oreo918
Topic Starter
My pc has been acting very strange. It's been getting slow. The internet has been getting very slow, and on top of that sometimes the browser will just stop, like it has no internet connection. I will disconnect from wifi using the icon in the bottom right corner next to the clock, and reconnect, right click and run the diagnostic on it until i'm ready to reboot and right before restarting most of the time it will just come back on all of a sudden and the connection is good and everything is fine. And then the other day I had to search the internet for a fix (called folderfix.reg inside a .zip, can provide) because when I was in my computer using right click on my computer > open. I was trying to add a new folder in C:\acer\example\new folder so I right clicked and there wasn't any "New Folder" option anywhere at all that I could find. Could these issues be walware? Can anyone help me with these issues.? Thank you for your time,.
OTL logfile created on: 7/6/2013 12:19:29 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karen\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.75 Gb Total Physical Memory | 2.68 Gb Available Physical Memory | 71.48% Memory free
7.50 Gb Paging File | 6.10 Gb Available in Paging File | 81.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.27 Gb Total Space | 202.13 Gb Free Space | 70.61% Space Free | Partition Type: NTFS
Computer Name: KAREN-PC | User Name: Karen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Karen\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\MouseHid.exe ()
PRC - C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\Tra.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\MouseHid.exe ()
MOD - C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\Tra.exe ()
========== Services (SafeList) ==========
SRV:64bit: - (Live Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\drivers\XAudio64.exe (Conexant Systems, Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (vToolbarUpdater14.2.0) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe ()
SRV - (avgfws) – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (dg_ssudbus) – C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (ssudmdm) – C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (androidusb) – C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Qualcomm Atheros Communications, Inc.)
DRV:64bit: - (avgtp) – C:\Windows\SysNative\drivers\avgtpx64.sys (AVG Technologies)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (pwdrvio) – C:\Windows\SysNative\pwdrvio.sys ()
DRV:64bit: - (pwdspio) – C:\Windows\SysNative\pwdspio.sys ()
DRV:64bit: - (taphss6) – C:\Windows\SysNative\drivers\taphss6.sys (Anchorfree Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgfwfd) – C:\Windows\SysNative\drivers\avgfwd6a.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (NMgamingmsFltr) – C:\Windows\SysNative\drivers\NMgamingms.sys (Primax Ltd)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (k57nd60a) – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (HSF_DPV) – C:\Windows\SysNative\drivers\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) – C:\Windows\SysNative\drivers\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\drivers\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\drivers\XAudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\drivers\mdmxsdk.sys (Conexant)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.sweetpacks.com/?src=10&st;…0-00262D7BE3A6}
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{84dc9f6c-c9a5-4c64-ab67-d6ef60f963c8}: "URL" = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.helpmefindyour.info/?l=1&…lg=EN&cc;=US
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://start.sweetpacks.com/?src=6&q;={…0-00262D7BE3A6}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {4A6AA337-BCDF-4E13-A072-C640AB2FBB09}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{4A6AA337-BCDF-4E13-A072-C640AB2FBB09}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKCU\..\SearchScopes\{7A0333EB-26A7-4F8B-92C1-862428320E4F}: "URL" = http://searchou.com/?q={searchTerms}&i;…filt=5&r;=92
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={62F2CD1…mp;d=2012-11-25 19:36:44&v;=14.2.0.1&pid;=avg&sg;=&sap;=dsp&q;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 64.191.70.164:8090
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.2.0.1 [2013/02/18 13:46:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\statuswinks@StatusWinks: C:\Users\Karen\AppData\Roaming\Mozilla\Extensions\statuswinks@StatusWinks
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/11/25 22:34:36 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\statuswinks@StatusWinks: C:\Users\Karen\AppData\Roaming\Mozilla\Extensions\statuswinks@StatusWinks
[2013/06/17 02:51:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Karen\AppData\Roaming\mozilla\Extensions
[2013/06/17 17:14:34 | 000,000,000 | —D | M] (Speed Analysis 2) – C:\Users\Karen\AppData\Roaming\mozilla\Extensions\[removed]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U21 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll
CHR - Extension: Google Drive = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: The Weather Channel for Chrome = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\iflpcokdamgefbghpdipcibmhlkdopop\1.0.0.4_0\
CHR - Extension: Click&Clean; App = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp\8.0_0\
CHR - Extension: Gmail = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2013/05/10 02:15:32 | 000,447,225 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.123fporn.info
O1 - Hosts: 15354 more lines…
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (no name) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No CLSID value found.
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [USB Optical Mouse] C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\MouseHid.exe ()
O4 - HKCU..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKLM..\RunOnce: [Del1568231] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [Del1568231] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_13)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.17.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{41E3175A-0BE7-433E-82CA-03AE7DC02D4D}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{59e7e991-7e37-11e2-9de6-00262d7be3a6}\Shell - "" = AutoRun
O33 - MountPoints2\{59e7e991-7e37-11e2-9de6-00262d7be3a6}\Shell\AutoRun\command - "" = E:\PcOptions.exe
O33 - MountPoints2\{75f45eba-92fb-11e2-b25c-00262d7be3a6}\Shell - "" = AutoRun
O33 - MountPoints2\{75f45eba-92fb-11e2-b25c-00262d7be3a6}\Shell\AutoRun\command - "" = "E:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
Drivers32:64bit: msacm.bdmpeg - bdmpega64.acm ()
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.mjpg - bdmjpeg64.dll ()
Drivers32:64bit: vidc.mpeg - bdmpegv64.dll ()
Drivers32: msacm.bdmpeg - C:\Windows\SysWow64\bdmpega.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.mjpg - C:\Windows\SysWow64\bdmjpeg.dll ()
Drivers32: vidc.mpeg - C:\Windows\SysWow64\bdmpegv.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/07/06 11:56:58 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Karen\Desktop\OTL.exe
[2013/07/06 11:28:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Open It!
[2013/07/06 11:28:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\OpenIt
[2013/07/06 02:04:49 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\USB Optical Mouse
[2013/07/06 02:01:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB Optical Mouse
[2013/07/06 02:00:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\USB Optical Mouse
[2013/07/05 16:45:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/07/04 20:48:14 | 000,000,000 | —D | C] – C:\Users\Public\Documents\CrashDump
[2013/07/04 17:09:50 | 000,000,000 | —D | C] – C:\Users\Karen\Desktop\Apks-7_4_2013
[2013/06/30 02:12:23 | 001,919,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WdfCoInstaller01005.dll
[2013/06/30 02:12:23 | 001,919,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdfCoInstaller01005.dll
[2013/06/30 02:12:23 | 000,188,232 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadmdm.sys
[2013/06/30 02:12:23 | 000,169,288 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadbus.sys
[2013/06/30 02:12:23 | 000,038,080 | —- | C] (Google Inc) – C:\Windows\SysNative\drivers\ssadadb.sys
[2013/06/30 02:12:23 | 000,021,320 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadmdfl.sys
[2013/06/30 02:12:23 | 000,017,736 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadwhnt.sys
[2013/06/30 02:12:23 | 000,017,736 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadwh.sys
[2013/06/30 02:12:23 | 000,017,224 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadcmnt.sys
[2013/06/30 02:12:23 | 000,017,224 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadcm.sys
[2013/06/30 01:59:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
[2013/06/30 01:59:26 | 000,821,824 | —- | C] (Devguru Co., Ltd.) – C:\Windows\SysWow64\dgderapi.dll
[2013/06/24 23:07:48 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Local\Facebook
[2013/06/17 19:02:37 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/06/17 19:02:37 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/06/17 19:02:37 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/06/17 19:02:37 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/06/17 19:02:37 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/06/17 19:02:37 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/06/17 19:02:37 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/17 19:02:37 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/06/17 19:02:37 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/06/17 19:02:35 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/06/17 19:02:35 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/17 19:02:35 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/17 19:02:34 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/17 19:01:39 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/06/17 19:01:38 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/17 17:26:58 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/06/17 17:26:57 | 000,492,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/06/17 17:26:45 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/06/17 17:26:45 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/06/17 17:26:39 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/06/17 17:26:00 | 001,192,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/06/17 17:26:00 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/06/17 17:25:59 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/06/17 17:25:59 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/06/17 17:25:59 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certenc.dll
[2013/06/17 17:25:59 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certenc.dll
[2013/06/17 17:25:46 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/06/17 17:25:46 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/06/17 02:51:44 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Mozilla
[2013/06/17 02:51:43 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\SpeedAnalysis2
[2013/06/17 02:51:35 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
[2013/06/16 05:25:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Acoustica Shared Effects
[2013/06/14 23:07:36 | 000,000,000 | —D | C] – C:\Users\Karen\Desktop\MINE
[2013/06/14 09:29:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\GPLGS
[2013/06/14 09:29:04 | 000,000,000 | —D | C] – C:\Program Files\PDFCreator
[2013/06/14 09:29:01 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Babylon
[2013/06/14 09:29:01 | 000,000,000 | —D | C] – C:\ProgramData\Babylon
[2013/06/13 16:00:16 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Malwarebytes
[2013/06/13 16:00:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/06/12 14:06:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Realtek
[2013/06/12 14:05:20 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Temp
[2013/06/12 06:40:03 | 000,000,000 | —D | C] – C:\ProgramData\Innovative Solutions
[2013/06/12 06:40:03 | 000,000,000 | —D | C] – C:\Windows\Fonts\AdvUninstal
[2013/06/12 06:39:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Innovative Solutions
[2013/06/12 05:35:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013/06/12 05:35:39 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2013/06/12 05:25:59 | 000,000,000 | —D | C] – C:\ProgramData\SparkTrust
========== Files - Modified Within 30 Days ==========
[2013/07/06 12:14:01 | 000,000,374 | —- | M] () – C:\Windows\tasks\WpsUpdateTask_Karen.job
[2013/07/06 11:56:59 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karen\Desktop\OTL.exe
[2013/07/06 11:51:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/06 11:49:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/06 11:28:53 | 000,001,078 | —- | M] () – C:\Users\Public\Desktop\Open It!.lnk
[2013/07/06 11:28:53 | 000,000,286 | —- | M] () – C:\Windows\tasks\DSite.job
[2013/07/06 11:11:50 | 000,015,824 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/06 11:11:50 | 000,015,824 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/06 11:05:18 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/06 11:03:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/06 11:03:00 | 3018,608,640 | -HS- | M] () – C:\hiberfil.sys
[2013/07/06 08:21:26 | 125,748,209 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2013/07/05 21:00:55 | 000,871,798 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/05 21:00:55 | 000,726,172 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/05 21:00:55 | 000,146,158 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/05 16:55:53 | 000,002,247 | —- | M] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/07/05 16:45:23 | 000,002,223 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/07/05 03:38:13 | 044,615,733 | —- | M] () – C:\Users\Karen\Desktop\I747UCDLK3_aio.tar.md5
[2013/07/04 22:17:07 | 006,400,000 | —- | M] () – C:\Users\Karen\recovery-twrp-2.5.0.0-SGHI747.tar
[2013/07/04 22:15:51 | 006,092,800 | —- | M] () – C:\Users\Karen\recovery-cwmtouch-6.0.3.1-SGHI747.tar
[2013/07/01 04:20:13 | 000,401,592 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2013/07/01 00:46:06 | 000,000,211 | —- | M] () – C:\ProgramData\acer.zip
[2013/06/30 05:22:15 | 000,000,792 | —- | M] () – C:\Users\Karen\Desktop\New folder - Shortcut.lnk
[2013/06/30 01:59:45 | 000,001,994 | —- | M] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies (Lite).lnk
[2013/06/30 01:59:45 | 000,001,984 | —- | M] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2013/06/30 01:57:54 | 000,866,014 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/06/29 05:38:31 | 000,007,601 | —- | M] () – C:\Users\Karen\AppData\Local\Resmon.ResmonCfg
[2013/06/17 00:21:48 | 000,000,005 | —- | M] () – C:\Users\Karen\AppData\Roaming\WBPU-TTL.DAT
[2013/06/12 06:03:58 | 000,073,612 | —- | M] () – C:\Users\Karen\Documents\cc_20130612_060345.reg
[2013/06/11 19:09:51 | 000,011,623 | —- | M] () – C:\Users\Karen\AppData\Roaming\UserTile.png
[2013/06/11 17:51:22 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/06/11 17:51:22 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/06/08 09:06:58 | 000,526,336 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/08 06:40:02 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
========== Files Created - No Company Name ==========
[2013/07/06 11:28:53 | 000,001,078 | —- | C] () – C:\Users\Public\Desktop\Open It!.lnk
[2013/07/05 16:45:23 | 000,002,223 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/07/05 16:44:49 | 000,000,896 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/05 16:44:48 | 000,000,892 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/05 03:37:24 | 044,615,733 | —- | C] () – C:\Users\Karen\Desktop\I747UCDLK3_aio.tar.md5
[2013/07/04 22:17:07 | 006,400,000 | —- | C] () – C:\Users\Karen\recovery-twrp-2.5.0.0-SGHI747.tar
[2013/07/04 22:15:51 | 006,092,800 | —- | C] () – C:\Users\Karen\recovery-cwmtouch-6.0.3.1-SGHI747.tar
[2013/06/30 05:22:15 | 000,000,792 | —- | C] () – C:\Users\Karen\Desktop\New folder - Shortcut.lnk
[2013/06/30 01:59:45 | 000,001,994 | —- | C] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies (Lite).lnk
[2013/06/30 01:59:45 | 000,001,984 | —- | C] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2013/06/16 00:30:31 | 000,000,005 | —- | C] () – C:\Users\Karen\AppData\Roaming\WBPU-TTL.DAT
[2013/06/12 06:03:51 | 000,073,612 | —- | C] () – C:\Users\Karen\Documents\cc_20130612_060345.reg
[2013/06/11 19:09:51 | 000,011,623 | —- | C] () – C:\Users\Karen\AppData\Roaming\UserTile.png
[2013/05/27 00:39:51 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2013/05/27 00:39:51 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2013/05/27 00:39:45 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2013/05/22 20:43:52 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2013/05/15 22:47:06 | 000,003,584 | —- | C] () – C:\Users\Karen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/05/15 13:51:41 | 000,000,047 | —- | C] () – C:\Windows\WinInit.Ini
[2013/05/01 15:25:32 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2013/02/11 19:14:10 | 000,000,258 | RHS- | C] () – C:\Users\Karen\ntuser.pol
[2013/02/05 17:52:50 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2013/02/05 17:52:50 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013/02/05 17:52:50 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013/02/05 17:52:50 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013/02/01 01:46:57 | 000,000,211 | —- | C] () – C:\ProgramData\acer.zip
[2013/01/22 03:11:45 | 000,109,784 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2013/01/21 09:24:37 | 000,866,014 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/11/24 09:34:32 | 000,007,601 | —- | C] () – C:\Users\Karen\AppData\Local\Resmon.ResmonCfg
[2012/11/19 02:33:32 | 000,065,656 | —- | C] () – C:\Windows\SysWow64\bdmpegv.dll
[2012/11/19 02:33:30 | 000,022,640 | —- | C] () – C:\Windows\SysWow64\bdmjpeg.dll
[2012/11/17 01:47:00 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
========== ZeroAccess Check ==========
[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/04/08 10:03:12 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Acoustica
[2013/03/09 04:22:57 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\AVG
[2013/06/17 17:15:07 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\AVG2012
[2013/06/14 09:29:01 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Babylon
[2013/06/17 17:15:07 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\BANDISOFT
[2013/06/29 09:04:11 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Canon
[2013/01/21 09:45:12 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\com.AdamOutler
[2013/04/27 20:38:21 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\DriverCure
[2013/05/15 19:44:32 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\DSite
[2013/01/13 09:54:30 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\FileOpen
[2013/05/08 22:00:54 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\FixBee
[2013/06/12 07:12:56 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\iPumper
[2013/06/17 17:10:29 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Kingsoft
[2013/05/14 22:43:09 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Lexmark Productivity Studio
[2013/05/15 19:48:46 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Mipony
[2013/03/17 03:21:04 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\MusicNet
[2013/05/18 15:22:23 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Nico Mak Computing
[2013/06/17 17:10:32 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Nitro
[2013/02/04 04:20:18 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Nitro PDF
[2013/07/03 03:45:47 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Notepad++
[2013/06/17 17:10:33 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\OpenOffice.org
[2013/02/18 13:13:55 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\PDF Architect
[2013/06/17 02:57:57 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\PerformerSoft
[2013/06/17 17:15:08 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Pinger Inc
[2013/06/17 17:15:08 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\player
[2013/05/07 12:58:06 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Sammsoft
[2013/03/21 23:12:30 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Samsung
[2013/06/17 02:51:44 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\SpeedAnalysis2
[2013/01/27 20:28:12 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\StatusWinks
[2013/05/24 02:52:29 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Strongvault
[2013/04/08 10:03:19 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\SynthMaker
[2013/03/04 19:20:20 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\TuneUp Software
[2013/02/28 07:38:35 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Unified Remote
[2013/01/07 20:22:35 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Unity
[2013/07/06 02:04:49 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\USB Optical Mouse
[2013/07/06 11:30:23 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\uTorrent
[2013/05/15 00:09:25 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\X5400 Series
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2009/07/13 21:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 15:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
< MD5 for: EXPLORER.EXE-D5E97654.PF >
[2013/07/06 11:08:23 | 000,068,468 | —- | M] () MD5=39AA2CE244EFAC50D7139B346070AFAA – C:\Windows\Prefetch\EXPLORER.EXE-D5E97654.pf
< MD5 for: IEXPLORE.EXE >
[2013/01/08 20:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2013/05/16 21:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/05/16 21:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_20d88bb252a3770f\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/11/18 00:02:28 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2013/03/12 19:47:53 | 000,770,560 | —- | M] (Microsoft Corporation) MD5=2859EBC065D2E1CCC94161CE28BAC085 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16521_none_20e4a040529a2792\iexplore.exe
[2013/02/24 19:58:09 | 000,775,232 | —- | M] (Microsoft Corporation) MD5=28F93BAFB3EB407E99A7ED3D9DBDE04C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20644_none_ffb93ba237e760ce\iexplore.exe
[2013/04/05 00:55:38 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=2DC6BD1047553611DAEF97C751131A5D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_0a122b746c443b42\iexplore.exe
[2013/05/16 20:57:28 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=3902E280F6117A468D5573343A7AA1F6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_09ffa3426c5372da\iexplore.exe
[2012/11/18 00:02:22 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2013/02/21 07:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_16920d4a1e377ea4\iexplore.exe
[2013/03/12 19:47:49 | 000,775,184 | —- | M] (Microsoft Corporation) MD5=681B380492ACB571ED6CCC1F37F53343 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16521_none_168ff5ee1e396597\iexplore.exe
[2013/01/08 17:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2013/02/02 03:09:12 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=7C2923004FFC497E54F38E835F108EE8 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2013/05/16 22:02:08 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=8F00471CA24ADF8D2AFAACF856EB70A4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_ffaaf8f037f2b0df\iexplore.exe
[2013/02/24 18:52:40 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=A11C5E3E288256C540B7ED8BE3A04B01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20644_none_0a0de5f46c4822c9\iexplore.exe
[2013/02/01 23:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013/02/02 02:37:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2013/04/05 01:02:26 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=AAD90795E84E710543C6C7C2F7048E30 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_20e92fca5296266a\iexplore.exe
[2012/11/15 22:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2013/04/05 02:53:33 | 000,775,232 | —- | M] (Microsoft Corporation) MD5=CEA304830B4770BDA3572B87D0841848 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_169485781e35646f\iexplore.exe
[2013/02/01 23:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2013/04/05 02:23:03 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=DE751E18F8DBF7BCCE46989CBA4A9828 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_ffbd812237e37947\iexplore.exe
[2013/02/21 06:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_20e6b79c5298409f\iexplore.exe
[2013/05/16 22:30:45 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=EDC77CF787FA015205936C9A3228486E – C:\Program Files\Internet Explorer\iexplore.exe
[2013/05/16 22:30:45 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=EDC77CF787FA015205936C9A3228486E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_1683e1601e42b514\iexplore.exe
[2013/01/08 19:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 16:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2012/11/13 21:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/11/14 02:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2012/11/18 00:02:23 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2012/11/18 00:02:28 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/03/12 19:47:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/03/12 19:47:49 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/03/12 19:47:49 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/03/12 19:47:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-A033F7A0.PF >
[2013/07/05 16:49:24 | 000,122,998 | —- | M] () MD5=50DD82EA441D65DF8B41599834D6E0DE – C:\Windows\Prefetch\IEXPLORE.EXE-A033F7A0.pf
< MD5 for: SERVICES >
[2009/06/10 16:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
< MD5 for: SERVICES.CFG >
[2012/09/23 21:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 05:37:26 | 000,558,990 | —- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 – C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.EXE >
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
< MD5 for: SERVICES.MSC >
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
< MD5 for: WINLOGON.ADML >
[2009/07/13 21:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 16:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2013/07/06 11:03:00 | 3018,608,640 | -HS- | M] () – C:\hiberfil.sys
[2013/07/06 11:03:06 | 4024,811,520 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2012/11/25 20:49:31 | 000,001,670 | -HS- | M] () – C:\Users\Karen\AppData\Roaming\Microsoft\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is ACER
Volume Serial Number is 58AF-192C
Directory of C:\
07/14/2009 12:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 12:08 AM Application Data [C:\ProgramData]
07/14/2009 12:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 12:08 AM All Users [C:\ProgramData]
07/14/2009 12:08 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\14d Trial - MX6 6-23
06/23/2013 02:04 PM Application Data [C:\Users\14d Trial - MX6 6-23\AppData\Roaming]
06/23/2013 02:04 PM Cookies [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Cookies]
06/23/2013 02:04 PM Local Settings [C:\Users\14d Trial - MX6 6-23\AppData\Local]
06/23/2013 02:04 PM My Documents [C:\Users\14d Trial - MX6 6-23\Documents]
06/23/2013 02:04 PM NetHood [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/23/2013 02:04 PM PrintHood [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/23/2013 02:04 PM Recent [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Recent]
06/23/2013 02:04 PM SendTo [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\SendTo]
06/23/2013 02:04 PM Start Menu [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Start Menu]
06/23/2013 02:04 PM Templates [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\14d Trial - MX6 6-23\AppData\Local
06/23/2013 02:04 PM Application Data [C:\Users\14d Trial - MX6 6-23\AppData\Local]
06/23/2013 02:04 PM History [C:\Users\14d Trial - MX6 6-23\AppData\Local\Microsoft\Windows\History]
06/23/2013 02:04 PM Temporary Internet Files [C:\Users\14d Trial - MX6 6-23\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\14d Trial - MX6 6-23\Documents
06/23/2013 02:04 PM My Music [C:\Users\14d Trial - MX6 6-23\Music]
06/23/2013 02:04 PM My Pictures [C:\Users\14d Trial - MX6 6-23\Pictures]
06/23/2013 02:04 PM My Videos [C:\Users\14d Trial - MX6 6-23\Videos]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 12:08 AM Application Data [C:\ProgramData]
07/14/2009 12:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Cecil
11/21/2012 08:26 PM Application Data [C:\Users\Cecil\AppData\Roaming]
11/21/2012 08:26 PM Cookies [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Cookies]
11/21/2012 08:26 PM Local Settings [C:\Users\Cecil\AppData\Local]
11/21/2012 08:26 PM My Documents [C:\Users\Cecil\Documents]
11/21/2012 08:26 PM NetHood [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
11/21/2012 08:26 PM PrintHood [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
11/21/2012 08:26 PM Recent [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Recent]
11/21/2012 08:26 PM SendTo [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\SendTo]
11/21/2012 08:26 PM Start Menu [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Start Menu]
11/21/2012 08:26 PM Templates [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Cecil\AppData\Local
11/21/2012 08:26 PM Application Data [C:\Users\Cecil\AppData\Local]
11/21/2012 08:26 PM History [C:\Users\Cecil\AppData\Local\Microsoft\Windows\History]
11/21/2012 08:26 PM Temporary Internet Files [C:\Users\Cecil\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Cecil\Documents
11/21/2012 08:26 PM My Music [C:\Users\Cecil\Music]
11/21/2012 08:26 PM My Pictures [C:\Users\Cecil\Pictures]
11/21/2012 08:26 PM My Videos [C:\Users\Cecil\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 12:08 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 12:08 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 12:08 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM My Documents [C:\Users\Default\Documents]
07/14/2009 12:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 12:08 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 12:08 AM My Music [C:\Users\Default\Music]
07/14/2009 12:08 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 12:08 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Karen
11/17/2012 01:29 AM Application Data [C:\Users\Karen\AppData\Roaming]
11/17/2012 01:29 AM Cookies [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Cookies]
11/17/2012 01:29 AM Local Settings [C:\Users\Karen\AppData\Local]
11/17/2012 01:29 AM My Documents [C:\Users\Karen\Documents]
11/17/2012 01:29 AM NetHood [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
11/17/2012 01:29 AM PrintHood [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
11/17/2012 01:29 AM Recent [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Recent]
11/17/2012 01:29 AM SendTo [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\SendTo]
11/17/2012 01:29 AM Start Menu [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Start Menu]
11/17/2012 01:29 AM Templates [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Karen\AppData\Local
11/17/2012 01:29 AM Application Data [C:\Users\Karen\AppData\Local]
11/17/2012 01:29 AM History [C:\Users\Karen\AppData\Local\Microsoft\Windows\History]
11/17/2012 01:29 AM Temporary Internet Files [C:\Users\Karen\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Karen\Documents
11/17/2012 01:29 AM My Music [C:\Users\Karen\Music]
11/17/2012 01:29 AM My Pictures [C:\Users\Karen\Pictures]
11/17/2012 01:29 AM My Videos [C:\Users\Karen\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 12:08 AM My Music [C:\Users\Public\Music]
07/14/2009 12:08 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 12:08 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public Account
04/24/2013 05:00 PM Application Data [C:\Users\Public Account\AppData\Roaming]
04/24/2013 05:00 PM Cookies [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Cookies]
04/24/2013 05:00 PM Local Settings [C:\Users\Public Account\AppData\Local]
04/24/2013 05:00 PM My Documents [C:\Users\Public Account\Documents]
04/24/2013 05:00 PM NetHood [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
04/24/2013 05:00 PM PrintHood [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
04/24/2013 05:00 PM Recent [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Recent]
04/24/2013 05:00 PM SendTo [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\SendTo]
04/24/2013 05:00 PM Start Menu [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Start Menu]
04/24/2013 05:00 PM Templates [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Public Account\AppData\Local
04/24/2013 05:00 PM Application Data [C:\Users\Public Account\AppData\Local]
04/24/2013 05:00 PM History [C:\Users\Public Account\AppData\Local\Microsoft\Windows\History]
04/24/2013 05:00 PM Temporary Internet Files [C:\Users\Public Account\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Public Account\Documents
04/24/2013 05:00 PM My Music [C:\Users\Public Account\Music]
04/24/2013 05:00 PM My Pictures [C:\Users\Public Account\Pictures]
04/24/2013 05:00 PM My Videos [C:\Users\Public Account\Videos]
0 File(s) 0 bytes
Directory of C:\Users\test
06/16/2013 05:44 AM Application Data [C:\Users\test\AppData\Roaming]
06/16/2013 05:44 AM Cookies [C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies]
06/16/2013 05:44 AM Local Settings [C:\Users\test\AppData\Local]
06/16/2013 05:44 AM My Documents [C:\Users\test\Documents]
06/16/2013 05:44 AM NetHood [C:\Users\test\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/16/2013 05:44 AM PrintHood [C:\Users\test\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/16/2013 05:44 AM Recent [C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent]
06/16/2013 05:44 AM SendTo [C:\Users\test\AppData\Roaming\Microsoft\Windows\SendTo]
06/16/2013 05:44 AM Start Menu [C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu]
06/16/2013 05:44 AM Templates [C:\Users\test\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\test\AppData\Local
06/16/2013 05:44 AM Application Data [C:\Users\test\AppData\Local]
06/16/2013 05:44 AM History [C:\Users\test\AppData\Local\Microsoft\Windows\History]
06/16/2013 05:44 AM Temporary Internet Files [C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\test\Documents
06/16/2013 05:44 AM My Music [C:\Users\test\Music]
06/16/2013 05:44 AM My Pictures [C:\Users\test\Pictures]
06/16/2013 05:44 AM My Videos [C:\Users\test\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
114 Dir(s) 217,006,120,960 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/11/18 03:06:52 | 000,000,221 | -HS- | M] () – C:\Users\Karen\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2013/07/06 11:56:59 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karen\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:0B4227B4
< End of report >
OTL Extras logfile created on: 7/6/2013 12:19:29 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karen\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.75 Gb Total Physical Memory | 2.68 Gb Available Physical Memory | 71.48% Memory free
7.50 Gb Paging File | 6.10 Gb Available in Paging File | 81.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.27 Gb Total Space | 202.13 Gb Free Space | 70.61% Space Free | Partition Type: NTFS
Computer Name: KAREN-PC | User Name: Karen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04353690-03D4-4A57-9863-4DBDCEB97442}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0A528707-4401-4F98-8432-16242EC3E287}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{1E951B86-E28F-4DD0-BD2A-7FA925210629}" = lport=138 | protocol=17 | dir=in | app=system |
"{449985BB-9195-4E88-8634-8016EEF0B94E}" = rport=445 | protocol=6 | dir=out | app=system |
"{4C1FF8B0-DF2A-46A0-96B6-E58B479D3DAC}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4E090BA2-FC5E-4603-943C-670857F6331C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{56C274C6-046C-4C64-BD06-9EE20D093BE8}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{596DBDF7-85D2-488A-B838-6A969CE77F9C}" = rport=138 | protocol=17 | dir=out | app=system |
"{751F9B82-3A12-4656-94DE-9FB96B237879}" = lport=137 | protocol=17 | dir=in | app=system |
"{80BBCCF9-033E-482E-B72D-2C98977A6066}" = rport=139 | protocol=6 | dir=out | app=system |
"{87D08CB7-FF0E-4E1B-A89C-2E785D494F14}" = rport=10243 | protocol=6 | dir=out | app=system |
"{8DC73AA1-EFF9-4783-95E5-AD3F0CE0894D}" = lport=6102 | protocol=6 | dir=in | name=rdm |
"{A64D2A49-DC84-41AD-985D-C4ACE09E60CC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A74C8063-62ED-41AE-B487-975BBAE77AA1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{AE3F06D3-7775-4B0E-B458-8F69080537AB}" = lport=139 | protocol=6 | dir=in | app=system |
"{BED21E29-E923-4815-9206-17AFADE16E2D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C3A66DDF-E9A2-4C6E-8029-3A6F0317F4C3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D1EA2668-418B-4ADC-9A41-B6B20AA1152A}" = rport=137 | protocol=17 | dir=out | app=system |
"{E0C150C3-94F5-40A6-8967-73BD94722284}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E3F416FF-410E-42E7-9D44-9D4F88E5321A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E7DC880E-9467-482F-9B2A-A48406F6CCB9}" = lport=10243 | protocol=6 | dir=in | app=system |
"{E85E3204-E598-4EFB-B68B-9A9E7B42A4CD}" = lport=445 | protocol=6 | dir=in | app=system |
"{F02E49F6-D3D8-47A8-8A4E-37BB0EADC9EE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A641224-7230-400C-9395-188024214D22}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{12A25B82-8FE4-455C-99DC-65234700253F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{17D1EFB9-2EEF-4E31-B922-3565EE6B0D29}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{208BFEF4-257A-4744-BEC7-DFF27732712C}" = protocol=17 | dir=in | app=c:\users\karen\appdata\roaming\utorrent\utorrent.exe |
"{212CC471-B83C-4989-8123-E92E5D7694CF}" = protocol=6 | dir=out | app=system |
"{217DD729-2729-4EF5-91B8-3724F90E3F46}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2BE468CF-739A-4A49-B9E1-447DCD227CF1}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{2CB7F60B-F2A1-4D52-B0B7-505744938BDA}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2D66DF65-85A1-46A1-AA20-930EBE03E7B0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2DF4A00C-5F00-49ED-8585-A8FC345CFDCF}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2EC655F1-820C-4036-8DB4-8DA7AAA0CF76}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{35CB2FC3-4D0E-4610-B08A-E79F179E4D1B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3CAAF28C-30D0-4F01-8822-E927768F0476}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3D6DEBDB-EF5C-4037-95CB-F9D80CDF5ADD}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4F2E5FA2-773C-4EF7-B933-268060A43C4B}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{4FF73137-72FC-4EFE-937C-D800DFAFA75F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{53FC0DD2-86D5-4073-9D0B-FADF8011C6AF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{5CA8B13D-3CB0-44F0-85E1-FEC219813A31}" = dir=in | app=c:\program files (x86)\file type assistant\tsassist.exe |
"{5D13D74D-6CFF-4B37-BB06-502123AD0789}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{675DA394-AEC4-43AB-B7FF-FA2A947256A6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6A477AFA-A2A9-43CD-9D52-DDCBF3879B93}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{6BDFEFBF-3283-4FD2-960B-C625572F08D8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7E4993FE-BAC1-42C0-A598-AE02C431DA32}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{8D4FC570-77DA-461C-A57D-9E4A60D01F97}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{934F65A0-62F9-4BA2-AF92-001E322E6A2E}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{9A2A56F3-E746-42CC-9EAA-7F295C7A473F}" = dir=in | app=c:\program files (x86)\file type assistant\tsassist.exe |
"{9AED4ED0-DF61-41A2-A2D0-83CE65951BBE}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{AA298193-39C5-4CF9-91CD-FC6110CFC106}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{AA766D47-2BDC-4B77-A0A5-FC8FCE2F6143}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{AB93609D-B3D8-433C-A690-A3314BB51067}" = protocol=6 | dir=in | app=c:\users\karen\appdata\roaming\utorrent\utorrent.exe |
"{C437F080-C2C6-4DEB-8F30-9AC722DA96E1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CDC4C15B-1196-4257-97FE-8D30B4121EDD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DBC5B321-F6D1-4C99-80D7-0C15AE122854}" = dir=in | app=c:\program files (x86)\file type assistant\tsassist.exe |
"{DC299E5B-CDFD-4D64-81FC-6B07700C00DB}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{EE97D8AC-B6D8-4870-B8F6-5FFC7B68875C}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{F43AA4BA-2052-4F30-8A18-5003F6DA099C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FDFF5759-4AA0-4E6C-90FD-7BFB33C026A6}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC4
"{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables
"{26A24AE4-039D-4CA4-87B4-2F86417017FF}" = Java 7 Update 17 (64-bit)
"{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program
"{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7ACE202B-1B01-4B43-B6AE-03D66D621CDE}" = Microsoft SQL Server 2008 RsFx Driver
"{893F27E6-D6BE-4B9F-80E6-0ADA694A31A8}" = Microsoft SQL Server 2008 Common Files
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BCA26999-EC22-3007-BB79-638913079C9A}" = Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU
"{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D50E19B5-A29A-4A78-8381-0E562B40CDFD}" = AVG 2012
"{DF167CE3-60E7-44EA-99EC-2507C51F37AE}" = Microsoft SQL Server 2008 Database Engine Shared
"{DFE4E6BB-70F0-4292-B7EB-7A3AD48EBB5C}" = AVG 2012
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = Microsoft SQL Server 2008 Database Engine Services
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services
"{FCADA26A-5672-31DD-BF0E-BA76ECF9B02D}" = Microsoft Help Viewer 1.0
"AVG" = AVG 2012
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2BFAOR2C06_118" = HDAUDIO Soft Data Fax Modem with SmartCP
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"WinRAR archiver" = WinRAR 4.00 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{23170F69-40C1-2701-0921-000001000000}" = 7-Zip 9.21
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{BA8B8ADA-084F-4F79-A0CA-6E58A0808794}" = FlashPlayer
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EEAE45EB-C1E3-4CCD-930D-D7B40F810063}" = USB Optical Mouse
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"Acoustica Mixcraft 6" = Acoustica Mixcraft 6
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG Secure Search" = AVG Security Toolbar
"Bandicam" = Bandicam
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"DomaIQ Uninstaller" = DomaIQ
"Google Chrome" = Google Chrome
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"Kingsoft Office" = Kingsoft Office 2012 (8.1.0.3385)
"OpenIt Open It!" = Open It!
"Trusted Software Assistant_is1" = File Type Assistant
"uTorrent" = µTorrent
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"DSite" = Update for Zip Opener
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 4/15/2013 11:12:21 PM | Computer Name = Karen-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1199461
Error - 4/15/2013 11:12:22 PM | Computer Name = Karen-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 4/15/2013 11:12:22 PM | Computer Name = Karen-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1200678
Error - 4/15/2013 11:12:22 PM | Computer Name = Karen-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1200678
Error - 4/17/2013 1:02:57 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 3038
Description =
Error - 4/17/2013 1:02:58 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 7040
Description =
Error - 4/17/2013 1:02:58 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 7042
Description =
Error - 4/17/2013 1:02:59 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 3028
Description =
Error - 4/17/2013 1:02:59 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 3058
Description =
Error - 4/17/2013 1:02:59 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 7010
Description =
[ Media Center Events ]
Error - 12/22/2012 12:49:22 AM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 10:49:22 PM - Error connecting to the internet. 10:49:22 PM - Unable
to contact server..
Error - 12/22/2012 12:52:52 AM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 10:52:47 PM - Error connecting to the internet. 10:52:47 PM - Unable
to contact server..
Error - 12/22/2012 6:23:33 AM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 4:23:33 AM - Error connecting to the internet. 4:23:33 AM - Unable
to contact server..
Error - 12/22/2012 6:24:29 AM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 4:24:28 AM - Error connecting to the internet. 4:24:28 AM - Unable
to contact server..
Error - 5/28/2013 5:02:58 PM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 4:02:57 PM - Error connecting to the internet. 4:02:57 PM - Unable
to contact server..
[ System Events ]
Error - 7/6/2013 11:16:09 AM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535
Error - 7/6/2013 12:05:56 PM | Computer Name = Karen-PC | Source = PNRPSvc | ID = 102
Description =
Error - 7/6/2013 12:05:56 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535
Error - 7/6/2013 12:05:56 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535
Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = PNRPSvc | ID = 102
Description =
Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = PNRPSvc | ID = 102
Description =
Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535
Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535
Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535
Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535
< End of report >
OTL logfile created on: 7/6/2013 12:19:29 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karen\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.75 Gb Total Physical Memory | 2.68 Gb Available Physical Memory | 71.48% Memory free
7.50 Gb Paging File | 6.10 Gb Available in Paging File | 81.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.27 Gb Total Space | 202.13 Gb Free Space | 70.61% Space Free | Partition Type: NTFS
Computer Name: KAREN-PC | User Name: Karen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Karen\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
PRC - C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\MouseHid.exe ()
PRC - C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\Tra.exe ()
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\MouseHid.exe ()
MOD - C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\Tra.exe ()
========== Services (SafeList) ==========
SRV:64bit: - (Live Updater Service) – C:\Program Files\Acer\Acer Updater\UpdaterService.exe (Acer Incorporated)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV:64bit: - (XAudioService) – C:\Windows\SysNative\drivers\XAudio64.exe (Conexant Systems, Inc.)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (vToolbarUpdater14.2.0) – C:\Program Files (x86)\Common Files\AVG Secure Search\vToolbarUpdater\14.2.0\ToolbarUpdater.exe ()
SRV - (avgfws) – C:\Program Files (x86)\AVG\AVG2012\avgfws.exe (AVG Technologies CZ, s.r.o.)
SRV - (AVGIDSAgent) – C:\Program Files (x86)\AVG\AVG2012\avgidsagent.exe (AVG Technologies CZ, s.r.o.)
SRV - (avgwd) – C:\Program Files (x86)\AVG\AVG2012\avgwdsvc.exe (AVG Technologies CZ, s.r.o.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (dg_ssudbus) – C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (ssudmdm) – C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (ssadmdm) – C:\Windows\SysNative\drivers\ssadmdm.sys (MCCI Corporation)
DRV:64bit: - (ssadbus) – C:\Windows\SysNative\drivers\ssadbus.sys (MCCI Corporation)
DRV:64bit: - (androidusb) – C:\Windows\SysNative\drivers\ssadadb.sys (Google Inc)
DRV:64bit: - (ssadmdfl) – C:\Windows\SysNative\drivers\ssadmdfl.sys (MCCI Corporation)
DRV:64bit: - (atikmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (Avgtdia) – C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (athr) – C:\Windows\SysNative\drivers\athrx.sys (Qualcomm Atheros Communications, Inc.)
DRV:64bit: - (avgtp) – C:\Windows\SysNative\drivers\avgtpx64.sys (AVG Technologies)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft Corporation)
DRV:64bit: - (pwdrvio) – C:\Windows\SysNative\pwdrvio.sys ()
DRV:64bit: - (pwdspio) – C:\Windows\SysNative\pwdspio.sys ()
DRV:64bit: - (taphss6) – C:\Windows\SysNative\drivers\taphss6.sys (Anchorfree Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (AVGIDSDriver) – C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgldx64) – C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (AVGIDSHA) – C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (Avgrkx64) – C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) – C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSFilter) – C:\Windows\SysNative\drivers\avgidsfiltera.sys (AVG Technologies CZ, s.r.o. )
DRV:64bit: - (Avgfwfd) – C:\Windows\SysNative\drivers\avgfwd6a.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (NMgamingmsFltr) – C:\Windows\SysNative\drivers\NMgamingms.sys (Primax Ltd)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems, Inc.)
DRV:64bit: - (k57nd60a) – C:\Windows\SysNative\drivers\k57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (WDC_SAM) – C:\Windows\SysNative\drivers\wdcsam64.sys (Western Digital Technologies)
DRV:64bit: - (HSF_DPV) – C:\Windows\SysNative\drivers\CAX_DPV.sys (Conexant Systems, Inc.)
DRV:64bit: - (CAXHWAZL) – C:\Windows\SysNative\drivers\CAXHWAZL.sys (Conexant Systems, Inc.)
DRV:64bit: - (winachsf) – C:\Windows\SysNative\drivers\CAX_CNXT.sys (Conexant Systems, Inc.)
DRV:64bit: - (XAudio) – C:\Windows\SysNative\drivers\XAudio64.sys (Conexant Systems, Inc.)
DRV:64bit: - (mdmxsdk) – C:\Windows\SysNative\drivers\mdmxsdk.sys (Conexant)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://start.sweetpacks.com/?src=10&st;…0-00262D7BE3A6}
IE - HKLM\..\SearchScopes,DefaultScope = {EEE6C360-6118-11DC-9C72-001320C79847}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{84dc9f6c-c9a5-4c64-ab67-d6ef60f963c8}: "URL" = http://search.mywebsearch.com/mywebsearch/…r={searchTerms}
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.helpmefindyour.info/?l=1&…lg=EN&cc;=US
IE - HKLM\..\SearchScopes\{EEE6C360-6118-11DC-9C72-001320C79847}: "URL" = http://start.sweetpacks.com/?src=6&q;={…0-00262D7BE3A6}
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com/ie
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com/ie
IE - HKCU\..\SearchScopes,DefaultScope = {4A6AA337-BCDF-4E13-A072-C640AB2FBB09}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{4A6AA337-BCDF-4E13-A072-C640AB2FBB09}: "URL" = http://www.google.com/search?q={searchTerm…tf8&oe;=utf8
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.com/search?q={sear
IE - HKCU\..\SearchScopes\{7A0333EB-26A7-4F8B-92C1-862428320E4F}: "URL" = http://searchou.com/?q={searchTerms}&i;…filt=5&r;=92
IE - HKCU\..\SearchScopes\{95B7759C-8C7F-4BF1-B163-73684A933233}: "URL" = http://isearch.avg.com/search?cid={62F2CD1…mp;d=2012-11-25 19:36:44&v;=14.2.0.1&pid;=avg&sg;=&sap;=dsp&q;={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = 64.191.70.164:8090
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_7_700_224.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll ()
FF - HKLM\Software\MozillaPlugins\@avg.com/AVG SiteSafety plugin,version=11.0.0.1,application/x-avg-sitesafety-plugin: C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.21.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 11.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\avg@toolbar: C:\ProgramData\AVG Secure Search\FireFoxExt\14.2.0.1 [2013/02/18 13:46:50 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\statuswinks@StatusWinks: C:\Users\Karen\AppData\Roaming\Mozilla\Extensions\statuswinks@StatusWinks
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{F53C93F1-07D5-430c-86D4-C9531B27DFAF}: C:\Program Files (x86)\AVG\AVG2012\Firefox\DoNotTrack\ [2012/11/25 22:34:36 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\statuswinks@StatusWinks: C:\Users\Karen\AppData\Roaming\Mozilla\Extensions\statuswinks@StatusWinks
[2013/06/17 02:51:44 | 000,000,000 | —D | M] (No name found) – C:\Users\Karen\AppData\Roaming\mozilla\Extensions
[2013/06/17 17:14:34 | 000,000,000 | —D | M] (Speed Analysis 2) – C:\Users\Karen\AppData\Roaming\mozilla\Extensions\[removed]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&q;={searchTerms}&{google:cursorPosition}sugkey={google:suggestAPIKeyParameter},
CHR - homepage:
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\27.0.1453.116\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Browser\nppdf32.dll
CHR - plugin: AVG SiteSafety plugin (Enabled) = C:\Program Files (x86)\Common Files\AVG Secure Search\SiteSafetyInstaller\14.2.0\\npsitesafety.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U21 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_7_700_224.dll
CHR - Extension: Google Drive = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: The Weather Channel for Chrome = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\iflpcokdamgefbghpdipcibmhlkdopop\1.0.0.4_0\
CHR - Extension: Click&Clean; App = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pdabfienifkbhoihedcgeogidfmibmhp\8.0_0\
CHR - Extension: Gmail = C:\Users\Karen\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2013/05/10 02:15:32 | 000,447,225 | R— | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 www.007guard.com
O1 - Hosts: 127.0.0.1 007guard.com
O1 - Hosts: 127.0.0.1 008i.com
O1 - Hosts: 127.0.0.1 www.008k.com
O1 - Hosts: 127.0.0.1 008k.com
O1 - Hosts: 127.0.0.1 www.00hq.com
O1 - Hosts: 127.0.0.1 00hq.com
O1 - Hosts: 127.0.0.1 010402.com
O1 - Hosts: 127.0.0.1 www.032439.com
O1 - Hosts: 127.0.0.1 032439.com
O1 - Hosts: 127.0.0.1 www.0scan.com
O1 - Hosts: 127.0.0.1 0scan.com
O1 - Hosts: 127.0.0.1 www.1000gratisproben.com
O1 - Hosts: 127.0.0.1 1000gratisproben.com
O1 - Hosts: 127.0.0.1 1001namen.com
O1 - Hosts: 127.0.0.1 www.1001namen.com
O1 - Hosts: 127.0.0.1 100888290cs.com
O1 - Hosts: 127.0.0.1 www.100888290cs.com
O1 - Hosts: 127.0.0.1 www.100sexlinks.com
O1 - Hosts: 127.0.0.1 100sexlinks.com
O1 - Hosts: 127.0.0.1 www.10sek.com
O1 - Hosts: 127.0.0.1 10sek.com
O1 - Hosts: 127.0.0.1 www.1-2005-search.com
O1 - Hosts: 127.0.0.1 1-2005-search.com
O1 - Hosts: 127.0.0.1 www.123fporn.info
O1 - Hosts: 15354 more lines…
O2:64bit: - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (no name) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No CLSID value found.
O2 - BHO: (AVG Do Not Track) - {31332EEF-CB9F-458F-AFEB-D30E9A66B6BA} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3 - HKLM\..\Toolbar: (AVG Security Toolbar) - {95B7759C-8C7F-4BF1-B163-73684A933233} - C:\Program Files (x86)\AVG Secure Search\14.2.0.1\AVG Secure Search_toolbar.dll ()
O4 - HKLM..\Run: [AVG_TRAY] C:\Program Files (x86)\AVG\AVG2012\avgtray.exe (AVG Technologies CZ, s.r.o.)
O4 - HKLM..\Run: [USB Optical Mouse] C:\Program Files (x86)\USB Optical Mouse\USB Optical Mouse\MouseHid.exe ()
O4 - HKCU..\Run: [] C:\Program Files (x86)\Samsung\Kies\External\FirmwareUpdate\KiesPDLR.exe (Samsung)
O4 - HKLM..\RunOnce: [Del1568231] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O4 - HKCU..\RunOnce: [Del1568231] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiea.dll (AVG Technologies CZ, s.r.o.)
O9 - Extra Button: AVG Do Not Track - {68BCFFE1-A2DA-4B40-9068-87ECBFC19D16} - C:\Program Files (x86)\AVG\AVG2012\avgdtiex.dll (AVG Technologies CZ, s.r.o.)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000005 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000005 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16:64bit: - DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 1.7.0_13)
O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-…indows-i586.cab (Java Plug-in 10.17.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{41E3175A-0BE7-433E-82CA-03AE7DC02D4D}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgppa.dll (AVG Technologies CZ, s.r.o.)
O18:64bit: - Protocol\Handler\viprotocol - No CLSID value found
O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG2012\avgpp.dll (AVG Technologies CZ, s.r.o.)
O18 - Protocol\Handler\viprotocol {B658800C-F66E-4EF3-AB85-6C0C227862A9} - C:\Program Files (x86)\Common Files\AVG Secure Search\ViProtocolInstaller\14.2.0\ViProtocol.dll ()
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O33 - MountPoints2\{59e7e991-7e37-11e2-9de6-00262d7be3a6}\Shell - "" = AutoRun
O33 - MountPoints2\{59e7e991-7e37-11e2-9de6-00262d7be3a6}\Shell\AutoRun\command - "" = E:\PcOptions.exe
O33 - MountPoints2\{75f45eba-92fb-11e2-b25c-00262d7be3a6}\Shell - "" = AutoRun
O33 - MountPoints2\{75f45eba-92fb-11e2-b25c-00262d7be3a6}\Shell\AutoRun\command - "" = "E:\WD SmartWare.exe" autoplay=true
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
Drivers32:64bit: msacm.bdmpeg - bdmpega64.acm ()
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:64bit: vidc.mjpg - bdmjpeg64.dll ()
Drivers32:64bit: vidc.mpeg - bdmpegv64.dll ()
Drivers32: msacm.bdmpeg - C:\Windows\SysWow64\bdmpega.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.mjpg - C:\Windows\SysWow64\bdmjpeg.dll ()
Drivers32: vidc.mpeg - C:\Windows\SysWow64\bdmpegv.dll ()
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/07/06 11:56:58 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Karen\Desktop\OTL.exe
[2013/07/06 11:28:53 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Open It!
[2013/07/06 11:28:51 | 000,000,000 | —D | C] – C:\Program Files (x86)\OpenIt
[2013/07/06 02:04:49 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\USB Optical Mouse
[2013/07/06 02:01:18 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\USB Optical Mouse
[2013/07/06 02:00:58 | 000,000,000 | —D | C] – C:\Program Files (x86)\USB Optical Mouse
[2013/07/05 16:45:23 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/07/04 20:48:14 | 000,000,000 | —D | C] – C:\Users\Public\Documents\CrashDump
[2013/07/04 17:09:50 | 000,000,000 | —D | C] – C:\Users\Karen\Desktop\Apks-7_4_2013
[2013/06/30 02:12:23 | 001,919,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WdfCoInstaller01005.dll
[2013/06/30 02:12:23 | 001,919,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdfCoInstaller01005.dll
[2013/06/30 02:12:23 | 000,188,232 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadmdm.sys
[2013/06/30 02:12:23 | 000,169,288 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadbus.sys
[2013/06/30 02:12:23 | 000,038,080 | —- | C] (Google Inc) – C:\Windows\SysNative\drivers\ssadadb.sys
[2013/06/30 02:12:23 | 000,021,320 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadmdfl.sys
[2013/06/30 02:12:23 | 000,017,736 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadwhnt.sys
[2013/06/30 02:12:23 | 000,017,736 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadwh.sys
[2013/06/30 02:12:23 | 000,017,224 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadcmnt.sys
[2013/06/30 02:12:23 | 000,017,224 | —- | C] (MCCI Corporation) – C:\Windows\SysNative\drivers\ssadcm.sys
[2013/06/30 01:59:45 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Samsung
[2013/06/30 01:59:26 | 000,821,824 | —- | C] (Devguru Co., Ltd.) – C:\Windows\SysWow64\dgderapi.dll
[2013/06/24 23:07:48 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Local\Facebook
[2013/06/17 19:02:37 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/06/17 19:02:37 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/06/17 19:02:37 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\RegisterIEPKEYs.exe
[2013/06/17 19:02:37 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\RegisterIEPKEYs.exe
[2013/06/17 19:02:37 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/06/17 19:02:37 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/06/17 19:02:37 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/06/17 19:02:37 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/06/17 19:02:37 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/06/17 19:02:35 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/06/17 19:02:35 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/06/17 19:02:35 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/06/17 19:02:34 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/06/17 19:01:39 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/06/17 19:01:38 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/17 17:26:58 | 000,751,104 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\win32spl.dll
[2013/06/17 17:26:57 | 000,492,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\win32spl.dll
[2013/06/17 17:26:45 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/06/17 17:26:45 | 000,024,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/06/17 17:26:39 | 001,424,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WindowsCodecs.dll
[2013/06/17 17:26:00 | 001,192,448 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certutil.exe
[2013/06/17 17:26:00 | 000,903,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certutil.exe
[2013/06/17 17:25:59 | 001,464,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/06/17 17:25:59 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll
[2013/06/17 17:25:59 | 000,052,224 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\certenc.dll
[2013/06/17 17:25:59 | 000,043,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\certenc.dll
[2013/06/17 17:25:46 | 001,887,232 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\d3d11.dll
[2013/06/17 17:25:46 | 001,505,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\d3d11.dll
[2013/06/17 02:51:44 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Mozilla
[2013/06/17 02:51:43 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\SpeedAnalysis2
[2013/06/17 02:51:35 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Haali Media Splitter
[2013/06/16 05:25:38 | 000,000,000 | —D | C] – C:\Program Files (x86)\Acoustica Shared Effects
[2013/06/14 23:07:36 | 000,000,000 | —D | C] – C:\Users\Karen\Desktop\MINE
[2013/06/14 09:29:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\GPLGS
[2013/06/14 09:29:04 | 000,000,000 | —D | C] – C:\Program Files\PDFCreator
[2013/06/14 09:29:01 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Babylon
[2013/06/14 09:29:01 | 000,000,000 | —D | C] – C:\ProgramData\Babylon
[2013/06/13 16:00:16 | 000,000,000 | —D | C] – C:\Users\Karen\AppData\Roaming\Malwarebytes
[2013/06/13 16:00:04 | 000,000,000 | —D | C] – C:\ProgramData\Malwarebytes
[2013/06/12 14:06:29 | 000,000,000 | —D | C] – C:\Program Files (x86)\Realtek
[2013/06/12 14:05:20 | 000,000,000 | -H-D | C] – C:\Program Files (x86)\Temp
[2013/06/12 06:40:03 | 000,000,000 | —D | C] – C:\ProgramData\Innovative Solutions
[2013/06/12 06:40:03 | 000,000,000 | —D | C] – C:\Windows\Fonts\AdvUninstal
[2013/06/12 06:39:55 | 000,000,000 | —D | C] – C:\Program Files (x86)\Innovative Solutions
[2013/06/12 05:35:43 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CCleaner
[2013/06/12 05:35:39 | 000,000,000 | —D | C] – C:\Program Files\CCleaner
[2013/06/12 05:25:59 | 000,000,000 | —D | C] – C:\ProgramData\SparkTrust
========== Files - Modified Within 30 Days ==========
[2013/07/06 12:14:01 | 000,000,374 | —- | M] () – C:\Windows\tasks\WpsUpdateTask_Karen.job
[2013/07/06 11:56:59 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karen\Desktop\OTL.exe
[2013/07/06 11:51:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/07/06 11:49:00 | 000,000,896 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/06 11:28:53 | 000,001,078 | —- | M] () – C:\Users\Public\Desktop\Open It!.lnk
[2013/07/06 11:28:53 | 000,000,286 | —- | M] () – C:\Windows\tasks\DSite.job
[2013/07/06 11:11:50 | 000,015,824 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/07/06 11:11:50 | 000,015,824 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/07/06 11:05:18 | 000,000,892 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/06 11:03:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/07/06 11:03:00 | 3018,608,640 | -HS- | M] () – C:\hiberfil.sys
[2013/07/06 08:21:26 | 125,748,209 | —- | M] () – C:\Windows\SysNative\drivers\AVG\incavi.avm
[2013/07/05 21:00:55 | 000,871,798 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/07/05 21:00:55 | 000,726,172 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/07/05 21:00:55 | 000,146,158 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/07/05 16:55:53 | 000,002,247 | —- | M] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/07/05 16:45:23 | 000,002,223 | —- | M] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/07/05 03:38:13 | 044,615,733 | —- | M] () – C:\Users\Karen\Desktop\I747UCDLK3_aio.tar.md5
[2013/07/04 22:17:07 | 006,400,000 | —- | M] () – C:\Users\Karen\recovery-twrp-2.5.0.0-SGHI747.tar
[2013/07/04 22:15:51 | 006,092,800 | —- | M] () – C:\Users\Karen\recovery-cwmtouch-6.0.3.1-SGHI747.tar
[2013/07/01 04:20:13 | 000,401,592 | —- | M] () – C:\Windows\SysNative\drivers\AVG\iavichjg.avm
[2013/07/01 00:46:06 | 000,000,211 | —- | M] () – C:\ProgramData\acer.zip
[2013/06/30 05:22:15 | 000,000,792 | —- | M] () – C:\Users\Karen\Desktop\New folder - Shortcut.lnk
[2013/06/30 01:59:45 | 000,001,994 | —- | M] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies (Lite).lnk
[2013/06/30 01:59:45 | 000,001,984 | —- | M] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2013/06/30 01:57:54 | 000,866,014 | —- | M] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2013/06/29 05:38:31 | 000,007,601 | —- | M] () – C:\Users\Karen\AppData\Local\Resmon.ResmonCfg
[2013/06/17 00:21:48 | 000,000,005 | —- | M] () – C:\Users\Karen\AppData\Roaming\WBPU-TTL.DAT
[2013/06/12 06:03:58 | 000,073,612 | —- | M] () – C:\Users\Karen\Documents\cc_20130612_060345.reg
[2013/06/11 19:09:51 | 000,011,623 | —- | M] () – C:\Users\Karen\AppData\Roaming\UserTile.png
[2013/06/11 17:51:22 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/06/11 17:51:22 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/06/08 09:06:58 | 000,526,336 | —- | M] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/06/08 06:40:02 | 000,391,168 | —- | M] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
========== Files Created - No Company Name ==========
[2013/07/06 11:28:53 | 000,001,078 | —- | C] () – C:\Users\Public\Desktop\Open It!.lnk
[2013/07/05 16:45:23 | 000,002,223 | —- | C] () – C:\Users\Public\Desktop\Google Chrome.lnk
[2013/07/05 16:44:49 | 000,000,896 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2013/07/05 16:44:48 | 000,000,892 | —- | C] () – C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2013/07/05 03:37:24 | 044,615,733 | —- | C] () – C:\Users\Karen\Desktop\I747UCDLK3_aio.tar.md5
[2013/07/04 22:17:07 | 006,400,000 | —- | C] () – C:\Users\Karen\recovery-twrp-2.5.0.0-SGHI747.tar
[2013/07/04 22:15:51 | 006,092,800 | —- | C] () – C:\Users\Karen\recovery-cwmtouch-6.0.3.1-SGHI747.tar
[2013/06/30 05:22:15 | 000,000,792 | —- | C] () – C:\Users\Karen\Desktop\New folder - Shortcut.lnk
[2013/06/30 01:59:45 | 000,001,994 | —- | C] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies (Lite).lnk
[2013/06/30 01:59:45 | 000,001,984 | —- | C] () – C:\Users\Karen\Application Data\Microsoft\Internet Explorer\Quick Launch\Samsung Kies.lnk
[2013/06/16 00:30:31 | 000,000,005 | —- | C] () – C:\Users\Karen\AppData\Roaming\WBPU-TTL.DAT
[2013/06/12 06:03:51 | 000,073,612 | —- | C] () – C:\Users\Karen\Documents\cc_20130612_060345.reg
[2013/06/11 19:09:51 | 000,011,623 | —- | C] () – C:\Users\Karen\AppData\Roaming\UserTile.png
[2013/05/27 00:39:51 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2013/05/27 00:39:51 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2013/05/27 00:39:45 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2013/05/22 20:43:52 | 000,030,568 | —- | C] () – C:\Windows\MusiccityDownload.exe
[2013/05/15 22:47:06 | 000,003,584 | —- | C] () – C:\Users\Karen\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/05/15 13:51:41 | 000,000,047 | —- | C] () – C:\Windows\WinInit.Ini
[2013/05/01 15:25:32 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2013/02/11 19:14:10 | 000,000,258 | RHS- | C] () – C:\Users\Karen\ntuser.pol
[2013/02/05 17:52:50 | 000,974,848 | —- | C] () – C:\Windows\SysWow64\cis-2.4.dll
[2013/02/05 17:52:50 | 000,081,920 | —- | C] () – C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2013/02/05 17:52:50 | 000,065,536 | —- | C] () – C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2013/02/05 17:52:50 | 000,057,344 | —- | C] () – C:\Windows\SysWow64\issacapi_se-2.3.dll
[2013/02/01 01:46:57 | 000,000,211 | —- | C] () – C:\ProgramData\acer.zip
[2013/01/22 03:11:45 | 000,109,784 | -H– | C] () – C:\Windows\SysWow64\mlfcache.dat
[2013/01/21 09:24:37 | 000,866,014 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2012/11/24 09:34:32 | 000,007,601 | —- | C] () – C:\Users\Karen\AppData\Local\Resmon.ResmonCfg
[2012/11/19 02:33:32 | 000,065,656 | —- | C] () – C:\Windows\SysWow64\bdmpegv.dll
[2012/11/19 02:33:30 | 000,022,640 | —- | C] () – C:\Windows\SysWow64\bdmjpeg.dll
[2012/11/17 01:47:00 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
========== ZeroAccess Check ==========
[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 00:52:56 | 014,172,672 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/26 23:55:05 | 012,872,704 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 20:40:51 | 000,909,312 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 07:19:02 | 000,606,208 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 20:41:56 | 000,505,856 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/04/08 10:03:12 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Acoustica
[2013/03/09 04:22:57 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\AVG
[2013/06/17 17:15:07 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\AVG2012
[2013/06/14 09:29:01 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Babylon
[2013/06/17 17:15:07 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\BANDISOFT
[2013/06/29 09:04:11 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Canon
[2013/01/21 09:45:12 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\com.AdamOutler
[2013/04/27 20:38:21 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\DriverCure
[2013/05/15 19:44:32 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\DSite
[2013/01/13 09:54:30 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\FileOpen
[2013/05/08 22:00:54 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\FixBee
[2013/06/12 07:12:56 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\iPumper
[2013/06/17 17:10:29 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Kingsoft
[2013/05/14 22:43:09 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Lexmark Productivity Studio
[2013/05/15 19:48:46 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Mipony
[2013/03/17 03:21:04 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\MusicNet
[2013/05/18 15:22:23 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Nico Mak Computing
[2013/06/17 17:10:32 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Nitro
[2013/02/04 04:20:18 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Nitro PDF
[2013/07/03 03:45:47 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Notepad++
[2013/06/17 17:10:33 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\OpenOffice.org
[2013/02/18 13:13:55 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\PDF Architect
[2013/06/17 02:57:57 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\PerformerSoft
[2013/06/17 17:15:08 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Pinger Inc
[2013/06/17 17:15:08 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\player
[2013/05/07 12:58:06 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Sammsoft
[2013/03/21 23:12:30 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Samsung
[2013/06/17 02:51:44 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\SpeedAnalysis2
[2013/01/27 20:28:12 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\StatusWinks
[2013/05/24 02:52:29 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Strongvault
[2013/04/08 10:03:19 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\SynthMaker
[2013/03/04 19:20:20 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\TuneUp Software
[2013/02/28 07:38:35 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Unified Remote
[2013/01/07 20:22:35 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\Unity
[2013/07/06 02:04:49 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\USB Optical Mouse
[2013/07/06 11:30:23 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\uTorrent
[2013/05/15 00:09:25 | 000,000,000 | —D | M] – C:\Users\Karen\AppData\Roaming\X5400 Series
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2009/07/13 21:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 15:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2011/02/26 00:19:21 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | —- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | —- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | —- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 21:26:48 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | —- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
< MD5 for: EXPLORER.EXE-D5E97654.PF >
[2013/07/06 11:08:23 | 000,068,468 | —- | M] () MD5=39AA2CE244EFAC50D7139B346070AFAA – C:\Windows\Prefetch\EXPLORER.EXE-D5E97654.pf
< MD5 for: IEXPLORE.EXE >
[2013/01/08 20:53:45 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2013/05/16 21:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/05/16 21:32:12 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=07DFD28E57879554D054464EE4A5662D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_20d88bb252a3770f\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/11/18 00:02:28 | 000,748,704 | —- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2013/03/12 19:47:53 | 000,770,560 | —- | M] (Microsoft Corporation) MD5=2859EBC065D2E1CCC94161CE28BAC085 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16521_none_20e4a040529a2792\iexplore.exe
[2013/02/24 19:58:09 | 000,775,232 | —- | M] (Microsoft Corporation) MD5=28F93BAFB3EB407E99A7ED3D9DBDE04C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20644_none_ffb93ba237e760ce\iexplore.exe
[2013/04/05 00:55:38 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=2DC6BD1047553611DAEF97C751131A5D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_0a122b746c443b42\iexplore.exe
[2013/05/16 20:57:28 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=3902E280F6117A468D5573343A7AA1F6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_09ffa3426c5372da\iexplore.exe
[2012/11/18 00:02:22 | 000,754,848 | —- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2013/02/21 07:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_16920d4a1e377ea4\iexplore.exe
[2013/03/12 19:47:49 | 000,775,184 | —- | M] (Microsoft Corporation) MD5=681B380492ACB571ED6CCC1F37F53343 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16521_none_168ff5ee1e396597\iexplore.exe
[2013/01/08 17:42:06 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2013/02/02 03:09:12 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=7C2923004FFC497E54F38E835F108EE8 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2013/05/16 22:02:08 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=8F00471CA24ADF8D2AFAACF856EB70A4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20719_none_ffaaf8f037f2b0df\iexplore.exe
[2013/02/24 18:52:40 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=A11C5E3E288256C540B7ED8BE3A04B01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20644_none_0a0de5f46c4822c9\iexplore.exe
[2013/02/01 23:19:03 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013/02/02 02:37:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2013/04/05 01:02:26 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=AAD90795E84E710543C6C7C2F7048E30 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_20e92fca5296266a\iexplore.exe
[2012/11/15 22:08:58 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2013/04/05 02:53:33 | 000,775,232 | —- | M] (Microsoft Corporation) MD5=CEA304830B4770BDA3572B87D0841848 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16576_none_169485781e35646f\iexplore.exe
[2013/02/01 23:19:04 | 000,757,296 | —- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2013/04/05 02:23:03 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=DE751E18F8DBF7BCCE46989CBA4A9828 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20681_none_ffbd812237e37947\iexplore.exe
[2013/02/21 06:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16540_none_20e6b79c5298409f\iexplore.exe
[2013/05/16 22:30:45 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=EDC77CF787FA015205936C9A3228486E – C:\Program Files\Internet Explorer\iexplore.exe
[2013/05/16 22:30:45 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=EDC77CF787FA015205936C9A3228486E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16614_none_1683e1601e42b514\iexplore.exe
[2013/01/08 19:51:57 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 16:32:42 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2012/11/13 21:19:28 | 000,757,280 | —- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/11/14 02:11:18 | 000,763,424 | —- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2012/11/18 00:02:23 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2012/11/18 00:02:28 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/03/12 19:47:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/03/12 19:47:49 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/03/12 19:47:49 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/03/12 19:47:53 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-A033F7A0.PF >
[2013/07/05 16:49:24 | 000,122,998 | —- | M] () MD5=50DD82EA441D65DF8B41599834D6E0DE – C:\Windows\Prefetch\IEXPLORE.EXE-A033F7A0.pf
< MD5 for: SERVICES >
[2009/06/10 16:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
< MD5 for: SERVICES.CFG >
[2012/09/23 21:43:36 | 000,603,848 | R— | M] () MD5=81B120EAEE296F0E54F66C16C5A21367 – C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744BA0000000010\11.0.0\services.cfg
[2013/05/11 05:37:26 | 000,558,990 | —- | M] () MD5=FE8FB005031C2574E990DAC1F9F5ACF8 – C:\Program Files (x86)\Adobe\Reader 11.0\Reader\Services\Services.cfg
< MD5 for: SERVICES.EXE >
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | —- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 21:25:40 | 000,017,408 | —- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
< MD5 for: SERVICES.MSC >
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysNative\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\SysWOW64\services.msc
[2009/07/13 21:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 15:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 21:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 16:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
< MD5 for: WINLOGON.ADML >
[2009/07/13 21:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 16:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | —- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 08:00:25 | 000,023,040 | —- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 21:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2009/07/13 20:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2013/07/06 11:03:00 | 3018,608,640 | -HS- | M] () – C:\hiberfil.sys
[2013/07/06 11:03:06 | 4024,811,520 | -HS- | M] () – C:\pagefile.sys
< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2012/11/25 20:49:31 | 000,001,670 | -HS- | M] () – C:\Users\Karen\AppData\Roaming\Microsoft\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is ACER
Volume Serial Number is 58AF-192C
Directory of C:\
07/14/2009 12:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 12:08 AM Application Data [C:\ProgramData]
07/14/2009 12:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 12:08 AM All Users [C:\ProgramData]
07/14/2009 12:08 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\14d Trial - MX6 6-23
06/23/2013 02:04 PM Application Data [C:\Users\14d Trial - MX6 6-23\AppData\Roaming]
06/23/2013 02:04 PM Cookies [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Cookies]
06/23/2013 02:04 PM Local Settings [C:\Users\14d Trial - MX6 6-23\AppData\Local]
06/23/2013 02:04 PM My Documents [C:\Users\14d Trial - MX6 6-23\Documents]
06/23/2013 02:04 PM NetHood [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/23/2013 02:04 PM PrintHood [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/23/2013 02:04 PM Recent [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Recent]
06/23/2013 02:04 PM SendTo [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\SendTo]
06/23/2013 02:04 PM Start Menu [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Start Menu]
06/23/2013 02:04 PM Templates [C:\Users\14d Trial - MX6 6-23\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\14d Trial - MX6 6-23\AppData\Local
06/23/2013 02:04 PM Application Data [C:\Users\14d Trial - MX6 6-23\AppData\Local]
06/23/2013 02:04 PM History [C:\Users\14d Trial - MX6 6-23\AppData\Local\Microsoft\Windows\History]
06/23/2013 02:04 PM Temporary Internet Files [C:\Users\14d Trial - MX6 6-23\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\14d Trial - MX6 6-23\Documents
06/23/2013 02:04 PM My Music [C:\Users\14d Trial - MX6 6-23\Music]
06/23/2013 02:04 PM My Pictures [C:\Users\14d Trial - MX6 6-23\Pictures]
06/23/2013 02:04 PM My Videos [C:\Users\14d Trial - MX6 6-23\Videos]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 12:08 AM Application Data [C:\ProgramData]
07/14/2009 12:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Cecil
11/21/2012 08:26 PM Application Data [C:\Users\Cecil\AppData\Roaming]
11/21/2012 08:26 PM Cookies [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Cookies]
11/21/2012 08:26 PM Local Settings [C:\Users\Cecil\AppData\Local]
11/21/2012 08:26 PM My Documents [C:\Users\Cecil\Documents]
11/21/2012 08:26 PM NetHood [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
11/21/2012 08:26 PM PrintHood [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
11/21/2012 08:26 PM Recent [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Recent]
11/21/2012 08:26 PM SendTo [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\SendTo]
11/21/2012 08:26 PM Start Menu [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Start Menu]
11/21/2012 08:26 PM Templates [C:\Users\Cecil\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Cecil\AppData\Local
11/21/2012 08:26 PM Application Data [C:\Users\Cecil\AppData\Local]
11/21/2012 08:26 PM History [C:\Users\Cecil\AppData\Local\Microsoft\Windows\History]
11/21/2012 08:26 PM Temporary Internet Files [C:\Users\Cecil\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Cecil\Documents
11/21/2012 08:26 PM My Music [C:\Users\Cecil\Music]
11/21/2012 08:26 PM My Pictures [C:\Users\Cecil\Pictures]
11/21/2012 08:26 PM My Videos [C:\Users\Cecil\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 12:08 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 12:08 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 12:08 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM My Documents [C:\Users\Default\Documents]
07/14/2009 12:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 12:08 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 12:08 AM My Music [C:\Users\Default\Music]
07/14/2009 12:08 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 12:08 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Karen
11/17/2012 01:29 AM Application Data [C:\Users\Karen\AppData\Roaming]
11/17/2012 01:29 AM Cookies [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Cookies]
11/17/2012 01:29 AM Local Settings [C:\Users\Karen\AppData\Local]
11/17/2012 01:29 AM My Documents [C:\Users\Karen\Documents]
11/17/2012 01:29 AM NetHood [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
11/17/2012 01:29 AM PrintHood [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
11/17/2012 01:29 AM Recent [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Recent]
11/17/2012 01:29 AM SendTo [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\SendTo]
11/17/2012 01:29 AM Start Menu [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Start Menu]
11/17/2012 01:29 AM Templates [C:\Users\Karen\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Karen\AppData\Local
11/17/2012 01:29 AM Application Data [C:\Users\Karen\AppData\Local]
11/17/2012 01:29 AM History [C:\Users\Karen\AppData\Local\Microsoft\Windows\History]
11/17/2012 01:29 AM Temporary Internet Files [C:\Users\Karen\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Karen\Documents
11/17/2012 01:29 AM My Music [C:\Users\Karen\Music]
11/17/2012 01:29 AM My Pictures [C:\Users\Karen\Pictures]
11/17/2012 01:29 AM My Videos [C:\Users\Karen\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 12:08 AM My Music [C:\Users\Public\Music]
07/14/2009 12:08 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 12:08 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public Account
04/24/2013 05:00 PM Application Data [C:\Users\Public Account\AppData\Roaming]
04/24/2013 05:00 PM Cookies [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Cookies]
04/24/2013 05:00 PM Local Settings [C:\Users\Public Account\AppData\Local]
04/24/2013 05:00 PM My Documents [C:\Users\Public Account\Documents]
04/24/2013 05:00 PM NetHood [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
04/24/2013 05:00 PM PrintHood [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
04/24/2013 05:00 PM Recent [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Recent]
04/24/2013 05:00 PM SendTo [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\SendTo]
04/24/2013 05:00 PM Start Menu [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Start Menu]
04/24/2013 05:00 PM Templates [C:\Users\Public Account\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Public Account\AppData\Local
04/24/2013 05:00 PM Application Data [C:\Users\Public Account\AppData\Local]
04/24/2013 05:00 PM History [C:\Users\Public Account\AppData\Local\Microsoft\Windows\History]
04/24/2013 05:00 PM Temporary Internet Files [C:\Users\Public Account\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Public Account\Documents
04/24/2013 05:00 PM My Music [C:\Users\Public Account\Music]
04/24/2013 05:00 PM My Pictures [C:\Users\Public Account\Pictures]
04/24/2013 05:00 PM My Videos [C:\Users\Public Account\Videos]
0 File(s) 0 bytes
Directory of C:\Users\test
06/16/2013 05:44 AM Application Data [C:\Users\test\AppData\Roaming]
06/16/2013 05:44 AM Cookies [C:\Users\test\AppData\Roaming\Microsoft\Windows\Cookies]
06/16/2013 05:44 AM Local Settings [C:\Users\test\AppData\Local]
06/16/2013 05:44 AM My Documents [C:\Users\test\Documents]
06/16/2013 05:44 AM NetHood [C:\Users\test\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
06/16/2013 05:44 AM PrintHood [C:\Users\test\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
06/16/2013 05:44 AM Recent [C:\Users\test\AppData\Roaming\Microsoft\Windows\Recent]
06/16/2013 05:44 AM SendTo [C:\Users\test\AppData\Roaming\Microsoft\Windows\SendTo]
06/16/2013 05:44 AM Start Menu [C:\Users\test\AppData\Roaming\Microsoft\Windows\Start Menu]
06/16/2013 05:44 AM Templates [C:\Users\test\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\test\AppData\Local
06/16/2013 05:44 AM Application Data [C:\Users\test\AppData\Local]
06/16/2013 05:44 AM History [C:\Users\test\AppData\Local\Microsoft\Windows\History]
06/16/2013 05:44 AM Temporary Internet Files [C:\Users\test\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\test\Documents
06/16/2013 05:44 AM My Music [C:\Users\test\Music]
06/16/2013 05:44 AM My Pictures [C:\Users\test\Pictures]
06/16/2013 05:44 AM My Videos [C:\Users\test\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
114 Dir(s) 217,006,120,960 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/11/18 03:06:52 | 000,000,221 | -HS- | M] () – C:\Users\Karen\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
[2013/07/06 11:56:59 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karen\Desktop\OTL.exe
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
========== Alternate Data Streams ==========
@Alternate Data Stream - 205 bytes -> C:\ProgramData\TEMP:0B4227B4
< End of report >
OTL Extras logfile created on: 7/6/2013 12:19:29 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karen\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16614)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.75 Gb Total Physical Memory | 2.68 Gb Available Physical Memory | 71.48% Memory free
7.50 Gb Paging File | 6.10 Gb Available in Paging File | 81.33% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 286.27 Gb Total Space | 202.13 Gb Free Space | 70.61% Space Free | Partition Type: NTFS
Computer Name: KAREN-PC | User Name: Karen | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = ChromeHTML] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – "C:\Program Files (x86)\File Type Assistant\tsassist.exe" "%1" (Trusted Software ApS)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{04353690-03D4-4A57-9863-4DBDCEB97442}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{0A528707-4401-4F98-8432-16242EC3E287}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{1E951B86-E28F-4DD0-BD2A-7FA925210629}" = lport=138 | protocol=17 | dir=in | app=system |
"{449985BB-9195-4E88-8634-8016EEF0B94E}" = rport=445 | protocol=6 | dir=out | app=system |
"{4C1FF8B0-DF2A-46A0-96B6-E58B479D3DAC}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{4E090BA2-FC5E-4603-943C-670857F6331C}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{56C274C6-046C-4C64-BD06-9EE20D093BE8}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{596DBDF7-85D2-488A-B838-6A969CE77F9C}" = rport=138 | protocol=17 | dir=out | app=system |
"{751F9B82-3A12-4656-94DE-9FB96B237879}" = lport=137 | protocol=17 | dir=in | app=system |
"{80BBCCF9-033E-482E-B72D-2C98977A6066}" = rport=139 | protocol=6 | dir=out | app=system |
"{87D08CB7-FF0E-4E1B-A89C-2E785D494F14}" = rport=10243 | protocol=6 | dir=out | app=system |
"{8DC73AA1-EFF9-4783-95E5-AD3F0CE0894D}" = lport=6102 | protocol=6 | dir=in | name=rdm |
"{A64D2A49-DC84-41AD-985D-C4ACE09E60CC}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{A74C8063-62ED-41AE-B487-975BBAE77AA1}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{AE3F06D3-7775-4B0E-B458-8F69080537AB}" = lport=139 | protocol=6 | dir=in | app=system |
"{BED21E29-E923-4815-9206-17AFADE16E2D}" = lport=2869 | protocol=6 | dir=in | app=system |
"{C3A66DDF-E9A2-4C6E-8029-3A6F0317F4C3}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{D1EA2668-418B-4ADC-9A41-B6B20AA1152A}" = rport=137 | protocol=17 | dir=out | app=system |
"{E0C150C3-94F5-40A6-8967-73BD94722284}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E3F416FF-410E-42E7-9D44-9D4F88E5321A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{E7DC880E-9467-482F-9B2A-A48406F6CCB9}" = lport=10243 | protocol=6 | dir=in | app=system |
"{E85E3204-E598-4EFB-B68B-9A9E7B42A4CD}" = lport=445 | protocol=6 | dir=in | app=system |
"{F02E49F6-D3D8-47A8-8A4E-37BB0EADC9EE}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0A641224-7230-400C-9395-188024214D22}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{12A25B82-8FE4-455C-99DC-65234700253F}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{17D1EFB9-2EEF-4E31-B922-3565EE6B0D29}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{208BFEF4-257A-4744-BEC7-DFF27732712C}" = protocol=17 | dir=in | app=c:\users\karen\appdata\roaming\utorrent\utorrent.exe |
"{212CC471-B83C-4989-8123-E92E5D7694CF}" = protocol=6 | dir=out | app=system |
"{217DD729-2729-4EF5-91B8-3724F90E3F46}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2BE468CF-739A-4A49-B9E1-447DCD227CF1}" = protocol=17 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{2CB7F60B-F2A1-4D52-B0B7-505744938BDA}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{2D66DF65-85A1-46A1-AA20-930EBE03E7B0}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{2DF4A00C-5F00-49ED-8585-A8FC345CFDCF}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{2EC655F1-820C-4036-8DB4-8DA7AAA0CF76}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{35CB2FC3-4D0E-4610-B08A-E79F179E4D1B}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3CAAF28C-30D0-4F01-8822-E927768F0476}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3D6DEBDB-EF5C-4037-95CB-F9D80CDF5ADD}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4F2E5FA2-773C-4EF7-B933-268060A43C4B}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{4FF73137-72FC-4EFE-937C-D800DFAFA75F}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{53FC0DD2-86D5-4073-9D0B-FADF8011C6AF}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{5CA8B13D-3CB0-44F0-85E1-FEC219813A31}" = dir=in | app=c:\program files (x86)\file type assistant\tsassist.exe |
"{5D13D74D-6CFF-4B37-BB06-502123AD0789}" = protocol=6 | dir=in | app=c:\windows\syswow64\muzapp.exe |
"{675DA394-AEC4-43AB-B7FF-FA2A947256A6}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6A477AFA-A2A9-43CD-9D52-DDCBF3879B93}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgdiagex.exe |
"{6BDFEFBF-3283-4FD2-960B-C625572F08D8}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{7E4993FE-BAC1-42C0-A598-AE02C431DA32}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{8D4FC570-77DA-461C-A57D-9E4A60D01F97}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{934F65A0-62F9-4BA2-AF92-001E322E6A2E}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{9A2A56F3-E746-42CC-9EAA-7F295C7A473F}" = dir=in | app=c:\program files (x86)\file type assistant\tsassist.exe |
"{9AED4ED0-DF61-41A2-A2D0-83CE65951BBE}" = protocol=6 | dir=in | app=c:\program files (x86)\avg\avg2012\avgnsa.exe |
"{AA298193-39C5-4CF9-91CD-FC6110CFC106}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{AA766D47-2BDC-4B77-A0A5-FC8FCE2F6143}" = protocol=17 | dir=in | app=c:\program files (x86)\avg\avg2012\avgemca.exe |
"{AB93609D-B3D8-433C-A690-A3314BB51067}" = protocol=6 | dir=in | app=c:\users\karen\appdata\roaming\utorrent\utorrent.exe |
"{C437F080-C2C6-4DEB-8F30-9AC722DA96E1}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{CDC4C15B-1196-4257-97FE-8D30B4121EDD}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DBC5B321-F6D1-4C99-80D7-0C15AE122854}" = dir=in | app=c:\program files (x86)\file type assistant\tsassist.exe |
"{DC299E5B-CDFD-4D64-81FC-6B07700C00DB}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{EE97D8AC-B6D8-4870-B8F6-5FFC7B68875C}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{F43AA4BA-2052-4F30-8A18-5003F6DA099C}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{FDFF5759-4AA0-4E6C-90FD-7BFB33C026A6}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{086D343F-8E78-4AFC-81AC-D6D414AFD8AC}_is1" = Core Temp 1.0 RC4
"{21B133D6-5979-47F0-BE1C-F6A6B304693F}" = Visual Studio 2010 x64 Redistributables
"{26A24AE4-039D-4CA4-87B4-2F86417017FF}" = Java 7 Update 17 (64-bit)
"{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program
"{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7ACE202B-1B01-4B43-B6AE-03D66D621CDE}" = Microsoft SQL Server 2008 RsFx Driver
"{893F27E6-D6BE-4B9F-80E6-0ADA694A31A8}" = Microsoft SQL Server 2008 Common Files
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{BCA26999-EC22-3007-BB79-638913079C9A}" = Microsoft Visual Studio 2010 Express Prerequisites x64 - ENU
"{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D50E19B5-A29A-4A78-8381-0E562B40CDFD}" = AVG 2012
"{DF167CE3-60E7-44EA-99EC-2507C51F37AE}" = Microsoft SQL Server 2008 Database Engine Shared
"{DFE4E6BB-70F0-4292-B7EB-7A3AD48EBB5C}" = AVG 2012
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = Microsoft SQL Server 2008 Database Engine Services
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services
"{FCADA26A-5672-31DD-BF0E-BA76ECF9B02D}" = Microsoft Help Viewer 1.0
"AVG" = AVG 2012
"CCleaner" = CCleaner
"CNXT_MODEM_HDAUDIO_VEN_14F1&DEV;_2BFAOR2C06_118" = HDAUDIO Soft Data Fax Modem with SmartCP
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"WinRAR archiver" = WinRAR 4.00 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{23170F69-40C1-2701-0921-000001000000}" = 7-Zip 9.21
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 21
"{28006915-2739-4EBE-B5E8-49B25D32EB33}" = Atheros Driver Installation Program
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{553C904F-57A2-4113-888E-BA0C3D1C69C0}" = Microsoft VC9 runtime libraries
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AB0000000001}" = Adobe Reader XI (11.0.03)
"{BA8B8ADA-084F-4F79-A0CA-6E58A0808794}" = FlashPlayer
"{EE171732-BEB4-4576-887D-CB62727F01CA}" = Acer Updater
"{EEAE45EB-C1E3-4CCD-930D-D7B40F810063}" = USB Optical Mouse
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"Acoustica Mixcraft 6" = Acoustica Mixcraft 6
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"AVG Secure Search" = AVG Security Toolbar
"Bandicam" = Bandicam
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"DomaIQ Uninstaller" = DomaIQ
"Google Chrome" = Google Chrome
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"Kingsoft Office" = Kingsoft Office 2012 (8.1.0.3385)
"OpenIt Open It!" = Open It!
"Trusted Software Assistant_is1" = File Type Assistant
"uTorrent" = µTorrent
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"DSite" = Update for Zip Opener
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 4/15/2013 11:12:21 PM | Computer Name = Karen-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1199461
Error - 4/15/2013 11:12:22 PM | Computer Name = Karen-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 4/15/2013 11:12:22 PM | Computer Name = Karen-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1200678
Error - 4/15/2013 11:12:22 PM | Computer Name = Karen-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1200678
Error - 4/17/2013 1:02:57 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 3038
Description =
Error - 4/17/2013 1:02:58 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 7040
Description =
Error - 4/17/2013 1:02:58 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 7042
Description =
Error - 4/17/2013 1:02:59 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 3028
Description =
Error - 4/17/2013 1:02:59 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 3058
Description =
Error - 4/17/2013 1:02:59 PM | Computer Name = Karen-PC | Source = Windows Search Service | ID = 7010
Description =
[ Media Center Events ]
Error - 12/22/2012 12:49:22 AM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 10:49:22 PM - Error connecting to the internet. 10:49:22 PM - Unable
to contact server..
Error - 12/22/2012 12:52:52 AM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 10:52:47 PM - Error connecting to the internet. 10:52:47 PM - Unable
to contact server..
Error - 12/22/2012 6:23:33 AM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 4:23:33 AM - Error connecting to the internet. 4:23:33 AM - Unable
to contact server..
Error - 12/22/2012 6:24:29 AM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 4:24:28 AM - Error connecting to the internet. 4:24:28 AM - Unable
to contact server..
Error - 5/28/2013 5:02:58 PM | Computer Name = Karen-PC | Source = MCUpdate | ID = 0
Description = 4:02:57 PM - Error connecting to the internet. 4:02:57 PM - Unable
to contact server..
[ System Events ]
Error - 7/6/2013 11:16:09 AM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535
Error - 7/6/2013 12:05:56 PM | Computer Name = Karen-PC | Source = PNRPSvc | ID = 102
Description =
Error - 7/6/2013 12:05:56 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535
Error - 7/6/2013 12:05:56 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535
Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = PNRPSvc | ID = 102
Description =
Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = PNRPSvc | ID = 102
Description =
Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535
Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535
Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7023
Description = The Peer Name Resolution Protocol service terminated with the following
error: %%-2140993535
Error - 7/6/2013 12:06:04 PM | Computer Name = Karen-PC | Source = Service Control Manager | ID = 7001
Description = The Peer Networking Grouping service depends on the Peer Name Resolution
Protocol service which failed to start because of the following error: %%-2140993535
< End of report >