This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Win32/Sirefef, ESET "unable 2 comm. with kernel"

10 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Symptoms: Failure of ESET to launch, "Unable to communicate with kernel", system severely slowed until it refused to open anything. Blue Win 8 status ring in endless loop, had to shut down to stop it. ESET Smart Security 6 on board and run faithfully, but even after issue with kernel started, scans continued to come up clean. Per their Knowledge base, ran ESET Sirefef Cleaner tool. Tool scanned and then attempted removal. Results: Suspicious EA_Attribute detected, Win32/Sirefef found, Services.exe appears to be infected, Error: ERR_CS03. Cleaning process stalled at 50%, message: Failed to clean Services.exe, Infection not completely removed. ESET advised to contact support. In return they requested 3 logs, Detected Threats, SysInspector, and Scan log, I also included the Sirefef Cleaner log. It has been 6 very long days waiting, but still no response and follow up emails have not been answered. I have researched volumes about this infection and opinions run from nasty to Call all financial institutions, wipe the drive, and even then it might not be possible to save it. Did I mention this laptop was my well deserved Christmas present to myself after agonizing over the purchase for 9 months!?! Rats Suggestions to use various cleaners and change or delete registry keys are well beyond my abilities.

I did hunt out and scan all the services.exe files I could find, all were "fine" except C:\Windows\System32\en-US\services.exe.mui. Unable to open, even with WinRAR, message: The archive is either unknown format or is damaged. Any help you can provide would be greatly appreciated, Thank you for your time and effort.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 5:24:54 AM, on 5/22/2013
Platform: Unknown Windows (WinNT 6.02.1008)
MSIE: Internet Explorer v10.0 (10.00.9200.16537)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\IObit\Advanced SystemCare 6\Monitor.exe
C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe
C:\Program Files (x86)\HP SimplePass\IEWebSiteLogon.exe
C:\Program Files (x86)\Common Files\Microsoft Shared\Ink\TabTip32.exe
C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe
C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe
C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe
C:\Program Files (x86)\CyberLink\YouCam\YCMMirage.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\Program Files (x86)\HP SimplePass\TouchControl.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: Advanced SystemCare Browser Protection - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\PROGRA~2\IObit\ADVANC~1\BROWER~1\ASCPlugin_Protection.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O4 - HKLM\..\Run: [RemoteControl10] "C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe"
O4 - HKLM\..\Run: [HP Quick Launch] C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe
O4 - HKLM\..\Run: [HP CoolSense] C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe -byrunkey
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files (x86)\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [CLVirtualDrive] "C:\Program Files (x86)\CyberLink\Power2Go8\VirtualDrive.exe" /R
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS6ServiceManager] "C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe
O4 - HKCU\..\Run: [Advanced SystemCare 6] "C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe" /AutoStart
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Power2GoExpress8] "C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe"
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office12\EXCEL.EXE/3000
O8 - Extra context menu item: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~2\MICROS~1\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~2\MICROS~1\Office12\REFIEBAR.DLL
O9 - Extra button: Send to Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O9 - Extra 'Tools' menuitem: Send to Bluetooth - {2F56DCAA-153B-4479-B4E2-547405B34FB9} - C:\Program Files (x86)\Intel\Bluetooth\btSendToPage.htm (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} (SpinTop DRM Control) - file:///C:/Program%20Files%20(x86)/VISTA%20prog-32%20bit/Bejeweled%202/Images/stg_drm.ocx
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files (x86)\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: ArcSoft Connect Daemon (ACDaemon) - ArcSoft Inc. - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Advanced SystemCare Service 6 (AdvancedSystemCareService6) - IObit - C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Service (AMPPALR3) - Intel Corporation - C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe
O23 - Service: Bluetooth Device Monitor - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe
O23 - Service: Bluetooth OBEX Service - Motorola Solutions, Inc. - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Intel® Centrino® Wireless Bluetooth® + High Speed Security Service (BTHSSecurityMgr) - Intel® Corporation - C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe
O23 - Service: Intel® Content Protection HECI Service (cphs) - Intel Corporation - C:\Windows\SysWow64\IntelCpHeciSvc.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: TrueSuiteService (FPLService) - HP - C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: @oem18.inf,%hpservice_desc%;HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file missing)
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: Intel® Capability Licensing Service Interface - Intel® Corporation - C:\Program Files\Intel\iCLS Client\HeciServer.exe
O23 - Service: Intel® ME Service - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe
O23 - Service: Intel® Dynamic Application Loader Host Interface Service (jhi_service) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\jhi_service.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program Files\IDT\WDM\STacSV64.exe
O23 - Service: Adobe SwitchBoard (SwitchBoard) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: TabletServiceWacom - Unknown owner - C:\Windows\system32\Wacom_Tablet.exe (file missing)
O23 - Service: TeamViewer 8 (TeamViewer8) - TeamViewer GmbH - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe
O23 - Service: TrueAPI Service component (TrueService) - AuthenTec, Inc. - C:\Program Files\Common Files\AuthenTec\TrueService.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: Validity WBF Policy Service (valWBFPolicyService) - Unknown owner - C:\Windows\system32\valWBFPolicyService.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Defender\MpAsDesc.dll,-310 (WinDefend) - Unknown owner - C:\Program Files (x86)\Windows Defender\MsMpEng.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Zero Configuration Service (ZeroConfigService) - Intel® Corporation - C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe

–
End of file - 14348 bytes
Dear oldman960, Thanks for responding. I am still having problems. ESET rep and I spent 3 hours on remote fix, he ended up contacting his boss who said that Windows 8 is not susceptible to Sirefef infection, and that error message and scan results were false positives. When I asked what was causing kernel communication issue, he didn't know, but was certain it wasn't Sirefef. I was told to contact them again if there was further problem. I am still having occasions where kernel error comes up. When this happens, my eset can't load, so I can't go on-line unless I wish to go unprotected. I am not at all confident in eset's rep as he didn't seem very familiar with his own software or Windows 8. At this point, I can't go online when error pops up, I just close down and hope it will clear by the next time I try to log on. ESET was recommended to me by a computer geek, but I don't know what to do now. I really dont want to have to reformat my hard drive if I can avoid it, but then again, Windows 8 would not be a great loss to me.
Hi SnapHappy,

Let's have a better look.

  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in

    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    services.*
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    /md5stop
    dir "%systemdrive%\*" /S /A:L /C
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
Hi, Sorry to have been so long in responding. Having lots of issues here. I am running OTL right now and will post when it completes. Please don't close my thread, Thanks again for your time and effort.
OTL logfile created on: 6/13/2013 10:23:27 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Pic Chic\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16599)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.89 Gb Total Physical Memory | 5.81 Gb Available Physical Memory | 73.65% Memory free
9.08 Gb Paging File | 6.82 Gb Available in Paging File | 75.11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 670.51 Gb Total Space | 527.54 Gb Free Space | 78.68% Space Free | Partition Type: NTFS
Drive D: | 27.35 Gb Total Space | 3.22 Gb Free Space | 11.76% Space Free | Partition Type: NTFS

Computer Name: ENVY | User Name: Pic Chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Pic Chic\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
PRC - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\TeamViewer\Version8\tv_w32.exe (TeamViewer GmbH)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe (IObit)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe (IObit)
PRC - C:\Program Files (x86)\IObit\Advanced SystemCare 6\Monitor.exe (IObit)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
PRC - C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
PRC - C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (ESET)
PRC - C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe (HP)
PRC - C:\Program Files (x86)\HP SimplePass\TouchControl.exe (AuthenTec Inc.)
PRC - C:\Program Files (x86)\HP SimplePass\IEWebSiteLogon.exe ()
PRC - C:\Program Files (x86)\CyberLink\Power2Go8\Power2GoExpress8.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP CoolSense\CoolSense.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPMSGSVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
PRC - C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Motorola Solutions, Inc.)
PRC - C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
PRC - C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvc_P2G8.exe (CyberLink)
PRC - C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
PRC - C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
PRC - C:\Program Files (x86)\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
PRC - C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ABBYY)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppgooglenaclpluginchrome.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\libglesv2.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\libegl.dll ()
MOD - C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ffmpegsumo.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Xml\bacedff71df875743daa9064b85c4e66\System.Xml.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Windows.Forms\1bc35bb3e6a392c0fef52bc289e6d3d9\System.Windows.Forms.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Drawing\9eff07ed10b6ae9f9b1159a7d3612fcb\System.Drawing.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System.Core\b3d842ef956729e3ca0a3bc5e37ea6d8\System.Core.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\System\eaa570735a52e0010d3e9caa9ba50124\System.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\mscorlib\93689d115589e64dd4912f7113a11656\mscorlib.ni.dll ()
MOD - C:\Windows\assembly\NativeImages_v4.0.30319_32\CustomMarshalers\32b8f308d20fce9245a194624c2d1acc\CustomMarshalers.ni.dll ()
MOD - C:\Program Files (x86)\HP SimplePass\IEWebSiteLogon.exe ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go8\UNO.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go8\CLVistaAudioMixer.dll ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 6\madexcept_.bpl ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 6\maddisAsm_.bpl ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 6\madbasic_.bpl ()
MOD - C:\Program Files (x86)\IObit\Advanced SystemCare 6\webres.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go8\Language\Enu\P2GRC.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go8\CLMLSvcPS.dll ()
MOD - C:\Program Files (x86)\CyberLink\Power2Go8\CLMediaLibrary.dll ()


========== Services (SafeList) ==========

SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (netprofm) – C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:64bit: - (BrokerInfrastructure) – C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:64bit: - (AudioEndpointBuilder) – C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:64bit: - (ekrn) – C:\Program Files\ESET\ESET Smart Security\x86\ekrn.exe (ESET)
SRV:64bit: - (TimeBroker) – C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (SystemEventsBroker) – C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (AMPPALR3) – C:\Program Files\Intel\BluetoothHS\BTHSAmpPalService.exe (Intel Corporation)
SRV:64bit: - (ZeroConfigService) – C:\Program Files\Intel\WiFi\bin\ZeroConfigService.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe (Intel® Corporation)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (wlidsvc) – C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:64bit: - (LSM) – C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:64bit: - (TrueService) – C:\Program Files\Common Files\AuthenTec\TrueService.exe (AuthenTec, Inc.)
SRV:64bit: - (PrintNotify) – C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (WSService) – C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
SRV:64bit: - (fhsvc) – C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:64bit: - (BTHSSecurityMgr) – C:\Program Files\Intel\BluetoothHS\BTHSSecurityMgr.exe (Intel® Corporation)
SRV:64bit: - (valWBFPolicyService) – C:\Windows\SysNative\valWBFPolicyService.exe ()
SRV:64bit: - (WiaRpc) – C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:64bit: - (Wcmsvc) – C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:64bit: - (VaultSvc) – C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:64bit: - (svsvc) – C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:64bit: - (Netlogon) – C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:64bit: - (NcaSvc) – C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:64bit: - (NcdAutoSetup) – C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:64bit: - (KeyIso) – C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:64bit: - (EFS) – C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:64bit: - (DsmSvc) – C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:64bit: - (DeviceAssociationService) – C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:64bit: - (AllUserInstallAgent) – C:\Windows\SysNative\AUInstallAgent.dll (Microsoft Corporation)
SRV:64bit: - (vmicvss) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmictimesync) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicshutdown) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicrdv) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmickvpexchange) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicheartbeat) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (Intel® – C:\Program Files\Intel\iCLS Client\HeciServer.exe (Intel® Corporation)
SRV:64bit: - (TabletServiceWacom) – C:\Windows\SysNative\Wacom_Tablet.exe (Wacom Technology, Corp.)
SRV - (IAStorDataMgrSvc) – C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (cphs) – C:\Windows\SysWOW64\IntelCpHeciSvc.exe (Intel Corporation)
SRV - (TeamViewer8) – C:\Program Files (x86)\TeamViewer\Version8\TeamViewer_Service.exe (TeamViewer GmbH)
SRV - (AdvancedSystemCareService6) – C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCService.exe (IObit)
SRV - (MBAMService) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe (Malwarebytes Corporation)
SRV - (MBAMScheduler) – C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamscheduler.exe (Malwarebytes Corporation)
SRV - (FPLService) – C:\Program Files (x86)\HP SimplePass\TrueSuiteService.exe (HP)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (PrintNotify) – C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard Development Company, L.P.)
SRV - (Bluetooth OBEX Service) – C:\Program Files (x86)\Intel\Bluetooth\obexsrv.exe (Motorola Solutions, Inc.)
SRV - (Bluetooth Device Monitor) – C:\Program Files (x86)\Intel\Bluetooth\devmonsrv.exe (Motorola Solutions, Inc.)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (StorSvc) – C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)
SRV - (WAS) – C:\Windows\SysWOW64\inetsrv\iisw3adm.dll (Microsoft Corporation)
SRV - (AppHostSvc) – C:\Windows\SysWOW64\inetsrv\apphostsvc.dll (Microsoft Corporation)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe (Intel Corporation)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel Corporation)
SRV - (Intel® – C:\Program Files (x86)\Intel\Intel® Management Engine Components\FWService\IntelMeFWService.exe (Intel Corporation)
SRV - (jhi_service) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\DAL\Jhi_service.exe (Intel Corporation)
SRV - (IMFservice) – C:\Program Files (x86)\IObit\IObit Malware Fighter\IMFsrv.exe (IObit)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (ACDaemon) – C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (SwitchBoard) – C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
SRV - (ABBYY.Licensing.FineReader.Sprint.9.0) – C:\Program Files (x86)\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe (ABBYY)


========== Driver Services (SafeList) ==========

DRV:64bit: - (STHDA) – C:\Windows\SysNative\Drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (igfx) – C:\Windows\SysNative\Drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (iaStorA) – C:\Windows\SysNative\Drivers\iaStorA.sys (Intel Corporation)
DRV:64bit: - (USBHUB3) – C:\Windows\SysNative\Drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:64bit: - (UCX01000) – C:\Windows\SysNative\Drivers\UCX01000.SYS (Microsoft Corporation)
DRV:64bit: - (spaceport) – C:\Windows\SysNative\Drivers\spaceport.sys (Microsoft Corporation)
DRV:64bit: - (MBAMProtector) – C:\Windows\SysNative\Drivers\mbam.sys (Malwarebytes Corporation)
DRV:64bit: - (USBXHCI) – C:\Windows\SysNative\Drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:64bit: - (storahci) – C:\Windows\SysNative\Drivers\storahci.sys (Microsoft Corporation)
DRV:64bit: - (TPM) – C:\Windows\SysNative\Drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\Drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (pdc) – C:\Windows\SysNative\Drivers\pdc.sys (Microsoft Corporation)
DRV:64bit: - (NETwNe64) – C:\Windows\SysNative\Drivers\NETwew00.sys (Intel Corporation)
DRV:64bit: - (epfwwfp) – C:\Windows\SysNative\Drivers\epfwwfp.sys (ESET)
DRV:64bit: - (eamonm) – C:\Windows\SysNative\Drivers\eamonm.sys (ESET)
DRV:64bit: - (AMPPALP) – C:\Windows\SysNative\Drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (AMPPAL) – C:\Windows\SysNative\Drivers\AmpPal.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (WirelessButtonDriver) – C:\Windows\SysNative\Drivers\WirelessButtonDriver64.sys (Hewlett-Packard Development Company, L.P.)
DRV:64bit: - (BthAvrcpTg) – C:\Windows\SysNative\Drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:64bit: - (WdBoot) – C:\Windows\SysNative\Drivers\WdBoot.sys (Microsoft Corporation)
DRV:64bit: - (WdFilter) – C:\Windows\SysNative\Drivers\WdFilter.sys (Microsoft Corporation)
DRV:64bit: - (XHCIPort) – C:\Windows\SysNative\Drivers\xHCIPort.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (usb3Hub) – C:\Windows\SysNative\Drivers\usb3Hub.sys (Windows ® Win 7 DDK provider)
DRV:64bit: - (intaud_WaveExtensible) – C:\Windows\SysNative\Drivers\intelaud.sys (Intel Corporation)
DRV:64bit: - (iwdbus) – C:\Windows\SysNative\Drivers\iwdbus.sys (Intel Corporation)
DRV:64bit: - (dtsoftbus01) – C:\Windows\SysNative\Drivers\dtsoftbus01.sys (DT Soft Ltd)
DRV:64bit: - (MEIx64) – C:\Windows\SysNative\Drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (epfw) – C:\Windows\SysNative\Drivers\epfw.sys (ESET)
DRV:64bit: - (EpfwLWF) – C:\Windows\SysNative\Drivers\EpfwLWF.sys (ESET)
DRV:64bit: - (ehdrv) – C:\Windows\SysNative\Drivers\ehdrv.sys (ESET)
DRV:64bit: - (msgpiowin32) – C:\Windows\SysNative\Drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\Drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (SmbDrvI) – C:\Windows\SysNative\Drivers\Smb_driver_Intel.sys (Synaptics Incorporated)
DRV:64bit: - (bthhfhid) – C:\Windows\SysNative\Drivers\BthhfHid.sys (Microsoft Corporation)
DRV:64bit: - (hidi2c) – C:\Windows\SysNative\Drivers\hidi2c.sys (Microsoft Corporation)
DRV:64bit: - (FxPPM) – C:\Windows\SysNative\Drivers\fxppm.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\Drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (sdstor) – C:\Windows\SysNative\Drivers\sdstor.sys (Microsoft Corporation)
DRV:64bit: - (dam) – C:\Windows\SysNative\Drivers\dam.sys (Microsoft Corporation)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\Drivers\Accelerometer.sys (Hewlett-Packard Company)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\Drivers\hpdskflt.sys (Hewlett-Packard Company)
DRV:64bit: - (GPIOClx0101) – C:\Windows\SysNative\Drivers\msgpioclx.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\Drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\Drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (btmhsf) – C:\Windows\SysNative\Drivers\btmhsf.sys (Motorola Solutions, Inc.)
DRV:64bit: - (btmaux) – C:\Windows\SysNative\Drivers\btmaux.sys (Motorola Solutions, Inc.)
DRV:64bit: - (SmbDrv) – C:\Windows\SysNative\Drivers\Smb_driver_AMDASF.sys (Synaptics Incorporated)
DRV:64bit: - (iBtFltCoex) – C:\Windows\SysNative\Drivers\iBtFltCoex.sys (Intel Corporation)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (condrv) – C:\Windows\SysNative\Drivers\condrv.sys (Microsoft Corporation)
DRV:64bit: - (VSTXRAID) – C:\Windows\SysNative\Drivers\VSTXRAID.SYS (VIA Corporation)
DRV:64bit: - (VerifierExt) – C:\Windows\SysNative\Drivers\VerifierExt.sys (Microsoft Corporation)
DRV:64bit: - (UASPStor) – C:\Windows\SysNative\Drivers\uaspstor.sys (Microsoft Corporation)
DRV:64bit: - (acpiex) – C:\Windows\SysNative\Drivers\acpiex.sys (Microsoft Corporation)
DRV:64bit: - (mvumis) – C:\Windows\SysNative\Drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\Drivers\stexstor.sys (Promise Technology, Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\Drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (LSI_SSS) – C:\Windows\SysNative\Drivers\lsi_sss.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\Drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (EhStorTcgDrv) – C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:64bit: - (EhStorClass) – C:\Windows\SysNative\Drivers\EhStorClass.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\Drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (3ware) – C:\Windows\SysNative\Drivers\3ware.sys (LSI)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\Drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\Drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (CLFS) – C:\Windows\SysNative\Drivers\clfs.sys (Microsoft Corporation)
DRV:64bit: - (WFPLWFS) – C:\Windows\SysNative\Drivers\wfplwfs.sys (Microsoft Corporation)
DRV:64bit: - (vpci) – C:\Windows\SysNative\Drivers\vpci.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) – C:\Windows\SysNative\Drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (mshidumdf) – C:\Windows\SysNative\Drivers\mshidumdf.sys (Microsoft Corporation)
DRV:64bit: - (BasicDisplay) – C:\Windows\SysNative\Drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:64bit: - (HyperVideo) – C:\Windows\SysNative\Drivers\HyperVideo.sys (Microsoft Corporation)
DRV:64bit: - (BasicRender) – C:\Windows\SysNative\Drivers\BasicRender.sys (Microsoft Corporation)
DRV:64bit: - (gencounter) – C:\Windows\SysNative\Drivers\vmgencounter.sys (Microsoft Corporation)
DRV:64bit: - (kdnic) – C:\Windows\SysNative\Drivers\kdnic.sys (Microsoft Corporation)
DRV:64bit: - (acpitime) – C:\Windows\SysNative\Drivers\acpitime.sys (Microsoft Corporation)
DRV:64bit: - (npsvctrig) – C:\Windows\SysNative\Drivers\npsvctrig.sys (Microsoft Corporation)
DRV:64bit: - (WpdUpFltr) – C:\Windows\SysNative\Drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:64bit: - (acpipagr) – C:\Windows\SysNative\Drivers\acpipagr.sys (Microsoft Corporation)
DRV:64bit: - (hyperkbd) – C:\Windows\SysNative\Drivers\hyperkbd.sys (Microsoft Corporation)
DRV:64bit: - (SerCx) – C:\Windows\SysNative\Drivers\SerCx.sys (Microsoft Corporation)
DRV:64bit: - (SpbCx) – C:\Windows\SysNative\Drivers\SpbCx.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\Drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (BthHFEnum) – C:\Windows\SysNative\Drivers\bthhfenum.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) – C:\Windows\SysNative\Drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\Drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (wpcfltr) – C:\Windows\SysNative\Drivers\wpcfltr.sys (Microsoft Corporation)
DRV:64bit: - (BthLEEnum) – C:\Windows\SysNative\Drivers\BthLEEnum.sys (Microsoft Corporation)
DRV:64bit: - (NdisImPlatform) – C:\Windows\SysNative\Drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:64bit: - (MsLldp) – C:\Windows\SysNative\Drivers\mslldp.sys (Microsoft Corporation)
DRV:64bit: - (Ndu) – C:\Windows\SysNative\Drivers\Ndu.sys (Microsoft Corporation)
DRV:64bit: - (CLVirtualDrive) – C:\Windows\SysNative\Drivers\CLVirtualDrive.sys (CyberLink)
DRV:64bit: - (IntcDAud) – C:\Windows\SysNative\Drivers\IntcDAud.sys (Intel® Corporation)
DRV:64bit: - (RSP2STOR) – C:\Windows\SysNative\Drivers\RtsP2Stor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (RTL8168) – C:\Windows\SysNative\Drivers\Rt630x64.sys (Realtek )
DRV:64bit: - (wacmoumonitor) – C:\Windows\SysNative\Drivers\wacmoumonitor.sys (Wacom Technology)
DRV:64bit: - (wacommousefilter) – C:\Windows\SysNative\Drivers\wacommousefilter.sys (Wacom Technology)
DRV:64bit: - (wacomvhid) – C:\Windows\SysNative\Drivers\wacomvhid.sys (Wacom Technology)
DRV:64bit: - (WacomVKHid) – C:\Windows\SysNative\Drivers\WacomVKHid.sys (Wacom Technology)
DRV - (UrlFilter) – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\UrlFilter.sys (IObit.com)
DRV - (RegFilter) – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\RegFilter.sys (IObit.com)
DRV - (FileMonitor) – C:\Program Files (x86)\IObit\IObit Malware Fighter\Drivers\win7_amd64\FileMonitor.sys (IObit)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE:64bit: - HKLM\..\SearchScopes\{1BA75D25-C379-41AF-917E-E987D3B46E7F}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPNOT13/1
IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE - HKLM\..\SearchScopes\{1BA75D25-C379-41AF-917E-E987D3B46E7F}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT13/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;pc=HPNTDFJS
IE - HKCU\..\SearchScopes\{1BA75D25-C379-41AF-917E-E987D3B46E7F}: "URL" = http://www.amazon.com/s/ref=azs_osd_iea?ie…s={searchTerms}
IE - HKCU\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.com/web?q={searchterms}&…is&o;=HPNTDF
IE - HKCU\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo.com/search?p={searchTe…amp;type=HPNTDF
IE - HKCU\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.com/rover/1/711-154371-11896-2/4 ?mpre=http%3A%2F%2Fwww.ebay.com%2Fsch%2F%3F_nkw%3D{searchTerms}&keyword;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\windows\SysWOW64\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@authentec.com/ffwloplugin: C:\Program Files (x86)\HP SimplePass\npffwloplugin.dll ( HP)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI ipt;version=2.1.42: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@intel-webapi.intel.com/Intel WebAPI updater: C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll (Intel Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.21.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Motive.com/NpMotive,version=1.0: File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.145\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: File not found

FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\ESET\ESET Smart Security\Mozilla Thunderbird [2013/05/30 07:58:50 | 000,000,000 | —D | M]


========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.110\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Simple Pass (Enabled) = C:\Program Files (x86)\HP SimplePass\npffwloplugin.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIIPT.dll
CHR - plugin: Intel\u00AE Identity Protection Technology (Enabled) = C:\Program Files (x86)\Intel\Intel® Management Engine Components\IPT\npIntelWebAPIUpdater.dll
CHR - plugin: WildTangent Games App V2 Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Art Project, powered by Google = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aafjiaooblldgcephecfcafbmckcfeep\0.0.0.4_0\
CHR - Extension: Entanglement = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: Bejeweled = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\adpkifcfcacgmnggcbpbjbkdijciiigm\2_0\
CHR - Extension: Learn French - Tr\u00E8s Bien = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aeifanonhefcaphaeeknpklkfnjjmpec\1.46_0\
CHR - Extension: Sudoku = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\agdhembpgcpfegeigidembjopfhghnpj\1.0.1.0_0\
CHR - Extension: Pinboard Shooter = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahffkdnkciknmhknjheadfmnhkpohjbi\1.0.0_0\
CHR - Extension: Duolingo = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aiahmijlpehemcpleichkcokhegllfjl\1.0.10_0\
CHR - Extension: Unblock = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajpngmclhbnbjmejolfgfcocnneljhcj\1.0_0\
CHR - Extension: Angry Birds = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: Mahjong Words 2 = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\akoaibgodkfmengiiainfdbjmmamfall\1.0.0.1_0\
CHR - Extension: Word Search Puzzle = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\alcobafdkcddhiabfgnongafffchimnl\1.2_0\
CHR - Extension: Solitaire Mania = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\alnidleapopckkijonokikmnheanegph\1.5_0\
CHR - Extension: TooManyTabs for Chrome = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\amigcgbheognjmfkaieeeadojiibgbdp\2.0.0_0\
CHR - Extension: Google Docs = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Make Me Fast = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\apbfphfpbpkmpeljdopikeamjjgponla\0.0.43_0\
CHR - Extension: Google Drive = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: Spider Solitaire = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\bcopgabdbdohekgeabpbfhledmdahkpe\0.2.6_0\
CHR - Extension: TV = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\beobeededemalmllhkmnkinmfembdimh\1.0.12_0\
CHR - Extension: Quizlet = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\bgofflgeghkhocbociocnckocbjmomjh\4.1_0\
CHR - Extension: WOT = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\bhmmomiinigofkjcapegjjndpbikblnp\1.4.12_0\
CHR - Extension: YouTube = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Solitaire = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpebaehgfgkcmmjjknibibbjacnplim\1.4.3_0\
CHR - Extension: Chinese Checkers = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\bmehijmfedecboikadhjbnehgkimbife\1.0_0\
CHR - Extension: eBay Web App = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\bnadbgmffcofipfljniafanjcafjlbom\1.0.4_0\
CHR - Extension: HelloFax: 50 Free Fax Pages = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\bocmleclimfnadgmcdgecijlblfcmfnm\1.12_0\
CHR - Extension: Angry Birds Heikki = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\bolihcpdoncbpbhlofmolkpkhdkhppdm\1.0_0\
CHR - Extension: Freecell Solitaire = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\cabpjbpfakfhcfidnjahmdophhihafkh\1.0.0.1_0\
CHR - Extension: Math Mahjong = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbcfbhpnngegochhbdlanodnmijfplal\1.0.1.1_0\
CHR - Extension: Angry Birds Space = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\cbggfppgjaaechofekcaogbgmkkigoep\1.8_0\
CHR - Extension: Heidi's Infinite Sudoku = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ccbhekjfmokgloklnjnidfhlaofegeno\0.0.0.63_0\
CHR - Extension: BrainPOP Featured Movie = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\cdikkckjinnmjpgkjjpnfmmbcpbhmklf\2.0_0\
CHR - Extension: Tetris = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfpkpcnigdggonhlcmbekffepnaflofk\13.2334.9140_0\
CHR - Extension: Do Not Track = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckdcpbflcbeillmamogkpmdhnbeggfja\0.1.1_0\
CHR - Extension: WGNTV = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ckpdekaidkbmmbajdiddndeocofhddgd\1.2_0\
CHR - Extension: Crazy4Jigsaws = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\clgliemokfgimmfodoeboneoibjklncc\1.1.1_0\
CHR - Extension: Google Search = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Simply Word Search = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\demdpckmblghejnbehcejcldomjfopgl\1.0.0_0\
CHR - Extension: 20 Things I Learned About Browsers & the Web = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\dfdlnlenokgjjchimonbekcmnofmlibg\0.91_0\
CHR - Extension: Solitaire Card Games = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\dkelcbhdkpcdiiancfjhjcpdinbbfolp\1.0.0.6_0\
CHR - Extension: Little Alchemy light = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\dlinaifoeodggjcfoonifcjppkklkdkd\0.0.4_0\
CHR - Extension: Bomomo = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnalbhgkcocoepphagnnlaiomnnngeln\1_0\
CHR - Extension: Word Search = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnjkggjhcbohgnikmegjkodmakmimlkj\1.0.0.1_0\
CHR - Extension: Word Search = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\dnjkggjhcbohgnikmegjkodmakmimlkj\1.0.0.1_0\~
CHR - Extension: Solitairey = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\dofbnmhnoodmmlhflbcihicmbnhhinhp\2.2.7.6_0\
CHR - Extension: MaskMe = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\dpkiidbpeijnaaacjlfnijncdlkicejg\1.18.245_0\
CHR - Extension: Sudoku = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ebgekfpgahlglgbnfiaabkpioonoaima\1.4_0\
CHR - Extension: NYTimes = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ecmphppfkcfflgglcokcbdkofpfegoel\1.2.4_0\
CHR - Extension: Mahjongg = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\eegpopcingfghbompjfejakfeaolmbop\1.0.0.2_0\
CHR - Extension: Search All = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\eekjldapjblgadclklmgolijbagmdnfk\2.1.5_0\
CHR - Extension: Hearts Card Game = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehoogbeipinlfnddcoinniofcocmnbjf\1.1.0.0_0\
CHR - Extension: Hearts Card Game = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ehoogbeipinlfnddcoinniofcocmnbjf\1.1.0.0_0\~
CHR - Extension: Solitaire Games = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\eljmkmbmhmgmpmmbkagbobpmpocacdbo\1.0.0.3_0\
CHR - Extension: DoNotTrackMe = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\epanfjkfahimkgomnigadpkobaefekcd\2.2.9.520_0\
CHR - Extension: Pandora = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbangkleohkafngihneedemihgfeikcl\1.0_0\
CHR - Extension: Web Lab = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\fgacgeibpdjllcjckbmgecpahipdjabe\1.0_0\
CHR - Extension: Gpanion = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\fggkioanopfgmbgkgbeljijdhjkpkpob\2.3_0\
CHR - Extension: Full Screen Weather = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\fkkaebihfmbofclegkcfkkemepfehibg\1.3_0\
CHR - Extension: TimeMaps: World History Atlas = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\gcknipbpempcbnncdekkeimmpjggfaem\1.0.5_0\
CHR - Extension: Ancient Odyssey Mahjong = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\gejnoiphkikhmpkfpilploabdnnpfpgm\1.2_0\
CHR - Extension: Stopwatch = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ggnidjbcahhbnleinchgobfnabopeioh\3.6_0\
CHR - Extension: Planetarium = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\gheikhdfflhlbemfmhcfpeblehemeklp\1.1.2_0\
CHR - Extension: Click&Clean; = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\8.3_0\
CHR - Extension: Cut the Rope = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkddaofiamhgfjmaccfcfpfolpgbeomj\15_0\
CHR - Extension: 247 Solitaire = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdelbagmgokcoecefcaklpocihjmobcg\1.0.0.1_0\
CHR - Extension: Angry Birds Space HD = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\headjcpkijafflpiedpeefofgjfcbkkb\0.0.0.1_0\
CHR - Extension: VoiceNote - speech to text. = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\hfknjgplnkgjihghcidajejfmldhibfm\2.4.22_0\
CHR - Extension: Flixster = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgbpjlnkjhllfgfdmieompodgaefjcfh\1.0.6_0\
CHR - Extension: PDF Mergy = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgecghmkcdefnknohcimkoemhaofpoha\0.5.2_0\
CHR - Extension: Tate Art Slideshow = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\hgfbniacchiboaeoaoaejhggfepbbmkj\0.0.0.8_0\
CHR - Extension: Pathuku = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\hkiilmogcdkeefnbemdagpmcediekadb\1.24.0.0_0\
CHR - Extension: Angry Birds Rio = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlbmidndnnlgjoedckgkmdhgaphfbkaf\1.0_0\
CHR - Extension: Cargo Bridge: Armor Games Edition = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\hlpiaibleklmjieibbnmkignbggodmmj\2.1.1_0\
CHR - Extension: Mahjong Words = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\hmefkohhpkdnaieghlijadogfapogebe\1.0.0.1_0\
CHR - Extension: Crackle = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibfamoapbmmmlknoopmmfofgladlinic\7.1.7_0\
CHR - Extension: Word Search = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ibgcembfplpfknjdcjifgfgpnijeppei\7_0\
CHR - Extension: Google Play Music = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\icppfcnhkcmnfdhfhphakoifcfokfdhg\5.1_0\
CHR - Extension: Angry Birds = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\idbfngcbpbkjmachgoephcmbjjfkgnfe\1.0_0\
CHR - Extension: Sudoku for Google Chrome\u2122 = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifaabgmcffhggbfgjknkgenljelbocin\1.5_0\
CHR - Extension: World of Solitaire = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ifbnllnaaaohekjkcpfdllhhjijnidgn\1.0.1_0\
CHR - Extension: WeatherBug = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ihdkejbciahopmbagpnjmmkkdpfpaaak\2.0.5_0\
CHR - Extension: Match 3 Games = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikgkgfnngoolfjpifmmpnebikjghpbdi\1.2_0\
CHR - Extension: UR Checkers = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ikmclhiijhbnkalfjmalejgpgbelgaao\1.0_0\
CHR - Extension: Test & Improve Your Knowledge = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ilagnajmjdobfhidldegnpomkhinccdi\1.3_0\
CHR - Extension: Master of Sudoku = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ioojgmelmdplpbpipdmeigaeniljlicf\1.0_0\
CHR - Extension: Sudoku X = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\iplikifojjiaagikabaeopcnoocpeahi\1_0\
CHR - Extension: Website Logon = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jaaieiajnhcnimjgfmjpccjmmfkploci\6.0.100_0\
CHR - Extension: Free Online PDF Tools = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jddfpnmfhodaljeelokfceepbeapgbdn\1.0.1.2_0\
CHR - Extension: Unblock 2 = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jhkhhpjhohechcaihlfieiikgijenaii\1.0_0\
CHR - Extension: Word Search = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jigekglfaceoiilbabcffhhakffifpci\1.1_0\
CHR - Extension: Pocket = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jijgclgmgjipgefcnnnibgllfonlfdap\1.0.1_0\
CHR - Extension: Sudoku = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\jknjmdhcdfnhedcghbjbklllbliheppm\1.0.1_0\
CHR - Extension: HelloSign: Online signatures made easy = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\kajjckmbclbffbpecfbiecehkfgopppd\1.12_0\
CHR - Extension: Cargo Bridge = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\keembkgclppcbilkekfgpobhldjjhpmn\1.5.7_0\
CHR - Extension: Test Your General Knowledge = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\kkbhhjpegajcfmgooeaeepdkmhjdelpe\1.0.0.0_0\
CHR - Extension: Mahjong 3D = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\lajfhjlefjpecindkbgbfllbejfhbkoh\1.0.2_0\
CHR - Extension: InvisibleHand = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\lghjfnfolmcikomdjmoiemllfnlmmoko\3.8.31_0\
CHR - Extension: Free Password Generator = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\licdodckeablhnjkfhmnbpapokiemncd\1.0.2_0\
CHR - Extension: Numerics Calculator & Converter = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\liglcienpnkhdajdfmnpbgmpjglonipe\4.3.4_0\
CHR - Extension: Logical Games = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ljlpibpofifaebepnejjaahdhoeelnae\1.2_0\
CHR - Extension: Google Maps = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\lneaknkopdijkpnocmklfnjbeapigfbh\5.2.7_0\
CHR - Extension: The Fancy Pants Adventure: World 2 = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\loamdenijebhollnjgehcfbnpeelfhlk\14_0\
CHR - Extension: Sprocket Rocket = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\lpdichmkdadfihhbgllepglgbkonlehe\1.0_0\
CHR - Extension: Word Seek = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mabcpjfkciefmefgkfneaogfmbljljif\0.4.0_0\
CHR - Extension: Harmony = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mbbibdblnnlapclckbdennhlbcnkkgcn\6_0\
CHR - Extension: Poppit = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: 3D Solar System Web = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdaaepplopehigjgkolniddiadbbkphd\0.50_0\
CHR - Extension: Google Dictionary (by Google) = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja\3.0.17_0\
CHR - Extension: Google Mail Checker = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\4.4.0_0\
CHR - Extension: Quick Note = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mijlebbfndhelmdpmllgcfadlkankhok\1.4.8_0\
CHR - Extension: Mahjong = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mimcabmfjaeoldnchodmelflfjmgaojh\5.0_0\
CHR - Extension: Google Drawings = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkaakpdehdafacodkgkpghoibnmamcme\0.8_0\
CHR - Extension: Hearts = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkkbmdeidonbobilknidkpldmecbiilm\1.0.0.0_0\
CHR - Extension: FastestChrome - Browse Faster = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmffncokckfccddfenhkhnllmlobdahm\7.1.9_0\
CHR - Extension: Google Play Books = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mmimngoggfoobjdlefbcabngfnmieonb\1.1.8_0\
CHR - Extension: Stream Master = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\mocgpjcogkajdhiabjjnobcacnmdagfn\1.0.1.12_0\
CHR - Extension: Tower of Hanoi = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nbadepndmmpjnpeokjkcmndfbgicacod\1_0\
CHR - Extension: Mahjong Solitaire = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\neojceinbonpjjcokpokpeobkhcpiloc\1.0.0.2_0\
CHR - Extension: Advanced SystemCare Surfing Protection = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfengeggddojhakldhlpjdlddgkkjkdd\1.0.0_0\
CHR - Extension: Lumosity = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nffmfbhcjemfledhndnpllechagamlfp\1.1_0\
CHR - Extension: Zoho Docs = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\nflhfcjfjkohgcgpldeffhlgeooejomn\1.1_0\
CHR - Extension: Micro Expression Recognition Application = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ngkcbihjelakpbponjhpmkkmopghnpip\1.0_0\
CHR - Extension: Pocket (formerly Read It Later) = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\niloccemoadcdkdjlinkgdfekeahmflj\1.5.4_0\
CHR - Extension: Picky Wallpapers = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\odklcfojpedohplkimfdpcamkjnhanaj\1.0.0_0\
CHR - Extension: Where is the red = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ohpblkkbmfceapbolfogbfpkcjdlhonb\2_0\
CHR - Extension: Origami Player = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\oiomepakkenneiifjocbinkmmampfbdn\2.4_0\
CHR - Extension: Daily Jigsaw = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojhhdobknmndpiljphdkcdmmlkphklfh\1.0.1_0\
CHR - Extension: Offline Solitaire = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ojldfpglenpceffckkjhajofdbpkfgmn\8_0\
CHR - Extension: Mahjong Solitaire = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\oklmlcjbcklepibadjjhfmbhlgjjjbci\1.0.0_0\
CHR - Extension: Towers of Hanoi = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\olkljogjenmmlkhkndneimnepljcfcao\2.0.6_0\
CHR - Extension: Spring Mahjong = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\oohmgpjbkliggjliakneoaedilbaihhl\1.0.0.8_0\
CHR - Extension: Word Search Puzzles = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pbeenmjejnjlfakffihmbonolbdcbbil\1.2_0\
CHR - Extension: Click&Clean; App = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp\8.0_0\
CHR - Extension: Viewster - Watch Free Movies Online = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfiekkcjcnhbjofcjcfblhcccjkpkheh\1.8_0\
CHR - Extension: Outlook.com = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfpeapihoiogbcmdmnibeplnikfnhoge\1.0.2_0\
CHR - Extension: Weather Underground = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjejbgheonogbpfkkjigbmahaljipoej\1.6_0\
CHR - Extension: Gmail = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
CHR - Extension: Cargo Bridge 2 = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pmphjijgcdpmmnfjbemolkdiidinogml\1.0.0_0\
CHR - Extension: Bejeweled = C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\pnpmgknohfcbfbkjphkbignoolkicajl\2.9_0\

O1 HOSTS File: ([2013/01/30 19:40:20 | 000,001,864 | —- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O1 - Hosts: 127.0.0.1 3dns-1.adobe.com 3dns-2.adobe.com 3dns-3.adobe.com 3dns-4.adobe.com 3dns.adobe.com activate-sea.adobe.com activate-sjc0.adobe.com activate.adobe.com activate.wip.adobe.com activate.wip1.adobe.com activate.wip2.adobe.com activate.wip3.adobe.com activate.wip4.adobe.com adobe-dns-1.adobe.com adobe-dns-2.adobe.com
O1 - Hosts: 127.0.0.1 adobe-dns-3.adobe.com adobe-dns-4.adobe.com adobe-dns.adobe.com adobeereg.com crl.verisign.net ereg.adobe.com ereg.wip.adobe.com ereg.wip1.adobe.com ereg.wip2.adobe.com ereg.wip3.adobe.com ereg.wip4.adobe.com hl2rcv.adobe.com lm.licenses.adobe.com lmlicenses.wip4.adobe.com na2m-pr.licenses.adobe.com
O1 - Hosts: 127.0.0.1 ood.opsource.net practivate.adobe practivate.adobe.com practivate.adobe.ipp practivate.adobe.newoa practivate.adobe.ntp wip.adobe.com wip1.adobe.com wip2.adobe.com wip3.adobe.com wip4.adobe.com wwis-dubc1-vip60.adobe.com www.adobeereg.com www.wip.adobe.com www.wip1.adobe.com
O1 - Hosts: 127.0.0.1 www.wip2.adobe.com www.wip3.adobe.com www.wip4.adobe.com
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Advanced SystemCare Browser Protection) - {BA0C978D-D909-49B6-AFE2-8BDE245DC7E6} - C:\Program Files (x86)\IObit\Advanced SystemCare 6\BrowerProtect\ASCPlugin_Protection.dll (IObit)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BTMTrayAgent] C:\Program Files (x86)\Intel\Bluetooth\btmshellex.dll (Motorola Solutions, Inc.)
O4:64bit: - HKLM..\Run: [egui] C:\Program Files\ESET\ESET Smart Security\egui.exe (ESET)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [PSQLLauncher] C:\Program Files\Protector Suite\launcher.exe (Authentec Inc.)
O4 - HKLM..\Run: [] File not found
O4 - HKLM..\Run: [AdobeCS6ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS6ServiceManager\CS6ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [ArcSoft Connection Service] C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACDaemon.exe (ArcSoft Inc.)
O4 - HKLM..\Run: [IObit Malware Fighter] C:\Program Files (x86)\IObit\IObit Malware Fighter\IMF.exe (IObit)
O4 - HKLM..\Run: [RemoteControl10] C:\Program Files (x86)\CyberLink\PowerDVD10\PDVD10Serv.exe (CyberLink Corp.)
O4 - HKLM..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe" File not found
O4 - HKLM..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Advanced SystemCare 6] C:\Program Files (x86)\IObit\Advanced SystemCare 6\ASCTray.exe (IObit)
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\DTLite.exe (DT Soft Ltd)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm ()
O8 - Extra context menu item: Send to Bluetooth - C:\Program Files (x86)\Intel\Bluetooth\btSendToObject.htm ()
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files%20(x86)/VISTA%20prog-32%20bit/Bejeweled%202/Images/stg_drm.ocx (SpinTop DRM Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{520F34E4-79A3-4AD0-AFFC-7A131A10222C}: DhcpNameServer = 192.168.1.254
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O20:64bit: - Winlogon\Notify\psfus: DllName - (C:\Program Files\Protector Suite\psqlpwd.dll) - C:\Program Files\Protector Suite\psqlpwd.dll (Authentec Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:64bit: DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:64bit: NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
NetSvcs:64bit: SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/06/12 22:23:26 | 000,000,000 | —D | C] – C:\Windows\tasks\TaskDisabled
[2013/06/12 22:19:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\IObit Malware Fighter
[2013/06/12 21:34:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Earth
[2013/06/12 01:21:51 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Desktop\New folder
[2013/06/11 22:03:33 | 000,693,112 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/06/11 22:03:33 | 000,078,200 | —- | C] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/06/11 20:23:23 | 001,889,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/06/11 20:23:22 | 001,255,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/06/11 20:23:22 | 001,013,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/06/11 20:23:22 | 000,141,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/06/11 20:23:09 | 013,644,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.UI.Xaml.dll
[2013/06/11 20:23:06 | 010,788,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.UI.Xaml.dll
[2013/06/11 20:23:06 | 001,131,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentServer.dll
[2013/06/11 20:23:05 | 010,116,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\twinui.dll
[2013/06/11 20:23:01 | 000,470,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netprofmsvc.dll
[2013/06/11 20:22:59 | 008,857,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\twinui.dll
[2013/06/11 20:22:59 | 002,305,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/06/11 20:22:59 | 002,035,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/06/11 20:22:59 | 000,760,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2013/06/11 20:22:58 | 000,446,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\USBHUB3.SYS
[2013/06/11 20:22:58 | 000,328,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ubpm.dll
[2013/06/11 20:22:58 | 000,014,848 | —- | C] (Microsoft) – C:\Windows\SysWow64\rars.rs
[2013/06/11 20:22:58 | 000,014,848 | —- | C] (Microsoft) – C:\Windows\SysNative\rars.rs
[2013/06/11 20:22:56 | 000,812,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Magnify.exe
[2013/06/11 20:22:56 | 000,708,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentExtensions.dll
[2013/06/11 20:22:56 | 000,621,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapi.dll
[2013/06/11 20:22:56 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\BCP47Langs.dll
[2013/06/11 20:22:56 | 000,330,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\stobject.dll
[2013/06/11 20:22:56 | 000,247,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ubpm.dll
[2013/06/11 20:22:56 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netplwiz.dll
[2013/06/11 20:22:55 | 000,560,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfmp4srcsnk.dll
[2013/06/11 20:22:55 | 000,501,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DevicePairing.dll
[2013/06/11 20:22:55 | 000,284,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\spaceport.sys
[2013/06/11 20:22:55 | 000,213,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\UCX01000.SYS
[2013/06/11 20:22:55 | 000,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netplwiz.dll
[2013/06/11 20:22:55 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psmsrv.dll
[2013/06/11 20:22:54 | 001,619,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2013/06/11 20:22:54 | 000,758,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Magnify.exe
[2013/06/11 20:22:54 | 000,449,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DevicePairing.dll
[2013/06/11 20:22:54 | 000,419,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\intl.cpl
[2013/06/11 20:22:54 | 000,122,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\biwinrt.dll
[2013/06/11 20:22:54 | 000,120,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AuthHost.exe
[2013/06/11 20:22:54 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\hidclass.sys
[2013/06/11 20:22:54 | 000,058,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2013/06/11 20:22:53 | 000,411,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfmp4srcsnk.dll
[2013/06/11 20:22:53 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\intl.cpl
[2013/06/11 20:22:53 | 000,309,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\BCP47Langs.dll
[2013/06/11 20:22:53 | 000,251,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUSettingsProvider.dll
[2013/06/11 20:22:53 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\bisrv.dll
[2013/06/11 20:22:53 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\storewuauth.dll
[2013/06/11 20:22:53 | 000,141,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2013/06/11 20:22:53 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuwebv.dll
[2013/06/11 20:22:53 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2013/06/11 20:22:53 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\biwinrt.dll
[2013/06/11 20:22:53 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wudriver.dll
[2013/06/11 20:22:53 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2013/06/11 20:22:53 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapp.exe
[2013/06/11 20:22:53 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\muifontsetup.dll
[2013/06/11 20:22:53 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\muifontsetup.dll
[2013/06/11 20:22:10 | 000,888,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\autochk.exe
[2013/06/11 20:22:10 | 000,542,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\untfs.dll
[2013/06/11 20:22:09 | 001,257,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/06/11 20:22:09 | 000,793,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\autochk.exe
[2013/06/11 20:22:09 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\untfs.dll
[2013/06/11 20:22:01 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/11 20:21:58 | 000,915,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\uxtheme.dll
[2013/06/11 20:21:58 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/06/11 20:21:58 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/11 20:21:58 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/11 20:21:58 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UXInit.dll
[2013/06/11 20:21:58 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/11 20:21:58 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UXInit.dll
[2013/06/11 20:21:56 | 001,300,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gdi32.dll
[2013/06/11 20:21:55 | 000,733,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/06/11 20:21:54 | 000,144,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tssdisai.dll
[2013/06/11 20:20:36 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/06/11 20:20:36 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/06/08 02:02:00 | 000,000,000 | —D | C] – C:\Users\Pic Chic\AppData\Roaming\OpenOffice.org
[2013/06/08 02:00:15 | 000,000,000 | –SD | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\OpenOffice.org 3.4.1
[2013/06/08 01:58:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\OpenOffice.org 3
[2013/06/08 01:57:37 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Desktop\OpenOffice.org 3.4.1 (en-US) Installation Files
[2013/06/08 00:47:09 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Desktop\PULMONARY
[2013/06/08 00:35:01 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Desktop\HP BLOAT
[2013/06/07 05:38:22 | 000,000,000 | —D | C] – C:\ProgramData\ALM
[2013/06/07 05:34:53 | 000,000,000 | —D | C] – C:\adobeTemp
[2013/06/07 05:33:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Adobe AIR
[2013/06/07 04:42:30 | 000,025,928 | —- | C] (Malwarebytes Corporation) – C:\Windows\SysNative\drivers\mbam.sys
[2013/06/07 04:42:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2013/06/06 17:47:42 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Documents\D's HDMI REBATE
[2013/06/06 14:12:19 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Desktop\Autoruns
[2013/06/01 08:26:12 | 000,000,000 | —D | C] – C:\Users\Pic Chic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Super Meat Boy
[2013/06/01 06:28:30 | 000,000,000 | R–D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel PROSet Wireless
[2013/06/01 06:28:15 | 000,000,000 | —D | C] – C:\Program Files (x86)\Cisco
[2013/06/01 06:28:13 | 000,000,000 | —D | C] – C:\ProgramData\Intel.sav
[2013/06/01 06:26:45 | 000,000,000 | —D | C] – C:\ProgramData\Package Cache
[2013/06/01 06:25:51 | 000,000,000 | —D | C] – C:\ProgramData\Intel® Update Manager
[2013/06/01 06:25:29 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel Corporation
[2013/06/01 06:25:23 | 000,000,000 | —D | C] – C:\Program Files\Intel Corporation
[2013/06/01 05:43:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\SystemRequirementsLab
[2013/06/01 05:42:35 | 000,000,000 | —D | C] – C:\Users\Pic Chic\AppData\Roaming\SystemRequirementsLab
[2013/06/01 05:39:56 | 000,000,000 | —D | C] – C:\ProgramData\Sun
[2013/06/01 05:39:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Java
[2013/06/01 05:39:51 | 000,866,720 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/06/01 05:39:51 | 000,788,896 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/06/01 05:39:51 | 000,263,584 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/06/01 05:39:49 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/06/01 05:39:49 | 000,174,496 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/06/01 05:39:49 | 000,095,648 | —- | C] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/06/01 05:39:42 | 000,000,000 | —D | C] – C:\Program Files (x86)\Java
[2013/06/01 04:59:16 | 000,671,744 | —- | C] (IDT, Inc.) – C:\Windows\SysNative\stapi64.dll
[2013/06/01 04:59:16 | 000,499,200 | —- | C] (IDT, Inc.) – C:\Windows\SysNative\stcplx64.dll
[2013/06/01 04:59:16 | 000,224,256 | —- | C] (IDT, Inc.) – C:\Windows\SysNative\HPToneCtrls64.dll
[2013/06/01 04:59:15 | 007,986,176 | —- | C] (IDT, Inc.) – C:\Windows\SysNative\IDTNGUI.exe
[2013/06/01 04:59:15 | 007,712,768 | —- | C] (IDT, Inc.) – C:\Windows\SysNative\IDTNHP.dll
[2013/06/01 04:59:15 | 006,085,632 | —- | C] (IDT, Inc.) – C:\Windows\SysNative\stlang64.dll
[2013/06/01 04:59:15 | 002,213,376 | —- | C] (IDT, Inc.) – C:\Windows\SysNative\IDTNX.dll
[2013/06/01 04:59:15 | 002,188,800 | —- | C] (IDT, Inc.) – C:\Windows\SysNative\stapo64.dll
[2013/06/01 04:59:15 | 001,821,184 | —- | C] (IDT, Inc.) – C:\Windows\SysNative\IDTNC64.cpl
[2013/06/01 04:59:15 | 001,664,000 | —- | C] (IDT, Inc.) – C:\Windows\sttray64.exe
[2013/06/01 04:59:15 | 000,464,384 | —- | C] (SRS Labs, Inc.) – C:\Windows\SysNative\slapoi64.dll
[2013/06/01 04:59:15 | 000,253,952 | —- | C] (IDT, Inc.) – C:\Windows\SysNative\IDTNJ.exe
[2013/06/01 04:58:36 | 000,000,000 | —D | C] – C:\Program Files\IDT
[2013/06/01 03:31:47 | 000,542,208 | —- | C] (IDT, Inc.) – C:\Windows\SysNative\drivers\stwrt64.sys
[2013/06/01 03:31:46 | 000,255,488 | —- | C] (IDT, Inc.) – C:\Windows\SysNative\st646425.dll
[2013/06/01 03:18:56 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Intel Corporation
[2013/06/01 03:10:34 | 000,000,000 | —D | C] – C:\Program Files (x86)\SP60050
[2013/06/01 02:34:33 | 000,276,288 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\IntelCpHeciSvc.exe
[2013/06/01 02:34:33 | 000,241,664 | —- | C] (Intel Corporation) – C:\Windows\SysNative\IntelOpenCL64.dll
[2013/06/01 02:34:33 | 000,195,584 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\IntelOpenCL32.dll
[2013/06/01 02:34:32 | 000,116,224 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxCoIn_v2857.dll
[2013/06/01 02:34:31 | 000,509,248 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxsrvc.exe
[2013/06/01 02:34:31 | 000,439,296 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrrus.lrc
[2013/06/01 02:34:31 | 000,439,296 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrrom.lrc
[2013/06/01 02:34:31 | 000,438,784 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrsky.lrc
[2013/06/01 02:34:31 | 000,438,784 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrptg.lrc
[2013/06/01 02:34:31 | 000,438,784 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrplk.lrc
[2013/06/01 02:34:31 | 000,438,784 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrnld.lrc
[2013/06/01 02:34:31 | 000,437,760 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrtrk.lrc
[2013/06/01 02:34:31 | 000,437,760 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrsve.lrc
[2013/06/01 02:34:31 | 000,437,760 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrslv.lrc
[2013/06/01 02:34:31 | 000,437,760 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrptb.lrc
[2013/06/01 02:34:31 | 000,437,760 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrnor.lrc
[2013/06/01 02:34:31 | 000,437,248 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrtha.lrc
[2013/06/01 02:34:31 | 000,431,104 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrkor.lrc
[2013/06/01 02:34:31 | 000,410,624 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxTMM.dll
[2013/06/01 02:34:31 | 000,170,304 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxtray.exe
[2013/06/01 02:34:31 | 000,063,488 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxsrvc.dll
[2013/06/01 02:34:30 | 009,007,616 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxress.dll
[2013/06/01 02:34:30 | 000,440,320 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrell.lrc
[2013/06/01 02:34:30 | 000,439,808 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrfra.lrc
[2013/06/01 02:34:30 | 000,439,808 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxresn.lrc
[2013/06/01 02:34:30 | 000,438,784 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrita.lrc
[2013/06/01 02:34:30 | 000,438,784 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrhrv.lrc
[2013/06/01 02:34:30 | 000,438,784 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrdeu.lrc
[2013/06/01 02:34:30 | 000,438,272 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrhun.lrc
[2013/06/01 02:34:30 | 000,438,272 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrfin.lrc
[2013/06/01 02:34:30 | 000,438,272 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrcsy.lrc
[2013/06/01 02:34:30 | 000,437,248 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrdan.lrc
[2013/06/01 02:34:30 | 000,435,712 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrheb.lrc
[2013/06/01 02:34:30 | 000,432,128 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrjpn.lrc
[2013/06/01 02:34:30 | 000,429,056 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrcht.lrc
[2013/06/01 02:34:30 | 000,286,208 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrenu.lrc
[2013/06/01 02:34:29 | 000,441,152 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxpers.exe
[2013/06/01 02:34:29 | 000,435,712 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrara.lrc
[2013/06/01 02:34:29 | 000,428,544 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxrchs.lrc
[2013/06/01 02:34:29 | 000,386,048 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxpph.dll
[2013/06/01 02:34:29 | 000,330,240 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\igfxdv32.dll
[2013/06/01 02:34:29 | 000,251,712 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxext.exe
[2013/06/01 02:34:29 | 000,142,336 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxdo.dll
[2013/06/01 02:34:29 | 000,028,672 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxexps.dll
[2013/06/01 02:34:29 | 000,025,088 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\igfxexps32.dll
[2013/06/01 02:34:28 | 027,664,896 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igdrcl64.dll
[2013/06/01 02:34:28 | 027,643,904 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\igdrcl32.dll
[2013/06/01 02:34:28 | 027,435,520 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igdfcl64.dll
[2013/06/01 02:34:28 | 021,816,320 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\igdfcl32.dll
[2013/06/01 02:34:28 | 012,604,928 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igdumd64.dll
[2013/06/01 02:34:28 | 011,040,256 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\igdumd32.dll
[2013/06/01 02:34:28 | 005,338,848 | —- | C] (Intel Corporation) – C:\Windows\SysNative\drivers\igdkmd64.sys
[2013/06/01 02:34:28 | 003,582,976 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igdbcl64.dll
[2013/06/01 02:34:28 | 002,899,968 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\igdbcl32.dll
[2013/06/01 02:34:28 | 000,441,856 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxdev.dll
[2013/06/01 02:34:28 | 000,126,976 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igfxcpl.cpl
[2013/06/01 02:34:27 | 012,836,864 | —- | C] (Intel Corporation) – C:\Windows\SysNative\igd10umd64.dll
[2013/06/01 02:34:27 | 011,593,728 | —- | C] (Intel Corporation) – C:\Windows\SysNative\ig7icd64.dll
[2013/06/01 02:34:27 | 011,158,528 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\igd10umd32.dll
[2013/06/01 02:34:27 | 008,577,536 | —- | C] (Intel Corporation) – C:\Windows\SysWow64\ig7icd32.dll
[2013/06/01 02:34:27 | 005,902,656 | —- | C] (Intel Corporation) – C:\Windows\SysNative\GfxUI.exe
[2013/06/01 02:34:27 | 000,398,656 | —- | C] (Intel Corporation) – C:\Windows\SysNative\hkcmd.exe
[2013/06/01 02:34:27 | 000,173,568 | —- | C] (Intel Corporation) – C:\Windows\SysNative\gfxSrvc.dll
[2013/06/01 02:34:27 | 000,110,592 | —- | C] (Intel Corporation) – C:\Windows\SysNative\hccutils.dll
[2013/06/01 02:34:21 | 000,184,640 | —- | C] (Intel Corporation) – C:\Windows\SysNative\difx64.exe
[2013/06/01 02:10:20 | 000,650,808 | —- | C] (Intel Corporation) – C:\Windows\SysNative\drivers\iaStorA.sys
[2013/06/01 02:08:22 | 000,000,000 | -H-D | C] – C:\Users\Public\Documents\YouCam
[2013/05/31 23:21:59 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Desktop\NEWEGG VOIDED ORDER
[2013/05/31 23:20:54 | 000,092,536 | —- | C] (CyberLink) – C:\Windows\SysNative\drivers\CLVirtualDrive.sys
[2013/05/31 01:51:07 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Documents\MINI WHEATS SETTLEMENT
[2013/05/31 01:18:01 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Documents\NEWEGG ORDER 5 30 2013 HDMI AND PRINT
[2013/05/31 00:43:19 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Documents\NEWEGG HDMI REBATE-JAN 6 1 2013
[2013/05/30 07:58:35 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ESET
[2013/05/30 07:58:34 | 000,000,000 | —D | C] – C:\ProgramData\ESET
[2013/05/28 13:50:28 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Documents\ENDO-LIDODERM APPL 05 28 2013
[2013/05/23 01:01:03 | 000,000,000 | —D | C] – C:\Users\Pic Chic\AppData\Roaming\foobar2000
[2013/05/23 01:00:50 | 000,000,000 | —D | C] – C:\Program Files (x86)\foobar2000
[2013/05/22 22:02:38 | 000,000,000 | —D | C] – C:\Users\Pic Chic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\IconLover
[2013/05/22 22:02:35 | 000,000,000 | —D | C] – C:\Program Files (x86)\IconLover
[2013/05/22 17:25:43 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Desktop\ESET Customer Care
[2013/05/21 07:34:22 | 000,000,000 | —D | C] – C:\Users\Pic Chic\AppData\Local\MigWiz
[2013/05/21 07:23:43 | 000,000,000 | R–D | C] – C:\Users\Pic Chic\Documents\Scanned Documents
[2013/05/21 07:23:43 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Documents\Fax
[2013/05/20 10:55:15 | 000,000,000 | —D | C] – C:\Users\Pic Chic\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games
[2013/05/20 10:28:30 | 000,000,000 | R–D | C] – C:\Users\Pic Chic\Desktop\ESET LOGS
[2013/05/19 08:06:31 | 000,000,000 | —D | C] – C:\Program Files (x86)\Kaspersky Lab
[2013/05/19 06:01:35 | 000,000,000 | —D | C] – C:\Users\Pic Chic\AppData\Roaming\IDT
[2013/05/19 02:56:34 | 003,552,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\tquery.dll
[2013/05/19 02:56:33 | 014,267,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wmp.dll
[2013/05/19 02:56:31 | 011,878,912 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wmp.dll
[2013/05/19 02:56:30 | 002,107,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssrch.dll
[2013/05/19 02:56:28 | 002,767,360 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\tquery.dll
[2013/05/19 02:56:28 | 001,593,344 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssrch.dll
[2013/05/19 02:56:27 | 001,829,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2013/05/19 02:56:27 | 001,444,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MSAudDecMFT.dll
[2013/05/19 02:56:21 | 001,113,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MSAudDecMFT.dll
[2013/05/19 02:56:21 | 000,306,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kd_02_10ec.dll
[2013/05/19 02:56:19 | 000,446,792 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AudioSes.dll
[2013/05/19 02:56:19 | 000,403,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssph.dll
[2013/05/19 02:56:19 | 000,298,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rsaenh.dll
[2013/05/19 02:56:18 | 000,373,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchProtocolHost.exe
[2013/05/19 02:56:17 | 000,489,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AudioEng.dll
[2013/05/19 02:56:16 | 000,435,200 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssph.dll
[2013/05/19 02:56:16 | 000,367,616 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\conhost.exe
[2013/05/19 02:56:16 | 000,172,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dwmredir.dll
[2013/05/19 02:56:15 | 000,595,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.Networking.dll
[2013/05/19 02:56:15 | 000,253,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\audiodg.exe
[2013/05/19 02:56:14 | 000,804,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RecoveryDrive.exe
[2013/05/19 02:56:13 | 001,403,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.efi
[2013/05/19 02:56:13 | 001,267,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.exe
[2013/05/19 02:56:13 | 000,456,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wpncore.dll
[2013/05/19 02:56:13 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.Networking.BackgroundTransfer.dll
[2013/05/19 02:56:12 | 001,217,328 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.efi
[2013/05/19 02:56:12 | 001,093,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.exe
[2013/05/19 02:56:12 | 000,523,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/05/19 02:56:11 | 000,659,456 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mssvp.dll
[2013/05/19 02:56:11 | 000,503,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ci.dll
[2013/05/19 02:56:11 | 000,468,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MFMediaEngine.dll
[2013/05/19 02:56:11 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fhengine.dll
[2013/05/19 02:56:11 | 000,196,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dmvdsitf.dll
[2013/05/19 02:56:10 | 000,411,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.Networking.dll
[2013/05/19 02:56:09 | 000,281,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfreadwrite.dll
[2013/05/19 02:56:09 | 000,268,800 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.Networking.BackgroundTransfer.dll
[2013/05/19 02:56:09 | 000,169,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AudioEndpointBuilder.dll
[2013/05/19 02:56:09 | 000,126,464 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Robocopy.exe
[2013/05/19 02:56:09 | 000,123,880 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wscapi.dll
[2013/05/19 02:56:09 | 000,077,960 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdvm.dll
[2013/05/19 02:56:08 | 000,210,432 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iuilp.dll
[2013/05/19 02:56:08 | 000,197,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\SearchFilterHost.exe
[2013/05/19 02:56:08 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Robocopy.exe
[2013/05/19 02:56:06 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/05/19 02:56:06 | 000,214,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfreadwrite.dll
[2013/05/19 02:56:06 | 000,155,648 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dmvdsitf.dll
[2013/05/19 02:56:06 | 000,086,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kdnet.dll
[2013/05/19 02:56:01 | 000,745,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssvp.dll
[2013/05/19 02:56:01 | 000,414,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\GenuineCenter.dll
[2013/05/19 02:56:01 | 000,361,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\MFMediaEngine.dll
[2013/05/19 02:56:01 | 000,050,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\fmifs.dll
[2013/05/19 02:56:01 | 000,041,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\fmifs.dll
[2013/05/19 02:56:01 | 000,013,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msshooks.dll
[2013/05/19 02:56:00 | 000,096,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mssprxy.dll
[2013/05/19 02:56:00 | 000,065,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msscntrs.dll
[2013/05/19 02:56:00 | 000,010,752 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\msshooks.dll
[2013/05/19 02:54:16 | 000,222,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\shdocvw.dll
[2013/05/19 02:54:15 | 000,112,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\consent.exe
[2013/05/19 02:53:01 | 006,987,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/05/18 21:18:00 | 000,000,000 | —D | C] – C:\Users\Pic Chic\Desktop\ProcessExplorer
[2013/05/18 20:34:37 | 000,000,000 | —D | C] – C:\Users\Pic Chic\AppData\Roaming\Malwarebytes
[2013/05/18 20:34:34 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/05/15 16:37:47 | 002,851,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\esent.dll
[2013/05/15 16:37:47 | 002,382,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\esent.dll
[3 C:\Users\Pic Chic\AppData\Local\*.tmp files -> C:\Users\Pic Chic\AppData\Local\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2013/06/13 22:19:23 | 000,001,435 | —- | M] () – C:\Users\Pic Chic\Desktop\OTL.exe - Shortcut.lnk
[2013/06/13 22:01:12 | 000,020,068 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/06/13 21:58:11 | 000,000,908 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/06/13 21:56:03 | 268,435,456 | -HS- | M] () – C:\swapfile.sys
[2013/06/13 21:56:00 | 2484,092,927 | -HS- | M] () – C:\hiberfil.sys
[2013/06/13 21:35:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/06/12 22:19:28 | 000,001,189 | —- | M] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2013/06/11 22:05:28 | 005,075,608 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/06/11 20:03:21 | 000,000,493 | —- | M] () – C:\Users\Pic Chic\Desktop\Personalization - Shortcut.lnk
[2013/06/08 01:11:51 | 000,001,129 | —- | M] () – C:\Users\Pic Chic\Desktop\procexp.exe - Shortcut.lnk
[2013/06/08 00:11:36 | 000,001,546 | —- | M] () – C:\Users\Pic Chic\Desktop\Illustrator.lnk
[2013/06/07 21:57:54 | 000,001,923 | —- | M] () – C:\Users\Pic Chic\Desktop\Desktop Wallpaper - Shortcut.lnk
[2013/06/07 20:21:55 | 000,128,941 | —- | M] () – C:\Users\Pic Chic\Desktop\SKMBT_50113052410240.pdf
[2013/06/07 04:42:32 | 000,001,131 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/06/04 17:09:22 | 000,693,112 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/06/04 17:09:22 | 000,078,200 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/06/01 20:09:27 | 000,016,310 | —- | M] () – C:\Windows\SysNative\results.xml
[2013/06/01 11:55:10 | 000,000,354 | —- | M] () – C:\Windows\tasks\HPCeeScheduleForPic Chic.job
[2013/06/01 06:26:09 | 000,037,274 | —- | M] () – C:\Users\Pic Chic\AppData\Local\WiDiSetupLog.20130601.062435.wdl
[2013/06/01 06:25:29 | 000,002,020 | —- | M] () – C:\Users\Public\Desktop\Intel® WiDi.lnk
[2013/06/01 05:39:46 | 000,095,648 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\WindowsAccessBridge-32.dll
[2013/06/01 05:39:44 | 000,263,584 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaws.exe
[2013/06/01 05:39:44 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\javaw.exe
[2013/06/01 05:39:43 | 000,866,720 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\npDeployJava1.dll
[2013/06/01 05:39:43 | 000,788,896 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\deployJava1.dll
[2013/06/01 05:39:43 | 000,174,496 | —- | M] (Oracle Corporation) – C:\Windows\SysWow64\java.exe
[2013/06/01 03:31:05 | 001,664,000 | —- | M] (IDT, Inc.) – C:\Windows\sttray64.exe
[2013/06/01 03:31:05 | 000,542,208 | —- | M] (IDT, Inc.) – C:\Windows\SysNative\drivers\stwrt64.sys
[2013/06/01 03:31:04 | 006,085,632 | —- | M] (IDT, Inc.) – C:\Windows\SysNative\stlang64.dll
[2013/06/01 03:31:04 | 002,188,800 | —- | M] (IDT, Inc.) – C:\Windows\SysNative\stapo64.dll
[2013/06/01 03:31:04 | 000,671,744 | —- | M] (IDT, Inc.) – C:\Windows\SysNative\stapi64.dll
[2013/06/01 03:31:04 | 000,499,200 | —- | M] (IDT, Inc.) – C:\Windows\SysNative\stcplx64.dll
[2013/06/01 03:31:04 | 000,255,488 | —- | M] (IDT, Inc.) – C:\Windows\SysNative\st646425.dll
[2013/06/01 03:31:02 | 002,213,376 | —- | M] (IDT, Inc.) – C:\Windows\SysNative\IDTNX.dll
[2013/06/01 03:31:02 | 000,464,384 | —- | M] (SRS Labs, Inc.) – C:\Windows\SysNative\slapoi64.dll
[2013/06/01 03:31:02 | 000,253,952 | —- | M] (IDT, Inc.) – C:\Windows\SysNative\IDTNJ.exe
[2013/06/01 03:31:01 | 007,986,176 | —- | M] (IDT, Inc.) – C:\Windows\SysNative\IDTNGUI.exe
[2013/06/01 03:31:01 | 007,712,768 | —- | M] (IDT, Inc.) – C:\Windows\SysNative\IDTNHP.dll
[2013/06/01 03:31:01 | 001,821,184 | —- | M] (IDT, Inc.) – C:\Windows\SysNative\IDTNC64.cpl
[2013/06/01 03:30:59 | 000,224,256 | —- | M] (IDT, Inc.) – C:\Windows\SysNative\HPToneCtrls64.dll
[2013/06/01 03:30:59 | 000,042,482 | —- | M] () – C:\Windows\SysNative\Balen&Yeats;_dv7.xml
[2013/06/01 02:34:08 | 000,598,780 | —- | M] () – C:\Windows\SysWow64\igvpkrng700.bin
[2013/06/01 02:34:08 | 000,598,780 | —- | M] () – C:\Windows\SysNative\igvpkrng700.bin
[2013/06/01 02:34:08 | 000,276,288 | —- | M] (Intel Corporation) – C:\Windows\SysWow64\IntelCpHeciSvc.exe
[2013/06/01 02:34:08 | 000,241,664 | —- | M] (Intel Corporation) – C:\Windows\SysNative\IntelOpenCL64.dll
[2013/06/01 02:34:08 | 000,195,584 | —- | M] (Intel Corporation) – C:\Windows\SysWow64\IntelOpenCL32.dll
[2013/06/01 02:34:08 | 000,116,224 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxCoIn_v2857.dll
[2013/06/01 02:34:08 | 000,017,014 | —- | M] () – C:\Windows\SysNative\iglhxs64.vp
[2013/06/01 02:34:07 | 000,509,248 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxsrvc.exe
[2013/06/01 02:34:07 | 000,439,296 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrrus.lrc
[2013/06/01 02:34:07 | 000,439,296 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrrom.lrc
[2013/06/01 02:34:07 | 000,438,784 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrsky.lrc
[2013/06/01 02:34:07 | 000,438,784 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrptg.lrc
[2013/06/01 02:34:07 | 000,438,784 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrplk.lrc
[2013/06/01 02:34:07 | 000,437,760 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrtrk.lrc
[2013/06/01 02:34:07 | 000,437,760 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrsve.lrc
[2013/06/01 02:34:07 | 000,437,760 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrslv.lrc
[2013/06/01 02:34:07 | 000,437,760 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrptb.lrc
[2013/06/01 02:34:07 | 000,437,760 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrnor.lrc
[2013/06/01 02:34:07 | 000,437,248 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrtha.lrc
[2013/06/01 02:34:07 | 000,410,624 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxTMM.dll
[2013/06/01 02:34:07 | 000,170,304 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxtray.exe
[2013/06/01 02:34:07 | 000,063,488 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxsrvc.dll
[2013/06/01 02:34:06 | 000,438,784 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrnld.lrc
[2013/06/01 02:34:06 | 000,438,784 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrita.lrc
[2013/06/01 02:34:06 | 000,438,784 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrhrv.lrc
[2013/06/01 02:34:06 | 000,438,272 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrhun.lrc
[2013/06/01 02:34:06 | 000,432,128 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrjpn.lrc
[2013/06/01 02:34:06 | 000,431,104 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrkor.lrc
[2013/06/01 02:34:05 | 009,007,616 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxress.dll
[2013/06/01 02:34:05 | 000,440,320 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrell.lrc
[2013/06/01 02:34:05 | 000,439,808 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrfra.lrc
[2013/06/01 02:34:05 | 000,439,808 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxresn.lrc
[2013/06/01 02:34:05 | 000,438,784 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrdeu.lrc
[2013/06/01 02:34:05 | 000,438,272 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrfin.lrc
[2013/06/01 02:34:05 | 000,438,272 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrcsy.lrc
[2013/06/01 02:34:05 | 000,437,248 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrdan.lrc
[2013/06/01 02:34:05 | 000,435,712 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrheb.lrc
[2013/06/01 02:34:05 | 000,435,712 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrara.lrc
[2013/06/01 02:34:05 | 000,429,056 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrcht.lrc
[2013/06/01 02:34:05 | 000,428,544 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrchs.lrc
[2013/06/01 02:34:05 | 000,386,048 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxpph.dll
[2013/06/01 02:34:05 | 000,286,208 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxrenu.lrc
[2013/06/01 02:34:04 | 000,441,856 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxdev.dll
[2013/06/01 02:34:04 | 000,441,152 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxpers.exe
[2013/06/01 02:34:04 | 000,330,240 | —- | M] (Intel Corporation) – C:\Windows\SysWow64\igfxdv32.dll
[2013/06/01 02:34:04 | 000,251,712 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxext.exe
[2013/06/01 02:34:04 | 000,142,336 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxdo.dll
[2013/06/01 02:34:04 | 000,126,976 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxcpl.cpl
[2013/06/01 02:34:04 | 000,028,672 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igfxexps.dll
[2013/06/01 02:34:04 | 000,025,088 | —- | M] (Intel Corporation) – C:\Windows\SysWow64\igfxexps32.dll
[2013/06/01 02:34:04 | 000,009,728 | —- | M] ( ) – C:\Windows\SysNative\IGFXDEVLib.dll
[2013/06/01 02:34:03 | 012,604,928 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igdumd64.dll
[2013/06/01 02:34:02 | 027,664,896 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igdrcl64.dll
[2013/06/01 02:34:02 | 011,040,256 | —- | M] (Intel Corporation) – C:\Windows\SysWow64\igdumd32.dll
[2013/06/01 02:34:01 | 027,643,904 | —- | M] (Intel Corporation) – C:\Windows\SysWow64\igdrcl32.dll
[2013/06/01 02:34:00 | 005,338,848 | —- | M] (Intel Corporation) – C:\Windows\SysNative\drivers\igdkmd64.sys
[2013/06/01 02:33:59 | 027,435,520 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igdfcl64.dll
[2013/06/01 02:33:58 | 021,816,320 | —- | M] (Intel Corporation) – C:\Windows\SysWow64\igdfcl32.dll
[2013/06/01 02:33:58 | 003,582,976 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igdbcl64.dll
[2013/06/01 02:33:58 | 000,080,384 | —- | M] () – C:\Windows\SysNative\igdde64.dll
[2013/06/01 02:33:58 | 000,064,512 | —- | M] () – C:\Windows\SysWow64\igdde32.dll
[2013/06/01 02:33:57 | 012,836,864 | —- | M] (Intel Corporation) – C:\Windows\SysNative\igd10umd64.dll
[2013/06/01 02:33:57 | 002,899,968 | —- | M] (Intel Corporation) – C:\Windows\SysWow64\igdbcl32.dll
[2013/06/01 02:33:56 | 011,593,728 | —- | M] (Intel Corporation) – C:\Windows\SysNative\ig7icd64.dll
[2013/06/01 02:33:56 | 011,158,528 | —- | M] (Intel Corporation) – C:\Windows\SysWow64\igd10umd32.dll
[2013/06/01 02:33:56 | 000,755,048 | —- | M] () – C:\Windows\SysWow64\igcodeckrng700.bin
[2013/06/01 02:33:56 | 000,755,048 | —- | M] () – C:\Windows\SysNative\igcodeckrng700.bin
[2013/06/01 02:33:55 | 008,577,536 | —- | M] (Intel Corporation) – C:\Windows\SysWow64\ig7icd32.dll
[2013/06/01 02:33:54 | 000,398,656 | —- | M] (Intel Corporation) – C:\Windows\SysNative\hkcmd.exe
[2013/06/01 02:33:54 | 000,110,592 | —- | M] (Intel Corporation) – C:\Windows\SysNative\hccutils.dll
[2013/06/01 02:33:54 | 000,000,259 | —- | M] () – C:\Windows\SysNative\GfxUI.exe.config
[2013/06/01 02:33:53 | 005,902,656 | —- | M] (Intel Corporation) – C:\Windows\SysNative\GfxUI.exe
[2013/06/01 02:33:53 | 000,223,233 | —- | M] () – C:\Windows\SysNative\Gfxres.th-TH.resources
[2013/06/01 02:33:53 | 000,209,727 | —- | M] () – C:\Windows\SysNative\Gfxres.el-GR.resources
[2013/06/01 02:33:53 | 000,193,862 | —- | M] () – C:\Windows\SysNative\Gfxres.ru-RU.resources
[2013/06/01 02:33:53 | 000,184,640 | —- | M] (Intel Corporation) – C:\Windows\SysNative\difx64.exe
[2013/06/01 02:33:53 | 000,173,568 | —- | M] (Intel Corporation) – C:\Windows\SysNative\gfxSrvc.dll
[2013/06/01 02:33:53 | 000,165,865 | —- | M] () – C:\Windows\SysNative\Gfxres.ar-SA.resources
[2013/06/01 02:33:53 | 000,163,120 | —- | M] () – C:\Windows\SysNative\Gfxres.ja-JP.resources
[2013/06/01 02:33:53 | 000,158,727 | —- | M] () – C:\Windows\SysNative\Gfxres.he-IL.resources
[2013/06/01 02:33:53 | 000,149,390 | —- | M] () – C:\Windows\SysNative\Gfxres.it-IT.resources
[2013/06/01 02:33:53 | 000,147,759 | —- | M] () – C:\Windows\SysNative\Gfxres.ko-KR.resources
[2013/06/01 02:33:53 | 000,147,101 | —- | M] () – C:\Windows\SysNative\Gfxres.de-DE.resources
[2013/06/01 02:33:53 | 000,147,010 | —- | M] () – C:\Windows\SysNative\Gfxres.es-ES.resources
[2013/06/01 02:33:53 | 000,145,715 | —- | M] () – C:\Windows\SysNative\Gfxres.ro-RO.resources
[2013/06/01 02:33:53 | 000,145,211 | —- | M] () – C:\Windows\SysNative\Gfxres.fr-FR.resources
[2013/06/01 02:33:53 | 000,144,378 | —- | M] () – C:\Windows\SysNative\Gfxres.tr-TR.resources
[2013/06/01 02:33:53 | 000,143,976 | —- | M] () – C:\Windows\SysNative\Gfxres.pt-BR.resources
[2013/06/01 02:33:53 | 000,143,730 | —- | M] () – C:\Windows\SysNative\Gfxres.nl-NL.resources
[2013/06/01 02:33:53 | 000,143,657 | —- | M] () – C:\Windows\SysNative\Gfxres.hu-HU.resources
[2013/06/01 02:33:53 | 000,142,990 | —- | M] () – C:\Windows\SysNative\Gfxres.pt-PT.resources
[2013/06/01 02:33:53 | 000,142,617 | —- | M] () – C:\Windows\SysNative\Gfxres.sv-SE.resources
[2013/06/01 02:33:53 | 000,142,423 | —- | M] () – C:\Windows\SysNative\Gfxres.pl-PL.resources
[2013/06/01 02:33:53 | 000,142,008 | —- | M] () – C:\Windows\SysNative\Gfxres.cs-CZ.resources
[2013/06/01 02:33:53 | 000,141,739 | —- | M] () – C:\Windows\SysNative\Gfxres.fi-FI.resources
[2013/06/01 02:33:53 | 000,141,574 | —- | M] () – C:\Windows\SysNative\Gfxres.sk-SK.resources
[2013/06/01 02:33:53 | 000,140,779 | —- | M] () – C:\Windows\SysNative\Gfxres.hr-HR.resources
[2013/06/01 02:33:53 | 000,137,621 | —- | M] () – C:\Windows\SysNative\Gfxres.sl-SI.resources
[2013/06/01 02:33:53 | 000,137,534 | —- | M] () – C:\Windows\SysNative\Gfxres.nb-NO.resources
[2013/06/01 02:33:53 | 000,136,873 | —- | M] () – C:\Windows\SysNative\Gfxres.da-DK.resources
[2013/06/01 02:33:53 | 000,126,035 | —- | M] () – C:\Windows\SysNative\Gfxres.zh-TW.resources
[2013/06/01 02:33:53 | 000,124,403 | —- | M] () – C:\Windows\SysNative\Gfxres.zh-CN.resources
[2013/06/01 02:10:09 | 000,650,808 | —- | M] (Intel Corporation) – C:\Windows\SysNative\drivers\iaStorA.sys
[2013/05/31 18:36:09 | 000,001,595 | —- | M] () – C:\Users\Pic Chic\Desktop\Programs - Shortcut.lnk
[2013/05/31 01:19:06 | 000,002,299 | —- | M] () – C:\Users\Pic Chic\Desktop\NEWEGG ORDER 5 30 2013 HDMI AND PRINT - Shortcut.lnk
[2013/05/31 01:13:47 | 000,001,283 | —- | M] () – C:\Users\Pic Chic\Desktop\NEWEGG HDMI REBATE-JAN 6 1 2013 - Shortcut.lnk
[2013/05/30 18:24:29 | 001,257,472 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/05/30 10:36:30 | 000,000,405 | —- | M] () – C:\Users\Pic Chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Control Panel (2).lnk
[2013/05/30 07:55:50 | 000,000,405 | —- | M] () – C:\Users\Pic Chic\Desktop\Control Panel.lnk
[2013/05/30 06:23:51 | 000,002,285 | —- | M] () – C:\Users\Pic Chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/05/23 18:01:46 | 001,300,992 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\gdi32.dll
[2013/05/23 01:00:51 | 000,001,039 | —- | M] () – C:\Users\Public\Desktop\foobar2000.lnk
[2013/05/22 22:02:38 | 000,001,018 | —- | M] () – C:\Users\Pic Chic\Desktop\IconLover.lnk
[2013/05/22 04:22:23 | 000,000,997 | —- | M] () – C:\Users\Pic Chic\Desktop\WinRAR.lnk
[2013/05/22 01:48:47 | 000,081,506 | —- | M] () – C:\Users\Pic Chic\Documents\Services exe files 5 22 2013.MHT
[2013/05/21 12:38:08 | 000,001,630 | —- | M] () – C:\Users\Pic Chic\Desktop\ESETOnline Scaner.lnk
[2013/05/21 12:32:26 | 000,001,127 | —- | M] () – C:\Users\Pic Chic\Desktop\~ESET Uninstaller.lnk
[2013/05/15 17:37:03 | 000,044,032 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\UXInit.dll
[2013/05/15 17:35:49 | 000,053,760 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\UXInit.dll
[2013/05/15 17:35:47 | 000,144,384 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\tssdisai.dll
[3 C:\Users\Pic Chic\AppData\Local\*.tmp files -> C:\Users\Pic Chic\AppData\Local\*.tmp -> ]

========== Files Created - No Company Name ==========

[2013/06/13 22:19:23 | 000,001,435 | —- | C] () – C:\Users\Pic Chic\Desktop\OTL.exe - Shortcut.lnk
[2013/06/12 22:19:28 | 000,001,189 | —- | C] () – C:\Users\Public\Desktop\IObit Malware Fighter.lnk
[2013/06/11 22:05:08 | 005,075,608 | —- | C] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/06/11 20:22:53 | 000,386,646 | —- | C] () – C:\Windows\SysNative\ApnDatabase.xml
[2013/06/11 20:03:21 | 000,000,493 | —- | C] () – C:\Users\Pic Chic\Desktop\Personalization - Shortcut.lnk
[2013/06/08 01:11:51 | 000,001,129 | —- | C] () – C:\Users\Pic Chic\Desktop\procexp.exe - Shortcut.lnk
[2013/06/08 00:11:36 | 000,001,546 | —- | C] () – C:\Users\Pic Chic\Desktop\Illustrator.lnk
[2013/06/07 21:57:54 | 000,001,923 | —- | C] () – C:\Users\Pic Chic\Desktop\Desktop Wallpaper - Shortcut.lnk
[2013/06/07 20:21:55 | 000,128,941 | —- | C] () – C:\Users\Pic Chic\Desktop\SKMBT_50113052410240.pdf
[2013/06/07 05:39:33 | 000,001,672 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator CS6.lnk
[2013/06/07 05:38:27 | 000,001,546 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Illustrator CS6 (64 Bit).lnk
[2013/06/07 05:37:35 | 000,001,053 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6 (64bit).lnk
[2013/06/07 05:36:39 | 000,001,181 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Bridge CS6.lnk
[2013/06/07 05:34:19 | 000,001,393 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Extension Manager CS6.lnk
[2013/06/07 05:34:11 | 000,001,563 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ExtendScript Toolkit CS6.lnk
[2013/06/07 05:33:45 | 000,001,001 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Help.lnk
[2013/06/07 04:42:32 | 000,001,131 | —- | C] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/06/01 11:55:10 | 000,000,354 | —- | C] () – C:\Windows\tasks\HPCeeScheduleForPic Chic.job
[2013/06/01 08:29:35 | 001,449,669 | —- | C] () – C:\Users\Pic Chic\Documents\HPSimplePass_UserGuide.pdf
[2013/06/01 06:25:29 | 000,002,032 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Intel® WiDi.lnk
[2013/06/01 06:25:29 | 000,002,020 | —- | C] () – C:\Users\Public\Desktop\Intel® WiDi.lnk
[2013/06/01 06:24:35 | 000,037,274 | —- | C] () – C:\Users\Pic Chic\AppData\Local\WiDiSetupLog.20130601.062435.wdl
[2013/06/01 04:59:15 | 000,042,482 | —- | C] () – C:\Windows\SysNative\Balen&Yeats;_dv7.xml
[2013/06/01 02:34:32 | 000,598,780 | —- | C] () – C:\Windows\SysWow64\igvpkrng700.bin
[2013/06/01 02:34:32 | 000,598,780 | —- | C] () – C:\Windows\SysNative\igvpkrng700.bin
[2013/06/01 02:34:32 | 000,017,014 | —- | C] () – C:\Windows\SysNative\iglhxs64.vp
[2013/06/01 02:34:29 | 000,009,728 | —- | C] ( ) – C:\Windows\SysNative\IGFXDEVLib.dll
[2013/06/01 02:34:28 | 000,080,384 | —- | C] () – C:\Windows\SysNative\igdde64.dll
[2013/06/01 02:34:28 | 000,064,512 | —- | C] () – C:\Windows\SysWow64\igdde32.dll
[2013/06/01 02:34:27 | 000,755,048 | —- | C] () – C:\Windows\SysWow64\igcodeckrng700.bin
[2013/06/01 02:34:27 | 000,755,048 | —- | C] () – C:\Windows\SysNative\igcodeckrng700.bin
[2013/06/01 02:34:27 | 000,000,259 | —- | C] () – C:\Windows\SysNative\GfxUI.exe.config
[2013/06/01 02:34:26 | 000,223,233 | —- | C] () – C:\Windows\SysNative\Gfxres.th-TH.resources
[2013/06/01 02:34:26 | 000,193,862 | —- | C] () – C:\Windows\SysNative\Gfxres.ru-RU.resources
[2013/06/01 02:34:26 | 000,145,715 | —- | C] () – C:\Windows\SysNative\Gfxres.ro-RO.resources
[2013/06/01 02:34:26 | 000,144,378 | —- | C] () – C:\Windows\SysNative\Gfxres.tr-TR.resources
[2013/06/01 02:34:26 | 000,142,990 | —- | C] () – C:\Windows\SysNative\Gfxres.pt-PT.resources
[2013/06/01 02:34:26 | 000,142,617 | —- | C] () – C:\Windows\SysNative\Gfxres.sv-SE.resources
[2013/06/01 02:34:26 | 000,141,574 | —- | C] () – C:\Windows\SysNative\Gfxres.sk-SK.resources
[2013/06/01 02:34:26 | 000,137,621 | —- | C] () – C:\Windows\SysNative\Gfxres.sl-SI.resources
[2013/06/01 02:34:26 | 000,126,035 | —- | C] () – C:\Windows\SysNative\Gfxres.zh-TW.resources
[2013/06/01 02:34:26 | 000,124,403 | —- | C] () – C:\Windows\SysNative\Gfxres.zh-CN.resources
[2013/06/01 02:34:25 | 000,163,120 | —- | C] () – C:\Windows\SysNative\Gfxres.ja-JP.resources
[2013/06/01 02:34:25 | 000,147,759 | —- | C] () – C:\Windows\SysNative\Gfxres.ko-KR.resources
[2013/06/01 02:34:25 | 000,143,976 | —- | C] () – C:\Windows\SysNative\Gfxres.pt-BR.resources
[2013/06/01 02:34:25 | 000,143,730 | —- | C] () – C:\Windows\SysNative\Gfxres.nl-NL.resources
[2013/06/01 02:34:25 | 000,142,423 | —- | C] () – C:\Windows\SysNative\Gfxres.pl-PL.resources
[2013/06/01 02:34:25 | 000,137,534 | —- | C] () – C:\Windows\SysNative\Gfxres.nb-NO.resources
[2013/06/01 02:34:24 | 000,158,727 | —- | C] () – C:\Windows\SysNative\Gfxres.he-IL.resources
[2013/06/01 02:34:24 | 000,149,390 | —- | C] () – C:\Windows\SysNative\Gfxres.it-IT.resources
[2013/06/01 02:34:24 | 000,145,211 | —- | C] () – C:\Windows\SysNative\Gfxres.fr-FR.resources
[2013/06/01 02:34:24 | 000,143,657 | —- | C] () – C:\Windows\SysNative\Gfxres.hu-HU.resources
[2013/06/01 02:34:24 | 000,141,739 | —- | C] () – C:\Windows\SysNative\Gfxres.fi-FI.resources
[2013/06/01 02:34:24 | 000,140,779 | —- | C] () – C:\Windows\SysNative\Gfxres.hr-HR.resources
[2013/06/01 02:34:21 | 000,209,727 | —- | C] () – C:\Windows\SysNative\Gfxres.el-GR.resources
[2013/06/01 02:34:21 | 000,165,865 | —- | C] () – C:\Windows\SysNative\Gfxres.ar-SA.resources
[2013/06/01 02:34:21 | 000,147,101 | —- | C] () – C:\Windows\SysNative\Gfxres.de-DE.resources
[2013/06/01 02:34:21 | 000,147,010 | —- | C] () – C:\Windows\SysNative\Gfxres.es-ES.resources
[2013/06/01 02:34:21 | 000,142,008 | —- | C] () – C:\Windows\SysNative\Gfxres.cs-CZ.resources
[2013/06/01 02:34:21 | 000,136,873 | —- | C] () – C:\Windows\SysNative\Gfxres.da-DK.resources
[2013/05/31 18:37:24 | 000,000,953 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\µTorrent.lnk
[2013/05/31 18:36:09 | 000,001,595 | —- | C] () – C:\Users\Pic Chic\Desktop\Programs - Shortcut.lnk
[2013/05/31 01:19:06 | 000,002,299 | —- | C] () – C:\Users\Pic Chic\Desktop\NEWEGG ORDER 5 30 2013 HDMI AND PRINT - Shortcut.lnk
[2013/05/31 01:13:47 | 000,001,283 | —- | C] () – C:\Users\Pic Chic\Desktop\NEWEGG HDMI REBATE-JAN 6 1 2013 - Shortcut.lnk
[2013/05/30 10:36:30 | 000,000,405 | —- | C] () – C:\Users\Pic Chic\Application Data\Microsoft\Internet Explorer\Quick Launch\Control Panel (2).lnk
[2013/05/30 07:55:50 | 000,000,405 | —- | C] () – C:\Users\Pic Chic\Desktop\Control Panel.lnk
[2013/05/23 01:00:51 | 000,001,121 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\foobar2000.lnk
[2013/05/23 01:00:51 | 000,001,039 | —- | C] () – C:\Users\Public\Desktop\foobar2000.lnk
[2013/05/22 22:02:38 | 000,001,018 | —- | C] () – C:\Users\Pic Chic\Desktop\IconLover.lnk
[2013/05/22 04:22:23 | 000,000,997 | —- | C] () – C:\Users\Pic Chic\Desktop\WinRAR.lnk
[2013/05/22 01:48:47 | 000,081,506 | —- | C] () – C:\Users\Pic Chic\Documents\Services exe files 5 22 2013.MHT
[2013/05/21 12:38:08 | 000,001,630 | —- | C] () – C:\Users\Pic Chic\Desktop\ESETOnline Scaner.lnk
[2013/05/21 12:32:26 | 000,001,127 | —- | C] () – C:\Users\Pic Chic\Desktop\~ESET Uninstaller.lnk
[2013/04/24 18:34:50 | 000,073,220 | —- | C] () – C:\Windows\SysWow64\EPPICPrinterDB.dat
[2013/04/24 18:34:50 | 000,004,943 | —- | C] () – C:\Windows\SysWow64\EPPICPattern6.dat
[2013/04/24 18:34:50 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_PT.dat
[2013/04/24 18:34:50 | 000,001,140 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_BP.dat
[2013/04/24 18:34:50 | 000,001,137 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_ES.dat
[2013/04/24 18:34:50 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_FR.dat
[2013/04/24 18:34:50 | 000,001,130 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_CF.dat
[2013/04/24 18:34:50 | 000,001,104 | —- | C] () – C:\Windows\SysWow64\EPPICPresetData_EN.dat
[2013/04/24 18:34:50 | 000,000,097 | —- | C] () – C:\Windows\SysWow64\PICSDK.ini
[2013/04/24 18:34:49 | 000,031,053 | —- | C] () – C:\Windows\SysWow64\EPPICPattern131.dat
[2013/04/24 18:34:49 | 000,029,114 | —- | C] () – C:\Windows\SysWow64\EPPICPattern1.dat
[2013/04/24 18:34:49 | 000,027,417 | —- | C] () – C:\Windows\SysWow64\EPPICPattern121.dat
[2013/04/24 18:34:49 | 000,021,021 | —- | C] () – C:\Windows\SysWow64\EPPICPattern3.dat
[2013/04/24 18:34:49 | 000,015,670 | —- | C] () – C:\Windows\SysWow64\EPPICPattern5.dat
[2013/04/24 18:34:49 | 000,013,280 | —- | C] () – C:\Windows\SysWow64\EPPICPattern2.dat
[2013/04/24 18:34:49 | 000,010,673 | —- | C] () – C:\Windows\SysWow64\EPPICPattern4.dat
[2013/04/24 18:34:02 | 000,000,060 | —- | C] () – C:\Windows\PERFV33_330.ini
[2013/03/05 20:04:28 | 000,007,605 | —- | C] () – C:\Users\Pic Chic\AppData\Local\Resmon.ResmonCfg
[2013/02/04 16:20:47 | 000,000,016 | —- | C] () – C:\Windows\popcinfo.dat
[2013/01/26 12:14:40 | 000,083,968 | —- | C] () – C:\Windows\SysWow64\OEMLicense.dll
[2012/08/03 17:40:09 | 000,916,510 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/07/26 03:13:10 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2012/07/26 03:13:09 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2012/07/26 02:21:26 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2012/07/25 20:17:42 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2012/07/25 15:37:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2012/07/25 15:28:31 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2012/07/25 15:22:54 | 000,982,240 | —- | C] () – C:\Windows\SysWow64\igkrng500.bin
[2012/07/25 15:22:54 | 000,439,308 | —- | C] () – C:\Windows\SysWow64\igcompkrng500.bin
[2012/07/25 15:22:54 | 000,092,356 | —- | C] () – C:\Windows\SysWow64\igfcg500m.bin
[2012/06/02 09:31:19 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2012/04/20 15:59:44 | 000,001,536 | —- | C] () – C:\Windows\SysWow64\IusEventLog.dll

========== ZeroAccess Check ==========

[2012/09/12 13:01:32 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/03/06 01:31:28 | 019,758,592 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/03/06 00:03:37 | 017,561,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2012/07/25 22:05:38 | 001,004,544 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2012/07/25 22:18:27 | 000,784,896 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2012/07/25 22:07:41 | 000,455,680 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2013/01/27 20:33:24 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\DAEMON Tools Lite
[2013/01/30 21:38:50 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\Dream Aquarium
[2013/04/24 19:50:01 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\EPSON
[2012/12/29 00:25:58 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\ESET
[2013/06/11 17:44:38 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\foobar2000
[2013/05/19 06:01:35 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\IDT
[2013/06/12 22:19:25 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\IObit
[2013/04/24 18:47:35 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\Leadertech
[2013/06/08 02:02:00 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\OpenOffice.org
[2013/03/07 01:57:06 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\Protector Suite
[2013/05/30 06:09:57 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\Software Informer
[2013/02/04 16:19:44 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\SpinTop
[2013/03/03 12:37:45 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2012/12/09 13:31:09 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\Synaptics
[2013/06/01 05:42:35 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\SystemRequirementsLab
[2013/03/05 21:31:04 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\TeamViewer
[2013/06/08 05:46:24 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\uTorrent
[2012/12/09 13:47:40 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\WildTangent
[2012/12/29 05:54:39 | 000,000,000 | —D | M] – C:\Users\Pic Chic\AppData\Roaming\WinBatch

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2012/10/11 00:53:24 | 002,115,952 | —- | M] (Microsoft Corporation) MD5=0AD19A3CA61271BA872AD90771BA47DC – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_b592a71650d677ed\explorer.exe
[2012/10/11 03:09:58 | 002,380,944 | —- | M] (Microsoft Corporation) MD5=0DDFEAA2AA18D4295EF220EB666B2312 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_ab3dfcc41c75b5f2\explorer.exe
[2012/07/25 22:50:01 | 002,114,936 | —- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_b4d2f8c937e166b1\explorer.exe
[2012/07/25 23:49:13 | 002,380,440 | —- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_aa7e4e770380a4b6\explorer.exe
[2012/10/11 00:56:41 | 002,115,952 | —- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 – C:\Windows\SysWOW64\explorer.exe
[2012/10/11 00:56:41 | 002,115,952 | —- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_b5080a0137b9becc\explorer.exe
[2012/10/11 02:35:16 | 002,380,944 | —- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 – C:\Windows\explorer.exe
[2012/10/11 02:35:16 | 002,380,944 | —- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_aab35faf0358fcd1\explorer.exe

< MD5 for: SERVICES >
[2013/05/21 17:15:42 | 000,092,866 | —- | M] () MD5=251B2A72DCB6F2688DB5DB818AF26B8A – C:\Users\Pic Chic\AppData\Roaming\Microsoft\MMC\services
[2012/07/26 00:26:47 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\WinSxS\amd64_microsoft-windows-w..ucture-other-minwin_31bf3856ad364e35_6.2.9200.16384_none_8e0944daeed62829\services

< MD5 for: SERVICES.AIP >
[2012/03/29 20:35:50 | 000,375,952 | —- | M] (Adobe Systems Incorporated) MD5=5965DFD83E10938A579952EB58C10298 – C:\Program Files (x86)\Adobe\Adobe Illustrator CS6\Plug-ins\Extensions\Services.aip
[2012/03/29 20:35:50 | 000,297,104 | —- | M] (Adobe Systems Incorporated) MD5=8311BFD3FD21EB8089259C491406A7B0 – C:\Program Files\Adobe\Adobe Illustrator CS6 (64 Bit)\Plug-ins\Extensions\Services.aip

< MD5 for: SERVICES.CFG >
[2012/09/23 21:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2012/12/18 09:28:18 | 000,558,791 | —- | M] () MD5=A9983CC532F9B3FB1E87918D2313731D – C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg

< MD5 for: SERVICES.EXE >
[2012/09/20 01:33:11 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=581190907DA1CF8CB7B87B35FFE64A07 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.20521_none_98a9ea2e9f571eb2\services.exe
[2012/07/26 00:26:45 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=754A2CC1F32107EA87CBD305ABE3E618 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16384_none_97e26cd38667756c\services.exe
[2012/09/20 01:33:46 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=8F226143046435C75C033B0C52E90FFE – C:\Windows\SysNative\services.exe
[2012/09/20 01:33:46 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=8F226143046435C75C033B0C52E90FFE – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16420_none_981f4d19863a6591\services.exe

< MD5 for: SERVICES.EXE.MUI - SHORTCUT.LNK >
[2013/05/21 17:13:10 | 000,004,695 | —- | M] () MD5=57962D49391E60BED82EF772B95E86D8 – C:\Users\Pic Chic\Desktop\ESET LOGS\services.exe.mui - Shortcut.lnk

< MD5 for: SERVICES.EXE.MUI >
[2012/07/26 02:50:12 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=8BCB19134E995FA62587DCE26E13B36C – C:\Windows\SysNative\en-US\services.exe.mui
[2012/07/26 02:50:12 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=8BCB19134E995FA62587DCE26E13B36C – C:\Windows\WinSxS\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.2.9200.16384_en-us_c2c6ee7bafb963b8\services.exe.mui

< MD5 for: SERVICES.JS >
[2013/04/17 01:59:24 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingFinance_2.0.0.275_x64__8wekyb3d8bbwe\common\js\services.js
[2013/04/17 01:56:34 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingNews_2.0.0.273_x64__8wekyb3d8bbwe\common\js\services.js
[2013/04/17 02:00:45 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingSports_2.0.0.273_x64__8wekyb3d8bbwe\common\js\services.js
[2013/04/17 01:49:31 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingTravel_2.0.0.274_x64__8wekyb3d8bbwe\common\js\services.js
[2013/04/30 10:34:05 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingWeather_2.0.0.288_x64__8wekyb3d8bbwe\common\js\services.js
[2012/07/26 02:53:58 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingFinance_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 02:53:49 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingNews_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 02:53:45 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingSports_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 02:54:27 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingTravel_1.2.0.145_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 02:53:53 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingWeather_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js

< MD5 for: SERVICES.LNK >
[2012/07/25 15:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 15:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 15:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_282d8a08cf7f1ada\services.lnk

< MD5 for: SERVICES.MOF >
[2012/06/02 09:35:05 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2012/06/02 09:35:05 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.2.9200.16384_none_282967cc570d3701\services.mof

< MD5 for: SERVICES.MSC >
[2012/07/26 02:50:36 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysNative\en-US\services.msc
[2012/06/02 09:31:20 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysNative\services.msc
[2012/07/26 02:50:36 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysWOW64\en-US\services.msc
[2012/06/02 09:31:13 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysWOW64\services.msc
[2012/07/26 02:50:36 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.2.9200.16384_en-us_fd08be678622fdab\services.msc
[2012/06/02 09:31:20 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_282d8a08cf7f1ada\services.msc
[2012/06/02 09:31:13 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\wow64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_3282345b03dfdcd5\services.msc
[2012/07/26 02:50:36 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.2.9200.16384_en-us_a0ea22e3cdc58c75\services.msc

< MD5 for: SERVICES.PNG >
[2013/05/30 04:36:57 | 000,000,653 | —- | M] () MD5=F4FFE88C8F84EE82D9EB026D42F449D4 – C:\Users\Pic Chic\AppData\Local\Google\Chrome\User Data\Default\Extensions\ghgabhipcejejjmhhchfonmamedcbeod\8.3_0\i\menu\services.png

< MD5 for: SERVICES.PTXML >
[2012/07/25 15:30:54 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2012/07/25 15:30:54 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.2.9200.16384_none_282967cc570d3701\Services.ptxml

< MD5 for: SVCHOST.EXE >
[2012/07/25 22:20:58 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=0A175AF8B65797BD22C11903A8BFEB2D – C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.16384_none_b2666581d6b482a6\svchost.exe
[2012/07/25 22:08:47 | 000,030,208 | —- | M] (Microsoft Corporation) MD5=57350BEDE3834915B6145B67C71C7BDA – C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.16384_none_0e8501058f11f3dc\svchost.exe
[2012/09/20 01:33:14 | 000,029,696 | —- | M] (Microsoft Corporation) MD5=607F7CB143783A8F9BA058D2FC4F2D36 – C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.20521_none_0f4c7e60a8019d22\svchost.exe
[2012/09/20 00:55:26 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=A46DC432F81473F526E3994AA483E366 – C:\Windows\SysWOW64\svchost.exe
[2012/09/20 00:55:26 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=A46DC432F81473F526E3994AA483E366 – C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.16420_none_b2a345c7d68772cb\svchost.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2012/09/20 01:33:52 | 000,029,696 | —- | M] (Microsoft Corporation) MD5=EDE27EACE742EE2888C5DD36400A2EC0 – C:\Windows\SysNative\svchost.exe
[2012/09/20 01:33:52 | 000,029,696 | —- | M] (Microsoft Corporation) MD5=EDE27EACE742EE2888C5DD36400A2EC0 – C:\Windows\WinSxS\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.16420_none_0ec1e14b8ee4e401\svchost.exe
[2012/09/20 00:56:27 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=EEF5E64822C3E21B186EA53463BE92DA – C:\Windows\WinSxS\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.2.9200.20521_none_b32de2dcefa42bec\svchost.exe

< MD5 for: USERINIT.EXE >
[2012/07/25 22:08:49 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 – C:\Windows\SysNative\userinit.exe
[2012/07/25 22:08:49 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E925F7BA032920D58DD284B6181A247 – C:\Windows\WinSxS\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_34f2617a5b742e02\userinit.exe
[2012/07/25 22:21:00 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 – C:\Windows\SysWOW64\userinit.exe
[2012/07/25 22:21:00 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=9F6289D194A04A09671FEED4B6CB6EF7 – C:\Windows\WinSxS\x86_microsoft-windows-userinit_31bf3856ad364e35_6.2.9200.16384_none_d8d3c5f6a316bccc\userinit.exe

< MD5 for: WINLOGON.EXE >
[2012/09/20 01:33:55 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=1F84B5F8DBDFFD36DF143C61CE25F12A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16420_none_c8c988c15e88a211\winlogon.exe
[2012/09/20 01:33:17 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=6522E98C94A2A81AE11EB66D2AF5743A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20521_none_c95425d677a55b32\winlogon.exe
[2012/07/25 22:08:50 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16384_none_c88ca87b5eb5b1ec\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2012/10/11 00:46:58 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E – C:\Windows\SysNative\winlogon.exe
[2012/10/11 00:46:58 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16433_none_c8c1b9b35e8e0a07\winlogon.exe
[2012/10/11 00:45:27 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=CBFD56B4EC07CB056A6ABD55DD33671F – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20534_none_c94c56c877aac328\winlogon.exe

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 1691-7909
Directory of C:\
07/26/2012 02:22 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/26/2012 02:22 AM Application Data [C:\ProgramData]
07/26/2012 02:22 AM Desktop [C:\Users\Public\Desktop]
07/26/2012 02:22 AM Documents [C:\Users\Public\Documents]
07/26/2012 02:22 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/26/2012 02:22 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/26/2012 02:22 AM All Users [C:\ProgramData]
07/26/2012 02:22 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/26/2012 02:22 AM Application Data [C:\ProgramData]
07/26/2012 02:22 AM Desktop [C:\Users\Public\Desktop]
07/26/2012 02:22 AM Documents [C:\Users\Public\Documents]
07/26/2012 02:22 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/26/2012 02:22 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/26/2012 02:22 AM Application Data [C:\Users\Default\AppData\Roaming]
07/26/2012 02:22 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/26/2012 02:22 AM Local Settings [C:\Users\Default\AppData\Local]
07/26/2012 02:22 AM My Documents [C:\Users\Default\Documents]
07/26/2012 02:22 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/26/2012 02:22 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/26/2012 02:22 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/26/2012 02:22 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/26/2012 02:22 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/26/2012 02:22 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/26/2012 02:22 AM Application Data [C:\Users\Default\AppData\Local]
07/26/2012 02:22 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/26/2012 02:22 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/26/2012 02:22 AM My Music [C:\Users\Default\Music]
07/26/2012 02:22 AM My Pictures [C:\Users\Default\Pictures]
07/26/2012 02:22 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Pic Chic
12/09/2012 01:30 PM Application Data [C:\Users\Pic Chic\AppData\Roaming]
12/09/2012 01:30 PM Cookies [C:\Users\Pic Chic\AppData\Roaming\Microsoft\Windows\Cookies]
12/09/2012 01:30 PM Local Settings [C:\Users\Pic Chic\AppData\Local]
12/09/2012 01:30 PM My Documents [C:\Users\Pic Chic\Documents]
12/09/2012 01:30 PM NetHood [C:\Users\Pic Chic\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
12/09/2012 01:30 PM PrintHood [C:\Users\Pic Chic\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
12/09/2012 01:30 PM Recent [C:\Users\Pic Chic\AppData\Roaming\Microsoft\Windows\Recent]
12/09/2012 01:30 PM SendTo [C:\Users\Pic Chic\AppData\Roaming\Microsoft\Windows\SendTo]
12/09/2012 01:30 PM Start Menu [C:\Users\Pic Chic\AppData\Roaming\Microsoft\Windows\Start Menu]
12/09/2012 01:30 PM Templates [C:\Users\Pic Chic\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Pic Chic\AppData\Local
12/09/2012 01:30 PM Application Data [C:\Users\Pic Chic\AppData\Local]
12/09/2012 01:30 PM History [C:\Users\Pic Chic\AppData\Local\Microsoft\Windows\History]
12/09/2012 01:30 PM Temporary Internet Files [C:\Users\Pic Chic\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Pic Chic\Documents
12/09/2012 01:30 PM My Music [C:\Users\Pic Chic\Music]
12/09/2012 01:30 PM My Pictures [C:\Users\Pic Chic\Pictures]
12/09/2012 01:30 PM My Videos [C:\Users\Pic Chic\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/26/2012 02:22 AM My Music [C:\Users\Public\Music]
07/26/2012 02:22 AM My Pictures [C:\Users\Public\Pictures]
07/26/2012 02:22 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile
04/27/2013 10:16 PM Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
04/27/2013 10:16 PM Cookies [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
04/27/2013 10:16 PM Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
04/27/2013 10:16 PM Start Menu [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\AppData\Local
04/27/2013 10:16 PM Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
04/27/2013 10:16 PM History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
04/27/2013 10:16 PM Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Windows\SysWOW64\config\systemprofile
04/27/2013 10:16 PM Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
04/27/2013 10:16 PM Cookies [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
04/27/2013 10:16 PM Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
04/27/2013 10:16 PM Start Menu [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu]
0 File(s) 0 bytes
Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Local
04/27/2013 10:16 PM Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
04/27/2013 10:16 PM History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
04/27/2013 10:16 PM Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
62 Dir(s) 566,421,676,032 bytes free

< End of report >
OTL Extras logfile created on: 6/13/2013 10:23:27 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Pic Chic\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16599)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

7.89 Gb Total Physical Memory | 5.81 Gb Available Physical Memory | 73.65% Memory free
9.08 Gb Paging File | 6.82 Gb Available in Paging File | 75.11% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 670.51 Gb Total Space | 527.54 Gb Free Space | 78.68% Space Free | Partition Type: NTFS
Drive D: | 27.35 Gb Total Space | 3.22 Gb Free Space | 11.76% Space Free | Partition Type: NTFS

Computer Name: ENVY | User Name: Pic Chic | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [Bridge] – C:\Program Files\Adobe\Adobe Bridge CS6 (64 Bit)\Bridge.exe "%L" (Adobe Systems, Inc.)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\KasperskyAntiVirus]
"DisableMonitoring" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 16
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 16
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 16
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0667DFB6-BC9D-444D-8593-4F4BA85AABCC}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{0B8C9F00-8393-4469-9098-AF177BA2C11E}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{13F1F52B-52F5-44B8-921F-F3C426B344F4}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{269B6080-6FE6-423B-AC8D-68375C1C020B}" = lport=2869 | protocol=6 | dir=in | app=system |
"{2B1741EF-2CC6-4D23-B2E4-CFBD1747BD75}" = lport=139 | protocol=6 | dir=in | app=system |
"{57926C50-CE26-497A-9076-CFCC434496A4}" = lport=10243 | protocol=6 | dir=in | app=system |
"{61777EEB-0607-417E-858D-D7498330EAF6}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{63D2589D-4070-4399-9B7B-DAAE1DC3C3E0}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{6A93D1B8-7AEC-4DD8-A2E6-67717D8F6B16}" = rport=138 | protocol=17 | dir=out | app=system |
"{790A16B1-CAEE-420B-9B5D-3EDB17F2E836}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{92B6C684-BD42-44F1-B426-19920DA27CDE}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{9390E29F-9A6E-4E4C-BA0F-7E660E9A308B}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{9B60C271-3B84-422D-B4FF-4D53B4A41262}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{A53F60F4-78A8-4E67-BA94-014C75190F10}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{AE7EDF3A-DBCF-48AF-AF5B-B1CA8BE8AE87}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{BCD5F6EC-7F98-468B-AB01-0E035895BBDD}" = rport=445 | protocol=6 | dir=out | app=system |
"{CC4C69A9-C8C7-4FD4-B92C-39302E4E426A}" = lport=445 | protocol=6 | dir=in | app=system |
"{CD499832-9A6A-4235-BFED-1E1064F87A0F}" = rport=139 | protocol=6 | dir=out | app=system |
"{CF1C52C4-CC36-4897-A416-47674F5650E1}" = rport=137 | protocol=17 | dir=out | app=system |
"{D6894977-B202-402B-B980-AED49118368D}" = lport=138 | protocol=17 | dir=in | app=system |
"{D74901D1-9824-472F-B4E5-FF98302FB314}" = rport=10243 | protocol=6 | dir=out | app=system |
"{F135B64B-BB6B-4C39-B246-74A209A9A2FB}" = lport=137 | protocol=17 | dir=in | app=system |
"{F5CEACDE-530A-4A15-B44A-25501B9FDA15}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F600E30F-92EB-4F53-8BDB-010A0554AC40}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01857395-230A-40AD-BAA9-B232B91FAE64}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{0670664C-B09B-4887-99FD-6CB676E576F0}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{0F5A289D-F7E0-470E-B7AD-AAB229A4CBB0}" = dir=out | name=@{microsoft.bingfinance_2.0.0.275_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{13684ACC-7632-4CF3-B683-8BA6B0DF03CB}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{1515E6FB-6730-49EA-9692-A08316E4FE6C}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{183955BC-F319-4FF8-AC66-53F50C99E4C7}" = protocol=6 | dir=out | app=system |
"{1848EF8A-DF00-4D30-BA47-2DD7D0DB5291}" = dir=out | name=@{microsoft.bing_1.5.1.259_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{189BB1D6-3300-4172-9329-447B97E1906F}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{191487FE-D290-4C6D-BE29-896BB8402A76}" = dir=out | name=windows_ie_ac_001 |
"{1E281321-D210-4993-A2F9-B415029B2861}" = dir=out | name=@{microsoft.bingweather_2.0.0.288_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{1F19D3E6-7F20-4AA6-87C7-2E9F43AEAB1E}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{2290E544-A2AA-40E9-996D-57341F1456DE}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{2A9005C7-D869-4E4B-8F7B-5B1B574DDA35}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{2E704215-78E3-4EEB-82D7-905162347E85}" = dir=out | name=netflix |
"{3237C5C7-B5EC-4761-A43A-DED364CC0F56}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{3435BD7A-2A15-4162-B076-2877FA9295D5}" = protocol=17 | dir=in | app=c:\users\pic chic\appdata\local\temp\7zsbdf8.tmp\symnrt.exe |
"{3950DC99-6A02-415B-A0C3-C94457B48068}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3E8600DC-4A81-41B1-8154-3269C9D33CA2}" = dir=in | name=kindle |
"{3EAFA0BB-9DA9-4BB3-A8C4-E10D513CF44A}" = dir=out | name=hp+ |
"{3F346EEC-2B13-4C7B-8406-17731449DC88}" = dir=out | name=hp connected photo powered by snapfish |
"{3F8ED14D-37D9-4E20-BFFF-F8CBF924D5BB}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{4021B9FB-17A2-47B5-A890-0E3A5346EA85}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{46C90C41-5EF1-4F2E-B8D2-4625FF036AFB}" = dir=in | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{4E6432DD-F4FD-4454-B438-099B4604DD72}" = dir=out | name=@{microsoft.zunemusic_1.3.59.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/ids_manifest_music_app_name} |
"{4F25E1EE-32F7-4210-9718-A03ACE5B2B82}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5952F67E-64BB-4AFD-B319-CF0E8C740DC7}" = dir=in | name=skype |
"{5D850EDC-0D84-4CED-9C9B-741CFBEBD042}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{5E0A8A4C-6D9C-4ABC-A7E4-7EFCB5A72994}" = dir=out | name=kindle |
"{6DD14F5F-3839-463B-A4A1-4B108EA03BA7}" = dir=out | name=getting started with windows 8 |
"{6E086788-0436-499D-BCB3-2BE60A2F963A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{6F7EE599-0DE5-4BE9-B45F-258AF55A0EC9}" = dir=out | name=@{microsoft.bingtravel_1.2.0.145_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{72F92D8C-68F0-4B12-916C-3FEA2FD95309}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} |
"{773ABE89-326B-4CAF-AEA8-0CEB792E3477}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{79B82F65-8D15-4DF6-B888-2CC108066B2C}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{7BC2667C-A254-4241-A2A0-D5B7A9EFF936}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{7DEF1CA3-36B1-4DAA-AE1F-164CAB8A1266}" = dir=out | name=@{microsoft.bingnews_2.0.0.273_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{7F585451-98FA-41A3-AC28-691EA82105C7}" = dir=out | name=microsoft mahjong |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{8549B02E-3C5F-49A0-80F0-D0DA193EA025}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{8611EFE4-AD75-4FEB-ADE2-937E912BF489}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{88A82148-6A63-463A-ACB2-F21F6E4B1894}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8AA0644A-45F7-4449-9933-A74D97F06EDE}" = protocol=6 | dir=in | app=c:\users\pic chic\appdata\local\temp\7zsbdf8.tmp\symnrt.exe |
"{9076D847-8CA1-4C76-A229-4B9643AA29C7}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{90FCAE52-BC6E-4D1B-AE42-4AE8C1B0F13A}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{940F96D7-2CA2-42CA-A4E6-053060908DF6}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{A1BC24F3-FDE7-4CD8-B3C9-BD8057D19945}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector10\pdr10.exe |
"{A47F68D0-29AF-4C00-B1F2-0CF4C644C902}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{A54DABA6-8401-49F0-9C6D-1E6FD4CEDCD1}" = dir=out | name=@{microsoft.bingmaps_1.6.1528.2509_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{A81E7DF9-48C6-403E-9B82-80C8D1341327}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{A957CE0A-624C-4219-82C4-D10EFC32A9E7}" = dir=out | name=@{microsoft.xboxlivegames_1.3.10.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{AB1E8C00-AF07-46CB-A967-BE90384068F2}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{ACE2E8AE-B74C-4847-A272-6D72A5F7DE86}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AF6A93A9-9A2D-4B03-87F9-66EDB77826E1}" = dir=in | name=ebay |
"{B20EC25A-8E08-4F4B-8693-3FD4F05F9C8D}" = dir=out | name=ebay |
"{B308630F-8C3F-44E6-80DC-943F9EE949C1}" = dir=out | name=@{microsoft.zunevideo_1.3.59.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/ids_manifest_video_app_name} |
"{B30C9A59-D1EE-456B-8DED-1E3433285369}" = dir=out | name=iheartradio |
"{B991C27F-1649-44A7-BEB7-10889D4542FC}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{B9F2E93D-E981-46F9-81E1-203915AA5BD9}" = dir=out | name=microsoft solitaire collection |
"{BDA9B546-3949-43B8-B2FB-571A971603C6}" = dir=in | app=c:\program files\intel\wifi\bin\pandhcpdns.exe |
"{C47ECE48-4E41-4395-BF16-D3F58D166DE2}" = dir=out | name=@{microsoft.bingsports_1.2.0.135_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{D038CAEC-0531-41B3-ADB6-551D363D8BF3}" = dir=in | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{D3F495E5-377C-4553-A14E-8EFADCC7F773}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{DAC162FB-F806-4020-9741-A46615477630}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{EA90004C-E4F0-42DD-9289-47A971D61B3C}" = dir=in | app=c:\program files (x86)\cyberlink\powerdvd10\powerdvd10.exe |
"{EC21C2CC-4DE1-438E-9EB8-ED23FD0D70D4}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{EE614F9E-BD96-4B38-8010-FD2127863E20}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{EFDBAB9B-F638-4D21-8552-FE64E0E71F1A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{F1C8716A-A017-4FE3-9E1A-BB246E837774}" = dir=out | name=@{microsoft.windowscommunicationsapps_16.4.4206.722_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{F557FFBD-E2A9-4E16-BD81-6AE96AD9E381}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{F7911D6F-92E3-46EE-9364-296F102FD5CF}" = dir=out | name=skype |
"{FA2D7B23-4B5B-4B3E-83C2-DD75A3B83ABA}" = dir=out | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{FA7B6071-0B9B-4E1D-80F2-0AA6F4A18256}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{FAC2DCFC-09FA-46BA-ABAB-053B48608C1C}" = dir=in | app=c:\program files\intel corporation\intel widi\widiapp.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{015C5B35-B678-451C-9AEE-821E8D69621C}_is1" = PeerBlock 1.1 (r518)
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{0728A184-F899-4356-B93D-8228674F0DEB}" = Intel® PROSet/Wireless Software for Bluetooth® Technology
"{0FA995CC-C849-4755-B14B-5404CC75DC24}" = Energy Star
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1F91C200-8F0F-4009-A75E-DB6CE151BD4E}" = Validity WBF DDK
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{4A18C875-B374-4868-B7EA-06CF2DD59FCC}" = ESET Smart Security
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{54CE68A8-4F2D-4328-B1F7-D6C720405F7F}" = HP 3D DriveGuard
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{62E7C369-64FF-452C-8F46-6BE9B77FF097}" = Intel® WiDi
"{6E14E6D6-3175-4E1A-B934-CAB5A86367CD}" = HP Postscript Converter
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7C6CD9B4-B230-4E76-80AA-FB465FF4DE29}" = Intel® PROSet/Wireless WiFi Software Driver
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A94C50AA-21E8-4627-ADD0-E16A07030D7D}" = Intel® PROSet/Wireless for Bluetooth® + High Speed
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{C767056D-3CE2-442D-BC78-F05E94F450D0}" = Protector Suite 2012
"{D759947B-8C5A-4480-B0DB-FC391F061C85}" = Adobe Photoshop Lightroom 4.3 64-bit
"{DEF50764-F1A7-4DD4-B8BA-C81A4807631A}" = Intel® PROSet/Wireless WiFi Software
"{E4D6CCF2-0AAF-4B9C-9DE5-893EDC9B4BAA}" = HP Registration Service
"{EBC0CC3F-B7A1-4FC8-8014-4C7BFD3925E8}" = AuthenTec TrueAPI 64-bit
"{F4404AFD-2EF3-40C1-8C09-29E5F3B6972B}" = Intel® Trusted Connect Service Client
"Recuva" = Recuva
"Software Informer_is1" = Software Informer 1.2
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"WinRAR archiver" = WinRAR 4.00 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"{03B8AA32-F23C-4178-B8E6-09ECD07EAA47}" = Epson Event Manager
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0C57987A-A03A-4B95-A309-D23F78F406CA}" = HP Utility Center
"{11AF9A96-6D83-4C3B-8DCB-16EA2A358E3F}" = HP CoolSense
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{26A24AE4-039D-4CA4-87B4-2F83217021FF}" = Java 7 Update 21
"{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34C821CA-6B55-44A0-8A9B-2EF471D6019E}" = HP SimplePass
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3B03E732-6150-4D0A-849F-C6F4141EA78C}" = EPSON Perfection V33/V330 Photo Scanner Driver Update
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4862344A-A39C-4897-ACD4-A1BED5163C5A}" = CyberLink PhotoDirector
"{4869414E-7AEA-4C8E-BE1C-8D40977FD517}" = Adobe Illustrator CS6
"{48FD006F-2320-4C13-AB11-F4D54EDC50E0}" = Mr. Rebates Desktop Icons
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{528AB81B-D65A-4AB0-A2B6-82B51A087D01}" = HP Recovery Manager
"{56009CA3-423B-41F8-884A-E5B049534F15}" = Kaspersky Security Scan
"{574F0207-8E98-46CD-8F79-318348C98C46}" = HP Quick Start
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6BA5F6E7-6CC1-4117-816D-A549A06CE44E}" = HP Connected Backup
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.0.0
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74EB3499-8B95-4B5C-96EB-7B342F3FD0C6}" = Adobe Photoshop CS6
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{7DE5085A-3665-40BC-9595-A1A209699137}" = HP Documentation
"{835B275B-F29B-464B-BD4B-097FD55FAB0A}" = HP Software Framework
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver
"{89704656-98FA-4EB0-9CC9-9C9839255FA0}" = Intel® Update Manager
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{941DE69D-6CEE-4171-8F1F-3D7E352AA498}" = HP Wireless Button Driver
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C35EDE5-4B0F-45E7-A438-314BA889948E}" = HP MyRoom
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA72FB28-73B4-49E5-B6B4-E78F44BBD0AD}" = Epson Copy Utility 3.5
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.02)
"{AF0CE7C0-A3E4-4D73-988B-B29187EC6E9A}" = QuickTime
"{AF37176A-78CA-545B-34EF-8B6A21514DD1}" = Adobe Help Manager
"{AF5D2519-C6B4-4AFD-9A8D-FBF74DD4F0A0}" = HP Product Detection
"{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}" = CyberLink PowerDirector 10
"{B8019B54-F9BE-490A-9619-6D06F18F129F}" = HP Support Assistant
"{BFEAAE77-BD7F-4534-B286-9C5CB4697EB1}" = PDF Settings CS6
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"{C7CA731B-BF9A-46D9-92CF-8A8737AE9240}" = System Requirements Lab for Intel
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E5823036-6F09-4D0A-B05C-E2BAA129288A}" = HP Quick Launch
"{EA561FC0-A965-11E2-94D3-B8AC6F98CCE3}" = Google Earth Plug-in
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F5266D28-E0B2-4130-BFC5-EE155AD514DC}" = Apple Application Support
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{F9000000-0018-0000-0000-074957833700}" = ABBYY FineReader 9.0 Sprint
"{fad118b4-798f-4755-9e67-a622eec95b62}" = Intel® PROSet/Wireless Software
"{FB46F473-333E-4A06-A777-31C54188593E}" = ArcSoft MediaImpression 2
"{FCB3772C-B7D0-4933-B1A9-3707EBACC573}" = Intel® SDK for OpenCL - CPU Only Runtime Package
"{FD071DBA-2994-4350-93BB-EC245D0D3C74}_is1" = iResizer 2.2
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF8455A9-21E8-457D-AC64-510A705D53B3}" = ArcSoft Scan-n-Stitch Deluxe
"ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint
"Adobe AIR" = Adobe AIR
"Adobe DNG Codec" = Adobe DNG Codec
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Advanced SystemCare 6_is1" = Advanced SystemCare 6
"Bejeweled 2" = Bejeweled 2
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Help Manager
"DAEMON Tools Lite" = DAEMON Tools Lite
"Dream Aquarium" = Dream Aquarium 1.234
"ENTERPRISE" = Microsoft Office Enterprise 2007
"EPSON Scanner" = EPSON Scan
"ESET Online Scanner" = ESET Online Scanner v3
"foobar2000" = foobar2000 v1.2.6
"Google Chrome" = Google Chrome
"IconLover" = IconLover
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = CyberLink YouCam
"InstallShield_{1FBF6C24-C1fD-4101-A42B-0C564F9E8E79}" = CyberLink Media Suite 10
"InstallShield_{2A87D48D-3FDF-41fd-97CD-A1E370EFFFE2}" = CyberLink Power2Go 8
"InstallShield_{4862344A-A39C-4897-ACD4-A1BED5163C5A}" = CyberLink PhotoDirector
"InstallShield_{B0B4F6D2-F2AE-451A-9496-6F2F6A897B32}" = CyberLink PowerDirector 10
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = CyberLink LabelPrint
"InstallShield_{DEC235ED-58A4-4517-A278-C41E8DAEAB3B}" = CyberLink PowerDVD
"IObit Malware Fighter_is1" = IObit Malware Fighter
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Revo Uninstaller" = Revo Uninstaller 1.94
"StartHPConnectedMusic" = HP Connected Music (Meridian - installer)
"TeamViewer 8" = TeamViewer 8
"uTorrent" = µTorrent
"Wacom Tablet Driver" = Wacom Tablet
"WildTangent hp Master Uninstall" = HP Games
"WildTangent wildgames Master Uninstall" = WildTangent Games
"WinLiveSuite" = Windows Live Essentials
"WTA-0258a500-fb43-4cfb-bc38-603e3077db14" = Mortimer Beckett and the Crimson Thief Premium Edition
"WTA-038be7f2-1795-463a-82a1-e1d4cc357e9b" = 4 Elements II
"WTA-32e3507f-f05f-44e6-b668-4fb1bc93045c" = Farm Frenzy
"WTA-3653d296-a57d-494f-8620-186606663493" = Build-a-lot 4 - Power Source
"WTA-4c8ab13a-c3ad-42ae-a467-a9f1fc8da67c" = Governor of Poker 2 Premium Edition
"WTA-5e84fec0-928b-47cc-9e95-b92f010037f5" = FlatOut 2
"WTA-6e2b4b9a-9dfe-4161-89c7-716f6d60e79e" = Mystery P.I. - Curious Case of Counterfeit Cove
"WTA-7af9d399-b381-411d-b6af-8200aed1d840" = Polar Golfer
"WTA-82068410-11b2-427f-adf1-2fd254d8e31b" = Jewel Match 3
"WTA-9c0f466d-6c3c-4702-8cf9-12182c2ff7bf" = Mahjongg Dimensions Deluxe: Tiles in Time
"WTA-9f734c76-91b1-413c-a141-4fb8c3c5b348" = Polar Bowler
"WTA-a055319d-fa2e-48cb-8425-af3e944a24fb" = Penguins!
"WTA-a6c6ed5d-177e-426a-8cca-86cc4a25ddf9" = Luxor Evolved
"WTA-b9388869-727a-45be-9efd-335eaed1254b" = Final Drive Fury
"WTA-bdce3905-c3cf-4aff-b82c-3045ce0c35f7" = FATE: The Cursed King
"WTA-c2245cdc-03c0-404e-8d76-0c2d1ccc238e" = Roads of Rome 3
"WTA-c57d9215-9a33-4b45-965d-8d6db80725e0" = Peggle Nights
"WTA-cd7d54d8-11de-4a8a-b054-d8ec8b287cef" = Hoyle Card Games
"WTA-ce4dd6e2-e0d4-4a33-bc03-500eaf3d7b2e" = Vacation Quest™ - Australia
"WTA-d87309ec-75b1-4b11-b8da-b4d196623906" = John Deere Drive Green
"WTA-e6788f44-c8f6-4740-868d-f3f9e85c30e8" = Bejeweled 3
"WTA-e9a68716-a94a-42a0-ba48-9befe918d669" = Chuzzle Deluxe
"WTA-ec56e32e-8bc2-42ce-9cfd-4629ded6eab0" = Cradle of Rome 2
"WTA-f06c9385-2cd0-4c05-8f8c-45c7857981aa" = Tales of Lagoona
"WTA-f4d72639-c391-4a4e-9656-b71e3862f0fd" = Cradle Of Egypt Collector's Edition
"WTA-f7839edb-b684-494f-bfbd-32355bdbe1dc" = Zuma's Revenge

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 6/6/2013 5:04:21 AM | Computer Name = Envy | Source = TabletServiceWacom | ID = 0
Description =

Error - 6/6/2013 5:04:22 AM | Computer Name = Envy | Source = Application Error | ID = 1000
Description = Faulting application name: TouchControl.exe, version: 6.0.100.272,
time stamp: 0x5113b6a2 Faulting module name: KERNELBASE.dll, version: 6.2.9200.16451,
time stamp: 0x50988950 Exception code: 0xc0000005 Fault offset: 0x0000d1cb Faulting
process id: 0x10a4 Faulting application start time: 0x01ce6294d41c493f Faulting application
path: C:\Program Files (x86)\HP SimplePass\TouchControl.exe Faulting module path:
C:\Windows\SYSTEM32\KERNELBASE.dll Report Id: 1381ed94-ce88-11e2-bebe-84a6c877299f
Faulting
package full name: Faulting package-relative application ID:

Error - 6/6/2013 6:07:11 AM | Computer Name = Envy | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Users\Pic Chic\Downloads\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error - 6/6/2013 6:07:51 AM | Computer Name = Envy | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Users\Pic Chic\Downloads\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error - 6/6/2013 9:35:10 AM | Computer Name = Envy | Source = Microsoft-Windows-Immersive-Shell | ID = 2486
Description = App Microsoft.Reader_8wekyb3d8bbwe!Microsoft.Reader did not launch
within its allotted time.

Error - 6/6/2013 10:12:59 AM | Computer Name = Envy | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\ESET\ESET
Online Scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error - 6/6/2013 10:31:51 AM | Computer Name = Envy | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\ESET\ESET
Online Scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error - 6/6/2013 10:36:55 AM | Computer Name = Envy | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\ESET\ESET
Online Scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

Error - 6/6/2013 2:39:56 PM | Computer Name = Envy | Source = Microsoft-Windows-LoadPerf | ID = 3002
Description = The performance counter explain text string value in the registry
is not formatted correctly. The malformed string is Number of WMI High Performance
provider returned by WMI Adapter. The first DWORD in the Data section contains
the index value to the malformed string while the second and third DWORDs in the
Data section contain the last valid index values.

Error - 6/6/2013 2:53:24 PM | Computer Name = Envy | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "F:\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_418ab7ef718b27ef.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.9200.16579_none_8937eec6860750f5.manifest.

[ System Events ]
Error - 5/30/2013 7:07:25 AM | Computer Name = Envy | Source = Service Control Manager | ID = 7011
Description = A timeout (30000 milliseconds) was reached while waiting for a transaction
response from the hpqwmiex service.

Error - 5/30/2013 8:59:32 AM | Computer Name = Envy | Source = Service Control Manager | ID = 7030
Description = The ESET Service service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 5/31/2013 9:22:19 AM | Computer Name = Envy | Source = DCOM | ID = 10010
Description =

Error - 6/1/2013 12:03:03 AM | Computer Name = Envy | Source = Service Control Manager | ID = 7030
Description = The HPWMISVC service is marked as an interactive service. However,
the system is configured to not allow interactive services. This service may not
function properly.

Error - 6/1/2013 12:20:55 AM | Computer Name = Envy | Source = Service Control Manager | ID = 7000
Description = The CLVirtualDrive service failed to start due to the following error:
%%183

Error - 6/1/2013 4:03:56 AM | Computer Name = Envy | Source = Service Control Manager | ID = 7034
Description = The TrueAPI Service component service terminated unexpectedly. It
has done this 1 time(s).

Error - 6/1/2013 4:18:55 AM | Computer Name = Envy | Source = Service Control Manager | ID = 7023
Description = The WMI Performance Adapter service terminated with the following
error: %%2147500037

Error - 6/1/2013 5:34:23 AM | Computer Name = Envy | Source = Service Control Manager | ID = 7023
Description = The WMI Performance Adapter service terminated with the following
error: %%2147500037

Error - 6/1/2013 5:38:58 AM | Computer Name = Envy | Source = Service Control Manager | ID = 7023
Description = The WMI Performance Adapter service terminated with the following
error: %%2147500037

Error - 6/1/2013 5:48:03 AM | Computer Name = Envy | Source = Service Control Manager | ID = 7023
Description = The WMI Performance Adapter service terminated with the following
error: %%2147500037


< End of report >
Hi SnapHappy,

This looks very much like a conflict between 2 antivirus programs.

SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)

This is not the Windows Defender that you may be accustomed to. For Windows 8 MicroSoft renamed Microsoft Security Essentials to Windows Defender.

Before we do anything please describe as best you can all the symptoms you are experiencing.
Wow, I had no idea, ESET support never mentioned this. Seems rather counter intuitive for Windows to keep recycling names and risking confusion. I have never been able to open Defender. Always get message that it is "turned off". Your information clears up a few things for me. Problem with error message that ESET couldn't communicate with kernel, and then it would fail to launch. With each subsequent attempt to launch ESET, things got worse, things loaded very slow, and some never loaded at all. Finally wouldn't advance past the very first start up screen, just kept circling. Had to force it to close. I didn't use it for a few days. Later it took a few tries, but it finally started, ESET launched and I followed ESET's instructions and ran their specific scan/cleaner tool. It said Sirefef was present, attempted cleaning, but cleaning stalled at 50% and failed. That's when ESET support got involved. No answers found, no "fix" attempted. That problem has gotten better, haven't gotten message in several days. However, it now has additional problems. Weird and unusual behavior,. Besides loading slowly or not at all, programs I am very familiar with, don't run correctly, browser pages with weird appearances (overlapping text, graphics of familiar web pages distorted and/or misplaced, fonts and graphics that have changed, often taking on very "basic" look), resource intense programs no longer attempt to run, On 6-12, "a variant of Win32/EXFriendAlert. B", and 2 instances of Win32//DownloadAdmin.G quarrantined by ESET. 6-14, Win32/DownloadAdmin.G again. In the last 2 days, some very disturbing things have happened; passwords not working at routine sites, on-line submissions that can't be located, an issue with a charge acct at vendor that neither they nor the charge company can explain. We have been having some technical issues with net service, so I just hoped it was responsible. Today there are changes in the file folders in the tree in the navigation pane. There are hidden folders that are now visible and now have the blue shortcut arrow on them. They cannot be opened, I have never seen anything like this before. I am no longer using the laptop.
Hi SnapHappy,


How long have you had ESET?

You also have Advanced SystemCare 6 and IObit Malware Fighter which is an antivirus program. Depending when it was installed Advanced SystemCare 6 would have been what turned Windows Defender off.

The next step would be to determine what you want for an antivirus solution. Let me know and we will carry on.
I got the eset in the beginning of January, when I got the laptop. I have removed IObit Malware, but still have the ASC (I dont use the registry cleaner or defrag) I'm not sure what you mean by what I want as an antiviral, If the ASC is a problem with the eset, I can lose that easily, I just use it to clean up junk files and the privacy sweeper, its just a convenience factor. As far as Defender being an antivirus now, I havent a clue. If its a problem even disabled, then I guess I would need your advise here. I purchased the eset on the advise of my son who swears by it, I dont really have an opinion about either. Also, my son is nagging me to rid myself of Win8 and use 7 instead, he claims its' the problem, but I dont see the wiz kid solving my problem here, so I'm up for whatever is best.
Hi SnapHappy,


There are hidden folders that are now visible and now have the blue shortcut arrow on them. They cannot be opened, I have never seen anything like this before. I am no longer using the laptop.

I meant to comment on this before. This is normal as OTL unhide some files and folders that are normally hidden from the users. the ones that can't be opened aren't really folders. They are junctions or SymLink. They are used in Vista and up for backwwards compatability. you can rehide them by
  • click the Windows Explorer icon near the start button (looks like a folder)
  • in the upper left corner click Organize
  • click folders and search options
  • click the view tab
  • check the box beside
    • Don't show hidden files, folders, or drives
    • Hide protected operating system files (Recommended)
  • click apply, click ok

You had 3 antivirus programs installed so i wanted to know which one you wanted to keep. It would be a shame to waste the $s you paid for ESET so let's see if we can get it to work correctly.

Not sure if IOBIT itself will cause problems with ESET but IObit Malware Fighter certainly can. IOBIT does monitor your system and perhaps it's a bit too snoopy for ESET or windows 8.

The items you are using ASC for can be done from within your browser and a couple of other small tools.

Was there any improvement after uninstalling IObit Malware Fighter?
Things have improved greatly since removing IObit Malware. Glad to say, I havent seen "unable to communicate with kernel" message since IOBits Malware' removal. The only other thing that was really worrying me was the hidden folders with the blue arrows. I often access hidden files because my Adobe graphics programs dump useless cache files that eat up lots of space and need to be purged regularly, but I never saw the shortcut arrows before. I have corrected that now. I think things are ok now, repeated scans come up clean, but I am still willing to remove ASC if you advise. It cost under $20 and I can accomplish the same functions the old fashioned way, I will just have to locate the necessary files on Win8, 6 months and I'm still groping in the dark here. Any recommendations you can make for tools that wont interfere, I'd appreciate the input. Yes, I would like to keep the ESET if I can. If I keep ESET, do I have to remove Defender or can it just be disabled? Also, I installed Malware Anti-Malware when I removed IObits, to scan on demand. It is my understanding that it wont launch on its' own so that it doesn't constantly monitor. Can I keep this or should I uninstall this too?
Hi SnapHappy,

If ACS seems to be playing nice with ESET go ahead and keep it. Don't use the registry cleaner or the defrag options.

If you would rather use the builtin browser features for clearing browsing history it can be done automatically from within IE and FireFox.

In IE it's
  • click Tools
  • click Internet Options
  • on the general tab check the box beside Delete browsing history upon exit
  • click apply, click ok

FireFox
  • click FireFox (top left corner)
  • highlight options
  • click Options
  • click on the Privacy tab
  • In the History section use the drop down menu to change Firefox will: to use custom setting for history
  • check the box beside clear history when Firefox closes

Chrome doesn't have that feature but you can use the information in this LINK to set Chrome to delete cookies automatically or install an addon to remove the browsing history. The link also includes the settings for IE and FF.

TFC is a good temporary file cleaner. Note: remove OTL before you download it or it will be removed when OTL is removed. To remove OTL from your computer, open OTL and clcik the Cleanup button.

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

To remove junk and unwanted toolbars both of these are very good.

[external image: Posted Image] AdwCleaner

Please download AdwCleaner by Xplode onto your desktop.
  • Right click on AdwCleaner.exe and click "Run as Administrator" to run the tool.
  • Click on Search if you want to see what will be removed or Delete[/B to remove what was found.
  • A logfile will automatically open after the scan has finished.
  • You can find the logfile at C:\AdwCleaner[R1].txt as well.

2. Junkware Removal Tool

Please download Junkware Removal Tool from HERE and save it to your desktop.
  • Shutdown your antivirus to avoid any potential conflicts.
  • Right-mouse click JRT.exe and select Run as Administrator.
  • JRTwill begin to backup your registry and start scanning your system.
  • Please be patient as this can take a while to complete depending on your system's specifications.
  • On completion, the log JRT.txt is saved on your desktop and will automatically open.

MS says disabling Windows Defender should be enough to keep it from interferring with another antivirus. We'll take their word for it as WD is built into win8.

Having MBAM installed as an on demand scanner is a recommendation I usually make. It should not cause any problems.
Hi oldman 960, I have used the cleaners you suggested. All ran like charms. Laptop is running fine, no error messages, no failure to communicate with kernel. It seems all is well now. Thanks so much. May I ask a few more questions? As these viruses were detected by ESET, I did some digging to research the harm they could do. The Sirefef, Win32/EXFriendAlert. B, and Win32//DownloadAdmin.G were all listed as trojans or trojans/worms. All info said that they would alter registry, download malicious programs, and/or would insert material that would compromise security. If these changes are hidden, can I be sure at this point that I have not only removed the viruses, but the malicious material they have added or changed? How would I know if these aren't readily detected? Also, the Win32's are currently quarantined in ESET, do I just leave them there forever? (BTW: When I first set up the laptop, I increased the space allotted for restore points to 15%, but when I went back there recently, it was back at the default amount and now I don't have any points far enough back to restore the registry to a point before all the problems started and I am not able to make the changes to registry that I have read about, way over my head!) Thanks again for all your help.
Hi, Today my laptop gave me an error message that it couldn't open windows/system32/config/system. When I started it up again a few hours later, it didn't open like usual and went into a disk check. Then I got a blue screen with a frowining face with a message that there were problems and it was going to fix them. Progressed to 27% and then no further. I powered it down, restarted it, but it went back to 27% immediately and went into the loop again. I tried a third time and message was to hit any key to stop disk check. I hit the space bar and now it starts the splash screen progress circle, flashes the blue screen with frown face, then goes black and doesnt appear to be doing anything.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI