cplewis
Topic Starter
Windows Action Center has been reminding me that my computer is infected with the Win32/Small.CA virus. I have received these notifications periodically since July of 2012. When I was first notified, I ran scans with Malwarebytes, Sophos Anti-virus, Microsoft Security Essentials, and Microsoft Safety Scanner. Because none of the scans were able to locate any problems, and I hadn't noticed anything abnormal occurring with my computer, I attributed the notifications to a false positive and ignored them. Now that they have become a nuisance, however, I was hoping someone more experienced than myself could look into this potential problem.
I downloaded and ran scans with HijackThis and OTL. Their log files are included bellow.
I'd appreciate any help that can be given!
HijackThis:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:01:22 PM, on 8/31/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16660)
CHROME: 29.0.1547.62
Boot mode: Normal
Running processes:
C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\Users\———\AppData\Local\Akamai\netsession_win.exe
C:\Users\———\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Program Files\TrueCrypt\TrueCrypt.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\Downloads\HijackThis.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
*.local;127.0.0.1:9421;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP
\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files
(x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program
Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program
Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files
(x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files
(x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files (x86)\Carbonite\Carbonite Backup
\CarboniteUI.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\———\AppData\Local\Akamai
\netsession_win.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\———\AppData\Local\Google\Update
\GoogleUpdate.exe"
/c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User
'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User
'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK
SERVICE')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:
\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no
file)
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-
1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer
\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer
\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files
(x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files
(x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program
Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources
\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:
\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck
\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework
\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08}
- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck
\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:
\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:
\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:
\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} -
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows
live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows
live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} -
http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} -
http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} -
http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
http://www.popcap.com/webgames/popcaploader_v10.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} -
http://utilities.pcpitstop.com/da2/PCPitStop2.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows
Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:
\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems
Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:
\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows
\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe
(file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple
\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files
\Carbonite\Carbonite Backup\carboniteservice.exe
O23 - Service: Cron Service for Prey (CronService) - Fork Ltd. - C:\Users\———\Vulture
\platform\windows\cronsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files
(x86)\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: @C:\Program Files\DigitalPersona\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona,
Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\SwSetup
\QuickWeb\QW.SYS\config\DVMExportService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows
\System32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program
Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows
\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files
(x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files
(x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files
(x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-
Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program
Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file
missing)
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files
(x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file
missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) -
Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS
\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file
missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel
\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows
\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:
\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:
\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows
\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows
\system32\lsass.exe (file missing)
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Limited - C:\Program
Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Limited - C:\Program Files (x86)\Sophos
\Sophos Anti-Virus\SavService.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\sua.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows
\System32\snmptrap.exe (file missing)
O23 - Service: Sophos Agent - Sophos Limited - C:\Program Files (x86)\Sophos\Remote Management
System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Limited - C:\Program Files (x86)\Sophos
\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Limited - C:\Program Files (x86)\Sophos\Remote
Management System\RouterNT.exe
O23 - Service: Sophos Web Control Service - Sophos Limited - C:\Program Files (x86)\Sophos\Sophos
Anti-Virus\Web Control\swc_service.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows
\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows
\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program
Files\IDT\WDM\STacSV64.exe
O23 - Service: Sophos Web Intelligence Service (swi_service) - Sophos Limited - C:\Program Files
(x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
O23 - Service: Sophos Web Intelligence Update (swi_update_64) - Sophos Limited - C:\ProgramData
\Sophos\Web Intelligence\swi_update_64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:
\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel
Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows
\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:
\Windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows
\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows
\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:
\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows
\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:
\Windows\system32\wbem\WmiApSrv.exe (file missing)
–
End of file - 17670 bytes
********************************************************************************
*******
OTL.txt:
OTL logfile created on: 8/31/2013 7:13:26 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\———\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.80 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 39.01% Memory free
7.60 Gb Paging File | 4.71 Gb Available in Paging File | 62.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 276.46 Gb Total Space | 142.57 Gb Free Space | 51.57% Space Free | Partition Type:
NTFS
Drive D: | 21.33 Gb Total Space | 3.10 Gb Free Space | 14.53% Space Free | Partition Type: NTFS
Drive E: | 99.34 Mb Total Space | 84.17 Mb Free Space | 84.74% Space Free | Partition Type: FAT32
Drive T: | 49.98 Gb Total Space | 46.89 Gb Free Space | 93.82% Space Free | Partition Type: FAT32
Computer Name: ——– | User Name: ——— | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File
Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\———\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Users\———\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\———\Vulture\platform\windows\cronsvc.exe (Fork Ltd.)
PRC - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple
Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple
Inc.)
PRC - C:\Program Files\TrueCrypt\TrueCrypt.exe (TrueCrypt Foundation)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos
Limited)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Remote Management System\RouterNT.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Remote Management System\ManagementAgentNT.exe (Sophos
Limited)
PRC - C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Sophos
Limited)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard
Development Company, L.P.)
PRC - C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.EXE (Intel
Corporation)
PRC - C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe (DeviceVM, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel
Corporation)
PRC - C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Acresso Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (CarboniteService) – C:\Program Files\Carbonite\Carbonite Backup
\CarboniteService.exe (Carbonite, Inc. (www.carbonite.com))
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft
Corporation)
SRV:64bit: - (RemSrvs) – C:\Program Files\DyKnow\Client\DyKnow.Host.dll (Dynamic
Knowledge Transfer, LLC.)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel® Corporation)
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics
Corporation)
SRV:64bit: - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona,
Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors,
Inc.)
SRV:64bit: - (HP Wireless Assistant Service) – C:\Program Files\Hewlett-Packard\HP
Wireless Assistant\HPWA_Service.exe (Hewlett-Packard)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash
\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Secunia PSI Agent) – C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (Akamai) – c:\program files (x86)\common files\akamai/netsession_win_8fa3539.dll ()
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe
Systems Incorporated)
SRV - (CronService) – C:\Users\———\Vulture\platform\windows\cronsvc.exe (Fork Ltd.)
SRV - (swi_service) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence
\swi_service.exe (Sophos Limited)
SRV - (SAVAdminService) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Sophos Limited)
SRV - (swi_update_64) – C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe (Sophos
Limited)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support
Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (Sophos Message Router) – C:\Program Files (x86)\Sophos\Remote Management System
\RouterNT.exe (Sophos Limited)
SRV - (Sophos Agent) – C:\Program Files (x86)\Sophos\Remote Management System
\ManagementAgentNT.exe (Sophos Limited)
SRV - (Sophos AutoUpdate Service) – C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos
Limited)
SRV - (SAVService) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Sophos
Limited)
SRV - (Sophos Web Control Service) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web
Control\swc_service.exe (Sophos Limited)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Hewlett-Packard Development Company, L.P.)
SRV - (CVPND) – C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (HPSLPSVC) – C:\Program Files (x86)\Hp\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard
Co.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework
\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.EXE
(Intel Corporation)
SRV - (DvmMDES) – C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe (DeviceVM, Inc.)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation)
SRV - (PCPitstop Scheduling) – C:\Program Files (x86)\PCPitstop\PCPitstopScheduleService.exe (PC
Pitstop LLC)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework
\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (PSI) – C:\Windows\SysNative\drivers\psi_mf_amd64.sys (Secunia)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft
Corporation)
DRV:64bit: - (truecrypt) – C:\Windows\SysNative\drivers\truecrypt.sys (TrueCrypt
Foundation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (sdcfilter) – C:\Windows\SysNative\drivers\sdcfilter.sys (Sophos Limited)
DRV:64bit: - (SAVOnAccess) – C:\Windows\SysNative\drivers\savonaccess.sys (Sophos
Limited)
DRV:64bit: - (SophosBootDriver) – C:\Windows\SysNative\drivers\SophosBootDriver.sys
(Sophos Plc)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
(Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft
Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software
Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (TIEHDUSB) – C:\Windows\SysNative\drivers\tiehdusb.sys (Texas Instruments)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (NETwNs64) – C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek
)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard
Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-
Packard Company)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro
Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro
Devices)
DRV:64bit: - (CVPNDRVA) – C:\Windows\SysNative\drivers\CVPNDRVA.sys ()
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies
Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro
Devices, Inc.)
DRV:64bit: - (intelkmd) – C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI
Technologies, Inc.)
DRV:64bit: - (NETw5s64) – C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (CVirtA) – C:\Windows\SysNative\drivers\CVirtA64.sys (Cisco Systems, Inc.)
DRV:64bit: - (DVMIO) – C:\Windows\SysNative\drivers\dvmio.sys (DeviceVM, Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek
Semiconductor Corp.)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (HECIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft
Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft
Corporation)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems,
Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems,
Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems,
Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom
Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer
Works, Inc.)
DRV:64bit: - (DNE) – C:\Windows\SysNative\drivers\dne64x.sys (Deterministic Networks,
Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
IE:64bit: - HKLM\..\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}: "URL" =
http://searchfunmoods.com/results.php?f=4&…q={searchTerms}
&a;=download&chnl;=download&cd;=2XzuyEtN2Y1L1Qzu0CzztD0A0Azy0AtDtDyEtC0AyD0ByDtAtN0D0Tzu0CtAtCyBtN1L
2XzutBtFtBtFtDtFtAyEyE&cr;=808477447
IE - HKLM\..\SearchScopes,DefaultScope = {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
IE - HKLM\..\SearchScopes\{5727EF33-8B6C-4E3B-B7CD-49B42D733B4C}: "URL" =
http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
IE - HKLM\..\SearchScopes\{EDCBA892-30A1-4472-8BB9-10D7A040DEEE}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {9D91E43C-A476-4522-A40B-71554B06C164}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{5727EF33-8B6C-4E3B-B7CD-49B42D733B4C}: "URL" =
http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
IE - HKCU\..\SearchScopes\{5AD59AA0-946D-4BD0-BC6E-09282E228D38}: "URL" =
http://search.avg.com/route/?d=4e163206&am;…;lng={language}
&iy;=&ychte;=us
IE - HKCU\..\SearchScopes\{8540A13E-3E6B-49FA-881E-F4DF4E8F4281}: "URL" =
http://us.yhs4.search.yahoo.com/yhs/search?hsimp=yhs-
affiliate_a&hspart;=greentree&type;=937811_yhs2tst&p;={searchTerms}
IE - HKCU\..\SearchScopes\{9D91E43C-A476-4522-A40B-71554B06C164}: "URL" =
http://www.google.com/search?q={searchTerm…oft:{language}:
{referrer:source}&ie;={inputEncoding?}&oe;={outputEncoding?}
IE - HKCU\..\SearchScopes\{EDCBA892-30A1-4472-8BB9-10D7A040DEEE}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
*.local;127.0.0.1:9421;
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows
\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows
\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program
Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program
Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash
\NPSWF32_11_8_800_94.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director
\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes
\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google
\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows
\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files
(x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files
(x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files
(x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files
(x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando
Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files
(x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files
(x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files
(x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader
\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\———\AppData
\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\———\AppData\Roaming
\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\———\AppData\Roaming
\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\———
\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\———
\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
[2013/03/23 19:58:25 | 000,000,000 | —D | M] (No name found) – C:\Users\———\AppData
\Roaming\Mozilla\Extensions
[2013/03/23 19:58:25 | 000,000,000 | —D | M] (No name found) – C:\Users\———\AppData
\Roaming\Mozilla\Extensions\[removed]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}
{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFiel
dtrialParameter}
{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}
{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?
{google:searchFieldtrialParameter}client={google:suggestClient}&q;={searchTerms}&
{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParamet
er},
CHR - homepage: http://www.drudgereport.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\———\AppData\Local\Google\Chrome
\Application\21.0.1180.79\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\———\AppData\Local\Google\Chrome
\Application\29.0.1547.62\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash
\NPSWF32_11_3_300_271.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\———\AppData\Local\Google\Chrome
\Application
\29.0.1547.62\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\———\AppData\Local\Google\Chrome
\Application\29.0.1547.62\pdf.dll
CHR - plugin: NPLastPass (Enabled) = C:\Users\———\AppData\Local\Google\Chrome\User Data
\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\2.0.1_0\nplastpass.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser
\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\———\AppData\Roaming\Mozilla\plugins
\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\———\AppData\Roaming
\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin
\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update
\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U5 (Enabled) = C:\Program Files (x86)\Java\jre7\bin
\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.5 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live
\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla
Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight
\5.1.10411.0\npctrl.dll
CHR - Extension: Google Drive = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Adblock Plus = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5.4_0\
CHR - Extension: Google Search = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Turkopticon = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\dgefbojfgdddnignhmfmnencgiloojpe\3.32_0\
CHR - Extension: IBA Opt-out (by Google) = C:\Users\———\AppData\Local\Google\Chrome\User
Data
\Default\Extensions\gbiekjoijknlhijdjbaadobpkdhmoebb\1.5_0\
CHR - Extension: LastPass = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\hdokiejnpimakedhajhdlcegeplioahd\2.5.5_0\
CHR - Extension: WeatherBug = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\ihdkejbciahopmbagpnjmmkkdpfpaaak\2.0.6_0\
CHR - Extension: Reddit Enhancement Suite = C:\Users\———\AppData\Local\Google\Chrome\User
Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.3.0.1_0\
CHR - Extension: Google Dictionary (by Google) = C:\Users\———\AppData\Local\Google\Chrome
\User
Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja\3.0.19_0\
CHR - Extension: Google Mail Checker = C:\Users\———\AppData\Local\Google\Chrome\User Data
\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\4.4.0_0\
CHR - Extension: Ghostery = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\mlomiejdfkolichcflejclcbmpeaniij\4.1.2_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\———\AppData\Local\Google\Chrome
\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Personal Blocklist (by Google) = C:\Users\———\AppData\Local\Google\Chrome
\User Data\Default\Extensions\nolijncfnkgaikbjbdaogikpmpbdcdef\2.4.1_0\
CHR - Extension: Google Quick Scroll = C:\Users\———\AppData\Local\Google\Chrome\User Data
\Default\Extensions\okanipcmceoeemlbjnmnbdibhgpbllgc\2.1.2_0\
CHR - Extension: YTshowRating = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\olohkebleofongajeodnhideeiapohgi\1.0.7_0\
CHR - Extension: Google Calendar Checker (by Google) = C:\Users\———\AppData\Local\Google
\Chrome\User Data\Default\Extensions\ookhcbgokankfmjafalglpofmolfopek\1.4.0_0\
CHR - Extension: Gmail = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers
\etc\hosts
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9}
- C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program
Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files
(x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
(Hewlett-Packard)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID
value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless
Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Microsoft Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel
\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel
Corporation)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files (x86)\Carbonite\Carbonite Backup
\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Sophos Limited)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\———\AppData\Local\Akamai
\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Acresso
Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin =
5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser =
3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
DontDisplayLogonHoursWarnings = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg
Error: Key error. File not found
O9 - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files
(x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program
Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe (Hewlett-Packard)
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources
\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:
\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck
\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework
\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08}
- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck
\NCLauncherFromIE.exe (Hewlett-Packard)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files
\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000019 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour
\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15:64bit: - ..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: localhost ([]* in Local intranet)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility
Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.0…oUploader55.cab (Reg Error:
Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_21-windows-i586.cab (Java Plug-in 10.25.2)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429}
http://www.sibelius.com/download/software/…tiveXPlugin.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_07-windows-i586.cab (Java Plug-in 1.7.0_07)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_09-windows-i586.cab (Java Plug-in 1.7.0_09)
O16 - DPF: {CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_11-windows-i586.cab (Java Plug-in 1.7.0_11)
O16 - DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_13-windows-i586.cab (Java Plug-in 1.7.0_13)
O16 - DPF: {CAFEEFAC-0017-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_15-windows-i586.cab (Java Plug-in 1.7.0_15)
O16 - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_21-windows-i586.cab (Java Plug-in 10.25.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
http://www.popcap.com/webgames/popcaploader_v10.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7}
http://utilities.pcpitstop.com/da2/PCPitStop2.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0B14EA22-C398-4A6A-B131-
129AC47535B8}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B3B58DAF-9BE7-4C03-8FB6-
E721D3E3937F}: DhcpNameServer = 192.168.42.129
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL) - C:\Program Files
(x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll (Sophos Limited)
O20 - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files (x86)\Sophos
\Sophos Anti-Virus\sophos_detoured.dll (Sophos Limited)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft
Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows
\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Program Files (x86)\DigitalPersona\Bin
\DPAgent.exe) - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft
Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows
\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative
\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value
found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/04/01 22:42:26 | 000,001,352 | —- | M] () - T:\AutoHotkey.ahk – [
FAT32 ]
O33 - MountPoints2\{16f65932-de1f-11df-bb53-a2154b190de2}\Shell - "" = AutoRun
O33 - MountPoints2\{16f65932-de1f-11df-bb53-a2154b190de2}\Shell\AutoRun\command - "" = G:
\SISetup.exe
O33 - MountPoints2\{52d07493-7dae-11e1-a03c-c80aa9a0041a}\Shell - "" = AutoRun
O33 - MountPoints2\{52d07493-7dae-11e1-a03c-c80aa9a0041a}\Shell\AutoRun\command - "" = C:
\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\TL-Bootstrap.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut
Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte
Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/08/26 16:26:45 | 000,000,000 | —D | C] – C:\Users\———\AppData\Roaming\vlc
[2013/08/21 20:21:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu
\Programs\iTunes
[2013/08/21 20:21:17 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/08/21 20:21:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013/08/21 20:21:17 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/08/18 18:41:51 | 003,913,664 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\ntoskrnl.exe
[2013/08/18 18:41:50 | 005,550,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\ntoskrnl.exe
[2013/08/18 18:41:50 | 003,968,960 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\ntkrnlpa.exe
[2013/08/18 18:41:50 | 001,732,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\ntdll.dll
[2013/08/18 18:41:49 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\wow64.dll
[2013/08/18 18:41:49 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\setup16.exe
[2013/08/18 18:41:49 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\ntvdm64.dll
[2013/08/18 18:41:49 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\instnm.exe
[2013/08/18 18:41:49 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\wow32.dll
[2013/08/18 18:41:49 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\user.exe
[2013/08/18 18:33:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu
\Programs\VideoLAN
[2013/08/18 02:23:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu
\Programs\Carbonite
[2013/08/17 01:22:28 | 000,000,000 | —D | C] – C:\Users\———\AppData\Roaming\Microsoft
\Windows\Start Menu\Programs\Vulture
[2013/08/17 01:07:44 | 000,000,000 | —D | C] – C:\Users\———\AppData\Roaming\Microsoft
\Windows\Start Menu\Programs\Revo Uninstaller
[2013/08/16 12:15:06 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\ieui.dll
[2013/08/16 12:15:06 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\ieui.dll
[2013/08/16 12:15:05 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\iesysprep.dll
[2013/08/16 12:15:05 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\iesysprep.dll
[2013/08/16 12:15:05 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\RegisterIEPKEYs.exe
[2013/08/16 12:15:05 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\RegisterIEPKEYs.exe
[2013/08/16 12:15:05 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\iesetup.dll
[2013/08/16 12:15:05 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\iesetup.dll
[2013/08/16 12:15:05 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\ie4uinit.exe
[2013/08/16 12:15:05 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\iernonce.dll
[2013/08/16 12:15:05 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\iernonce.dll
[2013/08/16 12:15:04 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\jscript.dll
[2013/08/16 12:15:04 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\jscript.dll
[2013/08/16 12:15:04 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\msfeeds.dll
[2013/08/16 12:15:03 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\jscript9.dll
[2013/08/15 20:28:04 | 001,472,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\crypt32.dll
[2013/08/15 20:28:04 | 000,224,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\wintrust.dll
[2013/08/15 20:28:04 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\cryptnet.dll
[2013/08/15 20:27:53 | 001,217,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\rpcrt4.dll
[2013/08/15 20:27:51 | 001,888,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\WMVDECOD.DLL
[2013/08/15 20:27:51 | 001,620,992 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\WMVDECOD.DLL
[2013/08/01 22:27:41 | 000,000,000 | —D | C] – C:\Windows\SysNative\MRT
[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Users\———\Desktop\*.tmp files -> C:\Users\———\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/08/31 19:15:00 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-
B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/31 19:15:00 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-
B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/31 19:07:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player
Updater.job
[2013/08/31 18:52:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-
21-1963934971-338906939-1860683910-1001UA.job
[2013/08/31 18:33:29 | 000,000,029 | —- | M] () – C:\Windows\SysWow64\TempWmicBatchFile.bat
[2013/08/31 18:26:41 | 2147,483,636 | —- | M] () – C:\Users\———\Documents\TrueCrypt
[2013/08/31 18:19:00 | 000,000,898 | —- | M] () – C:\Windows\tasks
\GoogleUpdateTaskMachineUA.job
[2013/08/31 17:33:26 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/31 15:19:01 | 000,000,894 | —- | M] () – C:\Windows\tasks
\GoogleUpdateTaskMachineCore.job
[2013/08/31 01:52:14 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-
21-1963934971-338906939-1860683910-1001Core.job
[2013/08/31 01:45:00 | 000,000,336 | —- | M] () – C:\Windows\tasks
\HPCeeScheduleFor———.job
[2013/08/31 00:28:07 | 000,002,367 | —- | M] () – C:\Users\———\Desktop\Google Chrome.lnk
[2013/08/31 00:05:35 | 000,743,732 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/08/31 00:05:35 | 000,636,084 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/08/31 00:05:35 | 000,111,626 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/08/30 23:59:23 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2013/08/29 00:25:14 | 000,000,542 | —- | M] () – C:\Windows\tasks\Thursday 1215am Scan.job
[2013/08/29 00:25:12 | 000,000,542 | —- | M] () – C:\Windows\tasks\Thursday 3am Scan.job
[2013/08/26 16:35:07 | 1073,741,824 | —- | M] () – C:\Users\———\Documents\TrueCrypt_2
[2013/08/21 20:21:51 | 000,001,743 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/08/18 17:56:46 | 000,002,176 | —- | M] () – C:\Users\Public\Desktop\Adobe Digital
Editions 2.0.lnk
[2013/08/18 16:46:46 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows
\SysWow64\FlashPlayerApp.exe
[2013/08/18 16:46:46 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows
\SysWow64\FlashPlayerCPLApp.cpl
[2013/08/18 03:03:06 | 2147,483,648 | —- | M] () – C:\Users\———\Documents\PCRs
[2013/08/18 02:23:31 | 000,002,092 | —- | M] () – C:\Users\Public\Desktop\Carbonite
InfoCenter.lnk
[2013/08/17 01:07:45 | 000,001,224 | —- | M] () – C:\Users\———\Desktop\Revo
Uninstaller.lnk
[2013/08/17 01:03:22 | 000,000,632 | RHS- | M] () – C:\Users\———\ntuser.pol
[2013/08/05 17:43:15 | 000,007,596 | —- | M] () – C:\Users\———\AppData\Local
\Resmon.ResmonCfg
[2013/08/04 17:32:15 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Users\———\Desktop\*.tmp files -> C:\Users\———\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/08/31 01:45:00 | 000,000,336 | —- | C] () – C:\Windows\tasks
\HPCeeScheduleFor———.job
[2013/08/21 20:21:51 | 000,001,743 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/08/18 17:56:46 | 000,002,176 | —- | C] () – C:\Users\Public\Desktop\Adobe Digital
Editions 2.0.lnk
[2013/08/18 02:23:31 | 000,002,092 | —- | C] () – C:\Users\Public\Desktop\Carbonite
InfoCenter.lnk
[2013/04/12 22:11:09 | 000,000,632 | RHS- | C] () – C:\Users\———\ntuser.pol
[2012/08/18 13:27:05 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2012/06/01 13:55:52 | 000,292,352 | —- | C] () – C:\Windows\SysWow64\MSAFDLsp.dll
[2012/03/13 14:58:51 | 000,004,096 | -H– | C] () – C:\Users\———\AppData\Local
\keyfile3.drm
[2011/09/18 21:58:54 | 000,000,000 | —- | C] () – C:\Users\———\AppData\Local\{9B826F9E-
E9D5-4DB4-A96C-D4A95AA5347C}
[2011/06/06 11:17:48 | 000,007,596 | —- | C] () – C:\Users\———\AppData\Local
\Resmon.ResmonCfg
[2010/12/01 21:12:36 | 000,001,854 | —- | C] () – C:\Users\———\AppData\Roaming
\GhostObjGAFix.xml
[2010/06/01 16:55:56 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
========== ZeroAccess Check ==========
[2010/12/23 12:20:51 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
/64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-
0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
/64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-
409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
/64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M]
(Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-
0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M]
(Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
/64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M]
(Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-
D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M]
(Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
/64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M]
(Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-
85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2011/04/25 15:00:03 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Audacity
[2011/07/07 17:51:13 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\AVG9
[2010/09/09 20:24:59 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming
\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/06/01 02:07:35 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming
\DigitalPersona
[2011/07/22 23:51:25 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\DVDVideoSoft
[2011/07/22 23:50:53 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming
\DVDVideoSoftIEHelpers
[2012/11/12 13:32:05 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Free-PDF-to-
Word.com
[2011/05/09 00:13:26 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\IObit
[2010/12/23 11:28:20 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\iolo
[2011/04/11 23:28:49 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming
\IsolatedStorage
[2011/03/25 13:53:37 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\LolClient
[2013/01/04 23:32:04 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Notepad++
[2011/09/01 00:11:24 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\ooVoo
Details
[2011/08/03 22:59:00 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Philipp
Winterberg
[2011/01/08 01:01:06 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\PlayFirst
[2012/08/29 20:33:38 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\SimBiotic
Software
[2011/04/11 21:24:07 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Symyx
[2011/11/22 01:38:06 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming
\SystemRequirementsLab
[2013/03/23 19:58:23 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\TomTom
[2013/08/31 19:13:18 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\TrueCrypt
[2010/06/05 17:36:15 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming
\WildTangentv1001
[2011/06/13 17:18:30 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Windows Live
Writer
[2012/03/02 04:34:31 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Xerox
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2009/07/13 22:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:
\Windows\winsxs\amd64_microsoft-windows-
s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:
\Windows\winsxs\amd64_microsoft-windows-shell-
grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2010/02/27 21:53:51 | 002,613,248 | —- | M] (Microsoft Corporation)
MD5=00B0358734CAA32C39D181FE6916B178 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe
[2011/02/26 02:23:14 | 002,870,272 | —- | M] (Microsoft Corporation)
MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation)
MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation)
MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | —- | M] (Microsoft Corporation)
MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2010/05/18 05:32:35 | 002,614,272 | —- | M] (Microsoft Corporation)
MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | —- | M] (Microsoft Corporation)
MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation)
MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation)
MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | —- | M] (Microsoft Corporation)
MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation)
MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2010/02/27 21:53:51 | 002,868,736 | —- | M] (Microsoft Corporation)
MD5=6D4F9E4B640B413C6F73414327484C80 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe
[2010/02/27 21:52:37 | 002,868,224 | —- | M] (Microsoft Corporation)
MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation)
MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation)
MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/05/18 05:32:35 | 002,870,272 | —- | M] (Microsoft Corporation)
MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2010/02/27 21:52:37 | 002,613,248 | —- | M] (Microsoft Corporation)
MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 09:24:45 | 002,872,320 | —- | M] (Microsoft Corporation)
MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2010/05/18 05:32:35 | 002,870,272 | —- | M] (Microsoft Corporation)
MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2010/02/27 21:52:37 | 002,613,248 | —- | M] (Microsoft Corporation)
MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation)
MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2010/05/18 05:32:35 | 002,614,272 | —- | M] (Microsoft Corporation)
MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2010/02/27 21:53:51 | 002,868,736 | —- | M] (Microsoft Corporation)
MD5=CA17F8620815267DC838E30B68CB5052 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe
[2011/02/26 02:26:45 | 002,870,784 | —- | M] (Microsoft Corporation)
MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2010/02/27 21:52:37 | 002,868,224 | —- | M] (Microsoft Corporation)
MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2010/02/27 21:53:51 | 002,613,248 | —- | M] (Microsoft Corporation)
MD5=FC89FACA0473641CB625EDA9277D0885 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation)
MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation)
MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation)
MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation)
MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/08/31 13:43:50 | 000,043,632 | —- | M] () MD5=13B293E99082CD30CD1E26DC85CB9A19 – C:
\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf
< MD5 for: EXPLORER.WSMODE >
[2013/02/25 01:56:00 | 000,000,576 | —- | M] () MD5=6B9A201C766ED41CCB80830192A8428A – C:
\Users\———\.netbeans\7.1.2\config\Windows2Local\Modes\explorer.wsmode
< MD5 for: IEXPLORE.EXE >
[2012/06/02 07:47:54 | 000,754,808 | —- | M] (Microsoft Corporation)
MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2013/01/08 21:53:45 | 000,763,424 | —- | M] (Microsoft Corporation)
MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012/05/17 19:21:54 | 000,748,664 | —- | M] (Microsoft Corporation)
MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2013/05/16 22:32:12 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=07DFD28E57879554D054464EE4A5662D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16614_none_20d88bb252a3770f\iexplore.exe
[2012/11/13 22:56:04 | 000,757,296 | —- | M] (Microsoft Corporation)
MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/06/29 01:02:52 | 000,754,784 | —- | M] (Microsoft Corporation)
MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2013/07/26 02:23:39 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=133CEF30905806A35606652D409EEEBA – C:\Program Files\Internet Explorer\iexplore.exe
[2013/07/26 02:23:39 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=133CEF30905806A35606652D409EEEBA – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16660_none_16893df21e3dcd43\iexplore.exe
[2010/09/08 00:36:39 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=14803EA3E5DD7CB37CB446C74CFDA38F – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.20795_none_1a39121b8bff3c23\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation)
MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012/05/17 18:59:46 | 000,748,664 | —- | M] (Microsoft Corporation)
MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20551_none_181271f4ce004017\iexplore.exe
[2012/10/08 04:37:24 | 000,748,704 | —- | M] (Microsoft Corporation)
MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2013/03/24 00:41:24 | 000,770,560 | —- | M] (Microsoft Corporation)
MD5=2859EBC065D2E1CCC94161CE28BAC085 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16521_none_20e4a040529a2792\iexplore.exe
[2013/02/24 20:58:09 | 000,775,232 | —- | M] (Microsoft Corporation)
MD5=28F93BAFB3EB407E99A7ED3D9DBDE04C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20644_none_ffb93ba237e760ce\iexplore.exe
[2013/06/12 00:41:27 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=2A5F565327BFD679EC5F790DC15BBF25 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20742_none_0a0343986c500b78\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation)
MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2012/08/24 07:23:44 | 000,754,824 | —- | M] (Microsoft Corporation)
MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2013/04/05 01:55:38 | 000,770,624 | —- | M] (Microsoft Corporation)
MD5=2DC6BD1047553611DAEF97C751131A5D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20681_none_0a122b746c443b42\iexplore.exe
[2013/06/11 20:23:57 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16635_none_20da757e52a1c35e\iexplore.exe
[2012/06/02 05:08:27 | 000,748,664 | —- | M] (Microsoft Corporation)
MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2013/05/16 21:57:28 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=3902E280F6117A468D5573343A7AA1F6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20719_none_09ffa3426c5372da\iexplore.exe
[2010/09/08 01:37:57 | 000,696,592 | —- | M] (Microsoft Corporation)
MD5=4879CB864E290BED38C5BDB641144B1B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.20795_none_0fe467c9579e7a28\iexplore.exe
[2012/10/08 08:29:46 | 000,754,848 | —- | M] (Microsoft Corporation)
MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2010/09/08 01:49:01 | 000,696,592 | —- | M] (Microsoft Corporation)
MD5=498035ABCCF1ED47AE6791D239187587 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16671_none_0f6c69ae3e743d20\iexplore.exe
[2012/05/17 22:51:05 | 000,754,808 | —- | M] (Microsoft Corporation)
MD5=4E99F42504A99D5024C2EFA015001937 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2010/11/04 01:54:54 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=58CF468D3FF4CF830339FE5E45356355 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16700_none_1a0bc510729d1f54\iexplore.exe
[2012/08/24 06:49:07 | 000,754,824 | —- | M] (Microsoft Corporation)
MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/06/28 22:45:31 | 000,754,808 | —- | M] (Microsoft Corporation)
MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012/06/02 08:52:21 | 000,754,808 | —- | M] (Microsoft Corporation)
MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2010/09/08 00:31:24 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16671_none_19c1140072d4ff1b\iexplore.exe
[2012/08/24 03:49:25 | 000,748,680 | —- | M] (Microsoft Corporation)
MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2013/02/21 08:59:57 | 000,775,216 | —- | M] (Microsoft Corporation)
MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16540_none_16920d4a1e377ea4\iexplore.exe
[2013/03/24 00:41:20 | 000,775,184 | —- | M] (Microsoft Corporation)
MD5=681B380492ACB571ED6CCC1F37F53343 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16521_none_168ff5ee1e396597\iexplore.exe
[2013/01/08 18:42:06 | 000,757,280 | —- | M] (Microsoft Corporation)
MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2010/11/04 01:54:59 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=6B2258FF6D2332073FE9E90122FA4168 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.20831_none_1a75f2618bd22c48\iexplore.exe
[2010/12/18 02:17:48 | 000,696,592 | —- | M] (Microsoft Corporation)
MD5=700B40EA39DFB25517A81032F03D6D20 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16722_none_0fa37b7a3e4ac7e9\iexplore.exe
[2013/07/25 23:49:06 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/07/25 23:49:06 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16660_none_20dde844529e8f3e\iexplore.exe
[2013/02/02 04:09:12 | 000,763,424 | —- | M] (Microsoft Corporation)
MD5=7C2923004FFC497E54F38E835F108EE8 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2010/11/20 09:28:25 | 000,695,056 | —- | M] (Microsoft Corporation)
MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2010/12/18 02:11:10 | 000,696,592 | —- | M] (Microsoft Corporation)
MD5=8C6C32E4AF8A3D7155656F5897C504E0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.20861_none_1000d84b5789be20\iexplore.exe
[2013/07/26 01:47:06 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=8D805B4EEEE0ECF6B604BE284978F135 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20768_none_ffb0112a37ee15f1\iexplore.exe
[2013/05/16 23:02:08 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=8F00471CA24ADF8D2AFAACF856EB70A4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20719_none_ffaaf8f037f2b0df\iexplore.exe
[2011/03/31 00:08:52 | 000,748,336 | —- | M] (Microsoft Corporation)
MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2010/12/18 01:32:25 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=9321CF0D023528C71E3645F8433C86C8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.20861_none_1a55829d8bea801b\iexplore.exe
[2012/06/28 21:00:47 | 000,748,664 | —- | M] (Microsoft Corporation)
MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2013/06/11 22:28:00 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16635_none_1685cb2c1e410163\iexplore.exe
[2013/02/24 19:52:40 | 000,770,624 | —- | M] (Microsoft Corporation)
MD5=A11C5E3E288256C540B7ED8BE3A04B01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20644_none_0a0de5f46c4822c9\iexplore.exe
[2013/02/02 00:19:03 | 000,757,280 | —- | M] (Microsoft Corporation)
MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013/02/02 03:37:58 | 000,763,424 | —- | M] (Microsoft Corporation)
MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2010/12/18 01:33:54 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16722_none_19f825cc72ab89e4\iexplore.exe
[2013/04/05 02:02:26 | 000,770,608 | —- | M] (Microsoft Corporation)
MD5=AAD90795E84E710543C6C7C2F7048E30 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16576_none_20e92fca5296266a\iexplore.exe
[2012/11/15 23:08:58 | 000,763,424 | —- | M] (Microsoft Corporation)
MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:
\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/06/02 04:51:58 | 000,748,664 | —- | M] (Microsoft Corporation)
MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2013/06/12 03:51:43 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=CA88A25280B1D85ED0BC26B042ABBCCF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20742_none_ffae994637ef497d\iexplore.exe
[2013/04/05 03:53:33 | 000,775,232 | —- | M] (Microsoft Corporation)
MD5=CEA304830B4770BDA3572B87D0841848 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16576_none_169485781e35646f\iexplore.exe
[2012/10/08 04:22:05 | 000,748,704 | —- | M] (Microsoft Corporation)
MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2010/11/04 02:37:41 | 000,696,592 | —- | M] (Microsoft Corporation)
MD5=D8E00EA671A1EFE95C69C7566C505AD4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16700_none_0fb71abe3e3c5d59\iexplore.exe
[2013/02/02 00:19:04 | 000,757,296 | —- | M] (Microsoft Corporation)
MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2013/04/05 03:23:03 | 000,775,216 | —- | M] (Microsoft Corporation)
MD5=DE751E18F8DBF7BCCE46989CBA4A9828 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20681_none_ffbd812237e37947\iexplore.exe
[2010/11/04 02:42:22 | 000,696,592 | —- | M] (Microsoft Corporation)
MD5=E220FB009F54AAF649C6A278A5156764 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.20831_none_1021480f57716a4d\iexplore.exe
[2013/02/21 07:28:11 | 000,770,608 | —- | M] (Microsoft Corporation)
MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16540_none_20e6b79c5298409f\iexplore.exe
[2013/07/26 01:09:39 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=E70D60B3A350BD09D86CDAD9CF55F36B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20768_none_0a04bb7c6c4ed7ec\iexplore.exe
[2012/06/28 19:35:27 | 000,748,664 | —- | M] (Microsoft Corporation)
MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2013/05/16 23:30:45 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=EDC77CF787FA015205936C9A3228486E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16614_none_1683e1601e42b514\iexplore.exe
[2013/01/08 20:51:57 | 000,763,424 | —- | M] (Microsoft Corporation)
MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 17:32:42 | 000,757,280 | —- | M] (Microsoft Corporation)
MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2011/03/31 00:08:49 | 000,754,480 | —- | M] (Microsoft Corporation)
MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2009/07/13 21:43:43 | 000,696,600 | —- | M] (Microsoft Corporation)
MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2012/10/08 07:09:10 | 000,754,824 | —- | M] (Microsoft Corporation)
MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012/11/13 22:19:28 | 000,757,280 | —- | M] (Microsoft Corporation)
MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/05/17 21:37:57 | 000,754,808 | —- | M] (Microsoft Corporation)
MD5=F8B2D47ED17C1D087D14EC747E5AC57A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20551_none_0dbdc7a2999f7e1c\iexplore.exe
[2012/11/14 03:11:18 | 000,763,424 | —- | M] (Microsoft Corporation)
MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2011/03/31 00:08:50 | 000,005,632 | —- | M] (Microsoft Corporation)
MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/03/31 00:08:53 | 000,005,632 | —- | M] (Microsoft Corporation)
MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/03/24 00:41:25 | 000,005,632 | —- | M] (Microsoft Corporation)
MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US
\iexplore.exe.mui
[2013/03/24 00:41:21 | 000,005,632 | —- | M] (Microsoft Corporation)
MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/03/24 00:41:21 | 000,005,632 | —- | M] (Microsoft Corporation)
MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/03/24 00:41:25 | 000,005,632 | —- | M] (Microsoft Corporation)
MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation)
MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation)
MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation)
MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation)
MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui
< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:
\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-
other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
< MD5 for: SERVICES.CFG >
[2013/05/10 03:57:30 | 000,558,879 | —- | M] () MD5=3679F8D3253DC110D1D8F2AE115EE00C – C:
\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:
\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation)
MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation)
MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-
servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation)
MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation)
MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-
s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:
\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:
\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:
\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:
\Windows\winsxs\amd64_microsoft-windows-s..s-
servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
< MD5 for: SERVICES.MSC >
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\SysNative\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\SysWOW64\services.msc
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\winsxs\amd64_microsoft-windows-
s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\winsxs\amd64_microsoft-windows-
servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-
us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\winsxs\x86_microsoft-windows-
servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:
\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:
\Windows\winsxs\amd64_microsoft-windows-s..s-
servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
< MD5 for: SERVICES.SETTINGS >
[2013/02/25 01:56:00 | 000,001,622 | —- | M] () MD5=488D8CC923D82E3FADA846EF9587A289 – C:
\Users\———\.netbeans\7.1.2\config\Windows2Local\Components\services.settings
< MD5 for: SERVICES.WSTCGRP >
[2013/02/25 01:56:00 | 000,000,224 | —- | M] () MD5=4C0234F9B3F49A3484CE64025050D7A7 – C:
\Users\———\.netbeans\7.1.2\config\Windows2Local\Groups\InitialLayout\services.wstcgrp
[2013/02/25 01:56:00 | 000,000,225 | —- | M] () MD5=E4AD31A486D75BC449F02775904D2430 – C:
\Users\———\.netbeans\7.1.2\config\Windows2Local\Groups\OpenedProjects\services.wstcgrp
< MD5 for: SERVICES.WSTCREF >
[2013/02/25 01:56:00 | 000,000,129 | —- | M] () MD5=73E5717A2B2C3FF0F7ED6EFDD0A658B3 – C:
\Users\———\.netbeans\7.1.2\config\Windows2Local\Modes\explorer\services.wstcref
< MD5 for: WINLOGON.ADML >
[2009/07/13 22:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:
\Windows\winsxs\amd64_microsoft-windows-winlogon-
adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:
\Windows\winsxs\amd64_microsoft-windows-winlogon-
adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation)
MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation)
MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-
winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation)
MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-
winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2010/05/18 05:32:35 | 000,389,632 | —- | M] (Microsoft Corporation)
MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-
winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:
\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010/05/18 05:32:35 | 000,389,632 | —- | M] (Microsoft Corporation)
MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-
winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation)
MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation)
MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-
winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2009/07/13 22:29:52 | 000,022,528 | —- | M] (Microsoft Corporation)
MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-
winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:
\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:
\Windows\winsxs\amd64_microsoft-windows-winlogon-
mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:
\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:
\Windows\winsxs\amd64_microsoft-windows-winlogon-
mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2001/09/05 21:00:58 | 001,700,352 | —- | M] (Microsoft Corporation) – C:\gdiplus.dll
[2013/08/30 23:59:23 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2010/09/06 12:56:46 | 000,015,872 | —- | M] () – C:\MDL.Draw.Editor.XmlSerializers.dll
[2010/09/06 12:57:06 | 004,275,200 | —- | M] () – C:\oedrawaddincsharp.dll
[2010/09/06 12:57:06 | 000,024,576 | —- | M] (OpenEye Scientific Software, Inc.) – C:
\OpenEye.oedrawaddin.dll
[2013/08/30 23:59:24 | 4083,007,488 | -HS- | M] () – C:\pagefile.sys
[2010/07/21 18:10:51 | 000,000,085 | —- | M] () – C:\SETUP.LOG
[2010/07/07 20:43:53 | 000,000,085 | —- | M] () – C:\SYNTPAD.LOG
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts
\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts
\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts
\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/07/22 20:51:05 | 000,001,670 | -HS- | M] () – C:\Users\———\AppData\Roaming\Microsoft
\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 726B-5B53
Directory of C:\
07/14/2009 01:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 01:08 AM All Users [C:\ProgramData]
07/14/2009 01:08 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\———
06/01/2010 02:07 AM Application Data [C:\Users\———\AppData\Roaming]
06/01/2010 02:07 AM Cookies [C:\Users\———\AppData\Roaming\Microsoft
\Windows\Cookies]
06/01/2010 02:07 AM Local Settings [C:\Users\———\AppData\Local]
06/01/2010 02:07 AM My Documents [C:\Users\———\Documents]
06/01/2010 02:07 AM NetHood [C:\Users\———\AppData\Roaming\Microsoft
\Windows\Network Shortcuts]
06/01/2010 02:07 AM PrintHood [C:\Users\———\AppData\Roaming\Microsoft
\Windows\Printer Shortcuts]
06/01/2010 02:07 AM Recent [C:\Users\———\AppData\Roaming\Microsoft
\Windows
\Recent]
06/01/2010 02:07 AM SendTo [C:\Users\———\AppData\Roaming\Microsoft
\Windows
\SendTo]
06/01/2010 02:07 AM Start Menu [C:\Users\———\AppData\Roaming\Microsoft
\Windows\Start Menu]
06/01/2010 02:07 AM Templates [C:\Users\———\AppData\Roaming\Microsoft
\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\———\AppData\Local
06/01/2010 02:07 AM Application Data [C:\Users\———\AppData\Local]
06/01/2010 02:07 AM History [C:\Users\———\AppData\Local\Microsoft
\Windows
\History]
06/01/2010 02:07 AM Temporary Internet Files [C:\Users\———\AppData\Local
\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\———\Documents
06/01/2010 02:07 AM My Music [C:\Users\———\Music]
06/01/2010 02:07 AM My Pictures [C:\Users\———\Pictures]
06/01/2010 02:07 AM My Videos [C:\Users\———\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 01:08 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\Cookies]
07/14/2009 01:08 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM My Documents [C:\Users\Default\Documents]
07/14/2009 01:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\Network Shortcuts]
07/14/2009 01:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\Printer Shortcuts]
07/14/2009 01:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\Recent]
07/14/2009 01:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\SendTo]
07/14/2009 01:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows
\History]
07/14/2009 01:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local
\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 01:08 AM My Music [C:\Users\Default\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Guest
08/01/2013 10:20 PM Application Data [C:\Users\Guest\AppData\Roaming]
08/01/2013 10:20 PM Cookies [C:\Users\Guest\AppData\Roaming\Microsoft\Windows
\Cookies]
08/01/2013 10:20 PM Local Settings [C:\Users\Guest\AppData\Local]
08/01/2013 10:20 PM My Documents [C:\Users\Guest\Documents]
08/01/2013 10:20 PM NetHood [C:\Users\Guest\AppData\Roaming\Microsoft\Windows
\Network Shortcuts]
08/01/2013 10:20 PM PrintHood [C:\Users\Guest\AppData\Roaming\Microsoft
\Windows\Printer Shortcuts]
08/01/2013 10:20 PM Recent [C:\Users\Guest\AppData\Roaming\Microsoft\Windows
\Recent]
08/01/2013 10:20 PM SendTo [C:\Users\Guest\AppData\Roaming\Microsoft\Windows
\SendTo]
08/01/2013 10:20 PM Start Menu [C:\Users\Guest\AppData\Roaming\Microsoft
\Windows\Start Menu]
08/01/2013 10:20 PM Templates [C:\Users\Guest\AppData\Roaming\Microsoft
\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Guest\AppData\Local
08/01/2013 10:20 PM Application Data [C:\Users\Guest\AppData\Local]
08/01/2013 10:20 PM History [C:\Users\Guest\AppData\Local\Microsoft\Windows
\History]
08/01/2013 10:20 PM Temporary Internet Files [C:\Users\Guest\AppData\Local
\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Guest\Documents
08/01/2013 10:20 PM My Music [C:\Users\Guest\Music]
08/01/2013 10:20 PM My Pictures [C:\Users\Guest\Pictures]
08/01/2013 10:20 PM My Videos [C:\Users\Guest\Videos]
0 File(s) 0 bytes
Directory of C:\Users\GuestUser
08/05/2013 06:13 PM Application Data [C:\Users\GuestUser\AppData\Roaming]
08/05/2013 06:13 PM Cookies [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\Cookies]
08/05/2013 06:13 PM Local Settings [C:\Users\GuestUser\AppData\Local]
08/05/2013 06:13 PM My Documents [C:\Users\GuestUser\Documents]
08/05/2013 06:13 PM NetHood [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\Network Shortcuts]
08/05/2013 06:13 PM PrintHood [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\Printer Shortcuts]
08/05/2013 06:13 PM Recent [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\Recent]
08/05/2013 06:13 PM SendTo [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\SendTo]
08/05/2013 06:13 PM Start Menu [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\Start Menu]
08/05/2013 06:13 PM Templates [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\GuestUser\AppData\Local
08/05/2013 06:13 PM Application Data [C:\Users\GuestUser\AppData\Local]
08/05/2013 06:13 PM History [C:\Users\GuestUser\AppData\Local\Microsoft
\Windows\History]
08/05/2013 06:13 PM Temporary Internet Files [C:\Users\GuestUser\AppData
\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\GuestUser\Documents
08/05/2013 06:13 PM My Music [C:\Users\GuestUser\Music]
08/05/2013 06:13 PM My Pictures [C:\Users\GuestUser\Pictures]
08/05/2013 06:13 PM My Videos [C:\Users\GuestUser\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 01:08 AM My Music [C:\Users\Public\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\TEMP
08/23/2010 03:49 PM Application Data [C:\Users\TEMP\AppData\Roaming]
08/23/2010 03:49 PM Cookies [C:\Users\TEMP\AppData\Roaming\Microsoft\Windows
\Cookies]
08/23/2010 03:49 PM Local Settings [C:\Users\TEMP\AppData\Local]
08/23/2010 03:49 PM My Documents [C:\Users\TEMP\Documents]
08/23/2010 03:49 PM NetHood [C:\Users\TEMP\AppData\Roaming\Microsoft\Windows
\Network Shortcuts]
08/23/2010 03:49 PM PrintHood [C:\Users\TEMP\AppData\Roaming\Microsoft
\Windows\Printer Shortcuts]
08/23/2010 03:49 PM Recent [C:\Users\TEMP\AppData\Roaming\Microsoft\Windows
\Recent]
08/23/2010 03:49 PM SendTo [C:\Users\TEMP\AppData\Roaming\Microsoft\Windows
\SendTo]
08/23/2010 03:49 PM Start Menu [C:\Users\TEMP\AppData\Roaming\Microsoft
\Windows\Start Menu]
08/23/2010 03:49 PM Templates [C:\Users\TEMP\AppData\Roaming\Microsoft
\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\TEMP\AppData\Local
08/23/2010 03:49 PM Application Data [C:\Users\TEMP\AppData\Local]
08/23/2010 03:49 PM History [C:\Users\TEMP\AppData\Local\Microsoft\Windows
\History]
08/23/2010 03:49 PM Temporary Internet Files [C:\Users\TEMP\AppData\Local
\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\TEMP\Documents
08/23/2010 03:49 PM My Music [C:\Users\TEMP\Music]
08/23/2010 03:49 PM My Pictures [C:\Users\TEMP\Pictures]
08/23/2010 03:49 PM My Videos [C:\Users\TEMP\Videos]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile
05/18/2010 06:12 AM Application Data [C:\Windows\system32\config
\systemprofile\AppData\Roaming]
05/18/2010 06:12 AM Cookies [C:\Windows\system32\config\systemprofile\AppData
\Roaming\Microsoft\Windows\Cookies]
05/18/2010 06:12 AM Local Settings [C:\Windows\system32\config\systemprofile
\AppData\Local]
07/23/2011 12:13 AM Start Menu [C:\Windows\system32\config\systemprofile
\AppData\Roaming\Microsoft\Windows\Start Menu]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\AppData\Local
05/18/2010 06:12 AM Application Data [C:\Windows\system32\config
\systemprofile\AppData\Local]
05/18/2010 06:12 AM History [C:\Windows\system32\config\systemprofile\AppData
\Local\Microsoft\Windows\History]
05/18/2010 06:12 AM Temporary Internet Files [C:\Windows\system32\config
\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Windows\SysWOW64\config\systemprofile
05/18/2010 06:12 AM Application Data [C:\Windows\system32\config
\systemprofile\AppData\Roaming]
05/18/2010 06:12 AM Cookies [C:\Windows\system32\config\systemprofile\AppData
\Roaming\Microsoft\Windows\Cookies]
05/18/2010 06:12 AM Local Settings [C:\Windows\system32\config\systemprofile
\AppData\Local]
07/23/2011 12:13 AM Start Menu [C:\Windows\system32\config\systemprofile
\AppData\Roaming\Microsoft\Windows\Start Menu]
0 File(s) 0 bytes
Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Local
05/18/2010 06:12 AM Application Data [C:\Windows\system32\config
\systemprofile\AppData\Local]
05/18/2010 06:12 AM History [C:\Windows\system32\config\systemprofile\AppData
\Local\Microsoft\Windows\History]
05/18/2010 06:12 AM Temporary Internet Files [C:\Windows\system32\config
\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
112 Dir(s) 153,010,155,520 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/11 18:17:36 | 000,000,221 | -HS- | M] () – C:\Users\———\AppData\Roaming\Microsoft
\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto
Update\Results\Install|LastSuccessTime /rs >
< End of report >
********************************************************************************
**********
Extras.txt:
OTL Extras logfile created on: 8/31/2013 7:13:26 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\———\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.80 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 39.01% Memory free
7.60 Gb Paging File | 4.71 Gb Available in Paging File | 62.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 276.46 Gb Total Space | 142.57 Gb Free Space | 51.57% Space Free | Partition Type:
NTFS
Drive D: | 21.33 Gb Total Space | 3.10 Gb Free Space | 14.53% Space Free | Partition Type: NTFS
Drive E: | 99.34 Mb Total Space | 84.17 Mb Free Space | 84.74% Space Free | Partition Type: FAT32
Drive T: | 49.98 Gb Total Space | 46.89 Gb Free Space | 93.82% Space Free | Partition Type: FAT32
Computer Name: ——— | User Name: ——— | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File
Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft
Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%
\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows
\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows
\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%
\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file
–playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –
no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1
(Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet
Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft
Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%
\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%
\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file
–playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –
no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1
(Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"" =
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\DomainProfile\GloballyOpenPorts\List]
"8192:TCP" = 8192:TCP:*:Enabled:Sophos AntiVirus
"8193:TCP" = 8193:TCP:*:Enabled:Sophos AntiVirus
"8194:TCP" = 8194:TCP:*:Enabled:Sophos AntiVirus
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\StandardProfile\GloballyOpenPorts\List]
"8192:TCP" = 8192:TCP:*:Enabled:Sophos AntiVirus
"8193:TCP" = 8193:TCP:*:Enabled:Sophos AntiVirus
"8194:TCP" = 8194:TCP:*:Enabled:Sophos AntiVirus
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\FirewallRules]
"{06369B26-1349-441A-9131-7FAC7568A0E3}" = rport=138 | protocol=17 | dir=out | app=system |
"{0ABD4E45-204B-40F0-B466-8ED75D43DFA0}" = lport=6004 | protocol=17 | dir=in | app=c:\program
files (x86)\microsoft office\office12\outlook.exe |
"{1743EC63-9BBE-412C-8729-B2BCCBB6AD7B}" = lport=8192 | protocol=6 | dir=in |
name=sophosdomain8192 |
"{263543C5-DEC6-49C6-AB40-F118A3E1D265}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv |
app=svchost.exe |
"{28301FBC-D455-4033-B46F-0F60809630BF}" = lport=139 | protocol=6 | dir=in | app=system |
"{441ECA01-2DAE-4808-9C1E-D1AC84971305}" = lport=5355 | protocol=17 | dir=in | svc=dnscache |
app=%systemroot%\system32\svchost.exe |
"{475552AD-51ED-4294-ADB6-C6061FBD0E07}" = lport=2869 | protocol=6 | dir=in | name=windows live
communications platform (upnp) |
"{492CED09-A62B-4771-9E10-DD846D0F2767}" = lport=2869 | protocol=6 | dir=in | app=system |
"{64224B44-517C-4AC6-AF3F-08D0601B8FBD}" = rport=137 | protocol=17 | dir=out | app=system |
"{662BEF3C-F82D-45A0-8DF3-1E5882E67B4F}" = lport=1900 | protocol=17 | dir=in | name=windows live
communications platform (ssdp) |
"{7957BC65-B941-4AD0-BF0E-1914AD32273A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache |
app=%systemroot%\system32\svchost.exe |
"{7C996A8C-CAB2-4E3D-9170-4178B3BA95C5}" = lport=8193 | protocol=6 | dir=in |
name=sophospublic8193 |
"{86A6E98B-7C75-421E-84A2-CE93E11CE3CB}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss |
name=@firewallapi.dll,-28539 |
"{8F97CB72-3F3D-4099-8A2F-1DF3CB1F3087}" = rport=445 | protocol=6 | dir=out | app=system |
"{90721D3F-E21A-44F1-A6B2-25A8575ED766}" = lport=8193 | protocol=6 | dir=in |
name=sophosdomain8193 |
"{91225E08-696C-414A-B188-309E39401C91}" = lport=8194 | protocol=6 | dir=in |
name=sophosdomain8194 |
"{98846273-FCE5-4FEF-924E-715B7408C2DF}" = lport=5355 | protocol=17 | dir=in | svc=dnscache |
app=%systemroot%\system32\svchost.exe |
"{9CD4115A-10C6-4D9F-9DB8-116E10BA2602}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=
%systemroot%\system32\spoolsv.exe |
"{9E07F4F2-3D8F-4408-8EAD-B33C09C4FBB6}" = rport=139 | protocol=6 | dir=out | app=system |
"{A5FCB6F4-F2AE-4120-8DA5-2390A02E3453}" = rport=5355 | protocol=17 | dir=out | svc=dnscache |
app=%systemroot%\system32\svchost.exe |
"{D3365AD0-B58E-4462-B10D-314A14244858}" = lport=138 | protocol=17 | dir=in | app=system |
"{D8206270-AC94-4361-97F6-1971BBCD1B0D}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc |
app=c:\windows\system32\svchost.exe |
"{DC7A6F3A-A69E-475E-A3A2-17FAD3E8A4E0}" = lport=8194 | protocol=6 | dir=in |
name=sophospublic8194 |
"{E2364760-EA20-49B1-B546-2E605A41C737}" = lport=445 | protocol=6 | dir=in | app=system |
"{E5E5D84D-44B0-46CE-A04C-977EB18BA010}" = lport=137 | protocol=17 | dir=in | app=system |
"{EAE7D401-85CC-4585-9057-9D599AA58130}" = lport=8192 | protocol=6 | dir=in |
name=sophospublic8192 |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\FirewallRules]
"{000C9CF3-F3A4-44D2-952B-8C2D8AF54542}" = protocol=17 | dir=out | app=%programfiles%\windows
media player\wmplayer.exe |
"{0508A32E-F3F2-4C08-B8A5-8157A7B8E9BB}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{0C44595B-9B02-42C4-B18D-2C9A480D66CE}" = protocol=6 | dir=in | app=c:\users\———\appdata
\local\google\google talk plugin\googletalkplugin.exe |
"{108EDA04-616B-4420-8639-412AFC1AF4B2}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqusgh.exe |
"{1219FAE0-E710-43F3-8BAC-D616B0F0D591}" = protocol=6 | dir=in | app=c:\users\———\appdata
\local\google\google talk plugin\googletalkplugin.exe |
"{16E0A08A-5F82-403C-85F0-B6433B37CDEE}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpofxm08.exe |
"{18D21069-7620-4B3F-A762-1138130932C4}" = protocol=6 | dir=in | app=c:\program files
(x86)\bonjour\mdnsresponder.exe |
"{1B65F1F8-CECD-48AA-8D3C-4E843E740B34}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpzwiz01.exe |
"{1CB17461-A480-48A6-BA5A-1C2B1AA483E5}" = dir=in | app=c:\program files\hp\hp officejet pro
8600\bin\hpnetworkcommunicatorcom.exe |
"{1CB27C2C-D03E-4A5A-A432-47870B12C431}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpoews01.exe |
"{2162F9E1-7CE4-4277-9B66-003FBC3E3408}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{2215995B-84F0-4090-AB33-EB4AA61BB0C8}" = dir=in | app=c:\program files (x86)\windows live
\messenger\msnmsgr.exe |
"{22329288-1724-41DD-BA57-CF2C88230D2B}" = dir=in | app=c:\program files (x86)\windows live\sync
\windowslivesync.exe |
"{231C333F-FD39-4931-98DA-489C9D64D42C}" = dir=in | app=c:\program files (x86)\hewlett-packard
\touchsmart\music\hptouchsmartmusic.exe |
"{2AF0460F-07EA-4081-A55F-5FF499FDFC25}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{2BF99A4A-A3AE-4251-BD08-B36BA35F9FD8}" = protocol=6 | dir=in | app=c:\program files
(x86)\microsoft office\office12\onenote.exe |
"{33FD3BDF-0D02-4C9F-B766-367360FC46B2}" = protocol=6 | dir=in | app=c:\program files\hp\hp
deskjet 3050 j610 series\bin\devicesetup.exe |
"{396BC68B-D88F-4B5C-B8B1-B8E31EC8FD9A}" = protocol=6 | dir=in | app=c:\users\———\appdata
\local\akamai\netsession_win.exe |
"{401570AD-D1E0-4115-BD79-C64BA347B46D}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqgplgtupl.exe |
"{4322F255-2072-4F8A-89F2-4CC4A7DA4095}" = dir=in | app=c:\program files (x86)\windows live
\contacts\wlcomm.exe |
"{47EFBAB2-5339-4D97-BA99-35FF5F37CAD7}" = dir=in | app=c:\program files\hp\hp officejet pro
8600\bin\faxapplications.exe |
"{4A633776-6793-4909-B8A9-040D788196CC}" = protocol=17 | dir=in | app=c:\program files\hp\hp
deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |
"{4D954FCD-E26C-4669-8E3F-CC9F3C4628E1}" = dir=in | app=c:\program files\hp\hp officejet pro
8600\bin\sendafax.exe |
"{4F3A5693-BD4B-46FE-AF47-D24D0FAA7650}" = protocol=17 | dir=in | app=c:\users\———\appdata
\local\akamai\netsession_win.exe |
"{528584E3-554B-4085-86E9-77D98D422A2A}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqfxt08.exe |
"{5554CDDA-7ECE-43DA-AF6E-C670718ADEF8}" = dir=in | app=c:\program files\intel\wifi\bin
\pandhcpdns.exe |
"{57BFBA45-2266-486C-B802-0D5EA559BFCF}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqste08.exe |
"{59A7A7A1-7201-4E46-9870-10862C70116B}" = protocol=17 | dir=out | app=%programfiles(x86)%
\windows media player\wmplayer.exe |
"{650E62D7-F33F-482D-8961-6D68C091774F}" = protocol=17 | dir=in | app=c:\program files\bonjour
\mdnsresponder.exe |
"{65EFACF9-F407-4BF8-A33E-0D2A3DDD85B8}" = protocol=17 | dir=in | app=c:\users\———\appdata
\local\google\google talk plugin\googletalkplugin.exe |
"{76C42CF3-30D7-49CD-AD09-E1B4D71A085B}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp
support framework\resources\hpwarrantycheck\hpdevicedetection3.exe |
"{77F962F6-C918-4811-9EF3-7483B2F8C348}" = protocol=17 | dir=in | app=c:\program files
(x86)\microsoft office\office12\onenote.exe |
"{7DA74380-9CE7-436C-88CE-2E45A954ACB3}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqkygrp.exe |
"{80D5776F-4D39-4FD8-952F-4833917162D9}" = dir=in | app=c:\program files (x86)\common files
\apple\apple application support\webkit2webprocess.exe |
"{810C9527-51E9-4B7D-AC2C-0325426C2E3F}" = dir=in | app=c:\program files\hp\hp officejet pro
8600\bin\digitalwizards.exe |
"{817DE8D6-569A-43C9-91A7-58EAA28A1D4A}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp
support framework\resources\hpwarrantycheck\hpwarrantychecker.exe |
"{85B5B769-ECEB-4AA4-B5CA-0FC6BDDDEC96}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqusgm.exe |
"{85DBA9A3-4A5D-4F16-8435-7CE5FE2209DE}" = protocol=6 | dir=in | app=c:\program files
(x86)\bonjour\mdnsresponder.exe |
"{992FB719-F3E8-4DFB-863D-5726252E9846}" = protocol=17 | dir=in | app=%programfiles%\windows
media player\wmplayer.exe |
"{9F2AEBF5-41E1-4FF9-B9A9-F51CC6A6E4B5}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows
media player\wmplayer.exe |
"{B2443E04-7A71-46BD-A75F-48DE0388C67F}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpofxs08.exe |
"{B26FD83C-0002-4166-9412-0B0B9764167F}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpfccopy.exe |
"{B276CA34-08BC-4E1B-9373-03A02774F09C}" = dir=in | app=f:\setup\hpznui40.exe |
"{B534C11A-D24A-4FE1-BCC5-D652A88BD5F7}" = protocol=6 | dir=in | app=c:\program files\bonjour
\mdnsresponder.exe |
"{BC92F26E-B405-4C39-B78F-FB96AC946345}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpiscnapp.exe |
"{BD2F4C4E-25F8-45BF-8BA2-F09A7F5C861E}" = protocol=6 | dir=in | app=c:\program files\hp\hp
deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |
"{C5D8D09A-ACD2-4CEA-9410-48F2FB21A128}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hposid01.exe |
"{C6F907E2-39DF-4F54-A70F-FF5C43285BA4}" = protocol=6 | dir=out | app=%programfiles%\windows
media player\wmplayer.exe |
"{C78F4F3B-79D4-4D86-8871-95CEBAB34CE2}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqtra08.exe |
"{C90D356F-EC17-4A74-9B7B-1D2023146390}" = protocol=17 | dir=in | app=c:\program files
(x86)\bonjour\mdnsresponder.exe |
"{CAE2E8E9-072E-4CDE-AAED-6F403561EC5E}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\smart web printing\smartwebprintexe.exe |
"{CAE96F8E-94AD-4989-B04B-A2C5298A8677}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe
|
"{CB9F066A-2691-432A-ABD6-D013CA8F615D}" = protocol=17 | dir=in | app=c:\program files
(x86)\internet explorer\iexplore.exe |
"{CD0F2DAD-E698-4C4F-B707-6220E46E1867}" = protocol=17 | dir=in | app=c:\program files
(x86)\bonjour\mdnsresponder.exe |
"{D04D7A99-CB58-49F3-A44E-6E57D31BF52C}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqgpc01.exe |
"{D7CC9EE7-CADD-4B18-BC5C-8A13A1C7FA64}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hposfx08.exe |
"{DB1206B4-B3B3-499E-80DC-CCE68D6CAEBF}" = dir=in | app=c:\program files\hp\hp officejet pro
8600\bin\hpnetworkcommunicator.exe |
"{E2090F0B-50F3-4607-92E9-2605003D1716}" = protocol=17 | dir=in | app=c:\program files\hp\hp
deskjet 3050 j610 series\bin\devicesetup.exe |
"{EABBE83A-A26D-4EBF-819F-FFC72FE94B52}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows
media player\wmplayer.exe |
"{ECCBDD9A-3332-407F-9533-9C3E3FE28651}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{F4492C96-E634-4484-9449-E4EFE59ABC28}" = dir=in | app=c:\program files (x86)\hp\hp software
update\hpwucli.exe |
"{F4714187-3025-477B-8D3C-1AF5E31D6EDF}" = protocol=17 | dir=in | app=c:\users\———\appdata
\local\google\google talk plugin\googletalkplugin.exe |
"{FAF422E8-2307-4D74-B0D2-5BDE6E56C82E}" = protocol=6 | dir=in | app=c:\program files
(x86)\internet explorer\iexplore.exe |
"{FB92E234-9289-4CCC-B6CE-DE48FA66B7D4}" = dir=in | app=c:\program files\hp\hp officejet pro
8600\bin\devicesetup.exe |
"TCP Query User{34EB02A4-BE6F-4BB1-926A-27B8C548A6DC}C:\program files (x86)\internet explorer
\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe
|
"TCP Query User{449B8EC9-919D-4EA3-8542-7DA6CB4FA3FD}C:\users\———\appdata\local\akamai
\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\———\appdata\local\akamai
\netsession_win.exe |
"TCP Query User{80D64307-718F-4C8C-B5F7-EA2F70AEA432}C:\program files (x86)\java\jre7\bin
\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{AD5DB7F4-0B9A-44CD-949E-5C5E9135A5BF}C:\program files (x86)\google\google earth
\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth
\plugin\geplugin.exe |
"TCP Query User{D30290B4-11CA-47A8-9FCD-AB33CD64F007}C:\windows\system32\mmc.exe" = protocol=6 |
dir=in | app=c:\windows\system32\mmc.exe |
"UDP Query User{4E3EE254-F6E9-44DC-99F0-3878DA1DE6CD}C:\windows\system32\mmc.exe" = protocol=17 |
dir=in | app=c:\windows\system32\mmc.exe |
"UDP Query User{5D0E89DB-26D3-47C0-B07E-C4B5EAA875CE}C:\users\———\appdata\local\akamai
\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\———\appdata\local\akamai
\netsession_win.exe |
"UDP Query User{AAC17B1E-E083-4C89-879B-F09D272CCA13}C:\program files (x86)\internet explorer
\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe
|
"UDP Query User{ED963E8A-FFE2-4D59-B09F-63B51917602D}C:\program files (x86)\google\google earth
\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth
\plugin\geplugin.exe |
"UDP Query User{FDA21321-1E95-4C22-9511-AA6321500290}C:\program files (x86)\java\jre7\bin
\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0279C882-B150-44B6-A769-A7C8A2F31CE3}" = HP Wireless Assistant
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86417025FF}" = Java 7 Update 25 (64-bit)
"{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}" = Intel® PROSet/Wireless WiFi Software
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{377672F0-6B8A-467D-8DDC-79338BCCD531}" = 64 Bit HP CIO Components Installer
"{427174C0-096E-40D9-9684-9C109BEE2CBF}" = iTunes
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64
9.0.30729.4148
"{5BF97E02-2F6A-412A-BB4D-B6E2DC65FCA7}" = HP SimplePass Identity Protection
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64
9.0.30729.6161
"{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}" = Cisco Systems VPN Client 5.0.07.0440
"{624C7F0A-89B2-4C49-9CAB-9D69613EC95A}" = Microsoft IntelliPoint 8.2
"{62BB6851-C373-47F7-B566-38D2E16FE2A6}" = DyKnow x64
"{64A3A4F4-B792-11D6-A78A-00B0D0170250}" = Java SE Development Kit 7 Update 25 (64-bit)
"{64A9C5B3-D166-4C6D-A11E-A54473151000}" = Java 3D 1.5.1 (x64)
"{69D65833-4A83-267A-7DB4-9FCBBE72675D}" = ATI Catalyst Install Manager
"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{704C0303-D20C-45AF-BD2B-556EAF31BE09}" = iCloud
"{731A1D36-BF17-4C76-B7E7-CC055AF8C54E}" = HP MediaSmart SmartMenu
"{791A06E2-340F-43B0-8FAB-62D151339362}" = HP Officejet Pro 8600 Basic Device Software
"{7D220A57-969F-4D09-9297-D48195A8ABDD}" = HP Deskjet 3050 J610 series Basic Device Software
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64
9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174
- x64 9.0.30729.5570
"{85A42FF0-F0D0-44A3-B226-C124D6E8B1D5}" = HP 3D DriveGuard
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI
(English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A269F383-3E55-DAFF-F948-655FDB3DB58A}" = ccc-utility64
"{A4DDB2AB-ECCD-4C3A-8633-77D5A1A0E542}" = Network64
"{CB6508F6-EC50-4829-A2C6-02990EFF0059}" = Windows Media Encoder 9 Series x64 Edition
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{E5083D57-D93F-404C-A91F-1C50D67C2BEB}" = HP Officejet 4500 G510g-m
"{EE5017A6-7525-4EE9-99DA-2EF1F6C16B1B}" = Validity Sensors DDK
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"HP Document Manager" = HP Document Manager 2.0
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2
"nbi-nb-base-[removed].0" = NetBeans IDE 7.1.2
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Windows Media Encoder 9" = Windows Media Encoder 9 Series x64 Edition
"WinRAR archiver" = WinRAR 4.20 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{024DE942-267A-4B60-A1C0-70C1163E0355}" = CCC Help Korean
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08C94F9D-EB51-D748-E299-E347A2C14A81}" = PX Profile Update
"{0A5B39D2-7ED6-4779-BCC9-37F381139DB3}" = Adobe AIR
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{15353551-375C-8E5A-5CAF-A4564C1CC2A5}" = ccc-core-static
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YTD Video Downloader 3.9
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86
9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20B88A14-02F9-48D4-ACEC-6D8F5F3E8A83}" = HP User Guides 0176
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{21E2508C-D5F4-44C6-C224-456DDA341BBB}" = CCC Help Turkish
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{28379381-B56A-43e1-B505-3098D82B1C30}" = 4500G510gm_Software_Min
"{29E70460-51CA-45A1-B76B-C2B69FE908DE}" = MediSpell for Microsoft Word
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{32D2E8C3-452A-69E9-21CF-C55E0612C974}" = CCC Help Chinese Traditional
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{394FA67A-FF0A-4356-BB77-D85E5A300BDE}" = HP QuickWeb Installer
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{4453AA9B-867A-17DB-C429-E9A64F0FB77F}" = CCC Help Finnish
"{44653096-3E44-402E-B68E-37D77240BFA8}" = Symyx Draw 4.0.0
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{46F2A322-7A34-4EEC-B7FA-62A2F3DAB44A}" = UofRMachineCheck
"{485B9C29-6B47-22AF-022A-F9D65292F3A7}" = CCC Help English
"{4893B2BB-5C9B-7E6C-4BAD-BDFBAB33184A}" = Catalyst Control Center Localization All
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4CFE23CC-779D-4572-A76F-AB60A958BC79}" = Adobe Flash Player 11 ActiveX
"{50C1A63E-4653-9DBE-E8E4-28DF2778BED0}" = CCC Help Polish
"{5725E5CA-A91D-C903-99DB-F8C010E0B637}" = Catalyst Control Center InstallProxy
"{5A89BFD5-12DB-038F-DBCE-58832B82D824}" = CCC Help Norwegian
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6C302296-6129-4125-9FD6-2188ECD8814E}" = HP Software Framework
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.1.1
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79361740-EAE3-11E2-9911-B8AC6F98CCE3}" = Google Earth Plug-in
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{81ED0B01-4DE2-CD82-F927-2E4C6208349A}" = PX Profile Update
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{85D10697-A1D4-472A-2114-E07A77019BE1}" = CCC Help Japanese
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174
- x86 9.0.30729.5570
"{87909077-445C-976C-0D23-D6C367B422D6}" = CCC Help Danish
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{8DD0171B-2ED1-311C-882E-AD3EC3A77A7E}" = CCC Help Czech
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" =
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" =
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" =
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}_SMALLBUSINESSR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" =
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" =
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}_SMALLBUSINESSR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" =
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_SMALLBUSINESSR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_SMALLBUSINESSR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English)
2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_SMALLBUSINESSR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9087C601-4B52-C0F0-D4EF-4C98DEC1D6B0}" = CCC Help Portuguese
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{91120000-00CA-0000-0000-0000000FF1CE}" = Microsoft Office Small Business 2007
"{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{91B82CC7-F33E-211B-DFD6-0A91B637B455}" = CCC Help Greek
"{925A0B4E-F885-997B-8A74-E8E7A2FAC049}" = CCC Help French
"{92A51949-EE4C-466D-AAF0-99E74A49A63F}" = DocMgr
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{96B7FD92-0D96-7C04-5D1C-D6CF70202403}" = CCC Help Hungarian
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86
9.0.30729.17
"{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}" = Sophos Anti-Virus
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86
9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A18E4E3A-5013-E319-AB36-4FDE7483AA5D}" = CCC Help Spanish
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB7D24EC-BB5A-E746-C5D2-526BBE6C36AD}" = Catalyst Control Center Graphics Previews Vista
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.7)
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{BA688606-4B20-4982-995E-EDADC6A6817E}" = League of Legends
"{BB0030F2-DA47-FABF-D3F2-903FA253D56D}" = CCC Help Thai
"{BB1C717E-376C-4AA1-8940-81BFC38D9778}" = HP Quick Launch
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{BE0D4271-69C9-4f28-AD9B-BB33D126A30E}" = 4500G510gm
"{BFBC6337-B7B9-4AEE-BC19-CA910EED755D}" = Adobe Flash Player 11 Plugin
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{CB8ABF7D-B3F7-D774-645B-0DCD0297D9FA}" = CCC Help German
"{CC7553CB-AB4E-5BCA-DC44-54D823B83E60}" = Catalyst Control Center InstallProxy
"{CD9A1574-197A-156D-9D8C-39D68AE9B7A6}" = CCC Help Russian
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver
"{D7C73761-237A-2B01-6DB5-E76276223C3B}" = CCC Help Italian
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DD082978-011E-7058-8252-15E2E1AAFABB}" = CCC Help Dutch
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DF0B357C-5874-47D0-81E7-79AA890B0CE0}" = 4500_G510gm_Help
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2831862-F131-4327-B9CC-FA30F587EB6C}" = HP Setup
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E7C97E98-4C2D-BEAF-5D2F-CC45A2F95D90}" = Acrobat.com
"{EB38C3E0-4863-3123-9114-5BE86EC8E5C7}" = Google Talk Plugin
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE202411-2C26-49E8-9784-1BC1DBF7DE96}" = HP Support Assistant
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}" = HP Deskjet 3050 J610 series Help
"{FA3B4B32-D753-672D-842C-946644FEFC0A}" = CCC Help Swedish
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FED1005D-CBC8-45D5-A288-FFC7BB304121}" = Sophos Remote Management System
"{FF6FA054-25B9-1CA2-D22A-DFD87735E9F6}" = CCC Help Chinese Standard
"Adobe AIR" = Adobe AIR
"Adobe Digital Editions 2.0" = Adobe Digital Editions 2.0
"Adobe Shockwave Player" = Adobe Shockwave Player 12.0
"Akamai" = Akamai NetSession Interface Service
"AutoHotkey" = AutoHotkey 1.0.48.05
"Carbonite Backup" = Carbonite
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{62BB6851-C373-47F7-B566-38D2E16FE2A6}" = DyKnow x64
"LastPass" = LastPass (uninstall only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable
Package
"Notepad++" = Notepad++
"Revo Uninstaller" = Revo Uninstaller 1.95
"Secunia PSI" = Secunia PSI (3.0.0.7011)
"SMALLBUSINESSR" = Microsoft Office Small Business 2007
"TrueCrypt" = TrueCrypt
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office
system 3.0 Runtime
"VLC media player" = VLC media player 2.0.8
"WinLiveSuite" = Windows Live Essentials
"YTdetect" = Yahoo! Detect
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 8/29/2013 12:12:22 PM | Computer Name = ——— | Source = VSS | ID = 8193
Description =
Error - 8/29/2013 1:21:24 PM | Computer Name = ——— | Source = Sophos Message Router | ID =
8006
Description = The network identity (also known as the Interoperable Object Reference
or IOR) of the local computer is invalid.%3
Error - 8/31/2013 12:00:53 AM | Computer Name = ——— | Source = Sophos Message Router | ID =
8006
Description = The network identity (also known as the Interoperable Object Reference
or IOR) of the local computer is invalid.%3
Error - 8/31/2013 12:11:25 AM | Computer Name = ——— | Source = VSS | ID = 8193
Description =
Error - 8/31/2013 12:19:27 AM | Computer Name = ——— | Source = Microsoft-Windows-
RestartManager | ID = 10006
Description = Application or service 'Google Chrome' could not be shut down.
Error - 8/31/2013 1:43:15 PM | Computer Name = ——— | Source = Application Error | ID = 1000
Description = Faulting application name: SearchProtocolHost.exe, version: 7.0.7601.17610,
time stamp: 0x4dc0d006 Faulting module name: ntdll.dll, version: 6.1.7601.18205,
time stamp: 0x51dba4e7 Exception code: 0xc0000005 Fault offset: 0x0000000000021cfa
Faulting
process id: 0x2558 Faulting application start time: 0x01cea6717f75eace Faulting application
path: C:\Windows\system32\SearchProtocolHost.exe Faulting module path: C:\Windows
\SYSTEM32\ntdll.dll
Report
Id: cfe9ecbb-1264-11e3-87bb-c80aa9a0041a
Error - 8/31/2013 3:42:05 PM | Computer Name = ——– | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 8/31/2013 3:42:06 PM | Computer Name = ——– | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1030
Error - 8/31/2013 3:42:06 PM | Computer Name = ——– | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1030
Error - 8/31/2013 7:15:33 PM | Computer Name = ——– | Source = VSS | ID = 8193
Description =
[ Hewlett-Packard Events ]
Error - 7/5/2012 9:14:16 PM | Computer Name = ——– | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at
HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3893 Ram Utilization: TargetSite: Void UpdateAndDetect()
Error - 7/5/2012 9:15:34 PM | Computer Name = ——– | Source = HPSF.exe | ID = 4000
Description =
Error - 7/5/2012 9:15:58 PM | Computer Name = ——– | Source = HPSF.exe | ID = 4000
Description =
Error - 7/5/2012 9:16:23 PM | Computer Name = ——– | Source = HPSF.exe | ID = 4000
Description =
Error - 7/12/2012 9:33:35 PM | Computer Name = ——– | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at
HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3893 Ram Utilization: 70 TargetSite: Void UpdateAndDetect()
Error - 7/19/2012 9:11:55 PM | Computer Name = ——– | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at
HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3893 Ram Utilization: 70 TargetSite: Void UpdateAndDetect()
Error - 7/26/2012 9:41:46 PM | Computer Name = ——– | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at
HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3893 Ram Utilization: 60 TargetSite: Void UpdateAndDetect()
Error - 8/2/2012 9:18:59 PM | Computer Name = ——– | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at
HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3893 Ram Utilization: 70 TargetSite: Void UpdateAndDetect()
Error - 8/9/2012 10:52:15 PM | Computer Name = ——– | Source = HPSF.exe | ID = 4000
Description =
Error - 8/9/2012 10:52:33 PM | Computer Name = ——– | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at
HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3893 Ram Utilization: 80 TargetSite: Void UpdateAndDetect()
[ HP Wireless Assistant Events ]
Error - 8/29/2013 12:11:53 PM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = System.Exception GetDeviceInfo() failed : 597 at
HP_Common.CaslWrapper.GetDeviceInfo(List`1&
radioList) at HPPA_Service.CurrentConfiguration.ReloadRadioList()
Error - 8/29/2013 12:12:02 PM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = System.Exception GetDeviceInfo() failed : 597 at
HP_Common.CaslWrapper.GetDeviceInfo(List`1&
radioList) at HPPA_Service.CurrentConfiguration.ReloadRadioList()
Error - 8/29/2013 12:12:05 PM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = System.Exception GetDeviceInfo() failed : 597 at
HP_Common.CaslWrapper.GetDeviceInfo(List`1&
radioList) at HPPA_Service.CurrentConfiguration.ReloadRadioList()
Error - 8/29/2013 12:12:16 PM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The interface is unknown.
(Exception from HRESULT: 0x800706B5) at
System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at
System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at
System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 8/29/2013 1:20:25 PM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = GetPanelBrightnessTables() failed : e_BIOS_INVALID_COMMAND_TYPE
Error - 8/31/2013 12:03:32 AM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = GetPanelBrightnessTables() failed : e_BIOS_INVALID_COMMAND_TYPE
Error - 8/31/2013 5:26:14 AM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = GetPanelBrightnessTables() failed : e_BIOS_INVALID_COMMAND_TYPE
Error - 8/31/2013 5:26:14 AM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = Unable to access panel brightness tables.
Error - 8/31/2013 11:08:22 AM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = GetPanelBrightnessTables() failed : e_BIOS_INVALID_COMMAND_TYPE
Error - 8/31/2013 11:08:22 AM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = Unable to access panel brightness tables.
[ OSession Events ]
Error - 7/28/2011 9:36:29 PM | Computer Name = ———-PC | Source = Microsoft Office 12
Sessions
| ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6557.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 24659
seconds with 60 seconds of active time. This session ended with a crash.
Error - 8/23/2011 8:55:30 PM | Computer Name = ———-PC | Source = Microsoft Office 12
Sessions
| ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 1572
seconds with 60 seconds of active time. This session ended with a crash.
Error - 9/4/2012 9:27:01 PM | Computer Name = ——– | Source = Microsoft Office 12 Sessions |
ID
= 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2527
seconds with 240 seconds of active time. This session ended with a crash.
Error - 9/11/2012 11:08:42 PM | Computer Name = ——– | Source = Microsoft Office 12 Sessions
|
ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 8287
seconds with 240 seconds of active time. This session ended with a crash.
Error - 10/19/2012 5:48:00 PM | Computer Name = ——– | Source = Microsoft Office 12 Sessions
|
ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 154823
seconds with 0 seconds of active time. This session ended with a crash.
Error - 11/12/2012 12:32:38 AM | Computer Name = ——— | Source = Microsoft Office 12
Sessions |
ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 557
seconds with 420 seconds of active time. This session ended with a crash.
Error - 11/12/2012 12:39:14 AM | Computer Name = ——— | Source = Microsoft Office 12
Sessions |
ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 383
seconds with 60 seconds of active time. This session ended with a crash.
Error - 2/27/2013 11:20:44 AM | Computer Name = ——— | Source = Microsoft Office 12 Sessions
|
ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 90280
seconds with 5400 seconds of active time. This session ended with a crash.
Error - 4/1/2013 1:47:06 PM | Computer Name = ——— | Source = Microsoft Office 12 Sessions |
ID
= 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 79313
seconds with 3660 seconds of active time. This session ended with a crash.
Error - 4/3/2013 10:33:33 PM | Computer Name = ——— | Source = Microsoft Office 12 Sessions
|
ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session
lasted 703 seconds with 600 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 8/30/2013 10:18:48 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:18:48 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:23:02 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:23:02 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:23:02 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:23:48 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:23:48 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:23:48 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/31/2013 12:02:30 AM | Computer Name = ——— | Source = DCOM | ID = 10016
Description =
Error - 8/31/2013 5:33:46 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7031
Description = The Sophos Message Router service terminated unexpectedly. It has
done this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.
< End of report >
I downloaded and ran scans with HijackThis and OTL. Their log files are included bellow.
I'd appreciate any help that can be given!
HijackThis:
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 2:01:22 PM, on 8/31/2013
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v10.0 (10.00.9200.16660)
CHROME: 29.0.1547.62
Boot mode: Normal
Running processes:
C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe
C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe
C:\Users\———\AppData\Local\Akamai\netsession_win.exe
C:\Users\———\AppData\Local\Akamai\netsession_win.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe
C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe
C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
C:\Program Files (x86)\Hp\HP Software Update\hpwuschd2.exe
C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
C:\Program Files\TrueCrypt\TrueCrypt.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\———\Downloads\HijackThis.exe
C:\Users\———\AppData\Local\Google\Chrome\Application\chrome.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL =
http://go.microsoft.com/fwlink/p/?LinkId=255141
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page =
http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page =
http://go.microsoft.com/fwlink/p/?LinkId=255141
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
*.local;127.0.0.1:9421;
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: HP Print Enhancer - {0347C33E-8762-4905-BF09-768834316C61} - C:\Program Files (x86)\HP
\Digital Imaging\Smart Web Printing\hpswp_printenhancer.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files
(x86)\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program
Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program
Files (x86)\Java\jre7\bin\jp2ssv.dll
O2 - BHO: HP Network Check Helper - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files
(x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
O2 - BHO: HP Smart BHO Class - {FFFFFFFF-CF4E-4F2B-BDC2-0E72E116A856} - C:\Program Files
(x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O3 - Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - (no file)
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\almon.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Carbonite Backup] C:\Program Files (x86)\Carbonite\Carbonite Backup
\CarboniteUI.exe
O4 - HKCU\..\Run: [ISUSPM] "C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe" -scheduler
O4 - HKCU\..\Run: [Akamai NetSession Interface] "C:\Users\———\AppData\Local\Akamai
\netsession_win.exe"
O4 - HKCU\..\Run: [Google Update] "C:\Users\———\AppData\Local\Google\Update
\GoogleUpdate.exe"
/c
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User
'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User
'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK
SERVICE')
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:
\PROGRA~2\MICROS~4\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no file)
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - (no
file)
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-
1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer
\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer
\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files
(x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files
(x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra 'Tools' menuitem: SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program
Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe
O9 - Extra button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources
\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:
\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck
\NCLauncherFromIE.exe
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework
\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08}
- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck
\NCLauncherFromIE.exe
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:
\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end; to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:
\PROGRA~2\MICROS~4\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:
\PROGRA~2\MICROS~4\Office12\REFIEBAR.DLL
O9 - Extra button: Show or hide HP Smart Web Printing - {DDE87865-83C5-48c4-8357-2F5B1AA84522} -
C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\hpswp_BHO.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows
live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows
live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O10 - Unknown file in Winsock LSP: c:\programdata\sophos\web intelligence\swi_ifslsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) -
http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) -
http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} -
http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968} -
http://upload.facebook.com/controls/2009.0…oUploader55.cab
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429} -
http://www.sibelius.com/download/software/…tiveXPlugin.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) -
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} -
http://www.popcap.com/webgames/popcaploader_v10.cab
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} -
http://utilities.pcpitstop.com/da2/PCPitStop2.cab
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows
Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O20 - AppInit_DLLs: C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:
\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems
Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: Andrea ST Filters Service (AESTFilters) - Andrea Electronics Corporation - C:
\Program Files\IDT\WDM\AESTSr64.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows
\System32\alg.exe (file missing)
O23 - Service: AMD External Events Utility - Unknown owner - C:\Windows\system32\atiesrxx.exe
(file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple
\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: CarboniteService - Carbonite, Inc. (www.carbonite.com) - C:\Program Files
\Carbonite\Carbonite Backup\carboniteservice.exe
O23 - Service: Cron Service for Prey (CronService) - Fork Ltd. - C:\Users\———\Vulture
\platform\windows\cronsvc.exe
O23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files
(x86)\Cisco Systems\VPN Client\cvpnd.exe
O23 - Service: @C:\Program Files\DigitalPersona\Bin\DpHostW.exe,-128 (DpHost) - DigitalPersona,
Inc. - C:\Program Files\DigitalPersona\Bin\DpHostW.exe
O23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\SwSetup
\QuickWeb\QW.SYS\config\DVMExportService.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows
\System32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Event Log (EvtEng) - Intel® Corporation - C:\Program
Files\Intel\WiFi\bin\EvtEng.exe
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows
\system32\fxssvc.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files
(x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files
(x86)\Google\Update\GoogleUpdate.exe
O23 - Service: HP Support Assistant Service - Hewlett-Packard Company - C:\Program Files
(x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
O23 - Service: HP Wireless Assistant Service - Hewlett-Packard - C:\Program Files\Hewlett-
Packard\HP Wireless Assistant\HPWA_Service.exe
O23 - Service: HP Software Framework Service (hpqwmiex) - Hewlett-Packard Company - C:\Program
Files (x86)\Hewlett-Packard\Shared\hpqWmiEx.exe
O23 - Service: HP Service (hpsrv) - Unknown owner - C:\Windows\system32\Hpservice.exe (file
missing)
O23 - Service: HPWMISVC - Hewlett-Packard Development Company, L.P. - C:\Program Files
(x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file
missing)
O23 - Service: Intel® Management and Security Application Local Management Service (LMS) -
Intel Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS
\LMS.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file
missing)
O23 - Service: Wireless PAN DHCP Server (MyWiFiDHCPDNS) - Unknown owner - C:\Program Files\Intel
\WiFi\bin\PanDhcpDns.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows
\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:
\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel® PROSet/Wireless Registry Service (RegSrvc) - Intel® Corporation - C:
\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows
\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows
\system32\lsass.exe (file missing)
O23 - Service: Sophos Anti-Virus status reporter (SAVAdminService) - Sophos Limited - C:\Program
Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
O23 - Service: Sophos Anti-Virus (SAVService) - Sophos Limited - C:\Program Files (x86)\Sophos
\Sophos Anti-Virus\SavService.exe
O23 - Service: Secunia PSI Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\PSIA.exe
O23 - Service: Secunia Update Agent - Secunia - C:\Program Files (x86)\Secunia\PSI\sua.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows
\System32\snmptrap.exe (file missing)
O23 - Service: Sophos Agent - Sophos Limited - C:\Program Files (x86)\Sophos\Remote Management
System\ManagementAgentNT.exe
O23 - Service: Sophos AutoUpdate Service - Sophos Limited - C:\Program Files (x86)\Sophos
\AutoUpdate\ALsvc.exe
O23 - Service: Sophos Message Router - Sophos Limited - C:\Program Files (x86)\Sophos\Remote
Management System\RouterNT.exe
O23 - Service: Sophos Web Control Service - Sophos Limited - C:\Program Files (x86)\Sophos\Sophos
Anti-Virus\Web Control\swc_service.exe
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows
\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows
\system32\sppsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\stlang64.dll,-10101 (STacSV) - IDT, Inc. - C:\Program
Files\IDT\WDM\STacSV64.exe
O23 - Service: Sophos Web Intelligence Service (swi_service) - Sophos Limited - C:\Program Files
(x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe
O23 - Service: Sophos Web Intelligence Update (swi_update_64) - Sophos Limited - C:\ProgramData
\Sophos\Web Intelligence\swi_update_64.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:
\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel® Management & Security Application User Notification Service (UNS) - Intel
Corporation - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows
\system32\lsass.exe (file missing)
O23 - Service: Validity VCS Fingerprint Service (vcsFPService) - Validity Sensors, Inc. - C:
\Windows\system32\vcsFPService.exe
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows
\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows
\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:
\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows
\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:
\Windows\system32\wbem\WmiApSrv.exe (file missing)
–
End of file - 17670 bytes
********************************************************************************
*******
OTL.txt:
OTL logfile created on: 8/31/2013 7:13:26 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\———\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.80 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 39.01% Memory free
7.60 Gb Paging File | 4.71 Gb Available in Paging File | 62.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 276.46 Gb Total Space | 142.57 Gb Free Space | 51.57% Space Free | Partition Type:
NTFS
Drive D: | 21.33 Gb Total Space | 3.10 Gb Free Space | 14.53% Space Free | Partition Type: NTFS
Drive E: | 99.34 Mb Total Space | 84.17 Mb Free Space | 84.74% Space Free | Partition Type: FAT32
Drive T: | 49.98 Gb Total Space | 46.89 Gb Free Space | 93.82% Space Free | Partition Type: FAT32
Computer Name: ——– | User Name: ——— | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File
Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\———\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files (x86)\Carbonite\Carbonite Backup\CarboniteUI.exe (Carbonite, Inc.)
PRC - C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
PRC - C:\Users\———\AppData\Local\Akamai\netsession_win.exe (Akamai Technologies, Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Users\———\Vulture\platform\windows\cronsvc.exe (Fork Ltd.)
PRC - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple
Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\iCloudServices.exe (Apple Inc.)
PRC - C:\Program Files (x86)\Common Files\Apple\Internet Services\ApplePhotoStreams.exe (Apple
Inc.)
PRC - C:\Program Files\TrueCrypt\TrueCrypt.exe (TrueCrypt Foundation)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence\swi_service.exe (Sophos
Limited)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Remote Management System\RouterNT.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Remote Management System\ManagementAgentNT.exe (Sophos
Limited)
PRC - C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Sophos Limited)
PRC - C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Control\swc_service.exe (Sophos
Limited)
PRC - C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe (Hewlett-Packard
Development Company, L.P.)
PRC - C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
PRC - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.EXE (Intel
Corporation)
PRC - C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe (DeviceVM, Inc.)
PRC - C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe (Intel
Corporation)
PRC - C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Acresso Corporation)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
========== Services (SafeList) ==========
SRV:64bit: - (CarboniteService) – C:\Program Files\Carbonite\Carbonite Backup
\CarboniteService.exe (Carbonite, Inc. (www.carbonite.com))
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft
Corporation)
SRV:64bit: - (RemSrvs) – C:\Program Files\DyKnow\Client\DyKnow.Host.dll (Dynamic
Knowledge Transfer, LLC.)
SRV:64bit: - (hpsrv) – C:\Windows\SysNative\hpservice.exe (Hewlett-Packard Company)
SRV:64bit: - (EvtEng) – C:\Program Files\Intel\WiFi\bin\EvtEng.exe (Intel® Corporation)
SRV:64bit: - (MyWiFiDHCPDNS) – C:\Program Files\Intel\WiFi\bin\PanDhcpDns.exe ()
SRV:64bit: - (RegSrvc) – C:\Program Files\Common Files\Intel\WirelessCommon\RegSrvc.exe
(Intel® Corporation)
SRV:64bit: - (STacSV) – C:\Program Files\IDT\WDM\stacsv64.exe (IDT, Inc.)
SRV:64bit: - (AESTFilters) – C:\Program Files\IDT\WDM\AESTSr64.exe (Andrea Electronics
Corporation)
SRV:64bit: - (DpHost) – C:\Program Files\DigitalPersona\Bin\DpHostW.exe (DigitalPersona,
Inc.)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (vcsFPService) – C:\Windows\SysNative\vcsFPService.exe (Validity Sensors,
Inc.)
SRV:64bit: - (HP Wireless Assistant Service) – C:\Program Files\Hewlett-Packard\HP
Wireless Assistant\HPWA_Service.exe (Hewlett-Packard)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash
\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Secunia PSI Agent) – C:\Program Files (x86)\Secunia\PSI\psia.exe (Secunia)
SRV - (Secunia Update Agent) – C:\Program Files (x86)\Secunia\PSI\sua.exe (Secunia)
SRV - (Akamai) – c:\program files (x86)\common files\akamai/netsession_win_8fa3539.dll ()
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe
Systems Incorporated)
SRV - (CronService) – C:\Users\———\Vulture\platform\windows\cronsvc.exe (Fork Ltd.)
SRV - (swi_service) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web Intelligence
\swi_service.exe (Sophos Limited)
SRV - (SAVAdminService) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SAVAdminService.exe
(Sophos Limited)
SRV - (swi_update_64) – C:\ProgramData\Sophos\Web Intelligence\swi_update_64.exe (Sophos
Limited)
SRV - (HP Support Assistant Service) – C:\Program Files (x86)\Hewlett-Packard\HP Support
Framework\HPSA_Service.exe (Hewlett-Packard Company)
SRV - (Sophos Message Router) – C:\Program Files (x86)\Sophos\Remote Management System
\RouterNT.exe (Sophos Limited)
SRV - (Sophos Agent) – C:\Program Files (x86)\Sophos\Remote Management System
\ManagementAgentNT.exe (Sophos Limited)
SRV - (Sophos AutoUpdate Service) – C:\Program Files (x86)\Sophos\AutoUpdate\ALsvc.exe (Sophos
Limited)
SRV - (SAVService) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\SavService.exe (Sophos
Limited)
SRV - (Sophos Web Control Service) – C:\Program Files (x86)\Sophos\Sophos Anti-Virus\Web
Control\swc_service.exe (Sophos Limited)
SRV - (HPWMISVC) – C:\Program Files (x86)\Hewlett-Packard\HP Quick Launch\HPWMISVC.exe
(Hewlett-Packard Development Company, L.P.)
SRV - (CVPND) – C:\Program Files (x86)\Cisco Systems\VPN Client\cvpnd.exe (Cisco Systems, Inc.)
SRV - (HPSLPSVC) – C:\Program Files (x86)\Hp\Digital Imaging\bin\HPSLPSVC64.DLL (Hewlett-Packard
Co.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework
\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (UNS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.EXE
(Intel Corporation)
SRV - (DvmMDES) – C:\SwSetup\QuickWeb\QW.SYS\config\DVMExportService.exe (DeviceVM, Inc.)
SRV - (vcsFPService) – C:\Windows\SysWOW64\vcsFPService.exe (Validity Sensors, Inc.)
SRV - (LMS) – C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
(Intel Corporation)
SRV - (PCPitstop Scheduling) – C:\Program Files (x86)\PCPitstop\PCPitstopScheduleService.exe (PC
Pitstop LLC)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework
\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
========== Driver Services (SafeList) ==========
DRV:64bit: - (PSI) – C:\Windows\SysNative\drivers\psi_mf_amd64.sys (Secunia)
DRV:64bit: - (usb_rndisx) – C:\Windows\SysNative\drivers\usb8023x.sys (Microsoft
Corporation)
DRV:64bit: - (truecrypt) – C:\Windows\SysNative\drivers\truecrypt.sys (TrueCrypt
Foundation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (sdcfilter) – C:\Windows\SysNative\drivers\sdcfilter.sys (Sophos Limited)
DRV:64bit: - (SAVOnAccess) – C:\Windows\SysNative\drivers\savonaccess.sys (Sophos
Limited)
DRV:64bit: - (SophosBootDriver) – C:\Windows\SysNative\drivers\SophosBootDriver.sys
(Sophos Plc)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\drivers\rdpvideominiport.sys
(Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft
Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software
Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (SynTP) – C:\Windows\SysNative\drivers\SynTP.sys (Synaptics Incorporated)
DRV:64bit: - (TIEHDUSB) – C:\Windows\SysNative\drivers\tiehdusb.sys (Texas Instruments)
DRV:64bit: - (Point64) – C:\Windows\SysNative\drivers\point64.sys (Microsoft Corporation)
DRV:64bit: - (NETwNs64) – C:\Windows\SysNative\drivers\NETwNs64.sys (Intel Corporation)
DRV:64bit: - (RTL8167) – C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek
)
DRV:64bit: - (hpdskflt) – C:\Windows\SysNative\drivers\hpdskflt.sys (Hewlett-Packard
Company)
DRV:64bit: - (Accelerometer) – C:\Windows\SysNative\drivers\Accelerometer.sys (Hewlett-
Packard Company)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro
Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro
Devices)
DRV:64bit: - (CVPNDRVA) – C:\Windows\SysNative\drivers\CVPNDRVA.sys ()
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (STHDA) – C:\Windows\SysNative\drivers\stwrt64.sys (IDT, Inc.)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\drivers\atikmdag.sys (ATI Technologies
Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro
Devices, Inc.)
DRV:64bit: - (intelkmd) – C:\Windows\SysNative\drivers\igdpmd64.sys (Intel Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (AtiHdmiService) – C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI
Technologies, Inc.)
DRV:64bit: - (NETw5s64) – C:\Windows\SysNative\drivers\NETw5s64.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (CVirtA) – C:\Windows\SysNative\drivers\CVirtA64.sys (Cisco Systems, Inc.)
DRV:64bit: - (DVMIO) – C:\Windows\SysNative\drivers\dvmio.sys (DeviceVM, Inc.)
DRV:64bit: - (RSUSBSTOR) – C:\Windows\SysNative\drivers\RtsUStor.sys (Realtek
Semiconductor Corp.)
DRV:64bit: - (Impcd) – C:\Windows\SysNative\drivers\Impcd.sys (Intel Corporation)
DRV:64bit: - (HECIx64) – C:\Windows\SysNative\drivers\HECIx64.sys (Intel Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\drivers\WSDPrint.sys (Microsoft
Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\drivers\serscan.sys (Microsoft
Corporation)
DRV:64bit: - (SrvHsfV92) – C:\Windows\SysNative\drivers\VSTDPV6.SYS (Conexant Systems,
Inc.)
DRV:64bit: - (SrvHsfWinac) – C:\Windows\SysNative\drivers\VSTCNXT6.SYS (Conexant Systems,
Inc.)
DRV:64bit: - (SrvHsfHDA) – C:\Windows\SysNative\drivers\VSTAZL6.SYS (Conexant Systems,
Inc.)
DRV:64bit: - (yukonw7) – C:\Windows\SysNative\drivers\yk62x64.sys (Marvell)
DRV:64bit: - (netw5v64) – C:\Windows\SysNative\drivers\netw5v64.sys (Intel Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) – C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom
Corporation)
DRV:64bit: - (hcw85cir) – C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer
Works, Inc.)
DRV:64bit: - (DNE) – C:\Windows\SysNative\drivers\dne64x.sys (Deterministic Networks,
Inc.)
DRV - (WIMMount) – C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
IE:64bit: - HKLM\..\SearchScopes\{B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}: "URL" =
http://searchfunmoods.com/results.php?f=4&…q={searchTerms}
&a;=download&chnl;=download&cd;=2XzuyEtN2Y1L1Qzu0CzztD0A0Azy0AtDtDyEtC0AyD0ByDtAtN0D0Tzu0CtAtCyBtN1L
2XzutBtFtBtFtDtFtAyEyE&cr;=808477447
IE - HKLM\..\SearchScopes,DefaultScope = {B7971660-A1CE-4FDD-B9E0-2C37D77AFB0B}
IE - HKLM\..\SearchScopes\{5727EF33-8B6C-4E3B-B7CD-49B42D733B4C}: "URL" =
http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
IE - HKLM\..\SearchScopes\{EDCBA892-30A1-4472-8BB9-10D7A040DEEE}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPNOT/1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {9D91E43C-A476-4522-A40B-71554B06C164}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" =
http://www.bing.com/search?q={searchTerms}…amp;FORM=IE10SR
IE - HKCU\..\SearchScopes\{5727EF33-8B6C-4E3B-B7CD-49B42D733B4C}: "URL" =
http://www.ask.com/web?q={searchterms}&l;=dis&o;=ushpl
IE - HKCU\..\SearchScopes\{5AD59AA0-946D-4BD0-BC6E-09282E228D38}: "URL" =
http://search.avg.com/route/?d=4e163206&am;…;lng={language}
&iy;=&ychte;=us
IE - HKCU\..\SearchScopes\{8540A13E-3E6B-49FA-881E-F4DF4E8F4281}: "URL" =
http://us.yhs4.search.yahoo.com/yhs/search?hsimp=yhs-
affiliate_a&hspart;=greentree&type;=937811_yhs2tst&p;={searchTerms}
IE - HKCU\..\SearchScopes\{9D91E43C-A476-4522-A40B-71554B06C164}: "URL" =
http://www.google.com/search?q={searchTerm…oft:{language}:
{referrer:source}&ie;={inputEncoding?}&oe;={outputEncoding?}
IE - HKCU\..\SearchScopes\{EDCBA892-30A1-4472-8BB9-10D7A040DEEE}: "URL" =
http://www.bing.com/search?q={searchTerms}…rc=IE-SearchBox
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" =
*.local;127.0.0.1:9421;
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows
\system32\Macromed\Flash\NPSWF64_11_8_800_94.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows
\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program
Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program
Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash
\NPSWF32_11_8_800_94.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\SysWOW64\Adobe\Director
\np32dsw_1203133.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes
\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google
\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows
\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files
(x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files
(x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files
(x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files
(x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando
Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files
(x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files
(x86)\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files
(x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader
\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\———\AppData
\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\———\AppData\Roaming
\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\———\AppData\Roaming
\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\———
\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\———
\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
[2013/03/23 19:58:25 | 000,000,000 | —D | M] (No name found) – C:\Users\———\AppData
\Roaming\Mozilla\Extensions
[2013/03/23 19:58:25 | 000,000,000 | —D | M] (No name found) – C:\Users\———\AppData
\Roaming\Mozilla\Extensions\[removed]
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}
{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFiel
dtrialParameter}
{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}
{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?
{google:searchFieldtrialParameter}client={google:suggestClient}&q;={searchTerms}&
{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyParamet
er},
CHR - homepage: http://www.drudgereport.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\———\AppData\Local\Google\Chrome
\Application\21.0.1180.79\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\———\AppData\Local\Google\Chrome
\Application\29.0.1547.62\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash
\NPSWF32_11_3_300_271.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\———\AppData\Local\Google\Chrome
\Application
\29.0.1547.62\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\———\AppData\Local\Google\Chrome
\Application\29.0.1547.62\pdf.dll
CHR - plugin: NPLastPass (Enabled) = C:\Users\———\AppData\Local\Google\Chrome\User Data
\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\2.0.1_0\nplastpass.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser
\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins
\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\———\AppData\Roaming\Mozilla\plugins
\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\———\AppData\Roaming
\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin
\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update
\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U5 (Enabled) = C:\Program Files (x86)\Java\jre7\bin
\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.5 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live
\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla
Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\SysWOW64\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight
\5.1.10411.0\npctrl.dll
CHR - Extension: Google Drive = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Adblock Plus = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.5.4_0\
CHR - Extension: Google Search = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: Turkopticon = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\dgefbojfgdddnignhmfmnencgiloojpe\3.32_0\
CHR - Extension: IBA Opt-out (by Google) = C:\Users\———\AppData\Local\Google\Chrome\User
Data
\Default\Extensions\gbiekjoijknlhijdjbaadobpkdhmoebb\1.5_0\
CHR - Extension: LastPass = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\hdokiejnpimakedhajhdlcegeplioahd\2.5.5_0\
CHR - Extension: WeatherBug = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\ihdkejbciahopmbagpnjmmkkdpfpaaak\2.0.6_0\
CHR - Extension: Reddit Enhancement Suite = C:\Users\———\AppData\Local\Google\Chrome\User
Data\Default\Extensions\kbmfpngjjgdllneeigpgjifpgocmfgmb\4.3.0.1_0\
CHR - Extension: Google Dictionary (by Google) = C:\Users\———\AppData\Local\Google\Chrome
\User
Data\Default\Extensions\mgijmajocgfcbeboacabfgobmjgjcoja\3.0.19_0\
CHR - Extension: Google Mail Checker = C:\Users\———\AppData\Local\Google\Chrome\User Data
\Default\Extensions\mihcahmgecmbnbcchbopgniflfhgnkff\4.4.0_0\
CHR - Extension: Ghostery = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\mlomiejdfkolichcflejclcbmpeaniij\4.1.2_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\———\AppData\Local\Google\Chrome
\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Personal Blocklist (by Google) = C:\Users\———\AppData\Local\Google\Chrome
\User Data\Default\Extensions\nolijncfnkgaikbjbdaogikpmpbdcdef\2.4.1_0\
CHR - Extension: Google Quick Scroll = C:\Users\———\AppData\Local\Google\Chrome\User Data
\Default\Extensions\okanipcmceoeemlbjnmnbdibhgpbllgc\2.1.2_0\
CHR - Extension: YTshowRating = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\olohkebleofongajeodnhideeiapohgi\1.0.7_0\
CHR - Extension: Google Calendar Checker (by Google) = C:\Users\———\AppData\Local\Google
\Chrome\User Data\Default\Extensions\ookhcbgokankfmjafalglpofmolfopek\1.4.0_0\
CHR - Extension: Gmail = C:\Users\———\AppData\Local\Google\Chrome\User Data\Default
\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2009/06/10 17:00:26 | 000,000,824 | —- | M]) - C:\Windows\SysNative\drivers
\etc\hosts
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} -
C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9}
- C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program
Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program
Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files
(x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll
(Hewlett-Packard)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID
value found.
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [HPWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless
Assistant\DelayedAppStarter.exe ()
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe
(Microsoft Corporation)
O4:64bit: - HKLM..\Run: [IntelWireless] C:\Program Files\Common Files\Intel
\WirelessCommon\iFrmewrk.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel
Corporation)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [Carbonite Backup] C:\Program Files (x86)\Carbonite\Carbonite Backup
\CarboniteUI.exe (Carbonite, Inc.)
O4 - HKLM..\Run: [Sophos AutoUpdate Monitor] C:\Program Files (x86)\Sophos\AutoUpdate\ALMon.exe
(Sophos Limited)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static
\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Akamai NetSession Interface] C:\Users\———\AppData\Local\Akamai
\netsession_win.exe (Akamai Technologies, Inc.)
O4 - HKCU..\Run: [ISUSPM] C:\ProgramData\Macrovision\FLEXnet Connect\6\ISUSPM.exe (Acresso
Corporation)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowLegacyWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: AllowUnhashedWebView = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin =
5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser =
3
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System:
DontDisplayLogonHoursWarnings = 1
O9 - Extra 'Tools' menuitem : Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Reg
Error: Key error. File not found
O9 - Extra Button: HP Smart Print - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program Files
(x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : SmartPrint - {22CC3EBD-C286-43aa-B8E6-06B115F74162} - C:\Program
Files (x86)\Hewlett-Packard\SmartPrint\smartprintsetup.exe (Hewlett-Packard)
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources
\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:
\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck
\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework
\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08}
- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck
\NCLauncherFromIE.exe (Hewlett-Packard)
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files
\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000019 - C:\ProgramData\Sophos\Web
Intelligence\swi_ifslsp_64.dll (Sophos Limited)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour
\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\ProgramData\Sophos\Web Intelligence
\swi_ifslsp.dll (Sophos Limited)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15:64bit: - ..Trusted Domains: localhost ([]http in Local intranet)
O15 - HKCU\..Trusted Domains: localhost ([]* in Local intranet)
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE}
http://security.symantec.com/sscv6/SharedC…bin/AvSniff.cab (Symantec AntiVirus scanner)
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5}
http://security.symantec.com/sscv6/SharedC…n/bin/cabsa.cab (Symantec RuFSI Utility
Class)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203}
http://h20270.www2.hp.com/ediags/gmn2/inst…tDetection2.cab (Reg Error: Key error.)
O16 - DPF: {8100D56A-5661-482C-BEE8-AFECE305D968}
http://upload.facebook.com/controls/2009.0…oUploader55.cab (Reg Error:
Key error.)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_21-windows-i586.cab (Java Plug-in 10.25.2)
O16 - DPF: {A8F2B9BD-A6A0-486A-9744-18920D898429}
http://www.sibelius.com/download/software/…tiveXPlugin.cab (Reg Error: Key error.)
O16 - DPF: {CAFEEFAC-0017-0000-0007-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_07-windows-i586.cab (Java Plug-in 1.7.0_07)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_09-windows-i586.cab (Java Plug-in 1.7.0_09)
O16 - DPF: {CAFEEFAC-0017-0000-0011-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_11-windows-i586.cab (Java Plug-in 1.7.0_11)
O16 - DPF: {CAFEEFAC-0017-0000-0013-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_13-windows-i586.cab (Java Plug-in 1.7.0_13)
O16 - DPF: {CAFEEFAC-0017-0000-0015-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_15-windows-i586.cab (Java Plug-in 1.7.0_15)
O16 - DPF: {CAFEEFAC-0017-0000-0021-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_21-windows-i586.cab (Java Plug-in 1.7.0_21)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-
1_7_0_21-windows-i586.cab (Java Plug-in 10.25.2)
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000}
http://fpdownload2.macromedia.com/get/shoc…ash/swflash.cab (Shockwave Flash Object)
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A}
http://www.popcap.com/webgames/popcaploader_v10.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7}
http://utilities.pcpitstop.com/da2/PCPitStop2.cab (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{0B14EA22-C398-4A6A-B131-
129AC47535B8}: DhcpNameServer = [removed] [removed]
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B3B58DAF-9BE7-4C03-8FB6-
E721D3E3937F}: DhcpNameServer = 192.168.42.129
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~2.DLL) - C:\Program Files
(x86)\Sophos\Sophos Anti-Virus\sophos_detoured_x64.dll (Sophos Limited)
O20 - AppInit_DLLs: (C:\PROGRA~2\Sophos\SOPHOS~1\SOPHOS~1.DLL) - C:\Program Files (x86)\Sophos
\Sophos Anti-Virus\sophos_detoured.dll (Sophos Limited)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft
Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows
\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Program Files (x86)\DigitalPersona\Bin
\DPAgent.exe) - C:\Program Files (x86)\DigitalPersona\Bin\DPAgent.exe (DigitalPersona, Inc.)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft
Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows
\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative
\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value
found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2012/04/01 22:42:26 | 000,001,352 | —- | M] () - T:\AutoHotkey.ahk – [
FAT32 ]
O33 - MountPoints2\{16f65932-de1f-11df-bb53-a2154b190de2}\Shell - "" = AutoRun
O33 - MountPoints2\{16f65932-de1f-11df-bb53-a2154b190de2}\Shell\AutoRun\command - "" = G:
\SISetup.exe
O33 - MountPoints2\{52d07493-7dae-11e1-a03c-c80aa9a0041a}\Shell - "" = AutoRun
O33 - MountPoints2\{52d07493-7dae-11e1-a03c-c80aa9a0041a}\Shell\AutoRun\command - "" = C:
\Windows\system32\RunDLL32.EXE Shell32.DLL,ShellExec_RunDLL G:\TL-Bootstrap.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut
Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWOW64\l3codeca.acm (Fraunhofer Institut Integrierte
Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/08/26 16:26:45 | 000,000,000 | —D | C] – C:\Users\———\AppData\Roaming\vlc
[2013/08/21 20:21:50 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu
\Programs\iTunes
[2013/08/21 20:21:17 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/08/21 20:21:17 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013/08/21 20:21:17 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/08/18 18:41:51 | 003,913,664 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\ntoskrnl.exe
[2013/08/18 18:41:50 | 005,550,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\ntoskrnl.exe
[2013/08/18 18:41:50 | 003,968,960 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\ntkrnlpa.exe
[2013/08/18 18:41:50 | 001,732,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\ntdll.dll
[2013/08/18 18:41:49 | 000,243,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\wow64.dll
[2013/08/18 18:41:49 | 000,025,600 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\setup16.exe
[2013/08/18 18:41:49 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\ntvdm64.dll
[2013/08/18 18:41:49 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\instnm.exe
[2013/08/18 18:41:49 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\wow32.dll
[2013/08/18 18:41:49 | 000,002,048 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\user.exe
[2013/08/18 18:33:28 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu
\Programs\VideoLAN
[2013/08/18 02:23:30 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu
\Programs\Carbonite
[2013/08/17 01:22:28 | 000,000,000 | —D | C] – C:\Users\———\AppData\Roaming\Microsoft
\Windows\Start Menu\Programs\Vulture
[2013/08/17 01:07:44 | 000,000,000 | —D | C] – C:\Users\———\AppData\Roaming\Microsoft
\Windows\Start Menu\Programs\Revo Uninstaller
[2013/08/16 12:15:06 | 000,526,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\ieui.dll
[2013/08/16 12:15:06 | 000,391,168 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\ieui.dll
[2013/08/16 12:15:05 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\iesysprep.dll
[2013/08/16 12:15:05 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\iesysprep.dll
[2013/08/16 12:15:05 | 000,089,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\RegisterIEPKEYs.exe
[2013/08/16 12:15:05 | 000,071,680 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\RegisterIEPKEYs.exe
[2013/08/16 12:15:05 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\iesetup.dll
[2013/08/16 12:15:05 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\iesetup.dll
[2013/08/16 12:15:05 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\ie4uinit.exe
[2013/08/16 12:15:05 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\iernonce.dll
[2013/08/16 12:15:05 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\iernonce.dll
[2013/08/16 12:15:04 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\jscript.dll
[2013/08/16 12:15:04 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\jscript.dll
[2013/08/16 12:15:04 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\msfeeds.dll
[2013/08/16 12:15:03 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\jscript9.dll
[2013/08/15 20:28:04 | 001,472,512 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\crypt32.dll
[2013/08/15 20:28:04 | 000,224,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\wintrust.dll
[2013/08/15 20:28:04 | 000,139,776 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\cryptnet.dll
[2013/08/15 20:27:53 | 001,217,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\rpcrt4.dll
[2013/08/15 20:27:51 | 001,888,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative
\WMVDECOD.DLL
[2013/08/15 20:27:51 | 001,620,992 | —- | C] (Microsoft Corporation) – C:\Windows
\SysWow64\WMVDECOD.DLL
[2013/08/01 22:27:41 | 000,000,000 | —D | C] – C:\Windows\SysNative\MRT
[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Users\———\Desktop\*.tmp files -> C:\Users\———\Desktop\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/08/31 19:15:00 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-
B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2013/08/31 19:15:00 | 000,023,248 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-
B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2013/08/31 19:07:00 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player
Updater.job
[2013/08/31 18:52:01 | 000,000,912 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-
21-1963934971-338906939-1860683910-1001UA.job
[2013/08/31 18:33:29 | 000,000,029 | —- | M] () – C:\Windows\SysWow64\TempWmicBatchFile.bat
[2013/08/31 18:26:41 | 2147,483,636 | —- | M] () – C:\Users\———\Documents\TrueCrypt
[2013/08/31 18:19:00 | 000,000,898 | —- | M] () – C:\Windows\tasks
\GoogleUpdateTaskMachineUA.job
[2013/08/31 17:33:26 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/08/31 15:19:01 | 000,000,894 | —- | M] () – C:\Windows\tasks
\GoogleUpdateTaskMachineCore.job
[2013/08/31 01:52:14 | 000,000,860 | —- | M] () – C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-
21-1963934971-338906939-1860683910-1001Core.job
[2013/08/31 01:45:00 | 000,000,336 | —- | M] () – C:\Windows\tasks
\HPCeeScheduleFor———.job
[2013/08/31 00:28:07 | 000,002,367 | —- | M] () – C:\Users\———\Desktop\Google Chrome.lnk
[2013/08/31 00:05:35 | 000,743,732 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/08/31 00:05:35 | 000,636,084 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/08/31 00:05:35 | 000,111,626 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/08/30 23:59:23 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2013/08/29 00:25:14 | 000,000,542 | —- | M] () – C:\Windows\tasks\Thursday 1215am Scan.job
[2013/08/29 00:25:12 | 000,000,542 | —- | M] () – C:\Windows\tasks\Thursday 3am Scan.job
[2013/08/26 16:35:07 | 1073,741,824 | —- | M] () – C:\Users\———\Documents\TrueCrypt_2
[2013/08/21 20:21:51 | 000,001,743 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/08/18 17:56:46 | 000,002,176 | —- | M] () – C:\Users\Public\Desktop\Adobe Digital
Editions 2.0.lnk
[2013/08/18 16:46:46 | 000,692,104 | —- | M] (Adobe Systems Incorporated) – C:\Windows
\SysWow64\FlashPlayerApp.exe
[2013/08/18 16:46:46 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows
\SysWow64\FlashPlayerCPLApp.cpl
[2013/08/18 03:03:06 | 2147,483,648 | —- | M] () – C:\Users\———\Documents\PCRs
[2013/08/18 02:23:31 | 000,002,092 | —- | M] () – C:\Users\Public\Desktop\Carbonite
InfoCenter.lnk
[2013/08/17 01:07:45 | 000,001,224 | —- | M] () – C:\Users\———\Desktop\Revo
Uninstaller.lnk
[2013/08/17 01:03:22 | 000,000,632 | RHS- | M] () – C:\Users\———\ntuser.pol
[2013/08/05 17:43:15 | 000,007,596 | —- | M] () – C:\Users\———\AppData\Local
\Resmon.ResmonCfg
[2013/08/04 17:32:15 | 000,000,822 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]
[1 C:\Users\———\Desktop\*.tmp files -> C:\Users\———\Desktop\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/08/31 01:45:00 | 000,000,336 | —- | C] () – C:\Windows\tasks
\HPCeeScheduleFor———.job
[2013/08/21 20:21:51 | 000,001,743 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/08/18 17:56:46 | 000,002,176 | —- | C] () – C:\Users\Public\Desktop\Adobe Digital
Editions 2.0.lnk
[2013/08/18 02:23:31 | 000,002,092 | —- | C] () – C:\Users\Public\Desktop\Carbonite
InfoCenter.lnk
[2013/04/12 22:11:09 | 000,000,632 | RHS- | C] () – C:\Users\———\ntuser.pol
[2012/08/18 13:27:05 | 000,000,057 | —- | C] () – C:\ProgramData\Ament.ini
[2012/06/01 13:55:52 | 000,292,352 | —- | C] () – C:\Windows\SysWow64\MSAFDLsp.dll
[2012/03/13 14:58:51 | 000,004,096 | -H– | C] () – C:\Users\———\AppData\Local
\keyfile3.drm
[2011/09/18 21:58:54 | 000,000,000 | —- | C] () – C:\Users\———\AppData\Local\{9B826F9E-
E9D5-4DB4-A96C-D4A95AA5347C}
[2011/06/06 11:17:48 | 000,007,596 | —- | C] () – C:\Users\———\AppData\Local
\Resmon.ResmonCfg
[2010/12/01 21:12:36 | 000,001,854 | —- | C] () – C:\Users\———\AppData\Roaming
\GhostObjGAFix.xml
[2010/06/01 16:55:56 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
========== ZeroAccess Check ==========
[2010/12/23 12:20:51 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
/64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-
0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
/64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-
409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
/64
"" = C:\Windows\SysNative\shell32.dll – [2013/02/27 01:52:56 | 014,172,672 | —- | M]
(Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-
0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/02/27 00:55:05 | 012,872,704 | —- | M]
(Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
/64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/07/13 21:40:51 | 000,909,312 | —- | M]
(Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-
D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2010/11/20 08:19:02 | 000,606,208 | —- | M]
(Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
/64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2009/07/13 21:41:56 | 000,505,856 | —- | M]
(Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-
85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2011/04/25 15:00:03 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Audacity
[2011/07/07 17:51:13 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\AVG9
[2010/09/09 20:24:59 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming
\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2010/06/01 02:07:35 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming
\DigitalPersona
[2011/07/22 23:51:25 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\DVDVideoSoft
[2011/07/22 23:50:53 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming
\DVDVideoSoftIEHelpers
[2012/11/12 13:32:05 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Free-PDF-to-
Word.com
[2011/05/09 00:13:26 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\IObit
[2010/12/23 11:28:20 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\iolo
[2011/04/11 23:28:49 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming
\IsolatedStorage
[2011/03/25 13:53:37 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\LolClient
[2013/01/04 23:32:04 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Notepad++
[2011/09/01 00:11:24 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\ooVoo
Details
[2011/08/03 22:59:00 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Philipp
Winterberg
[2011/01/08 01:01:06 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\PlayFirst
[2012/08/29 20:33:38 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\SimBiotic
Software
[2011/04/11 21:24:07 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Symyx
[2011/11/22 01:38:06 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming
\SystemRequirementsLab
[2013/03/23 19:58:23 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\TomTom
[2013/08/31 19:13:18 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\TrueCrypt
[2010/06/05 17:36:15 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming
\WildTangentv1001
[2011/06/13 17:18:30 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Windows Live
Writer
[2012/03/02 04:34:31 | 000,000,000 | —D | M] – C:\Users\———\AppData\Roaming\Xerox
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.ADML >
[2009/07/13 22:30:02 | 000,003,695 | —- | M] () MD5=7A4C7F3CB156543113596988479CAFCE – C:
\Windows\winsxs\amd64_microsoft-windows-
s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2009/06/10 16:53:55 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:
\Windows\winsxs\amd64_microsoft-windows-shell-
grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2010/02/27 21:53:51 | 002,613,248 | —- | M] (Microsoft Corporation)
MD5=00B0358734CAA32C39D181FE6916B178 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20542_none_b8b0208ee0ce1889\explorer.exe
[2011/02/26 02:23:14 | 002,870,272 | —- | M] (Microsoft Corporation)
MD5=0862495E0C825893DB75EF44FAEA8E93 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 01:19:21 | 002,616,320 | —- | M] (Microsoft Corporation)
MD5=0FB9C74046656D1579A64660AD67B746 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 21:14:20 | 002,613,248 | —- | M] (Microsoft Corporation)
MD5=15BC38A7492BEFE831966ADB477CF76F – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 01:51:13 | 002,614,784 | —- | M] (Microsoft Corporation)
MD5=255CF508D7CFB10E0794D6AC93280BD8 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2010/05/18 05:32:35 | 002,614,272 | —- | M] (Microsoft Corporation)
MD5=2626FC9755BE22F805D3CFA0CE3EE727 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 01:33:07 | 002,614,784 | —- | M] (Microsoft Corporation)
MD5=2AF58D15EDC06EC6FDACCE1F19482BBF – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation)
MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\explorer.exe
[2011/02/25 02:19:30 | 002,871,808 | —- | M] (Microsoft Corporation)
MD5=332FEAB1435662FC6C672E25BEB37BE3 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 02:14:34 | 002,871,808 | —- | M] (Microsoft Corporation)
MD5=3B69712041F3D63605529BD66DC00C48 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 08:17:09 | 002,616,320 | —- | M] (Microsoft Corporation)
MD5=40D777B7A95E00593EB1568C68514493 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2010/02/27 21:53:51 | 002,868,736 | —- | M] (Microsoft Corporation)
MD5=6D4F9E4B640B413C6F73414327484C80 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16434_none_addea9f19345cd81\explorer.exe
[2010/02/27 21:52:37 | 002,868,224 | —- | M] (Microsoft Corporation)
MD5=700073016DAC1C3D2E7E2CE4223334B6 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation)
MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\SysWOW64\explorer.exe
[2011/02/25 01:30:54 | 002,616,320 | —- | M] (Microsoft Corporation)
MD5=8B88EBBB05A0E56B7DCC708498C02B3E – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/05/18 05:32:35 | 002,870,272 | —- | M] (Microsoft Corporation)
MD5=9AAAEC8DAC27AA17B053E6352AD233AE – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2010/02/27 21:52:37 | 002,613,248 | —- | M] (Microsoft Corporation)
MD5=9FF6C4C91A3711C0A3B18F87B08B518D – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 09:24:45 | 002,872,320 | —- | M] (Microsoft Corporation)
MD5=AC4C51EB24AA95B77F705AB159189E24 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2010/05/18 05:32:35 | 002,870,272 | —- | M] (Microsoft Corporation)
MD5=B8EC4BD49CE8F6FC457721BFC210B67F – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2010/02/27 21:52:37 | 002,613,248 | —- | M] (Microsoft Corporation)
MD5=B95EEB0F4E5EFBF1038A35B3351CF047 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 21:39:10 | 002,868,224 | —- | M] (Microsoft Corporation)
MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2010/05/18 05:32:35 | 002,614,272 | —- | M] (Microsoft Corporation)
MD5=C76153C7ECA00FA852BB0C193378F917 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2010/02/27 21:53:51 | 002,868,736 | —- | M] (Microsoft Corporation)
MD5=CA17F8620815267DC838E30B68CB5052 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20542_none_ae5b763cac6d568e\explorer.exe
[2011/02/26 02:26:45 | 002,870,784 | —- | M] (Microsoft Corporation)
MD5=E38899074D4951D31B4040E994DD7C8D – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2010/02/27 21:52:37 | 002,868,224 | —- | M] (Microsoft Corporation)
MD5=F170B4A061C9E026437B193B4D571799 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
[2010/02/27 21:53:51 | 002,613,248 | —- | M] (Microsoft Corporation)
MD5=FC89FACA0473641CB625EDA9277D0885 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer_31bf3856ad364e35_6.1.7600.16434_none_b8335443c7a68f7c\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation)
MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\en-US\explorer.exe.mui
[2009/07/13 22:26:48 | 000,022,016 | —- | M] (Microsoft Corporation)
MD5=4B87EEFDC8E253F846A7DFB49A8E6C70 – C:\Windows\winsxs\amd64_microsoft-windows-
explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation)
MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 22:06:56 | 000,022,016 | —- | M] (Microsoft Corporation)
MD5=B9F4B1CA23D60775736059D72BA48526 – C:\Windows\winsxs\wow64_microsoft-windows-
explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
< MD5 for: EXPLORER.EXE-A80E4F97.PF >
[2013/08/31 13:43:50 | 000,043,632 | —- | M] () MD5=13B293E99082CD30CD1E26DC85CB9A19 – C:
\Windows\Prefetch\EXPLORER.EXE-A80E4F97.pf
< MD5 for: EXPLORER.WSMODE >
[2013/02/25 01:56:00 | 000,000,576 | —- | M] () MD5=6B9A201C766ED41CCB80830192A8428A – C:
\Users\———\.netbeans\7.1.2\config\Windows2Local\Modes\explorer.wsmode
< MD5 for: IEXPLORE.EXE >
[2012/06/02 07:47:54 | 000,754,808 | —- | M] (Microsoft Corporation)
MD5=004640AB259C1572EBD5FB0A32F63686 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2013/01/08 21:53:45 | 000,763,424 | —- | M] (Microsoft Corporation)
MD5=0100BCF23941C83462E4A70F94C3392E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012/05/17 19:21:54 | 000,748,664 | —- | M] (Microsoft Corporation)
MD5=0129BB16161C2FD9A6B19111AB047198 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2013/05/16 22:32:12 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=07DFD28E57879554D054464EE4A5662D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16614_none_20d88bb252a3770f\iexplore.exe
[2012/11/13 22:56:04 | 000,757,296 | —- | M] (Microsoft Corporation)
MD5=0D286C0FE561D1A7EB30E83A0FF305B2 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2012/06/29 01:02:52 | 000,754,784 | —- | M] (Microsoft Corporation)
MD5=1223ACBFC1093852DFF039E189599BBD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2013/07/26 02:23:39 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=133CEF30905806A35606652D409EEEBA – C:\Program Files\Internet Explorer\iexplore.exe
[2013/07/26 02:23:39 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=133CEF30905806A35606652D409EEEBA – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16660_none_16893df21e3dcd43\iexplore.exe
[2010/09/08 00:36:39 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=14803EA3E5DD7CB37CB446C74CFDA38F – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.20795_none_1a39121b8bff3c23\iexplore.exe
[2012/08/24 03:34:41 | 000,748,680 | —- | M] (Microsoft Corporation)
MD5=22CC6CDBA678790046693654C3B212E4 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2012/05/17 18:59:46 | 000,748,664 | —- | M] (Microsoft Corporation)
MD5=268982F1FD671A077C6A2AF41E351436 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20551_none_181271f4ce004017\iexplore.exe
[2012/10/08 04:37:24 | 000,748,704 | —- | M] (Microsoft Corporation)
MD5=270A1342BD5AF95CA25A586B4C2F1522 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2013/03/24 00:41:24 | 000,770,560 | —- | M] (Microsoft Corporation)
MD5=2859EBC065D2E1CCC94161CE28BAC085 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16521_none_20e4a040529a2792\iexplore.exe
[2013/02/24 20:58:09 | 000,775,232 | —- | M] (Microsoft Corporation)
MD5=28F93BAFB3EB407E99A7ED3D9DBDE04C – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20644_none_ffb93ba237e760ce\iexplore.exe
[2013/06/12 00:41:27 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=2A5F565327BFD679EC5F790DC15BBF25 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20742_none_0a0343986c500b78\iexplore.exe
[2009/07/13 21:17:29 | 000,673,048 | —- | M] (Microsoft Corporation)
MD5=2C32E3E596CFE660353753EABEFB0540 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2012/08/24 07:23:44 | 000,754,824 | —- | M] (Microsoft Corporation)
MD5=2D53C5F71653EF94E7829846405D4ED2 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2013/04/05 01:55:38 | 000,770,624 | —- | M] (Microsoft Corporation)
MD5=2DC6BD1047553611DAEF97C751131A5D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20681_none_0a122b746c443b42\iexplore.exe
[2013/06/11 20:23:57 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=30E7CA4620500FE012EB464F0E1DE91E – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16635_none_20da757e52a1c35e\iexplore.exe
[2012/06/02 05:08:27 | 000,748,664 | —- | M] (Microsoft Corporation)
MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2013/05/16 21:57:28 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=3902E280F6117A468D5573343A7AA1F6 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20719_none_09ffa3426c5372da\iexplore.exe
[2010/09/08 01:37:57 | 000,696,592 | —- | M] (Microsoft Corporation)
MD5=4879CB864E290BED38C5BDB641144B1B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.20795_none_0fe467c9579e7a28\iexplore.exe
[2012/10/08 08:29:46 | 000,754,848 | —- | M] (Microsoft Corporation)
MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2010/09/08 01:49:01 | 000,696,592 | —- | M] (Microsoft Corporation)
MD5=498035ABCCF1ED47AE6791D239187587 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16671_none_0f6c69ae3e743d20\iexplore.exe
[2012/05/17 22:51:05 | 000,754,808 | —- | M] (Microsoft Corporation)
MD5=4E99F42504A99D5024C2EFA015001937 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2010/11/04 01:54:54 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=58CF468D3FF4CF830339FE5E45356355 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16700_none_1a0bc510729d1f54\iexplore.exe
[2012/08/24 06:49:07 | 000,754,824 | —- | M] (Microsoft Corporation)
MD5=5A150AFABB25BEA50CEDC8650A7B8A9E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/06/28 22:45:31 | 000,754,808 | —- | M] (Microsoft Corporation)
MD5=5D03518409F37D1483C98869D86E23FF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012/06/02 08:52:21 | 000,754,808 | —- | M] (Microsoft Corporation)
MD5=610F6596921C4BAA8834ADBB9BE272EE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2010/09/08 00:31:24 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=61EDBCE47ADF3E52AB0B9F49EE4AEBB8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16671_none_19c1140072d4ff1b\iexplore.exe
[2012/08/24 03:49:25 | 000,748,680 | —- | M] (Microsoft Corporation)
MD5=62188720CE27B982B4285C03163C9FB3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2013/02/21 08:59:57 | 000,775,216 | —- | M] (Microsoft Corporation)
MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16540_none_16920d4a1e377ea4\iexplore.exe
[2013/03/24 00:41:20 | 000,775,184 | —- | M] (Microsoft Corporation)
MD5=681B380492ACB571ED6CCC1F37F53343 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16521_none_168ff5ee1e396597\iexplore.exe
[2013/01/08 18:42:06 | 000,757,280 | —- | M] (Microsoft Corporation)
MD5=698EB1E5F8C66344D97C00B5699E871D – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2010/11/04 01:54:59 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=6B2258FF6D2332073FE9E90122FA4168 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.20831_none_1a75f2618bd22c48\iexplore.exe
[2010/12/18 02:17:48 | 000,696,592 | —- | M] (Microsoft Corporation)
MD5=700B40EA39DFB25517A81032F03D6D20 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16722_none_0fa37b7a3e4ac7e9\iexplore.exe
[2013/07/25 23:49:06 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/07/25 23:49:06 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16660_none_20dde844529e8f3e\iexplore.exe
[2013/02/02 04:09:12 | 000,763,424 | —- | M] (Microsoft Corporation)
MD5=7C2923004FFC497E54F38E835F108EE8 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2010/11/20 09:28:25 | 000,695,056 | —- | M] (Microsoft Corporation)
MD5=86257731DDB311FBC283534CC0091634 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2010/12/18 02:11:10 | 000,696,592 | —- | M] (Microsoft Corporation)
MD5=8C6C32E4AF8A3D7155656F5897C504E0 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.20861_none_1000d84b5789be20\iexplore.exe
[2013/07/26 01:47:06 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=8D805B4EEEE0ECF6B604BE284978F135 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20768_none_ffb0112a37ee15f1\iexplore.exe
[2013/05/16 23:02:08 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=8F00471CA24ADF8D2AFAACF856EB70A4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20719_none_ffaaf8f037f2b0df\iexplore.exe
[2011/03/31 00:08:52 | 000,748,336 | —- | M] (Microsoft Corporation)
MD5=904E13BA41AF2E353A32CF351CA53639 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2010/12/18 01:32:25 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=9321CF0D023528C71E3645F8433C86C8 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.20861_none_1a55829d8bea801b\iexplore.exe
[2012/06/28 21:00:47 | 000,748,664 | —- | M] (Microsoft Corporation)
MD5=93569D46D79F9756ED077156496AFE23 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2013/06/11 22:28:00 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=98C6F2A9A981A54222602B87C6310BDE – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16635_none_1685cb2c1e410163\iexplore.exe
[2013/02/24 19:52:40 | 000,770,624 | —- | M] (Microsoft Corporation)
MD5=A11C5E3E288256C540B7ED8BE3A04B01 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20644_none_0a0de5f46c4822c9\iexplore.exe
[2013/02/02 00:19:03 | 000,757,280 | —- | M] (Microsoft Corporation)
MD5=A285E1965C115031DA02B777EE9D7689 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013/02/02 03:37:58 | 000,763,424 | —- | M] (Microsoft Corporation)
MD5=A8EBEBCD9F5C49475194099FCD276992 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2010/12/18 01:33:54 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=AA08B68EF4E35EFA170CF85A44B23B70 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16722_none_19f825cc72ab89e4\iexplore.exe
[2013/04/05 02:02:26 | 000,770,608 | —- | M] (Microsoft Corporation)
MD5=AAD90795E84E710543C6C7C2F7048E30 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16576_none_20e92fca5296266a\iexplore.exe
[2012/11/15 23:08:58 | 000,763,424 | —- | M] (Microsoft Corporation)
MD5=AC4957E154F750DF54F36ADC8E3E040D – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:
\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/06/02 04:51:58 | 000,748,664 | —- | M] (Microsoft Corporation)
MD5=BE967C74B89577B78FB57C061E12B04C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2010/11/20 08:22:51 | 000,673,040 | —- | M] (Microsoft Corporation)
MD5=C613E69C3B191BB02C7A191741A1D024 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2013/06/12 03:51:43 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=CA88A25280B1D85ED0BC26B042ABBCCF – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20742_none_ffae994637ef497d\iexplore.exe
[2013/04/05 03:53:33 | 000,775,232 | —- | M] (Microsoft Corporation)
MD5=CEA304830B4770BDA3572B87D0841848 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16576_none_169485781e35646f\iexplore.exe
[2012/10/08 04:22:05 | 000,748,704 | —- | M] (Microsoft Corporation)
MD5=CECB15F834FC2B4B150449717ADE18DD – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2010/11/04 02:37:41 | 000,696,592 | —- | M] (Microsoft Corporation)
MD5=D8E00EA671A1EFE95C69C7566C505AD4 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16700_none_0fb71abe3e3c5d59\iexplore.exe
[2013/02/02 00:19:04 | 000,757,296 | —- | M] (Microsoft Corporation)
MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2013/04/05 03:23:03 | 000,775,216 | —- | M] (Microsoft Corporation)
MD5=DE751E18F8DBF7BCCE46989CBA4A9828 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20681_none_ffbd812237e37947\iexplore.exe
[2010/11/04 02:42:22 | 000,696,592 | —- | M] (Microsoft Corporation)
MD5=E220FB009F54AAF649C6A278A5156764 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.20831_none_1021480f57716a4d\iexplore.exe
[2013/02/21 07:28:11 | 000,770,608 | —- | M] (Microsoft Corporation)
MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16540_none_20e6b79c5298409f\iexplore.exe
[2013/07/26 01:09:39 | 000,770,648 | —- | M] (Microsoft Corporation)
MD5=E70D60B3A350BD09D86CDAD9CF55F36B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.20768_none_0a04bb7c6c4ed7ec\iexplore.exe
[2012/06/28 19:35:27 | 000,748,664 | —- | M] (Microsoft Corporation)
MD5=EB4105348272018D096FEB655CD1608C – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2013/05/16 23:30:45 | 000,775,256 | —- | M] (Microsoft Corporation)
MD5=EDC77CF787FA015205936C9A3228486E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_10.2.9200.16614_none_1683e1601e42b514\iexplore.exe
[2013/01/08 20:51:57 | 000,763,424 | —- | M] (Microsoft Corporation)
MD5=EF1F6F41FB2C9BBB484B21017F380201 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 17:32:42 | 000,757,280 | —- | M] (Microsoft Corporation)
MD5=F05982E56ABD835AA8DF260EEC873E5B – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2011/03/31 00:08:49 | 000,754,480 | —- | M] (Microsoft Corporation)
MD5=F1424C1B9B1813BF825E45DF3790BC8A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2009/07/13 21:43:43 | 000,696,600 | —- | M] (Microsoft Corporation)
MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2012/10/08 07:09:10 | 000,754,824 | —- | M] (Microsoft Corporation)
MD5=F61714ABCF9BF0CEF0A6249AD4FD490B – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012/11/13 22:19:28 | 000,757,280 | —- | M] (Microsoft Corporation)
MD5=F691418EE9A6344AEB5C1B0518FBF8AE – C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2012/05/17 21:37:57 | 000,754,808 | —- | M] (Microsoft Corporation)
MD5=F8B2D47ED17C1D087D14EC747E5AC57A – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.20551_none_0dbdc7a2999f7e1c\iexplore.exe
[2012/11/14 03:11:18 | 000,763,424 | —- | M] (Microsoft Corporation)
MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 – C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-
optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2011/03/31 00:08:50 | 000,005,632 | —- | M] (Microsoft Corporation)
MD5=17FAE936C452188D05852DE8D1082013 – C:\Windows\winsxs\amd64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/03/31 00:08:53 | 000,005,632 | —- | M] (Microsoft Corporation)
MD5=4C71CCB3C8817185E67210856778831F – C:\Windows\winsxs\wow64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/03/24 00:41:25 | 000,005,632 | —- | M] (Microsoft Corporation)
MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files (x86)\Internet Explorer\en-US
\iexplore.exe.mui
[2013/03/24 00:41:21 | 000,005,632 | —- | M] (Microsoft Corporation)
MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/03/24 00:41:21 | 000,005,632 | —- | M] (Microsoft Corporation)
MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\amd64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/03/24 00:41:25 | 000,005,632 | —- | M] (Microsoft Corporation)
MD5=8EDDC50FD07326E7DF9C4EEA422F0918 – C:\Windows\winsxs\wow64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation)
MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 22:29:20 | 000,005,120 | —- | M] (Microsoft Corporation)
MD5=C29BCFB504E33FEADDFA2D0183CEF62F – C:\Windows\winsxs\amd64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation)
MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
[2009/07/13 22:05:06 | 000,005,120 | —- | M] (Microsoft Corporation)
MD5=FBA4CD95930248053A2C3F43CA70B986 – C:\Windows\winsxs\wow64_microsoft-windows-i..-
optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui
< MD5 for: SERVICES >
[2009/06/10 17:00:26 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:
\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-
other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
< MD5 for: SERVICES.CFG >
[2013/05/10 03:57:30 | 000,558,879 | —- | M] () MD5=3679F8D3253DC110D1D8F2AE115EE00C – C:
\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 13:55:30 | 000,584,045 | R— | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E – C:
\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
< MD5 for: SERVICES.EXE >
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation)
MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\SysNative\services.exe
[2009/07/13 21:39:37 | 000,328,704 | —- | M] (Microsoft Corporation)
MD5=24ACB7E5BE595468E3B9AA488B9B4FCB – C:\Windows\winsxs\amd64_microsoft-windows-s..s-
servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation)
MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 22:25:40 | 000,017,408 | —- | M] (Microsoft Corporation)
MD5=6507BF0DC2D1F5F32493C288EAA59277 – C:\Windows\winsxs\amd64_microsoft-windows-
s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
< MD5 for: SERVICES.LNK >
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:
\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 00:54:05 | 000,001,288 | —- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 – C:
\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
< MD5 for: SERVICES.MOF >
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:
\Windows\SysNative\wbem\services.mof
[2009/06/10 16:44:06 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:
\Windows\winsxs\amd64_microsoft-windows-s..s-
servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
< MD5 for: SERVICES.MSC >
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\SysNative\en-US\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\SysNative\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\SysWOW64\en-US\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\SysWOW64\services.msc
[2009/07/13 22:23:30 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\winsxs\amd64_microsoft-windows-
s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 16:38:36 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\winsxs\amd64_microsoft-windows-
servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 22:08:50 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-
us_a4156d265db25d25\services.msc
[2009/06/10 17:21:09 | 000,092,745 | —- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 – C:
\Windows\winsxs\x86_microsoft-windows-
servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
< MD5 for: SERVICES.PTXML >
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:
\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 16:16:17 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:
\Windows\winsxs\amd64_microsoft-windows-s..s-
servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
< MD5 for: SERVICES.SETTINGS >
[2013/02/25 01:56:00 | 000,001,622 | —- | M] () MD5=488D8CC923D82E3FADA846EF9587A289 – C:
\Users\———\.netbeans\7.1.2\config\Windows2Local\Components\services.settings
< MD5 for: SERVICES.WSTCGRP >
[2013/02/25 01:56:00 | 000,000,224 | —- | M] () MD5=4C0234F9B3F49A3484CE64025050D7A7 – C:
\Users\———\.netbeans\7.1.2\config\Windows2Local\Groups\InitialLayout\services.wstcgrp
[2013/02/25 01:56:00 | 000,000,225 | —- | M] () MD5=E4AD31A486D75BC449F02775904D2430 – C:
\Users\———\.netbeans\7.1.2\config\Windows2Local\Groups\OpenedProjects\services.wstcgrp
< MD5 for: SERVICES.WSTCREF >
[2013/02/25 01:56:00 | 000,000,129 | —- | M] () MD5=73E5717A2B2C3FF0F7ED6EFDD0A658B3 – C:
\Users\———\.netbeans\7.1.2\config\Windows2Local\Modes\explorer\services.wstcref
< MD5 for: WINLOGON.ADML >
[2009/07/13 22:25:22 | 000,008,013 | —- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E – C:
\Windows\winsxs\amd64_microsoft-windows-winlogon-
adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2009/06/10 17:04:41 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:
\Windows\winsxs\amd64_microsoft-windows-winlogon-
adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation)
MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\SysNative\winlogon.exe
[2010/11/20 09:25:30 | 000,390,656 | —- | M] (Microsoft Corporation)
MD5=1151B1BAA6F350B1DB6598E0FEA7C457 – C:\Windows\winsxs\amd64_microsoft-windows-
winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 21:39:52 | 000,389,120 | —- | M] (Microsoft Corporation)
MD5=132328DF455B0028F13BF0ABEE51A63A – C:\Windows\winsxs\amd64_microsoft-windows-
winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2010/05/18 05:32:35 | 000,389,632 | —- | M] (Microsoft Corporation)
MD5=A93D41A4D4B0D91C072D11DD8AF266DE – C:\Windows\winsxs\amd64_microsoft-windows-
winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:
\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2010/05/18 05:32:35 | 000,389,632 | —- | M] (Microsoft Corporation)
MD5=DA3E2A6FA9660CC75B471530CE88453A – C:\Windows\winsxs\amd64_microsoft-windows-
winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation)
MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 09:00:25 | 000,023,040 | —- | M] (Microsoft Corporation)
MD5=34C7D2E30868EDAFB191341D963ABA5F – C:\Windows\winsxs\amd64_microsoft-windows-
winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2009/07/13 22:29:52 | 000,022,528 | —- | M] (Microsoft Corporation)
MD5=56D03B64B8C483C1D12A8E4577B3B332 – C:\Windows\winsxs\amd64_microsoft-windows-
winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:
\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 22:27:22 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:
\Windows\winsxs\amd64_microsoft-windows-winlogon-
mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:
\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 16:30:01 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:
\Windows\winsxs\amd64_microsoft-windows-winlogon-
mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2009/07/13 21:38:58 | 000,383,562 | RHS- | M] () – C:\bootmgr
[2001/09/05 21:00:58 | 001,700,352 | —- | M] (Microsoft Corporation) – C:\gdiplus.dll
[2013/08/30 23:59:23 | 3062,255,616 | -HS- | M] () – C:\hiberfil.sys
[2010/09/06 12:56:46 | 000,015,872 | —- | M] () – C:\MDL.Draw.Editor.XmlSerializers.dll
[2010/09/06 12:57:06 | 004,275,200 | —- | M] () – C:\oedrawaddincsharp.dll
[2010/09/06 12:57:06 | 000,024,576 | —- | M] (OpenEye Scientific Software, Inc.) – C:
\OpenEye.oedrawaddin.dll
[2013/08/30 23:59:24 | 4083,007,488 | -HS- | M] () – C:\pagefile.sys
[2010/07/21 18:10:51 | 000,000,085 | —- | M] () – C:\SETUP.LOG
[2010/07/07 20:43:53 | 000,000,085 | —- | M] () – C:\SYNTPAD.LOG
< %systemroot%\Fonts\*.com >
[2009/07/14 01:32:31 | 000,026,040 | —- | M] () – C:\Windows\Fonts
\GlobalMonospace.CompositeFont
[2009/07/14 01:32:31 | 000,026,489 | —- | M] () – C:\Windows\Fonts
\GlobalSansSerif.CompositeFont
[2009/07/14 01:32:31 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 01:32:31 | 000,043,318 | —- | M] () – C:\Windows\Fonts
\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2009/06/10 16:49:50 | 000,000,065 | -H– | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2010/11/10 02:28:46 | 000,301,936 | —- | M] (Microsoft Corporation) – C:\Windows\WLXPGSS.SCR
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
[2010/07/22 20:51:05 | 000,001,670 | -HS- | M] () – C:\Users\———\AppData\Roaming\Microsoft
\LastFlashConfig.wfc
< %PROGRAMFILES%\*.* >
[2009/07/14 00:54:24 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C has no label.
Volume Serial Number is 726B-5B53
Directory of C:\
07/14/2009 01:08 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 01:08 AM All Users [C:\ProgramData]
07/14/2009 01:08 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 01:08 AM Application Data [C:\ProgramData]
07/14/2009 01:08 AM Desktop [C:\Users\Public\Desktop]
07/14/2009 01:08 AM Documents [C:\Users\Public\Documents]
07/14/2009 01:08 AM Favorites [C:\Users\Public\Favorites]
07/14/2009 01:08 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\———
06/01/2010 02:07 AM Application Data [C:\Users\———\AppData\Roaming]
06/01/2010 02:07 AM Cookies [C:\Users\———\AppData\Roaming\Microsoft
\Windows\Cookies]
06/01/2010 02:07 AM Local Settings [C:\Users\———\AppData\Local]
06/01/2010 02:07 AM My Documents [C:\Users\———\Documents]
06/01/2010 02:07 AM NetHood [C:\Users\———\AppData\Roaming\Microsoft
\Windows\Network Shortcuts]
06/01/2010 02:07 AM PrintHood [C:\Users\———\AppData\Roaming\Microsoft
\Windows\Printer Shortcuts]
06/01/2010 02:07 AM Recent [C:\Users\———\AppData\Roaming\Microsoft
\Windows
\Recent]
06/01/2010 02:07 AM SendTo [C:\Users\———\AppData\Roaming\Microsoft
\Windows
\SendTo]
06/01/2010 02:07 AM Start Menu [C:\Users\———\AppData\Roaming\Microsoft
\Windows\Start Menu]
06/01/2010 02:07 AM Templates [C:\Users\———\AppData\Roaming\Microsoft
\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\———\AppData\Local
06/01/2010 02:07 AM Application Data [C:\Users\———\AppData\Local]
06/01/2010 02:07 AM History [C:\Users\———\AppData\Local\Microsoft
\Windows
\History]
06/01/2010 02:07 AM Temporary Internet Files [C:\Users\———\AppData\Local
\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\———\Documents
06/01/2010 02:07 AM My Music [C:\Users\———\Music]
06/01/2010 02:07 AM My Pictures [C:\Users\———\Pictures]
06/01/2010 02:07 AM My Videos [C:\Users\———\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 01:08 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\Cookies]
07/14/2009 01:08 AM Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM My Documents [C:\Users\Default\Documents]
07/14/2009 01:08 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\Network Shortcuts]
07/14/2009 01:08 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\Printer Shortcuts]
07/14/2009 01:08 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\Recent]
07/14/2009 01:08 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\SendTo]
07/14/2009 01:08 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\Start Menu]
07/14/2009 01:08 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft
\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 01:08 AM Application Data [C:\Users\Default\AppData\Local]
07/14/2009 01:08 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows
\History]
07/14/2009 01:08 AM Temporary Internet Files [C:\Users\Default\AppData\Local
\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/14/2009 01:08 AM My Music [C:\Users\Default\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Default\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Guest
08/01/2013 10:20 PM Application Data [C:\Users\Guest\AppData\Roaming]
08/01/2013 10:20 PM Cookies [C:\Users\Guest\AppData\Roaming\Microsoft\Windows
\Cookies]
08/01/2013 10:20 PM Local Settings [C:\Users\Guest\AppData\Local]
08/01/2013 10:20 PM My Documents [C:\Users\Guest\Documents]
08/01/2013 10:20 PM NetHood [C:\Users\Guest\AppData\Roaming\Microsoft\Windows
\Network Shortcuts]
08/01/2013 10:20 PM PrintHood [C:\Users\Guest\AppData\Roaming\Microsoft
\Windows\Printer Shortcuts]
08/01/2013 10:20 PM Recent [C:\Users\Guest\AppData\Roaming\Microsoft\Windows
\Recent]
08/01/2013 10:20 PM SendTo [C:\Users\Guest\AppData\Roaming\Microsoft\Windows
\SendTo]
08/01/2013 10:20 PM Start Menu [C:\Users\Guest\AppData\Roaming\Microsoft
\Windows\Start Menu]
08/01/2013 10:20 PM Templates [C:\Users\Guest\AppData\Roaming\Microsoft
\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Guest\AppData\Local
08/01/2013 10:20 PM Application Data [C:\Users\Guest\AppData\Local]
08/01/2013 10:20 PM History [C:\Users\Guest\AppData\Local\Microsoft\Windows
\History]
08/01/2013 10:20 PM Temporary Internet Files [C:\Users\Guest\AppData\Local
\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Guest\Documents
08/01/2013 10:20 PM My Music [C:\Users\Guest\Music]
08/01/2013 10:20 PM My Pictures [C:\Users\Guest\Pictures]
08/01/2013 10:20 PM My Videos [C:\Users\Guest\Videos]
0 File(s) 0 bytes
Directory of C:\Users\GuestUser
08/05/2013 06:13 PM Application Data [C:\Users\GuestUser\AppData\Roaming]
08/05/2013 06:13 PM Cookies [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\Cookies]
08/05/2013 06:13 PM Local Settings [C:\Users\GuestUser\AppData\Local]
08/05/2013 06:13 PM My Documents [C:\Users\GuestUser\Documents]
08/05/2013 06:13 PM NetHood [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\Network Shortcuts]
08/05/2013 06:13 PM PrintHood [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\Printer Shortcuts]
08/05/2013 06:13 PM Recent [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\Recent]
08/05/2013 06:13 PM SendTo [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\SendTo]
08/05/2013 06:13 PM Start Menu [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\Start Menu]
08/05/2013 06:13 PM Templates [C:\Users\GuestUser\AppData\Roaming\Microsoft
\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\GuestUser\AppData\Local
08/05/2013 06:13 PM Application Data [C:\Users\GuestUser\AppData\Local]
08/05/2013 06:13 PM History [C:\Users\GuestUser\AppData\Local\Microsoft
\Windows\History]
08/05/2013 06:13 PM Temporary Internet Files [C:\Users\GuestUser\AppData
\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\GuestUser\Documents
08/05/2013 06:13 PM My Music [C:\Users\GuestUser\Music]
08/05/2013 06:13 PM My Pictures [C:\Users\GuestUser\Pictures]
08/05/2013 06:13 PM My Videos [C:\Users\GuestUser\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 01:08 AM My Music [C:\Users\Public\Music]
07/14/2009 01:08 AM My Pictures [C:\Users\Public\Pictures]
07/14/2009 01:08 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\TEMP
08/23/2010 03:49 PM Application Data [C:\Users\TEMP\AppData\Roaming]
08/23/2010 03:49 PM Cookies [C:\Users\TEMP\AppData\Roaming\Microsoft\Windows
\Cookies]
08/23/2010 03:49 PM Local Settings [C:\Users\TEMP\AppData\Local]
08/23/2010 03:49 PM My Documents [C:\Users\TEMP\Documents]
08/23/2010 03:49 PM NetHood [C:\Users\TEMP\AppData\Roaming\Microsoft\Windows
\Network Shortcuts]
08/23/2010 03:49 PM PrintHood [C:\Users\TEMP\AppData\Roaming\Microsoft
\Windows\Printer Shortcuts]
08/23/2010 03:49 PM Recent [C:\Users\TEMP\AppData\Roaming\Microsoft\Windows
\Recent]
08/23/2010 03:49 PM SendTo [C:\Users\TEMP\AppData\Roaming\Microsoft\Windows
\SendTo]
08/23/2010 03:49 PM Start Menu [C:\Users\TEMP\AppData\Roaming\Microsoft
\Windows\Start Menu]
08/23/2010 03:49 PM Templates [C:\Users\TEMP\AppData\Roaming\Microsoft
\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\TEMP\AppData\Local
08/23/2010 03:49 PM Application Data [C:\Users\TEMP\AppData\Local]
08/23/2010 03:49 PM History [C:\Users\TEMP\AppData\Local\Microsoft\Windows
\History]
08/23/2010 03:49 PM Temporary Internet Files [C:\Users\TEMP\AppData\Local
\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\TEMP\Documents
08/23/2010 03:49 PM My Music [C:\Users\TEMP\Music]
08/23/2010 03:49 PM My Pictures [C:\Users\TEMP\Pictures]
08/23/2010 03:49 PM My Videos [C:\Users\TEMP\Videos]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile
05/18/2010 06:12 AM Application Data [C:\Windows\system32\config
\systemprofile\AppData\Roaming]
05/18/2010 06:12 AM Cookies [C:\Windows\system32\config\systemprofile\AppData
\Roaming\Microsoft\Windows\Cookies]
05/18/2010 06:12 AM Local Settings [C:\Windows\system32\config\systemprofile
\AppData\Local]
07/23/2011 12:13 AM Start Menu [C:\Windows\system32\config\systemprofile
\AppData\Roaming\Microsoft\Windows\Start Menu]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\AppData\Local
05/18/2010 06:12 AM Application Data [C:\Windows\system32\config
\systemprofile\AppData\Local]
05/18/2010 06:12 AM History [C:\Windows\system32\config\systemprofile\AppData
\Local\Microsoft\Windows\History]
05/18/2010 06:12 AM Temporary Internet Files [C:\Windows\system32\config
\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Windows\SysWOW64\config\systemprofile
05/18/2010 06:12 AM Application Data [C:\Windows\system32\config
\systemprofile\AppData\Roaming]
05/18/2010 06:12 AM Cookies [C:\Windows\system32\config\systemprofile\AppData
\Roaming\Microsoft\Windows\Cookies]
05/18/2010 06:12 AM Local Settings [C:\Windows\system32\config\systemprofile
\AppData\Local]
07/23/2011 12:13 AM Start Menu [C:\Windows\system32\config\systemprofile
\AppData\Roaming\Microsoft\Windows\Start Menu]
0 File(s) 0 bytes
Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Local
05/18/2010 06:12 AM Application Data [C:\Windows\system32\config
\systemprofile\AppData\Local]
05/18/2010 06:12 AM History [C:\Windows\system32\config\systemprofile\AppData
\Local\Microsoft\Windows\History]
05/18/2010 06:12 AM Temporary Internet Files [C:\Windows\system32\config
\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
112 Dir(s) 153,010,155,520 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2012/03/11 18:17:36 | 000,000,221 | -HS- | M] () – C:\Users\———\AppData\Roaming\Microsoft
\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto
Update\Results\Install|LastSuccessTime /rs >
< End of report >
********************************************************************************
**********
Extras.txt:
OTL Extras logfile created on: 8/31/2013 7:13:26 PM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\———\Downloads
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.80 Gb Total Physical Memory | 1.48 Gb Available Physical Memory | 39.01% Memory free
7.60 Gb Paging File | 4.71 Gb Available in Paging File | 62.00% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 276.46 Gb Total Space | 142.57 Gb Free Space | 51.57% Space Free | Partition Type:
NTFS
Drive D: | 21.33 Gb Total Space | 3.10 Gb Free Space | 14.53% Space Free | Partition Type: NTFS
Drive E: | 99.34 Mb Total Space | 84.17 Mb Free Space | 84.74% Space Free | Partition Type: FAT32
Drive T: | 49.98 Gb Total Space | 46.89 Gb Free Space | 93.82% Space Free | Partition Type: FAT32
Computer Name: ——— | User Name: ——— | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File
Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = Reg Error: Value error.] – Reg Error: Key error. File not found
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft
Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%
\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows
\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows
\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%
\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file
–playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –
no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1
(Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet
Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft
Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%
\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%
\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file
–playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –
no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1
(Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring\SophosAntiVirus]
"" =
"DisableMonitoring" = 1
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\DomainProfile\GloballyOpenPorts\List]
"8192:TCP" = 8192:TCP:*:Enabled:Sophos AntiVirus
"8193:TCP" = 8193:TCP:*:Enabled:Sophos AntiVirus
"8194:TCP" = 8194:TCP:*:Enabled:Sophos AntiVirus
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\StandardProfile\GloballyOpenPorts\List]
"8192:TCP" = 8192:TCP:*:Enabled:Sophos AntiVirus
"8193:TCP" = 8193:TCP:*:Enabled:Sophos AntiVirus
"8194:TCP" = 8194:TCP:*:Enabled:Sophos AntiVirus
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
========== Authorized Applications List ==========
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\FirewallRules]
"{06369B26-1349-441A-9131-7FAC7568A0E3}" = rport=138 | protocol=17 | dir=out | app=system |
"{0ABD4E45-204B-40F0-B466-8ED75D43DFA0}" = lport=6004 | protocol=17 | dir=in | app=c:\program
files (x86)\microsoft office\office12\outlook.exe |
"{1743EC63-9BBE-412C-8729-B2BCCBB6AD7B}" = lport=8192 | protocol=6 | dir=in |
name=sophosdomain8192 |
"{263543C5-DEC6-49C6-AB40-F118A3E1D265}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv |
app=svchost.exe |
"{28301FBC-D455-4033-B46F-0F60809630BF}" = lport=139 | protocol=6 | dir=in | app=system |
"{441ECA01-2DAE-4808-9C1E-D1AC84971305}" = lport=5355 | protocol=17 | dir=in | svc=dnscache |
app=%systemroot%\system32\svchost.exe |
"{475552AD-51ED-4294-ADB6-C6061FBD0E07}" = lport=2869 | protocol=6 | dir=in | name=windows live
communications platform (upnp) |
"{492CED09-A62B-4771-9E10-DD846D0F2767}" = lport=2869 | protocol=6 | dir=in | app=system |
"{64224B44-517C-4AC6-AF3F-08D0601B8FBD}" = rport=137 | protocol=17 | dir=out | app=system |
"{662BEF3C-F82D-45A0-8DF3-1E5882E67B4F}" = lport=1900 | protocol=17 | dir=in | name=windows live
communications platform (ssdp) |
"{7957BC65-B941-4AD0-BF0E-1914AD32273A}" = rport=5355 | protocol=17 | dir=out | svc=dnscache |
app=%systemroot%\system32\svchost.exe |
"{7C996A8C-CAB2-4E3D-9170-4178B3BA95C5}" = lport=8193 | protocol=6 | dir=in |
name=sophospublic8193 |
"{86A6E98B-7C75-421E-84A2-CE93E11CE3CB}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss |
name=@firewallapi.dll,-28539 |
"{8F97CB72-3F3D-4099-8A2F-1DF3CB1F3087}" = rport=445 | protocol=6 | dir=out | app=system |
"{90721D3F-E21A-44F1-A6B2-25A8575ED766}" = lport=8193 | protocol=6 | dir=in |
name=sophosdomain8193 |
"{91225E08-696C-414A-B188-309E39401C91}" = lport=8194 | protocol=6 | dir=in |
name=sophosdomain8194 |
"{98846273-FCE5-4FEF-924E-715B7408C2DF}" = lport=5355 | protocol=17 | dir=in | svc=dnscache |
app=%systemroot%\system32\svchost.exe |
"{9CD4115A-10C6-4D9F-9DB8-116E10BA2602}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=
%systemroot%\system32\spoolsv.exe |
"{9E07F4F2-3D8F-4408-8EAD-B33C09C4FBB6}" = rport=139 | protocol=6 | dir=out | app=system |
"{A5FCB6F4-F2AE-4120-8DA5-2390A02E3453}" = rport=5355 | protocol=17 | dir=out | svc=dnscache |
app=%systemroot%\system32\svchost.exe |
"{D3365AD0-B58E-4462-B10D-314A14244858}" = lport=138 | protocol=17 | dir=in | app=system |
"{D8206270-AC94-4361-97F6-1971BBCD1B0D}" = rport=427 | protocol=17 | dir=in | svc=hpslpsvc |
app=c:\windows\system32\svchost.exe |
"{DC7A6F3A-A69E-475E-A3A2-17FAD3E8A4E0}" = lport=8194 | protocol=6 | dir=in |
name=sophospublic8194 |
"{E2364760-EA20-49B1-B546-2E605A41C737}" = lport=445 | protocol=6 | dir=in | app=system |
"{E5E5D84D-44B0-46CE-A04C-977EB18BA010}" = lport=137 | protocol=17 | dir=in | app=system |
"{EAE7D401-85CC-4585-9057-9D599AA58130}" = lport=8192 | protocol=6 | dir=in |
name=sophospublic8192 |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy
\FirewallRules]
"{000C9CF3-F3A4-44D2-952B-8C2D8AF54542}" = protocol=17 | dir=out | app=%programfiles%\windows
media player\wmplayer.exe |
"{0508A32E-F3F2-4C08-B8A5-8157A7B8E9BB}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{0C44595B-9B02-42C4-B18D-2C9A480D66CE}" = protocol=6 | dir=in | app=c:\users\———\appdata
\local\google\google talk plugin\googletalkplugin.exe |
"{108EDA04-616B-4420-8639-412AFC1AF4B2}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqusgh.exe |
"{1219FAE0-E710-43F3-8BAC-D616B0F0D591}" = protocol=6 | dir=in | app=c:\users\———\appdata
\local\google\google talk plugin\googletalkplugin.exe |
"{16E0A08A-5F82-403C-85F0-B6433B37CDEE}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpofxm08.exe |
"{18D21069-7620-4B3F-A762-1138130932C4}" = protocol=6 | dir=in | app=c:\program files
(x86)\bonjour\mdnsresponder.exe |
"{1B65F1F8-CECD-48AA-8D3C-4E843E740B34}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpzwiz01.exe |
"{1CB17461-A480-48A6-BA5A-1C2B1AA483E5}" = dir=in | app=c:\program files\hp\hp officejet pro
8600\bin\hpnetworkcommunicatorcom.exe |
"{1CB27C2C-D03E-4A5A-A432-47870B12C431}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpoews01.exe |
"{2162F9E1-7CE4-4277-9B66-003FBC3E3408}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{2215995B-84F0-4090-AB33-EB4AA61BB0C8}" = dir=in | app=c:\program files (x86)\windows live
\messenger\msnmsgr.exe |
"{22329288-1724-41DD-BA57-CF2C88230D2B}" = dir=in | app=c:\program files (x86)\windows live\sync
\windowslivesync.exe |
"{231C333F-FD39-4931-98DA-489C9D64D42C}" = dir=in | app=c:\program files (x86)\hewlett-packard
\touchsmart\music\hptouchsmartmusic.exe |
"{2AF0460F-07EA-4081-A55F-5FF499FDFC25}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{2BF99A4A-A3AE-4251-BD08-B36BA35F9FD8}" = protocol=6 | dir=in | app=c:\program files
(x86)\microsoft office\office12\onenote.exe |
"{33FD3BDF-0D02-4C9F-B766-367360FC46B2}" = protocol=6 | dir=in | app=c:\program files\hp\hp
deskjet 3050 j610 series\bin\devicesetup.exe |
"{396BC68B-D88F-4B5C-B8B1-B8E31EC8FD9A}" = protocol=6 | dir=in | app=c:\users\———\appdata
\local\akamai\netsession_win.exe |
"{401570AD-D1E0-4115-BD79-C64BA347B46D}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqgplgtupl.exe |
"{4322F255-2072-4F8A-89F2-4CC4A7DA4095}" = dir=in | app=c:\program files (x86)\windows live
\contacts\wlcomm.exe |
"{47EFBAB2-5339-4D97-BA99-35FF5F37CAD7}" = dir=in | app=c:\program files\hp\hp officejet pro
8600\bin\faxapplications.exe |
"{4A633776-6793-4909-B8A9-040D788196CC}" = protocol=17 | dir=in | app=c:\program files\hp\hp
deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |
"{4D954FCD-E26C-4669-8E3F-CC9F3C4628E1}" = dir=in | app=c:\program files\hp\hp officejet pro
8600\bin\sendafax.exe |
"{4F3A5693-BD4B-46FE-AF47-D24D0FAA7650}" = protocol=17 | dir=in | app=c:\users\———\appdata
\local\akamai\netsession_win.exe |
"{528584E3-554B-4085-86E9-77D98D422A2A}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqfxt08.exe |
"{5554CDDA-7ECE-43DA-AF6E-C670718ADEF8}" = dir=in | app=c:\program files\intel\wifi\bin
\pandhcpdns.exe |
"{57BFBA45-2266-486C-B802-0D5EA559BFCF}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqste08.exe |
"{59A7A7A1-7201-4E46-9870-10862C70116B}" = protocol=17 | dir=out | app=%programfiles(x86)%
\windows media player\wmplayer.exe |
"{650E62D7-F33F-482D-8961-6D68C091774F}" = protocol=17 | dir=in | app=c:\program files\bonjour
\mdnsresponder.exe |
"{65EFACF9-F407-4BF8-A33E-0D2A3DDD85B8}" = protocol=17 | dir=in | app=c:\users\———\appdata
\local\google\google talk plugin\googletalkplugin.exe |
"{76C42CF3-30D7-49CD-AD09-E1B4D71A085B}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp
support framework\resources\hpwarrantycheck\hpdevicedetection3.exe |
"{77F962F6-C918-4811-9EF3-7483B2F8C348}" = protocol=17 | dir=in | app=c:\program files
(x86)\microsoft office\office12\onenote.exe |
"{7DA74380-9CE7-436C-88CE-2E45A954ACB3}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqkygrp.exe |
"{80D5776F-4D39-4FD8-952F-4833917162D9}" = dir=in | app=c:\program files (x86)\common files
\apple\apple application support\webkit2webprocess.exe |
"{810C9527-51E9-4B7D-AC2C-0325426C2E3F}" = dir=in | app=c:\program files\hp\hp officejet pro
8600\bin\digitalwizards.exe |
"{817DE8D6-569A-43C9-91A7-58EAA28A1D4A}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp
support framework\resources\hpwarrantycheck\hpwarrantychecker.exe |
"{85B5B769-ECEB-4AA4-B5CA-0FC6BDDDEC96}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqusgm.exe |
"{85DBA9A3-4A5D-4F16-8435-7CE5FE2209DE}" = protocol=6 | dir=in | app=c:\program files
(x86)\bonjour\mdnsresponder.exe |
"{992FB719-F3E8-4DFB-863D-5726252E9846}" = protocol=17 | dir=in | app=%programfiles%\windows
media player\wmplayer.exe |
"{9F2AEBF5-41E1-4FF9-B9A9-F51CC6A6E4B5}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows
media player\wmplayer.exe |
"{B2443E04-7A71-46BD-A75F-48DE0388C67F}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpofxs08.exe |
"{B26FD83C-0002-4166-9412-0B0B9764167F}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpfccopy.exe |
"{B276CA34-08BC-4E1B-9373-03A02774F09C}" = dir=in | app=f:\setup\hpznui40.exe |
"{B534C11A-D24A-4FE1-BCC5-D652A88BD5F7}" = protocol=6 | dir=in | app=c:\program files\bonjour
\mdnsresponder.exe |
"{BC92F26E-B405-4C39-B78F-FB96AC946345}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpiscnapp.exe |
"{BD2F4C4E-25F8-45BF-8BA2-F09A7F5C861E}" = protocol=6 | dir=in | app=c:\program files\hp\hp
deskjet 3050 j610 series\bin\hpnetworkcommunicator.exe |
"{C5D8D09A-ACD2-4CEA-9410-48F2FB21A128}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hposid01.exe |
"{C6F907E2-39DF-4F54-A70F-FF5C43285BA4}" = protocol=6 | dir=out | app=%programfiles%\windows
media player\wmplayer.exe |
"{C78F4F3B-79D4-4D86-8871-95CEBAB34CE2}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqtra08.exe |
"{C90D356F-EC17-4A74-9B7B-1D2023146390}" = protocol=17 | dir=in | app=c:\program files
(x86)\bonjour\mdnsresponder.exe |
"{CAE2E8E9-072E-4CDE-AAED-6F403561EC5E}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\smart web printing\smartwebprintexe.exe |
"{CAE96F8E-94AD-4989-B04B-A2C5298A8677}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe
|
"{CB9F066A-2691-432A-ABD6-D013CA8F615D}" = protocol=17 | dir=in | app=c:\program files
(x86)\internet explorer\iexplore.exe |
"{CD0F2DAD-E698-4C4F-B707-6220E46E1867}" = protocol=17 | dir=in | app=c:\program files
(x86)\bonjour\mdnsresponder.exe |
"{D04D7A99-CB58-49F3-A44E-6E57D31BF52C}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hpqgpc01.exe |
"{D7CC9EE7-CADD-4B18-BC5C-8A13A1C7FA64}" = dir=in | app=c:\program files (x86)\hp\digital
imaging\bin\hposfx08.exe |
"{DB1206B4-B3B3-499E-80DC-CCE68D6CAEBF}" = dir=in | app=c:\program files\hp\hp officejet pro
8600\bin\hpnetworkcommunicator.exe |
"{E2090F0B-50F3-4607-92E9-2605003D1716}" = protocol=17 | dir=in | app=c:\program files\hp\hp
deskjet 3050 j610 series\bin\devicesetup.exe |
"{EABBE83A-A26D-4EBF-819F-FFC72FE94B52}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows
media player\wmplayer.exe |
"{ECCBDD9A-3332-407F-9533-9C3E3FE28651}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{F4492C96-E634-4484-9449-E4EFE59ABC28}" = dir=in | app=c:\program files (x86)\hp\hp software
update\hpwucli.exe |
"{F4714187-3025-477B-8D3C-1AF5E31D6EDF}" = protocol=17 | dir=in | app=c:\users\———\appdata
\local\google\google talk plugin\googletalkplugin.exe |
"{FAF422E8-2307-4D74-B0D2-5BDE6E56C82E}" = protocol=6 | dir=in | app=c:\program files
(x86)\internet explorer\iexplore.exe |
"{FB92E234-9289-4CCC-B6CE-DE48FA66B7D4}" = dir=in | app=c:\program files\hp\hp officejet pro
8600\bin\devicesetup.exe |
"TCP Query User{34EB02A4-BE6F-4BB1-926A-27B8C548A6DC}C:\program files (x86)\internet explorer
\iexplore.exe" = protocol=6 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe
|
"TCP Query User{449B8EC9-919D-4EA3-8542-7DA6CB4FA3FD}C:\users\———\appdata\local\akamai
\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\———\appdata\local\akamai
\netsession_win.exe |
"TCP Query User{80D64307-718F-4C8C-B5F7-EA2F70AEA432}C:\program files (x86)\java\jre7\bin
\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
"TCP Query User{AD5DB7F4-0B9A-44CD-949E-5C5E9135A5BF}C:\program files (x86)\google\google earth
\plugin\geplugin.exe" = protocol=6 | dir=in | app=c:\program files (x86)\google\google earth
\plugin\geplugin.exe |
"TCP Query User{D30290B4-11CA-47A8-9FCD-AB33CD64F007}C:\windows\system32\mmc.exe" = protocol=6 |
dir=in | app=c:\windows\system32\mmc.exe |
"UDP Query User{4E3EE254-F6E9-44DC-99F0-3878DA1DE6CD}C:\windows\system32\mmc.exe" = protocol=17 |
dir=in | app=c:\windows\system32\mmc.exe |
"UDP Query User{5D0E89DB-26D3-47C0-B07E-C4B5EAA875CE}C:\users\———\appdata\local\akamai
\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\———\appdata\local\akamai
\netsession_win.exe |
"UDP Query User{AAC17B1E-E083-4C89-879B-F09D272CCA13}C:\program files (x86)\internet explorer
\iexplore.exe" = protocol=17 | dir=in | app=c:\program files (x86)\internet explorer\iexplore.exe
|
"UDP Query User{ED963E8A-FFE2-4D59-B09F-63B51917602D}C:\program files (x86)\google\google earth
\plugin\geplugin.exe" = protocol=17 | dir=in | app=c:\program files (x86)\google\google earth
\plugin\geplugin.exe |
"UDP Query User{FDA21321-1E95-4C22-9511-AA6321500290}C:\program files (x86)\java\jre7\bin
\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre7\bin\javaw.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0279C882-B150-44B6-A769-A7C8A2F31CE3}" = HP Wireless Assistant
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{26A24AE4-039D-4CA4-87B4-2F86417025FF}" = Java 7 Update 25 (64-bit)
"{290D4DB2-F1B4-4B8E-918D-D71EF29A001B}" = Intel® PROSet/Wireless WiFi Software
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{377672F0-6B8A-467D-8DDC-79338BCCD531}" = 64 Bit HP CIO Components Installer
"{427174C0-096E-40D9-9684-9C109BEE2CBF}" = iTunes
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64
9.0.30729.4148
"{5BF97E02-2F6A-412A-BB4D-B6E2DC65FCA7}" = HP SimplePass Identity Protection
"{5EB6F3CB-46F4-451F-A028-7F6D8D35D7D0}" = Windows Live Language Selector
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64
9.0.30729.6161
"{5FDC06BF-3D3D-4367-8FFB-4FAFCB61972D}" = Cisco Systems VPN Client 5.0.07.0440
"{624C7F0A-89B2-4C49-9CAB-9D69613EC95A}" = Microsoft IntelliPoint 8.2
"{62BB6851-C373-47F7-B566-38D2E16FE2A6}" = DyKnow x64
"{64A3A4F4-B792-11D6-A78A-00B0D0170250}" = Java SE Development Kit 7 Update 25 (64-bit)
"{64A9C5B3-D166-4C6D-A11E-A54473151000}" = Java 3D 1.5.1 (x64)
"{69D65833-4A83-267A-7DB4-9FCBBE72675D}" = ATI Catalyst Install Manager
"{6BFAB6C1-6D46-46DB-A538-A269907C9F2F}" = Network64
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{704C0303-D20C-45AF-BD2B-556EAF31BE09}" = iCloud
"{731A1D36-BF17-4C76-B7E7-CC055AF8C54E}" = HP MediaSmart SmartMenu
"{791A06E2-340F-43B0-8FAB-62D151339362}" = HP Officejet Pro 8600 Basic Device Software
"{7D220A57-969F-4D09-9297-D48195A8ABDD}" = HP Deskjet 3050 J610 series Basic Device Software
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64
9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174
- x64 9.0.30729.5570
"{85A42FF0-F0D0-44A3-B226-C124D6E8B1D5}" = HP 3D DriveGuard
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI
(English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A269F383-3E55-DAFF-F948-655FDB3DB58A}" = ccc-utility64
"{A4DDB2AB-ECCD-4C3A-8633-77D5A1A0E542}" = Network64
"{CB6508F6-EC50-4829-A2C6-02990EFF0059}" = Windows Media Encoder 9 Series x64 Edition
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{E5083D57-D93F-404C-A91F-1C50D67C2BEB}" = HP Officejet 4500 G510g-m
"{EE5017A6-7525-4EE9-99DA-2EF1F6C16B1B}" = Validity Sensors DDK
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"CCleaner" = CCleaner
"Defraggler" = Defraggler
"HP Document Manager" = HP Document Manager 2.0
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Smart Web Printing" = HP Smart Web Printing 4.5
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"HPOCR" = OCR Software by I.R.I.S. 13.0
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft IntelliPoint 8.2" = Microsoft IntelliPoint 8.2
"nbi-nb-base-[removed].0" = NetBeans IDE 7.1.2
"ProInst" = Intel PROSet Wireless
"SynTPDeinstKey" = Synaptics Pointing Device Driver
"Windows Media Encoder 9" = Windows Media Encoder 9 Series x64 Edition
"WinRAR archiver" = WinRAR 4.20 (64-bit)
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"{024DE942-267A-4B60-A1C0-70C1163E0355}" = CCC Help Korean
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08C94F9D-EB51-D748-E299-E347A2C14A81}" = PX Profile Update
"{0A5B39D2-7ED6-4779-BCC9-37F381139DB3}" = Adobe AIR
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan
"{15353551-375C-8E5A-5CAF-A4564C1CC2A5}" = ccc-core-static
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{15C418EB-7675-42be-B2B3-281952DA014D}" = Sophos AutoUpdate
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1a413f37-ed88-4fec-9666-5c48dc4b7bb7}" = YTD Video Downloader 3.9
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86
9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{205C6BDD-7B73-42DE-8505-9A093F35A238}" = Windows Live Upload Tool
"{20B88A14-02F9-48D4-ACEC-6D8F5F3E8A83}" = HP User Guides 0176
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{21E2508C-D5F4-44C6-C224-456DDA341BBB}" = CCC Help Turkish
"{26A24AE4-039D-4CA4-87B4-2F83217025FF}" = Java 7 Update 25
"{28379381-B56A-43e1-B505-3098D82B1C30}" = 4500G510gm_Software_Min
"{29E70460-51CA-45A1-B76B-C2B69FE908DE}" = MediSpell for Microsoft Word
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update
"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"{32D2E8C3-452A-69E9-21CF-C55E0612C974}" = CCC Help Chinese Traditional
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{3877C901-7B90-4727-A639-B6ED2DD59D43}" = ESU for Microsoft Windows 7
"{394FA67A-FF0A-4356-BB77-D85E5A300BDE}" = HP QuickWeb Installer
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40FB8D7C-6FF8-4AF2-BC8B-0B1DB32AF04B}" = HP Advisor
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{440B915A-0C85-45DB-92AE-75AE14704A64}" = Fax
"{4453AA9B-867A-17DB-C429-E9A64F0FB77F}" = CCC Help Finnish
"{44653096-3E44-402E-B68E-37D77240BFA8}" = Symyx Draw 4.0.0
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{46F2A322-7A34-4EEC-B7FA-62A2F3DAB44A}" = UofRMachineCheck
"{485B9C29-6B47-22AF-022A-F9D65292F3A7}" = CCC Help English
"{4893B2BB-5C9B-7E6C-4BAD-BDFBAB33184A}" = Catalyst Control Center Localization All
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4CBABDFD-49F8-47FD-BE7D-ECDE7270525A}" = Windows Live PIMT Platform
"{4CFE23CC-779D-4572-A76F-AB60A958BC79}" = Adobe Flash Player 11 ActiveX
"{50C1A63E-4653-9DBE-E8E4-28DF2778BED0}" = CCC Help Polish
"{5725E5CA-A91D-C903-99DB-F8C010E0B637}" = Catalyst Control Center InstallProxy
"{5A89BFD5-12DB-038F-DBCE-58832B82D824}" = CCC Help Norwegian
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68A10D12-0D0F-4212-BDE6-D87FAD32A8FA}" = SmartWebPrinting
"{68A35043-C55A-4237-88C9-37EE1C63ED71}" = Microsoft Visual J# 2.0 Redistributable Package
"{69FDFBB6-351D-4B8C-89D8-867DC9D0A2A4}" = Windows Media Player Firefox Plugin
"{6A05FEDF-662E-46BF-8A25-010E3F1C9C69}" = Windows Live UX Platform Language Pack
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6C302296-6129-4125-9FD6-2188ECD8814E}" = HP Software Framework
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.1.1
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79361740-EAE3-11E2-9911-B8AC6F98CCE3}" = Google Earth Plug-in
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{81ED0B01-4DE2-CD82-F927-2E4C6208349A}" = PX Profile Update
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{85D10697-A1D4-472A-2114-E07A77019BE1}" = CCC Help Japanese
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174
- x86 9.0.30729.5570
"{87909077-445C-976C-0D23-D6C367B422D6}" = CCC Help Danish
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{8DD0171B-2ED1-311C-882E-AD3EC3A77A7E}" = CCC Help Czech
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" =
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" =
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" =
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}_SMALLBUSINESSR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" =
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" =
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}_SMALLBUSINESSR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" =
Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_SMALLBUSINESSR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_SMALLBUSINESSR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English)
2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}_SMALLBUSINESSR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_SMALLBUSINESSR_{98333358-268C-4164-B6D4-C96DF5153727}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{9087C601-4B52-C0F0-D4EF-4C98DEC1D6B0}" = CCC Help Portuguese
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{91120000-00CA-0000-0000-0000000FF1CE}" = Microsoft Office Small Business 2007
"{91120000-00CA-0000-0000-0000000FF1CE}_SMALLBUSINESSR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" =
Microsoft Office 2007 Service Pack 3 (SP3)
"{91B82CC7-F33E-211B-DFD6-0A91B637B455}" = CCC Help Greek
"{925A0B4E-F885-997B-8A74-E8E7A2FAC049}" = CCC Help French
"{92A51949-EE4C-466D-AAF0-99E74A49A63F}" = DocMgr
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{96AE7E41-E34E-47D0-AC07-1091A8127911}" = Realtek USB 2.0 Card Reader
"{96B7FD92-0D96-7C04-5D1C-D6CF70202403}" = CCC Help Hungarian
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86
9.0.30729.17
"{9ACB414D-9347-40B6-A453-5EFB2DB59DFA}" = Sophos Anti-Virus
"{9B362566-EC1B-4700-BB9C-EC661BDE2175}" = DocProc
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86
9.0.30729.6161
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{A18E4E3A-5013-E319-AB36-4FDE7483AA5D}" = CCC Help Spanish
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AB7D24EC-BB5A-E746-C5D2-526BBE6C36AD}" = Catalyst Control Center Graphics Previews Vista
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.7)
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{BA688606-4B20-4982-995E-EDADC6A6817E}" = League of Legends
"{BB0030F2-DA47-FABF-D3F2-903FA253D56D}" = CCC Help Thai
"{BB1C717E-376C-4AA1-8940-81BFC38D9778}" = HP Quick Launch
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{BE0D4271-69C9-4f28-AD9B-BB33D126A30E}" = 4500G510gm
"{BFBC6337-B7B9-4AEE-BC19-CA910EED755D}" = Adobe Flash Player 11 Plugin
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{CA6BCA2F-EDEB-408F-850B-31404BE16A61}" = I.R.I.S. OCR
"{CB8ABF7D-B3F7-D774-645B-0DCD0297D9FA}" = CCC Help German
"{CC7553CB-AB4E-5BCA-DC44-54D823B83E60}" = Catalyst Control Center InstallProxy
"{CD9A1574-197A-156D-9D8C-39D68AE9B7A6}" = CCC Help Russian
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D6C630BF-8DBB-4042-8562-DC9A52CB6E7E}" = Intel® Turbo Boost Technology Driver
"{D7C73761-237A-2B01-6DB5-E76276223C3B}" = CCC Help Italian
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DD082978-011E-7058-8252-15E2E1AAFABB}" = CCC Help Dutch
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DF0B357C-5874-47D0-81E7-79AA890B0CE0}" = 4500_G510gm_Help
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E2831862-F131-4327-B9CC-FA30F587EB6C}" = HP Setup
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E7C97E98-4C2D-BEAF-5D2F-CC45A2F95D90}" = Acrobat.com
"{EB38C3E0-4863-3123-9114-5BE86EC8E5C7}" = Google Talk Plugin
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EE202411-2C26-49E8-9784-1BC1DBF7DE96}" = HP Support Assistant
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F7632A9B-661E-4FD9-B1A4-3B86BC99847F}" = HP Deskjet 3050 J610 series Help
"{FA3B4B32-D753-672D-842C-946644FEFC0A}" = CCC Help Swedish
"{FCDBEA60-79F0-4FAE-BBA8-55A26C609A49}" = Visual Studio 2008 x64 Redistributables
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FED1005D-CBC8-45D5-A288-FFC7BB304121}" = Sophos Remote Management System
"{FF6FA054-25B9-1CA2-D22A-DFD87735E9F6}" = CCC Help Chinese Standard
"Adobe AIR" = Adobe AIR
"Adobe Digital Editions 2.0" = Adobe Digital Editions 2.0
"Adobe Shockwave Player" = Adobe Shockwave Player 12.0
"Akamai" = Akamai NetSession Interface Service
"AutoHotkey" = AutoHotkey 1.0.48.05
"Carbonite Backup" = Carbonite
"com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Acrobat.com
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = HP MediaSmart Webcam
"InstallShield_{3023EBDA-BF1B-4831-B347-E5018555F26E}" = Movie Theme Pack for HP MediaSmart Video
"InstallShield_{62BB6851-C373-47F7-B566-38D2E16FE2A6}" = DyKnow x64
"LastPass" = LastPass (uninstall only)
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft Visual J# 2.0 Redistributable Package" = Microsoft Visual J# 2.0 Redistributable
Package
"Notepad++" = Notepad++
"Revo Uninstaller" = Revo Uninstaller 1.95
"Secunia PSI" = Secunia PSI (3.0.0.7011)
"SMALLBUSINESSR" = Microsoft Office Small Business 2007
"TrueCrypt" = TrueCrypt
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office
system 3.0 Runtime
"VLC media player" = VLC media player 2.0.8
"WinLiveSuite" = Windows Live Essentials
"YTdetect" = Yahoo! Detect
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Akamai" = Akamai NetSession Interface
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 8/29/2013 12:12:22 PM | Computer Name = ——— | Source = VSS | ID = 8193
Description =
Error - 8/29/2013 1:21:24 PM | Computer Name = ——— | Source = Sophos Message Router | ID =
8006
Description = The network identity (also known as the Interoperable Object Reference
or IOR) of the local computer is invalid.%3
Error - 8/31/2013 12:00:53 AM | Computer Name = ——— | Source = Sophos Message Router | ID =
8006
Description = The network identity (also known as the Interoperable Object Reference
or IOR) of the local computer is invalid.%3
Error - 8/31/2013 12:11:25 AM | Computer Name = ——— | Source = VSS | ID = 8193
Description =
Error - 8/31/2013 12:19:27 AM | Computer Name = ——— | Source = Microsoft-Windows-
RestartManager | ID = 10006
Description = Application or service 'Google Chrome' could not be shut down.
Error - 8/31/2013 1:43:15 PM | Computer Name = ——— | Source = Application Error | ID = 1000
Description = Faulting application name: SearchProtocolHost.exe, version: 7.0.7601.17610,
time stamp: 0x4dc0d006 Faulting module name: ntdll.dll, version: 6.1.7601.18205,
time stamp: 0x51dba4e7 Exception code: 0xc0000005 Fault offset: 0x0000000000021cfa
Faulting
process id: 0x2558 Faulting application start time: 0x01cea6717f75eace Faulting application
path: C:\Windows\system32\SearchProtocolHost.exe Faulting module path: C:\Windows
\SYSTEM32\ntdll.dll
Report
Id: cfe9ecbb-1264-11e3-87bb-c80aa9a0041a
Error - 8/31/2013 3:42:05 PM | Computer Name = ——– | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
Error - 8/31/2013 3:42:06 PM | Computer Name = ——– | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 1030
Error - 8/31/2013 3:42:06 PM | Computer Name = ——– | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 1030
Error - 8/31/2013 7:15:33 PM | Computer Name = ——– | Source = VSS | ID = 8193
Description =
[ Hewlett-Packard Events ]
Error - 7/5/2012 9:14:16 PM | Computer Name = ——– | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at
HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3893 Ram Utilization: TargetSite: Void UpdateAndDetect()
Error - 7/5/2012 9:15:34 PM | Computer Name = ——– | Source = HPSF.exe | ID = 4000
Description =
Error - 7/5/2012 9:15:58 PM | Computer Name = ——– | Source = HPSF.exe | ID = 4000
Description =
Error - 7/5/2012 9:16:23 PM | Computer Name = ——– | Source = HPSF.exe | ID = 4000
Description =
Error - 7/12/2012 9:33:35 PM | Computer Name = ——– | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at
HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3893 Ram Utilization: 70 TargetSite: Void UpdateAndDetect()
Error - 7/19/2012 9:11:55 PM | Computer Name = ——– | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at
HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3893 Ram Utilization: 70 TargetSite: Void UpdateAndDetect()
Error - 7/26/2012 9:41:46 PM | Computer Name = ——– | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at
HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3893 Ram Utilization: 60 TargetSite: Void UpdateAndDetect()
Error - 8/2/2012 9:18:59 PM | Computer Name = ——– | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at
HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3893 Ram Utilization: 70 TargetSite: Void UpdateAndDetect()
Error - 8/9/2012 10:52:15 PM | Computer Name = ——– | Source = HPSF.exe | ID = 4000
Description =
Error - 8/9/2012 10:52:33 PM | Computer Name = ——– | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at
HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Message: One HP Active Check Local Mode job already running. StackTrace:
at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.UpdateAndDetect()
at HP.SupportAssistant.Service.ACLM.ActiveCheck.LaunchActiveCheck(Boolean singleScan,
Boolean localScan) Source: HP.ActiveCheckLocalMode.SessionManager Name: hpsa_service.exe
Version:
06.00.01.01 Path: C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe
Format:
en-US RAM: 3893 Ram Utilization: 80 TargetSite: Void UpdateAndDetect()
[ HP Wireless Assistant Events ]
Error - 8/29/2013 12:11:53 PM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = System.Exception GetDeviceInfo() failed : 597 at
HP_Common.CaslWrapper.GetDeviceInfo(List`1&
radioList) at HPPA_Service.CurrentConfiguration.ReloadRadioList()
Error - 8/29/2013 12:12:02 PM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = System.Exception GetDeviceInfo() failed : 597 at
HP_Common.CaslWrapper.GetDeviceInfo(List`1&
radioList) at HPPA_Service.CurrentConfiguration.ReloadRadioList()
Error - 8/29/2013 12:12:05 PM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = System.Exception GetDeviceInfo() failed : 597 at
HP_Common.CaslWrapper.GetDeviceInfo(List`1&
radioList) at HPPA_Service.CurrentConfiguration.ReloadRadioList()
Error - 8/29/2013 12:12:16 PM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = System.Runtime.InteropServices.COMException The interface is unknown.
(Exception from HRESULT: 0x800706B5) at
System.Runtime.InteropServices.Marshal.ThrowExceptionForHRInternal(Int32
errorCode, IntPtr errorInfo) at System.Management.ManagementScope.InitializeGuts(Object
o) at System.Management.ManagementScope.Initialize() at
System.Management.ManagementObject.Initialize(Boolean
getObject) at System.Management.ManagementBaseObject.get_Properties() at
System.Management.ManagementBaseObject.GetPropertyValue(String
propertyName) at HPPA_Service.CurrentConfiguration.b__c()
Error - 8/29/2013 1:20:25 PM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = GetPanelBrightnessTables() failed : e_BIOS_INVALID_COMMAND_TYPE
Error - 8/31/2013 12:03:32 AM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = GetPanelBrightnessTables() failed : e_BIOS_INVALID_COMMAND_TYPE
Error - 8/31/2013 5:26:14 AM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = GetPanelBrightnessTables() failed : e_BIOS_INVALID_COMMAND_TYPE
Error - 8/31/2013 5:26:14 AM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = Unable to access panel brightness tables.
Error - 8/31/2013 11:08:22 AM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = GetPanelBrightnessTables() failed : e_BIOS_INVALID_COMMAND_TYPE
Error - 8/31/2013 11:08:22 AM | Computer Name = ——– | Source = HP WA Service | ID = 0
Description = Unable to access panel brightness tables.
[ OSession Events ]
Error - 7/28/2011 9:36:29 PM | Computer Name = ———-PC | Source = Microsoft Office 12
Sessions
| ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6557.5000, Microsoft Office Version: 12.0.6425.1000. This session lasted 24659
seconds with 60 seconds of active time. This session ended with a crash.
Error - 8/23/2011 8:55:30 PM | Computer Name = ———-PC | Source = Microsoft Office 12
Sessions
| ID = 7001
Description = ID: 6, Application Name: Microsoft Office Outlook, Application Version:
12.0.6557.5001, Microsoft Office Version: 12.0.6425.1000. This session lasted 1572
seconds with 60 seconds of active time. This session ended with a crash.
Error - 9/4/2012 9:27:01 PM | Computer Name = ——– | Source = Microsoft Office 12 Sessions |
ID
= 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 2527
seconds with 240 seconds of active time. This session ended with a crash.
Error - 9/11/2012 11:08:42 PM | Computer Name = ——– | Source = Microsoft Office 12 Sessions
|
ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 8287
seconds with 240 seconds of active time. This session ended with a crash.
Error - 10/19/2012 5:48:00 PM | Computer Name = ——– | Source = Microsoft Office 12 Sessions
|
ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6661.5000, Microsoft Office Version: 12.0.6612.1000. This session lasted 154823
seconds with 0 seconds of active time. This session ended with a crash.
Error - 11/12/2012 12:32:38 AM | Computer Name = ——— | Source = Microsoft Office 12
Sessions |
ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 557
seconds with 420 seconds of active time. This session ended with a crash.
Error - 11/12/2012 12:39:14 AM | Computer Name = ——— | Source = Microsoft Office 12
Sessions |
ID = 7001
Description = ID: 0, Application Name: Microsoft Office Word, Application Version:
12.0.6662.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 383
seconds with 60 seconds of active time. This session ended with a crash.
Error - 2/27/2013 11:20:44 AM | Computer Name = ——— | Source = Microsoft Office 12 Sessions
|
ID = 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 90280
seconds with 5400 seconds of active time. This session ended with a crash.
Error - 4/1/2013 1:47:06 PM | Computer Name = ——— | Source = Microsoft Office 12 Sessions |
ID
= 7001
Description = ID: 1, Application Name: Microsoft Office Excel, Application Version:
12.0.6665.5003, Microsoft Office Version: 12.0.6612.1000. This session lasted 79313
seconds with 3660 seconds of active time. This session ended with a crash.
Error - 4/3/2013 10:33:33 PM | Computer Name = ——— | Source = Microsoft Office 12 Sessions
|
ID = 7001
Description = ID: 3, Application Name: Microsoft Office PowerPoint, Application
Version: 12.0.6600.1000, Microsoft Office Version: 12.0.6612.1000. This session
lasted 703 seconds with 600 seconds of active time. This session ended with a crash.
[ System Events ]
Error - 8/30/2013 10:18:48 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:18:48 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:23:02 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:23:02 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:23:02 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:23:48 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:23:48 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/30/2013 10:23:48 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7001
Description = The Computer Browser service depends on the Server service which failed
to start because of the following error: %%1068
Error - 8/31/2013 12:02:30 AM | Computer Name = ——— | Source = DCOM | ID = 10016
Description =
Error - 8/31/2013 5:33:46 PM | Computer Name = ——— | Source = Service Control Manager | ID
=
7031
Description = The Sophos Message Router service terminated unexpectedly. It has
done this 1 time(s). The following corrective action will be taken in 60000 milliseconds:
Restart the service.
< End of report >