This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Computer Freezing Up [Closed]

38 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

Ok Freyja :)

Run this:


Please read carefully and follow these steps.
06:59:54.0745 6504 TDSS rootkit removing tool 2.8.16.0 Feb 11 2013 18:50:42 06:59:55.0390 6504 ============================================================ 06:59:55.0390 6504 Current date / time: 2013/09/10 06:59:55.0390 06:59:55.0390 6504 SystemInfo: 06:59:55.0390 6504 06:59:55.0390 6504 OS Version: 6.0.6002 ServicePack: 2.0 06:59:55.0390 6504 Product type: Workstation 06:59:55.0391 6504 ComputerName: KARRI-PC 06:59:55.0391 6504 UserName: Karri 06:59:55.0391 6504 Windows directory: C:\Windows 06:59:55.0391 6504 System windows directory: C:\Windows 06:59:55.0391 6504 Running under WOW64 06:59:55.0391 6504 Processor architecture: Intel x64 06:59:55.0391 6504 Number of processors: 4 06:59:55.0391 6504 Page size: 0x1000 06:59:55.0391 6504 Boot type: Normal boot 06:59:55.0391 6504 ============================================================ 06:59:55.0861 6504 Drive \Device\Harddisk0\DR0 - Size: 0x950B056000 (596.17 Gb), SectorSize: 0x200, Cylinders: 0x13001, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'K0', Flags 0x00000040 06:59:55.0881 6504 Drive \Device\Harddisk6\DR6 - Size: 0xE8C4BA0000 (931.07 Gb), SectorSize: 0x200, Cylinders: 0x1DAC7, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 07:00:02.0778 6504 Drive \Device\Harddisk7\DR7 - Size: 0xF2C00000 (3.79 Gb), SectorSize: 0x200, Cylinders: 0x1EF, SectorsPerTrack: 0x3F, TracksPerCylinder: 0xFF, Type 'W' 07:00:02.0780 6504 ============================================================ 07:00:02.0780 6504 \Device\Harddisk0\DR0: 07:00:02.0780 6504 MBR partitions: 07:00:02.0780 6504 \Device\Harddisk0\DR0\Partition1: MBR, Type 0x7, StartLBA 0x1D4F800, BlocksNum 0x1D12D000 07:00:02.0780 6504 \Device\Harddisk0\DR0\Partition2: MBR, Type 0x7, StartLBA 0x1EE7C800, BlocksNum 0x2B9DB000 07:00:02.0780 6504 \Device\Harddisk6\DR6: 07:00:02.0781 6504 MBR partitions: 07:00:02.0781 6504 \Device\Harddisk6\DR6\Partition1: MBR, Type 0xC, StartLBA 0x3F, BlocksNum 0x746221C8 07:00:02.0781 6504 \Device\Harddisk7\DR7: 07:00:02.0782 6504 MBR partitions: 07:00:02.0782 6504 \Device\Harddisk7\DR7\Partition1: MBR, Type 0xB, StartLBA 0x2000, BlocksNum 0x794000 07:00:02.0782 6504 ============================================================ 07:00:02.0810 6504 C: <-> \Device\Harddisk0\DR0\Partition1 07:00:02.0847 6504 D: <-> \Device\Harddisk0\DR0\Partition2 07:00:02.0848 6504 O: <-> \Device\Harddisk6\DR6\Partition1 07:00:02.0848 6504 ============================================================ 07:00:02.0848 6504 Initialize success 07:00:02.0848 6504 ============================================================ 07:00:14.0812 2432 ============================================================ 07:00:14.0812 2432 Scan started 07:00:14.0812 2432 Mode: Manual; 07:00:14.0812 2432 ============================================================ 07:00:15.0119 2432 ================ Scan system memory ======================== 07:00:15.0119 2432 System memory - ok 07:00:15.0120 2432 ================ Scan services ============================= 07:00:15.0229 2432 [ 517D30057C726C797764BFD70A55D82A ] Acer HomeMedia Connect Service C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe 07:00:15.0231 2432 Acer HomeMedia Connect Service - ok 07:00:15.0334 2432 [ 1965AAFFAB07E3FB03C77F81BEBA3547 ] ACPI C:\Windows\system32\drivers\acpi.sys 07:00:15.0337 2432 ACPI - ok 07:00:15.0434 2432 [ ADDA5E1951B90D3D23C56D3CF0622ADC ] AdobeARMservice C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe 07:00:15.0434 2432 AdobeARMservice - ok 07:00:15.0539 2432 [ 476BB014F3F68C0C15EDDD5B444DA8FF ] AdobeFlashPlayerUpdateSvc C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe 07:00:15.0540 2432 AdobeFlashPlayerUpdateSvc - ok 07:00:15.0570 2432 [ F14215E37CF124104575073F782111D2 ] adp94xx C:\Windows\system32\drivers\adp94xx.sys 07:00:15.0596 2432 adp94xx - ok 07:00:15.0638 2432 [ 7D05A75E3066861A6610F7EE04FF085C ] adpahci C:\Windows\system32\drivers\adpahci.sys 07:00:15.0654 2432 adpahci - ok 07:00:15.0671 2432 [ 820A201FE08A0C345B3BEDBC30E1A77C ] adpu160m C:\Windows\system32\drivers\adpu160m.sys 07:00:15.0678 2432 adpu160m - ok 07:00:15.0703 2432 [ 9B4AB6854559DC168FBB4C24FC52E794 ] adpu320 C:\Windows\system32\drivers\adpu320.sys 07:00:15.0711 2432 adpu320 - ok 07:00:15.0745 2432 [ 0F421175574BFE0BF2F4D8E910A253BB ] AeLookupSvc C:\Windows\System32\aelupsvc.dll 07:00:15.0746 2432 AeLookupSvc - ok 07:00:15.0789 2432 [ C4F6CE6087760AD70960C9EB130E7943 ] AFD C:\Windows\system32\drivers\afd.sys 07:00:15.0812 2432 AFD - ok 07:00:15.0830 2432 [ F6F6793B7F17B550ECFDBD3B229173F7 ] agp440 C:\Windows\system32\drivers\agp440.sys 07:00:15.0837 2432 agp440 - ok 07:00:15.0853 2432 [ 222CB641B4B8A1D1126F8033F9FD6A00 ] aic78xx C:\Windows\system32\drivers\djsvs.sys 07:00:15.0860 2432 aic78xx - ok 07:00:15.0886 2432 [ 5922F4F59B7868F3D74BBBBEB7B825A3 ] ALG C:\Windows\System32\alg.exe 07:00:15.0887 2432 ALG - ok 07:00:15.0903 2432 [ 157D0898D4B73F075CE9FA26B482DF98 ] aliide C:\Windows\system32\drivers\aliide.sys 07:00:15.0908 2432 aliide - ok 07:00:15.0923 2432 [ 970FA5059E61E30D25307B99903E991E ] amdide C:\Windows\system32\drivers\amdide.sys 07:00:15.0928 2432 amdide - ok 07:00:15.0938 2432 [ CDC3632A3A5EA4DBB83E46076A3165A1 ] AmdK8 C:\Windows\system32\drivers\amdk8.sys 07:00:15.0944 2432 AmdK8 - ok 07:00:16.0029 2432 [ 746497D339C854053193119D119799BA ] AntiVirSchedulerService C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe 07:00:16.0030 2432 AntiVirSchedulerService - ok 07:00:16.0058 2432 [ A2D4915D1CCD0338AB85F14D1C22FD0C ] AntiVirService C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe 07:00:16.0059 2432 AntiVirService - ok 07:00:16.0096 2432 [ 616D075E0DA5B6674D572372F1B6727E ] AntiVirWebService C:\Program Files (x86)\Avira\AntiVir Desktop\AVWEBGRD.EXE 07:00:16.0102 2432 AntiVirWebService - ok 07:00:16.0163 2432 [ D41231AECFEE88973D56AEC2EE5B962D ] APNMCP C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe 07:00:16.0164 2432 APNMCP - ok 07:00:16.0208 2432 [ 9C37B3FD5615477CB9A0CD116CF43F5C ] Appinfo C:\Windows\System32\appinfo.dll 07:00:16.0209 2432 Appinfo - ok 07:00:16.0296 2432 [ 4FE5C6D40664AE07BE5105874357D2ED ] Apple Mobile Device C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe 07:00:16.0297 2432 Apple Mobile Device - ok 07:00:16.0326 2432 [ BA8417D4765F3988FF921F30F630E303 ] arc C:\Windows\system32\drivers\arc.sys 07:00:16.0333 2432 arc - ok 07:00:16.0369 2432 [ 9D41C435619733B34CC16A511E644B11 ] arcsas C:\Windows\system32\drivers\arcsas.sys 07:00:16.0377 2432 arcsas - ok 07:00:16.0479 2432 [ 9217D874131AE6FF8F642F124F00A555 ] aspnet_state C:\Windows\Microsoft.NET\Framework64\v4.0.30319\aspnet_state.exe 07:00:16.0486 2432 aspnet_state - ok 07:00:16.0506 2432 [ 22D13FF3DAFEC2A80634752B1EAA2DE6 ] AsyncMac C:\Windows\system32\DRIVERS\asyncmac.sys 07:00:16.0510 2432 AsyncMac - ok 07:00:16.0527 2432 [ 1898FAE8E07D97F2F6C2D5326C633FAC ] atapi C:\Windows\system32\drivers\atapi.sys 07:00:16.0527 2432 atapi - ok 07:00:16.0559 2432 [ 79318C744693EC983D20E9337A2F8196 ] AudioEndpointBuilder C:\Windows\System32\Audiosrv.dll 07:00:16.0563 2432 AudioEndpointBuilder - ok 07:00:16.0576 2432 [ 79318C744693EC983D20E9337A2F8196 ] AudioSrv C:\Windows\System32\Audiosrv.dll 07:00:16.0579 2432 AudioSrv - ok 07:00:16.0613 2432 [ 0D5C96FD25D6455D97A5C4D7706DFAB1 ] avgntflt C:\Windows\system32\DRIVERS\avgntflt.sys 07:00:16.0621 2432 avgntflt - ok 07:00:16.0660 2432 [ E26B3C8E9C3DDE047B32C5719955D715 ] avipbb C:\Windows\system32\DRIVERS\avipbb.sys 07:00:16.0668 2432 avipbb - ok 07:00:16.0694 2432 [ 490FA25161BF3E51993EB724ECF0ACEB ] avkmgr C:\Windows\system32\DRIVERS\avkmgr.sys 07:00:16.0700 2432 avkmgr - ok 07:00:16.0720 2432 Beep - ok 07:00:16.0756 2432 [ FFB96C2589FFA60473EAD78B39FBDE29 ] BFE C:\Windows\System32\bfe.dll 07:00:16.0760 2432 BFE - ok 07:00:16.0814 2432 [ 6D316F4859634071CC25C4FD4589AD2C ] BITS C:\Windows\system32\qmgr.dll 07:00:16.0838 2432 BITS - ok 07:00:16.0864 2432 [ 79FEEB40056683F8F61398D81DDA65D2 ] blbdrive C:\Windows\system32\drivers\blbdrive.sys 07:00:16.0865 2432 blbdrive - ok 07:00:16.0939 2432 [ EBBCD5DFBB1DE70E8F4AF8FA59E401FD ] Bonjour Service C:\Program Files\Bonjour\mDNSResponder.exe 07:00:16.0942 2432 Bonjour Service - ok 07:00:16.0976 2432 [ 2348447A80920B2493A9B582A23E81E1 ] bowser C:\Windows\system32\DRIVERS\bowser.sys 07:00:16.0982 2432 bowser - ok 07:00:17.0005 2432 [ F09EEE9EDC320B5E1501F749FDE686C8 ] BrFiltLo C:\Windows\system32\drivers\brfiltlo.sys 07:00:17.0009 2432 BrFiltLo - ok 07:00:17.0021 2432 [ B114D3098E9BDB8BEA8B053685831BE6 ] BrFiltUp C:\Windows\system32\drivers\brfiltup.sys 07:00:17.0025 2432 BrFiltUp - ok 07:00:17.0060 2432 [ A1B39DE453433B115B4EA69EE0343816 ] Browser C:\Windows\System32\browser.dll 07:00:17.0061 2432 Browser - ok 07:00:17.0076 2432 [ F0F0BA4D815BE446AA6A4583CA3BCA9B ] Brserid C:\Windows\system32\drivers\brserid.sys 07:00:17.0083 2432 Brserid - ok 07:00:17.0097 2432 [ A6ECA2151B08A09CACECA35C07F05B42 ] BrSerWdm C:\Windows\system32\drivers\brserwdm.sys 07:00:17.0103 2432 BrSerWdm - ok 07:00:17.0127 2432 [ B79968002C277E869CF38BD22CD61524 ] BrUsbMdm C:\Windows\system32\drivers\brusbmdm.sys 07:00:17.0131 2432 BrUsbMdm - ok 07:00:17.0142 2432 [ A87528880231C54E75EA7A44943B38BF ] BrUsbSer C:\Windows\system32\drivers\brusbser.sys 07:00:17.0146 2432 BrUsbSer - ok 07:00:17.0158 2432 [ E0777B34E05F8A82A21856EFC900C29F ] BTHMODEM C:\Windows\system32\drivers\bthmodem.sys 07:00:17.0163 2432 BTHMODEM - ok 07:00:17.0193 2432 [ 09E6AFFAE6C0E9158BF05C7D08D0107A ] BUNAgentSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\Client\Agentsvc.exe 07:00:17.0193 2432 BUNAgentSvc - ok 07:00:17.0223 2432 c2wts - ok 07:00:17.0226 2432 catchme - ok 07:00:17.0281 2432 [ 3D50891CAA71E3479A8A10F25CA9207F ] cbfs3 C:\Windows\system32\drivers\cbfs3.sys 07:00:17.0297 2432 cbfs3 - ok 07:00:17.0303 2432 [ B4D787DB8D30793A4D4DF9FEED18F136 ] cdfs C:\Windows\system32\DRIVERS\cdfs.sys 07:00:17.0308 2432 cdfs - ok 07:00:17.0345 2432 [ C025AA69BE3D0D25C7A2E746EF6F94FC ] cdrom C:\Windows\system32\DRIVERS\cdrom.sys 07:00:17.0351 2432 cdrom - ok 07:00:17.0385 2432 [ 5A268127633C7EE2A7FB87F39D748D56 ] CertPropSvc C:\Windows\System32\certprop.dll 07:00:17.0394 2432 CertPropSvc - ok 07:00:17.0415 2432 [ 02EA568D498BBDD4BA55BF3FCE34D456 ] circlass C:\Windows\system32\drivers\circlass.sys 07:00:17.0437 2432 circlass - ok 07:00:17.0486 2432 [ 3DCA9A18B204939CFB24BEA53E31EB48 ] CLFS C:\Windows\system32\CLFS.sys 07:00:17.0497 2432 CLFS - ok 07:00:17.0561 2432 [ 8EE772032E2FE80A924F3B8DD5082194 ] clr_optimization_v2.0.50727_32 C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe 07:00:17.0570 2432 clr_optimization_v2.0.50727_32 - ok 07:00:17.0626 2432 [ CE07A466201096F021CD09D631B21540 ] clr_optimization_v2.0.50727_64 C:\Windows\Microsoft.NET\Framework64\v2.0.50727\mscorsvw.exe 07:00:17.0634 2432 clr_optimization_v2.0.50727_64 - ok 07:00:17.0697 2432 [ C5A75EB48E2344ABDC162BDA79E16841 ] clr_optimization_v4.0.30319_32 C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe 07:00:17.0698 2432 clr_optimization_v4.0.30319_32 - ok 07:00:17.0710 2432 [ C6F9AF94DCD58122A4D7E89DB6BED29D ] clr_optimization_v4.0.30319_64 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe 07:00:17.0712 2432 clr_optimization_v4.0.30319_64 - ok 07:00:17.0722 2432 [ E5D5499A1C50A54B5161296B6AFE6192 ] cmdide C:\Windows\system32\drivers\cmdide.sys 07:00:17.0727 2432 cmdide - ok 07:00:17.0755 2432 [ 7FB8AD01DB0EABE60C8A861531A8F431 ] Compbatt C:\Windows\system32\DRIVERS\compbatt.sys 07:00:17.0760 2432 Compbatt - ok 07:00:17.0765 2432 COMSysApp - ok 07:00:17.0771 2432 [ A8585B6412253803CE8EFCBD6D6DC15C ] crcdisk C:\Windows\system32\drivers\crcdisk.sys 07:00:17.0777 2432 crcdisk - ok 07:00:17.0864 2432 [ C7412FC0316FC8B9FF60DC73290EC633 ] CrmSqlStartupSvc C:\Program Files\Microsoft Dynamics CRM\Client\bin\CrmSqlStartupSvc.exe 07:00:17.0864 2432 CrmSqlStartupSvc - ok 07:00:17.0902 2432 [ 5AAC48EAF8EACF247DB44FB61B900D89 ] CryptSvc C:\Windows\system32\cryptsvc.dll 07:00:17.0904 2432 CryptSvc - ok 07:00:17.0938 2432 [ 6CB6E82300947870A873A7288B96E9BF ] CyberLink Live Monitor Service C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaMonitorService.exe 07:00:17.0939 2432 CyberLink Live Monitor Service - ok 07:00:17.0954 2432 [ 0FDAAE1EA129D0F3948564F96C010BA3 ] CyberLink Live Push Update Service C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdateService.exe 07:00:17.0955 2432 CyberLink Live Push Update Service - ok 07:00:17.0974 2432 [ 24F71344D945C85B15C0717196238BD2 ] CyberLink Live Service C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaService.exe 07:00:17.0976 2432 CyberLink Live Service - ok 07:00:18.0017 2432 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] DcomLaunch C:\Windows\system32\rpcss.dll 07:00:18.0023 2432 DcomLaunch - ok 07:00:18.0064 2432 [ 8B722BA35205C71E7951CDC4CDBADE19 ] DfsC C:\Windows\system32\Drivers\dfsc.sys 07:00:18.0070 2432 DfsC - ok 07:00:18.0156 2432 [ C647F468F7DE343DF8C143655C5557D4 ] DFSR C:\Windows\system32\DFSR.exe 07:00:18.0222 2432 DFSR - ok 07:00:18.0277 2432 [ 3ED0321127CE70ACDAABBF77E157C2A7 ] Dhcp C:\Windows\System32\dhcpcsvc.dll 07:00:18.0280 2432 Dhcp - ok 07:00:18.0310 2432 [ B0107E40ECDB5FA692EBF832F295D905 ] disk C:\Windows\system32\drivers\disk.sys 07:00:18.0317 2432 disk - ok 07:00:18.0353 2432 [ 06230F1B721494A6DF8D47FD395BB1B0 ] Dnscache C:\Windows\System32\dnsrslvr.dll 07:00:18.0355 2432 Dnscache - ok 07:00:18.0369 2432 [ 1A7156DD1E850E9914E5E991E3225B94 ] dot3svc C:\Windows\System32\dot3svc.dll 07:00:18.0372 2432 dot3svc - ok 07:00:18.0407 2432 [ 74C02B1717740C3B8039539E23E4B53F ] Dot4 C:\Windows\system32\DRIVERS\Dot4.sys 07:00:18.0414 2432 Dot4 - ok 07:00:18.0440 2432 [ 08321D1860235BF42CF2854234337AEA ] Dot4Print C:\Windows\system32\DRIVERS\Dot4Prt.sys 07:00:18.0444 2432 Dot4Print - ok 07:00:18.0453 2432 [ 4ADCCF0124F2B6911D3786A5D0E779E5 ] dot4usb C:\Windows\system32\DRIVERS\dot4usb.sys 07:00:18.0459 2432 dot4usb - ok 07:00:18.0480 2432 [ 1583B39790DB3EAEC7EDB0CB0140C708 ] DPS C:\Windows\system32\dps.dll 07:00:18.0482 2432 DPS - ok 07:00:18.0503 2432 [ F1A78A98CFC2EE02144C6BEC945447E6 ] drmkaud C:\Windows\system32\drivers\drmkaud.sys 07:00:18.0507 2432 drmkaud - ok 07:00:18.0545 2432 [ F3932288EEECD776FF1F9F653AD878F3 ] DXGKrnl C:\Windows\System32\drivers\dxgkrnl.sys 07:00:18.0550 2432 DXGKrnl - ok 07:00:18.0580 2432 [ 264CEE7B031A9D6C827F3D0CB031F2FE ] E1G60 C:\Windows\system32\DRIVERS\E1G6032E.sys 07:00:18.0588 2432 E1G60 - ok 07:00:18.0615 2432 [ B64CFEB83AB75AA74D0E193C423A991D ] e1yexpress C:\Windows\system32\DRIVERS\e1y60x64.sys 07:00:18.0631 2432 e1yexpress - ok 07:00:18.0669 2432 [ C2303883FD9BE49DC36A6400643002EA ] EapHost C:\Windows\System32\eapsvc.dll 07:00:18.0670 2432 EapHost - ok 07:00:18.0693 2432 [ 5F94962BE5A62DB6E447FF6470C4F48A ] Ecache C:\Windows\system32\drivers\ecache.sys 07:00:18.0702 2432 Ecache - ok 07:00:18.0775 2432 [ B1F2503E23425B386DF0F3413B2596F3 ] eDataSecurity Service C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe 07:00:18.0778 2432 eDataSecurity Service - ok 07:00:18.0806 2432 [ 14CE384D2E27B64C256BDA4DC39C312D ] ehRecvr C:\Windows\ehome\ehRecvr.exe 07:00:18.0829 2432 ehRecvr - ok 07:00:18.0853 2432 [ B93159C1313D66FDFBBE876F5189CD52 ] ehSched C:\Windows\ehome\ehsched.exe 07:00:18.0864 2432 ehSched - ok 07:00:18.0896 2432 [ F5EE2527D74449868E3C3227A59BCD28 ] ehstart C:\Windows\ehome\ehstart.dll 07:00:18.0896 2432 ehstart - ok 07:00:18.0919 2432 [ C4636D6E10469404AB5308D9FD45ED07 ] elxstor C:\Windows\system32\drivers\elxstor.sys 07:00:18.0935 2432 elxstor - ok 07:00:18.0978 2432 [ A9B18B63A4FD6BAAB83326706D857FAB ] EMDMgmt C:\Windows\system32\emdmgmt.dll 07:00:18.0982 2432 EMDMgmt - ok 07:00:19.0010 2432 [ BC3A58E938BB277E46BF4B3003B01ABD ] ErrDev C:\Windows\system32\drivers\errdev.sys 07:00:19.0014 2432 ErrDev - ok 07:00:19.0048 2432 [ 27D2754314D12EB27D81D462FD0D86C0 ] ETService C:\Program Files\Acer\Empowering Technology\Service\ETService.exe 07:00:19.0049 2432 ETService - ok 07:00:19.0083 2432 [ E12F22B73F153DECE721CD45EC05B4AF ] EventSystem C:\Windows\system32\es.dll 07:00:19.0086 2432 EventSystem - ok 07:00:19.0118 2432 [ 486844F47B6636044A42454614ED4523 ] exfat C:\Windows\system32\drivers\exfat.sys 07:00:19.0126 2432 exfat - ok 07:00:19.0174 2432 [ 1A4BEE34277784619DDAF0422C0C6E23 ] fastfat C:\Windows\system32\drivers\fastfat.sys 07:00:19.0191 2432 fastfat - ok 07:00:19.0203 2432 [ 81B79B6DF71FA1D2C6D688D830616E39 ] fdc C:\Windows\system32\DRIVERS\fdc.sys 07:00:19.0207 2432 fdc - ok 07:00:19.0219 2432 [ BB9267ACACD8B7533DD936C34A0CBA5E ] fdPHost C:\Windows\system32\fdPHost.dll 07:00:19.0221 2432 fdPHost - ok 07:00:19.0231 2432 [ 300C80931EABBE1DB7591C516EFE8D0F ] FDResPub C:\Windows\system32\fdrespub.dll 07:00:19.0232 2432 FDResPub - ok 07:00:19.0240 2432 [ 457B7D1D533E4BD62A99AED9C7BB4C59 ] FileInfo C:\Windows\system32\drivers\fileinfo.sys 07:00:19.0249 2432 FileInfo - ok 07:00:19.0277 2432 [ D421327FD6EFCCAF884A54C58E1B0D7F ] Filetrace C:\Windows\system32\drivers\filetrace.sys 07:00:19.0277 2432 Filetrace - ok 07:00:19.0286 2432 [ 230923EA2B80F79B0F88D90F87B87EBD ] flpydisk C:\Windows\system32\DRIVERS\flpydisk.sys 07:00:19.0290 2432 flpydisk - ok 07:00:19.0328 2432 [ E3041BC26D6930D61F42AEDB79C91720 ] FltMgr C:\Windows\system32\drivers\fltmgr.sys 07:00:19.0344 2432 FltMgr - ok 07:00:19.0406 2432 [ F20A97F51C104DD0A163251325460747 ] FontCache C:\Windows\system32\FntCache.dll 07:00:19.0430 2432 FontCache - ok 07:00:19.0489 2432 [ BC5B0BE5AF3510B0FD8C140EE42C6D3E ] FontCache3.0.0.0 C:\Windows\Microsoft.Net\Framework64\v3.0\WPF\PresentationFontCache.exe 07:00:19.0495 2432 FontCache3.0.0.0 - ok 07:00:19.0552 2432 [ 5779B86CD8B32519FBECB136394D946A ] Fs_Rec C:\Windows\system32\drivers\Fs_Rec.sys 07:00:19.0555 2432 Fs_Rec - ok 07:00:19.0570 2432 [ C8E416668D3DC2BE3D4FE4C79224997F ] gagp30kx C:\Windows\system32\drivers\gagp30kx.sys 07:00:19.0577 2432 gagp30kx - ok 07:00:19.0621 2432 [ 8E98D21EE06192492A5671A6144D092F ] GEARAspiWDM C:\Windows\system32\DRIVERS\GEARAspiWDM.sys 07:00:19.0626 2432 GEARAspiWDM - ok 07:00:19.0661 2432 [ A0E1B575BA8F504968CD40C0FAEB2384 ] gpsvc C:\Windows\System32\gpsvc.dll 07:00:19.0678 2432 gpsvc - ok 07:00:19.0738 2432 [ C1B577B2169900F4CF7190C39F085794 ] gusvc C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe 07:00:19.0750 2432 gusvc - ok 07:00:19.0770 2432 [ DF45F8142DC6DF9D18C39B3EFFBD0409 ] HdAudAddService C:\Windows\system32\drivers\HdAudio.sys 07:00:19.0786 2432 HdAudAddService - ok 07:00:19.0836 2432 [ F942C5820205F2FB453243EDFEC82A3D ] HDAudBus C:\Windows\system32\DRIVERS\HDAudBus.sys 07:00:19.0844 2432 HDAudBus - ok 07:00:19.0872 2432 [ 72D70BCF68C092978BFCD32F88BD6454 ] HECIx64 C:\Windows\system32\DRIVERS\HECIx64.sys 07:00:19.0878 2432 HECIx64 - ok 07:00:19.0904 2432 [ 68214C82FA6222591873677A72DF2A66 ] HidBatt C:\Windows\system32\DRIVERS\HidBatt.sys 07:00:19.0908 2432 HidBatt - ok 07:00:19.0919 2432 [ B4881C84A180E75B8C25DC1D726C375F ] HidBth C:\Windows\system32\drivers\hidbth.sys 07:00:19.0924 2432 HidBth - ok 07:00:19.0936 2432 [ 4E77A77E2C986E8F88F996BB3E1AD829 ] HidIr C:\Windows\system32\drivers\hidir.sys 07:00:19.0940 2432 HidIr - ok 07:00:19.0971 2432 [ 59361D38A297755D46A540E450202B2A ] hidserv C:\Windows\System32\hidserv.dll 07:00:19.0972 2432 hidserv - ok 07:00:19.0989 2432 [ 443BDD2D30BB4F00795C797E2CF99EDF ] HidUsb C:\Windows\system32\DRIVERS\hidusb.sys 07:00:19.0993 2432 HidUsb - ok 07:00:20.0017 2432 [ B12F367EA39C0795FD57E31242CE1A5A ] hkmsvc C:\Windows\system32\kmsvc.dll 07:00:20.0030 2432 hkmsvc - ok 07:00:20.0058 2432 [ D7109A1E6BD2DFDBCBA72A6BC626A13B ] HpCISSs C:\Windows\system32\drivers\hpcisss.sys 07:00:20.0066 2432 HpCISSs - ok 07:00:20.0133 2432 [ CE0FCEC4D4D860F36D972759B11EAF0F ] hpqcxs08 C:\Program Files (x86)\HP\Digital Imaging\bin\hpqcxs08.dll 07:00:20.0134 2432 hpqcxs08 - ok 07:00:20.0142 2432 [ EE4C7A4CF2316701FFDE90F404520265 ] hpqddsvc C:\Program Files (x86)\HP\Digital Imaging\bin\hpqddsvc.dll 07:00:20.0144 2432 hpqddsvc - ok 07:00:20.0174 2432 [ 098F1E4E5C9CB5B0063A959063631610 ] HTTP C:\Windows\system32\drivers\HTTP.sys 07:00:20.0200 2432 HTTP - ok 07:00:20.0217 2432 [ DA94C854CEA5FAC549D4E1F6E88349E8 ] i2omp C:\Windows\system32\drivers\i2omp.sys 07:00:20.0222 2432 i2omp - ok 07:00:20.0242 2432 [ CBB597659A2713CE0C9CC20C88C7591F ] i8042prt C:\Windows\system32\DRIVERS\i8042prt.sys 07:00:20.0248 2432 i8042prt - ok 07:00:20.0274 2432 [ 3E42C4691AAD4B1E8D0466F9CBF05CBE ] IAANTMON C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTMon.exe 07:00:20.0276 2432 IAANTMON - ok 07:00:20.0306 2432 [ FC28E90F2204D8FD147FA9BFA8A51C01 ] iaStor C:\Windows\system32\DRIVERS\iaStor.sys 07:00:20.0309 2432 iaStor - ok 07:00:20.0325 2432 [ 3E3BF3627D886736D0B4E90054F929F6 ] iaStorV C:\Windows\system32\drivers\iastorv.sys 07:00:20.0341 2432 iaStorV - ok 07:00:20.0381 2432 [ 749F5F8CEDCA70F2A512945325FC489D ] idsvc C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\infocard.exe 07:00:20.0427 2432 idsvc - ok 07:00:20.0597 2432 [ CF00559906E45ECC6F035913880BE2FC ] igfx C:\Windows\system32\DRIVERS\igdkmd64.sys 07:00:20.0747 2432 igfx - ok 07:00:20.0761 2432 [ 8C3951AD2FE886EF76C7B5027C3125D3 ] iirsp C:\Windows\system32\drivers\iirsp.sys 07:00:20.0766 2432 iirsp - ok 07:00:20.0804 2432 [ 0C9EA6E654E7B0471741E343A6C671AF ] IKEEXT C:\Windows\System32\ikeext.dll 07:00:20.0810 2432 IKEEXT - ok 07:00:20.0896 2432 [ 8C7FA71CB1EBCD3EDE8958D27B1BF0B4 ] int15 C:\Windows\SysWOW64\drivers\int15_64.sys 07:00:20.0901 2432 int15 - ok 07:00:20.0956 2432 [ AECDAA95B5BBFAC856C4A22D06D3D76A ] IntcAzAudAddService C:\Windows\system32\drivers\RTKVHD64.sys 07:00:21.0005 2432 IntcAzAudAddService - ok 07:00:21.0025 2432 [ DEA2AB452B4FA773187369C4B6517320 ] IntcHdmiAddService C:\Windows\system32\drivers\IntcHdmi.sys 07:00:21.0032 2432 IntcHdmiAddService - ok 07:00:21.0052 2432 [ DF797A12176F11B2D301C5B234BB200E ] intelide C:\Windows\system32\drivers\intelide.sys 07:00:21.0057 2432 intelide - ok 07:00:21.0066 2432 [ BFD84AF32FA1BAD6231C4585CB469630 ] intelppm C:\Windows\system32\DRIVERS\intelppm.sys 07:00:21.0067 2432 intelppm - ok 07:00:21.0090 2432 [ 5624BC1BC5EEB49C0AB76A8114F05EA3 ] IPBusEnum C:\Windows\system32\ipbusenum.dll 07:00:21.0102 2432 IPBusEnum - ok 07:00:21.0134 2432 [ D8AABC341311E4780D6FCE8C73C0AD81 ] IpFilterDriver C:\Windows\system32\DRIVERS\ipfltdrv.sys 07:00:21.0140 2432 IpFilterDriver - ok 07:00:21.0167 2432 [ BF0DBFA9792C5C14FA00F61C75116C1B ] iphlpsvc C:\Windows\System32\iphlpsvc.dll 07:00:21.0170 2432 iphlpsvc - ok 07:00:21.0174 2432 IpInIp - ok 07:00:21.0189 2432 [ 9C2EE2E6E5A7203BFAE15C299475EC67 ] IPMIDRV C:\Windows\system32\drivers\ipmidrv.sys 07:00:21.0196 2432 IPMIDRV - ok 07:00:21.0212 2432 [ B7E6212F581EA5F6AB0C3A6CEEEB89BE ] IPNAT C:\Windows\system32\DRIVERS\ipnat.sys 07:00:21.0219 2432 IPNAT - ok 07:00:21.0264 2432 [ 78486992AC657AE5065C4A2135838570 ] iPod Service C:\Program Files\iPod\bin\iPodService.exe 07:00:21.0268 2432 iPod Service - ok 07:00:21.0285 2432 [ 8C42CA155343A2F11D29FECA67FAA88D ] IRENUM C:\Windows\system32\drivers\irenum.sys 07:00:21.0289 2432 IRENUM - ok 07:00:21.0320 2432 [ 0672BFCEDC6FC468A2B0500D81437F4F ] isapnp C:\Windows\system32\drivers\isapnp.sys 07:00:21.0326 2432 isapnp - ok 07:00:21.0359 2432 [ E4FDF99599F27EC25D2CF6D754243520 ] iScsiPrt C:\Windows\system32\DRIVERS\msiscsi.sys 07:00:21.0361 2432 iScsiPrt - ok 07:00:21.0377 2432 [ 63C766CDC609FF8206CB447A65ABBA4A ] iteatapi C:\Windows\system32\drivers\iteatapi.sys 07:00:21.0383 2432 iteatapi - ok 07:00:21.0403 2432 [ 1281FE73B17664631D12F643CBEA3F59 ] iteraid C:\Windows\system32\drivers\iteraid.sys 07:00:21.0409 2432 iteraid - ok 07:00:21.0415 2432 [ 423696F3BA6472DD17699209B933BC26 ] kbdclass C:\Windows\system32\DRIVERS\kbdclass.sys 07:00:21.0421 2432 kbdclass - ok 07:00:21.0460 2432 [ DBDF75D51464FBC47D0104EC3D572C05 ] kbdhid C:\Windows\system32\DRIVERS\kbdhid.sys 07:00:21.0464 2432 kbdhid - ok 07:00:21.0472 2432 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] KeyIso C:\Windows\system32\lsass.exe 07:00:21.0473 2432 KeyIso - ok 07:00:21.0512 2432 [ 88956AD9FA510848AD176777A6C6C1F5 ] KSecDD C:\Windows\system32\Drivers\ksecdd.sys 07:00:21.0543 2432 KSecDD - ok 07:00:21.0555 2432 [ 1D419CF43DB29396ECD7113D129D94EB ] ksthunk C:\Windows\system32\drivers\ksthunk.sys 07:00:21.0559 2432 ksthunk - ok 07:00:21.0606 2432 [ 1FAF6926F3416D3DA05C5B265491BDAE ] KtmRm C:\Windows\system32\msdtckrm.dll 07:00:21.0612 2432 KtmRm - ok 07:00:21.0646 2432 [ 50C7A3CB427E9BB5ED0708A669956AB5 ] LanmanServer C:\Windows\System32\srvsvc.dll 07:00:21.0649 2432 LanmanServer - ok 07:00:21.0682 2432 [ CAF86FC1388BE1E470F1A7B43E348ADB ] LanmanWorkstation C:\Windows\System32\wkssvc.dll 07:00:21.0685 2432 LanmanWorkstation - ok 07:00:21.0722 2432 [ 793FF718477345CD5D232C50BED1E452 ] LightScribeService C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe 07:00:21.0722 2432 LightScribeService - ok 07:00:21.0732 2432 [ 96ECE2659B6654C10A0C310AE3A6D02C ] lltdio C:\Windows\system32\DRIVERS\lltdio.sys 07:00:21.0738 2432 lltdio - ok 07:00:21.0762 2432 [ 961CCBD0B1CCB5675D64976FAE37D092 ] lltdsvc C:\Windows\System32\lltdsvc.dll 07:00:21.0782 2432 lltdsvc - ok 07:00:21.0797 2432 [ A47F8080CACC23C91FE823AD19AA5612 ] lmhosts C:\Windows\System32\lmhsvc.dll 07:00:21.0798 2432 lmhosts - ok 07:00:21.0828 2432 [ 650B3BE84ECA8BE345F9C423EF02605D ] LMS C:\Program Files\Intel\AMT\LMS.exe 07:00:21.0829 2432 LMS - ok 07:00:21.0848 2432 [ ACBE1AF32D3123E330A07BFBC5EC4A9B ] LSI_FC C:\Windows\system32\drivers\lsi_fc.sys 07:00:21.0855 2432 LSI_FC - ok 07:00:21.0868 2432 [ 799FFB2FC4729FA46D2157C0065B3525 ] LSI_SAS C:\Windows\system32\drivers\lsi_sas.sys 07:00:21.0875 2432 LSI_SAS - ok 07:00:21.0894 2432 [ F445FF1DAAD8A226366BFAF42551226B ] LSI_SCSI C:\Windows\system32\drivers\lsi_scsi.sys 07:00:21.0901 2432 LSI_SCSI - ok 07:00:21.0918 2432 [ 52F87B9CC8932C2A7375C3B2A9BE5E3E ] luafv C:\Windows\system32\drivers\luafv.sys 07:00:21.0925 2432 luafv - ok 07:00:21.0937 2432 lvpepf64 - ok 07:00:21.0942 2432 LVPr2M64 - ok 07:00:21.0979 2432 [ 0C85B2B6FB74B36A251792D45E0EF860 ] LVRS64 C:\Windows\system32\DRIVERS\lvrs64.sys 07:00:21.0996 2432 LVRS64 - ok 07:00:22.0011 2432 [ 5C3FF68267A5D242EE79EE01B993D6CE ] LVUSBS64 C:\Windows\system32\drivers\LVUSBS64.sys 07:00:22.0017 2432 LVUSBS64 - ok 07:00:22.0132 2432 [ FF3A488924B0032B1A9CA6948C1FA9E8 ] LVUVC64 C:\Windows\system32\DRIVERS\lvuvc64.sys 07:00:22.0236 2432 LVUVC64 - ok 07:00:22.0377 2432 [ 5CA51F47554C0F01C5EEDC6B9A385082 ] M4-Service C:\Users\Karri\AppData\Local\Mikogo4\Viewer\Service\M4-Service.exe 07:00:22.0383 2432 M4-Service - ok 07:00:22.0431 2432 [ 76A58DF02BD4EA29F189B82D0BEF17F8 ] Mcx2Svc C:\Windows\system32\Mcx2Svc.dll 07:00:22.0443 2432 Mcx2Svc - ok 07:00:22.0536 2432 [ 7C08B11778AE7FF97E4601D6111F104A ] ME Services Manager C:\Program Files\intel\inteldh\msm\MSM.exe 07:00:22.0552 2432 ME Services Manager - ok 07:00:22.0579 2432 [ 5C5CD6AACED32FB26C3FB34B3DCF972F ] megasas C:\Windows\system32\drivers\megasas.sys 07:00:22.0585 2432 megasas - ok 07:00:22.0611 2432 [ 859BC2436B076C77C159ED694ACFE8F8 ] MegaSR C:\Windows\system32\drivers\megasr.sys 07:00:22.0631 2432 MegaSR - ok 07:00:22.0658 2432 Microsoft SharePoint Workspace Audit Service - ok 07:00:22.0678 2432 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] MMCSS C:\Windows\system32\mmcss.dll 07:00:22.0679 2432 MMCSS - ok 07:00:22.0697 2432 [ 59848D5CC74606F0EE7557983BB73C2E ] Modem C:\Windows\system32\drivers\modem.sys 07:00:22.0702 2432 Modem - ok 07:00:22.0736 2432 [ C247CC2A57E0A0C8C6DCCF7807B3E9E5 ] monitor C:\Windows\system32\DRIVERS\monitor.sys 07:00:22.0736 2432 monitor - ok 07:00:22.0744 2432 [ 9367304E5E412B120CF5F4EA14E4E4F1 ] mouclass C:\Windows\system32\DRIVERS\mouclass.sys 07:00:22.0750 2432 mouclass - ok 07:00:22.0767 2432 [ C2C2BD5C5CE5AAF786DDD74B75D2AC69 ] mouhid C:\Windows\system32\DRIVERS\mouhid.sys 07:00:22.0771 2432 mouhid - ok 07:00:22.0785 2432 [ 11BC9B1E8801B01F7F6ADB9EAD30019B ] MountMgr C:\Windows\system32\drivers\mountmgr.sys 07:00:22.0792 2432 MountMgr - ok 07:00:22.0832 2432 [ 528A5C2570F468155A1B3CF0A2FF5EBD ] MozillaMaintenance C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe 07:00:22.0842 2432 MozillaMaintenance - ok 07:00:22.0866 2432 [ F8276EB8698142884498A528DFEA8478 ] mpio C:\Windows\system32\drivers\mpio.sys 07:00:22.0876 2432 mpio - ok 07:00:22.0892 2432 [ C92B9ABDB65A5991E00C28F13491DBA2 ] mpsdrv C:\Windows\system32\drivers\mpsdrv.sys 07:00:22.0900 2432 mpsdrv - ok 07:00:22.0933 2432 [ 897E3BAF68BA406A61682AE39C83900C ] MpsSvc C:\Windows\system32\mpssvc.dll 07:00:22.0950 2432 MpsSvc - ok 07:00:22.0965 2432 [ 3C200630A89EF2C0864D515B7A75802E ] Mraid35x C:\Windows\system32\drivers\mraid35x.sys 07:00:22.0971 2432 Mraid35x - ok 07:00:23.0001 2432 [ 7C1DE4AA96DC0C071611F9E7DE02A68D ] MRxDAV C:\Windows\system32\drivers\mrxdav.sys 07:00:23.0009 2432 MRxDAV - ok 07:00:23.0040 2432 [ 1485811B320FF8C7EDAD1CAEBB1C6C2B ] mrxsmb C:\Windows\system32\DRIVERS\mrxsmb.sys 07:00:23.0048 2432 mrxsmb - ok 07:00:23.0073 2432 [ 3B929A60C833FC615FD97FBA82BC7632 ] mrxsmb10 C:\Windows\system32\DRIVERS\mrxsmb10.sys 07:00:23.0089 2432 mrxsmb10 - ok 07:00:23.0094 2432 [ C64AB3E1F53B4F5B5BB6D796B2D7BEC3 ] mrxsmb20 C:\Windows\system32\DRIVERS\mrxsmb20.sys 07:00:23.0102 2432 mrxsmb20 - ok 07:00:23.0111 2432 [ 1AC860612B85D8E85EE257D372E39F4D ] msahci C:\Windows\system32\drivers\msahci.sys 07:00:23.0116 2432 msahci - ok 07:00:23.0128 2432 [ 264BBB4AAF312A485F0E44B65A6B7202 ] msdsm C:\Windows\system32\drivers\msdsm.sys 07:00:23.0136 2432 msdsm - ok 07:00:23.0153 2432 [ 7EC02CE772F068ED0BEAFA3DA341A9BC ] MSDTC C:\Windows\System32\msdtc.exe 07:00:23.0155 2432 MSDTC - ok 07:00:23.0171 2432 [ 704F59BFC4512D2BB0146AEC31B10A7C ] Msfs C:\Windows\system32\drivers\Msfs.sys 07:00:23.0175 2432 Msfs - ok 07:00:23.0202 2432 [ 00EBC952961664780D43DCA157E79B27 ] msisadrv C:\Windows\system32\drivers\msisadrv.sys 07:00:23.0207 2432 msisadrv - ok 07:00:23.0222 2432 [ 366B0C1F4478B519C181E37D43DCDA32 ] MSiSCSI C:\Windows\system32\iscsiexe.dll 07:00:23.0224 2432 MSiSCSI - ok 07:00:23.0228 2432 msiserver - ok 07:00:23.0249 2432 [ 0EA73E498F53B96D83DBFCA074AD4CF8 ] MSKSSRV C:\Windows\system32\drivers\MSKSSRV.sys 07:00:23.0252 2432 MSKSSRV - ok 07:00:23.0347 2432 [ 47A616802531735DF88CD331739D6E97 ] msoidsvc C:\Program Files\Common Files\Microsoft Shared\Microsoft Online Services\MSOIDSVC.EXE 07:00:23.0384 2432 msoidsvc - ok 07:00:23.0403 2432 [ 52E59B7E992A58E740AA63F57EDBAE8B ] MSPCLOCK C:\Windows\system32\drivers\MSPCLOCK.sys 07:00:23.0407 2432 MSPCLOCK - ok 07:00:23.0418 2432 [ 49084A75BAE043AE02D5B44D02991BB2 ] MSPQM C:\Windows\system32\drivers\MSPQM.sys 07:00:23.0419 2432 MSPQM - ok 07:00:23.0455 2432 [ DC6CCF440CDEDE4293DB41C37A5060A5 ] MsRPC C:\Windows\system32\drivers\MsRPC.sys 07:00:23.0471 2432 MsRPC - ok 07:00:23.0504 2432 [ 855796E59DF77EA93AF46F20155BF55B ] mssmbios C:\Windows\system32\DRIVERS\mssmbios.sys 07:00:23.0505 2432 mssmbios - ok 07:00:23.0517 2432 [ 86D632D75D05D5B7C7C043FA3564AE86 ] MSTEE C:\Windows\system32\drivers\MSTEE.sys 07:00:23.0521 2432 MSTEE - ok 07:00:23.0526 2432 [ 0CC49F78D8ACA0877D885F149084E543 ] Mup C:\Windows\system32\Drivers\mup.sys 07:00:23.0533 2432 Mup - ok 07:00:23.0574 2432 [ A5B10C845E7538C60C0F5D87A57CB3F5 ] napagent C:\Windows\system32\qagentRT.dll 07:00:23.0581 2432 napagent - ok 07:00:23.0623 2432 [ 2007B826C4ACD94AE32232B41F0842B9 ] NativeWifiP C:\Windows\system32\DRIVERS\nwifi.sys 07:00:23.0631 2432 NativeWifiP - ok 07:00:23.0679 2432 [ 65950E07329FCEE8E6516B17C8D0ABB6 ] NDIS C:\Windows\system32\drivers\ndis.sys 07:00:23.0684 2432 NDIS - ok 07:00:23.0713 2432 [ 64DF698A425478E321981431AC171334 ] NdisTapi C:\Windows\system32\DRIVERS\ndistapi.sys 07:00:23.0717 2432 NdisTapi - ok 07:00:23.0727 2432 [ 8BAA43196D7B5BB972C9A6B2BBF61A19 ] Ndisuio C:\Windows\system32\DRIVERS\ndisuio.sys 07:00:23.0731 2432 Ndisuio - ok 07:00:23.0760 2432 [ F8158771905260982CE724076419EF19 ] NdisWan C:\Windows\system32\DRIVERS\ndiswan.sys 07:00:23.0768 2432 NdisWan - ok 07:00:23.0777 2432 [ 9CB77ED7CB72850253E973A2D6AFDF49 ] NDProxy C:\Windows\system32\drivers\NDProxy.sys 07:00:23.0783 2432 NDProxy - ok 07:00:23.0842 2432 [ B90E093E7A7250906F1054418B5339C0 ] Nero BackItUp Scheduler 4.0 C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe 07:00:23.0849 2432 Nero BackItUp Scheduler 4.0 - ok 07:00:23.0890 2432 [ 2334DC48997BA203B794DF3EE70521DB ] Net Driver HPZ12 C:\Windows\system32\HPZinw12.dll 07:00:23.0891 2432 Net Driver HPZ12 - ok 07:00:23.0903 2432 [ A499294F5029A7862ADC115BDA7371CE ] NetBIOS C:\Windows\system32\DRIVERS\netbios.sys 07:00:23.0909 2432 NetBIOS - ok 07:00:23.0949 2432 [ FC2C792EBDDC8E28DF939D6A92C83D61 ] netbt C:\Windows\system32\DRIVERS\netbt.sys 07:00:23.0965 2432 netbt - ok 07:00:23.0970 2432 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] Netlogon C:\Windows\system32\lsass.exe 07:00:23.0972 2432 Netlogon - ok 07:00:23.0990 2432 [ 9B63B29DEFC0F3115A559D2597BF5D75 ] Netman C:\Windows\System32\netman.dll 07:00:23.0995 2432 Netman - ok 07:00:24.0076 2432 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetMsmqActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 07:00:24.0088 2432 NetMsmqActivator - ok 07:00:24.0093 2432 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetPipeActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 07:00:24.0094 2432 NetPipeActivator - ok 07:00:24.0113 2432 [ 7846D0136CC2B264926A73047BA7688A ] netprofm C:\Windows\System32\netprofm.dll 07:00:24.0117 2432 netprofm - ok 07:00:24.0128 2432 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpActivator C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 07:00:24.0129 2432 NetTcpActivator - ok 07:00:24.0134 2432 [ D22CD77D4F0D63D1169BB35911BFF12D ] NetTcpPortSharing C:\Windows\Microsoft.NET\Framework64\v4.0.30319\SMSvcHost.exe 07:00:24.0135 2432 NetTcpPortSharing - ok 07:00:24.0152 2432 [ 4AC08BD6AF2DF42E0C3196D826C8AEA7 ] nfrd960 C:\Windows\system32\drivers\nfrd960.sys 07:00:24.0158 2432 nfrd960 - ok 07:00:24.0173 2432 [ F145BF4C4668E7E312069F81EF847CFC ] NlaSvc C:\Windows\System32\nlasvc.dll 07:00:24.0175 2432 NlaSvc - ok 07:00:24.0198 2432 [ B298874F8E0EA93F06EC40AA8D146478 ] Npfs C:\Windows\system32\drivers\Npfs.sys 07:00:24.0203 2432 Npfs - ok 07:00:24.0223 2432 [ ACB62BAA1C319B17752553DF3026EEEB ] nsi C:\Windows\system32\nsisvc.dll 07:00:24.0225 2432 nsi - ok 07:00:24.0235 2432 [ 1523AF19EE8B030BA682F7A53537EAEB ] nsiproxy C:\Windows\system32\drivers\nsiproxy.sys 07:00:24.0239 2432 nsiproxy - ok 07:00:24.0293 2432 [ 2ACCAA3C3C55370A32F17B3595E1A217 ] Ntfs C:\Windows\system32\drivers\Ntfs.sys 07:00:24.0342 2432 Ntfs - ok 07:00:24.0376 2432 [ A2B6583A5652A385DFF5E4F49AD48761 ] NTIBackupSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BackupSvc.exe 07:00:24.0376 2432 NTIBackupSvc - ok 07:00:24.0386 2432 [ 7D397449AAF52B0E7C79B64F6AD4473E ] NTIDrvr C:\Windows\system32\Drivers\NTIDrvr.sys 07:00:24.0390 2432 NTIDrvr - ok 07:00:24.0405 2432 [ 40B87FE8A1A9A5AC9E5A91D96F212BCD ] NTISchedulerSvc C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\SchedulerSvc.exe 07:00:24.0406 2432 NTISchedulerSvc - ok 07:00:24.0445 2432 [ D4012918D3A3847B44B888D56BC095D6 ] NuidFltr C:\Windows\system32\DRIVERS\NuidFltr.sys 07:00:24.0450 2432 NuidFltr - ok 07:00:24.0471 2432 [ DD5D684975352B85B52E3FD5347C20CB ] Null C:\Windows\system32\drivers\Null.sys 07:00:24.0474 2432 Null - ok 07:00:24.0678 2432 [ FCBA1C22727939E7CFF9EB08FE9692AB ] nvlddmkm C:\Windows\system32\DRIVERS\nvlddmkm.sys 07:00:24.0924 2432 nvlddmkm - ok 07:00:24.0954 2432 [ 2C040B7ADA5B06F6FACADAC8514AA034 ] nvraid C:\Windows\system32\drivers\nvraid.sys 07:00:24.0961 2432 nvraid - ok 07:00:24.0973 2432 [ F7EA0FE82842D05EDA3EFDD376DBFDBA ] nvstor C:\Windows\system32\drivers\nvstor.sys 07:00:24.0980 2432 nvstor - ok 07:00:25.0020 2432 [ 10C232F6CFFD51D2332898AE7AE0FF23 ] nvsvc C:\Windows\system32\nvvsvc.exe 07:00:25.0032 2432 nvsvc - ok 07:00:25.0104 2432 [ 4789E020D2617046862D1790FC235FF6 ] nvUpdatusService C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe 07:00:25.0112 2432 nvUpdatusService - ok 07:00:25.0124 2432 [ 19067CA93075EF4823E3938A686F532F ] nv_agp C:\Windows\system32\drivers\nv_agp.sys 07:00:25.0132 2432 nv_agp - ok 07:00:25.0136 2432 NwlnkFlt - ok 07:00:25.0142 2432 NwlnkFwd - ok 07:00:25.0185 2432 [ B5B1CE65AC15BBD11C0619E3EF7CFC28 ] ohci1394 C:\Windows\system32\DRIVERS\ohci1394.sys 07:00:25.0186 2432 ohci1394 - ok 07:00:25.0227 2432 [ 4965B005492CBA7719E82B71E3245495 ] ose64 C:\Program Files\Common Files\Microsoft Shared\Source Engine\OSE.EXE 07:00:25.0228 2432 ose64 - ok 07:00:25.0347 2432 [ 61BFFB5F57AD12F83AB64B7181829B34 ] osppsvc C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE 07:00:25.0375 2432 osppsvc - ok 07:00:25.0418 2432 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2pimsvc C:\Windows\system32\p2psvc.dll 07:00:25.0453 2432 p2pimsvc - ok 07:00:25.0473 2432 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] p2psvc C:\Windows\system32\p2psvc.dll 07:00:25.0480 2432 p2psvc - ok 07:00:25.0496 2432 [ AECD57F94C887F58919F307C35498EA0 ] Parport C:\Windows\system32\drivers\parport.sys 07:00:25.0502 2432 Parport - ok 07:00:25.0534 2432 [ B43751085E2ABE389DA466BC62A4B987 ] partmgr C:\Windows\system32\drivers\partmgr.sys 07:00:25.0541 2432 partmgr - ok 07:00:25.0558 2432 [ 9AB157B374192FF276C1628FBDBA2B0E ] PcaSvc C:\Windows\System32\pcasvc.dll 07:00:25.0561 2432 PcaSvc - ok 07:00:25.0571 2432 [ 47AB1E0FC9D0E12BB53BA246E3A0906D ] pci C:\Windows\system32\drivers\pci.sys 07:00:25.0580 2432 pci - ok 07:00:25.0593 2432 [ 8D618C829034479985A9ED56106CC732 ] pciide C:\Windows\system32\drivers\pciide.sys 07:00:25.0597 2432 pciide - ok 07:00:25.0610 2432 [ 037661F3D7C507C9993B7010CEEE6288 ] pcmcia C:\Windows\system32\drivers\pcmcia.sys 07:00:25.0621 2432 pcmcia - ok 07:00:25.0650 2432 [ 58865916F53592A61549B04941BFD80D ] PEAUTH C:\Windows\system32\drivers\peauth.sys 07:00:25.0674 2432 PEAUTH - ok 07:00:25.0726 2432 [ 0ED8727EA0172860F47258456C06CAEA ] PerfHost C:\Windows\SysWow64\perfhost.exe 07:00:25.0732 2432 PerfHost - ok 07:00:25.0811 2432 [ 087A343DFC337F37723DD7912DE6B6CD ] PID_PEPI C:\Windows\system32\DRIVERS\LV302V64.SYS 07:00:25.0884 2432 PID_PEPI - ok 07:00:25.0921 2432 [ E9E68C1A0F25CF4A7AC966EEA74EE89E ] pla C:\Windows\system32\pla.dll 07:00:25.0945 2432 pla - ok 07:00:25.0976 2432 [ FE6B0F59215C9FD9F9D26539C58C8B82 ] PlugPlay C:\Windows\system32\umpnpmgr.dll 07:00:25.0981 2432 PlugPlay - ok 07:00:26.0011 2432 [ AC78DF349F0E4CFB8B667C0CFFF83CCE ] Pml Driver HPZ12 C:\Windows\system32\HPZipm12.dll 07:00:26.0013 2432 Pml Driver HPZ12 - ok 07:00:26.0035 2432 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPAutoReg C:\Windows\system32\p2psvc.dll 07:00:26.0041 2432 PNRPAutoReg - ok 07:00:26.0060 2432 [ 9AE31D2E1D15C10D91318E0EC149CEAC ] PNRPsvc C:\Windows\system32\p2psvc.dll 07:00:26.0066 2432 PNRPsvc - ok 07:00:26.0104 2432 [ 89A5560671C2D8B4A4B51F3E1AA069D8 ] PolicyAgent C:\Windows\System32\ipsecsvc.dll 07:00:26.0120 2432 PolicyAgent - ok 07:00:26.0154 2432 [ 23386E9952025F5F21C368971E2E7301 ] PptpMiniport C:\Windows\system32\DRIVERS\raspptp.sys 07:00:26.0161 2432 PptpMiniport - ok 07:00:26.0169 2432 [ 5080E59ECEE0BC923F14018803AA7A01 ] Processor C:\Windows\system32\drivers\processr.sys 07:00:26.0175 2432 Processor - ok 07:00:26.0210 2432 [ E058CE4FC2449D8BFA14739C83B7FF2A ] ProfSvc C:\Windows\system32\profsvc.dll 07:00:26.0213 2432 ProfSvc - ok 07:00:26.0221 2432 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] ProtectedStorage C:\Windows\system32\lsass.exe 07:00:26.0223 2432 ProtectedStorage - ok 07:00:26.0251 2432 [ C5AB7F0809392D0DA027F4A2A81BFA31 ] PSched C:\Windows\system32\DRIVERS\pacer.sys 07:00:26.0252 2432 PSched - ok 07:00:26.0279 2432 [ 2CFD31D41CDE75328ACAEEE2D4F4B836 ] PSDFilter C:\Windows\system32\DRIVERS\psdfilter.sys 07:00:26.0284 2432 PSDFilter - ok 07:00:26.0316 2432 [ 51A585F999672D8BB07F22AE12B40846 ] PSDNServ C:\Windows\system32\DRIVERS\PSDNServ.sys 07:00:26.0321 2432 PSDNServ - ok 07:00:26.0348 2432 [ DB50D3F5C31B1A848B04F7F2A6FF2709 ] psdvdisk C:\Windows\system32\DRIVERS\PSDVdisk.sys 07:00:26.0354 2432 psdvdisk - ok 07:00:26.0386 2432 [ 0B83F4E681062F3839BE2EC1D98FD94A ] ql2300 C:\Windows\system32\drivers\ql2300.sys 07:00:26.0427 2432 ql2300 - ok 07:00:26.0467 2432 [ E1C80F8D4D1E39EF9595809C1369BF2A ] ql40xx C:\Windows\system32\drivers\ql40xx.sys 07:00:26.0476 2432 ql40xx - ok 07:00:26.0503 2432 [ 90574842C3DA781E279061A3EFF91F07 ] QWAVE C:\Windows\system32\qwave.dll 07:00:26.0507 2432 QWAVE - ok 07:00:26.0515 2432 [ E8D76EDAB77EC9C634C27B8EAC33ADC5 ] QWAVEdrv C:\Windows\system32\drivers\qwavedrv.sys 07:00:26.0521 2432 QWAVEdrv - ok 07:00:26.0527 2432 [ 1013B3B663A56D3DDD784F581C1BD005 ] RasAcd C:\Windows\system32\DRIVERS\rasacd.sys 07:00:26.0530 2432 RasAcd - ok 07:00:26.0554 2432 [ B2AE18F847D07F0044404DDF7CB04497 ] RasAuto C:\Windows\System32\rasauto.dll 07:00:26.0557 2432 RasAuto - ok 07:00:26.0563 2432 [ AC7BC4D42A7E558718DFDEC599BBFC2C ] Rasl2tp C:\Windows\system32\DRIVERS\rasl2tp.sys 07:00:26.0570 2432 Rasl2tp - ok 07:00:26.0599 2432 [ 3AD83E4046C43BE510DE681588ACB8AF ] RasMan C:\Windows\System32\rasmans.dll 07:00:26.0604 2432 RasMan - ok 07:00:26.0631 2432 [ 4517FBF8B42524AFE4EDE1DE102AAE3E ] RasPppoe C:\Windows\system32\DRIVERS\raspppoe.sys 07:00:26.0637 2432 RasPppoe - ok 07:00:26.0663 2432 [ C6A593B51F34C33E5474539544072527 ] RasSstp C:\Windows\system32\DRIVERS\rassstp.sys 07:00:26.0669 2432 RasSstp - ok 07:00:26.0699 2432 [ 322DB5C6B55E8D8EE8D6F358B2AAABB1 ] rdbss C:\Windows\system32\DRIVERS\rdbss.sys 07:00:26.0716 2432 rdbss - ok 07:00:26.0721 2432 [ 603900CC05F6BE65CCBF373800AF3716 ] RDPCDD C:\Windows\system32\DRIVERS\RDPCDD.sys 07:00:26.0725 2432 RDPCDD - ok 07:00:26.0744 2432 [ C045D1FB111C28DF0D1BE8D4BDA22C06 ] rdpdr C:\Windows\system32\drivers\rdpdr.sys 07:00:26.0756 2432 rdpdr - ok 07:00:26.0768 2432 [ CAB9421DAF3D97B33D0D055858E2C3AB ] RDPENCDD C:\Windows\system32\drivers\rdpencdd.sys 07:00:26.0772 2432 RDPENCDD - ok 07:00:26.0809 2432 [ AE4BD9E1C33D351D8E607FC81F15160C ] RDPWD C:\Windows\system32\drivers\RDPWD.sys 07:00:26.0826 2432 RDPWD - ok 07:00:26.0843 2432 [ C612B9557DA73F70D41F8A6FBC8E5344 ] RemoteAccess C:\Windows\System32\mprdim.dll 07:00:26.0845 2432 RemoteAccess - ok 07:00:26.0877 2432 [ 44B9D8EC2F3EF3A0EFB00857AF70D861 ] RemoteRegistry C:\Windows\system32\regsvc.dll 07:00:26.0888 2432 RemoteRegistry - ok 07:00:26.0931 2432 [ A035A7BF5132682F53F1E7B955690CE7 ] RichVideo C:\Program Files (x86)\CyberLink\Shared Files\RichVideo.exe 07:00:26.0932 2432 RichVideo - ok 07:00:26.0952 2432 [ F46C457840D4B7A4DAAFEE739CE04102 ] RpcLocator C:\Windows\system32\locator.exe 07:00:26.0953 2432 RpcLocator - ok 07:00:26.0992 2432 [ CF8B9A3A5E7DC57724A89D0C3E8CF9EF ] RpcSs C:\Windows\System32\rpcss.dll 07:00:26.0998 2432 RpcSs - ok 07:00:27.0012 2432 [ 22A9CB08B1A6707C1550C6BF099AAE73 ] rspndr C:\Windows\system32\DRIVERS\rspndr.sys 07:00:27.0018 2432 rspndr - ok 07:00:27.0030 2432 [ 260BF9C43EE12C6898A9F5AAB0FB0E5D ] SamSs C:\Windows\system32\lsass.exe 07:00:27.0031 2432 SamSs - ok 07:00:27.0050 2432 [ CD9C693589C60AD59BBBCFB0E524E01B ] sbp2port C:\Windows\system32\drivers\sbp2port.sys 07:00:27.0057 2432 sbp2port - ok 07:00:27.0081 2432 [ FD1CDCF108D5EF3366F00D18B70FB89B ] SCardSvr C:\Windows\System32\SCardSvr.dll 07:00:27.0084 2432 SCardSvr - ok 07:00:27.0118 2432 [ 0F838C811AD295D2A4489B9993096C63 ] Schedule C:\Windows\system32\schedsvc.dll 07:00:27.0125 2432 Schedule - ok 07:00:27.0151 2432 [ 5A268127633C7EE2A7FB87F39D748D56 ] SCPolicySvc C:\Windows\System32\certprop.dll 07:00:27.0152 2432 SCPolicySvc - ok 07:00:27.0172 2432 [ 4FF71B076A7760FE75EA5AE2D0EE0018 ] SDRSVC C:\Windows\System32\SDRSVC.dll 07:00:27.0175 2432 SDRSVC - ok 07:00:27.0189 2432 [ 3EA8A16169C26AFBEB544E0E48421186 ] secdrv C:\Windows\system32\drivers\secdrv.sys 07:00:27.0193 2432 secdrv - ok 07:00:27.0203 2432 [ 5ACDCBC67FCF894A1815B9F96D704490 ] seclogon C:\Windows\system32\seclogon.dll 07:00:27.0205 2432 seclogon - ok 07:00:27.0216 2432 [ 90973A64B96CD647FF81C79443618EED ] SENS C:\Windows\system32\sens.dll 07:00:27.0218 2432 SENS - ok 07:00:27.0223 2432 [ 2449316316411D65BD2C761A6FFB2CE2 ] Serenum C:\Windows\system32\DRIVERS\serenum.sys 07:00:27.0230 2432 Serenum - ok 07:00:27.0251 2432 [ 4B438170BE2FC8E0BD35EE87A960F84F ] Serial C:\Windows\system32\DRIVERS\serial.sys 07:00:27.0259 2432 Serial - ok 07:00:27.0272 2432 [ A842F04833684BCEEA7336211BE478DF ] sermouse C:\Windows\system32\drivers\sermouse.sys 07:00:27.0277 2432 sermouse - ok 07:00:27.0297 2432 [ A8E4A4407A09F35DCCC3771AF590B0C4 ] SessionEnv C:\Windows\system32\sessenv.dll 07:00:27.0311 2432 SessionEnv - ok 07:00:27.0323 2432 [ 14D4B4465193A87C127933978E8C4106 ] sffdisk C:\Windows\system32\drivers\sffdisk.sys 07:00:27.0327 2432 sffdisk - ok 07:00:27.0336 2432 [ 7073AEE3F82F3D598E3825962AA98AB2 ] sffp_mmc C:\Windows\system32\drivers\sffp_mmc.sys 07:00:27.0341 2432 sffp_mmc - ok 07:00:27.0353 2432 [ 35E59EBE4A01A0532ED67975161C7B82 ] sffp_sd C:\Windows\system32\drivers\sffp_sd.sys 07:00:27.0360 2432 sffp_sd - ok 07:00:27.0371 2432 [ 6B7838C94135768BD455CBDC23E39E5F ] sfloppy C:\Windows\system32\drivers\sfloppy.sys 07:00:27.0375 2432 sfloppy - ok 07:00:27.0402 2432 [ 4C5AEE179DA7E1EE9A9CCB9DA289AF34 ] SharedAccess C:\Windows\System32\ipnathlp.dll 07:00:27.0426 2432 SharedAccess - ok 07:00:27.0461 2432 [ 56793271ECDEDD350C5ADD305603E963 ] ShellHWDetection C:\Windows\System32\shsvcs.dll 07:00:27.0465 2432 ShellHWDetection - ok 07:00:27.0480 2432 [ 7A5DE502AEB719D4594C6471060A78B3 ] SiSRaid2 C:\Windows\system32\drivers\sisraid2.sys 07:00:27.0486 2432 SiSRaid2 - ok 07:00:27.0508 2432 [ 3A2F769FAB9582BC720E11EA1DFB184D ] SiSRaid4 C:\Windows\system32\drivers\sisraid4.sys 07:00:27.0515 2432 SiSRaid4 - ok 07:00:27.0650 2432 [ D0776778A9FC5E37F2E9EB21FC8A9709 ] Skype C2C Service C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe 07:00:27.0670 2432 Skype C2C Service - ok 07:00:27.0741 2432 [ 3E587DBBDFF938DDE5D4CE4047BE9041 ] SkypeUpdate C:\Program Files (x86)\Skype\Updater\Updater.exe 07:00:27.0793 2432 SkypeUpdate - ok 07:00:27.0859 2432 [ A9A27A8E257B45A604FDAD4F26FE7241 ] slsvc C:\Windows\system32\SLsvc.exe 07:00:27.0895 2432 slsvc - ok 07:00:27.0923 2432 [ FD74B4B7C2088E390A30C85A896FC3AF ] SLUINotify C:\Windows\system32\SLUINotify.dll 07:00:27.0925 2432 SLUINotify - ok 07:00:27.0952 2432 [ 290B6F6A0EC4FCDFC90F5CB6D7020473 ] Smb C:\Windows\system32\DRIVERS\smb.sys 07:00:27.0958 2432 Smb - ok 07:00:27.0984 2432 [ F8F47F38909823B1AF28D60B96340CFF ] SNMPTRAP C:\Windows\System32\snmptrap.exe 07:00:27.0986 2432 SNMPTRAP - ok 07:00:28.0016 2432 [ BDCE0DE74BC57ABD1EF2CE6AEAC37876 ] Software Services Manager C:\Program Files\intel\inteldh\common\IntelDHSvcMgr.exe 07:00:28.0017 2432 Software Services Manager - ok 07:00:28.0047 2432 [ 386C3C63F00A7040C7EC5E384217E89D ] spldr C:\Windows\system32\drivers\spldr.sys 07:00:28.0053 2432 spldr - ok 07:00:28.0093 2432 [ F66FF751E7EFC816D266977939EF5DC3 ] Spooler C:\Windows\System32\spoolsv.exe 07:00:28.0097 2432 Spooler - ok 07:00:28.0151 2432 [ 88E5162E58C8919CC873F5D8946197CF ] sptd C:\Windows\system32\Drivers\sptd.sys 07:00:28.0151 2432 Suspicious file (NoAccess): C:\Windows\system32\Drivers\sptd.sys. md5: 88E5162E58C8919CC873F5D8946197CF 07:00:28.0153 2432 sptd ( LockedFile.Multi.Generic ) - warning 07:00:28.0153 2432 sptd - detected LockedFile.Multi.Generic (1) 07:00:28.0189 2432 [ 880A57FCCB571EBD063D4DD50E93E46D ] srv C:\Windows\system32\DRIVERS\srv.sys 07:00:28.0211 2432 srv - ok 07:00:28.0243 2432 [ A1AD14A6D7A37891FFFECA35EBBB0730 ] srv2 C:\Windows\system32\DRIVERS\srv2.sys 07:00:28.0250 2432 srv2 - ok 07:00:28.0270 2432 [ 4BED62F4FA4D8300973F1151F4C4D8A7 ] srvnet C:\Windows\system32\DRIVERS\srvnet.sys 07:00:28.0278 2432 srvnet - ok 07:00:28.0308 2432 [ 192C74646EC5725AEF3F80D19FF75F6A ] SSDPSRV C:\Windows\System32\ssdpsrv.dll 07:00:28.0311 2432 SSDPSRV - ok 07:00:28.0326 2432 [ 2EE3FA0308E6185BA64A9A7F2E74332B ] SstpSvc C:\Windows\system32\sstpsvc.dll 07:00:28.0329 2432 SstpSvc - ok 07:00:28.0386 2432 [ 394BC2EEC0D81F70B80B0D951665A690 ] Steam Client Service C:\Program Files (x86)\Common Files\Steam\SteamService.exe 07:00:28.0390 2432 Steam Client Service - ok 07:00:28.0452 2432 [ 5A19667A580B1CE886EAF968B9743F45 ] Stereo Service C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe 07:00:28.0455 2432 Stereo Service - ok 07:00:28.0494 2432 [ 15825C1FBFB8779992CB65087F316AF5 ] stisvc C:\Windows\System32\wiaservc.dll 07:00:28.0510 2432 stisvc - ok 07:00:28.0539 2432 [ 8A851CA908B8B974F89C50D2E18D4F0C ] swenum C:\Windows\system32\DRIVERS\swenum.sys 07:00:28.0543 2432 swenum - ok 07:00:28.0577 2432 [ 6DE37F4DE19D4EFD9C48C43ADDBC949A ] swprv C:\Windows\System32\swprv.dll 07:00:28.0593 2432 swprv - ok 07:00:28.0616 2432 [ 2F26A2C6FC96B29BEFF5D8ED74E6625B ] Symc8xx C:\Windows\system32\drivers\symc8xx.sys 07:00:28.0621 2432 Symc8xx - ok 07:00:28.0664 2432 [ A909667976D3BCCD1DF813FED517D837 ] Sym_hi C:\Windows\system32\drivers\sym_hi.sys 07:00:28.0671 2432 Sym_hi - ok 07:00:28.0681 2432 [ 36887B56EC2D98B9C362F6AE4DE5B7B0 ] Sym_u3 C:\Windows\system32\drivers\sym_u3.sys 07:00:28.0686 2432 Sym_u3 - ok 07:00:28.0727 2432 [ 92D7A8B0F87B036F17D25885937897A6 ] SysMain C:\Windows\system32\sysmain.dll 07:00:28.0742 2432 SysMain - ok 07:00:28.0756 2432 [ 005CE42567F9113A3BCCB3B20073B029 ] TabletInputService C:\Windows\System32\TabSvc.dll 07:00:28.0759 2432 TabletInputService - ok 07:00:28.0781 2432 [ 595CB8DA5B522AD8CC28193DC21FD496 ] tap0901 C:\Windows\system32\DRIVERS\tap0901.sys 07:00:28.0785 2432 tap0901 - ok 07:00:28.0814 2432 [ CC2562B4D55E0B6A4758C65407F63B79 ] TapiSrv C:\Windows\System32\tapisrv.dll 07:00:28.0819 2432 TapiSrv - ok 07:00:28.0834 2432 [ CDBE8D7C1E201B911CDC346D06617FB5 ] TBS C:\Windows\System32\tbssvc.dll 07:00:28.0836 2432 TBS - ok 07:00:28.0880 2432 [ C2CB949645C299E23FBFD26CAD3FC96E ] Tcpip C:\Windows\system32\drivers\tcpip.sys 07:00:28.0933 2432 Tcpip - ok 07:00:28.0991 2432 [ C2CB949645C299E23FBFD26CAD3FC96E ] Tcpip6 C:\Windows\system32\DRIVERS\tcpip.sys 07:00:29.0000 2432 Tcpip6 - ok 07:00:29.0029 2432 [ C7E72A4071EE0200E3C075DACFB2B334 ] tcpipreg C:\Windows\system32\drivers\tcpipreg.sys 07:00:29.0034 2432 tcpipreg - ok 07:00:29.0049 2432 [ 1D8BF4AAA5FB7A2761475781DC1195BC ] TDPIPE C:\Windows\system32\drivers\tdpipe.sys 07:00:29.0053 2432 TDPIPE - ok 07:00:29.0065 2432 [ 7F7E00CDF609DF657F4CDA02DD1C9BB1 ] TDTCP C:\Windows\system32\drivers\tdtcp.sys 07:00:29.0070 2432 TDTCP - ok 07:00:29.0093 2432 [ 458919C8C42E398DC4802178D5FFEE27 ] tdx C:\Windows\system32\DRIVERS\tdx.sys 07:00:29.0099 2432 tdx - ok 07:00:29.0132 2432 [ 8C19678D22649EC002EF2282EAE92F98 ] TermDD C:\Windows\system32\DRIVERS\termdd.sys 07:00:29.0138 2432 TermDD - ok 07:00:29.0174 2432 [ 5CDD30BC217082DAC71A9878D9BFD566 ] TermService C:\Windows\System32\termsrv.dll 07:00:29.0190 2432 TermService - ok 07:00:29.0202 2432 [ 56793271ECDEDD350C5ADD305603E963 ] Themes C:\Windows\system32\shsvcs.dll 07:00:29.0206 2432 Themes - ok 07:00:29.0227 2432 [ 3CBE4995E80E13CCFBC42E5DCF3AC81A ] THREADORDER C:\Windows\system32\mmcss.dll 07:00:29.0229 2432 THREADORDER - ok 07:00:29.0244 2432 [ F4689F05AF472A651A7B1B7B02D200E7 ] TrkWks C:\Windows\System32\trkwks.dll 07:00:29.0247 2432 TrkWks - ok 07:00:29.0295 2432 [ 66328B08EF5A9305D8EDE36B93930369 ] TrustedInstaller C:\Windows\servicing\TrustedInstaller.exe 07:00:29.0296 2432 TrustedInstaller - ok 07:00:29.0308 2432 [ B2388462329ACD17AF50D8701E0C1B18 ] tssecsrv C:\Windows\system32\DRIVERS\tssecsrv.sys 07:00:29.0313 2432 tssecsrv - ok 07:00:29.0337 2432 [ 89EC74A9E602D16A75A4170511029B3C ] tunmp C:\Windows\system32\DRIVERS\tunmp.sys 07:00:29.0341 2432 tunmp - ok 07:00:29.0357 2432 [ 30A9B3F45AD081BFFC3BCAA9C812B609 ] tunnel C:\Windows\system32\DRIVERS\tunnel.sys 07:00:29.0361 2432 tunnel - ok 07:00:29.0375 2432 [ FEC266EF401966311744BD0F359F7F56 ] uagp35 C:\Windows\system32\drivers\uagp35.sys 07:00:29.0381 2432 uagp35 - ok 07:00:29.0403 2432 [ 00C8CE31657624A125FDB90EFD554371 ] UBHelper C:\Windows\system32\drivers\UBHelper.sys 07:00:29.0408 2432 UBHelper - ok 07:00:29.0440 2432 [ FAF2640A2A76ED03D449E443194C4C34 ] udfs C:\Windows\system32\DRIVERS\udfs.sys 07:00:29.0450 2432 udfs - ok 07:00:29.0471 2432 [ 060507C4113391394478F6953A79EEDC ] UI0Detect C:\Windows\system32\UI0Detect.exe 07:00:29.0474 2432 UI0Detect - ok 07:00:29.0492 2432 [ 4EC9447AC3AB462647F60E547208CA00 ] uliagpkx C:\Windows\system32\drivers\uliagpkx.sys 07:00:29.0499 2432 uliagpkx - ok 07:00:29.0537 2432 [ 697F0446134CDC8F99E69306184FBBB4 ] uliahci C:\Windows\system32\drivers\uliahci.sys 07:00:29.0553 2432 uliahci - ok 07:00:29.0581 2432 [ 31707F09846056651EA2C37858F5DDB0 ] UlSata C:\Windows\system32\drivers\ulsata.sys 07:00:29.0589 2432 UlSata - ok 07:00:29.0616 2432 [ 85E5E43ED5B48C8376281BAB519271B7 ] ulsata2 C:\Windows\system32\drivers\ulsata2.sys 07:00:29.0624 2432 ulsata2 - ok 07:00:29.0633 2432 [ 46E9A994C4FED537DD951F60B86AD3F4 ] umbus C:\Windows\system32\DRIVERS\umbus.sys 07:00:29.0638 2432 umbus - ok 07:00:29.0711 2432 [ 67A95B9D129ED5399E7965CD09CF30E7 ] UMVPFSrv C:\Program Files (x86)\Common Files\logishrd\LVMVFM\UMVPFSrv.exe 07:00:29.0714 2432 UMVPFSrv - ok 07:00:29.0732 2432 [ 7093799FF80E9DECA0680D2E3535BE60 ] upnphost C:\Windows\System32\upnphost.dll 07:00:29.0738 2432 upnphost - ok 07:00:29.0782 2432 [ AF1B9474D67897D0C2CFF58E0ACEACCC ] USBAAPL64 C:\Windows\system32\Drivers\usbaapl64.sys 07:00:29.0787 2432 USBAAPL64 - ok 07:00:29.0817 2432 [ C6BA890DE6E41857FBE84175519CAE7D ] usbaudio C:\Windows\system32\drivers\usbaudio.sys 07:00:29.0823 2432 usbaudio - ok 07:00:29.0848 2432 [ 07E3498FC60834219D2356293DA0FECC ] usbccgp C:\Windows\system32\DRIVERS\usbccgp.sys 07:00:29.0854 2432 usbccgp - ok 07:00:29.0875 2432 [ 9247F7E0B65852C1F6631480984D6ED2 ] usbcir C:\Windows\system32\drivers\usbcir.sys 07:00:29.0884 2432 usbcir - ok 07:00:29.0903 2432 [ 827E44DE934A736EA31E91D353EB126F ] usbehci C:\Windows\system32\DRIVERS\usbehci.sys 07:00:29.0908 2432 usbehci - ok 07:00:29.0937 2432 [ BB35CD80A2ECECFADC73569B3D70C7D1 ] usbhub C:\Windows\system32\DRIVERS\usbhub.sys 07:00:29.0953 2432 usbhub - ok 07:00:29.0969 2432 [ EBA14EF0C07CEC233F1529C698D0D154 ] usbohci C:\Windows\system32\drivers\usbohci.sys 07:00:29.0974 2432 usbohci - ok 07:00:29.0994 2432 [ 28B693B6D31E7B9332C1BDCEFEF228C1 ] usbprint C:\Windows\system32\DRIVERS\usbprint.sys 07:00:29.0999 2432 usbprint - ok 07:00:30.0030 2432 [ EA0BF666868964FBE8CB10E50C97B9F1 ] usbscan C:\Windows\system32\DRIVERS\usbscan.sys 07:00:30.0035 2432 usbscan - ok 07:00:30.0042 2432 [ B854C1558FCA0C269A38663E8B59B581 ] USBSTOR C:\Windows\system32\DRIVERS\USBSTOR.SYS 07:00:30.0048 2432 USBSTOR - ok 07:00:30.0053 2432 [ B2872CBF9F47316ABD0E0C74A1ABA507 ] usbuhci C:\Windows\system32\DRIVERS\usbuhci.sys 07:00:30.0057 2432 usbuhci - ok 07:00:30.0082 2432 [ FC33099877790D51B0927B7039059855 ] usbvideo C:\Windows\system32\Drivers\usbvideo.sys 07:00:30.0089 2432 usbvideo - ok 07:00:30.0117 2432 [ D76E231E4850BB3F88A3D9A78DF191E3 ] UxSms C:\Windows\System32\uxsms.dll 07:00:30.0120 2432 UxSms - ok 07:00:30.0153 2432 [ 294945381DFA7CE58CECF0A9896AF327 ] vds C:\Windows\System32\vds.exe 07:00:30.0170 2432 vds - ok 07:00:30.0184 2432 [ 916B94BCF1E09873FFF2D5FB11767BBC ] vga C:\Windows\system32\DRIVERS\vgapnp.sys 07:00:30.0188 2432 vga - ok 07:00:30.0193 2432 [ B83AB16B51FEDA65DD81B8C59D114D63 ] VgaSave C:\Windows\System32\drivers\vga.sys 07:00:30.0198 2432 VgaSave - ok 07:00:30.0211 2432 [ 8294B6C3FDB6C33F24E150DE647ECDAA ] viaide C:\Windows\system32\drivers\viaide.sys 07:00:30.0216 2432 viaide - ok 07:00:30.0232 2432 [ 2B7E885ED951519A12C450D24535DFCA ] volmgr C:\Windows\system32\drivers\volmgr.sys 07:00:30.0238 2432 volmgr - ok 07:00:30.0276 2432 [ CEC5AC15277D75D9E5DEC2E1C6EAF877 ] volmgrx C:\Windows\system32\drivers\volmgrx.sys 07:00:30.0288 2432 volmgrx - ok 07:00:30.0317 2432 [ 582F710097B46140F5A89A19A6573D4B ] volsnap C:\Windows\system32\drivers\volsnap.sys 07:00:30.0341 2432 volsnap - ok 07:00:30.0355 2432 [ A68F455ED2673835209318DD61BFBB0E ] vsmraid C:\Windows\system32\drivers\vsmraid.sys 07:00:30.0363 2432 vsmraid - ok 07:00:30.0406 2432 [ B75232DAD33BFD95BF6F0A3E6BFF51E1 ] VSS C:\Windows\system32\vssvc.exe 07:00:30.0431 2432 VSS - ok 07:00:30.0473 2432 [ F14A7DE2EA41883E250892E1E5230A9A ] W32Time C:\Windows\system32\w32time.dll 07:00:30.0479 2432 W32Time - ok 07:00:30.0491 2432 [ FEF8FE5923FEAD2CEE4DFABFCE3393A7 ] WacomPen C:\Windows\system32\drivers\wacompen.sys 07:00:30.0496 2432 WacomPen - ok 07:00:30.0525 2432 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarp C:\Windows\system32\DRIVERS\wanarp.sys 07:00:30.0532 2432 Wanarp - ok 07:00:30.0536 2432 [ B8E7049622300D20BA6D8BE0C47C0CFD ] Wanarpv6 C:\Windows\system32\DRIVERS\wanarp.sys 07:00:30.0537 2432 Wanarpv6 - ok 07:00:30.0558 2432 [ B4E4C37D0AA6100090A53213EE2BF1C1 ] wcncsvc C:\Windows\System32\wcncsvc.dll 07:00:30.0574 2432 wcncsvc - ok 07:00:30.0590 2432 [ EA4B369560E986F19D93F45A881484AC ] WcsPlugInService C:\Windows\System32\WcsPlugInService.dll 07:00:30.0593 2432 WcsPlugInService - ok 07:00:30.0610 2432 [ 0C17A0816F65B89E362E682AD5E7266E ] Wd C:\Windows\system32\drivers\wd.sys 07:00:30.0616 2432 Wd - ok 07:00:30.0654 2432 [ 442783E2CB0DA19873B7A63833FF4CB4 ] Wdf01000 C:\Windows\system32\drivers\Wdf01000.sys 07:00:30.0684 2432 Wdf01000 - ok 07:00:30.0700 2432 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiServiceHost C:\Windows\system32\wdi.dll 07:00:30.0703 2432 WdiServiceHost - ok 07:00:30.0707 2432 [ C5EFDA73EBFCA8B02A094898DE0A9276 ] WdiSystemHost C:\Windows\system32\wdi.dll 07:00:30.0710 2432 WdiSystemHost - ok 07:00:30.0723 2432 [ 3E6D05381CF35F75EBB055544A8ED9AC ] WebClient C:\Windows\System32\webclnt.dll 07:00:30.0727 2432 WebClient - ok 07:00:30.0760 2432 [ 8D40BC587993F876658BF9FB0F7D3462 ] Wecsvc C:\Windows\system32\wecsvc.dll 07:00:30.0779 2432 Wecsvc - ok 07:00:30.0792 2432 [ 9C980351D7E96288EA0C23AE232BD065 ] wercplsupport C:\Windows\System32\wercplsupport.dll 07:00:30.0795 2432 wercplsupport - ok 07:00:30.0804 2432 [ 66B9ECEBC46683F47EDC06333C075FEF ] WerSvc C:\Windows\System32\WerSvc.dll 07:00:30.0807 2432 WerSvc - ok 07:00:30.0827 2432 WinDefend - ok 07:00:30.0835 2432 WinHttpAutoProxySvc - ok 07:00:30.0891 2432 [ D2E7296ED1BD26D8DB2799770C077A02 ] Winmgmt C:\Windows\system32\wbem\WMIsvc.dll 07:00:30.0893 2432 Winmgmt - ok 07:00:30.0951 2432 [ 6CBB0C68F13B9C2EC1B16F5FA5E7C869 ] WinRM C:\Windows\system32\WsmSvc.dll 07:00:31.0025 2432 WinRM - ok 07:00:31.0072 2432 [ EC339C8115E91BAED835957E9A677F16 ] Wlansvc C:\Windows\System32\wlansvc.dll 07:00:31.0111 2432 Wlansvc - ok 07:00:31.0192 2432 [ 2BACD71123F42CEA603F4E205E1AE337 ] wlidsvc C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE 07:00:31.0205 2432 wlidsvc - ok 07:00:31.0221 2432 [ E18AEBAAA5A773FE11AA2C70F65320F5 ] WmiAcpi C:\Windows\system32\DRIVERS\wmiacpi.sys 07:00:31.0222 2432 WmiAcpi - ok 07:00:31.0252 2432 [ 21FA389E65A852698B6A1341F36EE02D ] wmiApSrv C:\Windows\system32\wbem\WmiApSrv.exe 07:00:31.0261 2432 wmiApSrv - ok 07:00:31.0271 2432 WMPNetworkSvc - ok 07:00:31.0290 2432 [ CBC156C913F099E6680D1DF9307DB7A8 ] WPCSvc C:\Windows\System32\wpcsvc.dll 07:00:31.0305 2432 WPCSvc - ok 07:00:31.0333 2432 [ 490A18B4E4D53DC10879DEAA8E8B70D9 ] WPDBusEnum C:\Windows\system32\wpdbusenum.dll 07:00:31.0336 2432 WPDBusEnum - ok 07:00:31.0378 2432 [ 5E2401B3FC1089C90E081291357371A9 ] WpdUsb C:\Windows\system32\DRIVERS\wpdusb.sys 07:00:31.0378 2432 WpdUsb - ok 07:00:31.0500 2432 [ 8E344C1B4FE7EDE0E9055405B9987862 ] WPFFontCache_v0400 C:\Windows\Microsoft.NET\Framework64\v4.0.30319\WPF\WPFFontCache_v0400.exe 07:00:31.0514 2432 WPFFontCache_v0400 - ok 07:00:31.0550 2432 [ 8A900348370E359B6BFF6A550E4649E1 ] ws2ifsl C:\Windows\system32\drivers\ws2ifsl.sys 07:00:31.0554 2432 ws2ifsl - ok 07:00:31.0583 2432 [ 9EA3E6D0EF7A5C2B9181961052A4B01A ] wscsvc C:\Windows\system32\wscsvc.dll 07:00:31.0586 2432 wscsvc - ok 07:00:31.0591 2432 WSearch - ok 07:00:31.0669 2432 [ D9EF901DCA379CFE914E9FA13B73B4C4 ] wuauserv C:\Windows\system32\wuaueng.dll 07:00:31.0709 2432 wuauserv - ok 07:00:31.0742 2432 [ AB886378EEB55C6C75B4F2D14B6C869F ] WudfPf C:\Windows\system32\drivers\WudfPf.sys 07:00:31.0743 2432 WudfPf - ok 07:00:31.0764 2432 [ DDA4CAF29D8C0A297F886BFE561E6659 ] WUDFRd C:\Windows\system32\DRIVERS\WUDFRd.sys 07:00:31.0771 2432 WUDFRd - ok 07:00:31.0793 2432 [ B20F051B03A966392364C83F009F7D17 ] wudfsvc C:\Windows\System32\WUDFSvc.dll 07:00:31.0796 2432 wudfsvc - ok 07:00:31.0802 2432 ================ Scan global =============================== 07:00:31.0837 2432 [ 060DC3A7A9A2626031EB23D90151428D ] C:\Windows\system32\basesrv.dll 07:00:31.0865 2432 [ D665D594B7E11133D29D726BDDC7A5B0 ] C:\Windows\system32\winsrv.dll 07:00:31.0889 2432 [ D665D594B7E11133D29D726BDDC7A5B0 ] C:\Windows\system32\winsrv.dll 07:00:31.0923 2432 [ 934E0B7D77FF78C18D9F8891221B6DE3 ] C:\Windows\system32\services.exe 07:00:31.0927 2432 [Global] - ok 07:00:31.0928 2432 ================ Scan MBR ================================== 07:00:31.0934 2432 [ EF9CDC51B437D322D54016B68F003416 ] \Device\Harddisk0\DR0 07:00:34.0033 2432 \Device\Harddisk0\DR0 - ok 07:00:34.0038 2432 [ 8F558EB6672622401DA993E1E865C861 ] \Device\Harddisk6\DR6 07:00:34.0042 2432 \Device\Harddisk6\DR6 - ok 07:00:34.0047 2432 [ 5FB38429D5D77768867C76DCBDB35194 ] \Device\Harddisk7\DR7 07:00:34.0054 2432 \Device\Harddisk7\DR7 - ok 07:00:34.0054 2432 ================ Scan VBR ================================== 07:00:34.0057 2432 [ F37317A04E269FC7D3212197B7B9F501 ] \Device\Harddisk0\DR0\Partition1 07:00:34.0058 2432 \Device\Harddisk0\DR0\Partition1 - ok 07:00:34.0072 2432 [ F9408424C850BD05070FD9BC762A4383 ] \Device\Harddisk0\DR0\Partition2 07:00:34.0074 2432 \Device\Harddisk0\DR0\Partition2 - ok 07:00:34.0078 2432 [ C497324757B0F16BF7D8E585C2E62BF9 ] \Device\Harddisk6\DR6\Partition1 07:00:34.0079 2432 \Device\Harddisk6\DR6\Partition1 - ok 07:00:34.0084 2432 [ C1B8EEB1DD2BD4F572BD55F2202480C5 ] \Device\Harddisk7\DR7\Partition1 07:00:34.0085 2432 \Device\Harddisk7\DR7\Partition1 - ok 07:00:34.0086 2432 ============================================================ 07:00:34.0086 2432 Scan finished 07:00:34.0086 2432 ============================================================ 07:00:34.0098 8440 Detected object count: 1 07:00:34.0098 8440 Actual detected object count: 1 07:01:00.0305 8440 sptd ( LockedFile.Multi.Generic ) - skipped by user 07:01:00.0305 8440 sptd ( LockedFile.Multi.Generic ) - User select action: Skip
Hi FreyjaGoddess;)

Please run the F-Secure Online Scanner
Follow the Instruction here for installation.
Accept the License Agreement.
Once the ActiveX installs,Click Full System Scan
Once the download completes, the scan will begin automatically.
The scan will take some time to finish, so please be patient.
When the scan completes, click the Automatic cleaning (recommended) button.
Click the Show Report button and Copy&Paste the entire report in your next reply.
Malwarebytes Anti-Malware 1.75.0.1300 www.malwarebytes.org Database version: v2013.09.09.05 Windows Vista Service Pack 2 x64 NTFS Internet Explorer 9.0.8112.16421 Karri :: KARRI-PC [administrator] 11/09/2013 12:47:28 PM mbam-log-2013-09-11 (12-47-28).txt Scan type: Quick scan Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM Scan options disabled: P2P Objects scanned: 324025 Time elapsed: 4 minute(s), 28 second(s) Memory Processes Detected: 0 (No malicious items detected) Memory Modules Detected: 0 (No malicious items detected) Registry Keys Detected: 0 (No malicious items detected) Registry Values Detected: 0 (No malicious items detected) Registry Data Items Detected: 0 (No malicious items detected) Folders Detected: 3 C:\Users\Karri\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0113D088-8ED1-468C-B225-585A9C53B5E3} (PUP.Optional.TopArcadeHits.A) -> Quarantined and deleted successfully. C:\Users\Karri\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0113D088-8ED1-468C-B225-585A9C53B5E3}\chrome (PUP.Optional.TopArcadeHits.A) -> Quarantined and deleted successfully. C:\Users\Karri\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\{0113D088-8ED1-468C-B225-585A9C53B5E3}\chrome\content (PUP.Optional.TopArcadeHits.A) -> Quarantined and deleted successfully. Files Detected: 0 (No malicious items detected) (end)
Hi Freyja ;)

Clean up with OTL:
  • Double-click OTL.exe to start the program.
  • Close all other programs apart from OTL as this step will require a reboot
  • On the OTL main screen, press the CLEANUP button
  • Say Yes to the prompt and then allow the program to reboot your computer.

Next


Scan with OTL
  • Download OTL to your desktop.
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • When the window appears, underneath Output at the top change it to Minimal Output.
  • Check the boxes beside LOP Check and Purity Check.
  • Under Custom Scan paste this in


    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    services.exe
    /md5stop
    %systemroot%\*. /rp /s
    %systemdrive%\$Recycle.Bin|@;true;true;true /fp
    DRIVES
    CREATERESTOREPOINT

  • Click the Run Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time, and post it with your next reply.
  • You may need two posts to fit them both in.
OTL logfile created on: 12/09/2013 7:35:10 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karri\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

7.93 Gb Total Physical Memory | 3.90 Gb Available Physical Memory | 49.15% Memory free
16.05 Gb Paging File | 10.21 Gb Available in Paging File | 63.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.59 Gb Total Space | 56.74 Gb Free Space | 24.40% Space Free | Partition Type: NTFS
Drive D: | 348.93 Gb Total Space | 90.22 Gb Free Space | 25.86% Space Free | Partition Type: NTFS
Drive J: | 295.02 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive N: | 3.79 Gb Total Space | 3.79 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive O: | 930.95 Gb Total Space | 813.57 Gb Free Space | 87.39% Space Free | Partition Type: FAT32

Computer Name: KARRI-PC | User Name: Karri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - C:\Users\Karri\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Karri\AppData\Local\Mikogo4\Viewer\Service\M4-Capture.exe ()
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
PRC - C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
PRC - C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
PRC - C:\Users\Karri\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe (Google)
PRC - C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
PRC - C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (APN LLC.)
PRC - C:\Users\Karri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
PRC - C:\Users\Karri\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
PRC - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
PRC - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
PRC - C:\Users\Karri\AppData\Local\Mikogo4\Viewer\Service\M4-Service.exe ()
PRC - C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\WinZip\WZQKPICK.EXE (WinZip Computing, S.L.)
PRC - C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
PRC - C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
PRC - C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
PRC - C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdateService.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdate.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaMonitorService.exe (CyberLink)
PRC - C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaService.exe (CyberLink Corp.)
PRC - C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe ()
PRC - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
PRC - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSMSNLoader32.exe (Egis inc.)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAAnotif.exe (Intel Corporation)
PRC - C:\Program Files\Intel\AMT\LMS.exe (Intel Corporation)
PRC - C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe (CyberLink)


========== Modules (No Company Name) ==========

MOD - C:\Program Files (x86)\Steam\bin\chromehtml.dll ()
MOD - C:\Users\Karri\AppData\Local\Google\Chrome\Application\29.0.1547.62\ppgooglenaclpluginchrome.dll ()
MOD - C:\Users\Karri\AppData\Local\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll ()
MOD - C:\Users\Karri\AppData\Local\Google\Chrome\Application\29.0.1547.62\pdf.dll ()
MOD - C:\Users\Karri\AppData\Local\Google\Chrome\Application\29.0.1547.62\libglesv2.dll ()
MOD - C:\Users\Karri\AppData\Local\Google\Chrome\Application\29.0.1547.62\libegl.dll ()
MOD - C:\Users\Karri\AppData\Local\Google\Chrome\Application\29.0.1547.62\ffmpegsumo.dll ()
MOD - C:\Program Files (x86)\Steam\SDL2.dll ()
MOD - C:\Program Files (x86)\Steam\bin\libcef.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avcodec-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avformat-53.dll ()
MOD - C:\Program Files (x86)\Steam\bin\avutil-51.dll ()
MOD - C:\Users\Karri\AppData\Roaming\Dropbox\bin\libcef.dll ()
MOD - C:\Users\Karri\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll ()
MOD - C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll ()
MOD - C:\Program Files (x86)\Common Files\LogiShrd\SharedBin\LvApi11.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTXml4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QJpeg4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\ImageFormats\QGif4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTGui4.dll ()
MOD - C:\Program Files (x86)\Logitech\LWS\Webcam Software\QTCore4.dll ()
MOD - C:\Program Files (x86)\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\vpxmd.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\SDL.dll ()
MOD - C:\Program Files (x86)\Microsoft Office\Office14\1033\GrooveIntlResource.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtNetwork4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtCore4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qjpeg4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qico4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\plugins\imageformats\qgif4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtWebKit4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtXml4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtSql4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtOpenGL4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\QtGui4.dll ()
MOD - C:\Program Files (x86)\Logitech\Vid HD\phonon4.dll ()
MOD - C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe ()
MOD - C:\Program Files (x86)\NewTech Infosystems\NTI Backup Now 5\BkupTrayLOC.dll ()
MOD - C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQDEVCL.dll ()
MOD - C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMDLL.DLL ()


========== Services (SafeList) ==========

SRV:64bit: - (CrmSqlStartupSvc) – C:\Program Files\Microsoft Dynamics CRM\Client\bin\CrmSqlStartupSvc.exe (Microsoft Corporation)
SRV:64bit: - (c2wts) – C:\Program Files\Windows Identity Foundation\v3.5\c2wtshost.exe (Microsoft Corporation)
SRV:64bit: - (ME Services Manager) – C:\Program Files\Intel\inteldh\msm\MSM.exe (Intel® Corporation)
SRV:64bit: - (Software Services Manager) – C:\Program Files\Intel\inteldh\common\IntelDHSvcMgr.exe (Intel® Corporation)
SRV:64bit: - (LMS) – C:\Program Files\Intel\AMT\LMS.exe (Intel Corporation)
SRV:64bit: - (ETService) – C:\Program Files\Acer\Empowering Technology\Service\ETService.exe ()
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MpSvc.dll (Microsoft Corporation)
SRV - (AdobeFlashPlayerUpdateSvc) – C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (AntiVirSchedulerService) – C:\Program Files (x86)\Avira\AntiVir Desktop\sched.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirWebService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avwebgrd.exe (Avira Operations GmbH & Co. KG)
SRV - (AntiVirService) – C:\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe (Avira Operations GmbH & Co. KG)
SRV - (Steam Client Service) – C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (Skype C2C Service) – C:\ProgramData\Skype\Toolbars\Skype C2C Service\c2c_service.exe (Skype Technologies S.A.)
SRV - (APNMCP) – C:\Program Files (x86)\AskPartnerNetwork\Toolbar\apnmcp.exe (APN LLC.)
SRV - (MozillaMaintenance) – C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (SkypeUpdate) – C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (AdobeARMservice) – C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (nvUpdatusService) – C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe (NVIDIA Corporation)
SRV - (Stereo Service) – C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe (NVIDIA Corporation)
SRV - (M4-Service) – C:\Users\Karri\AppData\Local\Mikogo4\Viewer\Service\M4-Service.exe ()
SRV - (UMVPFSrv) – C:\Program Files (x86)\Common Files\LogiShrd\LVMVFM\UMVPFSrv.exe (Logitech Inc.)
SRV - (clr_optimization_v4.0.30319_32) – C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (Nero BackItUp Scheduler 4.0) – C:\Program Files (x86)\Common Files\Nero\Nero BackItUp 4\NBService.exe (Nero AG)
SRV - (clr_optimization_v2.0.50727_32) – C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (CyberLink Live Push Update Service) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdateService.exe (CyberLink)
SRV - (CyberLink Live Monitor Service) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaMonitorService.exe (CyberLink)
SRV - (CyberLink Live Service) – C:\Program Files (x86)\CyberLink\CyberLink Live\CLSomaService.exe (CyberLink Corp.)
SRV - (eDataSecurity Service) – C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDSService.exe (Egis Incorporated)
SRV - (IAANTMON) – C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\IAANTmon.exe (Intel Corporation)
SRV - (Acer HomeMedia Connect Service) – C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\CLMSServer.exe (CyberLink)


========== Driver Services (SafeList) ==========

DRV:64bit: - (avipbb) – C:\Windows\SysNative\DRIVERS\avipbb.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avgntflt) – C:\Windows\SysNative\DRIVERS\avgntflt.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (avkmgr) – C:\Windows\SysNative\DRIVERS\avkmgr.sys (Avira Operations GmbH & Co. KG)
DRV:64bit: - (cbfs3) – C:\Windows\SysNative\drivers\cbfs3.sys (EldoS Corporation)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\DRIVERS\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (LVUVC64) – C:\Windows\SysNative\DRIVERS\lvuvc64.sys (Logitech Inc.)
DRV:64bit: - (LVRS64) – C:\Windows\SysNative\DRIVERS\lvrs64.sys (Logitech Inc.)
DRV:64bit: - (tap0901) – C:\Windows\SysNative\DRIVERS\tap0901.sys (The OpenVPN Project)
DRV:64bit: - (WpdUsb) – C:\Windows\SysNative\DRIVERS\wpdusb.sys (Microsoft Corporation)
DRV:64bit: - (sptd) – C:\Windows\SysNative\Drivers\sptd.sys ()
DRV:64bit: - (NuidFltr) – C:\Windows\SysNative\DRIVERS\NuidFltr.sys (Microsoft Corporation)
DRV:64bit: - (igfx) – C:\Windows\SysNative\DRIVERS\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (psdvdisk) – C:\Windows\SysNative\DRIVERS\PSDVdisk.sys (Egis Incorporated)
DRV:64bit: - (PSDNServ) – C:\Windows\SysNative\DRIVERS\PSDNServ.sys (Egis Incorporated)
DRV:64bit: - (PSDFilter) – C:\Windows\SysNative\DRIVERS\psdfilter.sys (Egis Incorporated)
DRV:64bit: - (LVUSBS64) – C:\Windows\SysNative\drivers\LVUSBS64.sys (Logitech Inc.)
DRV:64bit: - (PID_PEPI) – C:\Windows\SysNative\DRIVERS\LV302V64.SYS (Logitech Inc.)
DRV:64bit: - (e1yexpress) – C:\Windows\SysNative\DRIVERS\e1y60x64.sys (Intel Corporation)
DRV:64bit: - (iaStor) – C:\Windows\SysNative\DRIVERS\iaStor.sys (Intel Corporation)
DRV:64bit: - (IntcHdmiAddService) – C:\Windows\SysNative\drivers\IntcHdmi.sys (Intel® Corporation)
DRV:64bit: - (HECIx64) – C:\Windows\SysNative\DRIVERS\HECIx64.sys (Intel Corporation)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\Drivers\NTIDrvr.sys (NewTech Infosystems, Inc.)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\drivers\UBHelper.sys (NewTech Infosystems Corporation)
DRV - (int15) – C:\Windows\SysWOW64\drivers\int15_64.sys (Acer, Inc.)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM;=IE8SRC
IE - HKLM\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACAW

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Secondary_Page_URL = http://global.acer.com [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,SearchDefaultBranded = 1
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://homepage.acer.com/rdr.aspx?b=ACAW&a;…;m=aspire_m5700
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKCU\..\SearchScopes,DefaultScope = {67A2568C-7A0A-4EED-AECC-B5405DE63B64}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}…amp;FORM=IE8SRC
IE - HKCU\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.com/search?sourceid=ie7&…amp;rlz=1I7ACAW
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

========== FireFox ==========

FF - prefs.js..browser.startup.homepage: "http://www.theweathernetwork.com/weather/caon0532"
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:22.0
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0020-ABCDEFFEDCBA}:6.0.20
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0021-ABCDEFFEDCBA}:6.0.21
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0023-ABCDEFFEDCBA}:6.0.23
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0024-ABCDEFFEDCBA}:6.0.24
FF - prefs.js..extensions.enabledItems: {23fcfd51-4958-4f00-80a3-ae97e717ed8b}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {6904342A-8307-11DF-A508-4AE2DFD72085}:2.1.1.94
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0026-ABCDEFFEDCBA}:6.0.26
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0029-ABCDEFFEDCBA}:6.0.29
FF - prefs.js..extensions.enabledItems: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA}:6.0.30
FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_8_800_168.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~2\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_11_8_800_168.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Player Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Player\npDivxPlayerPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.25.2: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.25.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter: C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll (Oberon-Media )
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.5: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@citrixonline.com/appdetectorplugin: C:\Users\Karri\AppData\Local\Citrix\Plugins\79\npappdetector.dll (Citrix Online)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Karri\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Karri\AppData\Local\Google\Update\1.3.21.153\npGoogleUpdate3.dll (Google Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/06/27 12:28:38 | 000,000,000 | —D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/09/08 10:02:48 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2013/06/27 12:28:38 | 000,000,000 | —D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Mozilla Firefox 22.0\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2013/09/08 10:02:48 | 000,000,000 | —D | M]

[2009/10/29 13:03:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Karri\AppData\Roaming\Mozilla\Extensions
[2009/10/29 13:03:00 | 000,000,000 | —D | M] (No name found) – C:\Users\Karri\AppData\Roaming\Mozilla\Extensions\[removed]
[2013/09/08 10:06:23 | 000,000,000 | —D | M] (No name found) – C:\Users\Karri\AppData\Roaming\Mozilla\Firefox\Profiles\3rkyge3u.default\extensions
[2011/10/15 14:35:37 | 000,000,000 | —D | M] (Microsoft .NET Framework Assistant) – C:\Users\Karri\AppData\Roaming\Mozilla\Firefox\Profiles\3rkyge3u.default\extensions\{20a82645-c095-46ed-80e3-08825760534b}
[2013/09/01 20:04:08 | 000,824,302 | —- | M] () (No name found) – C:\Users\Karri\AppData\Roaming\Mozilla\Firefox\Profiles\3rkyge3u.default\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2013/08/20 08:37:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/08/20 08:37:46 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/06/27 12:28:38 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA}
[2013/06/27 12:28:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0035-ABCDEFFEDCBA}
[2013/06/27 12:28:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0037-ABCDEFFEDCBA}
[2013/06/27 12:28:39 | 000,000,000 | —D | M] (Java Console) – C:\Program Files (x86)\Mozilla Firefox\extensions\{CAFEEFAC-0016-0000-0038-ABCDEFFEDCBA}
[2013/08/20 08:37:10 | 000,000,000 | —D | M] (No name found) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2013/08/20 08:37:46 | 000,000,000 | —D | M] (Skype Click to Call) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{82AF8DCA-6DE9-405D-BD5E-43525BDAD38A}
[2013/06/27 12:28:47 | 000,000,000 | —D | M] (Default) – C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncodin
g}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}sugkey={google:suggestAPIKeyPar
ameter}
CHR - homepage: http://www.google.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Karri\AppData\Local\Google\Chrome\Application\29.0.1547.62\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Karri\AppData\Local\Google\Chrome\Application\29.0.1547.62\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Users\Karri\AppData\Local\Google\Chrome\Application\29.0.1547.62\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npCouponPrinter.dll
CHR - plugin: DivX Player Netscape Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npDivxPlayerPlugin.dll
CHR - plugin: Microsoft Lync 2010 Meeting Join Plug-in (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npMeetingJoinPluginOC.dll
CHR - plugin: Coupons Inc., Coupon Printer Manager (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npMozCouponPrinter.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.3 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Google Talk Plugin Video Renderer (Enabled) = C:\Users\Karri\AppData\Roaming\Mozilla\plugins\npo1d.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Oberon com adapter (Enabled) = C:\Program Files (x86)\Common Files\Oberon Media\NCAdapter\1.0.0.7\npapicomadapter.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Java™ Platform SE 7 U17 (Enabled) = C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Citrix Online Web Deployment Plugin 1.0.0.79 (Enabled) = C:\Users\Karri\AppData\Local\Citrix\Plugins\79\npappdetector.dll
CHR - plugin: Google Update (Enabled) = C:\Users\Karri\AppData\Local\Google\Update\1.3.21.135\npGoogleUpdate3.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll
CHR - plugin: Java Deployment Toolkit 7.0.170.2 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll
CHR - Extension: Entanglement Web App = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\3.4.9_0\
CHR - Extension: AT_JamesWhite = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\bkeidgmehkdjmpjodpjkepolokanalkm\3\
CHR - Extension: AdBlock = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.6_0\
CHR - Extension: Skype Click to Call = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\lifbcibllhkdhoafpjfnlhfpfgnpldfl\6.11.0.13348_0\
CHR - Extension: Poppit = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Karri\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.11_0\

O1 HOSTS File: ([2013/09/12 07:17:55 | 000,000,027 | —- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (ShowBarObj Class) - {83A2F9B1-01A2-4AA5-87D1-45B6B8505E96} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\ActiveToolBand.dll (Egis)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (no name) - {41564952-412D-5637-00A7-7A786E7484D7} - No CLSID value found.
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O3:64bit: - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (no name) - {41564952-412D-5637-00A7-7A786E7484D7} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477e-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDStoolbar.dll (Egis Incorporated.)
O3 - HKCU\..\Toolbar\ShellBrowser: (Acer eDataSecurity Management) - {5CBE3B7C-1E47-477E-A7DD-396DB0476E29} - C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x86\eDStoolbar.dll (Egis Incorporated.)
O4:64bit: - HKLM..\Run: [Acer Empowering Technology Monitor] C:\Program Files\Acer\Empowering Technology\SysMonitor.exe ()
O4:64bit: - HKLM..\Run: [eDataSecurity Loader] C:\Program Files (x86)\Acer\Empowering Technology\eDataSecurity\x64\eDSloader.exe (Egis Incorporated)
O4:64bit: - HKLM..\Run: [EmpoweringTechnology] C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe boot File not found
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IAAnotif] C:\Program Files (x86)\Intel\Intel Matrix Storage Manager\iaanotif.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IntelSWUpdateClient] C:\Program Files\Intel\inteldh\common\SWUpdateClient.exe (Intel® Corporation)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Windows\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [Acer Assist Launcher] C:\Program Files (x86)\Acer\Acer Assist\launcher.exe ()
O4 - HKLM..\Run: [Acer Product Registration] C:\Program Files (x86)\Acer\Acer Registration\ACE1.exe (Leader Technologies)
O4 - HKLM..\Run: [ACQTMOUSE] C:\Program Files (x86)\Mouse Setting\Mouse Setting Software\4.0\ACQTMAPP.exe ()
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avgnt] C:\Program Files (x86)\Avira\AntiVir Desktop\avgnt.exe (Avira Operations GmbH & Co. KG)
O4 - HKLM..\Run: [CLPushUpdate] C:\Program Files (x86)\CyberLink\CyberLink Live\CLPushUpdate.exe (CyberLink)
O4 - HKLM..\Run: [LWS] C:\Program Files (x86)\Logitech\LWS\Webcam Software\LWS.exe (Logitech Inc.)
O4 - HKLM..\Run: [PCMMediaSharing] C:\Program Files (x86)\Acer Arcade Live\Acer HomeMedia Connect\Kernel\DMS\PCMMediaSharing.exe ()
O4 - HKCU..\Run: [DAEMON Tools Lite] C:\Program Files (x86)\DAEMON Tools Lite\daemon.exe (DT Soft Ltd)
O4 - HKCU..\Run: [EADM] C:\Program Files (x86)\Origin\Origin.exe (Electronic Arts)
O4 - HKCU..\Run: [Logitech Vid] C:\Program Files (x86)\Logitech\Vid HD\Vid.exe (Logitech Inc.)
O4 - HKCU..\Run: [SansaDispatch] C:\Users\Karri\AppData\Roaming\SanDisk\Sansa Updater\SansaDispatch.exe (SanDisk Corporation)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\Steam.exe (Valve Corporation)
O4 - HKCU..\Run: [WindowsWelcomeCenter] C:\Windows\SysWow64\oobefldr.dll (Microsoft Corporation)
O4 - Startup: C:\Users\Karri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Karri\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:64bit: - Extra context menu item: Add to Google Photos Screensa&ver; - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8 - Extra context menu item: Add to Google Photos Screensa&ver; - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O9:64bit: - Extra Button: Skype Click to Call - {898EA8C8-E7FF-479B-8935-AEC46303B9E5} - Reg Error: Key error. File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000005 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000006 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000007 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000008 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10:64bit: - Protocol_Catalog9\Catalog_Entries64\000000000019 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda64.dll (Avira Operations GmbH & Co. KG)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - Protocol_Catalog9\Catalog_Entries\000000000001 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000002 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000003 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000004 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000005 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000006 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000007 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000008 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O10 - Protocol_Catalog9\Catalog_Entries\000000000019 - C:\Program Files (x86)\Avira\AntiVir Desktop\avsda.dll (Avira Operations GmbH & Co. KG)
O13 - gopher Prefix: missing
O16 - DPF: {2EB1E425-74DC-4DC0-A9E1-03A4C852E1F2} http://www.shockwave.com/content/trijinx/s…nx.1.0.0.86.cab (CPlayFirstTriJinxControl Object)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset.com/special/eos/OnlineScanner.cab (OnlineScanner Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3DF7249C-DC40-4434-8123-8375B94A51F0}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\intu-qt2008 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-qt2009 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-tt2010 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-tt2011 - No CLSID value found
O18:64bit: - Protocol\Handler\intu-tt2012 - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer x64\skypeieplugin.dll (Skype Technologies S.A.)
O18 - Protocol\Handler\intu-qt2008 {05E53CE9-66C8-4a9e-A99F-FDB7A8E7B596} - C:\Program Files (x86)\QuickTax 2008\ic2008pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-qt2009 {03947252-2355-4e9b-B446-8CCC75C43370} - C:\Program Files (x86)\QuickTax 2009\ic2009pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2010 {97A0575E-2309-4e75-8509-B1F9390C4DE7} - C:\Program Files (x86)\TurboTax 2010\ic2010pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2011 {B3B5DAD9-E96D-45b4-B636-B6CF2F773DE1} - C:\Program Files (x86)\TurboTax 2011\ic2011pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\intu-tt2012 {02F985EF-502B-4597-993F-6BF9E004C138} - C:\Program Files (x86)\TurboTax 2012\ic2012pp.dll (Intuit Canada, a general partnership/une société en nom collectif.)
O18 - Protocol\Handler\ms-help - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O18 - Protocol\Handler\skype-ie-addon-data {91774881-D725-4E58-B298-07617B9B86A8} - C:\Program Files (x86)\Skype\Toolbars\Internet Explorer\skypeieplugin.dll (Skype Technologies S.A.)
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysNative\CbFsMntNtf3.dll (EldoS Corporation)
O21 - SSODL: EldosMountNotificator - {5FF49FE8-B332-4CB9-B102-FB6951629E55} - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O22:64bit: - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\Windows\SysNative\CbFsMntNtf3.dll (EldoS Corporation)
O22 - SharedTaskScheduler: {5FF49FE8-B332-4CB9-B102-FB6951629E55} - Virtual Storage Mount Notification - C:\Windows\SysWOW64\CbFsMntNtf3.dll (EldoS Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img16.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img16.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2010/05/24 11:26:00 | 000,000,740 | R— | M] () - J:\autorun.inf – [ UDF ]
O32 - Unable to obtain root file information for disk N:\
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = ComFile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = ComFile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2013/09/12 07:34:22 | 000,602,112 | —- | C] (OldTimer Tools) – C:\Users\Karri\Desktop\OTL.exe
[2013/09/10 23:59:48 | 004,838,656 | —- | C] (F-Secure Corporation) – C:\Users\Karri\Desktop\F-SecureOnlineScanner.exe
[2013/09/09 10:04:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\ESET
[2013/09/09 10:04:27 | 002,347,384 | —- | C] (ESET) – C:\Users\Karri\Desktop\esetsmartinstaller_enu.exe
[2013/09/09 09:36:55 | 000,000,000 | -HSD | C] – C:\$RECYCLE.BIN
[2013/09/08 09:58:59 | 000,000,000 | —D | C] – C:\Windows\ERUNT
[2013/09/08 09:57:06 | 001,029,490 | —- | C] (Thisisu) – C:\Users\Karri\Desktop\JRT.exe
[2013/09/08 08:56:19 | 000,000,000 | —D | C] – C:\AdwCleaner
[2013/09/02 19:47:14 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Avira
[2013/09/02 19:42:54 | 000,000,000 | —D | C] – C:\ProgramData\AskPartnerNetwork
[2013/09/02 19:42:54 | 000,000,000 | —D | C] – C:\Program Files (x86)\AskPartnerNetwork
[2013/09/02 19:41:51 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Avira
[2013/09/02 19:41:46 | 000,132,088 | —- | C] (Avira Operations GmbH & Co. KG) – C:\Windows\SysNative\drivers\avipbb.sys
[2013/09/02 19:41:46 | 000,105,344 | —- | C] (Avira Operations GmbH & Co. KG) – C:\Windows\SysNative\drivers\avgntflt.sys
[2013/09/02 19:41:46 | 000,028,600 | —- | C] (Avira Operations GmbH & Co. KG) – C:\Windows\SysNative\drivers\avkmgr.sys
[2013/09/02 19:41:45 | 000,000,000 | —D | C] – C:\ProgramData\Avira
[2013/09/02 19:41:45 | 000,000,000 | —D | C] – C:\Program Files (x86)\Avira
[2013/08/28 10:49:01 | 001,706,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WMVDECOD.DLL
[2013/08/28 10:49:01 | 001,548,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\WMVDECOD.DLL
[2013/08/22 23:06:34 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/08/22 23:06:10 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/08/22 23:06:08 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/08/22 23:06:08 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/08/18 19:39:18 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Rainbow
[2013/08/18 19:37:21 | 000,000,000 | —D | C] – C:\Users\Karri\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Rush for Gold - Alaska
[2013/08/18 19:37:21 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Rush for Gold - Alaska
[2013/08/18 19:37:21 | 000,000,000 | —D | C] – C:\Program Files (x86)\Rush for Gold - Alaska
[2013/08/14 23:19:10 | 000,000,000 | —D | C] – C:\Windows\SysNative\MRT
[2013/08/14 23:16:50 | 000,248,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieui.dll
[2013/08/14 23:16:50 | 000,176,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieui.dll
[2013/08/14 23:16:50 | 000,096,768 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mshtmled.dll
[2013/08/14 23:16:50 | 000,073,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mshtmled.dll
[2013/08/14 23:16:49 | 000,237,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\url.dll
[2013/08/14 23:16:49 | 000,231,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\url.dll
[2013/08/14 23:16:49 | 000,173,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ieUnatt.exe
[2013/08/14 23:16:49 | 000,142,848 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ieUnatt.exe
[2013/08/14 23:16:48 | 002,312,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/08/14 23:16:48 | 001,494,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\inetcpl.cpl
[2013/08/14 23:16:48 | 001,427,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\inetcpl.cpl
[2013/08/14 23:16:48 | 000,729,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/08/14 23:16:47 | 000,816,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/08/14 23:16:47 | 000,717,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/08/14 23:16:47 | 000,599,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vbscript.dll
[2013/08/14 18:33:28 | 004,691,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/08/14 18:33:28 | 001,585,256 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntdll.dll
[2013/08/14 18:33:28 | 000,234,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wow64.dll
[2013/08/14 18:33:28 | 000,026,112 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\setup16.exe
[2013/08/14 18:33:28 | 000,016,384 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntvdm64.dll
[2013/08/14 18:33:28 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ntvdm64.dll
[2013/08/14 18:33:28 | 000,007,680 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\instnm.exe
[2013/08/14 18:33:28 | 000,005,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wow32.dll
[2013/08/14 18:33:28 | 000,002,560 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\user.exe
[2013/08/14 18:33:27 | 000,020,480 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\icaapi.dll
[2013/08/14 18:33:26 | 001,303,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rpcrt4.dll
[2013/08/14 18:33:21 | 001,276,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/08/14 18:33:21 | 000,218,624 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2013/08/14 18:33:21 | 000,132,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptnet.dll

========== Files - Modified Within 30 Days ==========

[2013/09/12 07:34:23 | 000,602,112 | —- | M] (OldTimer Tools) – C:\Users\Karri\Desktop\OTL.exe
[2013/09/12 07:33:13 | 003,380,726 | —- | M] () – C:\Users\Karri\Desktop\2013-09-11 13.56.07.jpg
[2013/09/12 07:32:56 | 000,486,713 | —- | M] () – C:\Users\Karri\Desktop\2013-09-11 20.11.56.jpg
[2013/09/12 07:28:15 | 000,000,830 | —- | M] () – C:\Windows\tasks\Adobe Flash Player Updater.job
[2013/09/12 07:17:55 | 000,065,536 | —- | M] () – C:\Windows\SysNative\Ikeext.etl
[2013/09/12 07:17:55 | 000,000,027 | —- | M] () – C:\Windows\SysNative\drivers\etc\hosts
[2013/09/12 07:17:22 | 000,003,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2013/09/12 07:17:22 | 000,003,344 | -H– | M] () – C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2013/09/12 07:17:20 | 000,393,832 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/09/12 07:17:12 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/09/10 23:59:56 | 004,838,656 | —- | M] (F-Secure Corporation) – C:\Users\Karri\Desktop\F-SecureOnlineScanner.exe
[2013/09/10 14:52:41 | 000,766,246 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/09/10 14:52:41 | 000,652,288 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/09/10 14:52:41 | 000,125,686 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/09/10 14:25:30 | 000,136,958 | —- | M] () – C:\Users\Karri\Desktop\1082628-6fJDIMOpH8INJ1NAKoH.PDF
[2013/09/10 13:28:28 | 000,692,616 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerApp.exe
[2013/09/10 13:28:28 | 000,071,048 | —- | M] (Adobe Systems Incorporated) – C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2013/09/10 11:19:09 | 000,005,588 | -HS- | M] () – C:\Users\Karri\Desktop\Folder.jpg
[2013/09/10 11:19:09 | 000,001,672 | -HS- | M] () – C:\Users\Karri\Desktop\AlbumArtSmall.jpg
[2013/09/10 07:30:21 | 000,242,516 | —- | M] () – C:\Users\Karri\Desktop\PDF_506540566207DA7D21817764E2831250CF419BC141B457EA5FB051B2B00548B9627EA58
3DF62BFF3_57_2013-09-01_0000000000.pdf
[2013/09/10 06:30:54 | 000,465,642 | —- | M] () – C:\Users\Karri\Desktop\2013-09-09 22.35.43.jpg
[2013/09/09 11:42:13 | 000,163,959 | —- | M] () – C:\Users\Karri\Desktop\DSC00504.jpg
[2013/09/09 10:04:32 | 002,347,384 | —- | M] (ESET) – C:\Users\Karri\Desktop\esetsmartinstaller_enu.exe
[2013/09/09 09:16:28 | 000,350,017 | —- | M] () – C:\Users\Karri\Desktop\Resume-ColinTudehope2013.pdf
[2013/09/08 10:12:46 | 003,787,264 | —- | M] () – C:\Users\Karri\Desktop\RogueKillerX64.exe
[2013/09/08 09:57:43 | 001,029,490 | —- | M] (Thisisu) – C:\Users\Karri\Desktop\JRT.exe
[2013/09/08 09:47:19 | 000,891,144 | —- | M] () – C:\Users\Karri\Desktop\SecurityCheck.exe
[2013/09/08 08:56:14 | 001,037,278 | —- | M] () – C:\Users\Karri\Desktop\adwcleaner.exe
[2013/09/08 08:46:51 | 000,132,088 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Windows\SysNative\drivers\avipbb.sys
[2013/09/08 08:46:51 | 000,105,344 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Windows\SysNative\drivers\avgntflt.sys
[2013/09/03 11:57:42 | 000,041,984 | —- | M] () – C:\Users\Karri\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2013/09/02 19:45:14 | 000,000,952 | —- | M] () – C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2013/09/02 19:41:51 | 000,001,905 | —- | M] () – C:\Users\Public\Desktop\Avira Control Center.lnk
[2013/09/02 19:41:17 | 000,028,600 | —- | M] (Avira Operations GmbH & Co. KG) – C:\Windows\SysNative\drivers\avkmgr.sys
[2013/09/02 17:28:49 | 002,092,792 | —- | M] () – C:\Users\Karri\Desktop\avira_free_antivirus.exe
[2013/09/01 09:58:22 | 000,002,048 | —- | M] () – C:\Users\Karri\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/09/01 09:58:22 | 000,002,046 | —- | M] () – C:\Users\Karri\Desktop\Google Chrome.lnk
[2013/08/29 11:35:02 | 000,000,680 | —- | M] () – C:\Users\Karri\AppData\Local\d3d9caps.dat
[2013/08/25 19:49:42 | 008,340,514 | —- | M] () – C:\Users\Karri\Desktop\Echo and the Bunnymen - The Killing Moon.mp3
[2013/08/22 23:06:34 | 000,001,698 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/08/20 12:23:47 | 000,999,707 | —- | M] () – C:\Users\Karri\Desktop\scan0002.jpg
[2013/08/18 19:34:38 | 000,000,683 | —- | M] () – C:\Users\Karri\Application Data\Microsoft\Internet Explorer\Quick Launch\rush-for-gold-alaska_s1_l1_gF6467T1L1_d2141755934 - Shortcut.lnk

========== Files Created - No Company Name ==========

[2013/09/12 07:33:13 | 003,380,726 | —- | C] () – C:\Users\Karri\Desktop\2013-09-11 13.56.07.jpg
[2013/09/12 07:32:56 | 000,486,713 | —- | C] () – C:\Users\Karri\Desktop\2013-09-11 20.11.56.jpg
[2013/09/10 14:25:28 | 000,136,958 | —- | C] () – C:\Users\Karri\Desktop\1082628-6fJDIMOpH8INJ1NAKoH.PDF
[2013/09/10 11:19:09 | 000,005,588 | -HS- | C] () – C:\Users\Karri\Desktop\Folder.jpg
[2013/09/10 11:19:09 | 000,001,672 | -HS- | C] () – C:\Users\Karri\Desktop\AlbumArtSmall.jpg
[2013/09/10 11:18:44 | 008,022,979 | R— | C] () – C:\Users\Karri\Desktop\02 Emeli Sandé - My Kind of Love.mp3
[2013/09/10 07:30:20 | 000,242,516 | —- | C] () – C:\Users\Karri\Desktop\PDF_506540566207DA7D21817764E2831250CF419BC141B457EA5FB051B2B00548B9627EA58
3DF62BFF3_57_2013-09-01_0000000000.pdf
[2013/09/09 22:47:23 | 000,465,642 | —- | C] () – C:\Users\Karri\Desktop\2013-09-09 22.35.43.jpg
[2013/09/09 11:42:12 | 000,163,959 | —- | C] () – C:\Users\Karri\Desktop\DSC00504.jpg
[2013/09/09 09:16:27 | 000,350,017 | —- | C] () – C:\Users\Karri\Desktop\Resume-ColinTudehope2013.pdf
[2013/09/08 10:12:30 | 003,787,264 | —- | C] () – C:\Users\Karri\Desktop\RogueKillerX64.exe
[2013/09/08 09:47:18 | 000,891,144 | —- | C] () – C:\Users\Karri\Desktop\SecurityCheck.exe
[2013/09/08 08:56:13 | 001,037,278 | —- | C] () – C:\Users\Karri\Desktop\adwcleaner.exe
[2013/09/02 19:41:51 | 000,001,905 | —- | C] () – C:\Users\Public\Desktop\Avira Control Center.lnk
[2013/09/02 17:27:47 | 002,092,792 | —- | C] () – C:\Users\Karri\Desktop\avira_free_antivirus.exe
[2013/08/25 19:19:34 | 008,340,514 | —- | C] () – C:\Users\Karri\Desktop\Echo and the Bunnymen - The Killing Moon.mp3
[2013/08/20 12:24:37 | 000,999,707 | —- | C] () – C:\Users\Karri\Desktop\scan0002.jpg
[2013/08/18 19:34:38 | 000,000,683 | —- | C] () – C:\Users\Karri\Application Data\Microsoft\Internet Explorer\Quick Launch\rush-for-gold-alaska_s1_l1_gF6467T1L1_d2141755934 - Shortcut.lnk
[2012/07/22 18:32:00 | 000,004,096 | —- | C] () – C:\Windows\d3dx.dat
[2012/02/01 18:18:15 | 000,000,552 | —- | C] () – C:\Users\Karri\AppData\Local\d3d8caps.dat
[2012/01/18 06:44:00 | 010,920,984 | —- | C] () – C:\Windows\SysWow64\LogiDPP.dll
[2012/01/18 06:44:00 | 000,336,408 | —- | C] () – C:\Windows\SysWow64\DevManagerCore.dll
[2012/01/18 06:44:00 | 000,104,472 | —- | C] () – C:\Windows\SysWow64\LogiDPPApp.exe
[2011/12/30 22:49:42 | 000,000,680 | —- | C] () – C:\Users\Karri\AppData\Local\d3d9caps.dat
[2011/10/10 18:52:43 | 000,752,602 | —- | C] () – C:\Windows\SysWow64\PerfStringBackup.INI
[2011/09/02 14:28:57 | 000,041,984 | —- | C] () – C:\Users\Karri\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2010/03/12 22:00:58 | 000,000,760 | —- | C] () – C:\Users\Karri\AppData\Roaming\setup_ldm.iss
[2009/09/21 12:30:38 | 000,000,029 | —- | C] () – C:\Users\Karri\AppData\Roaming\default.rss
[2009/09/15 12:40:54 | 000,000,056 | -H– | C] () – C:\ProgramData\ezsidmv.dat
[2009/06/28 11:50:52 | 000,048,127 | —- | C] () – C:\ProgramData\nvModes.dat
[2009/06/28 11:50:52 | 000,048,127 | —- | C] () – C:\ProgramData\nvModes.001
[2008/10/28 08:57:39 | 000,000,052 | —- | C] () – C:\ProgramData\CLSDefine.ini

========== ZeroAccess Check ==========

[2006/11/02 11:30:40 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2012/06/08 13:59:03 | 012,899,840 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2012/06/08 13:47:00 | 011,586,048 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2009/04/11 03:11:14 | 000,891,392 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\fastprox.dll – [2009/04/11 02:28:19 | 000,614,912 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2008/01/20 22:50:58 | 000,513,024 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\SysWow64\wbem\wbemess.dll

========== LOP Check ==========

[2010/12/18 12:49:09 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\.minecraft
[2012/11/19 12:51:06 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\1morebee
[2012/07/07 22:02:22 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\8floor
[2009/03/29 20:30:38 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Acer
[2008/10/28 09:17:30 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Acer GameZone Console
[2011/04/16 21:08:14 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\aliasworlds
[2012/07/14 16:40:16 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Anino Games
[2010/09/25 20:05:35 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Atlus
[2011/12/12 22:07:00 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\blg
[2009/08/06 13:12:47 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\DAEMON Tools Lite
[2012/09/17 20:00:26 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\DivoGames
[2013/09/12 07:19:38 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Dropbox
[2009/03/30 20:40:22 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\eSobi
[2009/04/06 07:42:54 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\FloodLightGames
[2012/11/20 08:53:50 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\GamesCafe
[2012/08/10 20:09:27 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\HipSoft
[2013/08/20 12:23:59 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Image Zone Express
[2012/01/03 20:40:28 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Islands2
[2012/07/22 18:32:17 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Jumb-O-Fun Games
[2009/03/29 20:30:38 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Leadertech
[2012/12/14 09:14:34 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\LimeWire
[2011/03/04 12:36:00 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\MumboJumbo
[2012/11/19 09:47:11 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\northern_tale_bfg_en
[2011/02/13 21:55:28 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Oberon Media
[2013/01/02 16:50:23 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\ooVoo Details
[2013/01/28 09:36:20 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Origin
[2012/01/20 20:35:58 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\PetRush
[2011/11/27 14:02:08 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Ph03nixNewMedia
[2012/04/07 16:11:40 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\PlayFirst
[2011/12/21 19:50:08 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Playrix Entertainment
[2012/09/13 19:58:22 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Princess Isabella CE
[2009/10/28 15:05:06 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Printer Info Cache
[2013/08/18 19:39:18 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\Rainbow
[2010/06/04 22:03:13 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\runic games
[2012/07/17 18:45:03 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\SanDisk
[2013/06/18 08:36:08 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\TeamViewer
[2013/09/10 18:28:27 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\uTorrent
[2011/12/18 19:18:25 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\ValuSoft
[2012/09/12 19:41:41 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\VC 2 Paradise Resort
[2012/09/16 19:51:24 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\ViquaSoft
[2012/01/02 13:34:19 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\WendigoStudios
[2012/07/14 16:18:47 | 000,000,000 | —D | M] – C:\Users\Karri\AppData\Roaming\YoudaGames

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2008/10/29 02:20:29 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_b5f700fe698beb14\explorer.exe
[2008/10/29 02:29:41 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_b7eb106e66a7ac19\explorer.exe
[2008/10/29 02:15:50 | 003,087,360 | —- | M] (Microsoft Corporation) MD5=50514057C28A74BAC2BD04B7B990D615 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_aba256ac352b2919\explorer.exe
[2008/10/29 23:59:17 | 002,927,616 | —- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_b8583e9d7fda0512\explorer.exe
[2009/04/11 03:10:17 | 003,079,168 | —- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 – C:\Windows\erdnt\cache86\explorer.exe
[2009/04/11 03:10:17 | 003,079,168 | —- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 – C:\Windows\explorer.exe
[2009/04/11 03:10:17 | 003,079,168 | —- | M] (Microsoft Corporation) MD5=6B08E54A451B3F95E4109DBA7E594270 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_afbebba22f3bab41\explorer.exe
[2008/10/27 22:30:12 | 003,086,848 | —- | M] (Microsoft Corporation) MD5=72B9990E45C25AA3C75C4FB50A9D6CE0 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_ac5266dd4e2b0a41\explorer.exe
[2008/10/29 02:49:22 | 003,080,704 | —- | M] (Microsoft Corporation) MD5=BBD8E74F23D7605CB0CDB57A1B25D826 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_ad96661c3246ea1e\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\SysWOW64\explorer.exe
[2009/04/11 02:27:36 | 002,926,592 | —- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_ba1365f4639c6d3c\explorer.exe
[2008/10/30 01:30:07 | 003,081,216 | —- | M] (Microsoft Corporation) MD5=E404A65EF890140410E9F3D405841C95 – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_ae03944b4b794317\explorer.exe
[2008/10/27 22:15:02 | 002,923,520 | —- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_b6a7112f828bcc3c\explorer.exe
[2008/01/20 22:48:44 | 003,080,704 | —- | M] (Microsoft Corporation) MD5=F6D765FB6B457542D954682F50C26E4F – C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_add342963219dff5\explorer.exe
[2008/01/20 22:49:23 | 002,927,104 | —- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F – C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_b827ece8667aa1f0\explorer.exe

< MD5 for: SERVICES.EXE >
[2006/11/02 07:16:09 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=0A87F57DFC2C0EB9BBA8BE1C87BAFE1A – C:\ACER\Preload\Acer\Recovery\HPartition\Windows\System32\services.exe
[2006/11/02 07:16:09 | 000,389,632 | —- | M] (Microsoft Corporation) MD5=0A87F57DFC2C0EB9BBA8BE1C87BAFE1A – C:\ACER\Preload\Acer\Recovery\HPartition\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_294799ef88bb616c\services.exe
[2008/01/20 22:50:34 | 000,279,040 | —- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2009/04/11 03:10:50 | 000,384,512 | —- | M] (Microsoft Corporation) MD5=934E0B7D77FF78C18D9F8891221B6DE3 – C:\Windows\erdnt\cache64\services.exe
[2009/04/11 03:10:50 | 000,384,512 | —- | M] (Microsoft Corporation) MD5=934E0B7D77FF78C18D9F8891221B6DE3 – C:\Windows\SysNative\services.exe
[2009/04/11 03:10:50 | 000,384,512 | —- | M] (Microsoft Corporation) MD5=934E0B7D77FF78C18D9F8891221B6DE3 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_2d69d4f782c83d8c\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\SysWOW64\services.exe
[2009/04/11 02:27:59 | 000,279,552 | —- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B – C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe
[2008/01/20 22:49:44 | 000,384,512 | —- | M] (Microsoft Corporation) MD5=DFAC660F0F139276CC9299812DE42719 – C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_2b7e5beb85a67240\services.exe

< MD5 for: SVCHOST.EXE >
[2008/01/20 22:48:05 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\erdnt\cache86\svchost.exe
[2008/01/20 22:48:05 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\SysWOW64\svchost.exe
[2008/01/20 22:48:05 | 000,021,504 | —- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF – C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe
[2006/11/02 07:16:13 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=6B30067D55E10E4DEBDC842FB1911479 – C:\ACER\Preload\Acer\Recovery\HPartition\Windows\System32\svchost.exe
[2006/11/02 07:16:13 | 000,026,624 | —- | M] (Microsoft Corporation) MD5=6B30067D55E10E4DEBDC842FB1911479 – C:\ACER\Preload\Acer\Recovery\HPartition\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_0fa33328c0c01e47\svchost.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2008/01/20 22:50:24 | 000,027,648 | —- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D – C:\Windows\erdnt\cache64\svchost.exe
[2008/01/20 22:50:24 | 000,027,648 | —- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D – C:\Windows\SysNative\svchost.exe
[2008/01/20 22:50:24 | 000,027,648 | —- | M] (Microsoft Corporation) MD5=CDA9F1373805AF88F6FA4F2064BBA24D – C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_11d9f524bdab2f1b\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/01/20 22:50:36 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\erdnt\cache86\userinit.exe
[2008/01/20 22:50:36 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\SysWOW64\userinit.exe
[2008/01/20 22:50:36 | 000,025,088 | —- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 – C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006/11/02 07:16:15 | 000,028,160 | —- | M] (Microsoft Corporation) MD5=46D5B6B80E4A5997F508F938F96B7628 – C:\ACER\Preload\Acer\Recovery\HPartition\Windows\System32\userinit.exe
[2006/11/02 07:16:15 | 000,028,160 | —- | M] (Microsoft Corporation) MD5=46D5B6B80E4A5997F508F938F96B7628 – C:\ACER\Preload\Acer\Recovery\HPartition\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_3610939d8d22586d\userinit.exe
[2008/01/20 22:49:46 | 000,028,160 | —- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE – C:\Windows\erdnt\cache64\userinit.exe
[2008/01/20 22:49:46 | 000,028,160 | —- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE – C:\Windows\SysNative\userinit.exe
[2008/01/20 22:49:46 | 000,028,160 | —- | M] (Microsoft Corporation) MD5=A0AB2BB9A92293D9CE66E252719AB5FE – C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_384755998a0d6941\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/04/11 03:11:08 | 000,405,504 | —- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A – C:\Windows\erdnt\cache64\winlogon.exe
[2009/04/11 03:11:08 | 000,405,504 | —- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A – C:\Windows\SysNative\winlogon.exe
[2009/04/11 03:11:08 | 000,405,504 | —- | M] (Microsoft Corporation) MD5=6D0773A3A65D28B663F334C90441D01A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_cdcd15a68a70b877\winlogon.exe
[2008/01/20 22:49:47 | 000,406,016 | —- | M] (Microsoft Corporation) MD5=856491FCED98093D824B9EB2892F564A – C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_cbe19c9a8d4eed2b\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\SysWOW64\winlogon.exe
[2009/04/11 02:28:13 | 000,314,368 | —- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006/11/02 07:16:20 | 000,397,312 | —- | M] (Microsoft Corporation) MD5=9642EED809219A2F914DD8E40A09C48B – C:\ACER\Preload\Acer\Recovery\HPartition\Windows\System32\winlogon.exe
[2006/11/02 07:16:20 | 000,397,312 | —- | M] (Microsoft Corporation) MD5=9642EED809219A2F914DD8E40A09C48B – C:\ACER\Preload\Acer\Recovery\HPartition\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_c9aada9e9063dc57\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2008/01/20 22:50:38 | 000,314,880 | —- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 – C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

< %systemroot%\*. /rp /s >

< %systemdrive%\$Recycle.Bin|@;true;true;true /fp >

========== Drive Information ==========

Physical Drives
—————

Drive: \\\\.\\PHYSICALDRIVE0 - Fixed hard disk media
Interface type: SCSI
Media Type: Fixed hard disk media
Model: WDC WD6400AAKS-22A7B2
Partitions: 3
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE1 -
Interface type: USB
Media Type:
Model: Generic- Compact Flash USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE2 -
Interface type: USB
Media Type:
Model: Generic- SM/xD-Picture USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE3 -
Interface type: USB
Media Type:
Model: Generic- SD/MMC USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE4 -
Interface type: USB
Media Type:
Model: Generic- MS/MS-Pro USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE5 -
Interface type: USB
Media Type:
Model: HP Officejet Pro L7 USB Device
Partitions: 0
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE6 - External hard disk media
Interface type: USB
Media Type: External hard disk media
Model: Hitachi HDS721010CLA332 USB Device
Partitions: 1
Status: OK
Status Info: 0

Drive: \\\\.\\PHYSICALDRIVE7 - Removable Media
Interface type: USB
Media Type: Removable Media
Model: Generic STORAGE DEVICE USB Device
Partitions: 1
Status: OK
Status Info: 0

Partitions
—————

DeviceID: Disk #0, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 15.00GB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #0, Partition #1
PartitionType: Installable File System
Bootable: True
BootPartition: True
PrimaryPartition: True
Size: 233.00GB
Starting Offset: 15735980032
Hidden sectors: 0


DeviceID: Disk #0, Partition #2
PartitionType: Installable File System
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 349.00GB
Starting Offset: 265475325952
Hidden sectors: 0


DeviceID: Disk #6, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 931.00GB
Starting Offset: 32256
Hidden sectors: 0


DeviceID: Disk #7, Partition #0
PartitionType: Unknown
Bootable: False
BootPartition: False
PrimaryPartition: True
Size: 4.00GB
Starting Offset: 4194304
Hidden sectors: 0


========== Files - Unicode (All) ==========
[2013/09/09 08:24:11 | 096,665,497 | —- | M] ()(C:\Windows\SysWow64\???¿) – C:\Windows\SysWow64\噮ᆎ¿
[2013/09/09 08:24:11 | 096,665,497 | —- | C] ()(C:\Windows\SysWow64\???¿) – C:\Windows\SysWow64\噮ᆎ¿
[2013/09/08 13:33:36 | 096,566,691 | —- | M] ()(C:\Windows\SysWow64\???¥) – C:\Windows\SysWow64\䇢�¥
[2013/09/08 13:33:36 | 096,566,691 | —- | C] ()(C:\Windows\SysWow64\???¥) – C:\Windows\SysWow64\䇢�¥
[2013/09/02 16:07:34 | 095,286,781 | —- | M] ()(C:\Windows\SysWow64\????) – C:\Windows\SysWow64\ᷟ舶Ÿ
[2013/09/02 16:07:34 | 095,286,781 | —- | C] ()(C:\Windows\SysWow64\????) – C:\Windows\SysWow64\ᷟ舶Ÿ
[2013/09/01 14:25:15 | 095,199,041 | —- | M] ()(C:\Windows\SysWow64\???L) – C:\Windows\SysWow64\득왲L
[2013/09/01 08:25:29 | 095,199,041 | —- | C] ()(C:\Windows\SysWow64\???L) – C:\Windows\SysWow64\득왲L

========== Alternate Data Streams ==========

@Alternate Data Stream - 94 bytes -> C:\ProgramData\Temp:D5AA39DD
@Alternate Data Stream - 257 bytes -> C:\ProgramData\Temp:36608448
@Alternate Data Stream - 252 bytes -> C:\ProgramData\Temp:1E288DA3
@Alternate Data Stream - 251 bytes -> C:\ProgramData\Temp:AE289451
@Alternate Data Stream - 247 bytes -> C:\ProgramData\Temp:7D288858
@Alternate Data Stream - 247 bytes -> C:\ProgramData\Temp:0E61938B
@Alternate Data Stream - 242 bytes -> C:\ProgramData\Temp:FEE00EB9
@Alternate Data Stream - 237 bytes -> C:\ProgramData\Temp:2EB79F01
@Alternate Data Stream - 236 bytes -> C:\ProgramData\Temp:F2327E82
@Alternate Data Stream - 236 bytes -> C:\ProgramData\Temp:DE6EED8B
@Alternate Data Stream - 235 bytes -> C:\ProgramData\Temp:35629AE6
@Alternate Data Stream - 233 bytes -> C:\ProgramData\Temp:CEE4A457
@Alternate Data Stream - 230 bytes -> C:\ProgramData\Temp:08DB8D99
@Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:3B07E6F4
@Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:349E5B74
@Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:10D45FC3
@Alternate Data Stream - 224 bytes -> C:\ProgramData\Temp:4B244549
@Alternate Data Stream - 223 bytes -> C:\ProgramData\Temp:38D2EA83
@Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:5AE33054
@Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:014BC3B4
@Alternate Data Stream - 221 bytes -> C:\ProgramData\Temp:3C0887BF
@Alternate Data Stream - 218 bytes -> C:\ProgramData\Temp:41884BBE
@Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:CB0FEE2B
@Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:169E7AC5
@Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:A9ABA3FF
@Alternate Data Stream - 210 bytes -> C:\ProgramData\Temp:ED9B661E
@Alternate Data Stream - 196 bytes -> C:\ProgramData\Temp:3D36932D
@Alternate Data Stream - 194 bytes -> C:\ProgramData\Temp:260575F1
@Alternate Data Stream - 162 bytes -> C:\Users\Karri\Desktop\DSCN1040.JPG:com.dropbox.attributes
@Alternate Data Stream - 161 bytes -> C:\Users\Karri\Desktop\DSCF4335.JPG:com.dropbox.attributes
@Alternate Data Stream - 161 bytes -> C:\Users\Karri\Desktop\DSC00973.JPG:com.dropbox.attributes
@Alternate Data Stream - 161 bytes -> C:\Users\Karri\Desktop\DSC00367.JPG:com.dropbox.attributes
@Alternate Data Stream - 160 bytes -> C:\Users\Karri\Desktop\HPIM1144.jpg:com.dropbox.attributes
@Alternate Data Stream - 160 bytes -> C:\Users\Karri\Desktop\_DSC0198.JPG:com.dropbox.attributes
@Alternate Data Stream - 152 bytes -> C:\ProgramData\Temp:6301CE40
@Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:2A8A3140
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:E9900C74
@Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:4B70A9FA
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:908A1B53
@Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:6E11933F
@Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:1B3549F2
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:7BB584AA
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:274516E7
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:131C0EE9
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:57173DB4
@Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:3AC0ED43
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:C9BC8592
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:793F316E
@Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:92DB4653
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:8AB6C1D7
@Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:CFF6B3FF
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:490BCC52
@Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:DCA79AB3
@Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:2CED8825
@Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:FC60E0F8
@Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:861A898F
@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:580E04D8
@Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:4F636E25

< End of report >
OTL Extras logfile created on: 12/09/2013 7:35:10 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Karri\Desktop
64bit-Windows Vista Home Premium Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00001009 | Country: Canada | Language: ENC | Date Format: dd/MM/yyyy

7.93 Gb Total Physical Memory | 3.90 Gb Available Physical Memory | 49.15% Memory free
16.05 Gb Paging File | 10.21 Gb Available in Paging File | 63.65% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 232.59 Gb Total Space | 56.74 Gb Free Space | 24.40% Space Free | Partition Type: NTFS
Drive D: | 348.93 Gb Total Space | 90.22 Gb Free Space | 25.86% Space Free | Partition Type: NTFS
Drive J: | 295.02 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: UDF
Drive N: | 3.79 Gb Total Space | 3.79 Gb Free Space | 100.00% Space Free | Partition Type: FAT32
Drive O: | 930.95 Gb Total Space | 813.57 Gb Free Space | 87.39% Space Free | Partition Type: FAT32

Computer Name: KARRI-PC | User Name: Karri | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

[HKEY_CURRENT_USER\SOFTWARE\Classes\]
.html [@ = FirefoxHTML] – C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – rundll32.exe shell32.dll,Control_RunDLL "%1",%*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –playlist-enqueue "%1" (VideoLAN)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] – "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" –started-from-file –no-playlist-enqueue "%1" (VideoLAN)
Folder [open] – %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] – %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = 9F 9E 16 8C DC 5B C8 01 [binary data]
"VistaSp2" = C9 C1 E4 2F 8B 3A CA 01 [binary data]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"oobe_av" = 1

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0485F8E3-1A09-4024-BA7E-F98A6E3B67FB}" = rport=138 | protocol=17 | dir=out | app=system |
"{26EACD8C-7194-4F96-81ED-2154D5E90590}" = lport=2869 | protocol=6 | dir=in | app=system |
"{42D82151-1A35-4B9D-A760-559221DBBA4F}" = rport=137 | protocol=17 | dir=out | app=system |
"{438F3FCE-8893-48B9-A035-40554350B370}" = lport=139 | protocol=6 | dir=in | app=system |
"{50115D97-DB49-44CD-84E2-4DA4E2F2EEF9}" = lport=137 | protocol=17 | dir=in | app=system |
"{5AA76EEF-6B8E-438A-B21C-10FE61C8273E}" = rport=445 | protocol=6 | dir=out | app=system |
"{72723F71-5C72-4E2F-A8BB-1B2FACDB0B03}" = lport=138 | protocol=17 | dir=in | app=system |
"{7368AFD0-6C88-4905-BAB2-CC2F4BB6602B}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{8A9ABA56-F005-42CB-835A-680487CE04E1}" = lport=445 | protocol=6 | dir=in | app=system |
"{B1E53891-F0B7-4D8F-87CF-92D87825598A}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{B8806828-0C3B-4515-8175-852416FE4373}" = rport=139 | protocol=6 | dir=out | app=system |
"{BCE834EC-BBCE-41BD-8EAE-8AD289A873AF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{C73FCED9-8013-44F9-9592-8A54D7382EFF}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{D8416C81-AE7C-4BDA-9F38-50CB9711BFF2}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe |
"{EA7FAF37-873E-474D-ACA0-61CFD228318E}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{026A20FC-E75E-4AE5-A84F-3FB1E5C8E8FD}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{08966A8D-5290-4720-80D1-98FAE18A4575}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe |
"{0A599829-DE90-4608-B5C6-DA5B68F1D90D}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{0D80A6FE-DF65-421F-9336-1A166CC05632}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\droplitz\cascade.exe |
"{1374527C-6193-4800-BCCF-F0D460DC864F}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{143090E1-9C5F-41B5-9B2E-C1D71C44FB47}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotel dash\hoteldash.exe |
"{15586373-00E5-411F-BFF2-941CC4C64474}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\eufloria\eufloria.exe |
"{1A6A2C55-F5C3-49DA-95B9-70BBA78D5589}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{1CB745C2-A73C-42B2-ACA3-A3F7F2C3C15B}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia connect\kernel\dms\clmsserver.exe |
"{1D84E0DD-067E-4B7D-88CB-A6E2F48DD0A5}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{1EA7F63C-7067-4D49-9142-04CCD9AFB958}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\simcity 4 deluxe\support\ea help\electronic_arts_technical_support.htm |
"{211AD758-F2EB-4C6B-867E-9E1B7A5A0437}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hotel dash\hoteldash.exe |
"{25757D9E-3675-4F14-A555-A49B3425CE2B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{28280830-880C-44CF-8B73-76D37540F99B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzle chronicles\puzzlechronicles.exe |
"{2F4D3580-9E97-40D0-993E-04DADC4CE426}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{31DB2597-38D6-4A4E-AA8B-EF6C74DEF37B}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia connect\acer homemedia connect.exe |
"{33B49371-D92B-40D5-867C-05009872AB14}" = protocol=6 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{36BE2B08-E41C-430A-8CE3-BA072FB7BB18}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\zuma's revenge\zumasrevenge.exe |
"{41EB73A3-0B7B-4FE3-89F3-ABF7F7551415}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\luxor 5th passage\luxor - 5th passage.exe |
"{42D7C32D-AFB0-4E17-805C-D17ACCBF9B1F}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{437A62E9-5F86-447B-BC81-C06350379349}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{45E1E295-7947-4BC0-A7D5-1341E4C006DF}" = dir=in | app=c:\program files (x86)\acer arcade live\acer arcade live main page\acer arcade live.exe |
"{46319C9A-D991-4DF5-AAB0-75693DD14404}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{482E5199-DCBB-40E3-A1DB-BC2D27399AB0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{49DF5E5B-FAC5-4C46-A567-8DEC235647EC}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\backupsvc.exe |
"{4CD3CDE7-136E-4D80-8E17-BCA58F2A9160}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{4DE71902-F71D-485C-BFA2-FCFFC948878D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |
"{50BCD8A0-DE73-4E01-8E42-A26440FEA07D}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clsomamonitorservice.exe |
"{5128F576-1743-46EE-BD62-15FD815E5D6F}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{53D985A5-E8E5-46C4-9237-54057EBCA917}" = protocol=17 | dir=in | app=c:\users\karri\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{53F1AE12-C085-4AF4-A1A3-3E0493DDE57C}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clsomaservice.exe |
"{59F76541-B1FB-4C81-A98D-9DFB3F36A7A7}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia trial creator\acer homemedia trial creator.exe |
"{5A4CD912-D98B-4752-8758-9CBEFF37B38C}" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{5A846A34-4E3D-4397-B499-EA651EAC799A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |
"{5B53DBD0-CF30-4E48-A60A-B8F14A7338AB}" = dir=in | app=c:\program files (x86)\acer arcade live\acer slideshow dvd\acer slideshow dvd.exe |
"{5BFCE5AC-A1CF-4E02-945E-082F476C53AB}" = protocol=17 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{60908FE1-AD5A-44DE-973F-D1B56E4C95C4}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{63529CEB-A982-4D8F-B3D4-38798D235B97}" = dir=in | app=c:\program files (x86)\acer arcade live\acer dv magician\acer dv magician.exe |
"{648FA8A1-30D3-4F66-8814-BBCB08B2C948}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\simcity 4 deluxe\support\ea help\electronic_arts_technical_support.htm |
"{6773A271-386A-4D7B-8E50-A1151DA7A4AC}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer.exe |
"{6B53143B-FAF1-4826-A5C4-2D0D25E3B6B1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\eufloria\eufloria.exe |
"{6BF7994F-F161-4D37-BA52-9F2B7903F92D}" = protocol=17 | dir=in | app=c:\program files (x86)\yahoo!\messenger\yahoomessenger.exe |
"{6CFCE972-4C44-411F-B004-18865AFAB48E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\modlauncher.exe |
"{6EF76C59-39D2-4E16-A3D9-FD112F09E4D5}" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"{6FBD2739-ADB3-41BA-8795-D057E1713CCB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\simcity 4 deluxe\apps\simcity 4.exe |
"{70DDDEC1-424F-4FB0-90AB-DC467AF2DE73}" = protocol=6 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{722B5250-5770-4A57-AA8A-77F2F3935D0C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\luxor 5th passage\luxor - 5th passage.exe |
"{75E95DFD-F335-458C-AE61-4E0416758F5B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\torchlight2.exe |
"{7992BD87-E39E-4DF3-AE41-7CC61872FA91}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzlequest2\puzzlequest2.exe |
"{8B57FA11-FAAA-45D7-9CD0-779B67A0691F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\zuma's revenge\zumasrevenge.exe |
"{9268FA5B-ABB4-4B99-80C5-BE1A37977EB9}" = protocol=17 | dir=in | app=c:\users\karri\appdata\roaming\dropbox\bin\dropbox.exe |
"{9AE2D478-D3BA-40C2-ADE9-3C8EBE115FAF}" = dir=in | app=c:\program files (x86)\acer arcade live\acer videomagician\acer videomagician.exe |
"{9B15B625-B7A4-4142-BAC3-C11097CAC77F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\simcity 4 deluxe\apps\simcity 4.exe |
"{9EBA2EBE-1437-41D5-B5DD-D10C4459955A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"{A755F2BB-5391-4EC8-8CC9-2A6E28230F0D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{AAAEA79D-600C-44A5-BA49-96C2E838CA53}" = protocol=6 | dir=in | app=c:\users\karri\appdata\roaming\dropbox\bin\dropbox.exe |
"{AF57DC65-FE10-4F0E-87EB-850082FEC2A5}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{B4160887-A805-4838-B63E-B30E507A6585}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight ii\modlauncher.exe |
"{B4B4EF0A-F441-4C4E-9B49-E8DF65F3DC53}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\client\agentsvc.exe |
"{B7035FE8-3D41-48BC-83DB-3069996FDF15}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{BA977534-1A57-46A1-9D5C-E8CAF28DA686}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzle chronicles\puzzlechronicles.exe |
"{BAE33E54-2BEA-4488-AE6A-9184671ACDB0}" = protocol=6 | dir=in | app=c:\program files\microsoft office\office14\onenote.exe |
"{BCB23F56-6620-45C9-97B1-743DA0A787D2}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clpushupdateservice.exe |
"{BDEE44E1-CC0F-418D-BDE1-F2A29A22B66A}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{BE958C74-7849-4FC8-955D-53C4840F85DE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\puzzlequest2\puzzlequest2.exe |
"{BF19804D-8981-4AAA-9C72-BE228024FFC3}" = protocol=17 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{C30E81C8-6756-4A8E-A10A-75D500F199C8}" = protocol=17 | dir=in | app=c:\program files (x86)\newtech infosystems\nti backup now 5\schedulersvc.exe |
"{C6E9C062-FDE1-4E8F-B5E9-E60EDAB60356}" = dir=in | app=c:\program files (x86)\acer arcade live\acer dvdivine\acer dvdivine.exe |
"{CE2A96E7-0A4E-4840-987F-8AE7692D4E66}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |
"{CF6AFB91-9BB1-40CD-951F-7334F89F92D9}" = protocol=6 | dir=in | app=c:\program files (x86)\limewire\limewire.exe |
"{D2B0635A-BF7B-4CCD-9FF4-33A786BF9772}" = protocol=17 | dir=in | app=c:\program files\microsoft office\office14\groove.exe |
"{D531D9DD-1D83-4C03-8449-1FAAB018A66F}" = protocol=6 | dir=in | app=c:\program files (x86)\teamviewer\version8\teamviewer_service.exe |
"{D7929809-9DB7-4971-BE00-795D130BB3DA}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{DBBFBF7F-6998-4EE7-8B1C-5D4F1298ED14}" = dir=in | app=c:\program files (x86)\acer arcade live\acer homemedia\acer homemedia.exe |
"{E21B7CAE-632B-4891-B03B-7FEC13816437}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{E641B636-C37B-4AAA-AD9F-EF7BF7850A80}" = protocol=6 | dir=in | app=c:\users\karri\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{E890FBFF-A9A1-41D1-B7F6-DF8CD784C568}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{F3315C0F-CCAA-4FE6-B1C1-D1FC8116906E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fitness dash\fitnessdash.exe |
"{F44E840B-CA0A-494D-974E-F88DC2AE18E8}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{F4E391D2-9AD6-4A86-B632-A7B3D4DB1868}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{F736369E-A09E-4770-82FA-EE01A02543D4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\droplitz\cascade.exe |
"{FB3D19E9-958E-43D1-9E96-A676CE39491A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fitness dash\fitnessdash.exe |
"{FD2FA6DC-FA5E-4EC9-8311-481D5157822B}" = dir=in | app=c:\program files (x86)\cyberlink\cyberlink live\clhomemediaserver.exe |
"{FE228B95-329B-46E8-950B-70EE4F5B549E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |
"TCP Query User{1FD7F4E9-C63D-4CFD-89DE-0279CE61ACBA}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"TCP Query User{236DB553-2209-4978-BD98-DDA820C234FE}C:\program files (x86)\oovoo\oovoo.exe" = protocol=6 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"TCP Query User{385704E7-8985-4F92-8901-C6FE813E201A}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{B504721D-C368-4CB9-90EB-852F3C2212B7}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"TCP Query User{CE3E5FCD-7C89-492C-9C89-CCA6312E7DED}C:\program files (x86)\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"TCP Query User{E6899A08-551C-4CBB-8A09-8514A08C1D03}C:\program files (x86)\logitech\vid hd\vid.exe" = protocol=6 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"UDP Query User{534508C2-EC9A-4B83-BE0C-780DD08D8D53}C:\program files (x86)\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"UDP Query User{5B1C0B5B-B3D2-46B4-9AAF-F334DD805AAF}C:\program files (x86)\logitech\vid hd\vid.exe" = protocol=17 | dir=in | app=c:\program files (x86)\logitech\vid hd\vid.exe |
"UDP Query User{9A50E594-A30A-4554-9667-ADB34FA275F8}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"UDP Query User{BF90CEB4-CD3C-49C5-8BDE-10B1040E2383}C:\program files (x86)\oovoo\oovoo.exe" = protocol=17 | dir=in | app=c:\program files (x86)\oovoo\oovoo.exe |
"UDP Query User{CCA1448D-D510-44CC-953D-484C5605B7F5}C:\program files (x86)\electronic arts\eadm\core.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\eadm\core.exe |
"UDP Query User{E121835F-7ABC-45F8-84AE-DAC397530DEB}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{0370E621-61D1-4199-82AF-8F21851FD194}" = i_instrumentation [removed]
"{072F206C-2F30-48C9-8ED0-3CDF4F612CB1}" = ME_Kit_Files_x64
"{0C524D20-1409-0050-8A9E-0C4C490E4E54}" = Microsoft Dynamics CRM 2011 for Microsoft Office Outlook
"{0C524DC1-1409-0050-8121-88490F4D5549}" = Microsoft Dynamics CRM 2011 English (United States) Language Pack
"{138A4072-9E64-46BD-B5F9-DB2BB395391F}" = LWS VideoEffects
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D666E21-2924-4B94-9A33-D6136761ACAB}" = Intel® Remote Wake Technology 1.0.296.0
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86417017FF}" = Java 7 Update 17 (64-bit)
"{273799F6-BC76-46F1-95E1-EF05322C3A5F}" = i_msm 1.0.312.0
"{2BE51F94-8ED9-4B31-898C-01BFA71CC1DC}" = i_swupdate [removed]
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{427174C0-096E-40D9-9684-9C109BEE2CBF}" = iTunes
"{46E637E2-AC34-4B45-B5DF-D20903A3DB61}" = Microsoft Online Services Sign-in Assistant
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{52A7026F-476C-4E3B-A4C7-8FF7DAD65FEB}" = i_redistributables 1.0.45
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{70E8EBD5-78C9-4258-B20A-5098CCA000F0}" = Dolby Control Center
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{868EA922-5675-4E91-BDA6-BBD0F923C5EF}" = HP Officejet Pro All-In-One Series
"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended
"{90140000-0015-0409-1000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2010
"{90140000-0015-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0016-0409-1000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2010
"{90140000-0016-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0018-0409-1000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2010
"{90140000-0018-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0019-0409-1000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2010
"{90140000-0019-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001A-0409-1000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001B-0409-1000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2010
"{90140000-001B-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-1000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{0242505C-4E90-407F-9299-B5B275F50D86}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-1000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-1000-0000000FF1CE}_Office14.PROPLUSR_{B51389C8-2890-4633-81D8-47D2A7402274}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-1000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-1000-0000000FF1CE}_Office14.PROPLUSR_{1779650B-2E44-4A19-8DF6-3866D645764A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-1000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{270CA0B9-9881-44DB-BC3B-37C7E66A044A}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0000-1000-0000000FF1CE}" = Microsoft Office Office 32-bit Components 2010
"{90140000-0043-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{E8B6D35B-0B6F-4DCE-9493-859BF3809A7F}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0043-0409-1000-0000000FF1CE}" = Microsoft Office Shared 32-bit MUI (English) 2010
"{90140000-0043-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{FCD1C311-8B02-4DBD-BA46-1079C629577E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0044-0409-1000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2010
"{90140000-0044-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-1000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00A1-0409-1000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2010
"{90140000-00A1-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-00BA-0409-1000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2010
"{90140000-00BA-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-1000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{516CA4A9-98E6-4F77-A863-CBD8487368E4}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0117-0409-1000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2010
"{90140000-0117-0409-1000-0000000FF1CE}_Office14.PROPLUSR_{EC583796-6BBB-47DD-B9CE-B5DA12D71135}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9068B2BE-D93A-4C0A-861C-5E35E2C0E09E}" = Intel® Matrix Storage Manager
"{91140000-0011-0000-1000-0000000FF1CE}" = Microsoft Office Professional Plus 2010
"{91140000-0011-0000-1000-0000000FF1CE}_Office14.PROPLUSR_{7BC9B5EB-125A-4E9B-97E1-8D85B5E960B8}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 311.06
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 311.06
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.11.3
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{F39076D7-7168-44CD-A2C6-EBC1CDA7DC1C}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"HDMI" = Intel® Graphics Media Accelerator Driver
"HP Imaging Device Functions" = HP Imaging Device Functions 8.0
"HP Solution Center & Imaging Support Tools" = HP Solution Center 8.0
"HPExtendedCapabilities" = HP Customer Participation Program 8.0
"HPOCR" = HP OCR Software 8.0
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft CRM Client" = Microsoft Dynamics CRM 2011 for Microsoft Office Outlook
"Office14.PROPLUSR" = Microsoft Office Professional Plus 2010
"WinRAR archiver" = WinRAR 4.01 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{021C4C4F-C93C-4425-BFFD-C2D16776BFAE}" = Visual C++ 8.0 Runtime Setup Package (x64)
"{0289B35E-DC07-4c7a-9710-BBD686EA4B7D}" = Status
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{08610298-29AE-445B-B37D-EFBE05802967}" = LWS Pictures And Video
"{0A55CDBB-0566-4AA2-A15B-24C7F27C6FF4}" = BPD_Scan
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0D2F6F25-394B-4ACA-BC9C-1394E963C620}" = Intel® Remote Wake Technology [removed]
"{12CAA28E-56CA-4C3D-B3F2-7311540DD410}" = TurboTax 2011
"{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now Standard
"{131B84C2-5435-4993-9888-6C62D9AC755E}" = CyberLink Live
"{132888AE-EF67-41C5-BCA2-7D5D2488AB63}" = Acer HomeMedia Connect
"{13D85C14-2B85-419F-AC41-C7F21E68B25D}" = Acer eSettings Management
"{15634701-BACE-4449-8B25-1567DA8C9FD3}" = CameraHelperMsi
"{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"{1651216E-E7AD-4250-92A1-FB8ED61391C9}" = LWS Help_main
"{1746EA69-DCB6-4408-B5A5-E75F55439CDF}" = Scan
"{174A3B31-4C43-43DD-866F-73C9DB887B48}" = LWS Twitter
"{179C56A4-F57F-4561-8BBF-F911D26EB435}" = WebReg
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{21DF0294-6B9D-4741-AB6F-B2ABFBD2387E}" = LWS YouTube Plugin
"{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"{24AE6B5B-3D5A-488C-9224-1BEE11F75DD9}" = TurboTax 2010
"{26A24AE4-039D-4CA4-87B4-2F83217017FF}" = Java 7 Update 25
"{28DA3304-9EC2-4097-BC64-B59A1958841F}" = Microsoft SQL Server Compact 3.5 SP2 ENU
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{33cf58f5-48d8-4575-83d6-96f574e4d83a}" = Nero DriveSpeed
"{359cfc0a-beb1-440d-95ba-cf63a86da34f}" = Nero Recode
"{368ba326-73ad-4351-84ed-3c0a7a52cc53}" = Nero Rescue Agent
"{36FDBE6E-6684-462B-AE98-9A39A1B200CC}" = HP Product Assistant
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = erLT
"{3FC7CBBC4C1E11DCA1A752EA55D89593}" = DivX Version Checker
"{41564952-412D-5637-00A7-A758B70C0202}" = Avira SearchFree Toolbar plus Web Protection
"{41581EF5-45A7-11DA-9D78-000129760D75}" = Acer SlideShow DVD
"{43e39830-1826-415d-8bae-86845787b54b}" = Nero Vision
"{49F2B650-2D7B-4F59-B33D-346F63776BD3}" = DocProc
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4E76FF7E-AEBA-4C87-B788-CD47E5425B9D}" = Skype™ 6.6
"{4FB600F5-C478-4DF7-A2BC-57D3807BAC91}" = BPDSoftware_Ini
"{5104B07C-6A3D-4E7E-8BBB-960B52554BDD}" = BPD_HPSU
"{56C049BE-79E9-4502-BEA7-9754A3E60F9B}" = neroxml
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{595a3116-40bb-4e0f-a2e8-d7951da56270}" = NeroExpress
"{5AE12194-3EAA-40DF-B2BF-FE1D6B78BBF4}" = Nero Vision
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{5DD4FCBD-A3C1-4155-9E17-4161C70AAABA}" = Segoe UI
"{62ac81f6-bdd3-4110-9d36-3e9eaab40999}" = Nero CoverDesigner
"{63e01893-1aef-40c9-b436-5817c1394f52}" = Nero 9 Trial
"{66E6CE0C-5A1E-430C-B40A-0C90FF1804A8}" = eSupportQFolder
"{67D3F1A0-A1F2-49b7-B9EE-011277B170CD}" = HPProductAssistant
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6ad7d061-da98-4a17-8960-1ba830ff4861}" = Nero 9
"{6D52C408-B09A-4520-9B18-475B81D393F1}" = Microsoft Works
"{6F5E2F4A-377D-4700-B0E3-8F7F7507EA15}" = CustomerResearchQFolder
"{6F76EC3C-34B1-436E-97FB-48C58D7BEDCD}" = LWS Gallery
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71828142-5A24-4BD0-97E7-976DA08CE6CF}" = The Sims™ 3 High-End Loft Stuff
"{71E66D3F-A009-44AB-8784-75E2819BA4BA}" = LWS Motion Detection
"{726DDC29-79B3-41B4-BDBF-97DF25BF1EA8}" = TurboTax 2012
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{7748ac8c-18e3-43bb-959b-088faea16fb2}" = Nero StartSmart
"{7829db6f-a066-4e40-8912-cb07887c20bb}" = Nero BurnRights
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79DD56FC-DB8B-47F5-9C80-78B62E05F9BC}" = Acer ScreenSaver
"{7B63B2922B174135AFC0E1377DD81EC2}" =
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110111700}" = Zuma Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110113233}" = Bookworm Deluxe
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-11029123}" = Bricks of Egypt
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110322783}" = Big Kahuna Reef
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-110411970}" = Chuzzle
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111199750}" = Cake Mania
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111252743}" = Mahjong Escape Ancient China
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111324990}" = Kick N Rush
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111543617}" = Backspin Billiards
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111692950}" = Mahjongg Artifacts
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111771833}" = Jewel Quest Solitaire
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111796363}" = Mystery Solitaire - Secret Island
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-111872660}" = Diner Dash Flo on the Go
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112310577}" = Flip Words 2
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112531267}" = Chicken Invaders 3
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-112920767}" = Alice Greenfingers
"{82C36957-D2B8-4EF2-B88C-5FA03AA848C7-113080210}" = Azada
"{83BEEFB4-8C28-4F4F-8A9D-E0D1ADCE335B}" = The Sims Medieval
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{83C8FA3C-F4EA-46C4-8392-D3CE353738D6}" = LWS Launcher
"{846B5DED-DC8C-4E1A-B5B4-9F5B39A0CACE}" = HPDiagnosticAlert
"{869200db-287a-4dc0-b02b-2b6787fbcd4c}" = Nero DiscSpeed
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87E2B986-07E8-477a-93DC-AF0B6758B192}" = DocProcQFolder
"{8868D822-2CBA-46B2-A286-B400B6185769}" = 7500_7600_7700_Help
"{8937D274-C281-42E4-8CDB-A0B2DF979189}" = LWS Webcam Software
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F1B6239-FEA0-450A-A950-B05276CE177C}" = Acer Empowering Technology
"{8F968232-15C6-4872-84C2-9FCDAA1AEAB6}" = MPM
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{910F4A29-1134-49E0-AD8B-56E4A3152BD1}" = The Sims™ 3 Ambitions
"{933B4015-4618-4716-A828-5289FC03165F}" = VC80CRTRedist - 8.0.50727.6195
"{95D08F4E-DFC2-4ce3-ACB7-8C8E206217E9}" = MarketResearch
"{97486FBE-A3FC-4783-8D55-EA37E9D171CC}" = HP Update
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A875B56-A35C-46BA-A3AA-DF8D03EE9F2F}" = Nero ControlCenter
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C2D4047-0E40-499a-AC7A-C4B9BB12FE03}" = TrayApp
"{9DAEA76B-E50F-4272-A595-0124E826553D}" = LWS WLM Plugin
"{9e82b934-9a25-445b-b8df-8012808074ac}" = Nero PhotoSnap
"{9e9fdde6-2c26-492a-85a0-05646b3f2795}" = NeroLiveGadget
"{a209525b-3377-43f4-b886-32f6b6e7356f}" = Nero WaveEditor
"{A36CD345-625C-4d6c-B3E2-76E1248CB451}" = SolutionCenter
"{A495D4DC-4036-4914-9CB2-0FCF6A3166EF}" = L7500
"{A5633652-3795-4829-BB0B-644F0279E279}" = Acer eDataSecurity Management
"{A8F2089B-1F79-4BF6-B385-A2C2B0B9A74D}" = ImagXpress
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA0D2D5F-612B-45D3-8759-DA87206E5CC9}" = QuickTax 2008
"{AA4BF92B-2AAF-11DA-9D78-000129760D75}" = Acer HomeMedia
"{AB5D51AE-EBC3-438D-872C-705C7C2084B0}" = DeviceManagementQFolder
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.7)
"{B145EC69-66F5-11D8-9D75-000129760D75}" = Acer DVDivine
"{B194272D-1F92-46DF-99EB-8D5CE91CB4EC}" = Adobe AIR
"{b1adf008-e898-4fe2-8a1f-690d9a06acaf}" = DolbyFiles
"{b2ec4a38-b545-4a00-8214-13fe0e915e6d}" = Advertising Center
"{B580C409-E16F-44FF-904D-3AE94E113BE0}" = Acer HomeMedia Trial Creator
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B6CF2967-C81E-40C0-9815-C05774FEF120}" = Skype Click to Call
"{b78120a0-cf84-4366-a393-4d0a59bc546c}" = Menu Templates - Starter Kit
"{B83FC356-B7C0-441F-8A4D-D71E088E7974}" = NVIDIA PhysX
"{BA26FFA5-6D47-47DB-BE56-34C357B5F8CC}" = The Sims™ 3 World Adventures
"{bd5ca0da-71ad-43da-b19e-6eee0c9adc9a}" = Nero ControlCenter
"{BE77A81F-B315-4666-9BF3-AE70C0ADB057}" = BufferChm
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C19B3EB6-B54C-3204-A4DF-88432E0C79F7}" = Microsoft ReportViewer 2010 Redistributable
"{c5a7cb6c-e76d-408f-ba0e-85605420fe9d}" = SoundTrax
"{C716522C-3731-4667-8579-40B098294500}" = Toolbox
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C1}" = WinZip 15.0
"{CE386A4E-D0DA-4208-8235-BCE43275C694}" = LightScribe 1.4.142.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{d025a639-b9c9-417d-8531-208859000af8}" = NeroBurningROM
"{D0E39A1D-0CEE-4D85-B4A2-E3BE990D075E}" = Destination Component
"{D40EB009-0499-459c-A8AF-C9C110766215}" = Logitech Webcam Software
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{d9dcf92e-72eb-412d-ac71-3b01276e5f8b}" = Nero ShowTime
"{DEB9AEF7-3ADA-40a9-9C98-546D54FE9CBD}" = ProductContext
"{df6a95f5-adc1-406a-bdc6-2aa7cc0182aa}" = Nero Live
"{E06F04B9-45E6-4AC0-8083-85F7515F40F7}" = UnloadSupport
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{e498385e-1c51-459a-b45f-1721e37aa1a0}" = Movie Templates - Starter Kit
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{e8a80433-302b-4ff1-815d-fcc8eac482ff}" = Nero Installer
"{EB21A812-671B-4D08-B974-2A347F0D8F70}" = HP Photosmart Essential
"{EB38C3E0-4863-3123-9114-5BE86EC8E5C7}" = Google Talk Plugin
"{EB75DE50-5754-4F6F-875D-126EDF8E4CB3}" = HPSSupply
"{ECAD4F6A-0BF3-4028-9C81-E5D9F9606CBA}" = BPDSoftware
"{ECB9C58E-C565-4683-9599-B72290BD3B25}" = QuickTax 2009
"{EED027B7-0DB6-404B-8F45-6DFEE34A0441}" = LWS Video Mask Maker
"{EEEB604C-C1A7-4f8c-B03F-56F9C1C9C45F}" = Fax
"{EF1ADA5A-0B1A-4662-8C55-7475A61D8B65}" = DeviceDiscovery
"{EFBDC2B0-FAA8-4B78-8DE1-AEBE7958FA37}" = Acer Arcade Live Main Page
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{f1861f30-3419-44db-b2a1-c274825698b3}" = Nero Disc Copy Gadget
"{F6EFFB76-4A07-11DA-9D78-000129760D75}" = Acer DV Magician
"{F79A208D-D929-11D9-9D77-000129760D75}" = Acer VideoMagician
"{fbcdfd61-7dcf-4e71-9226-873ba0053139}" = Nero InfoTool
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF167195-9EE4-46C0-8CD7-FBA3457E88AB}" = LWS Facebook
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"Acer Assist" = Acer Assist
"Acer GameZone Console_is1" = Acer GameZone Console DTV 2.0.1.1
"Acer Registration" = Acer Registration
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin
"Avira AntiVir Desktop" = Avira Free Antivirus
"B991B020-2968-11D8-AF23-444553540000_is1" = FreeMind
"BFG-Be a King - Golden Empire" = Be a King: Golden Empire
"BFG-Be Richest!" = Be Richest!
"BFG-Bistro Boulevard" = Bistro Boulevard
"BFG-Boutique Boulevard" = Boutique Boulevard
"BFG-Build-a-lot - Fairy Tales" = Build-a-lot: Fairy Tales
"BFG-Build-a-lot - On Vacation" = Build-a-lot: On Vacation
"BFG-Build-a-Lot 4 - Power Source" = Build-a-Lot 4: Power Source
"BFGC" = Big Fish: Game Manager
"BFG-Campgrounds" = Campgrounds
"BFG-Casino Chaos" = Casino Chaos
"BFG-Chloe's Dream Resort" = Chloe's Dream Resort
"BFG-Club Paradise" = Club Paradise
"BFG-Cooking Dash 3 - Thrills and Spills" = Cooking Dash 3: Thrills and Spills
"BFG-Dancing Craze" = Dancing Craze
"BFG-DinerTown - Detective Agency" = DinerTown: Detective Agency
"BFG-Dress Up Rush" = Dress Up Rush
"BFG-Farm Frenzy 3" = Farm Frenzy 3
"BFG-Fiona Finch and the Finest Flowers" = Fiona Finch and the Finest Flowers
"BFG-First Class Flurry" = First Class Flurry
"BFG-Grave Mania - Undead Fever" = Grave Mania: Undead Fever
"BFG-Hotel Dash 2 - Lost Luxuries" = Hotel Dash 2: Lost Luxuries
"BFG-Island Tribe 2" = Island Tribe 2
"BFG-Jet Set Go" = Jet Set Go
"BFG-Jo's Dream - Organic Coffee" = Jo's Dream: Organic Coffee
"BFG-Juliette's Fashion Empire" = Juliette's Fashion Empire
"BFG-Katy and Bob - Way Back Home" = Katy and Bob: Way Back Home
"BFG-My Farm Life" = My Farm Life
"BFG-Northern Tale" = Northern Tale
"BFG-Pet Rush - Arround the World" = Pet Rush: Arround the World
"BFG-Princess Isabella - A Witch's Curse" = Princess Isabella: A Witch's Curse
"BFG-Rescue Frenzy" = Rescue Frenzy
"BFG-Roads of Rome III" = Roads of Rome III
"BFG-Royal Envoy 2 Collector's Edition" = Royal Envoy 2 Collector's Edition
"BFG-Rush for Gold - Alaska" = Rush for Gold: Alaska
"BFG-Sally's Studio Collector's Edition" = Sally's Studio Collector's Edition
"BFG-Shop-n-Spree - Shopping Paradise" = Shop-n-Spree: Shopping Paradise
"BFG-Soap Opera Dash" = Soap Opera Dash
"BFG-Spa Mania 2" = Spa Mania 2
"BFG-The Timebuilders - Pyramid Rising" = The Timebuilders: Pyramid Rising
"BFG-Virtual City 2 - Paradise Resort" = Virtual City 2: Paradise Resort
"BFG-Wedding Dash 2 - Rings Around the World" = Wedding Dash 2: Rings Around the World
"BFG-Wedding Dash 4-Ever" = Wedding Dash 4-Ever
"BFG-Wedding Salon" = Wedding Salon
"Comical_is1" = Comical 0.8
"Coupon Printer for Windows5.0.0.2" = Coupon Printer for Windows
"ESET Online Scanner" = ESET Online Scanner v3
"InstallShield_{12EFA1A4-AC3B-443C-8143-237EDE760403}" = NTI Backup Now 5
"InstallShield_{131B84C2-5435-4993-9888-6C62D9AC755E}" = CyberLink Live
"InstallShield_{15D967B5-A4BE-42AE-9E84-64CD062B25AA}" = eSobi v2
"InstallShield_{2413930C-8309-47A6-BC61-5EF27A4222BC}" = NTI Media Maker 8
"Kobo" = Kobo
"Logitech Vid" = Logitech Vid HD
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Mouse Setting Software_is1" = Mouse Setting Software 4.0
"Mozilla Firefox 22.0 (x86 en-US)" = Mozilla Firefox 22.0 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"OpenAL" = OpenAL
"Origin" = Origin
"Picasa 3" = Picasa 3
"Royal Envoy Collector's Edition" = Royal Envoy Collector's Edition
"Runic Games Torchlight" = Torchlight
"Steam App 19020" = Puzzle Chronicles
"Steam App 200710" = Torchlight II
"Steam App 23120" = Droplitz
"Steam App 24780" = SimCity 4 Deluxe
"Steam App 3620" = Zuma's Revenge
"Steam App 37340" = Fitness Dash
"Steam App 41210" = Eufloria
"Steam App 47540" = Puzzle Quest 2
"Steam App 49000" = Hotel Dash
"Steam App 60340" = LUXOR: 5th Passage
"Steam App 70400" = Recettear: An Item Shop's Tale
"uTorrent" = µTorrent
"VLC media player" = VLC media player 2.0.5
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"YTdetect" = Yahoo! Detect

========== HKEY_CURRENT_USER Uninstall List ==========

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Adobe Connect 9 Add-in" = Adobe Connect 9 Add-in
"Dropbox" = Dropbox
"Google Chrome" = Google Chrome
"Oracle Live Help On Demand - Agent Console - NNA CLPOC ORILLIA Karri Tougas (105652707)" = Oracle Live Help On Demand - Agent Console - NNA CLPOC ORILLIA Karri Tougas (105652707)
"Sansa Updater" = Sansa Updater
"uTorrent" = µTorrent

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 10/09/2013 11:57:22 PM | Computer Name = Karri-PC | Source = Application Hang | ID = 1002
Description = The program OUTLOOK.EXE version 14.0.6133.5000 stopped interacting
with Windows and was closed. To see if more information about the problem is available,
check the problem history in the Problem Reports and Solutions control panel. Process
ID: 181c Start Time: 01ceaea13d626660 Termination Time: 0

Error - 11/09/2013 12:36:53 AM | Computer Name = Karri-PC | Source = Application Error | ID = 1000
Description = Faulting application Skype.exe, version 6.6.0.106, time stamp 0x51c414b3,
faulting module Skype.exe, version 6.6.0.106, time stamp 0x51c414b3, exception
code 0xc0000005, fault offset 0x003afd0a, process id 0xb5c, application start time
0x01ceae10bada5d00.

Error - 11/09/2013 12:57:42 PM | Computer Name = Karri-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Users\Karri\Desktop\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error - 11/09/2013 12:57:42 PM | Computer Name = Karri-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Users\Karri\Desktop\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error - 11/09/2013 12:57:47 PM | Computer Name = Karri-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Users\Karri\Desktop\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error - 12/09/2013 7:10:17 AM | Computer Name = Karri-PC | Source = WinMgmt | ID = 10
Description =

Error - 12/09/2013 7:10:50 AM | Computer Name = Karri-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error - 12/09/2013 7:18:52 AM | Computer Name = Karri-PC | Source = WinMgmt | ID = 10
Description =

Error - 12/09/2013 7:19:57 AM | Computer Name = Karri-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

Error - 12/09/2013 7:19:58 AM | Computer Name = Karri-PC | Source = SideBySide | ID = 16842830
Description = Activation context generation failed for "C:\Program Files (x86)\Nero\Nero
9\Nero PhotoSnap\PhotoSnapViewer.exe.Manifest".Error in manifest or policy file
"" on line . A component version required by the application conflicts with another
component version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_1509f852f40ee5cd.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6002.18305_none_5cb72f2a088b0ed3.manifest.

[ System Events ]
Error - 12/09/2013 7:11:02 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 12/09/2013 7:13:08 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7038
Description =

Error - 12/09/2013 7:13:08 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 12/09/2013 7:20:44 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 12/09/2013 7:20:44 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7022
Description =

Error - 12/09/2013 7:20:44 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7026
Description =

Error - 12/09/2013 7:20:49 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7009
Description =

Error - 12/09/2013 7:20:49 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 12/09/2013 7:22:46 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7038
Description =

Error - 12/09/2013 7:22:46 AM | Computer Name = Karri-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >
Hi Freyja :)


Run OTL.exe
  • Copy/paste the following text written inside of the code box into the Custom Scans/Fixes box located at the bottom of OTL

    :OTL
    O1 - Hosts: 127.0.0.1 localhost
    O2 - BHO: (no name) - {41564952-412D-5637-00A7-7A786E7484D7} - No CLSID value found.
    O3 - HKLM\..\Toolbar: (no name) - {CCC7A320-B3CA-4199-B1A6-9F516DD69829} - No CLSID value found.
    O4:64bit: - HKLM..\Run: [EmpoweringTechnology] C:\Program Files\Acer\Empowering Technology\Framework.Launcher.exe boot File not found
    O18:64bit: - Protocol\Handler\intu-qt2008 - No CLSID value found
    O18:64bit: - Protocol\Handler\intu-qt2009 - No CLSID value found
    O18:64bit: - Protocol\Handler\intu-tt2010 - No CLSID value found
    O18:64bit: - Protocol\Handler\intu-tt2011 - No CLSID value found
    O18:64bit: - Protocol\Handler\intu-tt2012 - No CLSID value found
    O18:64bit: - Protocol\Handler\livecall - No CLSID value found
    O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
    O18:64bit: - Protocol\Handler\msnim - No CLSID value found
    O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
    O18 - Protocol\Handler\ms-help - No CLSID value found
    @Alternate Data Stream - 94 bytes -> C:\ProgramData\Temp:D5AA39DD
    @Alternate Data Stream - 257 bytes -> C:\ProgramData\Temp:36608448
    @Alternate Data Stream - 252 bytes -> C:\ProgramData\Temp:1E288DA3
    @Alternate Data Stream - 251 bytes -> C:\ProgramData\Temp:AE289451
    @Alternate Data Stream - 247 bytes -> C:\ProgramData\Temp:7D288858
    @Alternate Data Stream - 247 bytes -> C:\ProgramData\Temp:0E61938B
    @Alternate Data Stream - 242 bytes -> C:\ProgramData\Temp:FEE00EB9
    @Alternate Data Stream - 237 bytes -> C:\ProgramData\Temp:2EB79F01
    @Alternate Data Stream - 236 bytes -> C:\ProgramData\Temp:F2327E82
    @Alternate Data Stream - 236 bytes -> C:\ProgramData\Temp:DE6EED8B
    @Alternate Data Stream - 235 bytes -> C:\ProgramData\Temp:35629AE6
    @Alternate Data Stream - 233 bytes -> C:\ProgramData\Temp:CEE4A457
    @Alternate Data Stream - 230 bytes -> C:\ProgramData\Temp:08DB8D99
    @Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:3B07E6F4
    @Alternate Data Stream - 229 bytes -> C:\ProgramData\Temp:349E5B74
    @Alternate Data Stream - 225 bytes -> C:\ProgramData\Temp:10D45FC3
    @Alternate Data Stream - 224 bytes -> C:\ProgramData\Temp:4B244549
    @Alternate Data Stream - 223 bytes -> C:\ProgramData\Temp:38D2EA83
    @Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:5AE33054
    @Alternate Data Stream - 222 bytes -> C:\ProgramData\Temp:014BC3B4
    @Alternate Data Stream - 221 bytes -> C:\ProgramData\Temp:3C0887BF
    @Alternate Data Stream - 218 bytes -> C:\ProgramData\Temp:41884BBE
    @Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:CB0FEE2B
    @Alternate Data Stream - 216 bytes -> C:\ProgramData\Temp:169E7AC5
    @Alternate Data Stream - 214 bytes -> C:\ProgramData\Temp:A9ABA3FF
    @Alternate Data Stream - 210 bytes -> C:\ProgramData\Temp:ED9B661E
    @Alternate Data Stream - 196 bytes -> C:\ProgramData\Temp:3D36932D
    @Alternate Data Stream - 194 bytes -> C:\ProgramData\Temp:260575F1
    @Alternate Data Stream - 162 bytes -> C:\Users\Karri\Desktop\DSCN1040.JPG:com.dropbox.attributes
    @Alternate Data Stream - 161 bytes -> C:\Users\Karri\Desktop\DSCF4335.JPG:com.dropbox.attributes
    @Alternate Data Stream - 161 bytes -> C:\Users\Karri\Desktop\DSC00973.JPG:com.dropbox.attributes
    @Alternate Data Stream - 161 bytes -> C:\Users\Karri\Desktop\DSC00367.JPG:com.dropbox.attributes
    @Alternate Data Stream - 160 bytes -> C:\Users\Karri\Desktop\HPIM1144.jpg:com.dropbox.attributes
    @Alternate Data Stream - 160 bytes -> C:\Users\Karri\Desktop\_DSC0198.JPG:com.dropbox.attributes
    @Alternate Data Stream - 152 bytes -> C:\ProgramData\Temp:6301CE40
    @Alternate Data Stream - 147 bytes -> C:\ProgramData\Temp:2A8A3140
    @Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:E9900C74
    @Alternate Data Stream - 142 bytes -> C:\ProgramData\Temp:4B70A9FA
    @Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:908A1B53
    @Alternate Data Stream - 141 bytes -> C:\ProgramData\Temp:6E11933F
    @Alternate Data Stream - 135 bytes -> C:\ProgramData\Temp:1B3549F2
    @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:7BB584AA
    @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:274516E7
    @Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:131C0EE9
    @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:57173DB4
    @Alternate Data Stream - 131 bytes -> C:\ProgramData\Temp:3AC0ED43
    @Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:C9BC8592
    @Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:793F316E
    @Alternate Data Stream - 129 bytes -> C:\ProgramData\Temp:92DB4653
    @Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:8AB6C1D7
    @Alternate Data Stream - 119 bytes -> C:\ProgramData\Temp:CFF6B3FF
    @Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:490BCC52
    @Alternate Data Stream - 112 bytes -> C:\ProgramData\Temp:DCA79AB3
    @Alternate Data Stream - 111 bytes -> C:\ProgramData\Temp:2CED8825
    @Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:FC60E0F8
    @Alternate Data Stream - 108 bytes -> C:\ProgramData\Temp:861A898F
    @Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:580E04D8
    @Alternate Data Stream - 104 bytes -> C:\ProgramData\Temp:4F636E25
    
    
    :Files
    ipconfig /flushdns /c
    
    
    :Commands
    [EMPTYFLASH]
    [REBOOT]
    [RESETHOSTS]
    [CREATERESTOREPOINT]
  • Then click the Run Fix button at the top
  • Let the program run unhindered.
  • OTL may ask to reboot the machine. Please do so if asked.
  • The report should appear in Notepad after the reboot.Copy and Paste that report in your next reply.
========== OTL ==========
Unable to save new HOSTS file
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{41564952-412D-5637-00A7-7A786E7484D7}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{41564952-412D-5637-00A7-7A786E7484D7}\ not found.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{CCC7A320-B3CA-4199-B1A6-9F516DD69829} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCC7A320-B3CA-4199-B1A6-9F516DD69829}\ not found.
64bit-Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run\\EmpoweringTechnology deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\intu-qt2008\ deleted successfully.
File Protocol\Handler\intu-qt2008 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\intu-qt2009\ deleted successfully.
File Protocol\Handler\intu-qt2009 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\intu-tt2010\ deleted successfully.
File Protocol\Handler\intu-tt2010 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\intu-tt2011\ deleted successfully.
File Protocol\Handler\intu-tt2011 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\intu-tt2012\ deleted successfully.
File Protocol\Handler\intu-tt2012 - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\livecall\ deleted successfully.
File Protocol\Handler\livecall - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-itss\ deleted successfully.
File Protocol\Handler\ms-itss - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\msnim\ deleted successfully.
File Protocol\Handler\msnim - No CLSID value found not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\skype4com\ deleted successfully.
File Protocol\Handler\skype4com - No CLSID value found not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\PROTOCOLS\Handler\ms-help\ deleted successfully.
File Protocol\Handler\ms-help - No CLSID value found not found.
ADS C:\ProgramData\Temp:D5AA39DD deleted successfully.
ADS C:\ProgramData\Temp:36608448 deleted successfully.
ADS C:\ProgramData\Temp:1E288DA3 deleted successfully.
ADS C:\ProgramData\Temp:AE289451 deleted successfully.
ADS C:\ProgramData\Temp:7D288858 deleted successfully.
ADS C:\ProgramData\Temp:0E61938B deleted successfully.
ADS C:\ProgramData\Temp:FEE00EB9 deleted successfully.
ADS C:\ProgramData\Temp:2EB79F01 deleted successfully.
ADS C:\ProgramData\Temp:F2327E82 deleted successfully.
ADS C:\ProgramData\Temp:DE6EED8B deleted successfully.
ADS C:\ProgramData\Temp:35629AE6 deleted successfully.
ADS C:\ProgramData\Temp:CEE4A457 deleted successfully.
ADS C:\ProgramData\Temp:08DB8D99 deleted successfully.
ADS C:\ProgramData\Temp:3B07E6F4 deleted successfully.
ADS C:\ProgramData\Temp:349E5B74 deleted successfully.
ADS C:\ProgramData\Temp:10D45FC3 deleted successfully.
ADS C:\ProgramData\Temp:4B244549 deleted successfully.
ADS C:\ProgramData\Temp:38D2EA83 deleted successfully.
ADS C:\ProgramData\Temp:5AE33054 deleted successfully.
ADS C:\ProgramData\Temp:014BC3B4 deleted successfully.
ADS C:\ProgramData\Temp:3C0887BF deleted successfully.
ADS C:\ProgramData\Temp:41884BBE deleted successfully.
ADS C:\ProgramData\Temp:CB0FEE2B deleted successfully.
ADS C:\ProgramData\Temp:169E7AC5 deleted successfully.
ADS C:\ProgramData\Temp:A9ABA3FF deleted successfully.
ADS C:\ProgramData\Temp:ED9B661E deleted successfully.
ADS C:\ProgramData\Temp:3D36932D deleted successfully.
ADS C:\ProgramData\Temp:260575F1 deleted successfully.
ADS C:\Users\Karri\Desktop\DSCN1040.JPG:com.dropbox.attributes deleted successfully.
ADS C:\Users\Karri\Desktop\DSCF4335.JPG:com.dropbox.attributes deleted successfully.
ADS C:\Users\Karri\Desktop\DSC00973.JPG:com.dropbox.attributes deleted successfully.
ADS C:\Users\Karri\Desktop\DSC00367.JPG:com.dropbox.attributes deleted successfully.
ADS C:\Users\Karri\Desktop\HPIM1144.jpg:com.dropbox.attributes deleted successfully.
ADS C:\Users\Karri\Desktop\_DSC0198.JPG:com.dropbox.attributes deleted successfully.
ADS C:\ProgramData\Temp:6301CE40 deleted successfully.
ADS C:\ProgramData\Temp:2A8A3140 deleted successfully.
ADS C:\ProgramData\Temp:E9900C74 deleted successfully.
ADS C:\ProgramData\Temp:4B70A9FA deleted successfully.
ADS C:\ProgramData\Temp:908A1B53 deleted successfully.
ADS C:\ProgramData\Temp:6E11933F deleted successfully.
ADS C:\ProgramData\Temp:1B3549F2 deleted successfully.
ADS C:\ProgramData\Temp:7BB584AA deleted successfully.
ADS C:\ProgramData\Temp:274516E7 deleted successfully.
ADS C:\ProgramData\Temp:131C0EE9 deleted successfully.
ADS C:\ProgramData\Temp:57173DB4 deleted successfully.
ADS C:\ProgramData\Temp:3AC0ED43 deleted successfully.
ADS C:\ProgramData\Temp:C9BC8592 deleted successfully.
ADS C:\ProgramData\Temp:793F316E deleted successfully.
ADS C:\ProgramData\Temp:92DB4653 deleted successfully.
ADS C:\ProgramData\Temp:8AB6C1D7 deleted successfully.
ADS C:\ProgramData\Temp:CFF6B3FF deleted successfully.
ADS C:\ProgramData\Temp:490BCC52 deleted successfully.
ADS C:\ProgramData\Temp:DCA79AB3 deleted successfully.
ADS C:\ProgramData\Temp:2CED8825 deleted successfully.
ADS C:\ProgramData\Temp:FC60E0F8 deleted successfully.
ADS C:\ProgramData\Temp:861A898F deleted successfully.
ADS C:\ProgramData\Temp:580E04D8 deleted successfully.
ADS C:\ProgramData\Temp:4F636E25 deleted successfully.
========== FILES ==========
< ipconfig /flushdns /c >
Windows IP Configuration
Successfully flushed the DNS Resolver Cache.
C:\Users\Karri\Desktop\cmd.bat deleted successfully.
C:\Users\Karri\Desktop\cmd.txt deleted successfully.
========== COMMANDS ==========

[EMPTYFLASH]

User: Administrator

User: All Users

User: AppData

User: Default
->Flash cache emptied: 56504 bytes

User: Default User
->Flash cache emptied: 0 bytes

User: Guest
->Flash cache emptied: 4215 bytes

User: Karri
->Flash cache emptied: 9913326 bytes

User: Pat
->Flash cache emptied: 57579 bytes

User: Public

User: UpdatusUser
->Flash cache emptied: 56504 bytes

Total Flash Files Cleaned = 10.00 mb

File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.
Error: Unble to create default HOSTS file!
Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.69.0 log created on 09122013_151001

Files\Folders moved on Reboot…
File move failed. C:\Windows\System32\drivers\etc\Hosts scheduled to be moved on reboot.

PendingFileRenameOperations files…

Registry entries deleted on Reboot…
Hi Freyja :)

Please let me know how your machine is running and if there are any outstanding issues.


Next

We are almost at the end

Complete Internet Repair

  • Please download comintrep.exe and save it to your desktop
  • Double click the icon and select Run
  • Click Extract
  • Double click the Complete Internet Repair folder on your desktop
  • Double click the CIntRep.exe icon
  • Place a checkmark next to the following entries:
    • Reset Internet Protocol (TCP/IP)
    • Repair Winsock (Reset Catalog)
    • Renew Internet Connections
    • Flush DNS Resolver Cache
    • Repair Internet Explorer 6.0.2900
    • Clear Windows Update History
    • Repair Windows / Automatic Updates
    • Repair SSL / HTTPS / Cryptography
    • Reset Windows Firewall Configuration
    • Restore the default hosts file
    • Repair Workgroup Computers view
  • Click Go!
  • Ignore any error messages for now
  • Click OK to reboot your computer
Hi Sonja

Try this:

Download TFC to your desktop
  • Close any open windows.
  • Double click the TFC icon to run the program
  • TFC will close all open programs itself in order to run,
  • Click the Start button to begin the process.
  • Allow TFC to run uninterrupted.
  • The program should not take long to finish it's job
  • Once its finished it should automatically reboot your machine,
  • if it doesn't, manually reboot to ensure a complete clean

Next

See the note in Using Windows Security Center

In your next reply Please let me know if work it :D
Hello, You addressed the last update to Sonja and I wanted to make sure that it was for me and that you didn't accidentally post on my topic. thanks, Freyja

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI