoolsv.exe – (Spooler)
SRV - [2011/11/17 01:29:50 | 000,022,528 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\lsass.exe – (ProtectedStorage)
No service found with a name of EMDMgmt
SRV - [2009/07/13 21:16:12 | 000,090,624 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\rasauto.dll – (RasAuto)
SRV - [2010/11/20 08:21:00 | 000,286,208 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\rasmans.dll – (RasMan)
SRV - [2010/11/20 08:21:03 | 000,376,832 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\rpcss.dll – (RpcSs)
SRV - [2009/07/13 21:16:13 | 000,021,504 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\seclogon.dll – (seclogon)
SRV - [2011/11/17 01:29:50 | 000,022,528 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\lsass.exe – (SamSs)
SRV - [2009/07/13 21:16:20 | 000,073,728 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wscsvc.dll – (wscsvc)
SRV - [2010/11/20 08:21:26 | 000,168,960 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\srvsvc.dll – (LanmanServer)
SRV - [2010/11/20 08:21:19 | 000,328,192 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\shsvcs.dll – (ShellHWDetection)
No service found with a name of slsvc
SRV - [2010/11/20 08:21:05 | 000,750,592 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\schedsvc.dll – (Schedule)
SRV - [2010/11/20 08:21:28 | 000,242,176 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\tapisrv.dll – (TapiSrv)
SRV - [2009/07/13 21:16:16 | 000,037,376 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\themeservice.dll – (Themes)
SRV - [2010/11/20 08:20:57 | 000,164,352 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\profsvc.dll – (ProfSvc)
SRV - [2010/11/20 08:17:51 | 001,025,536 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\VSSVC.exe – (VSS)
SRV - [2010/11/20 08:18:05 | 000,473,600 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\audiosrv.dll – (Audiosrv)
SRV - [2010/11/20 08:18:05 | 000,473,600 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\audiosrv.dll – (AudioEndpointBuilder)
SRV - [2010/11/20 08:21:06 | 000,125,952 | —- | M] (Microsoft Corporation) [On_Demand | Running] – C:\Windows\System32\sdrsvc.dll – (SDRSVC)
SRV - [2009/07/13 21:15:41 | 000,680,960 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Program Files\Windows Defender\MpSvc.dll – (WinDefend)
SRV - [2010/11/20 08:21:35 | 001,086,976 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wevtsvc.dll – (eventlog)
SRV - [2010/11/20 08:19:40 | 000,566,272 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\MPSSVC.dll – (MpsSvc)
SRV - [2010/11/20 08:21:35 | 000,463,360 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wiaservc.dll – (StiSvc)
SRV - [2010/11/20 08:17:22 | 000,073,216 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\windows\System32\msiexec.exe – (msiserver)
SRV - [2009/07/13 21:16:19 | 000,168,960 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wbem\WMIsvc.dll – (Winmgmt)
SRV - [2012/06/02 18:19:17 | 001,933,848 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wuaueng.dll – (wuauserv)
SRV - [2010/11/20 08:18:34 | 000,214,016 | —- | M] (Microsoft Corporation) [On_Demand | Stopped] – C:\Windows\System32\dot3svc.dll – (dot3svc)
SRV - [2009/07/13 21:16:19 | 000,829,440 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wlansvc.dll – (Wlansvc)
SRV - [2010/11/20 08:21:36 | 000,084,480 | —- | M] (Microsoft Corporation) [Auto | Running] – C:\Windows\System32\wkssvc.dll – (LanmanWorkstation)

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: IDE
Media Type: Fixed hard disk media
Model: Hitachi HTS545032B9A300 ATA Device
Partitions: 3
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: HP USB Device
Partitions: 0
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 1.00GB
Starting Offset: 1048576
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 289.00GB
Starting Offset: 1573912576
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 8.00GB
Starting Offset: 311570726912
Hidden sectors: 0


< End of report >
aswMBR version 0.9.9.1771 Copyright© 2011 AVAST Software Run date: 2013-05-08 19:49:21 —————————– 19:49:21.202 OS Version: Windows 6.1.7601 Service Pack 1 19:49:21.202 Number of processors: 2 586 0x602 19:49:21.202 ComputerName: RICHARDGMARTIN UserName: User 19:49:22.559 Initialize success 19:51:50.699 AVAST engine defs: 13050801 19:51:59.263 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1 19:51:59.263 Disk 0 Vendor: Hitachi_HTS545032B9A300 PB3OC64G Size: 305245MB BusType: 11 19:51:59.388 Disk 0 MBR read successfully 19:51:59.404 Disk 0 MBR scan 19:51:59.419 Disk 0 Windows VISTA default MBR code 19:51:59.435 Disk 0 Partition 1 80 (A) 27 Hidden NTFS WinRE NTFS 1500 MB offset 2048 19:51:59.450 Disk 0 Partition 2 00 07 HPFS/NTFS NTFS 295636 MB offset 3074048 19:51:59.497 Disk 0 Partition 3 00 17 Hidd HPFS/NTFS NTFS 8108 MB offset 608536576 19:51:59.528 Disk 0 scanning sectors +625141760 19:51:59.638 Disk 0 scanning C:\windows\system32\drivers 19:52:12.118 Service scanning 19:52:51.649 Modules scanning 19:53:00.370 Disk 0 trace - called modules: 19:53:00.416 ntkrnlpa.exe CLASSPNP.SYS disk.sys ACPI.sys halmacpi.dll ataport.SYS PCIIDEX.SYS msahci.sys 19:53:00.775 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x863c5ac8] 19:53:00.791 3 CLASSPNP.SYS[8b1bb59e] -> nt!IofCallDriver -> [0x863c5408] 19:53:00.822 5 ACPI.sys[8aba23d4] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0x863ba030] 19:53:02.242 AVAST engine scan C:\windows 19:53:05.393 AVAST engine scan C:\windows\system32 20:01:15.748 AVAST engine scan C:\windows\system32\drivers 20:01:43.829 AVAST engine scan C:\Users\User 20:10:03.404 AVAST engine scan C:\ProgramData 20:13:04.801 Scan finished successfully 20:14:14.205 Disk 0 MBR has been saved successfully to "C:\Users\User\Downloads\MBR.dat" 20:14:14.221 The log file has been saved successfully to "C:\Users\User\Downloads\aswMBR.txt"
Hi MARTY1946,

Please provide the remainder of the logs requested when they are available. :thumbup:

In your next post please provide the following:
  • AdwCleaner.txt
  • attach MBR.zip
  • Extras.txt
  • Describe what symptoms you are experiencing.
Helllo,
Here is the otl extras log
I attached the file you wanted
Not sure about the other log you wanted
Thanks Marty

OTL Extras logfile created on: 5/8/2013 6:53:51 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Downloads
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.94 Gb Available Physical Memory | 70.48% Memory free
5.49 Gb Paging File | 4.23 Gb Available in Paging File | 77.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.71 Gb Total Space | 235.88 Gb Free Space | 81.70% Space Free | Partition Type: NTFS

Computer Name: RICHARDGMARTIN | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] – C:\windows\winhlp32.exe (Microsoft Corporation)
.html [@ = ChromeHTML] – C:\Program Files\Google\Chrome\Application\chrome.exe (Google Inc.)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
hlpfile [open] – %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
https [open] – "C:\Program Files\Google\Chrome\Application\chrome.exe" – "%1" (Google Inc.)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –playlist-enqueue "%1" ()
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – C:\Program Files\VideoLAN\VLC\vlc.exe –started-from-file –no-playlist-enqueue "%1" ()
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = Reg Error: Unknown registry data type – File not found
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D 2 Background update service – (Safer-Networking Ltd.)


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{070A8257-02E2-4CC9-A846-7674983984CB}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{0AAC95E7-FA85-420A-95A3-26B2FE69723E}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0CF1AEEF-338D-4947-B36B-28E6F48A40B5}" = rport=137 | protocol=17 | dir=out | app=system |
"{292CD831-A9E4-4B89-B81B-CFE26BC05009}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{3DF83CB9-8D52-4BB7-9C0D-CAE9238845B7}" = lport=137 | protocol=17 | dir=in | app=system |
"{448C8E5C-23D4-46B6-98C2-E54673427F69}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{63CBC3CC-E1F7-4B6E-A8CD-A2711BBF56DD}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{6733A18A-D1F4-4419-A255-0F29EB182AE7}" = rport=445 | protocol=6 | dir=out | app=system |
"{6879DD80-18CC-44F6-82C2-BBA2772606F7}" = lport=139 | protocol=6 | dir=in | app=system |
"{6A298F9A-894F-42A8-99C3-59B51914989B}" = rport=138 | protocol=17 | dir=out | app=system |
"{700C1987-E69E-476A-BE70-9DF627A5E0B5}" = rport=139 | protocol=6 | dir=out | app=system |
"{727FF0C7-EDF0-498F-A41B-945CB13806F1}" = rport=137 | protocol=17 | dir=out | app=system |
"{7291D820-390F-4B6D-95E5-1BC3B6184FD2}" = lport=139 | protocol=6 | dir=in | app=system |
"{74BC5FB0-961C-42F9-B349-D6D457CDCBB2}" = lport=2869 | protocol=6 | dir=in | app=system |
"{75F04C04-ABD6-429B-B7DB-59B9C33FEE8E}" = lport=138 | protocol=17 | dir=in | app=system |
"{76F7191B-E3A7-439A-9281-0D1D05E4D35B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{799F77BA-8CC5-4840-BF2B-3C19A67CD6E8}" = lport=137 | protocol=17 | dir=in | app=system |
"{8B687D72-9A98-4895-9E6D-9C3029243EBE}" = rport=10243 | protocol=6 | dir=out | app=system |
"{990D8E77-46EF-4445-9476-B563DC916562}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{9C975F05-6D64-4CBE-B64F-DD2104D7BC83}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A5D2C003-93BF-40D1-8A54-488E5074652B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{ADB94C69-54D7-4736-ADEE-FC5AA595A54F}" = lport=445 | protocol=6 | dir=in | app=system |
"{AE3CCAF4-17E4-408B-BF5A-78E762DC577B}" = lport=138 | protocol=17 | dir=in | app=system |
"{B68A1FBF-5026-4D38-8AD9-EE9B88A30881}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office12\outlook.exe |
"{C77DC55C-3FAE-45F9-93FA-65D8C8831A93}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{D502551B-1319-40DF-9117-CD902377BA35}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{D6262D86-F71C-4EAA-8096-6321D2748637}" = rport=445 | protocol=6 | dir=out | app=system |
"{D9AA9336-EC6C-4275-8B21-1F72403229C6}" = rport=138 | protocol=17 | dir=out | app=system |
"{E229D5D4-D3B3-4A14-95F7-5437D11B1209}" = lport=445 | protocol=6 | dir=in | app=system |
"{E3B0E1B3-33D0-4B2E-AEB4-75A1428C9215}" = rport=139 | protocol=6 | dir=out | app=system |
"{E728FBF1-C2EE-4014-BEBA-07FB97DCC611}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{EE0AB99D-87CC-4D3E-8DF7-ED3E3FC46149}" = lport=2869 | protocol=6 | dir=in | app=system |
"{EEF08182-FF23-46DE-A90B-560A9D3E1F30}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{F01F8055-473F-4CBB-AD85-72D7F3AD0205}" = lport=10243 | protocol=6 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0176E861-E7CB-4DBB-B678-F32A7EFE7A99}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{07F6931D-1F51-4966-A167-FFEB346930DE}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{09390451-C68B-4469-BFE1-34FC8C670CF8}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{111B9F6B-6E5E-4C78-84A1-D709D77E5A76}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpsapp.exe |
"{2BC0BB42-512C-4C71-926E-BFF9A0ED0DA2}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2E070A29-5A4D-4038-A7D8-36CE48BBC754}" = protocol=6 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
"{3277A7A6-11C7-481A-94B4-99F04F50BBFA}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqpse.exe |
"{43723C6D-6F3F-46CE-A852-8C96B70D43EA}" = dir=in | app=c:\program files\common files\hp\digital imaging\bin\hpqphotocrm.exe |
"{46B8ABED-D20B-445B-8B2A-904DC6B8C3DB}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{4C04F02E-01D6-4B04-8EC2-A3DE3763BF13}" = dir=in | app=c:\program files\windows live\messenger\wlcsdk.exe |
"{4EC01B8F-19B2-4931-8247-3E2AA22FD859}" = protocol=58 | dir=in | app=system |
"{50D39613-E494-407B-BB10-AA127B788AD7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{51A19268-FD94-40CB-B92C-77144954A03B}" = protocol=6 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{52D5502F-38C9-4B76-B017-EAA1B827B137}" = protocol=58 | dir=out | name=@iphlpsvc.dll,-503 |
"{5BA4637E-2772-4031-8751-AB27685324B6}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{6239BF1C-0C92-4BCE-8A11-1D9F44B4C095}" = dir=in | app=c:\program files\hp\digital imaging\bin\hpqsudi.exe |
"{6684ABBE-2F13-4560-BBC4-712006BE97ED}" = dir=in | app=c:\program files\windows live\sync\windowslivesync.exe |
"{68C63DED-FC65-4BDF-BA12-AC2B24FCE413}" = protocol=6 | dir=in | app=c:\program files\relevantknowledge\rlvknlg.exe |
"{69F3D2F8-CE8A-4405-8D82-329029178FF9}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{6F398624-0940-40BB-BC6F-4841B4DCBF8E}" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
"{6FB40FF5-4AD0-46AE-90CF-BE5D0815D200}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{79FAF85F-09B3-4743-9368-D8708A84876D}" = protocol=17 | dir=in | app=c:\program files\avg\avg2012\avgmfapx.exe |
"{89C64287-ED50-4FE7-A8D4-9032C3B1154A}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{8AA9E420-F7FF-4DC9-A462-2ADC76726149}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office12\onenote.exe |
"{8ACFFA95-00B2-4BE9-873E-B347878CB1FA}" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
"{8F08EAAD-5133-45C0-AB81-DE5C87D040CE}" = protocol=17 | dir=in | app=c:\program files\relevantknowledge\rlvknlg.exe |
"{92540C0F-3DA5-49F2-A557-49E5121B11F8}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{9B64DFF6-11FF-4DC8-80F0-9C0D66DA7A4C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{A324DA70-2623-42DF-8B3F-DBC2404A1C06}" = dir=in | app=c:\program files\windows live\messenger\msnmsgr.exe |
"{A33B18E1-D3C0-4183-8432-D5A234831F9F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{A68566B6-4099-4B5B-86A0-FCD88B355ACD}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgnsx.exe |
"{A6E4DB45-44DC-4F4B-A0B5-C568985A92B2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{AD30153B-F49B-48CC-8BB3-B64D8924301F}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{AEEF5CEC-A7D4-448F-AB60-7749AE210491}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{C4A31044-85D7-4E48-B23C-2511AA46B8E6}" = protocol=17 | dir=in | app=c:\program files\avg\avg2013\avgdiagex.exe |
"{C5B61845-E89A-43FC-AAEE-8DC52299B5D9}" = protocol=6 | dir=in | app=c:\program files\avg\avg2013\avgmfapx.exe |
"{C7033EC0-9E99-4452-A742-4133FB23FA54}" = protocol=17 | dir=in | app=c:\program files\avg\avg10\avgmfapx.exe |
"{DF37A1B0-E952-4EB4-B103-BDDBDEEA5C4D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{EB84BB00-E299-41CD-865D-0B3D7E6D9274}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{F3A3D565-FBAA-4A03-8C8C-17EE8483407A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{F62D4657-48B3-4ADE-965B-6B94D66D38A2}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{FC99F486-19D5-4F8F-8536-168AD84FA2CF}" = protocol=6 | dir=out | app=system |
"TCP Query User{9826EBB2-FE43-478C-A9C2-324DE24C5889}C:\program files\e games\solitaire master 3\master.exe" = protocol=6 | dir=in | app=c:\program files\e games\solitaire master 3\master.exe |
"TCP Query User{A612DC93-1369-488E-8FF6-83FDF4D0ECBB}C:\program files\live tv\livetv.exe" = protocol=6 | dir=in | app=c:\program files\live tv\livetv.exe |
"TCP Query User{F587DDF9-09E2-4C1F-BA1A-096F223F9B61}C:\program files\opera\opera.exe" = protocol=6 | dir=in | app=c:\program files\opera\opera.exe |
"TCP Query User{FB06E249-6104-4818-BC91-EDF11EBD663D}C:\program files\live tv\livetv.exe" = protocol=6 | dir=in | app=c:\program files\live tv\livetv.exe |
"UDP Query User{2F41D7C9-221D-402E-BB1A-6F2407DA8F10}C:\program files\e games\solitaire master 3\master.exe" = protocol=17 | dir=in | app=c:\program files\e games\solitaire master 3\master.exe |
"UDP Query User{61717153-AC2B-4E13-AB58-A72EBF2B5DBD}C:\program files\live tv\livetv.exe" = protocol=17 | dir=in | app=c:\program files\live tv\livetv.exe |
"UDP Query User{9D9B5A61-1C6F-4F8E-BBCE-6B2740B136EE}C:\program files\opera\opera.exe" = protocol=17 | dir=in | app=c:\program files\opera\opera.exe |
"UDP Query User{DDB00E32-1F90-4A2C-8ACB-597A2AC1B83F}C:\program files\live tv\livetv.exe" = protocol=17 | dir=in | app=c:\program files\live tv\livetv.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{008D69EB-70FF-46AB-9C75-924620DF191A}" = TOSHIBA Speech System SR Engine(U.S.) Version1.0
"{01250B8F-D947-4F8A-9408-FE8E3EE2EC92}" = MyToshiba
"{0D795777-9D60-4692-8386-F2B3F2B5E5BF}" = Label@Once 1.0
"{0DB8F853-899A-8628-E0D7-29FB190CF848}" = Catalyst Control Center Graphics Full Existing
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0FB630AB-7BD8-40AE-B223-60397D57C3C9}" = Realtek WLAN Driver
"{117BCF94-6A1E-6741-39F5-09444381445E}" = CCC Help Italian
"{1211D6B0-B7B5-CB9A-99A2-066473FC35CA}" = CCC Help Swedish
"{12B3A009-A080-4619-9A2A-C6DB151D8D67}" = TOSHIBA Assist
"{14956199-1890-C3D4-F8B8-3C0C6FD82993}" = ccc-core-static
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{178832DE-9DE0-4C87-9F82-9315A9B03985}" = Windows Live Writer
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18E65799-76BD-46EF-9E53-972FE5A40736}" = Opera 10.62
"{1D210042-41EE-4472-2219-6A900366B9A3}" = CCC Help French
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{22B775E7-6C42-4FC5-8E10-9A5E3257BD94}" = MSVCRT
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{2ABB6396-785C-E2CB-579E-79BAF98E0527}" = Catalyst Control Center Graphics Previews Vista
"{2B290B14-1C25-4180-99B1-354B2D5D1D1E}" = AutoCAD 2009 Network License Activation Utility
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3B4E636E-9D65-4D67-BA61-189800823F52}" = Windows Live Communications Platform
"{3B53324C-AE52-42CC-9AA5-8EB11D8F657B}" = ARX Signature API
"{3B843B38-04B1-4CE6-8888-586273E0F289}" = Quickbooks Financial Center
"{3E1B8E31-9692-207B-77B7-A8339AF03795}" = Catalyst Control Center Graphics Full New
"{3E7F5E50-6956-4446-87BF-F422A8736B7F}" = Secure Online Account Numbers
"{3FBF6F99-8EC6-41B4-8527-0A32241B5496}" = TOSHIBA Speech System TTS Engine(U.S.) Version1.0
"{45338B07-A236-4270-9A77-EBB4115517B5}" = Windows Live Sign-in Assistant
"{46C045BF-2B3F-4BC4-8E4C-00E0CF8BD9DB}" = Adobe AIR
"{48A5AB54-6327-43DC-A376-4AC74C5D40B0}" = AVG 2013
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{51C77E17-3337-6409-16A9-A90CA8B9BBF6}" = ccc-utility
"{53536479-DFB0-47ED-9D10-43F3708C222D}" = TOSHIBA eco Utility
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{5783F2D7-0111-0409-0010-0060B0CE6BBA}" = Autodesk CAD Manager Tools
"{5783F2D7-7001-0409-0002-0060B0CE6BBA}" = AutoCAD 2009 - English
"{58630658-9DF7-E873-9F5D-0EAF87D25DAA}" = CCC Help Norwegian
"{594A3C2C-19B3-E02E-359C-B8D134F6B939}" = CCC Help Korean
"{5AF550B4-BB67-4E7E-82F1-2C4300279050}" = ToshibaRegistration
"{5DA0E02F-970B-424B-BF41-513A5018E4C0}" = TOSHIBA Disc Creator
"{5E6F6CF3-BACC-4144-868C-E14622C658F3}" = TOSHIBA Web Camera Application
"{6055830B-40E4-C794-3F04-2D0CD8AF1AAC}" = CCC Help Russian
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"{6412CECE-8172-4BE5-935B-6CECACD2CA87}" = Windows Live Mail
"{65980EBF-C4B5-4555-823A-94DB7F709E53}" = Secure Online Account Numbers
"{6615AD32-C190-4E61-B418-4357B7A3C11E}" = ARX CoSign Client
"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6C5F3BDC-0A1B-4436-A696-5939629D5C31}" = TOSHIBA DVD PLAYER
"{6E932CA6-FD17-7694-FD7C-14CE25770EA5}" = Catalyst Control Center Graphics Previews Common
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-toshiba" = WildTangent Games App (Toshiba Games)
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames" = WildTangent Games App
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7148F0A8-6813-11D6-A77B-00B0D0142040}" = Java 2 Runtime Environment, SE v1.4.2_04
"{739A6E9D-5D7D-8A5D-EC8A-4BD11E5749AA}" = CCC Help Hungarian
"{746FB02B-1D03-43B7-917A-E1341AB69A00}" = Toshiba Online Backup
"{7735BD50-87C5-4838-A276-4A3621BBD306}" = AVG 2013
"{7770E71B-2D43-4800-9CB3-5B6CAAEBEBEA}" = RealNetworks - Microsoft Visual C++ 2008 Runtime
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7B15D70E-9449-4CFB-B9BC-798465B2BD5C}" = Norton Internet Security
"{81128EE8-8EAD-4DB0-85C6-17C2CE50FF71}" = Windows Live Essentials
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86D4B82A-ABED-442A-BE86-96357B70F4FE}" = Ask Toolbar
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C72927B-7410-131A-E641-B9C505F4973C}" = CCC Help Japanese
"{8DC069E7-893C-41E1-9442-DE89FEC33371}" = Xobni Core
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}_STANDARDR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_STANDARDR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}_STANDARDR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}_STANDARDR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}_STANDARDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}_STANDARDR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-0012-0000-0000-0000000FF1CE}" = Microsoft Office Standard 2007
"{91120000-0012-0000-0000-0000000FF1CE}_STANDARDR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{911AB6CA-E04C-1E98-523D-8FCFAB4F456C}" = CCC Help Czech
"{9216C6A7-694A-4437-BD00-BD1CF58E1839}" = CCC Help Spanish
"{92DE68CE-BC3E-7323-EA53-99490C8BD34D}" = Catalyst Control Center Graphics Light
"{944C7ABA-33A6-9E48-8210-B3335FF64D65}" = Secure Backup and Share
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{95A6C205-5364-458B-AF5E-5102C9555ED4}" = ARX OmniSign Printer
"{9668AE11-E05C-8169-F6D8-FBF7B507D7DB}" = CCC Help German
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{970472D0-F5F9-4158-A6E3-1AE49EFEF2D3}" = Toshiba Application and Driver Installer
"{979587FD-F264-3C71-B0BE-6FC8DA993790}" = CCC Help Thai
"{999307CD-D57D-8C98-27ED-07F384ACFAA1}" = CCC Help Turkish
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9AEAF9CC-390B-49C0-8F7F-14092BF163B6}" = NetZero Launcher
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9DECD0F9-D3E8-48B0-A390-1CF09F54E3A4}" = TOSHIBA PC Health Monitor
"{A208044D-A88B-4ACF-AE95-E4F213E6EDC0}" = TOSHIBA Supervisor Password
"{A7594D38-0B7E-BCF7-A938-1AC03A6477FB}" = CCC Help English
"{A85FD55B-891B-4314-97A5-EA96C0BD80B5}" = Windows Live Messenger
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AAECF7BA-E83B-4A10-87EA-DE0B333F8734}" = RealNetworks - Microsoft Visual C++ 2010 Runtime
"{AC6569FA-6919-442A-8552-073BE69E247A}" = TOSHIBA Service Station
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.6)
"{AC7BE07B-14D3-6EB5-814A-EB0A63CBFB47}" = CCC Help Polish
"{AD37DC96-D09B-4819-96E7-A9799D6B00E4}" = ARX Office Signatures
"{B1CDB3C6-8DD8-4864-8589-BDFBDA033941}" = CCC Help Chinese Traditional
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B4BB4CF2-F475-FB20-7AFA-F8AED032BFF8}" = ATI Catalyst Install Manager
"{B65BBB06-1F8E-48F5-8A54-B024A9E15FDF}" = TOSHIBA Recovery Media Creator
"{BD77C684-DF3C-4237-A9F9-FA90ED58CA3F}" = PCLinq3
"{BDABF8CD-7436-EC6C-DD82-439225E22557}" = CCC Help Finnish
"{BEFBEDDF-1417-4C8A-92FB-F003C0D41199}" = OpenOffice.org 3.2
"{C5A15C68-0DF3-8A13-352E-E605491D7E3D}" = Catalyst Control Center InstallProxy
"{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CFAE78A9-A7A4-537E-7CC0-5A794FFBF73F}" = Catalyst Control Center Core Implementation
"{D0387727-C89D-4774-B643-B9333EAA09DE}" = TOSHIBA Hardware Setup
"{D19A1978-2FB2-B39A-5D30-C1EA38F788DD}" = CCC Help Danish
"{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"{D6C75F0B-3BC1-4FC9-B8C5-3F7E8ED059CA}" = Windows Live Photo Gallery
"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential
"{D8634D93-03DD-01F1-AC7D-EE468AA24F45}" = CCC Help Dutch
"{DA84ECBF-4B79-47F2-B34C-95C38484C058}" = Skype Launcher
"{DF2035BE-5820-4965-BD97-7FAF8D4A7879}" = Microsoft_VC90_CRT_x86
"{E151E679-4EC8-36F9-A691-C7600688A1CA}" = CCC Help Chinese Standard
"{E2DFE069-083E-4631-9B6C-43C48E991DE5}" = Junk Mail filter update
"{E3D63B95-4B21-414A-A2C7-D6D6A6AC6D79}" = Catalyst Control Center - Branding
"{E50AE784-FABE-46DA-A1F8-7B6B56DCB22E}" = Microsoft Office Suite Activation Assistant
"{E69992ED-A7F6-406C-9280-1C156417BC49}" = Toshiba Quality Application
"{EA1FAE0F-2354-4E32-B423-ABAE8E358F91}" = RealDownloader
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EBC6193C-ED23-E332-9A9C-D5CB83CDDE2B}" = Catalyst Control Center Localization All
"{EE033C1F-443E-41EC-A0E2-559B539A4E4D}" = TOSHIBA Speech System Applications
"{EF71A531-5B6C-4B20-8D1E-E6379C7FB6D3}" = Microsoft IntelliPoint 7.0
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E12BBA-AD66-4022-A453-A1C8A0C4D570}" = Microsoft Choice Guard
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F3529665-D75E-4D6D-98F0-745C78C68E9B}" = TOSHIBA ConfigFree
"{F544CA20-6810-E275-D288-F0D92CFADE4A}" = CCC Help Greek
"{F6BD194C-4190-4D73-B1B1-C48C99921BFE}" = Windows Live Call
"{F75D2B1D-5309-41DF-BC96-DFC3C3568C1D}" = ARX CryptoKit
"{FE2F2589-96A6-4F38-98F5-DDAC34BD41B9}" = Autodesk Network License Manager
"{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"{FEED29DD-7BF3-582C-3353-1F2634C2323D}" = CCC Help Portuguese
"7412d9dc1891c221a5c1aa6b7dec16be" = Bejeweled 2
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"alotToolbar" = ALOT Toolbar
"AutoCAD 2009 - English" = AutoCAD 2009 - English
"AVG" = AVG 2013
"AVG Secure Search" = AVG Security Toolbar
"CCleaner" = CCleaner
"Coupon Printer for Windows5.0.0.0" = Coupon Printer for Windows
"Defraggler" = Defraggler
"Google Chrome" = Google Chrome
"HijackThis" = HijackThis 2.0.2
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"HP Photosmart Essential" = HP Photosmart Essential 3.5
"InstallShield_{53536479-DFB0-47ED-9D10-43F3708C222D}" = TOSHIBA eco Utility
"InstallShield_{617C36FD-0CBE-4600-84B2-441CEB12FADF}" = TOSHIBA Extended Tiles for Windows Mobility Center
"InstallShield_{C730E42C-935A-45BB-A0C5-37E5234D111B}" = TOSHIBA Face Recognition
"InstallShield_{D4322448-B6AF-4316-B859-D8A0E84DCB38}" = TOSHIBA HDD/SSD Alert
"InstallShield_{FEDD27A0-B306-45EF-BF58-B527406B42C8}" = TOSHIBA Value Added Package
"LIVE TV_is1" = Live TV
"Mozilla Firefox 20.0.1 (x86 en-US)" = Mozilla Firefox 20.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MyOwnSuperherobar Uninstall" = MyOwnSuperhero
"Picasa 3" = Picasa 3
"PriceGong" = PriceGong 2.1.0
"RealPlayer 16.0" = RealPlayer
"Reimage Repair" = Reimage Repair
"Search Toolbar" = Search Toolbar
"Solitaire Master 3" = Solitaire Master 3
"STANDARDR" = Microsoft Office Standard 2007
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"UtilityChest_49bar Uninstall" = Utility Chest Toolbar
"Veetle TV" = Veetle TV 0.9.17
"VLC media player" = VLC media player 0.9.8a
"Webfettibar Uninstall" = Webfetti
"WildTangent toshiba Master Uninstall" = WildTangent Games
"WildTangent wildgames Master Uninstall" = WildTangent Games
"WinGimp-2.0_is1" = GIMP 2.6.10
"WinLiveSuite_Wave3" = Windows Live Essentials
"WTA-0576a020-a24f-42d3-9a07-0a04fe08112b" = Jar of Marbles
"WTA-05c35416-991b-4a56-bdc3-eb019f355b63" = Jewel Match 3
"WTA-0e32d50d-ebba-4088-9524-c7ba288df4b6" = KaromatiX The Broken World
"WTA-0e5bbeb2-c079-4613-822b-72bd2429c4ee" = QBeez 2
"WTA-161f6a95-b322-48bc-9e84-5f12db8eb695" = Bejeweled Twist
"WTA-18afc0a7-3841-46c4-b764-3ddd3e439945" = Blasterball 2: Remix
"WTA-1c905fbe-c759-4386-b705-b6d082bc9351" = 7 Wonders: Magical Mystery Tour
"WTA-20b887a9-69e4-4b47-8e60-d11a99b3c763" = Jewel Quest® The Sapphire Dragon Collector's Edition
"WTA-25c475e5-237b-4a42-b8e5-5ce7efc2c11c" = Fruit Lockers
"WTA-25e6e6cd-2330-4004-b0d9-d35ac02428cf" = Magic Gem
"WTA-261d94ed-18b2-4544-a1a3-6399ddec6078" = Crystal Path
"WTA-2736f18a-d43e-4541-bc27-d24e3238ed02" = Amazonia
"WTA-27a5836d-fce6-418a-98f3-9cc2c8c639e4" = Mah Jong Quest
"WTA-281db566-74e7-475e-8dbe-0159358a7288" = Mahjong: Legacy of Toltecs
"WTA-29c1c48c-99bc-4a05-8512-828b32955ead" = Rotate Mania Deluxe
"WTA-2a7bbae0-3a99-46a0-b0a6-50fbcea70bd0" = Super Collapse Puzzle Gallery
"WTA-309107dd-f2c2-4677-9da6-3ad8f87582f6" = Jewels of Cleopatra
"WTA-310461bc-877c-4d10-ae5c-15319d934a16" = Enchanted Cavern 2
"WTA-35e02af7-c0b8-465f-9445-1d65abdf3a33" = Incadia
"WTA-38031e2c-f910-410b-bc00-a7a089d752e3" = Bejeweled 3
"WTA-3e742830-d792-4dee-8314-0558affa1f4b" = Jewel Quest 3
"WTA-3eb8fb24-30c8-44aa-9ac9-266efc47360f" = Crystal Maze
"WTA-3f8107ee-9545-42b2-866c-0cd0dcb155ac" = Luxor HD
"WTA-43cde702-51cc-4c40-b9fd-7f4e4ff89b04" = Super Collapse Puzzle Gallery 3
"WTA-461e9b4e-ae64-4cab-b877-9fb27e22b15d" = Jewel Keepers: Easter Island
"WTA-49c3fefd-af3b-4f2b-b1d0-47930d985f11" = Fishdom
"WTA-49f442a7-c0fb-42a4-8e07-1544cecff2bb" = Chainz 2
"WTA-4d8cfb8f-1691-4a1f-ab5f-fdccd3f3ac14" = Balloon Blast
"WTA-5027c969-8423-42b1-8d3b-f95a76918b9e" = Boogie Bunnies
"WTA-53893139-bea2-4961-8b43-13999f2b0fee" = Luxor Evolved
"WTA-58d265c5-a63d-41a1-87b3-72fc78261fee" = Mahjong Escape Ancient Japan
"WTA-5a10edbb-6c83-4df4-a433-c8e94f22902a" = Magic Lanterns
"WTA-5a80c53e-f214-4e86-b55a-47b033834220" = Jewelleria
"WTA-5bf46b9f-eb37-4b33-b92e-5a07873f9207" = Bejeweled
"WTA-64e4e175-b0bf-43fb-a18a-1688fdef6c73" = Gold Rush Deluxe
"WTA-65669fe3-5396-4003-8aef-561ff0e0aad4" = Hyperballoid: The Next Challenge
"WTA-6629905b-bb84-4120-bf92-5c5a64ed3af1" = Jewel Quest
"WTA-68f72d80-233e-4e05-9c02-695a40e41fa9" = Otto's Magic Blocks
"WTA-69d99f63-24ef-40da-a2b7-cbbd75edb0d4" = Oriental Dreams
"WTA-6bfe1761-c964-4515-8c5a-09a03cdca6fe" = Flip Words
"WTA-6e1911cc-62e6-4309-8195-5af2f25a0a70" = Zulu Gems
"WTA-70baff05-3723-4f35-9d58-ca063f238bfc" = Alchemy Deluxe
"WTA-71e97c79-fc47-40f3-9a27-085976f493bf" = Are You Smarter than a 5th Grader - Make the Grade
"WTA-739dae9c-92e6-449b-a4da-ae2f6775798a" = Collapse Crunch
"WTA-7635140d-363e-4165-87d4-40fd96b7acd0" = Jewel Quest Solitaire 2
"WTA-7a119c39-66d3-4866-824d-9b18e997d04a" = World Mosaics
"WTA-7c8bd2e2-1dff-41ca-a70d-bd494226c283" = Trijinx
"WTA-81e59582-24b0-4e6b-8ce2-0f7313a62f7d" = SpiderMania Solitaire
"WTA-820f27f1-f1bf-4a98-a2ab-935133ebf2bb" = Atlantis Adventure
"WTA-82e71984-6d0b-48a9-99f5-65803960502f" = Paris Mahjong
"WTA-85b53da5-2fb4-4fe3-a7b8-f4aa61aaf5ad" = 3Tones
"WTA-8619c933-e121-4634-b01e-33e18f354e5e" = Drop'Em Deluxe
"WTA-8749c946-e378-4106-8af3-6a47ecb1ecf4" = Tinseltown Dreams - The 50s
"WTA-8ae0dc80-a35b-4e7f-98ae-0bac51fdcbab" = Bookworm Adventures
"WTA-8fb8981a-fd6b-4c02-938c-b41d6025b2cd" = Vesuvia
"WTA-933a0524-aaa5-47f6-91ad-fdd7a2c330de" = Mahjong Garden Deluxe
"WTA-9a17cb67-4421-4d26-afb7-55d208f9c0cd" = Sticky Linky
"WTA-9f144078-27fe-45a2-a317-e55bbd33236d" = ZIMO
"WTA-a57e4c13-7c9b-4174-b00c-042a3a2b5b93" = Jenguu
"WTA-a5ba5ffd-ac21-44c3-bc0b-92e52e26ba1d" = Christmas Wonderland
"WTA-a8c1d6fe-503c-496c-b5d4-5172f16e95ee" = Jungle Quest
"WTA-ace7d8e3-e04d-4c10-a42d-b187d371182b" = Aquacade
"WTA-acf5c2ba-2851-4d70-affa-7b6d42929ffe" = Maui Wowee
"WTA-ad06f53a-9c92-44a1-8063-03bdde84bfc0" = Penguins!
"WTA-adf49387-51ba-4213-b966-10f0932bc954" = Battle Slots
"WTA-b48f489a-42a8-4ba7-9859-ba0506380a59" = Hexus
"WTA-b7a5c8e5-239b-40bd-aa74-4bd6f203d0fc" = Big Kahuna Reef
"WTA-bb0b43e2-0bed-4a0a-9b15-88c22b7a278c" = Rainforest Adventure
"WTA-c754e6fa-59d2-48a2-93e9-46f65d495312" = Jewel of Atlantis
"WTA-cac77155-c7ff-491d-a8c5-8b570eb25f4a" = Fishdom: Seasons Under the Sea
"WTA-cc73bbd7-8cec-4c64-bf9a-b99f3786345f" = Zuma's Revenge
"WTA-ce6b578c-4704-48e0-9307-73bd74945e21" = Jewel Match
"WTA-d36d8140-dd25-4b75-a93f-a630bcec0a8e" = Insaniquarium Deluxe
"WTA-df6522d3-a61d-4bb6-9931-092a50c15f20" = Gem Shop
"WTA-e2e3c28d-d4d1-4951-b202-c4ac8ec4adce" = The Treasures of Montezuma 3
"WTA-f191b3b9-5a96-4fa3-b373-be743eb3a877" = Azteca
"WTA-f73f53bc-1082-44f7-a5a4-2a5eb0046896" = 4 Elements II
"WTA-f7e192b6-1331-4770-9ec7-57fe576665a1" = Blasterball 3
"WTA-fe089046-f8f7-427e-a3b9-03278ce9b3c9" = Puzzle Blast
"XobniMain" = Xobni
"Zuma Deluxe" = Zuma Deluxe
"Zynga Toolbar" = Zynga Toolbar

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{79A765E1-C399-405B-85AF-466F52E918B0}" = Ask Toolbar Updater
"UnityWebPlayer" = Unity Web Player

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 9/29/2012 8:12:33 PM | Computer Name = RichardGMartin | Source = Application Error | ID = 1000
Description = Faulting application name: StickyLinky-WT.exe, version: 3.0.2.32,
time stamp: 0x500ddec9 Faulting module name: StickyLinky-WT.exe, version: 3.0.2.32,
time stamp: 0x500ddec9 Exception code: 0x40000015 Fault offset: 0x000126aa Faulting
process id: 0x13c4 Faulting application start time: 0x01cd9ea049268f17 Faulting application
path: C:\Program Files\WildTangent Games\Games\StickyLinky\StickyLinky-WT.exe Faulting
module path: C:\Program Files\WildTangent Games\Games\StickyLinky\StickyLinky-WT.exe
Report
Id: 8766af48-0a93-11e2-aad1-001e33fcbcc8

Error - 9/30/2012 7:00:01 PM | Computer Name = RichardGMartin | Source = Windows Backup | ID = 4103
Description =

Error - 10/7/2012 7:00:01 PM | Computer Name = RichardGMartin | Source = Windows Backup | ID = 4103
Description =

Error - 10/10/2012 3:01:46 AM | Computer Name = RichardGMartin | Source = Windows Search Service | ID = 3007
Description =

Error - 10/15/2012 10:42:32 AM | Computer Name = RichardGMartin | Source = Windows Backup | ID = 4103
Description =

Error - 10/19/2012 8:58:05 AM | Computer Name = RichardGMartin | Source = Windows Backup | ID = 4103
Description =

Error - 10/22/2012 9:41:55 AM | Computer Name = RichardGMartin | Source = Windows Backup | ID = 4103
Description =

Error - 10/28/2012 7:00:01 PM | Computer Name = RichardGMartin | Source = Windows Backup | ID = 4103
Description =

Error - 11/4/2012 8:00:03 PM | Computer Name = RichardGMartin | Source = Windows Backup | ID = 4103
Description =

Error - 11/11/2012 8:00:02 PM | Computer Name = RichardGMartin | Source = Windows Backup | ID = 4103
Description =

[ Media Center Events ]
Error - 12/7/2010 11:39:42 AM | Computer Name = User-PC | Source = MCUpdate | ID = 0
Description = 10:39:41 AM - Error connecting to the internet. 10:39:42 AM - Unable
to contact server..

Error - 12/7/2010 11:40:19 AM | Computer Name = User-PC | Source = MCUpdate | ID = 0
Description = 10:40:12 AM - Error connecting to the internet. 10:40:12 AM - Unable
to contact server..

Error - 12/7/2010 12:40:52 PM | Computer Name = User-PC | Source = MCUpdate | ID = 0
Description = 11:40:52 AM - Error connecting to the internet. 11:40:52 AM - Unable
to contact server..

Error - 12/7/2010 12:41:25 PM | Computer Name = User-PC | Source = MCUpdate | ID = 0
Description = 11:41:21 AM - Error connecting to the internet. 11:41:21 AM - Unable
to contact server..

Error - 12/9/2010 11:53:01 AM | Computer Name = User-PC | Source = MCUpdate | ID = 0
Description = 10:53:01 AM - Error connecting to the internet. 10:53:01 AM - Unable
to contact server..

Error - 12/9/2010 11:53:37 AM | Computer Name = User-PC | Source = MCUpdate | ID = 0
Description = 10:53:30 AM - Error connecting to the internet. 10:53:30 AM - Unable
to contact server..

Error - 12/11/2010 11:18:30 AM | Computer Name = User-PC | Source = MCUpdate | ID = 0
Description = 10:18:30 AM - Error connecting to the internet. 10:18:30 AM - Unable
to contact server..

Error - 12/11/2010 11:22:06 AM | Computer Name = User-PC | Source = MCUpdate | ID = 0
Description = 10:19:05 AM - Error connecting to the internet. 10:19:05 AM - Unable
to contact server..

Error - 12/22/2010 11:11:16 AM | Computer Name = RichardGMartin | Source = MCUpdate | ID = 0
Description = 10:11:04 AM - Error connecting to the internet. 10:11:04 AM - Unable
to contact server..

Error - 12/22/2010 12:11:53 PM | Computer Name = RichardGMartin | Source = MCUpdate | ID = 0
Description = 11:11:49 AM - Error connecting to the internet. 11:11:49 AM - Unable
to contact server..

[ OSession Events ]
Error - 8/22/2010 2:09:10 PM | Computer Name = User-PC | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.4518.1014, Microsoft Office Version: 12.0.6425.1000. This session lasted 11621
seconds with 120 seconds of active time. This session ended with a crash.

Error - 12/22/2010 11:51:51 PM | Computer Name = RichardGMartin | Source = Microsoft Office 12 Sessions | ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6545.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 18857
seconds with 300 seconds of active time. This session ended with a crash.

[ Spybot - Search and Destroy Events ]
Error - 5/8/2013 3:45:24 PM | Computer Name = RichardGMartin | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions

Error - 5/8/2013 5:14:24 PM | Computer Name = RichardGMartin | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions

[ System Events ]
Error - 5/8/2013 5:13:56 PM | Computer Name = RichardGMartin | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 5/8/2013 5:35:45 PM | Computer Name = RichardGMartin | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 5/8/2013 5:41:10 PM | Computer Name = RichardGMartin | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 5/8/2013 5:41:10 PM | Computer Name = RichardGMartin | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 5/8/2013 5:41:10 PM | Computer Name = RichardGMartin | Source = atikmdag | ID = 43029
Description = Display is not active

Error - 5/8/2013 5:41:27 PM | Computer Name = RichardGMartin | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 5/8/2013 6:31:45 PM | Computer Name = RichardGMartin | Source = Service Control Manager | ID = 7006
Description = The ScRegSetValueExW call failed for FailureActions with the following
error: %%5

Error - 5/8/2013 6:33:49 PM | Computer Name = RichardGMartin | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 5/8/2013 6:33:49 PM | Computer Name = RichardGMartin | Source = atikmdag | ID = 52236
Description = CPLIB :: General - Invalid Parameter

Error - 5/8/2013 6:33:49 PM | Computer Name = RichardGMartin | Source = atikmdag | ID = 43029
Description = Display is not active


< End of report >

Attachments:

Hello OCD I dowloaded ADW Cleaner The program I got is ReImage Repair the scan said I had a problem with C:\Program Files\Search Toolbar\Search Toolbar dll Also System Restore is crashing and other issues It wants me to buy the Software to fix the problems Do I have to purchase this software I didn't get any logs Thanks Marty
Hi MARTY1946,

Please only run the tools requested at this time. Running other tools may just prolong the cleaning process. It is not necessary to purchase any software at this time, the cleaning process can be done with free tools. After we have completed the cleaning process you may choose to purchase a paid subscription to an Anti-Virus & Firewall if you so desire.

Please run these tools in this order.

1. Download AdwCleaner to your desktop.

Right click and select "Run as Administrator".
  • Run AdwCleaner and select Delete
  • Once done it will ask to reboot, allow the reboot
  • On reboot a log will be produced, please attach the content of the log to your next reply

2. [external image: Posted Image] Please download Junkware Removal Tool to your desktop.

Right click and select "Run as Administrator".
  • Shut down your protection software now to avoid potential conflicts.
  • The tool will open and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, a log (JRT.txt) is saved to your desktop and will automatically open.
  • Post the contents of JRT.txt into your next message.
3. Re-run OTL (it should be located on your desktop).

Windows Vista and Windows 7 users Right Click and select "Run as Administrator" on the icon to run it.
  • Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Uncheck the boxes beside LOP Check and Purity Check.
  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open one notepad window. OTL.Txt. (No Extras.txt will be produced)
    Note:The log can be located in the OTL. folder on you C:\ drive if they fail to open automatically.
  • Please copy (Edit->Select All, Edit->Copy) the contents of the file, and post it with your next reply.
In your next post please provide the following:
  • AdwCleaner log
  • JRT log
  • OTL.txt
OCD I am having a bad time now I can;t download anything now When the file is trying to save a series of dots appear in the save file name What do I do now? Thanks Marty
Hi MARTY1946,

When the file is trying to save a series of dots appear in the save file name

Are you unable to name the file you are trying to download?

  • Please describe what the computer will do? (i.e. boot normally, use the Internet, etc)
  • Conversely, describe what the computer will not do. (i.e download files, etc)
  • What tool were you trying to download when the issue occurred?
Hi OCD I used Microsoft Explorer instead of Firefox this time downloads work Sometimes when I start computer it doesn't boot correctly, I get a loud BEEPING sound Start menu doesn't work correctly System Restore does not work I am having trouble with notepad sometimes can't get the log for you when the dots appear The computer is very unstable I don't know what else to tell you Thanks Marty Here is JRT LOG ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Junkware Removal Tool (JRT) by Thisisu Version: 4.9.4 (05.06.2013:1) OS: Windows 7 Home Premium x86 Ran by [removed] on Thu 05/09/2013 at 18:41:42.05 ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~ Services ~~~ Registry Values ~~~ Registry Keys ~~~ Files ~~~ Folders Failed to delete: [Folder] "C:\Program Files\utilitychest_49" ~~~ FireFox Successfully deleted the following from C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\pk9h6b1c.default\prefs.js user_pref("CT2438727.generalConfigFromLogin", "{\"ApiMaxAlerts\":\"12\",\"SocialDomains\":\"social.conduit.com;apps.conduit.com;services.apps.conduit.com\",\"AppsDetectionUrlP user_pref("CommunityToolbar.ETag.hxxp://Settings.toolbar.search.conduit.com/root/CT2438727/CT2438727", "\"0ee0e3a593d53037fbc0815ad2520b2e3\""); user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1248439/1244112/US", "\"0\""); user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/1249594/1245267/US", "\"0\""); user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/832836/828639/US", "\"0\""); user_pref("CommunityToolbar.ETag.hxxp://alerts.conduit-services.com/root/909619/905414/US", "\"0\""); user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2438727", "\"0\""); user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2856415", "\"0\""); user_pref("CommunityToolbar.ETag.hxxp://appsmetadata.toolbar.conduit-services.com/?ctid=CT2857572", "\"0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.alert.conduit-services.com/alert/dlg.pkg", "\"8076e3ce381dcd1:0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.10.0.1", "\"4ead38b3e6bcd1:1308\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12.0.7", "\"4ead38b3e6bcd1:0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.12.2.3", "\"4ead38b3e6bcd1:0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.13.0.6", "\"0d648794549cd1:14f1\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.14.1.0", "\"0e0a4327275cd1:0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.15.1.0", "\"0343677cfb1cd1:0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.18.0.7", "\"0343677cfb1cd1:0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.3.2", "\"07b2625f8cb1:0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.3.5.1", "\"07b2625f8cb1:0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.5.0.12", "\"8028f138140cc1:0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.6.0.10", "\"0ee90707f77cc1:0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.7.0.6", "\"6a637346d78ccc1:0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.0.8", "\"6a637346d78ccc1:0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.8.1.0", "\"6a637346d78ccc1:0\""); user_pref("CommunityToolbar.ETag.hxxp://dynamicdialogs.toolbar.conduit-services.com/DLG.pkg?ver=3.9.0.3", "\"801a319dd78ccc1:12e4\""); user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/Toolbar/?ownerId=CT2438727", "\"6341c50648fd59897cde84cfa3927631\""); user_pref("CommunityToolbar.ETag.hxxp://servicemap.conduit-services.com/toolbar/", "\"634289840782570000\""); user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.conduit-services.com/?ctid=CT2438727&octid=CT2438727", "\"1322100586\""); user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2438727/CT2438727", "\"1311168869\""); user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2856415/CT2856415", "\"1294239661\""); user_pref("CommunityToolbar.ETag.hxxp://settings.toolbar.search.conduit.com/root/CT2857572/CT2857572", "\"1294239661\""); user_pref("CommunityToolbar.ETag.hxxp://storage.conduit.com/27/243/CT2438727/Images/Blank.png", "\"27f9ceb6f365cb1:0\""); user_pref("CommunityToolbar.ETag.hxxp://translation.toolbar.conduit-services.com/?locale=en", "\"316213d3b588e4de88a5d40f981ece1d\""); user_pref("CommunityToolbar.LatestLibsPath", "file:///C:\\Users\\User\\AppData\\Roaming\\Mozilla\\Firefox\\Profiles\\pk9h6b1c.default\\conduitCommon\\modules\\3.15.1.0"); Emptied folder: C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\pk9h6b1c.default\minidumps [1 files] ~~~ Event Viewer Logs were cleared ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Scan was completed on Thu 05/09/2013 at 18:45:33.51 End of JRT log ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Hi MARTY1946,

Thanks for the explanation. :thumbup:

Start menu doesn't work correctly

Can you explain in more detail what you mean by this statement?

= = = = = = = = = = = = = = = = = = = =

Please download Farbar Service Scanner and save it to your desktop.
  • Right click and select "Run as Administrator"
  • Make sure the following options are checked:
    • Internet Services
    • Windows Firewall
    • System Restore
    • Security Center
    • Windows Update
    • Windows Defender
  • Press "Scan".
  • It will create a log (FSS.txt) in the same directory the tool is run.
  • Please copy and paste the log to your reply.
- - - - - Next - - - - -

Re-run OTL as outlined in my previous post, and post a fresh log.

In your next post please provide the following:
  • FSS.txt
  • OTL.txt
OCD
Here are the logs you asked for
Thanks, Marty

Farbar Service Scanner Version: 14-04-2013
Ran by [removed] (administrator) on 09-05-2013 at 19:48:23
Running from "C:\Users\User\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\OXIF8KC5"
Windows 7 Home Premium Service Pack 1 (X86)
Boot Mode: Normal
****************************************************************

Internet Services:
============

Connection Status:
==============
Localhost is accessible.
LAN connected.
Google IP is accessible.
Google.com is accessible.
Attempt to access Yahoo IP returned error. Yahoo IP is offline
Yahoo.com is accessible.


Windows Firewall:
=============

Firewall Disabled Policy:
==================


System Restore:
============

System Restore Disabled Policy:
========================


Action Center:
============

Windows Update:
============

Windows Autoupdate Disabled Policy:
============================


Windows Defender:
==============
WinDefend Service is not running. Checking service configuration:
The start type of WinDefend service is set to Demand. The default start type is Auto.
The ImagePath of WinDefend service is OK.
The ServiceDll of WinDefend service is OK.


Windows Defender Disabled Policy:
==========================
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender]
"DisableAntiSpyware"=DWORD:1


Other Services:
==============


File Check:
========
C:\windows\system32\nsisvc.dll => MD5 is legit
C:\windows\system32\Drivers\nsiproxy.sys => MD5 is legit
C:\windows\system32\dhcpcore.dll => MD5 is legit
C:\windows\system32\Drivers\afd.sys => MD5 is legit
C:\windows\system32\Drivers\tdx.sys => MD5 is legit
C:\windows\system32\Drivers\tcpip.sys => MD5 is legit
C:\windows\system32\dnsrslvr.dll => MD5 is legit
C:\windows\system32\mpssvc.dll => MD5 is legit
C:\windows\system32\bfe.dll => MD5 is legit
C:\windows\system32\Drivers\mpsdrv.sys => MD5 is legit
C:\windows\system32\SDRSVC.dll => MD5 is legit
C:\windows\system32\vssvc.exe => MD5 is legit
C:\windows\system32\wscsvc.dll => MD5 is legit
C:\windows\system32\wbem\WMIsvc.dll => MD5 is legit
C:\windows\system32\wuaueng.dll => MD5 is legit
C:\windows\system32\qmgr.dll => MD5 is legit
C:\windows\system32\es.dll => MD5 is legit
C:\windows\system32\cryptsvc.dll => MD5 is legit
C:\Program Files\Windows Defender\MpSvc.dll => MD5 is legit
C:\windows\system32\svchost.exe => MD5 is legit
C:\windows\system32\rpcss.dll => MD5 is legit


**** End of log ****

OTL logfile created on: 5/9/2013 7:18:42 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\User\Downloads
Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16540)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.75 Gb Total Physical Memory | 1.44 Gb Available Physical Memory | 52.39% Memory free
5.49 Gb Paging File | 3.64 Gb Available in Paging File | 66.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files
Drive C: | 288.71 Gb Total Space | 234.88 Gb Free Space | 81.35% Space Free | Partition Type: NTFS

Computer Name: RICHARDGMARTIN | User Name: User | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\User\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\UtilityChest_49\bar\1.bin\49barsvc.exe (COMPANYVERS_NAME)
PRC - C:\Windows\System32\MsSpellCheckingFacility.exe (Microsoft Corporation)
PRC - C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\AVG\AVG2013\avgnsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Real\RealPlayer\Update\realsched.exe (RealNetworks, Inc.)
PRC - C:\Program Files\AVG\AVG2013\avgrsx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe ()
PRC - C:\Windows\System32\Macromed\Flash\FlashUtil32_11_6_602_180_ActiveX.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\RealNetworks\RealDownloader\recordingmanager.exe (RealNetworks, Inc.)
PRC - C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
PRC - C:\Program Files\AVG\AVG2013\avgcsrvx.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files\Google\Google Toolbar\GoogleToolbarUser_32.exe (Google Inc.)
PRC - C:\Windows\System32\taskhost.exe (Microsoft Corporation)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdate.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
PRC - C:\Program Files\SecureBackupShare\ComcastSecureBackupSharestat.exe (Secure Backup and Share)
PRC - C:\Windows\explorer.exe (Microsoft Corporation)
PRC - C:\Program Files\SecureBackupShare\ComcastSecureBackupSharebackup.exe (Secure Backup and Share)
PRC - C:\Program Files\Discover\SOAN\DiscoverSOAN.exe (Orbiscom Ltd. All rights reserved.)
PRC - C:\Windows\System32\OBroker.exe (Orbiscom Ltd.)
PRC - C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe ()
PRC - C:\Program Files\ARX\ARX CryptoKit\utils\ARcltsrv.exe (Algorithmic Research Ltd.)
PRC - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TECO\TEco.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe (TOSHIBA CORPORATION)
PRC - C:\Program Files\TOSHIBA\TPHM\TPCHWMsg.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSENotify.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
PRC - C:\Windows\System32\atieclxx.exe (AMD)
PRC - C:\Windows\System32\atiesrxx.exe (AMD)
PRC - C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
PRC - C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)


========== Modules (No Company Name) ==========

MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\XobniStatistics\7b10f464b28d133a5ed3a417b4dbbfe6\XobniStatistics.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\XobniFeeds\440dcdab9e30030678f807e559dd48c6\XobniFeeds.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Xobni.XMapiAccessor\e7ca9a7adb751b9980257293731b710e\Xobni.XMapiAccessor.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\XobniGadgets\ec980e4092ebca8d12057cddcbdb0e54\XobniGadgets.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\XobniPluginAPI\35a6a04833fb8bb1aebff40432b49f1b\XobniPluginAPI.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\XobniCommon\88db8d27a69e411db497b4b1c6563438\XobniCommon.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web.Services\64cf6c356be66bb17c4667d6d8aa467b\System.Web.Services.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\5ecf01964c70e453d71e5d7653912ff9\System.Web.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\cb562e2e4f74ae607f1186f6ec50cec7\System.Windows.Forms.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Microsoft.Office.In#\6f62c9035248cbba2dae864b3a39636d\Microsoft.Office.Interop.Outlook.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\stdole\e48a55170d389688bb93808fdfebf8f7\stdole.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\office\212651f618176161df02f2483d004843\office.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Antlr3.Runtime\25f1ec4ec1c24503db6d29427e967537\Antlr3.Runtime.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\XobniResources\6314b5bd70644992ba08235bfd31c006\XobniResources.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data.SQLite\e83a0f67b05bfc2b76d16faa08fc4cf4\System.Data.SQLite.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Interop.shdocvw\3ad1d64d639f730acc378f623ffdadb1\Interop.shdocvw.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\LinqBridge\2cb2f04ae448cd918ecc979a39c380e7\LinqBridge.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\XobniDataTransfer\70e04da165c0fb94e768a889113260d8\XobniDataTransfer.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\Newtonsoft.Json.Net#\6498a0a7f2597e15d9d53bc7b9be10ab\Newtonsoft.Json.Net20.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Management\302207b4fa3083899fd8ab4db98cecc5\System.Management.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\CustomMarshalers\5baea82888a13fa558004b24e3b107cf\CustomMarshalers.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\90b89f6e8032310e9ac72a309fd49e83\System.Runtime.Remoting.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.EnterpriseSe#\01c6cb58745f397c9b7ccf3ab7bfc9cd\System.EnterpriseServices.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Transactions\536d704e93ffec9b54e4a0312fb5b996\System.Transactions.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\dd20416f723ee13ffb4173ec1afc4ec4\System.Data.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\eead6629e384a5b69f9ae35284b7eeed\System.Drawing.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\f687c43e9fdec031988b33ae722c4613\System.Xml.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\195a77fcc6206f8bb35d419ff2cf0d72\System.Configuration.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\System\369f8bdca364e2b4936d18dea582912c\System.ni.dll ()
MOD - C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\7150b9136fad5b79e88f6c7f9d3d2c39\mscorlib.ni.dll ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\VirtualTreesDXE150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\JSDialogPack150.bpl ()
MOD - C:\Program Files\Spybot - Search & Destroy 2\DEC150.bpl ()
MOD - C:\Program Files\Common Files\microsoft shared\OFFICE12\MSPTLS.DLL ()
MOD - C:\Program Files\Microsoft Office\Office12\ADDINS\UmOutlookAddin.dll ()
MOD - C:\windows\assembly\GAC_32\System.Data.SQLite\1.0.66.0__db937bc2d44ff139\System.Data.SQLite.dll ()
MOD - C:\windows\assembly\GAC_32\Xobni.XMapiAccessor\2.0.1.13496__6298d2d1fcfb5d85\Xobni.XMapiAccessor.dll ()
MOD - C:\windows\assembly\GAC_32\ServerSync\2.0.1.13496__6298d2d1fcfb5d85\ServerSync.dll ()
MOD - C:\windows\assembly\GAC_32\Utilities\2.0.1.13496__6298d2d1fcfb5d85\Utilities.dll ()
MOD - C:\windows\assembly\GAC_MSIL\Extensibility\7.0.3300.0__6298d2d1fcfb5d85\Extensibility.dll ()
MOD - C:\Program Files\Xobni\XobniMainConnector.dll ()
MOD - C:\Program Files\Xobni\XobniFailsafeUpdateChecker.dll ()
MOD - C:\Program Files\Xobni\ManagedAggregator.dll ()
MOD - C:\Program Files\Xobni\WindowDriver.dll ()
MOD - C:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll ()
MOD - C:\windows\assembly\GAC_32\CustomMarshalers\2.0.0.0__b03f5f7f11d50a3a\CustomMarshalers.dll ()
MOD - C:\Program Files\ARX\ARX CoSign Client\cosign.dll ()
MOD - C:\Program Files\Discover\SOAN\DiscoverSOAN.dll ()
MOD - C:\Program Files\Toshiba Online Backup\Toast.dll ()
MOD - C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe ()
MOD - C:\Program Files\Toshiba Online Backup\SdbShared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager.Graphics.Wizard\2.0.3497.38831__90ba9c70f846762e\CLI.Aspect.DisplaysManager.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysManager2.Graphics.Dashboard\2.0.3497.38923__90ba9c70f846762e\CLI.Aspect.DisplaysManager2.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Dashboard\2.0.3497.38856__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Dashboard\2.0.3497.38833__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Wizard\2.0.3497.38899__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Wizard\2.0.3497.38875__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Dashboard\2.0.3497.38855__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime\2.0.3497.38814__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Dashboard\2.0.3497.38868__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Dashboard\2.0.3497.38862__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Wizard\2.0.3497.38837__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Wizard\2.0.3497.38833__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.InfoCentre.Graphics.Dashboard\2.0.3497.38833__90ba9c70f846762e\CLI.Aspect.InfoCentre.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard\2.0.3497.38898__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Wizard\2.0.3497.38868__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Dashboard\2.0.3497.38861__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Runtime\2.0.3497.38856__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Runtime\2.0.3497.38880__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard\2.0.3497.38822__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Runtime\2.0.3497.38863__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Runtime\2.0.3497.38867__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Runtime\2.0.3497.38855__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Welcome.Graphics.Dashboard\2.0.3497.38899__90ba9c70f846762e\CLI.Aspect.Welcome.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime\2.0.3497.38898__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard\2.0.3497.38828__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Runtime\2.0.3497.38837__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Runtime\2.0.3497.38860__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Runtime\2.0.3497.38855__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Runtime\2.0.3497.38862__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Runtime\2.0.3497.38823__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CrossDisplay.Graphics.Dashboard\1.0.0.0__90ba9c70f846762e\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Implementation\2.0.3497.38894__90ba9c70f846762e\MOM.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Shared\2.0.3428.28305__90ba9c70f846762e\CLI.Caste.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation\2.0.3428.28298__90ba9c70f846762e\CLI.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceTV.Graphics.Shared\2.0.3428.28316__90ba9c70f846762e\CLI.Aspect.DeviceTV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.Radeon3D.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.Radeon3D.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.MMVideo.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.MMVideo.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceDFP.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DeviceDFP.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0601\2.0.2573.17685__90ba9c70f846762e\DEM.Graphics.I0601.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Source.Kit.Server\2.0.3497.38904__90ba9c70f846762e\AEM.Plugin.Source.Kit.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.TransCode.Graphics.Shared\2.0.3428.28324__90ba9c70f846762e\CLI.Aspect.TransCode.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCV.Graphics.Shared\2.0.3428.28315__90ba9c70f846762e\CLI.Aspect.DeviceCV.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceCRT.Graphics.Runtime\2.0.3497.38856__90ba9c70f846762e\CLI.Aspect.DeviceCRT.Graphics.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation\2.0.3428.28296__90ba9c70f846762e\LOG.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceProperty.Graphics.Shared\2.0.3428.28309__90ba9c70f846762e\CLI.Aspect.DeviceProperty.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\NEWAEM.Foundation\2.0.3428.28297__90ba9c70f846762e\NEWAEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.XManifest\2.0.3428.28354__90ba9c70f846762e\CLI.Foundation.XManifest.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.PowerPlayDPPE.Graphics.Shared\2.0.3428.28323__90ba9c70f846762e\CLI.Aspect.PowerPlayDPPE.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysColour2.Graphics.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Aspect.DisplaysColour2.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DeviceLCD.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.DeviceLCD.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.CustomFormats.Graphics.Shared\2.0.3428.28311__90ba9c70f846762e\CLI.Aspect.CustomFormats.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared\2.0.3428.28304__90ba9c70f846762e\CLI.Component.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.DisplaysOptions.Graphics.Shared\2.0.3428.28314__90ba9c70f846762e\CLI.Aspect.DisplaysOptions.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ResourceManagement.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\ResourceManagement.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared\2.0.3428.28302__90ba9c70f846762e\CLI.Component.Client.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Aspect.HotkeysHandling.Graphics.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Aspect.HotkeysHandling.Graphics.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Foundation\2.0.3428.28310__90ba9c70f846762e\APM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.Hotkeys.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Plugin.Hotkeys.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Actions.CCAA.Shared\2.0.3428.28302__90ba9c70f846762e\AEM.Actions.CCAA.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\MOM.Foundation\2.0.3428.28310__90ba9c70f846762e\MOM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics.I0706\2.0.2743.23304__90ba9c70f846762e\DEM.Graphics.I0706.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Graphics\2.0.3428.28324__90ba9c70f846762e\DEM.Graphics.dll ()
MOD - C:\windows\assembly\GAC_MSIL\DEM.Foundation\2.0.2573.17684__90ba9c70f846762e\DEM.Foundation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared\2.0.3428.28303__90ba9c70f846762e\CLI.Component.Runtime.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Wizard.Shared\2.0.3428.28313__90ba9c70f846762e\CLI.Caste.Graphics.Wizard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Dashboard.Shared\2.0.3428.28312__90ba9c70f846762e\CLI.Caste.Graphics.Dashboard.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server.Shared\2.0.3428.28304__90ba9c70f846762e\AEM.Server.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.WinMessages.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.WinMessages.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.REG.Shared\2.0.3428.28329__90ba9c70f846762e\AEM.Plugin.REG.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.GD.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.GD.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.EEU.Shared\2.0.3428.28311__90ba9c70f846762e\AEM.Plugin.EEU.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Plugin.DPPE.Shared\2.0.3428.28327__90ba9c70f846762e\AEM.Plugin.DPPE.Shared.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Extension.EEU\2.0.3497.38810__90ba9c70f846762e\CLI.Component.Runtime.Extension.EEU.dll ()
MOD - C:\windows\assembly\GAC_MSIL\atixclib\1.0.0.0__90ba9c70f846762e\atixclib.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard\2.0.3497.38819__90ba9c70f846762e\CLI.Component.Dashboard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard\2.0.3497.38827__90ba9c70f846762e\CLI.Component.Wizard.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation\2.0.3497.38892__90ba9c70f846762e\LOG.Foundation.Implementation.dll ()
MOD - C:\windows\assembly\GAC_MSIL\APM.Server\2.0.3497.38811__90ba9c70f846762e\APM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.SkinFactory\2.0.3497.38813__90ba9c70f846762e\CLI.Component.SkinFactory.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime\2.0.3497.38812__90ba9c70f846762e\CLI.Component.Runtime.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Runtime.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\AEM.Server\2.0.3497.38810__90ba9c70f846762e\AEM.Server.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Foundation.Private\2.0.3428.28301__90ba9c70f846762e\CLI.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Client.Shared.Private\2.0.3428.28308__90ba9c70f846762e\CLI.Component.Client.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Private\2.0.3428.28303__90ba9c70f846762e\LOG.Foundation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\ATICCCom\2.0.0.0__90ba9c70f846762e\ATICCCom.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Wizard.Shared.Private\2.0.3428.28311__90ba9c70f846762e\CLI.Component.Wizard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\LOG.Foundation.Implementation.Private\2.0.3428.28310__90ba9c70f846762e\LOG.Foundation.Implementation.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Component.Dashboard.Shared.Private\2.0.3428.28309__90ba9c70f846762e\CLI.Component.Dashboard.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CLI.Caste.Graphics.Runtime.Shared.Private\2.0.3428.28316__90ba9c70f846762e\CLI.Caste.Graphics.Runtime.Shared.Private.dll ()
MOD - C:\windows\assembly\GAC_MSIL\CCC.Implementation\2.0.3497.38893__90ba9c70f846762e\CCC.Implementation.dll ()
MOD - C:\windows\assembly\GAC\Microsoft.mshtml\7.0.3300.0__b03f5f7f11d50a3a\Microsoft.mshtml.dll ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosIPCWraper.dll ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA Disc Creator\NotifyTDC.dll ()
MOD - C:\Program Files\TOSHIBA\FlashCards\Hotkey\FnZ.dll ()
MOD - C:\Program Files\TOSHIBA\FlashCards\BlackPng.dll ()
MOD - C:\Program Files\TOSHIBA\TOSHIBA Assist\NotifyX.dll ()
MOD - C:\windows\assembly\GAC_32\System.Transactions\2.0.0.0__b77a5c561934e089\System.Transactions.dll ()
MOD - C:\Program Files\ATI Technologies\ATI.ACE\Branding\Branding.dll ()
MOD - C:\Program Files\TOSHIBA\PCDiag\NotifyPCD.dll ()
MOD - C:\Program Files\Microsoft Office\Office12\ADDINS\ColleagueImport.dll ()


========== Services (SafeList) ==========

SRV - (SDWSCService) – C:\Program Files\Spybot File not found
SRV - (SDUpdateService) – C:\Program Files\Spybot File not found
SRV - (SDScannerService) – C:\Program Files\Spybot File not found
SRV - (UtilityChest_49Service) – C:\Program Files\UtilityChest_49\bar\1.bin\49barsvc.exe (COMPANYVERS_NAME)
SRV - (AVGIDSAgent) – C:\Program Files\AVG\AVG2013\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files\AVG\AVG2013\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (MozillaMaintenance) – C:\Program Files\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (vToolbarUpdater15.0.0) – C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe ()
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (RealNetworks Downloader Resolver Service) – C:\Program Files\RealNetworks\RealDownloader\rndlresolversvc.exe ()
SRV - (AdobeARMservice) – C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (AVG Security Toolbar Service) – C:\Program Files\AVG\AVG10\Toolbar\ToolbarBroker.exe ()
SRV - (XobniService) – C:\Program Files\Xobni\XobniService.exe (Xobni Corporation)
SRV - (GamesAppService) – C:\Program Files\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (WatAdminSvc) – C:\Windows\System32\Wat\WatAdminSvc.exe (Microsoft Corporation)
SRV - (ComcastSecureBackupSharebackup) – C:\Program Files\SecureBackupShare\ComcastSecureBackupSharebackup.exe (Secure Backup and Share)
SRV - (Autodesk Licensing Service) – C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe (Autodesk)
SRV - (ARcltsrv) – C:\Program Files\ARX\ARX CryptoKit\utils\ARcltsrv.exe (Algorithmic Research Ltd.)
SRV - (TosCoSrv) – C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe (TOSHIBA Corporation)
SRV - (TMachInfo) – C:\Program Files\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe (TOSHIBA Corporation)
SRV - (TOSHIBA eco Utility Service) – C:\Program Files\TOSHIBA\TECO\TecoService.exe (TOSHIBA Corporation)
SRV - (cfWiMAXService) – C:\Program Files\TOSHIBA\ConfigFree\CFIWmxSvcs.exe (TOSHIBA CORPORATION)
SRV - (TPCHSrv) – C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe (TOSHIBA Corporation)
SRV - (TOSHIBA HDD SSD Alert Service) – C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe (TOSHIBA Corporation)
SRV - (AMD External Events Utility) – C:\Windows\System32\atiesrxx.exe (AMD)
SRV - (TODDSrv) – C:\Windows\System32\TODDSrv.exe (TOSHIBA Corporation)
SRV - (SensrSvc) – C:\Windows\System32\sensrsvc.dll (Microsoft Corporation)
SRV - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (ConfigFree Service) – C:\Program Files\TOSHIBA\ConfigFree\CFSvcs.exe (TOSHIBA CORPORATION)


========== Driver Services (SafeList) ==========

DRV - (USBCCID) – system32\DRIVERS\RtsUCcid.sys File not found
DRV - (RtsUIR) – system32\DRIVERS\Rts516xIR.sys File not found
DRV - (RSUSBSTOR) – System32\Drivers\RtsUStor.sys File not found
DRV - (cpuz134) – C:\Users\User\AppData\Local\Temp\cpuz134\cpuz134_x32.sys File not found
DRV - (AVGIDSDriver) – C:\Windows\System32\drivers\avgidsdriverx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgtdix) – C:\Windows\System32\drivers\avgtdix.sys (AVG Technologies CZ, s.r.o.)
DRV - (avgtp) – C:\Windows\System32\drivers\avgtpx86.sys (AVG Technologies)
DRV - (AVGIDSShim) – C:\Windows\System32\drivers\avgidsshimx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgmfx86) – C:\Windows\System32\drivers\avgmfx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avglogx) – C:\Windows\System32\drivers\avglogx.sys (AVG Technologies CZ, s.r.o.)
DRV - (AVGIDSHX) – C:\Windows\System32\drivers\avgidshx.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgldx86) – C:\Windows\System32\drivers\avgldx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (Avgrkx86) – C:\Windows\System32\drivers\avgrkx86.sys (AVG Technologies CZ, s.r.o.)
DRV - (ComcastSecureBackupShareFilter) – C:\Windows\System32\drivers\ComcastSecureBackupShare.sys (Mozy, Inc.)
DRV - (TsUsbFlt) – C:\Windows\System32\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV - (winusb) – C:\Windows\System32\drivers\winusb.sys (Microsoft Corporation)
DRV - (rtl8192se) – C:\Windows\System32\drivers\rtl8192se.sys (Realtek Semiconductor Corporation )
DRV - (tdcmdpst) – C:\Windows\System32\drivers\tdcmdpst.sys (TOSHIBA Corporation.)
DRV - (atikmdag) – C:\Windows\System32\drivers\atikmdag.sys (ATI Technologies Inc.)
DRV - (tos_sps32) – C:\Windows\System32\drivers\tos_sps32.sys (TOSHIBA Corporation)
DRV - (TVALZ) – C:\Windows\System32\drivers\TVALZ_O.SYS (TOSHIBA Corporation)
DRV - (vwifimp) – C:\Windows\System32\drivers\vwifimp.sys (Microsoft Corporation)
DRV - (AgereSoftModem) – C:\Windows\System32\drivers\AGRSM.sys (LSI Corp)
DRV - (athr) – C:\Windows\System32\drivers\athr.sys (Atheros Communications, Inc.)
DRV - (FwLnk) – C:\Windows\System32\drivers\FwLnk.sys (TOSHIBA Corporation)
DRV - (PGEffect) – C:\Windows\System32\drivers\PGEffect.sys (TOSHIBA Corporation)
DRV - (TVALZFL) – C:\Windows\System32\drivers\TVALZFL.sys (TOSHIBA Corporation)
DRV - (dc3d) – C:\Windows\System32\drivers\dc3d.sys (Microsoft Corporation)
DRV - (Point32) – C:\Windows\System32\drivers\point32k.sys (Microsoft Corporation)
DRV - (AtiPcie) – C:\Windows\System32\drivers\AtiPcie.sys (Advanced Micro Devices Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0EF3D5EE-B833-43EC-8265-E0B5C71D50AB}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7TSNA

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.com/ig/redirectdomain?br…A&bmod=TSNA
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Restore = http://www.comcast.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\URLSearchHook: {7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a} - No CLSID value found
IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{0EF3D5EE-B833-43EC-8265-E0B5C71D50AB}: "URL" = http://www.google.com/search?sourceid=ie7&…1I7TSNA_enUS360
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

========== FireFox ==========

FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..extensions.enabledAddons: %7B3e0e7d2a-070f-4a47-b019-91fe5385ba79%7D:3.5.9
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:20.0.1
FF - prefs.js..extensions.enabledItems: {3f963a5b-e555-4543-90e2-c3908898db71}:9.0.0.872
FF - prefs.js..extensions.enabledItems: avg@igeared:6.103.018.001
FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA}:6.0.22
FF - prefs.js..extensions.enabledItems: [removed]:1.2
FF - prefs.js..extensions.enabledItems: discoversoan@orbiscom:[removed]
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: [removed]:1.0.0
FF - prefs.js..extensions.enabledItems: {3e0e7d2a-070f-4a47-b019-91fe5385ba79}:3.1.1
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - user.js - File not found

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\system32\Macromed\Flash\NPSWF32_11_6_602_180.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=14.0.8081.0709: C:\Program Files\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@MyOwnSuperhero.com/Plugin: C:\Program Files\MyOwnSuperhero\bar\2.bin\NPv3Stub.dll (MyOwnSuperhero)
FF - HKLM\Software\MozillaPlugins\@real.com/nppl3260;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nppl3260.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlchromebrowserrecordext;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlchromebrowserrecordext.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlhtml5videoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlhtml5videoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprndlpepperflashvideoshim;version=1.3.1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\MozillaPlugins\nprndlpepperflashvideoshim.dll (RealNetworks, Inc.)
FF - HKLM\Software\MozillaPlugins\@real.com/nprpplugin;version=16.0.1.18: c:\program files\real\realplayer\Netscape6\nprpplugin.dll (RealPlayer)
FF - HKLM\Software\MozillaPlugins\@realnetworks.com/npdlplugin;version=1: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\npdlplugin.dll (RealDownloader)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@UtilityChest_49.com/Plugin: C:\Program Files\UtilityChest_49\bar\1.bin\NP49Stub.dll File not found
FF - HKLM\Software\MozillaPlugins\@veetle.com/vbp;version=0.9.17: C:\Program Files\Veetle\VLCBroadcast\npvbp.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetleCorePlugin,version=0.9.17: C:\Program Files\Veetle\plugins\npVeetle.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@veetle.com/veetlePlayerPlugin,version=0.9.17: C:\Program Files\Veetle\Player\npvlc.dll (Veetle Inc)
FF - HKLM\Software\MozillaPlugins\@Webfetti.com/Plugin: C:\Program Files\Webfetti\bar\2.bin\NP7dStub.dll (Webfetti)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files\WildTangent Games\App\BrowserIntegration\Registered\14\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\User\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\Webfetti\bar\2.bin [2011/08/18 12:29:58 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[removed]: C:\Program Files\MyOwnSuperhero\bar\2.bin [2011/08/17 09:32:31 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\discoversoan@orbiscom: C:\Program Files\Discover\SOAN [2010/12/24 13:53:17 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{ABDE892B-13A8-4d1b-88E6-365A6E755758}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext [2013/03/31 08:50:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{DAC3F861-B30D-40dd-9166-F4E75327FAC7}: C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\Firefox\Ext\ [2013/03/31 08:50:21 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/04/12 16:50:58 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/09 15:54:13 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Components: C:\Program Files\Mozilla Firefox\components [2013/04/12 16:50:58 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 20.0.1\extensions\\Plugins: C:\Program Files\Mozilla Firefox\plugins [2013/05/09 15:54:13 | 000,000,000 | —D | M]

[2010/01/31 03:42:40 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\mozilla\Extensions
[2013/05/09 15:55:36 | 000,000,000 | —D | M] (No name found) – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\pk9h6b1c.default\extensions
[2012/08/31 23:24:30 | 000,000,000 | —D | M] (AddThis) – C:\Users\User\AppData\Roaming\mozilla\Firefox\Profiles\pk9h6b1c.default\extensions\{3e0e7d2a-070f-4a47-b019-91fe5385ba79}
[2010/12/03 16:35:37 | 000,010,039 | —- | M] () – C:\Users\User\AppData\Roaming\mozilla\firefox\profiles\pk9h6b1c.default\searchplugins\Webfetti.xml
[2013/04/12 16:50:48 | 000,000,000 | —D | M] (No name found) – C:\Program Files\Mozilla Firefox\extensions
[2013/04/12 16:50:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2013/04/12 16:50:48 | 000,000,000 | —D | M] (Java Console) – C:\Program Files\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013/04/12 16:50:58 | 000,263,064 | —- | M] (Mozilla Foundation) – C:\Program Files\mozilla firefox\components\browsercomps.dll
[2012/12/26 09:51:03 | 000,466,944 | —- | M] (Catalina Marketing Corporation) – C:\Program Files\mozilla firefox\plugins\NPcol400.dll
[2013/03/31 08:49:17 | 000,124,504 | —- | M] (RealPlayer) – C:\Program Files\mozilla firefox\plugins\nprpplugin.dll
[2012/10/21 16:43:46 | 000,002,465 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\bing.xml
[2013/02/27 19:53:32 | 000,002,086 | —- | M] () – C:\Program Files\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\hnhgoncokajlafhnhjmccgcmgggiehjm\
CHR - Extension: No name found = C:\Users\User\AppData\Local\Google\Chrome\User Data\Default\Extensions\jfmjfhklogoienhpfnppmbcbjfjnkonk\1.3_0\

O1 HOSTS File: ([2011/12/22 16:11:00 | 000,000,833 | —- | M]) - C:\Windows\System32\drivers\etc\hosts
O2 - BHO: (RealNetworks Download and Record Plugin for Internet Explorer) - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\ProgramData\RealNetworks\RealDownloader\BrowserPlugins\IE\rndlbrowserrecordplugin.dll (RealDownloader)
O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
O2 - BHO: (Secure Online Account Numbers Helper) - {435EAA86-D32B-484F-869C-53745FCB1642} - C:\Program Files\Discover\SOAN\DiscoverSOANHelper.dll (Orbiscom Ltd. All rights reserved.)
O2 - BHO: (Spybot-S&D IE Protection) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll File not found
O3 - HKLM\..\Toolbar: (Secure Online Account Numbers) - {A8C7C2CA-6DFD-4E16-8458-592361564D38} - C:\Program Files\Discover\SOAN\DiscoverSOANToolbar.dll (Orbiscom Ltd. All rights reserved.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Utility Chest) - {cf67755f-9265-449c-87cf-b945519e073b} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll File not found
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [00TCrdMain] C:\Program Files\TOSHIBA\FlashCards\TCrdMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [AVG_UI] C:\Program Files\AVG\AVG2013\avgui.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [SDTray] C:\Program Files\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [Secure Online Account Numbers] C:\Program Files\Discover\SOAN\DiscoverSOAN.exe (Orbiscom Ltd. All rights reserved.)
O4 - HKLM..\Run: [SmartFaceVWatcher] C:\Program Files\TOSHIBA\SmartFaceV\SmartFaceVWatcher.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [SmoothView] C:\Program Files\TOSHIBA\SmoothView\SmoothView.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Teco] C:\Program Files\TOSHIBA\TECO\Teco.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TkBellExe] c:\program files\real\realplayer\Update\realsched.exe (RealNetworks, Inc.)
O4 - HKLM..\Run: [Toshiba Online Backup] C:\Program Files\Toshiba Online Backup\ToshibaOnlineBackup.exe ()
O4 - HKLM..\Run: [TosSENotify] C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TosWaitSrv] C:\Program Files\TOSHIBA\TPHM\TosWaitSrv.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TPwrMain] C:\Program Files\TOSHIBA\Power Saver\TPwrMain.exe (TOSHIBA Corporation)
O4 - HKLM..\Run: [TWebCamera] C:\Program Files\TOSHIBA\TOSHIBA Web Camera Application\TWebCamera.exe (TOSHIBA CORPORATION.)
O4 - HKCU..\Run: [MyTOSHIBA] C:\Program Files\TOSHIBA\My Toshiba\MyToshiba.exe (TOSHIBA)
O4 - HKCU..\Run: [Spybot-S&D Cleaning] C:\Program Files\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\windows\System32\GPhotos.scr (Google Inc.)
O9 - Extra 'Tools' menuitem : Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\Program Files\Spybot - Search & Destroy 2\SDHelper.dll (Safer-Networking Ltd.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 10.21.2)
O16 - DPF: {CAFEEFAC-0014-0002-0004-ABCDEFFEDCBA} http://java.sun.com/update/1.4.2/jinstall-…indows-i586.cab (Java Plug-in 1.4.2_04)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 75.75.76.76 75.75.75.75
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ABBFB7FF-852E-4FF6-9DC0-3A692906985E}: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CF438D8B-532B-4B7A-972C-707EF7287EFF}: DhcpNameServer = 75.75.76.76 75.75.75.75
O18 - Protocol\Handler\linkscanner - No CLSID value found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\windows\System32\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2009/06/10 17:42:20 | 000,000,024 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2013/05/09 18:07:49 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SmartPCFixer
[2013/05/09 18:07:47 | 000,000,000 | —D | C] – C:\Program Files\SmartPCFixer
[2013/05/09 15:53:37 | 000,000,000 | —D | C] – C:\windows\ERUNT
[2013/05/09 15:53:28 | 000,000,000 | —D | C] – C:\JRT
[2013/05/09 09:04:40 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\AVG
[2013/05/09 08:50:18 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Foresight Software
[2013/05/09 08:50:08 | 000,000,000 | —D | C] – C:\Users\User\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Foresight Software
[2013/05/09 08:50:02 | 000,000,000 | —D | C] – C:\Program Files\Common Files\Foresight Software
[2013/05/09 08:50:01 | 000,000,000 | —D | C] – C:\ProgramData\Foresight Software
[2013/05/09 08:50:01 | 000,000,000 | —D | C] – C:\Program Files\Foresight Software
[2013/05/08 18:19:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Reimage Repair
[2013/05/08 18:19:05 | 000,000,000 | —D | C] – C:\rei
[2013/05/08 18:19:00 | 000,000,000 | —D | C] – C:\Program Files\Reimage
[2013/05/08 17:23:14 | 000,000,000 | —D | C] – C:\Program Files\UtilityChest_49
[2013/05/08 14:56:10 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/05/08 14:56:01 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/05/08 14:55:47 | 000,015,224 | —- | C] (Safer Networking Limited) – C:\windows\System32\sdnclean.exe
[2013/05/08 14:55:42 | 000,000,000 | —D | C] – C:\Program Files\Spybot - Search & Destroy 2
[2013/05/08 14:55:04 | 000,000,000 | —D | C] – C:\Users\User\AppData\Local\Programs
[2013/05/01 08:29:22 | 000,174,496 | —- | C] (Oracle Corporation) – C:\windows\System32\javaw.exe
[2013/05/01 08:29:22 | 000,174,496 | —- | C] (Oracle Corporation) – C:\windows\System32\java.exe
[2013/05/01 08:29:22 | 000,094,112 | —- | C] (Oracle Corporation) – C:\windows\System32\WindowsAccessBridge.dll
[2013/04/29 21:34:39 | 000,745,472 | —- | C] (Microsoft Corporation) – C:\windows\System32\MsSpellCheckingFacility.exe
[2013/04/29 21:34:39 | 000,185,344 | —- | C] (Microsoft Corporation) – C:\windows\System32\elshyph.dll
[2013/04/29 21:34:39 | 000,158,720 | —- | C] (Microsoft Corporation) – C:\windows\System32\msls31.dll
[2013/04/29 21:34:39 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\windows\System32\RegisterIEPKEYs.exe
[2013/04/29 21:34:39 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\windows\System32\jsproxy.dll
[2013/04/29 21:34:38 | 000,493,056 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeeds.dll
[2013/04/29 21:34:38 | 000,163,840 | —- | C] (Microsoft Corporation) – C:\windows\System32\msrating.dll
[2013/04/29 21:34:38 | 000,150,528 | —- | C] (Microsoft Corporation) – C:\windows\System32\iexpress.exe
[2013/04/29 21:34:38 | 000,138,752 | —- | C] (Microsoft Corporation) – C:\windows\System32\wextract.exe
[2013/04/29 21:34:38 | 000,082,432 | —- | C] (Microsoft Corporation) – C:\windows\System32\inseng.dll
[2013/04/29 21:34:37 | 002,706,432 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2013/04/29 21:34:37 | 000,137,216 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieUnatt.exe
[2013/04/29 21:34:37 | 000,117,248 | —- | C] (Microsoft Corporation) – C:\windows\System32\iepeers.dll
[2013/04/29 21:34:37 | 000,110,592 | —- | C] (Microsoft Corporation) – C:\windows\System32\IEAdvpack.dll
[2013/04/29 21:34:37 | 000,057,344 | —- | C] (Microsoft Corporation) – C:\windows\System32\pngfilt.dll
[2013/04/29 21:34:37 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedsbs.dll
[2013/04/29 21:34:37 | 000,038,400 | —- | C] (Microsoft Corporation) – C:\windows\System32\imgutil.dll
[2013/04/29 21:34:37 | 000,011,776 | —- | C] (Microsoft Corporation) – C:\windows\System32\msfeedssync.exe
[2013/04/29 21:34:36 | 002,877,440 | —- | C] (Microsoft Corporation) – C:\windows\System32\jscript9.dll
[2013/04/29 21:34:36 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2013/04/29 21:34:36 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\windows\System32\iesysprep.dll
[2013/04/29 21:34:36 | 000,073,728 | —- | C] (Microsoft Corporation) – C:\windows\System32\SetIEInstalledDate.exe
[2013/04/29 21:34:36 | 000,048,640 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtmler.dll
[2013/04/29 21:34:35 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\windows\System32\html.iec
[2013/04/29 21:34:35 | 000,226,816 | —- | C] (Microsoft Corporation) – C:\windows\System32\dxtrans.dll
[2013/04/29 21:34:34 | 001,441,280 | —- | C] (Microsoft Corporation) – C:\windows\System32\inetcpl.cpl
[2013/04/29 21:34:34 | 001,400,416 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dat
[2013/04/29 21:34:34 | 000,719,360 | —- | C] (Microsoft Corporation) – C:\windows\System32\mshtmlmedia.dll
[2013/04/29 21:34:34 | 000,629,248 | —- | C] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dll
[2013/04/29 21:34:34 | 000,357,888 | —- | C] (Microsoft Corporation) – C:\windows\System32\dxtmsft.dll
[2013/04/29 21:34:34 | 000,242,200 | —- | C] (Microsoft Corporation) – C:\windows\System32\iedkcs32.dll
[2013/04/29 21:34:34 | 000,232,960 | —- | C] (Microsoft Corporation) – C:\windows\System32\url.dll
[2013/04/29 21:34:34 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\windows\System32\iesetup.dll
[2013/04/29 21:34:34 | 000,042,496 | —- | C] (Microsoft Corporation) – C:\windows\System32\ie4uinit.exe
[2013/04/29 21:34:34 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\windows\System32\iernonce.dll
[2013/04/29 21:34:34 | 000,023,040 | —- | C] (Microsoft Corporation) – C:\windows\System32\licmgr10.dll
[2013/04/29 21:33:06 | 000,009,728 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/29 21:33:06 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/29 21:33:06 | 000,004,096 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/29 21:33:06 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/29 21:33:05 | 002,284,544 | —- | C] (Microsoft Corporation) – C:\windows\System32\msmpeg2vdec.dll
[2013/04/29 21:33:05 | 001,504,768 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d11.dll
[2013/04/29 21:33:05 | 001,247,744 | —- | C] (Microsoft Corporation) – C:\windows\System32\DWrite.dll
[2013/04/29 21:33:05 | 001,158,144 | —- | C] (Microsoft Corporation) – C:\windows\System32\XpsPrint.dll
[2013/04/29 21:33:05 | 000,417,792 | —- | C] (Microsoft Corporation) – C:\windows\System32\WMPhoto.dll
[2013/04/29 21:33:05 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\windows\System32\XpsGdiConverter.dll
[2013/04/29 21:33:05 | 000,220,160 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10core.dll
[2013/04/29 21:33:05 | 000,010,752 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,005,632 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,003,584 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/29 21:33:05 | 000,003,072 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,002,560 | -H– | C] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/29 21:33:04 | 003,419,136 | —- | C] (Microsoft Corporation) – C:\windows\System32\d2d1.dll
[2013/04/29 21:33:04 | 001,988,096 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10warp.dll
[2013/04/29 21:33:04 | 001,080,832 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10.dll
[2013/04/29 21:33:04 | 000,604,160 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10level9.dll
[2013/04/29 21:33:04 | 000,293,376 | —- | C] (Microsoft Corporation) – C:\windows\System32\dxgi.dll
[2013/04/29 21:33:04 | 000,249,856 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10_1core.dll
[2013/04/29 21:33:04 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\windows\System32\WindowsCodecsExt.dll
[2013/04/29 21:33:04 | 000,187,392 | —- | C] (Microsoft Corporation) – C:\windows\System32\UIAnimation.dll
[2013/04/29 21:33:04 | 000,161,792 | —- | C] (Microsoft Corporation) – C:\windows\System32\d3d10_1.dll
[2013/04/12 16:50:47 | 000,000,000 | —D | C] – C:\Program Files\Mozilla Firefox
[2013/04/10 11:05:30 | 002,347,008 | —- | C] (Microsoft Corporation) – C:\windows\System32\win32k.sys
[2013/04/10 11:05:26 | 003,968,856 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntkrnlpa.exe
[2013/04/10 11:05:26 | 003,913,560 | —- | C] (Microsoft Corporation) – C:\windows\System32\ntoskrnl.exe
[2013/04/10 11:05:25 | 000,038,912 | —- | C] (Microsoft Corporation) – C:\windows\System32\csrsrv.dll
[2013/04/10 11:05:13 | 000,131,584 | —- | C] (Microsoft Corporation) – C:\windows\System32\aaclient.dll
[2013/04/10 11:05:12 | 000,036,864 | —- | C] (Microsoft Corporation) – C:\windows\System32\tsgqec.dll
[2011/05/11 07:00:10 | 006,533,152 | —- | C] (Xobni) – C:\Users\User\XobniSetup.exe
[2011/01/25 19:18:13 | 008,969,504 | —- | C] (Secure Backup and Share) – C:\ProgramData\TempComcastSecureBackupShare-update-94576f825cbee21cffeff81117efd21f.exe
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/05/09 18:40:51 | 000,015,792 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/05/09 18:40:51 | 000,015,792 | -H– | M] () – C:\windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/05/09 18:35:00 | 000,000,830 | —- | M] () – C:\windows\tasks\Adobe Flash Player Updater.job
[2013/05/09 18:33:23 | 000,000,882 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/05/09 18:33:17 | 000,067,584 | –S- | M] () – C:\windows\bootstat.dat
[2013/05/09 18:31:50 | 2211,577,856 | -HS- | M] () – C:\hiberfil.sys
[2013/05/09 18:27:49 | 000,000,690 | —- | M] () – C:\windows\DeleteOnReboot.bat
[2013/05/09 18:25:04 | 000,000,886 | —- | M] () – C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/05/09 18:07:50 | 000,000,984 | —- | M] () – C:\Users\Public\Desktop\SmartPCFixer.lnk
[2013/05/09 18:00:00 | 000,000,470 | —- | M] () – C:\windows\tasks\Foresight Software Registration3.job
[2013/05/09 10:19:27 | 000,000,444 | —- | M] () – C:\windows\tasks\Foresight Software Update3.job
[2013/05/09 10:19:27 | 000,000,416 | —- | M] () – C:\windows\tasks\PC Helper 360.job
[2013/05/09 09:47:09 | 000,000,162 | —- | M] () – C:\windows\Reimage.ini
[2013/05/09 09:04:40 | 000,000,906 | —- | M] () – C:\Users\Public\Desktop\AVG 2013.lnk
[2013/05/09 08:51:52 | 000,002,283 | —- | M] () – C:\Users\User\Windows Easy Transfer.lnk
[2013/05/09 08:50:08 | 000,001,160 | —- | M] () – C:\Users\User\Desktop\PC Helper 360.lnk
[2013/05/08 18:19:06 | 000,002,025 | —- | M] () – C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
[2013/05/08 16:16:17 | 000,001,586 | —- | M] () – C:\Users\User\Documents\cc_20130508_161612.reg
[2013/05/08 15:45:24 | 000,001,772 | —- | M] () – C:\windows\wininit.ini
[2013/05/08 14:56:02 | 000,002,090 | —- | M] () – C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/05/08 14:19:40 | 001,012,646 | —- | M] () – C:\Users\User\AppData\Local\census.cache
[2013/05/08 14:18:41 | 000,196,593 | —- | M] () – C:\Users\User\AppData\Local\ars.cache
[2013/05/08 14:00:25 | 000,000,036 | —- | M] () – C:\Users\User\AppData\Local\housecall.guid.cache
[2013/05/07 17:57:19 | 000,003,416 | —- | M] () – C:\windows\ComcastSecureBackupShare.blk
[2013/05/07 17:57:19 | 000,000,354 | —- | M] () – C:\windows\ComcastSecureBackupShare.flt
[2013/04/30 08:13:30 | 000,433,584 | —- | M] () – C:\windows\System32\FNTCACHE.DAT
[2013/04/29 21:34:39 | 000,745,472 | —- | M] (Microsoft Corporation) – C:\windows\System32\MsSpellCheckingFacility.exe
[2013/04/29 21:34:39 | 000,185,344 | —- | M] (Microsoft Corporation) – C:\windows\System32\elshyph.dll
[2013/04/29 21:34:39 | 000,158,720 | —- | M] (Microsoft Corporation) – C:\windows\System32\msls31.dll
[2013/04/29 21:34:39 | 000,071,680 | —- | M] (Microsoft Corporation) – C:\windows\System32\RegisterIEPKEYs.exe
[2013/04/29 21:34:39 | 000,039,424 | —- | M] (Microsoft Corporation) – C:\windows\System32\jsproxy.dll
[2013/04/29 21:34:38 | 000,493,056 | —- | M] (Microsoft Corporation) – C:\windows\System32\msfeeds.dll
[2013/04/29 21:34:38 | 000,163,840 | —- | M] (Microsoft Corporation) – C:\windows\System32\msrating.dll
[2013/04/29 21:34:38 | 000,150,528 | —- | M] (Microsoft Corporation) – C:\windows\System32\iexpress.exe
[2013/04/29 21:34:38 | 000,138,752 | —- | M] (Microsoft Corporation) – C:\windows\System32\wextract.exe
[2013/04/29 21:34:38 | 000,082,432 | —- | M] (Microsoft Corporation) – C:\windows\System32\inseng.dll
[2013/04/29 21:34:37 | 002,706,432 | —- | M] (Microsoft Corporation) – C:\windows\System32\mshtml.tlb
[2013/04/29 21:34:37 | 000,137,216 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieUnatt.exe
[2013/04/29 21:34:37 | 000,117,248 | —- | M] (Microsoft Corporation) – C:\windows\System32\iepeers.dll
[2013/04/29 21:34:37 | 000,110,592 | —- | M] (Microsoft Corporation) – C:\windows\System32\IEAdvpack.dll
[2013/04/29 21:34:37 | 000,057,344 | —- | M] (Microsoft Corporation) – C:\windows\System32\pngfilt.dll
[2013/04/29 21:34:37 | 000,041,984 | —- | M] (Microsoft Corporation) – C:\windows\System32\msfeedsbs.dll
[2013/04/29 21:34:37 | 000,038,400 | —- | M] (Microsoft Corporation) – C:\windows\System32\imgutil.dll
[2013/04/29 21:34:37 | 000,011,776 | —- | M] (Microsoft Corporation) – C:\windows\System32\msfeedssync.exe
[2013/04/29 21:34:36 | 002,877,440 | —- | M] (Microsoft Corporation) – C:\windows\System32\jscript9.dll
[2013/04/29 21:34:36 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieui.dll
[2013/04/29 21:34:36 | 000,109,056 | —- | M] (Microsoft Corporation) – C:\windows\System32\iesysprep.dll
[2013/04/29 21:34:36 | 000,073,728 | —- | M] (Microsoft Corporation) – C:\windows\System32\SetIEInstalledDate.exe
[2013/04/29 21:34:36 | 000,048,640 | —- | M] (Microsoft Corporation) – C:\windows\System32\mshtmler.dll
[2013/04/29 21:34:35 | 000,361,984 | —- | M] (Microsoft Corporation) – C:\windows\System32\html.iec
[2013/04/29 21:34:35 | 000,226,816 | —- | M] (Microsoft Corporation) – C:\windows\System32\dxtrans.dll
[2013/04/29 21:34:34 | 001,441,280 | —- | M] (Microsoft Corporation) – C:\windows\System32\inetcpl.cpl
[2013/04/29 21:34:34 | 001,400,416 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dat
[2013/04/29 21:34:34 | 000,719,360 | —- | M] (Microsoft Corporation) – C:\windows\System32\mshtmlmedia.dll
[2013/04/29 21:34:34 | 000,629,248 | —- | M] (Microsoft Corporation) – C:\windows\System32\ieapfltr.dll
[2013/04/29 21:34:34 | 000,357,888 | —- | M] (Microsoft Corporation) – C:\windows\System32\dxtmsft.dll
[2013/04/29 21:34:34 | 000,242,200 | —- | M] (Microsoft Corporation) – C:\windows\System32\iedkcs32.dll
[2013/04/29 21:34:34 | 000,232,960 | —- | M] (Microsoft Corporation) – C:\windows\System32\url.dll
[2013/04/29 21:34:34 | 000,061,440 | —- | M] (Microsoft Corporation) – C:\windows\System32\iesetup.dll
[2013/04/29 21:34:34 | 000,042,496 | —- | M] (Microsoft Corporation) – C:\windows\System32\ie4uinit.exe
[2013/04/29 21:34:34 | 000,033,280 | —- | M] (Microsoft Corporation) – C:\windows\System32\iernonce.dll
[2013/04/29 21:34:34 | 000,025,185 | —- | M] () – C:\windows\System32\ieuinit.inf
[2013/04/29 21:34:34 | 000,023,040 | —- | M] (Microsoft Corporation) – C:\windows\System32\licmgr10.dll
[2013/04/29 21:33:06 | 000,009,728 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l1-1-0.dll
[2013/04/29 21:33:06 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shlwapi-l2-1-0.dll
[2013/04/29 21:33:06 | 000,004,096 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-user32-l1-1-0.dll
[2013/04/29 21:33:06 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-version-l1-1-0.dll
[2013/04/29 21:33:05 | 002,284,544 | —- | M] (Microsoft Corporation) – C:\windows\System32\msmpeg2vdec.dll
[2013/04/29 21:33:05 | 001,504,768 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d11.dll
[2013/04/29 21:33:05 | 001,247,744 | —- | M] (Microsoft Corporation) – C:\windows\System32\DWrite.dll
[2013/04/29 21:33:05 | 001,158,144 | —- | M] (Microsoft Corporation) – C:\windows\System32\XpsPrint.dll
[2013/04/29 21:33:05 | 000,417,792 | —- | M] (Microsoft Corporation) – C:\windows\System32\WMPhoto.dll
[2013/04/29 21:33:05 | 000,364,544 | —- | M] (Microsoft Corporation) – C:\windows\System32\XpsGdiConverter.dll
[2013/04/29 21:33:05 | 000,220,160 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10core.dll
[2013/04/29 21:33:05 | 000,010,752 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,005,632 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-ole32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,003,584 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-advapi32-l2-1-0.dll
[2013/04/29 21:33:05 | 000,003,072 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-shell32-l1-1-0.dll
[2013/04/29 21:33:05 | 000,002,560 | -H– | M] (Microsoft Corporation) – C:\windows\System32\api-ms-win-downlevel-normaliz-l1-1-0.dll
[2013/04/29 21:33:04 | 003,419,136 | —- | M] (Microsoft Corporation) – C:\windows\System32\d2d1.dll
[2013/04/29 21:33:04 | 001,988,096 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10warp.dll
[2013/04/29 21:33:04 | 001,080,832 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10.dll
[2013/04/29 21:33:04 | 000,604,160 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10level9.dll
[2013/04/29 21:33:04 | 000,293,376 | —- | M] (Microsoft Corporation) – C:\windows\System32\dxgi.dll
[2013/04/29 21:33:04 | 000,249,856 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10_1core.dll
[2013/04/29 21:33:04 | 000,207,872 | —- | M] (Microsoft Corporation) – C:\windows\System32\WindowsCodecsExt.dll
[2013/04/29 21:33:04 | 000,187,392 | —- | M] (Microsoft Corporation) – C:\windows\System32\UIAnimation.dll
[2013/04/29 21:33:04 | 000,161,792 | —- | M] (Microsoft Corporation) – C:\windows\System32\d3d10_1.dll
[2013/04/12 17:54:47 | 000,002,001 | —- | M] () – C:\Users\User\Application Data\Microsoft\Internet Explorer\Quick Launch\Mozilla Firefox.lnk
[2013/04/10 08:20:37 | 000,002,100 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[1 C:\windows\*.tmp files -> C:\windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/05/09 18:07:50 | 000,000,984 | —- | C] () – C:\Users\Public\Desktop\SmartPCFixer.lnk
[2013/05/09 11:00:45 | 000,000,690 | —- | C] () – C:\windows\DeleteOnReboot.bat
[2013/05/09 08:50:21 | 000,000,470 | —- | C] () – C:\windows\tasks\Foresight Software Registration3.job
[2013/05/09 08:50:08 | 000,001,160 | —- | C] () – C:\Users\User\Desktop\PC Helper 360.lnk
[2013/05/09 08:50:06 | 000,000,444 | —- | C] () – C:\windows\tasks\Foresight Software Update3.job
[2013/05/09 08:50:04 | 000,000,416 | —- | C] () – C:\windows\tasks\PC Helper 360.job
[2013/05/08 18:19:06 | 000,002,025 | —- | C] () – C:\Users\Public\Desktop\PC Scan & Repair by Reimage.lnk
[2013/05/08 18:18:39 | 000,000,162 | —- | C] () – C:\windows\Reimage.ini
[2013/05/08 16:16:15 | 000,001,586 | —- | C] () – C:\Users\User\Documents\cc_20130508_161612.reg
[2013/05/08 15:45:22 | 000,001,772 | —- | C] () – C:\windows\wininit.ini
[2013/05/08 14:56:02 | 000,002,102 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D Start Center.lnk
[2013/05/08 14:56:02 | 000,002,090 | —- | C] () – C:\Users\Public\Desktop\Spybot-S&D Start Center.lnk
[2013/05/08 14:19:40 | 001,012,646 | —- | C] () – C:\Users\User\AppData\Local\census.cache
[2013/05/08 14:18:41 | 000,196,593 | —- | C] () – C:\Users\User\AppData\Local\ars.cache
[2013/05/08 14:00:25 | 000,000,036 | —- | C] () – C:\Users\User\AppData\Local\housecall.guid.cache
[2013/04/29 21:34:34 | 000,025,185 | —- | C] () – C:\windows\System32\ieuinit.inf
[2011/10/08 08:48:11 | 000,000,210 | —- | C] () – C:\Users\User\AppData\Roaming\wklnhst.dat
[2011/04/13 17:51:02 | 000,001,502 | —- | C] () – C:\Users\User\.recently-used.xbel
[2011/03/16 18:54:03 | 000,000,000 | —- | C] () – C:\Users\User\AppData\Local\prvlcl.dat
[2010/12/05 03:58:53 | 000,026,837 | —- | C] () – C:\Users\User\AppData\Roaming\Comma Separated Values (Windows).ADR
[2010/12/02 10:05:38 | 000,000,017 | —- | C] () – C:\Users\User\AppData\Local\resmon.resmoncfg
[2010/12/01 03:12:28 | 000,002,283 | —- | C] () – C:\Users\User\Windows Easy Transfer.lnk
[2010/12/01 03:12:28 | 000,000,706 | —- | C] () – C:\Users\User\autorun.inf

========== ZeroAccess Check ==========

[2009/07/14 00:42:31 | 000,000,227 | RHS- | M] () – C:\windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/09 00:41:00 | 012,873,728 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll – [2009/07/13 21:16:17 | 000,342,528 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

< End of report >
Hi MARTY1946,

I see you have Reimage installed. It is a questionable program, I suggest you uninstall it.

Click Start > Control Panel > Programs and Features. Locate and select the following that are present on the list and click the Remove button:
  • Reimage
  • AVG Secure Search
  • UtilityChest_49
- - - - - Next - - - - -

Run OTL.exe

Windows Vista and Windows 7 users Right Click and select "Run as Administrator"
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    PRC - C:\Program Files\Common Files\AVG Secure Search\vToolbarUpdater\15.0.0\ToolbarUpdater.exe ()
    PRC - C:\Program Files\UtilityChest_49\bar\1.bin\49barsvc.exe (COMPANYVERS_NAME)
    IE - HKCU\..\URLSearchHook: {7a55cbb2-2b2e-4a41-9de1-6ac5d2c2be0a} - No CLSID value found
    IE - HKCU\..\URLSearchHook: {A3BC75A2-1F87-4686-AA43-5347D756017C} - No CLSID value found
    FF - prefs.js..browser.search.defaultenginename: "AVG Secure Search"
    FF - prefs.js..extensions.enabledItems: {7b13ec3e-999a-4b70-b9cb-2617b8323822}:2.7.1.3
    FF - HKLM\Software\MozillaPlugins\@UtilityChest_49.com/Plugin: C:\Program Files\UtilityChest_49\bar\1.bin\NP49Stub.dll File not found
    O2 - BHO: (no name) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - No CLSID value found.
    O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (ALOT Toolbar) - {5AA2BA46-9913-4dc7-9620-69AB0FA17AE7} - C:\Program Files\alot\bin\alot.dll File not found
    O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (Utility Chest) - {cf67755f-9265-449c-87cf-b945519e073b} - C:\Program Files\UtilityChest_49\bar\1.bin\49bar.dll File not found
    O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    [2013/05/08 17:23:14 | 000,000,000 | —D | C] – C:\Program Files\UtilityChest_49
    
    :Services
    UtilityChest_49Service
    vToolbarUpdater15.0.0
    AVG Security Toolbar Service
    
    :Files
    C:\Program Files\UtilityChest_49
    C:\Program Files\Common Files\AVG Secure Search
    C:\Program Files\AVG\AVG10
    
    :Commands
    [purity]
    [createrestorepoint]
    [emptyjava]
    [emptycache]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot when it is done
  • Then re-run OTL and post new OTL log ( don't check the boxes beside LOP Check or Purity this time )
In your next post please provide the following:
  • Fresh OTL log
  • How is the computer running?
OCD I did want you asked, but I had the same problem with the OTL log in Notepad so I attached it below I could not uninstall the Utility Chest it said it couldn't find a module Didn't see the AVG toolbar listed The start menu when I hit start it starts searching for more options, I have never seen this before it started happening recently Still have problems Thanks Marty

Attachments:

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI