Sweetpotato
Topic Starter
I have been having problems with my computer freezing up and running at a snails pace. I did do spybot search and destroy and it di d find some things, but there is still something there. Not sure what to do? Thank in advance for the help. I am posting the two OT logs.
OTL logfile created on: 9/11/2013 7:54:16 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Regina\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.57 Gb Total Physical Memory | 2.39 Gb Available Physical Memory | 66.85% Memory free
4.20 Gb Paging File | 2.93 Gb Available in Paging File | 69.75% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 444.19 Gb Total Space | 273.11 Gb Free Space | 61.49% Space Free | Partition Type: NTFS
Computer Name: CARTER | User Name: Regina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Regina\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Garmin Ltd or its subsidiaries)
PRC - C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe (Samsung Electronics Co., Ltd.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl ()
========== Services (SafeList) ==========
SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (DsmSvc) – C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:64bit: - (netprofm) – C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:64bit: - (BrokerInfrastructure) – C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:64bit: - (AudioEndpointBuilder) – C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:64bit: - (TimeBroker) – C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (SystemEventsBroker) – C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (ETDService) – C:\Program Files\Elantech\ETDService.exe (ELAN Microelectronics Corp.)
SRV:64bit: - (wlidsvc) – C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:64bit: - (LSM) – C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:64bit: - (PrintNotify) – C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:64bit: - (WSService) – C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
SRV:64bit: - (fhsvc) – C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (DeviceFastLaneService) – C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe (Acer Incorporated)
SRV:64bit: - (WiaRpc) – C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:64bit: - (Wcmsvc) – C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:64bit: - (VaultSvc) – C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:64bit: - (svsvc) – C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:64bit: - (Netlogon) – C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:64bit: - (NcaSvc) – C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:64bit: - (NcdAutoSetup) – C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:64bit: - (KeyIso) – C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:64bit: - (EFS) – C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:64bit: - (DeviceAssociationService) – C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:64bit: - (AllUserInstallAgent) – C:\Windows\SysNative\AUInstallAgent.dll (Microsoft Corporation)
SRV:64bit: - (vmicvss) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmictimesync) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicshutdown) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicrdv) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmickvpexchange) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicheartbeat) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV - (Spooler) – C:\Windows\SysWOW64\spoolsv.exe ()
SRV - (SamSs) – C:\Windows\SysWOW64\lsass.exe ()
SRV - (AMD External Events Utility) – C:\Windows\SysWOW64\atiesrxx.exe ()
SRV - (Garmin Core Update Service) – C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Garmin Ltd or its subsidiaries)
SRV - (PrintNotify) – C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (RfButtonDriverService) – C:\Windows\RfBtnSvc64.exe (Dritek System INC.)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (NTI Corporation)
SRV - (CCDMonitorService) – C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (Acer Incorporated)
SRV - (StorSvc) – C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)
SRV - (IconMan_R) – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (EgisTec Ticket Service) – C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. )
SRV - (SamsungAllShareV2.0) – C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe (Samsung Electronics Co., Ltd.)
SRV - (SimpleSlideShowServer) – C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe (Samsung Electronics Co., Ltd.)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswVmm) – C:\Windows\SysNative\drivers\aswVmm.sys ()
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\Drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswRvrt) – C:\Windows\SysNative\drivers\aswRvrt.sys ()
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\Drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (WdBoot) – C:\Windows\SysNative\Drivers\WdBoot.sys (Microsoft Corporation)
DRV:64bit: - (WdFilter) – C:\Windows\SysNative\Drivers\WdFilter.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\Drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (USBXHCI) – C:\Windows\SysNative\Drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:64bit: - (UCX01000) – C:\Windows\SysNative\Drivers\UCX01000.SYS (Microsoft Corporation)
DRV:64bit: - (BthAvrcpTg) – C:\Windows\SysNative\Drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:64bit: - (USBHUB3) – C:\Windows\SysNative\Drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:64bit: - (spaceport) – C:\Windows\SysNative\Drivers\spaceport.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) – C:\Windows\SysNative\Drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (storahci) – C:\Windows\SysNative\Drivers\storahci.sys (Microsoft Corporation)
DRV:64bit: - (TPM) – C:\Windows\SysNative\Drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (pdc) – C:\Windows\SysNative\Drivers\pdc.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\Drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\Drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (ETD) – C:\Windows\SysNative\Drivers\ETD.sys (ELAN Microelectronics Corp.)
DRV:64bit: - (msgpiowin32) – C:\Windows\SysNative\Drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (bthhfhid) – C:\Windows\SysNative\Drivers\BthhfHid.sys (Microsoft Corporation)
DRV:64bit: - (hidi2c) – C:\Windows\SysNative\Drivers\hidi2c.sys (Microsoft Corporation)
DRV:64bit: - (FxPPM) – C:\Windows\SysNative\Drivers\fxppm.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\Drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (sdstor) – C:\Windows\SysNative\Drivers\sdstor.sys (Microsoft Corporation)
DRV:64bit: - (dam) – C:\Windows\SysNative\Drivers\dam.sys (Microsoft Corporation)
DRV:64bit: - (WSDScan) – C:\Windows\SysNative\Drivers\WSDScan.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\Drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (GPIOClx0101) – C:\Windows\SysNative\Drivers\msgpioclx.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\Drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\Drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (Ps2Kb2Hid) – C:\Windows\SysNative\Drivers\aPs2Kb2Hid.sys (Dritek System Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\Drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\Drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\Drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (condrv) – C:\Windows\SysNative\Drivers\condrv.sys (Microsoft Corporation)
DRV:64bit: - (VSTXRAID) – C:\Windows\SysNative\Drivers\VSTXRAID.SYS (VIA Corporation)
DRV:64bit: - (VerifierExt) – C:\Windows\SysNative\Drivers\VerifierExt.sys (Microsoft Corporation)
DRV:64bit: - (UASPStor) – C:\Windows\SysNative\Drivers\uaspstor.sys (Microsoft Corporation)
DRV:64bit: - (acpiex) – C:\Windows\SysNative\Drivers\acpiex.sys (Microsoft Corporation)
DRV:64bit: - (mvumis) – C:\Windows\SysNative\Drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\Drivers\stexstor.sys (Promise Technology, Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\Drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (LSI_SSS) – C:\Windows\SysNative\Drivers\lsi_sss.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\Drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (EhStorTcgDrv) – C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:64bit: - (EhStorClass) – C:\Windows\SysNative\Drivers\EhStorClass.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\Drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (3ware) – C:\Windows\SysNative\Drivers\3ware.sys (LSI)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\Drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\Drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (CLFS) – C:\Windows\SysNative\Drivers\clfs.sys (Microsoft Corporation)
DRV:64bit: - (WFPLWFS) – C:\Windows\SysNative\Drivers\wfplwfs.sys (Microsoft Corporation)
DRV:64bit: - (vpci) – C:\Windows\SysNative\Drivers\vpci.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) – C:\Windows\SysNative\Drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\Drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (mshidumdf) – C:\Windows\SysNative\Drivers\mshidumdf.sys (Microsoft Corporation)
DRV:64bit: - (BasicDisplay) – C:\Windows\SysNative\Drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:64bit: - (HyperVideo) – C:\Windows\SysNative\Drivers\HyperVideo.sys (Microsoft Corporation)
DRV:64bit: - (BasicRender) – C:\Windows\SysNative\Drivers\BasicRender.sys (Microsoft Corporation)
DRV:64bit: - (gencounter) – C:\Windows\SysNative\Drivers\vmgencounter.sys (Microsoft Corporation)
DRV:64bit: - (kdnic) – C:\Windows\SysNative\Drivers\kdnic.sys (Microsoft Corporation)
DRV:64bit: - (acpitime) – C:\Windows\SysNative\Drivers\acpitime.sys (Microsoft Corporation)
DRV:64bit: - (npsvctrig) – C:\Windows\SysNative\Drivers\npsvctrig.sys (Microsoft Corporation)
DRV:64bit: - (WpdUpFltr) – C:\Windows\SysNative\Drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:64bit: - (acpipagr) – C:\Windows\SysNative\Drivers\acpipagr.sys (Microsoft Corporation)
DRV:64bit: - (hyperkbd) – C:\Windows\SysNative\Drivers\hyperkbd.sys (Microsoft Corporation)
DRV:64bit: - (SerCx) – C:\Windows\SysNative\Drivers\SerCx.sys (Microsoft Corporation)
DRV:64bit: - (SpbCx) – C:\Windows\SysNative\Drivers\SpbCx.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\Drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (BthHFEnum) – C:\Windows\SysNative\Drivers\bthhfenum.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) – C:\Windows\SysNative\Drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\Drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (wpcfltr) – C:\Windows\SysNative\Drivers\wpcfltr.sys (Microsoft Corporation)
DRV:64bit: - (NdisImPlatform) – C:\Windows\SysNative\Drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:64bit: - (MsLldp) – C:\Windows\SysNative\Drivers\mslldp.sys (Microsoft Corporation)
DRV:64bit: - (Ndu) – C:\Windows\SysNative\Drivers\Ndu.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\Drivers\AtihdW86.sys (Advanced Micro Devices)
DRV:64bit: - (RTWlanE) – C:\Windows\SysNative\Drivers\rtwlane.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RTL8192Ce) – C:\Windows\SysNative\Drivers\rtwlane.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (L1C) – C:\Windows\SysNative\Drivers\L1C63x64.sys (Qualcomm Atheros Co., Ltd.)
DRV:64bit: - (RSPCIESTOR) – C:\Windows\SysNative\Drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\Drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\Drivers\BCMWL63A.SYS (Broadcom Corporation)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\Drivers\UBHelper.sys (NTI Corporation)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\Drivers\NTIDrvr.sys (NTI Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE:64bit: - HKLM\..\SearchScopes\{D66AF222-5CCE-42CC-95B3-D61D423295E1}: "URL" = http://www.bing.com/search?q={searchTerms}…R&pc;=MAARJS
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {D66AF222-5CCE-42CC-95B3-D61D423295E1}
IE - HKLM\..\SearchScopes\{D66AF222-5CCE-42CC-95B3-D61D423295E1}: "URL" = http://www.bing.com/search?q={searchTerms}…R&pc;=MAARJS
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\SearchScopes,DefaultScope = {E8306F4C-C68D-4654-AC74-C6754A8EB48B}
IE - HKCU\..\SearchScopes\{E8306F4C-C68D-4654-AC74-C6754A8EB48B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…513922&UM;=2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\4\NP_wtapp.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\McAfee\MSK
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncodin
g}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugk
ey={google:suggestAPIKeyParameter},
CHR - homepage: http://search.conduit.com/?SearchSource=10…;ctid=CT3286042
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Regina\AppData\Local\Google\Chrome\Application\31.0.1622.7\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Regina\AppData\Local\Google\Chrome\Application\31.0.1622.7\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Regina\AppData\Local\Google\Chrome\Application\31.0.1622.7\pdf.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll
CHR - plugin: WildTangent Games App V2 Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\4\NP_wtapp.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RocketLife Secure Plug-In Layer (Enabled) = C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AdBlock = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.6_0\
CHR - Extension: avast! Online Security = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Gmail = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/07/26 00:26:49 | 000,000,824 | —- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (no name) - {9D717F81-9148-4f12-8568-69135F087DB0} - No CLSID value found.
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AllShareAgent] C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BakupManagerTray] C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [GarminExpressTrayApp] C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKCU..\Run: [Spybot-S&D; Cleaning] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: swcportal.org ([mymadisoncollege] https in Trusted sites)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{038C89A4-7FA6-4076-85EC-7E40F6EC8085}: DhcpNameServer = 192.168.1.1
O20:64bit: - AppInit_DLLs: (C:\PROGRA~3\Wincert\WIN64C~1.DLL) - C:\ProgramData\Wincert\win64cert.dll ()
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\Datamngr\x64\mgrldr.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~3\Wincert\WIN32C~1.DLL) - C:\ProgramData\Wincert\win32cert.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\Datamngr\mgrldr.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/09/10 20:48:02 | 000,000,000 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs:64bit: wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:64bit: DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:64bit: NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
NetSvcs:64bit: SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/09/10 20:46:14 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2013/09/10 20:42:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2013/09/10 07:07:19 | 000,000,000 | —D | C] – C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/09/09 12:42:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2013/09/09 12:42:46 | 000,000,000 | —D | C] – C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2013/09/09 12:27:29 | 000,688,992 | R— | C] (Swearware) – C:\Users\Regina\Desktop\dds.com
[2013/09/08 21:12:05 | 000,173,504 | —- | C] (Trend Micro Inc.) – C:\Windows\SysNative\drivers\tmcomm.sys
[2013/09/08 12:44:10 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/09/08 12:43:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/09/08 12:43:37 | 000,017,272 | —- | C] (Safer Networking Limited) – C:\Windows\SysNative\sdnclean64.exe
[2013/09/08 12:43:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy 2
[2013/09/07 19:44:21 | 001,257,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/09/07 19:44:17 | 001,300,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gdi32.dll
[2013/09/06 22:05:34 | 000,000,000 | —D | C] – C:\ProgramData\PCPitstop
[2013/09/06 22:05:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\PCPitstop
[2013/09/06 19:07:34 | 000,000,000 | —D | C] – C:\ProgramData\Samsung
[2013/09/06 19:04:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Samsung Electronics
[2013/09/04 19:28:29 | 000,888,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\autochk.exe
[2013/09/04 19:28:29 | 000,542,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\untfs.dll
[2013/09/04 19:28:28 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\untfs.dll
[2013/09/04 19:28:27 | 000,793,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\autochk.exe
[2013/09/03 15:15:23 | 013,644,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.UI.Xaml.dll
[2013/09/03 15:15:14 | 010,788,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.UI.Xaml.dll
[2013/09/03 15:15:08 | 001,131,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentServer.dll
[2013/09/03 15:15:03 | 010,116,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\twinui.dll
[2013/09/03 15:14:54 | 000,470,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netprofmsvc.dll
[2013/09/03 15:14:49 | 008,857,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\twinui.dll
[2013/09/03 15:14:47 | 002,305,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/09/03 15:14:46 | 000,760,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2013/09/03 15:14:44 | 002,035,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/09/03 15:14:42 | 000,014,848 | —- | C] (Microsoft) – C:\Windows\SysWow64\rars.rs
[2013/09/03 15:14:41 | 000,014,848 | —- | C] (Microsoft) – C:\Windows\SysNative\rars.rs
[2013/09/03 15:14:40 | 000,446,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\USBHUB3.SYS
[2013/09/03 15:14:40 | 000,328,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ubpm.dll
[2013/09/03 15:14:39 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\BCP47Langs.dll
[2013/09/03 15:14:39 | 000,330,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\stobject.dll
[2013/09/03 15:14:39 | 000,247,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ubpm.dll
[2013/09/03 15:14:38 | 000,621,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapi.dll
[2013/09/03 15:14:37 | 000,708,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentExtensions.dll
[2013/09/03 15:14:36 | 000,812,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Magnify.exe
[2013/09/03 15:14:36 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netplwiz.dll
[2013/09/03 15:14:35 | 000,560,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfmp4srcsnk.dll
[2013/09/03 15:14:35 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psmsrv.dll
[2013/09/03 15:14:34 | 000,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netplwiz.dll
[2013/09/03 15:14:32 | 000,501,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DevicePairing.dll
[2013/09/03 15:14:32 | 000,284,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\spaceport.sys
[2013/09/03 15:14:31 | 000,058,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2013/09/03 15:14:30 | 000,419,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\intl.cpl
[2013/09/03 15:14:29 | 000,120,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AuthHost.exe
[2013/09/03 15:14:28 | 001,619,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2013/09/03 15:14:28 | 000,758,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Magnify.exe
[2013/09/03 15:14:27 | 000,449,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DevicePairing.dll
[2013/09/03 15:14:26 | 000,122,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\biwinrt.dll
[2013/09/03 15:14:24 | 000,251,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUSettingsProvider.dll
[2013/09/03 15:14:24 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\biwinrt.dll
[2013/09/03 15:14:22 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\intl.cpl
[2013/09/03 15:14:22 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\bisrv.dll
[2013/09/03 15:14:20 | 000,411,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfmp4srcsnk.dll
[2013/09/03 15:14:20 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\storewuauth.dll
[2013/09/03 15:14:19 | 000,141,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2013/09/03 15:14:19 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuwebv.dll
[2013/09/03 15:14:19 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2013/09/03 15:14:18 | 000,309,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\BCP47Langs.dll
[2013/09/03 15:14:18 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wudriver.dll
[2013/09/03 15:14:17 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2013/09/03 15:14:17 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\muifontsetup.dll
[2013/09/03 15:14:16 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapp.exe
[2013/09/03 15:14:15 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\muifontsetup.dll
[2013/09/03 13:07:30 | 000,247,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdFilter.sys
[2013/09/03 13:07:29 | 000,036,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdBoot.sys
[2013/09/03 11:35:32 | 000,000,000 | —D | C] – C:\Windows\SysNative\MRT
[2013/09/03 11:29:41 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rpcrt4.dll
[2013/09/02 15:13:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/09/02 15:11:19 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/09/02 15:11:16 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/09/02 15:11:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013/09/02 15:11:16 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/09/02 11:52:06 | 000,915,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\uxtheme.dll
[2013/09/02 11:52:06 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UXInit.dll
[2013/09/02 11:52:05 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UXInit.dll
[2013/09/02 11:52:05 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/09/02 11:52:04 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/09/02 11:51:47 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/09/02 11:51:47 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/09/02 11:51:47 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/09/02 11:51:41 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/09/02 11:51:37 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/09/02 11:51:35 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/09/02 11:51:09 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/09/02 11:49:00 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/09/02 11:48:58 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/09/02 08:37:44 | 001,889,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/09/02 08:37:39 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2013/09/02 08:37:38 | 000,124,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\apprepapi.dll
[2013/09/02 08:37:38 | 000,087,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apprepapi.dll
[2013/09/02 08:37:37 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\apprepsync.dll
[2013/09/02 08:37:36 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apprepsync.dll
[2013/09/02 05:37:26 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/09/02 05:37:26 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/09/01 23:52:07 | 000,595,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/09/01 23:52:06 | 000,496,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/09/01 19:26:44 | 000,800,824 | —- | C] (Microsoft Corporation) – C:\Users\Regina\AppData\Roaming\DPInst.exe
[2013/09/01 19:26:44 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Users\Regina\AppData\Roaming\gacutil.exe
[2013/09/01 19:26:44 | 000,036,352 | —- | C] (Microsoft Corporation) – C:\Users\Regina\AppData\Roaming\PnPutil.exe
[2013/09/01 18:40:50 | 000,000,000 | —D | C] – C:\Users\Regina\AppData\Local\ElevatedDiagnostics
[2013/08/24 16:46:00 | 001,838,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/08/24 09:10:10 | 001,842,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dwmcore.dll
[2013/08/24 09:10:09 | 001,453,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfcore.dll
[2013/08/24 09:10:09 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/08/24 09:10:08 | 000,850,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfasfsrcsnk.dll
[2013/08/24 09:10:07 | 002,106,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2013/08/24 09:09:55 | 000,337,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\USBXHCI.SYS
[2013/08/24 09:09:55 | 000,213,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\UCX01000.SYS
[2013/08/24 09:09:55 | 000,194,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\sdbus.sys
[2013/08/24 09:09:54 | 000,125,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dumpsd.sys
[2013/08/24 09:09:53 | 000,190,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vdsutil.dll
[2013/08/24 09:09:51 | 006,987,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/08/24 09:09:49 | 001,527,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfcore.dll
[2013/08/24 09:09:49 | 001,048,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfasfsrcsnk.dll
[2013/08/24 09:09:48 | 000,583,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mscms.dll
[2013/08/24 09:09:48 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MbaeParserTask.exe
[2013/08/24 09:09:47 | 002,391,280 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2013/08/24 09:09:47 | 000,729,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\samsrv.dll
[2013/08/24 09:09:47 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DeviceSetupManager.dll
[2013/08/24 09:09:47 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\samlib.dll
[2013/08/24 09:09:46 | 002,219,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dwmcore.dll
[2013/08/24 09:09:46 | 000,523,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/08/24 09:09:45 | 001,093,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.exe
[2013/08/24 09:09:44 | 001,403,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.efi
[2013/08/24 09:09:44 | 001,271,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.exe
[2013/08/24 09:09:44 | 001,217,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.efi
[2013/08/24 09:09:36 | 000,037,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\BthAvrcpTg.sys
[2013/08/19 20:46:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/08/19 20:41:57 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2013/08/19 20:41:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/09/11 07:52:26 | 000,001,421 | —- | M] () – C:\Users\Regina\Desktop\OTL - Shortcut.lnk
[2013/09/11 07:08:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/09/11 07:06:09 | 268,435,456 | -HS- | M] () – C:\swapfile.sys
[2013/09/11 07:06:08 | 3068,764,160 | -HS- | M] () – C:\hiberfil.sys
[2013/09/10 20:48:02 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2013/09/10 19:52:33 | 000,931,243 | —- | M] () – C:\Users\Regina\AppData\Local\census.cache
[2013/09/10 19:52:13 | 000,085,354 | —- | M] () – C:\Users\Regina\AppData\Local\ars.cache
[2013/09/10 07:07:19 | 000,002,377 | —- | M] () – C:\Users\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/09/10 07:07:19 | 000,002,375 | —- | M] () – C:\Users\Regina\Desktop\Google Chrome.lnk
[2013/09/09 20:12:13 | 000,003,924 | —- | M] () – C:\Users\Regina\Documents\cc_20130909_201207.reg
[2013/09/09 14:11:47 | 000,281,088 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/09/09 13:10:40 | 000,009,670 | —- | M] () – C:\Users\Regina\Documents\cc_20130909_131036.reg
[2013/09/09 12:42:46 | 000,002,981 | —- | M] () – C:\Users\Regina\Desktop\HiJackThis.lnk
[2013/09/09 12:30:48 | 001,402,880 | —- | M] () – C:\Users\Regina\Desktop\HiJackThis.msi
[2013/09/09 12:27:34 | 000,688,992 | R— | M] (Swearware) – C:\Users\Regina\Desktop\dds.com
[2013/09/09 12:00:49 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/09/09 11:33:47 | 000,007,605 | —- | M] () – C:\Users\Regina\AppData\Local\Resmon.ResmonCfg
[2013/09/08 22:52:44 | 000,000,000 | —- | M] () – C:\Windows\SysNative\olepro32.dll
[2013/09/08 22:52:33 | 000,000,000 | —- | M] () – C:\Windows\SysNative\atiuxpag.dll
[2013/09/08 22:52:33 | 000,000,000 | —- | M] () – C:\Windows\SysNative\atidxx32.dll
[2013/09/08 22:52:33 | 000,000,000 | —- | M] () – C:\Windows\SysNative\aticfx32.dll
[2013/09/08 21:15:57 | 000,001,184 | —- | M] () – C:\Users\Public\Desktop\Install Microsoft Mouse and Keyboard Center.lnk
[2013/09/08 16:01:50 | 000,005,111 | —- | M] () – C:\Windows\wininit.ini
[2013/09/08 12:43:54 | 000,001,387 | —- | M] () – C:\Users\Public\Desktop\Spybot-S&D; Start Center.lnk
[2013/09/06 19:02:42 | 000,848,230 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/09/06 19:02:42 | 000,719,418 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/09/06 19:02:42 | 000,132,748 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/09/02 15:13:07 | 000,001,787 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/09/01 23:27:14 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\taskhost.exe
[2013/09/01 23:27:12 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\RuntimeBroker.exe
[2013/09/01 23:27:12 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\printfilterpipelinesvc.exe
[2013/09/01 23:27:12 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\atieclxx.exe
[2013/09/01 23:24:57 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\taskhostex.exe
[2013/09/01 23:24:57 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\conhost.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\winlogon.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\spoolsv.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\services.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\lsass.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\dasHost.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\atiesrxx.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\wininit.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\smss.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\dwm.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\csrss.exe
[2013/09/01 20:35:58 | 000,008,500 | —- | M] () – C:\Users\Regina\Documents\cc_20130901_203552.reg
[2013/09/01 19:26:44 | 000,800,824 | —- | M] (Microsoft Corporation) – C:\Users\Regina\AppData\Roaming\DPInst.exe
[2013/09/01 19:26:44 | 000,106,496 | —- | M] (Microsoft Corporation) – C:\Users\Regina\AppData\Roaming\gacutil.exe
[2013/09/01 19:26:44 | 000,036,352 | —- | M] (Microsoft Corporation) – C:\Users\Regina\AppData\Roaming\PnPutil.exe
[2013/09/01 19:26:44 | 000,000,181 | —- | M] () – C:\Users\Regina\AppData\Roaming\gacutil.exe.config
[2013/09/01 19:13:59 | 000,000,460 | —- | M] () – C:\Users\Regina\Documents\cc_20130901_191353.reg
[2013/09/01 19:10:10 | 000,000,826 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/08/30 13:01:23 | 000,002,457 | —- | M] () – C:\Users\Regina\Documents\To Do List.rtf
[2013/08/30 02:48:10 | 001,030,952 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2013/08/30 02:48:10 | 000,378,944 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2013/08/30 02:48:10 | 000,204,880 | —- | M] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/08/30 02:48:10 | 000,072,016 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2013/08/30 02:48:10 | 000,065,336 | —- | M] () – C:\Windows\SysNative\drivers\aswRvrt.sys
[2013/08/30 02:48:10 | 000,064,288 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2013/08/30 02:48:09 | 000,080,816 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2013/08/30 02:48:09 | 000,033,400 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2013/08/30 02:47:40 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2013/08/30 02:47:14 | 000,287,840 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2013/08/26 18:56:10 | 000,002,156 | —- | M] () – C:\Users\Regina\Documents\resume.rtf
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/09/11 07:52:08 | 000,001,421 | —- | C] () – C:\Users\Regina\Desktop\OTL - Shortcut.lnk
[2013/09/10 20:48:02 | 000,000,000 | —- | C] () – C:\autoexec.bat
[2013/09/10 07:07:19 | 000,002,377 | —- | C] () – C:\Users\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/09/10 07:07:19 | 000,002,375 | —- | C] () – C:\Users\Regina\Desktop\Google Chrome.lnk
[2013/09/09 20:12:09 | 000,003,924 | —- | C] () – C:\Users\Regina\Documents\cc_20130909_201207.reg
[2013/09/09 14:11:33 | 000,281,088 | —- | C] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/09/09 13:10:38 | 000,009,670 | —- | C] () – C:\Users\Regina\Documents\cc_20130909_131036.reg
[2013/09/09 12:42:46 | 000,002,981 | —- | C] () – C:\Users\Regina\Desktop\HiJackThis.lnk
[2013/09/09 12:30:37 | 001,402,880 | —- | C] () – C:\Users\Regina\Desktop\HiJackThis.msi
[2013/09/09 11:33:47 | 000,007,605 | —- | C] () – C:\Users\Regina\AppData\Local\Resmon.ResmonCfg
[2013/09/08 22:52:44 | 000,000,000 | —- | C] () – C:\Windows\SysNative\olepro32.dll
[2013/09/08 22:52:33 | 000,000,000 | —- | C] () – C:\Windows\SysNative\atiuxpag.dll
[2013/09/08 22:52:33 | 000,000,000 | —- | C] () – C:\Windows\SysNative\atidxx32.dll
[2013/09/08 22:52:33 | 000,000,000 | —- | C] () – C:\Windows\SysNative\aticfx32.dll
[2013/09/08 21:15:57 | 000,001,184 | —- | C] () – C:\Users\Public\Desktop\Install Microsoft Mouse and Keyboard Center.lnk
[2013/09/08 14:31:38 | 000,005,111 | —- | C] () – C:\Windows\wininit.ini
[2013/09/08 12:43:54 | 000,001,399 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D; Start Center.lnk
[2013/09/08 12:43:54 | 000,001,387 | —- | C] () – C:\Users\Public\Desktop\Spybot-S&D; Start Center.lnk
[2013/09/02 15:13:07 | 000,001,787 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/09/02 00:37:29 | 000,931,243 | —- | C] () – C:\Users\Regina\AppData\Local\census.cache
[2013/09/02 00:36:28 | 000,085,354 | —- | C] () – C:\Users\Regina\AppData\Local\ars.cache
[2013/09/01 23:27:14 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\taskhost.exe
[2013/09/01 23:27:12 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\RuntimeBroker.exe
[2013/09/01 23:27:12 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\printfilterpipelinesvc.exe
[2013/09/01 23:27:12 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\atieclxx.exe
[2013/09/01 23:24:57 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\taskhostex.exe
[2013/09/01 23:24:57 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\conhost.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\winlogon.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\spoolsv.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\services.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\lsass.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\dasHost.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\atiesrxx.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\wininit.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\smss.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\dwm.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\csrss.exe
[2013/09/01 20:35:56 | 000,008,500 | —- | C] () – C:\Users\Regina\Documents\cc_20130901_203552.reg
[2013/09/01 19:26:44 | 000,000,181 | —- | C] () – C:\Users\Regina\AppData\Roaming\gacutil.exe.config
[2013/09/01 19:13:57 | 000,000,460 | —- | C] () – C:\Users\Regina\Documents\cc_20130901_191353.reg
[2013/08/28 19:52:28 | 000,002,457 | —- | C] () – C:\Users\Regina\Documents\To Do List.rtf
[2013/08/26 18:56:10 | 000,002,156 | —- | C] () – C:\Users\Regina\Documents\resume.rtf
[2013/08/24 09:09:54 | 000,386,642 | —- | C] () – C:\Windows\SysNative\ApnDatabase.xml
[2013/03/07 14:49:56 | 000,000,036 | —- | C] () – C:\Users\Regina\AppData\Local\housecall.guid.cache
[2013/01/11 10:27:59 | 000,083,968 | —- | C] () – C:\Windows\SysWow64\OEMLicense.dll
[2012/09/03 16:59:49 | 000,451,072 | —- | C] () – C:\Windows\SysWow64\ISSRemoveSP.exe
[2012/09/03 16:44:30 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/08/14 10:06:37 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/08/14 10:06:37 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/08/14 10:06:37 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2012/07/26 03:13:10 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2012/07/26 03:13:09 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2012/07/26 02:21:26 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2012/07/25 20:17:42 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2012/07/25 15:37:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2012/07/25 15:28:31 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2012/06/02 09:31:19 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2012/05/10 17:35:16 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
========== ZeroAccess Check ==========
[2012/09/03 17:30:15 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/03/06 01:31:28 | 019,758,592 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/03/06 00:03:37 | 017,561,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2012/07/25 22:05:38 | 001,004,544 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2012/07/25 22:18:27 | 000,784,896 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2012/07/25 22:07:41 | 000,455,680 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/01/11 18:26:32 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Awem
[2013/01/10 20:43:35 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\FloodLightGames
[2013/04/23 23:10:20 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Garmin
[2013/01/23 09:49:54 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\ICAClient
[2013/01/12 22:04:05 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Jewel Match 3
[2013/01/08 18:44:06 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\lm
[2013/03/17 22:28:52 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Rovio
[2013/04/12 17:28:52 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Samsung
[2013/01/20 11:05:48 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Temp
[2013/03/14 21:18:58 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\TFP
[2013/04/13 23:14:43 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\TuneUp Software
[2013/01/20 11:47:14 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Visan
[2013/01/08 22:39:28 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\WildTangent
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.0.LOCALSETTINGUNIT >
[2013/04/04 17:26:37 | 000,000,357 | -HS- | M] () MD5=CB434B1A74F1B07A7A9F444F25D4AD59 – C:\Users\Regina\AppData\Local\Microsoft\Windows\Live\Roaming\LocalCache\windows-explorer\Explorer.0.localsettingunit
< MD5 for: EXPLORER.ADML >
[2012/07/26 02:49:05 | 000,003,671 | —- | M] () MD5=007B16AEF3E958080573CDB80648167D – C:\Windows\WinSxS\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.2.9200.16384_en-us_7bca26f6f419a854\Explorer.adml
[2012/07/26 02:49:05 | 000,003,671 | —- | M] () MD5=007B16AEF3E958080573CDB80648167D – C:\Windows\WinSxS\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.2.9200.16433_en-us_7bff382ef3f2006f\Explorer.adml
[2012/07/26 02:49:05 | 000,003,671 | —- | M] () MD5=007B16AEF3E958080573CDB80648167D – C:\Windows\WinSxS\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.2.9200.20534_en-us_7c89d5440d0eb990\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2012/06/02 09:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.16384_none_6e8451187a9a1607\Explorer.admx
[2012/06/02 09:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.16420_none_6ec1315e7a6d062c\Explorer.admx
[2012/06/02 09:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.16433_none_6eb962507a726e22\Explorer.admx
[2012/06/02 09:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.20521_none_6f4bce739389bf4d\Explorer.admx
[2012/06/02 09:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.20534_none_6f43ff65938f2743\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2013/05/16 10:58:12 | 003,859,928 | —- | M] (Safer-Networking Ltd.) MD5=03250DB0886A23B1F6C077C5D9F152B0 – C:\Program Files (x86)\Spybot - Search & Destroy 2\explorer.exe
[2012/10/11 00:53:24 | 002,115,952 | —- | M] (Microsoft Corporation) MD5=0AD19A3CA61271BA872AD90771BA47DC – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_b592a71650d677ed\explorer.exe
[2012/10/11 03:09:58 | 002,380,944 | —- | M] (Microsoft Corporation) MD5=0DDFEAA2AA18D4295EF220EB666B2312 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_ab3dfcc41c75b5f2\explorer.exe
[2013/06/01 06:34:21 | 002,391,280 | —- | M] (Microsoft Corporation) MD5=0E8E6463F81C80AFBED533E0F1F8895D – C:\Windows\explorer.exe
[2013/06/01 06:34:21 | 002,391,280 | —- | M] (Microsoft Corporation) MD5=0E8E6463F81C80AFBED533E0F1F8895D – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16628_none_aac334d9034c59e1\explorer.exe
[2013/06/01 05:17:57 | 002,116,520 | —- | M] (Microsoft Corporation) MD5=15C505AD0118275E7363A539009EF3AF – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20733_none_b591aa9850d758e4\explorer.exe
[2012/07/25 22:50:01 | 002,114,936 | —- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_b4d2f8c937e166b1\explorer.exe
[2012/07/25 23:49:13 | 002,380,440 | —- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_aa7e4e770380a4b6\explorer.exe
[2012/10/11 00:56:41 | 002,115,952 | —- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_b5080a0137b9becc\explorer.exe
[2013/06/01 07:41:08 | 002,380,968 | —- | M] (Microsoft Corporation) MD5=D1FF6792A3B0FBD2F2F17DC936AF6177 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20733_none_ab3d00461c7696e9\explorer.exe
[2012/10/11 02:35:16 | 002,380,944 | —- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_aab35faf0358fcd1\explorer.exe
[2013/06/01 05:24:46 | 002,106,176 | —- | M] (Microsoft Corporation) MD5=EAFE46B0292D2BD2467835E2ACF717CC – C:\Windows\SysWOW64\explorer.exe
[2013/06/01 05:24:46 | 002,106,176 | —- | M] (Microsoft Corporation) MD5=EAFE46B0292D2BD2467835E2ACF717CC – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16628_none_b517df2b37ad1bdc\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2012/07/26 02:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\en-US\explorer.exe.mui
[2012/07/26 02:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2012/07/26 02:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\WinSxS\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.2.9200.16384_en-us_5ebc2e81fd6600eb\explorer.exe.mui
[2012/07/26 02:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\WinSxS\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.2.9200.16384_en-us_6910d8d431c6c2e6\explorer.exe.mui
< MD5 for: EXPLORER.EXE-03C49D11.PF >
[2013/09/10 20:07:24 | 000,182,764 | —- | M] () MD5=8E0A73A44D84CB2FDE358B420F219CAD – C:\Windows\Prefetch\EXPLORER.EXE-03C49D11.pf
< MD5 for: IEXPLORE.EXE >
[2012/10/11 01:34:54 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=06E77B5F6BB60E11A377B68BA4AA1DA7 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20534_none_2b74d7cd3a353a33\iexplore.exe
[2013/02/21 06:11:26 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=0A1FC149D1F01AEE5D66D42953CDD751 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20644_none_2b6b082b3a3c6f7b\iexplore.exe
[2013/02/21 06:11:26 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=0A1FC149D1F01AEE5D66D42953CDD751 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20703_none_2b5c4ddf3a480c6f\iexplore.exe
[2013/02/21 06:11:26 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=0A1FC149D1F01AEE5D66D42953CDD751 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20742_none_2b6065cf3a44582a\iexplore.exe
[2012/10/11 02:33:47 | 000,775,168 | —- | M] (Microsoft Corporation) MD5=0A5074651C95792D32BCF536D64D0463 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20534_none_21202d7b05d47838\iexplore.exe
[2012/07/25 22:36:56 | 000,770,504 | —- | M] (Microsoft Corporation) MD5=1249974F2A658D07E2647DD9C3592B9E – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16384_none_425d1fb32079214f\iexplore.exe
[2013/07/26 01:23:39 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=133CEF30905806A35606652D409EEEBA – C:\Program Files\Internet Explorer\iexplore.exe
[2013/07/26 01:23:39 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=133CEF30905806A35606652D409EEEBA – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16660_none_37e66028ec3219f5\iexplore.exe
[2012/10/11 02:24:22 | 000,775,168 | —- | M] (Microsoft Corporation) MD5=13F97D5006C3E37D0A4AABC767C0E553 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16433_none_37f8bacaec24e2f1\iexplore.exe
[2012/07/25 23:58:31 | 000,775,112 | —- | M] (Microsoft Corporation) MD5=29CD24D8CA72FDB986B39277E70A48B6 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16384_none_38087560ec185f54\iexplore.exe
[2012/11/08 01:58:26 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=2F92EE7EE7E189EBDDADD5BEEB7E9DE0 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16453_none_37fabb5eec23159f\iexplore.exe
[2012/12/19 19:51:27 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=328569E3CA8BDB3FF74A3DBB8A1FE827 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20589_none_2b7967573a31390b\iexplore.exe
[2012/10/23 22:14:41 | 000,770,528 | —- | M] (Microsoft Corporation) MD5=39F90724C1A98648CCCDDF13631F2D4A – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16442_none_424e7c2f2084a4a2\iexplore.exe
[2013/02/05 00:23:09 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=4B20825770C794AF430529FCD962FDF5 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20624_none_2b6907973a3e3ccd\iexplore.exe
[2012/11/08 01:48:39 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=4B33704E4B071EC44806846CBE50EB2A – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20557_none_2121e9b705d2f7c9\iexplore.exe
[2013/02/04 17:49:56 | 000,775,136 | —- | M] (Microsoft Corporation) MD5=50BB41EF1CBC08E10CAB2993EEA15586 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16519_none_37eb619aec2f65fa\iexplore.exe
[2013/02/21 07:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16540_none_37ef2f80ec2bcb56\iexplore.exe
[2013/02/21 07:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16599_none_37f363eaec2830b2\iexplore.exe
[2013/02/21 07:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16635_none_37e2ed62ec354e15\iexplore.exe
[2012/10/23 22:20:45 | 000,770,528 | —- | M] (Microsoft Corporation) MD5=79FF6755B94FF918441D8F8162E5AC9C – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20544_none_2b75d8173a34538a\iexplore.exe
[2013/07/25 22:49:06 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/07/25 22:49:06 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16660_none_423b0a7b2092dbf0\iexplore.exe
[2012/12/19 21:27:37 | 000,775,128 | —- | M] (Microsoft Corporation) MD5=7C4D4537048B255A851F19EA2C656BCB – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16484_none_37fda574ec207b45\iexplore.exe
[2012/11/07 23:52:27 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=7EBFC838C815C3DACA135837D8F7906E – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20557_none_2b7694093a33b9c4\iexplore.exe
[2013/07/26 00:47:06 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=8D805B4EEEE0ECF6B604BE284978F135 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20768_none_210d336105e262a3\iexplore.exe
[2012/10/23 23:43:41 | 000,775,136 | —- | M] (Microsoft Corporation) MD5=8E1B68702CDB0DDC6597357766E941D9 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16442_none_37f9d1dcec23e2a7\iexplore.exe
[2013/02/05 01:45:26 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=97808A1A701DC42B07725F8C3D3BDF8D – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20624_none_21145d4505dd7ad2\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/12/19 20:00:31 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=B8B50206CEA0791C26B63B753BCFB1D4 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16484_none_42524fc720813d40\iexplore.exe
[2012/10/11 00:41:41 | 000,770,560 | —- | M] (Microsoft Corporation) MD5=BCF25D644DF1288CD9A6524FF7AB23C8 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16433_none_424d651d2085a4ec\iexplore.exe
[2012/11/07 23:45:20 | 000,770,520 | —- | M] (Microsoft Corporation) MD5=D05965C02FD5781503968225B22189F4 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16453_none_424f65b12083d79a\iexplore.exe
[2012/12/19 21:55:26 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=D865B906C71BD10633BA0E9627050943 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20589_none_2124bd0505d07710\iexplore.exe
[2013/02/05 00:23:07 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=DEAE808A574CF9FC667D6939387FC1CE – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16519_none_42400bed209027f5\iexplore.exe
[2013/02/21 06:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16540_none_4243d9d3208c8d51\iexplore.exe
[2013/02/21 06:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16599_none_42480e3d2088f2ad\iexplore.exe
[2013/02/21 06:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16635_none_423797b520961010\iexplore.exe
[2013/02/21 08:13:16 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=E61732C1203A6BCA2FFB91022CA48AC6 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20644_none_21165dd905dbad80\iexplore.exe
[2013/02/21 08:13:16 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=E61732C1203A6BCA2FFB91022CA48AC6 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20703_none_2107a38d05e74a74\iexplore.exe
[2013/02/21 08:13:16 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=E61732C1203A6BCA2FFB91022CA48AC6 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20742_none_210bbb7d05e3962f\iexplore.exe
[2013/07/26 00:09:39 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=E70D60B3A350BD09D86CDAD9CF55F36B – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20768_none_2b61ddb33a43249e\iexplore.exe
[2012/10/24 01:08:39 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=F78F14096EB41341C4D880CEA6D681A2 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20544_none_21212dc505d3918f\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2012/07/26 02:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C724BBF739D40D8AA3023943F3450A7 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2012/07/26 02:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C724BBF739D40D8AA3023943F3450A7 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/07/26 02:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C724BBF739D40D8AA3023943F3450A7 – C:\Windows\WinSxS\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.0.9200.16384_en-us_31b50ad823c5a03b\iexplore.exe.mui
[2012/07/26 02:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C724BBF739D40D8AA3023943F3450A7 – C:\Windows\WinSxS\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.0.9200.16384_en-us_3c09b52a58266236\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-7A9337F2.PF >
[2013/09/10 06:44:51 | 000,082,454 | —- | M] () MD5=6CC4AC8F97E0D1D982E1AAA89D6465CA – C:\Windows\Prefetch\IEXPLORE.EXE-7A9337F2.pf
< MD5 for: IEXPLORE.EXE-F4FB5D2D.PF >
[2013/09/09 20:06:48 | 000,017,848 | —- | M] () MD5=C742E0E576EB853B09EFD9EA0FD7C479 – C:\Windows\Prefetch\IEXPLORE.EXE-F4FB5D2D.pf
< MD5 for: IEXPLORE.EXE-F4FB5D2F.PF >
[2013/09/10 06:49:58 | 000,213,296 | —- | M] () MD5=2ACFAA8D2925BF7E3FA5A1537E461D52 – C:\Windows\Prefetch\IEXPLORE.EXE-F4FB5D2F.pf
< MD5 for: SERVICES >
[2013/09/09 11:30:08 | 000,092,866 | —- | M] () MD5=2AF38A532752BB4FD1A5FE50AB3AF2BA – C:\Users\Regina\AppData\Roaming\Microsoft\MMC\services
[2012/07/26 00:26:47 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\WinSxS\amd64_microsoft-windows-w..ucture-other-minwin_31bf3856ad364e35_6.2.9200.16384_none_8e0944daeed62829\services
< MD5 for: SERVICES.EXE >
[2012/09/20 01:33:11 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=581190907DA1CF8CB7B87B35FFE64A07 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.20521_none_98a9ea2e9f571eb2\services.exe
[2012/07/26 00:26:45 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=754A2CC1F32107EA87CBD305ABE3E618 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16384_none_97e26cd38667756c\services.exe
[2012/09/20 01:33:46 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=8F226143046435C75C033B0C52E90FFE – C:\Windows\SysNative\services.exe
[2012/09/20 01:33:46 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=8F226143046435C75C033B0C52E90FFE – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16420_none_981f4d19863a6591\services.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Windows\SysWOW64\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2012/07/26 02:48:33 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=8BCB19134E995FA62587DCE26E13B36C – C:\Windows\SysNative\en-US\services.exe.mui
[2012/07/26 02:48:33 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=8BCB19134E995FA62587DCE26E13B36C – C:\Windows\WinSxS\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.2.9200.16384_en-us_c2c6ee7bafb963b8\services.exe.mui
< MD5 for: SERVICES.JS >
[2013/04/17 19:59:23 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingFinance_2.0.0.300_x64__8wekyb3d8bbwe\common\js\services.js
[2013/04/17 19:59:23 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingFinance_2.0.0.308_x64__8wekyb3d8bbwe\common\js\services.js
[2013/07/27 17:18:18 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingNews_2.0.0.273_x64__8wekyb3d8bbwe\common\js\services.js
[2013/07/27 17:18:18 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingNews_2.0.0.308_x64__8wekyb3d8bbwe\common\js\services.js
[2013/07/27 17:27:37 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingSports_2.0.0.273_x64__8wekyb3d8bbwe\common\js\services.js
[2013/07/27 17:27:37 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingSports_2.0.0.309_x64__8wekyb3d8bbwe\common\js\services.js
[2013/07/27 17:14:54 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingTravel_2.0.0.274_x64__8wekyb3d8bbwe\common\js\services.js
[2013/07/27 17:14:54 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingTravel_2.0.0.308_x64__8wekyb3d8bbwe\common\js\services.js
[2013/08/10 16:16:32 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingWeather_2.0.0.288_x64__8wekyb3d8bbwe\common\js\services.js
[2013/08/10 16:16:32 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingWeather_2.0.0.310_x64__8wekyb3d8bbwe\common\js\services.js
[2013/05/10 19:34:46 | 000,007,138 | —- | M] () MD5=20D56CE4E843D60EE9EFBEF6D2A6E24E – C:\Program Files\WindowsApps\ChaChaSearch.ChaChaPushNotification_2.0.1.2_neutral__62vv7yjt7tgyp\js\services.js
[2013/05/10 19:34:46 | 000,007,138 | —- | M] () MD5=20D56CE4E843D60EE9EFBEF6D2A6E24E – C:\Program Files\WindowsApps\ChaChaSearch.ChaChaPushNotification_2.0.1.5_neutral__62vv7yjt7tgyp\js\services.js
[2012/07/26 02:54:02 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingFinance_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 02:53:53 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingNews_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 02:53:50 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingSports_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 02:54:33 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingTravel_1.2.0.145_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 02:53:57 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingWeather_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2013/01/09 21:49:56 | 000,069,359 | —- | M] () MD5=6AA9F10CF05F9848EFAA91062BBEB586 – C:\Program Files\WindowsApps\Microsoft.BingFinance_1.7.0.38_x64__8wekyb3d8bbwe\common\js\services.js
[2013/01/09 21:48:12 | 000,069,359 | —- | M] () MD5=6AA9F10CF05F9848EFAA91062BBEB586 – C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\js\services.js
[2013/01/10 14:50:19 | 000,069,359 | —- | M] () MD5=6AA9F10CF05F9848EFAA91062BBEB586 – C:\Program Files\WindowsApps\Microsoft.BingTravel_1.7.0.26_x64__8wekyb3d8bbwe\Common\js\services.js
[2013/01/09 21:44:12 | 000,069,359 | —- | M] () MD5=6AA9F10CF05F9848EFAA91062BBEB586 – C:\Program Files\WindowsApps\Microsoft.BingWeather_1.7.0.26_x64__8wekyb3d8bbwe\common\js\services.js
[2013/01/09 21:02:15 | 000,006,271 | —- | M] () MD5=70C3BFEF8C7A6FEF764BB4B737935AC3 – C:\Program Files\WindowsApps\ChaChaSearch.ChaChaPushNotification_1.1.3.0_neutral__62vv7yjt7tgyp\js\services.js
[2013/01/23 19:27:38 | 000,069,359 | —- | M] () MD5=80CE8A6918A7BDB5328F93F4A3BB26B0 – C:\Program Files\WindowsApps\Microsoft.BingSports_1.8.0.51_x64__8wekyb3d8bbwe\common\js\services.js
[2012/07/31 22:27:04 | 000,004,761 | —- | M] () MD5=9D136FCA750DBB05B52AB77A35D536D6 – C:\Program Files\WindowsApps\ChaChaSearch.ChaChaPushNotification_1.0.0.32_neutral__62vv7yjt7tgyp\js\services.js
< MD5 for: SERVICES.LNK >
[2012/07/25 15:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 15:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 15:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_282d8a08cf7f1ada\services.lnk
< MD5 for: SERVICES.MOF >
[2012/06/02 09:35:05 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2012/06/02 09:35:05 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.2.9200.16384_none_282967cc570d3701\services.mof
< MD5 for: SERVICES.MSC >
[2012/07/26 02:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysNative\en-US\services.msc
[2012/06/02 09:31:20 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysNative\services.msc
[2012/07/26 02:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysWOW64\en-US\services.msc
[2012/06/02 09:31:13 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysWOW64\services.msc
[2012/07/26 02:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.2.9200.16384_en-us_fd08be678622fdab\services.msc
[2012/06/02 09:31:20 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_282d8a08cf7f1ada\services.msc
[2012/06/02 09:31:13 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\wow64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_3282345b03dfdcd5\services.msc
[2012/07/26 02:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.2.9200.16384_en-us_a0ea22e3cdc58c75\services.msc
< MD5 for: SERVICES.PTXML >
[2012/07/25 15:30:54 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2012/07/25 15:30:54 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.2.9200.16384_none_282967cc570d3701\Services.ptxml
< MD5 for: SERVICES.SBS >
[2011/03/01 00:00:00 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files (x86)\Spybot - Search & Destroy 2\Includes\Services.sbs
[2011/03/01 02:58:46 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files (x86)\Spybot - Search & Destroy 2\Updates\Extracts\Services.sbs
< MD5 for: SERVICES.SBS-20110301.CAB >
[2013/09/08 12:48:51 | 000,041,248 | —- | M] () MD5=149FF3413EED31253183D6E65E383138 – C:\Program Files (x86)\Spybot - Search & Destroy 2\Updates\Downloads\Services.sbs-20110301.cab
< MD5 for: WINLOGON.ADML >
[2012/07/26 02:49:05 | 000,008,017 | —- | M] () MD5=C270056255498A723E7331EFF1AA162F – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.2.9200.16384_en-us_edcdb8ec66a62fc0\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2012/06/02 09:34:22 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.2.9200.16384_none_d3d704270306719d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2012/09/20 01:33:55 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=1F84B5F8DBDFFD36DF143C61CE25F12A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16420_none_c8c988c15e88a211\winlogon.exe
[2012/09/20 01:33:17 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=6522E98C94A2A81AE11EB66D2AF5743A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20521_none_c95425d677a55b32\winlogon.exe
[2012/07/25 22:08:50 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16384_none_c88ca87b5eb5b1ec\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2012/10/11 00:46:58 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E – C:\Windows\SysNative\winlogon.exe
[2012/10/11 00:46:58 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16433_none_c8c1b9b35e8e0a07\winlogon.exe
[2012/10/11 00:45:27 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=CBFD56B4EC07CB056A6ABD55DD33671F – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20534_none_c94c56c877aac328\winlogon.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Windows\SysWOW64\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2012/07/26 02:48:51 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=B9094B7088CD579E5AED57A693F9BFBD – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2012/07/26 02:48:51 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=B9094B7088CD579E5AED57A693F9BFBD – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.2.9200.16384_en-us_23c238ef8ddaa831\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2012/07/26 02:48:52 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2012/07/26 02:48:52 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.2.9200.16384_en-us_81848abaa91301c6\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2012/07/25 15:30:16 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2012/07/25 15:30:16 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.2.9200.16384_none_d9027134ffac135f\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2013/09/10 20:48:02 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2012/06/02 09:30:55 | 000,000,001 | -HS- | M] () – C:\BOOTNXT
[2013/09/11 07:06:08 | 3068,764,160 | -HS- | M] () – C:\hiberfil.sys
[2013/01/21 17:09:41 | 000,000,040 | —- | M] () – C:\log.txt
[2013/09/11 07:06:09 | 671,088,640 | -HS- | M] () – C:\pagefile.sys
[2013/09/11 07:06:09 | 268,435,456 | -HS- | M] () – C:\swapfile.sys
< %systemroot%\Fonts\*.com >
[2012/08/03 00:14:00 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2012/08/03 00:14:00 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2012/08/03 00:14:00 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2012/08/03 00:14:00 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2012/07/26 03:11:41 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2013/08/30 02:47:40 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2012/07/26 03:11:35 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Acer
Volume Serial Number is EC20-BBE4
Directory of C:\
07/26/2012 02:22 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/26/2012 02:22 AM Application Data [C:\ProgramData]
07/26/2012 02:22 AM Desktop [C:\Users\Public\Desktop]
07/26/2012 02:22 AM Documents [C:\Users\Public\Documents]
07/26/2012 02:22 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/26/2012 02:22 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/26/2012 02:22 AM All Users [C:\ProgramData]
07/26/2012 02:22 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/26/2012 02:22 AM Application Data [C:\ProgramData]
07/26/2012 02:22 AM Desktop [C:\Users\Public\Desktop]
07/26/2012 02:22 AM Documents [C:\Users\Public\Documents]
07/26/2012 02:22 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/26/2012 02:22 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/26/2012 02:22 AM Application Data [C:\Users\Default\AppData\Roaming]
07/26/2012 02:22 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/26/2012 02:22 AM Local Settings [C:\Users\Default\AppData\Local]
07/26/2012 02:22 AM My Documents [C:\Users\Default\Documents]
07/26/2012 02:22 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/26/2012 02:22 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/26/2012 02:22 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/26/2012 02:22 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/26/2012 02:22 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/26/2012 02:22 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/26/2012 02:22 AM Application Data [C:\Users\Default\AppData\Local]
07/26/2012 02:22 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/26/2012 02:22 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/26/2012 02:22 AM My Music [C:\Users\Default\Music]
07/26/2012 02:22 AM My Pictures [C:\Users\Default\Pictures]
07/26/2012 02:22 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/26/2012 02:22 AM My Music [C:\Users\Public\Music]
07/26/2012 02:22 AM My Pictures [C:\Users\Public\Pictures]
07/26/2012 02:22 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Regina
01/08/2013 06:42 PM Application Data [C:\Users\Regina\AppData\Roaming]
01/08/2013 06:42 PM Cookies [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Cookies]
01/08/2013 06:42 PM Local Settings [C:\Users\Regina\AppData\Local]
01/08/2013 06:42 PM My Documents [C:\Users\Regina\Documents]
01/08/2013 06:42 PM NetHood [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/08/2013 06:42 PM PrintHood [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
01/08/2013 06:42 PM Recent [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Recent]
01/08/2013 06:42 PM SendTo [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\SendTo]
01/08/2013 06:42 PM Start Menu [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Start Menu]
01/08/2013 06:42 PM Templates [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Regina\AppData\Local
01/08/2013 06:42 PM Application Data [C:\Users\Regina\AppData\Local]
01/08/2013 06:42 PM History [C:\Users\Regina\AppData\Local\Microsoft\Windows\History]
01/08/2013 06:42 PM Temporary Internet Files [C:\Users\Regina\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Regina\Documents
01/08/2013 06:42 PM My Music [C:\Users\Regina\Music]
01/08/2013 06:42 PM My Pictures [C:\Users\Regina\Pictures]
01/08/2013 06:42 PM My Videos [C:\Users\Regina\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
48 Dir(s) 293,247,643,648 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/02/18 20:05:14 | 000,000,319 | -HS- | M] () – C:\Users\Regina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
OTL Extras logfile created on: 9/11/2013 7:54:16 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Regina\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.57 Gb Total Physical Memory | 2.39 Gb Available Physical Memory | 66.85% Memory free
4.20 Gb Paging File | 2.93 Gb Available in Paging File | 69.75% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 444.19 Gb Total Space | 273.11 Gb Free Space | 61.49% Space Free | Partition Type: NTFS
Computer Name: CARTER | User Name: Regina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D; 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D; 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D; 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D; 2 Background update service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D; 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D; 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D; 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D; 2 Background update service – (Safer-Networking Ltd.)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00929A60-540C-4D0F-893F-8050E6859F7B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{082378E6-9FA0-47C7-8328-3F91166DDE0B}" = rport=138 | protocol=17 | dir=out | app=system |
"{2649ADDC-EB10-4805-8498-ED1A7965EFAD}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{29698EC3-320C-4F26-A764-49BCD72270FF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{29D8DF66-0D28-4B93-81EA-F19A22AF3D36}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |
"{35D7BA01-1022-451D-9F09-CD0D9967BA24}" = lport=10243 | protocol=6 | dir=in | app=system |
"{36FBD585-394C-461B-AD3E-A6FEE174B2FD}" = rport=139 | protocol=6 | dir=out | app=system |
"{3B1427D7-957E-4517-ACB9-48B6484F261F}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{52DA214C-3A7F-48C1-B7D9-01E516A4ED66}" = lport=139 | protocol=6 | dir=in | app=system |
"{53E29F7C-1F5A-4FCD-A812-A05E50E1AE31}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5BBA4783-4C4D-4599-AEBA-0ABC30E3C6EB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{799570D7-7314-43A1-A363-A3DA1E08CDA8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7ADA710A-FCF2-4C2D-820C-C3E5A27A732C}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |
"{7DEF645C-7BE3-41A8-83B9-24547379B544}" = lport=445 | protocol=6 | dir=in | app=system |
"{7E729806-295F-411F-BD22-C2E01CC4BB63}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7FCC2E3F-847A-495F-8E34-A21817816A5E}" = lport=137 | protocol=17 | dir=in | app=system |
"{827E3C62-D14A-4AAA-9307-BC154157DA53}" = lport=2869 | protocol=6 | dir=in | app=system |
"{84B53E96-CF58-45D5-A27B-B1809F628D3B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{862B86DD-FA75-4AFF-A8D7-BA5C5B8FB91C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8A5C3610-A60E-47D9-9DD0-71AF980444C8}" = rport=137 | protocol=17 | dir=out | app=system |
"{AF6652CF-F6D2-4B14-A4C6-8B66A33B7089}" = rport=445 | protocol=6 | dir=out | app=system |
"{C512ED72-D254-4002-8C5E-B65B27E224EA}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |
"{E5B69F96-62C8-40F5-9839-6067470F8A7B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FC514E29-9B87-4B05-8DCE-9DE56C490F7B}" = lport=138 | protocol=17 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01FE2170-27E2-48B6-B1BD-0D917321F551}" = dir=out | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{028091E3-F294-4980-A98C-43621C690494}" = dir=in | app=c:\program files (x86)\nti\acer backup manager\ischedulesvc.exe |
"{063FB4AA-5975-4194-A2A2-FA8786540DC2}" = dir=out | name=word search |
"{0825F47A-A01F-4682-A339-D9B4785F0C8B}" = dir=out | name=ebay |
"{0B41E1AC-B176-44CB-8EBA-56EA67D71430}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe |
"{110DBBD2-13B9-4F2D-A240-DA367661BEB5}" = dir=in | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{12220FA2-64FD-4F5B-944C-A3D926A531F6}" = dir=in | name=skype |
"{1361992B-DAB4-4AEC-AB66-B907822F5742}" = dir=out | name=@{microsoft.bingnews_1.7.0.38_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{143163B5-94D9-4C0A-89C0-2310EDD3B4AD}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{1A839730-329C-466B-AB3F-2D7B28C84A6B}" = dir=out | name=drag race online |
"{1FAFC1F6-9A9E-467A-B32E-BFF50EDF9EB1}" = dir=in | name=drivehq filemanager |
"{22397173-91A6-4D2F-8FAE-142C974F6EB8}" = dir=out | name=stumbleupon |
"{22F47221-98CE-4D42-8115-FF4FF4D795CA}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe |
"{239577D0-E7B4-4A50-BEEA-A7603F8305EA}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{23BF3870-D9DA-4F2B-AC57-13BF2BAED664}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{255F5B22-8D78-4D93-B411-C2B905728468}" = dir=out | name=netflix |
"{27AF884A-9D42-4159-8981-033569C0A0F4}" = dir=in | app=c:\program files (x86)\samsung\allshare\allshareagent.exe |
"{28A42902-A8E9-4904-8A05-606CB2946558}" = dir=out | name=social jogger |
"{29242695-A779-4C70-BBF0-8BDE516545FF}" = dir=out | name=shark dash |
"{2BA19AEA-EEF9-49DE-A15F-557B32A288EB}" = dir=out | name=piano8 |
"{2BFB88B2-58B9-4191-BEF0-6572CED5669D}" = dir=in | app=c:\program files (x86)\nti\acer backup manager\backupmanager.exe |
"{2D94F3F8-6FDC-4E5C-9356-703272F0ABF5}" = dir=out | name=deal or no deal+ |
"{3A7690D6-CB12-46A7-AEFF-61EB6E423183}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\video\videoplayer.exe |
"{3AD2D436-1B9A-4333-A692-A1F570677540}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe |
"{3B6E4396-8001-497C-9944-4E2DA505A775}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3D39256B-9D5A-484E-B0FB-B03235A6EC7A}" = dir=in | name=ebay |
"{41A68EBE-C91E-4BEB-A4A0-8BAC979978BA}" = dir=out | name=chacha |
"{421D1E91-FCB1-4E61-BD82-44AFBFD12638}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{4370A49C-F8EF-4C66-8C7C-FD47C9BFACAD}" = dir=in | app=c:\program files (x86)\nti\acer backup manager\fileexplorer.exe |
"{45CA8BF8-74FC-4829-878C-4D8999A5A001}" = dir=out | name=dog sounds |
"{4765DEF9-ADC3-46CA-9C3D-2D095E6C5144}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{483C0C00-75B4-486D-A2A6-04F3A4F0D58C}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4DC69ED9-489F-49CC-9CAA-5D6DE18566EF}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} |
"{4E6B9D69-053E-4E87-BCE8-28D2F16C5962}" = protocol=6 | dir=in | app=c:\programdata\kodak\installer\setup.exe |
"{56ACC02B-2B24-4604-9432-61BD3B4C0B1F}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe |
"{58F0606E-8B82-4F93-8104-FD1705BB01FB}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe |
"{59ACD79A-8FE0-4BB9-A7D8-CC4A079FB31C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5B3A091C-6F7B-4374-BFF7-76BBDB6FB3E1}" = protocol=17 | dir=in | app=c:\programdata\kodak\installer\setup.exe |
"{5B54CB76-EB22-4040-ACBB-6CD95C494B94}" = dir=out | name=encyclopaedia britannica |
"{5EB662BD-B55D-4846-B3E5-25208D86E111}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5FF6B2D4-A961-47AB-9661-7268B7F42170}" = dir=out | name=fresh paint |
"{5FFDFE27-B877-4F59-8CE6-30BB8904F207}" = dir=out | name=@{microsoft.xboxlivegames_1.2.143.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{6149CB6D-3700-4372-A6B9-E905108A4484}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{61D0B53A-6D13-4556-B98D-1382D1B1B982}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe |
"{63BC5F3F-6D38-438C-9927-3AFE585664F7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6480C03A-CAD1-46CC-B679-4D59B8FB3E93}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6529267A-A9C0-4843-8CE3-8D13E18E5251}" = dir=out | name=acer crystal eye |
"{688C0821-D67C-4C65-9B06-4C045A5F6A08}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{69EE3068-FFB8-4EA8-AFB1-48D87B1E7130}" = dir=out | name=windows_ie_ac_001 |
"{6A2696D4-CC45-4788-938F-435B3420402C}" = dir=out | name=family guy soundboard |
"{6B2863F9-5CB2-4A58-AC04-015D9D515510}" = protocol=6 | dir=out | app=system |
"{6BF39DE6-8DFE-4B3A-B99D-6B8F50C1675C}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\acer cloud\ccd.exe |
"{6CA5294F-D314-48BC-BE79-1B2D8AB94E42}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6D2D0B06-A70C-4AB6-840A-64B3BC481942}" = dir=out | name=@{microsoft.bingweather_1.7.0.26_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{6E554D2D-E946-461A-9FAA-A172AD335C66}" = dir=out | name=kindle |
"{7021E4FB-DFC3-400A-BA7F-D706D2DDAC50}" = dir=out | name=@{7289elapietro.paint4kids_2.8.1.139_neutral__69wh28dtbwp4w?ms-resource://7289elapietro.paint4kids/resources/appname} |
"{704A3DA1-E90B-4AD8-8EFE-399E9A1C603F}" = dir=out | name=evernote touch |
"{71315664-804C-49B6-986E-BAB15C25B38B}" = dir=out | name=angry birds space |
"{717C54AF-BA54-4D53-9AA0-8F206C530423}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{79A88146-F858-4013-88FD-9D494DC47418}" = dir=out | name=@{microsoft.bing_1.5.1.259_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{847F8450-6DD6-4ECF-B1A5-C9A703DDBA66}" = dir=out | name=special force anti-terrorism |
"{8685FA38-568A-4B42-A49E-51ACF67FE0B0}" = dir=out | name=@{microsoft.bingfinance_1.7.0.38_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{8864B097-D523-4456-BB94-3AD19CC38B63}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{917B1786-4EB6-4AA7-921E-98897FF9D6B4}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{95C5EF66-31EE-4004-93E6-B1DCE00A0FCF}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe |
"{978E988B-3934-4D4A-AAF5-F099EAD0B6A8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9A6508D3-FDB1-49B5-804B-827BD344D1AF}" = dir=out | name=the treasures of montezuma 3 |
"{9C8A6BFE-92DA-4FCC-BBE5-E1548839B027}" = dir=out | name=@{microsoft.bingsports_1.8.0.51_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{A0CDB13C-78F8-46A0-8C40-594110E7DFC5}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A15546F0-1B45-4B61-87AB-C284D8CBEBB1}" = dir=out | name=drivehq filemanager |
"{A40FAF15-DCCC-46DC-B350-CE3D52400AF5}" = dir=out | name=acer explorer |
"{ADE4A962-DC55-4118-842A-498A466F211C}" = dir=in | name=newsxpresso |
"{B085D162-875C-4177-8976-7857957F2D98}" = dir=out | name=real cat sounds |
"{B9045028-8375-4B6A-A9D0-50B6E5AFC911}" = dir=out | name=skitch touch |
"{B93617FC-7C77-4A76-B7BB-7754952201FE}" = dir=out | name=@{microsoft.bingmaps_1.5.1.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{B973C7D2-2D3A-4646-8440-EF47DD6F7B9F}" = dir=out | name=amazon |
"{BAB46863-F665-40A1-B38F-759B4080804A}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{BC334CBF-B088-4C76-9478-DBB921BA094E}" = dir=out | name=@{microsoft.zunevideo_1.2.150.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} |
"{BE8E4AFE-0C8D-4B16-B4C5-A5131B723725}" = dir=out | name=@{microsoft.zunemusic_1.2.150.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} |
"{C29FC607-640F-4CE6-8ADC-24F031754B03}" = dir=out | name=skype |
"{C321BDF4-A70B-48CC-9AC2-1EBD8FE42CFC}" = dir=out | name=kick the can |
"{C4C597E5-F7A5-43A6-BDA9-75C1CA8062D9}" = dir=out | name=taptiles |
"{C5B09ABC-45D4-4499-B909-07D3BA3DFF35}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\acer cloud\ccd.exe |
"{C8C8A043-B6BA-48F0-9610-F99113F62953}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{C8FAB5D6-AC89-4F01-8539-DD4817B53E74}" = dir=in | app=c:\program files (x86)\samsung\allshare\allshare.exe |
"{CAAC6B64-1BB6-478B-966E-B8451A1C00A1}" = dir=out | name=tomb hunter |
"{CBD272D6-CB0F-4B1B-8853-9B973B1A0E09}" = dir=in | app=c:\program files (x86)\samsung\allshare\allsharedms\allsharedms.exe |
"{D0BDEF29-9BD1-483F-A86F-48BDB8C1F141}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{D39EDE1F-DA37-4CE4-9DC7-EF8ED91E4D69}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D56012D6-2AA5-4D7D-8A3C-ABD2C33B3AF2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D59A2EDF-A3FD-41A0-A700-AD1739FB3DD7}" = dir=out | name=newsxpresso |
"{D5F3B473-014A-4D8B-BC69-6B73B4570B8A}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{D6DDD32E-CCE5-4031-9C8A-0F44947C1C7D}" = dir=out | name=7digital music store |
"{D77EF8B8-2C3C-4A65-A0A0-26C41BAB3ACA}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{DD2B056D-08D3-462A-8016-6FAC87771E7B}" = dir=in | name=acer explorer |
"{E128FC6F-2990-4BEB-AF0E-1521D0D4C346}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{E2FDA25A-5C0B-40C2-BE88-933D8B452ECD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E5049241-1C0B-4090-AB8B-D73B5BCE17AD}" = dir=in | name=evernote touch |
"{E606C57B-70F6-4723-99FE-D5C1A0DD4836}" = dir=out | name=@{microsoft.bingtravel_1.7.0.26_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{E7F9229F-BC69-4916-A021-D4591209BD77}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe |
"{FD5899D2-A56D-404E-946C-DB21CF24B8BB}" = dir=out | name=icookbook se |
"TCP Query User{F55858F7-A60F-4497-8232-646BE5B41187}C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe" = protocol=6 | dir=in | app=c:\program files (x86)\spybot - search & destroy 2\sdupdate.exe |
"UDP Query User{3D7780EF-AB64-4235-889B-039BD7FE3322}C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe" = protocol=17 | dir=in | app=c:\program files (x86)\spybot - search & destroy 2\sdupdate.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}" = Acer Recovery Management
"{0B78ECB0-1A6B-4E6D-89D7-0E7CE77F0427}" = MyWinLocker
"{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder
"{237D687E-9E50-4A30-B810-262764CC491B}" = Garmin Communicator Plugin x64
"{2F1EB597-74DA-2C71-C065-BF4C6B89062C}" = AMD Accelerated Video Transcoding
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{3F62D2FD-13C1-49A2-8B5D-47623D9460D7}" = Acer Device Fast-lane
"{427174C0-096E-40D9-9684-9C109BEE2CBF}" = iTunes
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7BABDF85-566A-FCC6-E6FE-12DCFF3F9FEB}" = AMD Catalyst Install Manager
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{91F52DE4-B789-42B0-9311-A349F10E5479}" = Acer Power Management
"{CE02F046-9083-701A-0996-96190306DD5E}" = ccc-utility64
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64
"CCleaner" = CCleaner
"Elantech" = ETDWare PS/2-X64 11.6.11.002_WHQL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0CB90E9C-E1C9-4A83-04D3-BF7A6CB9C376}" = CCC Help Japanese
"{0CCE1791-4AD2-0202-2FE9-308D47482C46}" = CCC Help Spanish
"{0F4A9F62-336C-A3DB-3DCB-5E35CCF908D3}" = CCC Help Finnish
"{136F0577-FF5A-3978-4535-3F8034697982}" = AMD VISION Engine Control Center
"{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FCC073B-CC01-4443-AD20-E559F66E6E83}" = Office Addin 2003
"{234378F3-28CC-9038-8732-DE44FCD53384}" = CCC Help German
"{25347987-6E58-A41F-19D8-D55EACF69DAF}" = CCC Help French
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{32DD0880-9000-988D-28FA-CBEC75ADE655}" = CCC Help Swedish
"{33FA327B-E7E2-4E38-BF1A-67DCE285BD5C}" = Catalyst Control Center - Branding
"{35DA427D-BB23-49B8-9AFD-CFFCFE3B708D}" = clear.fi SDK- Movie 2
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{39F15B50-A977-4CA6-B1C3-6A8724CDA025}" = MyWinLocker 4
"{3D9CB654-99AD-4301-89C6-0D12A790767C}" = Identity Card
"{3EADFC9D-5747-1F40-B2C9-35EDB21C3B7A}" = CCC Help Portuguese
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4993BB61-D98D-8AC1-3F15-1DF54E51192C}" = CCC Help Danish
"{4B79E2D3-C5CF-3A41-929E-4FD8D90EE1C3}" = CCC Help Korean
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{647BB978-2876-487B-9B0E-FDB73F0EA4A2}" = Garmin Communicator Plugin
"{65135558-F1AE-4B9B-8C0B-180730ACA261}" = Garmin Express
"{679F4771-F0E8-BB49-1CB7-6FEEA109DE6A}" = CCC Help Thai
"{698B2C9E-A1B6-37F7-C1E1-EEE252ADC1D0}" = CCC Help Czech
"{6D2BBE1D-E600-4695-BA37-0B0E605542CC}" = Office Addin
"{6EC7E0E1-5BCA-A74E-CA99-79E765BB271E}" = Catalyst Control Center Localization All
"{700EC2DC-84AC-1C3E-0106-CB11B5B4F7D3}" = CCC Help Dutch
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer" = WildTangent Games App
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames" = WildTangent Games App
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74D10916-2A98-A824-3CA2-9668D64A0231}" = CCC Help Greek
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{876AB032-B2A4-41FF-AF87-DBC78454C1B0}" = Garmin Update Service
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{9100F286-8053-6382-2DF1-8F50F9E17597}" = CCC Help Italian
"{93765DFA-8A67-41FB-9FC0-B12341CA65F3}" = Elevated Installer
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B46C84F-4985-42F7-9AFC-437B53C84397}" = Bad Piggies
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D3D8C60-A55F-4123-B2B9-173F09590E16}" = REALTEK Wireless LAN Driver
"{9DDDF20E-9FD1-4434-A43E-E7889DBC9420}" = Backup Manager v4
"{A0E1F04B-9B85-5EEB-86C4-435567588EC3}" = CCC Help Norwegian
"{A3DD31D0-9B99-7222-B038-7D7EF43ED72C}" = Catalyst Control Center InstallProxy
"{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}" = AcerCloud
"{A6ACFAF3-71E6-88DC-083B-C21F15D2C334}" = CCC Help Russian
"{A81456C9-8CAA-4424-BB9D-E330FDDA717E}" = Samsung Simple Upgrade Tool for SCH-I500 EH09
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B58AC487-F6E9-336E-204C-DD48F0057CDD}" = CCC Help English
"{B5AD89F2-03D3-4206-8487-018298007DD0}" = clear.fi Photo
"{B860F5DA-9908-FF57-005C-3BBABDB60E7A}" = CCC Help Chinese Standard
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C233BCC3-29C4-49C0-B955-0A94509FC4FC}" = Garmin Express Tray
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}" = AcerCloud Docs
"{D0F2B581-5AE4-70B3-95D0-E761BC89E686}" = CCC Help Hungarian
"{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"{D3EAAC35-98A9-8231-2648-0C3BB84606A6}" = CCC Help Polish
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DF47ACA3-7C78-4C08-8007-AC682563C9F1}" = Samsung AllShare
"{e47a5c85-88a2-47d2-b380-fc2e763c2e6d}" = Garmin Express
"{E99A5F3B-50D0-F66F-6FDB-C0DC1B90973E}" = CCC Help Turkish
"{E9AF1707-3F3A-49E2-8345-4F2D629D0876}" = clear.fi Media
"{EB8920E9-5534-2E03-BE4B-B050C9736676}" = Catalyst Control Center Graphics Previews Common
"{EBA33CAD-E071-48d5-A168-FBA4EEB42E93}" = clear.fi SDK - Video 2
"{EE26E302-876A-48D9-9058-3129E5B99999}" = Live Updater
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2F8656A-BDEC-0852-D9FB-8088B9357EA5}" = CCC Help Chinese Traditional
"avast" = avast! Free Antivirus
"InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"InstallShield_{9DDDF20E-9FD1-4434-A43E-E7889DBC9420}" = Acer Backup Manager
"InstallShield_{A81456C9-8CAA-4424-BB9D-E330FDDA717E}" = Samsung Simple Upgrade Tool for SCH-I500 EH09
"InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"InstallShield_{DF47ACA3-7C78-4C08-8007-AC682563C9F1}" = Samsung AllShare
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"WildTangent wildgames Master Uninstall" = WildTangent Games
"WTA-060ae6b0-2d42-4a1a-b236-a73fe2e491a7" = Penguins!
"WTA-2d7fdb82-c38c-4ed9-8547-860ca22c3a1a" = Peggle Nights
"WTA-3ff7da3a-cdba-4ca5-847b-dcd3f24cf195" = Jewel Match 3
"WTA-6437089d-43db-4138-bad3-ca1751586a6d" = Tales of Lagoona
"WTA-7f763398-b50e-4ceb-a417-410d9597e147" = Polar Bowler
"WTA-80fff23a-de75-4b51-890f-51f2c5ea205c" = Cradle Of Egypt Collector's Edition
"WTA-81dbd76b-3727-48ab-8245-53fb940f2d30" = Zuma's Revenge
"WTA-8937668d-53e7-420f-884c-ac073c964511" = Agatha Christie - Death on the Nile
"WTA-d5ab2698-2035-4194-9fb9-85ec8094147d" = Final Drive: Nitro
"WTA-dff0051a-5cfe-4847-8156-8d2c7928a4ec" = Polar Golfer
"WTA-e620d2e6-d682-4882-b2bb-1e07b73a3f65" = Mystery P.I. - Curious Case of Counterfeit Cove
"WTA-eaa449b7-f52f-4a15-bf27-0f433d595ae2" = Aloha TriPeaks
"WTA-f6862d50-5000-48f8-a1fb-596e5a337cc0" = Bejeweled 3
"WTA-f86d7cc9-c6c7-4381-bd4c-4eefa715957a" = Plants vs. Zombies - Game of the Year
"WTA-f9cc76d0-83bf-466e-a0fa-6d53946c6712" = Dora's World Adventure
"WTA-fd48042d-469e-47f6-9498-0b7e56e3d235" = Delicious: Emily's True Love Premium Edition
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 9/8/2013 3:19:49 PM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\PowerPointAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.Manifest" on line 4.
The
element asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
Error - 9/8/2013 3:21:20 PM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\ExcelAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\ExcelAddIn2003.dll.Manifest" on line 4. The element
asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
Error - 9/8/2013 3:21:20 PM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\WordAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\WordAddIn2003.dll.Manifest" on line 4. The element
asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
Error - 9/8/2013 3:21:20 PM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\PowerPointAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.Manifest" on line 4.
The
element asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
Error - 9/8/2013 3:33:01 PM | Computer Name = Carter | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image
of service Datamngr Coordinator since QueryServiceConfig API failed System Error:
The
system cannot find the file specified. .
Error - 9/8/2013 3:33:47 PM | Computer Name = Carter | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image
of service Datamngr Coordinator since QueryServiceConfig API failed System Error:
The
system cannot find the file specified. .
Error - 9/8/2013 8:26:30 PM | Computer Name = Carter | Source = Application Error | ID = 1000
Description = Faulting application name: DllHost.exe, version: 6.2.9200.16384, time
stamp: 0x50108850 Faulting module name: ntdll.dll, version: 6.2.9200.16579, time
stamp: 0x51637f77 Exception code: 0xc0000005 Fault offset: 0x000000000006daa4 Faulting
process id: 0x840 Faulting application start time: 0x01ceacf33991bab9 Faulting application
path: C:\Windows\system32\DllHost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: 7854c8e7-18e6-11e3-bede-b888e35b0690 Faulting package full name: Faulting package-relative
application ID:
Error - 9/9/2013 4:01:11 AM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\ExcelAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\ExcelAddIn2003.dll.Manifest" on line 4. The element
asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
Error - 9/9/2013 4:01:11 AM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\WordAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\WordAddIn2003.dll.Manifest" on line 4. The element
asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
Error - 9/9/2013 4:01:11 AM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\PowerPointAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.Manifest" on line 4.
The
element asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
[ Spybot - Search and Destroy Events ]
Error - 9/8/2013 3:32:46 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 3:33:31 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 3:34:26 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 3:34:31 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 3:35:08 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 3:35:17 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 3:36:07 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 5:00:27 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 5:01:55 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 9:22:42 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
[ System Events ]
Error - 9/10/2013 4:49:35 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:49:35 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:50:42 PM | Computer Name = Carter | Source = DCOM | ID = 10005
Description =
Error - 9/10/2013 4:51:44 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:51:44 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:51:44 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:52:35 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:52:35 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:52:35 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:54:42 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
< End of report >
OTL logfile created on: 9/11/2013 7:54:16 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Regina\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.57 Gb Total Physical Memory | 2.39 Gb Available Physical Memory | 66.85% Memory free
4.20 Gb Paging File | 2.93 Gb Available in Paging File | 69.75% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 444.19 Gb Total Space | 273.11 Gb Free Space | 61.49% Space Free | Partition Type: NTFS
Computer Name: CARTER | User Name: Regina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ==========
PRC - C:\Users\Regina\Downloads\OTL.exe (OldTimer Tools)
PRC - C:\Program Files\AVAST Software\Avast\AvastUI.exe (AVAST Software)
PRC - C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Spybot - Search & Destroy 2\SDWSCSvc.exe (Safer-Networking Ltd.)
PRC - C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Garmin Ltd or its subsidiaries)
PRC - C:\Program Files (x86)\Launch Manager\LMutilps32.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\LManager.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
PRC - C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (Acer Incorporated)
PRC - C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe (Samsung Electronics Co., Ltd.)
========== Modules (No Company Name) ==========
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlFileFormats150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\snlThirdParty150.bpl ()
MOD - C:\Program Files (x86)\Spybot - Search & Destroy 2\DEC150.bpl ()
========== Services (SafeList) ==========
SRV:64bit: - (avast! Antivirus) – C:\Program Files\AVAST Software\Avast\AvastSvc.exe (AVAST Software)
SRV:64bit: - (WinDefend) – C:\Program Files\Windows Defender\MsMpEng.exe (Microsoft Corporation)
SRV:64bit: - (DsmSvc) – C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
SRV:64bit: - (netprofm) – C:\Windows\SysNative\netprofmsvc.dll (Microsoft Corporation)
SRV:64bit: - (BrokerInfrastructure) – C:\Windows\SysNative\bisrv.dll (Microsoft Corporation)
SRV:64bit: - (AudioEndpointBuilder) – C:\Windows\SysNative\AudioEndpointBuilder.dll (Microsoft Corporation)
SRV:64bit: - (TimeBroker) – C:\Windows\SysNative\TimeBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (SystemEventsBroker) – C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) – C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (ETDService) – C:\Program Files\Elantech\ETDService.exe (ELAN Microelectronics Corp.)
SRV:64bit: - (wlidsvc) – C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
SRV:64bit: - (LSM) – C:\Windows\SysNative\lsm.dll (Microsoft Corporation)
SRV:64bit: - (PrintNotify) – C:\Windows\SysNative\spool\drivers\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV:64bit: - (WSService) – C:\Windows\SysNative\WSService.dll (Microsoft Corporation)
SRV:64bit: - (fhsvc) – C:\Windows\SysNative\fhsvc.dll (Microsoft Corporation)
SRV:64bit: - (ePowerSvc) – C:\Program Files\Acer\Acer Power Management\ePowerSvc.exe (Acer Incorporated)
SRV:64bit: - (DeviceFastLaneService) – C:\Program Files\Acer\Acer Device Fast-lane\DeviceFastLaneSvc.exe (Acer Incorporated)
SRV:64bit: - (WiaRpc) – C:\Windows\SysNative\wiarpc.dll (Microsoft Corporation)
SRV:64bit: - (Wcmsvc) – C:\Windows\SysNative\wcmsvc.dll (Microsoft Corporation)
SRV:64bit: - (VaultSvc) – C:\Windows\SysNative\vaultsvc.dll (Microsoft Corporation)
SRV:64bit: - (svsvc) – C:\Windows\SysNative\svsvc.dll (Microsoft Corporation)
SRV:64bit: - (Netlogon) – C:\Windows\SysNative\netlogon.dll (Microsoft Corporation)
SRV:64bit: - (NcaSvc) – C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
SRV:64bit: - (NcdAutoSetup) – C:\Windows\SysNative\NcdAutoSetup.dll (Microsoft Corporation)
SRV:64bit: - (KeyIso) – C:\Windows\SysNative\keyiso.dll (Microsoft Corporation)
SRV:64bit: - (EFS) – C:\Windows\SysNative\efssvc.dll (Microsoft Corporation)
SRV:64bit: - (DeviceAssociationService) – C:\Windows\SysNative\das.dll (Microsoft Corporation)
SRV:64bit: - (AllUserInstallAgent) – C:\Windows\SysNative\AUInstallAgent.dll (Microsoft Corporation)
SRV:64bit: - (vmicvss) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmictimesync) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicshutdown) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicrdv) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmickvpexchange) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV:64bit: - (vmicheartbeat) – C:\Windows\SysNative\icsvc.dll (Microsoft Corporation)
SRV - (Spooler) – C:\Windows\SysWOW64\spoolsv.exe ()
SRV - (SamSs) – C:\Windows\SysWOW64\lsass.exe ()
SRV - (AMD External Events Utility) – C:\Windows\SysWOW64\atiesrxx.exe ()
SRV - (Garmin Core Update Service) – C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe (Garmin Ltd or its subsidiaries)
SRV - (PrintNotify) – C:\Windows\system32\spool\DRIVERS\x64\3\PrintConfig.dll (Microsoft Corporation)
SRV - (FLEXnet Licensing Service) – C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (RfButtonDriverService) – C:\Windows\RfBtnSvc64.exe (Dritek System INC.)
SRV - (DsiWMIService) – C:\Program Files (x86)\Launch Manager\dsiwmis.exe (Dritek System Inc.)
SRV - (NTI IScheduleSvc) – C:\Program Files (x86)\NTI\Acer Backup Manager\IScheduleSvc.exe (NTI Corporation)
SRV - (CCDMonitorService) – C:\Program Files (x86)\Acer\Acer Cloud\CCDMonitorService.exe (Acer Incorporated)
SRV - (StorSvc) – C:\Windows\SysWOW64\StorSvc.dll (Microsoft Corporation)
SRV - (IconMan_R) – C:\Program Files (x86)\Realtek\Realtek PCIE Card Reader\RIconMan.exe (Realsil Microelectronics Inc.)
SRV - (EgisTec Ticket Service) – C:\Program Files (x86)\Common Files\EgisTec\Services\EgisTicketService.exe (Egis Technology Inc. )
SRV - (SamsungAllShareV2.0) – C:\Program Files (x86)\Samsung\AllShare\AllShareDMS\AllShareDMS.exe (Samsung Electronics Co., Ltd.)
SRV - (SimpleSlideShowServer) – C:\Program Files (x86)\Samsung\AllShare\AllShareSlideShowService.exe (Samsung Electronics Co., Ltd.)
SRV - (GamesAppService) – C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
========== Driver Services (SafeList) ==========
DRV:64bit: - (aswSnx) – C:\Windows\SysNative\drivers\aswSnx.sys (AVAST Software)
DRV:64bit: - (aswSP) – C:\Windows\SysNative\drivers\aswSP.sys (AVAST Software)
DRV:64bit: - (aswVmm) – C:\Windows\SysNative\drivers\aswVmm.sys ()
DRV:64bit: - (aswRdr) – C:\Windows\SysNative\Drivers\aswRdr2.sys (AVAST Software)
DRV:64bit: - (aswRvrt) – C:\Windows\SysNative\drivers\aswRvrt.sys ()
DRV:64bit: - (aswTdi) – C:\Windows\SysNative\drivers\aswTdi.sys (AVAST Software)
DRV:64bit: - (aswMonFlt) – C:\Windows\SysNative\Drivers\aswMonFlt.sys (AVAST Software)
DRV:64bit: - (aswFsBlk) – C:\Windows\SysNative\drivers\aswFsBlk.sys (AVAST Software)
DRV:64bit: - (WdBoot) – C:\Windows\SysNative\Drivers\WdBoot.sys (Microsoft Corporation)
DRV:64bit: - (WdFilter) – C:\Windows\SysNative\Drivers\WdFilter.sys (Microsoft Corporation)
DRV:64bit: - (sdbus) – C:\Windows\SysNative\Drivers\sdbus.sys (Microsoft Corporation)
DRV:64bit: - (USBXHCI) – C:\Windows\SysNative\Drivers\USBXHCI.SYS (Microsoft Corporation)
DRV:64bit: - (UCX01000) – C:\Windows\SysNative\Drivers\UCX01000.SYS (Microsoft Corporation)
DRV:64bit: - (BthAvrcpTg) – C:\Windows\SysNative\Drivers\BthAvrcpTg.sys (Microsoft Corporation)
DRV:64bit: - (USBHUB3) – C:\Windows\SysNative\Drivers\USBHUB3.SYS (Microsoft Corporation)
DRV:64bit: - (spaceport) – C:\Windows\SysNative\Drivers\spaceport.sys (Microsoft Corporation)
DRV:64bit: - (dc3d) – C:\Windows\SysNative\Drivers\dc3d.sys (Microsoft Corporation)
DRV:64bit: - (storahci) – C:\Windows\SysNative\Drivers\storahci.sys (Microsoft Corporation)
DRV:64bit: - (TPM) – C:\Windows\SysNative\Drivers\tpm.sys (Microsoft Corporation)
DRV:64bit: - (pdc) – C:\Windows\SysNative\Drivers\pdc.sys (Microsoft Corporation)
DRV:64bit: - (amdkmdag) – C:\Windows\SysNative\Drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdap) – C:\Windows\SysNative\Drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (ETD) – C:\Windows\SysNative\Drivers\ETD.sys (ELAN Microelectronics Corp.)
DRV:64bit: - (msgpiowin32) – C:\Windows\SysNative\Drivers\msgpiowin32.sys (Microsoft Corporation)
DRV:64bit: - (USBAAPL64) – C:\Windows\SysNative\Drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (bthhfhid) – C:\Windows\SysNative\Drivers\BthhfHid.sys (Microsoft Corporation)
DRV:64bit: - (hidi2c) – C:\Windows\SysNative\Drivers\hidi2c.sys (Microsoft Corporation)
DRV:64bit: - (FxPPM) – C:\Windows\SysNative\Drivers\fxppm.sys (Microsoft Corporation)
DRV:64bit: - (RdpVideoMiniport) – C:\Windows\SysNative\Drivers\rdpvideominiport.sys (Microsoft Corporation)
DRV:64bit: - (sdstor) – C:\Windows\SysNative\Drivers\sdstor.sys (Microsoft Corporation)
DRV:64bit: - (dam) – C:\Windows\SysNative\Drivers\dam.sys (Microsoft Corporation)
DRV:64bit: - (WSDScan) – C:\Windows\SysNative\Drivers\WSDScan.sys (Microsoft Corporation)
DRV:64bit: - (StillCam) – C:\Windows\SysNative\Drivers\serscan.sys (Microsoft Corporation)
DRV:64bit: - (GPIOClx0101) – C:\Windows\SysNative\Drivers\msgpioclx.sys (Microsoft Corporation)
DRV:64bit: - (ebdrv) – C:\Windows\SysNative\Drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) – C:\Windows\SysNative\Drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (Ps2Kb2Hid) – C:\Windows\SysNative\Drivers\aPs2Kb2Hid.sys (Dritek System Inc.)
DRV:64bit: - (GEARAspiWDM) – C:\Windows\SysNative\Drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (mwlPSDVDisk) – C:\Windows\SysNative\Drivers\mwlPSDVDisk.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDFilter) – C:\Windows\SysNative\Drivers\mwlPSDFilter.sys (Egis Technology Inc.)
DRV:64bit: - (mwlPSDNServ) – C:\Windows\SysNative\Drivers\mwlPSDNserv.sys (Egis Technology Inc.)
DRV:64bit: - (Fs_Rec) – C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (condrv) – C:\Windows\SysNative\Drivers\condrv.sys (Microsoft Corporation)
DRV:64bit: - (VSTXRAID) – C:\Windows\SysNative\Drivers\VSTXRAID.SYS (VIA Corporation)
DRV:64bit: - (VerifierExt) – C:\Windows\SysNative\Drivers\VerifierExt.sys (Microsoft Corporation)
DRV:64bit: - (UASPStor) – C:\Windows\SysNative\Drivers\uaspstor.sys (Microsoft Corporation)
DRV:64bit: - (acpiex) – C:\Windows\SysNative\Drivers\acpiex.sys (Microsoft Corporation)
DRV:64bit: - (mvumis) – C:\Windows\SysNative\Drivers\mvumis.sys (Marvell Semiconductor, Inc.)
DRV:64bit: - (stexstor) – C:\Windows\SysNative\Drivers\stexstor.sys (Promise Technology, Inc.)
DRV:64bit: - (LSI_SAS2) – C:\Windows\SysNative\Drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (LSI_SSS) – C:\Windows\SysNative\Drivers\lsi_sss.sys (LSI Corporation)
DRV:64bit: - (HpSAMD) – C:\Windows\SysNative\Drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (EhStorTcgDrv) – C:\Windows\SysNative\Drivers\EhStorTcgDrv.sys (Microsoft Corporation)
DRV:64bit: - (EhStorClass) – C:\Windows\SysNative\Drivers\EhStorClass.sys (Microsoft Corporation)
DRV:64bit: - (amdsbs) – C:\Windows\SysNative\Drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (3ware) – C:\Windows\SysNative\Drivers\3ware.sys (LSI)
DRV:64bit: - (amdsata) – C:\Windows\SysNative\Drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) – C:\Windows\SysNative\Drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (CLFS) – C:\Windows\SysNative\Drivers\clfs.sys (Microsoft Corporation)
DRV:64bit: - (WFPLWFS) – C:\Windows\SysNative\Drivers\wfplwfs.sys (Microsoft Corporation)
DRV:64bit: - (vpci) – C:\Windows\SysNative\Drivers\vpci.sys (Microsoft Corporation)
DRV:64bit: - (terminpt) – C:\Windows\SysNative\Drivers\terminpt.sys (Microsoft Corporation)
DRV:64bit: - (WSDPrintDevice) – C:\Windows\SysNative\Drivers\WSDPrint.sys (Microsoft Corporation)
DRV:64bit: - (mshidumdf) – C:\Windows\SysNative\Drivers\mshidumdf.sys (Microsoft Corporation)
DRV:64bit: - (BasicDisplay) – C:\Windows\SysNative\Drivers\BasicDisplay.sys (Microsoft Corporation)
DRV:64bit: - (HyperVideo) – C:\Windows\SysNative\Drivers\HyperVideo.sys (Microsoft Corporation)
DRV:64bit: - (BasicRender) – C:\Windows\SysNative\Drivers\BasicRender.sys (Microsoft Corporation)
DRV:64bit: - (gencounter) – C:\Windows\SysNative\Drivers\vmgencounter.sys (Microsoft Corporation)
DRV:64bit: - (kdnic) – C:\Windows\SysNative\Drivers\kdnic.sys (Microsoft Corporation)
DRV:64bit: - (acpitime) – C:\Windows\SysNative\Drivers\acpitime.sys (Microsoft Corporation)
DRV:64bit: - (npsvctrig) – C:\Windows\SysNative\Drivers\npsvctrig.sys (Microsoft Corporation)
DRV:64bit: - (WpdUpFltr) – C:\Windows\SysNative\Drivers\WpdUpFltr.sys (Microsoft Corporation)
DRV:64bit: - (acpipagr) – C:\Windows\SysNative\Drivers\acpipagr.sys (Microsoft Corporation)
DRV:64bit: - (hyperkbd) – C:\Windows\SysNative\Drivers\hyperkbd.sys (Microsoft Corporation)
DRV:64bit: - (SerCx) – C:\Windows\SysNative\Drivers\SerCx.sys (Microsoft Corporation)
DRV:64bit: - (SpbCx) – C:\Windows\SysNative\Drivers\SpbCx.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbGD) – C:\Windows\SysNative\Drivers\TsUsbGD.sys (Microsoft Corporation)
DRV:64bit: - (BthHFEnum) – C:\Windows\SysNative\Drivers\bthhfenum.sys (Microsoft Corporation)
DRV:64bit: - (dmvsc) – C:\Windows\SysNative\Drivers\dmvsc.sys (Microsoft Corporation)
DRV:64bit: - (TsUsbFlt) – C:\Windows\SysNative\Drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (wpcfltr) – C:\Windows\SysNative\Drivers\wpcfltr.sys (Microsoft Corporation)
DRV:64bit: - (NdisImPlatform) – C:\Windows\SysNative\Drivers\NdisImPlatform.sys (Microsoft Corporation)
DRV:64bit: - (MsLldp) – C:\Windows\SysNative\Drivers\mslldp.sys (Microsoft Corporation)
DRV:64bit: - (Ndu) – C:\Windows\SysNative\Drivers\Ndu.sys (Microsoft Corporation)
DRV:64bit: - (AtiHDAudioService) – C:\Windows\SysNative\Drivers\AtihdW86.sys (Advanced Micro Devices)
DRV:64bit: - (RTWlanE) – C:\Windows\SysNative\Drivers\rtwlane.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (RTL8192Ce) – C:\Windows\SysNative\Drivers\rtwlane.sys (Realtek Semiconductor Corporation )
DRV:64bit: - (L1C) – C:\Windows\SysNative\Drivers\L1C63x64.sys (Qualcomm Atheros Co., Ltd.)
DRV:64bit: - (RSPCIESTOR) – C:\Windows\SysNative\Drivers\RtsPStor.sys (Realtek Semiconductor Corp.)
DRV:64bit: - (usbfilter) – C:\Windows\SysNative\Drivers\usbfilter.sys (Advanced Micro Devices)
DRV:64bit: - (BCM43XX) – C:\Windows\SysNative\Drivers\BCMWL63A.SYS (Broadcom Corporation)
DRV:64bit: - (UBHelper) – C:\Windows\SysNative\Drivers\UBHelper.sys (NTI Corporation)
DRV:64bit: - (NTIDrvr) – C:\Windows\SysNative\Drivers\NTIDrvr.sys (NTI Corporation)
========== Standard Registry (SafeList) ==========
========== Internet Explorer ==========
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD2406}
IE:64bit: - HKLM\..\SearchScopes\{D66AF222-5CCE-42CC-95B3-D61D423295E1}: "URL" = http://www.bing.com/search?q={searchTerms}…R&pc;=MAARJS
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {D66AF222-5CCE-42CC-95B3-D61D423295E1}
IE - HKLM\..\SearchScopes\{D66AF222-5CCE-42CC-95B3-D61D423295E1}: "URL" = http://www.bing.com/search?q={searchTerms}…R&pc;=MAARJS
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://acer13.msn.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.bing.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.com/
IE - HKCU\..\SearchScopes,DefaultScope = {E8306F4C-C68D-4654-AC74-C6754A8EB48B}
IE - HKCU\..\SearchScopes\{E8306F4C-C68D-4654-AC74-C6754A8EB48B}: "URL" = http://search.conduit.com/ResultsExt.aspx?…513922&UM;=2
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local
========== FireFox ==========
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20513.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@rocketlife.com/RocketLife Secure Plug-In Layer;version=1.0.5: C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll (RocketLife, LLP)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\4\NP_wtapp.dll ()
FF - HKEY_LOCAL_MACHINE\software\mozilla\Thunderbird\Extensions\\[removed]: C:\Program Files\McAfee\MSK
========== Chrome ==========
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{g
oogle:searchFieldtrialParameter}{google:searchClient}{google:sourceId}{google:ins
tantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncodin
g}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&q;={searchTerms}&{google:cursorPosition}{google:zeroPrefixUrl}{google:pageClassification}sugk
ey={google:suggestAPIKeyParameter},
CHR - homepage: http://search.conduit.com/?SearchSource=10…;ctid=CT3286042
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Regina\AppData\Local\Google\Chrome\Application\31.0.1622.7\PepperFlash\pepflashplayer.dll
CHR - plugin: Chrome Remote Desktop Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Regina\AppData\Local\Google\Chrome\Application\31.0.1622.7\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Regina\AppData\Local\Google\Chrome\Application\31.0.1622.7\pdf.dll
CHR - plugin: Garmin Communicator Plug-In (Enabled) = C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.149\npGoogleUpdate3.dll
CHR - plugin: WildTangent Games App V2 Presence Detector (Enabled) = C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\4\NP_wtapp.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: RocketLife Secure Plug-In Layer (Enabled) = C:\ProgramData\Visan\plugins\npRLSecurePluginLayer.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.20125.0\npctrl.dll
CHR - Extension: Google Docs = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\aohghmighlieiainnegkcijnfilokake\0.5_0\
CHR - Extension: Google Drive = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\apdfllckaahabafndbhieahigkjlhalf\6.3_0\
CHR - Extension: YouTube = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.6_0\
CHR - Extension: Google Search = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.20_0\
CHR - Extension: AdBlock = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\gighmmpiobklfepjocnamgkkbiglidom\2.6.6_0\
CHR - Extension: avast! Online Security = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\gomekmidlodglbbmalcneegieacbdmki\8.0.8_0\
CHR - Extension: Chrome In-App Payments service = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.4.10_0\
CHR - Extension: Gmail = C:\Users\Regina\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\
O1 HOSTS File: ([2012/07/26 00:26:49 | 000,000,824 | —- | M]) - C:\Windows\SysNative\Drivers\etc\hosts
O2:64bit: - BHO: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O2:64bit: - BHO: (no name) - {9D717F81-9148-4f12-8568-69135F087DB0} - No CLSID value found.
O2 - BHO: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (avast! Online Security) - {318A227B-5E9F-45bd-8999-7F8F10CA4CF5} - C:\Program Files\AVAST Software\Avast\aswWebRepIE64.dll (AVAST Software)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (avast! Online Security) - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\Program Files\AVAST Software\Avast\aswWebRepIE.dll (AVAST Software)
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O4:64bit: - HKLM..\Run: [ETDCtrl] C:\Program Files\Elantech\ETDCtrl.exe (ELAN Microelectronics Corp.)
O4:64bit: - HKLM..\Run: [RTHDVCPL] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4 - HKLM..\Run: [AllShareAgent] C:\Program Files (x86)\Samsung\AllShare\AllShareAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [avast] C:\Program Files\AVAST Software\Avast\avastUI.exe (AVAST Software)
O4 - HKLM..\Run: [BakupManagerTray] C:\Program Files (x86)\NTI\Acer Backup Manager\BackupManagerTray.exe (NTI Corporation)
O4 - HKLM..\Run: [SDTray] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe (Safer-Networking Ltd.)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [GarminExpressTrayApp] C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKCU..\Run: [Spybot-S&D; Cleaning] C:\Program Files (x86)\Spybot - Search & Destroy 2\SDCleaner.exe (Safer-Networking Ltd.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableCursorSuppression = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O15 - HKCU\..Trusted Domains: swcportal.org ([mymadisoncollege] https in Trusted sites)
O16 - DPF: {0E5F0222-96B9-11D3-8997-00104BD12D94} http://utilities.pcpitstop.com/Nirvana/controls/pcmatic.cab (PCPitstop Utility)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{038C89A4-7FA6-4076-85EC-7E40F6EC8085}: DhcpNameServer = 192.168.1.1
O20:64bit: - AppInit_DLLs: (C:\PROGRA~3\Wincert\WIN64C~1.DLL) - C:\ProgramData\Wincert\win64cert.dll ()
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\Datamngr\x64\mgrldr.dll) - File not found
O20 - AppInit_DLLs: (C:\PROGRA~3\Wincert\WIN32C~1.DLL) - C:\ProgramData\Wincert\win32cert.dll ()
O20 - AppInit_DLLs: (C:\PROGRA~2\SEARCH~1\Datamngr\mgrldr.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - Winlogon\Notify\SDWinLogon: DllName - (SDWinLogon.dll) - File not found
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O30 - LSA: Security Packages - (livessp) - File not found
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2013/09/10 20:48:02 | 000,000,000 | —- | M] () - C:\autoexec.bat – [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] – "%1" %*
O35:64bit: - HKLM\..exefile [open] – "%1" %*
O35 - HKLM\..comfile [open] – "%1" %*
O35 - HKLM\..exefile [open] – "%1" %*
O37:64bit: - HKLM\…com [@ = comfile] – "%1" %*
O37:64bit: - HKLM\…exe [@ = exefile] – "%1" %*
O37 - HKLM\…com [@ = comfile] – "%1" %*
O37 - HKLM\…exe [@ = exefile] – "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
NetSvcs:64bit: wlidsvc - C:\Windows\SysNative\wlidsvc.dll (Microsoft Corporation)
NetSvcs:64bit: DsmSvc - C:\Windows\SysNative\DeviceSetupManager.dll (Microsoft Corporation)
NetSvcs:64bit: NcaSvc - C:\Windows\SysNative\NcaSvc.dll (Microsoft Corporation)
NetSvcs:64bit: SystemEventsBroker - C:\Windows\SysNative\SystemEventsBrokerServer.dll (Microsoft Corporation)
Drivers32:64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
CREATERESTOREPOINT
Restore point Set: OTL Restore Point
========== Files/Folders - Created Within 30 Days ==========
[2013/09/10 20:46:14 | 000,000,000 | —D | C] – C:\Program Files\Enigma Software Group
[2013/09/10 20:42:39 | 000,000,000 | —D | C] – C:\Program Files (x86)\Common Files\Wise Installation Wizard
[2013/09/10 07:07:19 | 000,000,000 | —D | C] – C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2013/09/09 12:42:46 | 000,000,000 | —D | C] – C:\Program Files (x86)\Trend Micro
[2013/09/09 12:42:46 | 000,000,000 | —D | C] – C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\HiJackThis
[2013/09/09 12:27:29 | 000,688,992 | R— | C] (Swearware) – C:\Users\Regina\Desktop\dds.com
[2013/09/08 21:12:05 | 000,173,504 | —- | C] (Trend Micro Inc.) – C:\Windows\SysNative\drivers\tmcomm.sys
[2013/09/08 12:44:10 | 000,000,000 | —D | C] – C:\ProgramData\Spybot - Search & Destroy
[2013/09/08 12:43:54 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot - Search & Destroy 2
[2013/09/08 12:43:37 | 000,017,272 | —- | C] (Safer Networking Limited) – C:\Windows\SysNative\sdnclean64.exe
[2013/09/08 12:43:07 | 000,000,000 | —D | C] – C:\Program Files (x86)\Spybot - Search & Destroy 2
[2013/09/07 19:44:21 | 001,257,472 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\kernel32.dll
[2013/09/07 19:44:17 | 001,300,992 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\gdi32.dll
[2013/09/06 22:05:34 | 000,000,000 | —D | C] – C:\ProgramData\PCPitstop
[2013/09/06 22:05:32 | 000,000,000 | —D | C] – C:\Program Files (x86)\PCPitstop
[2013/09/06 19:07:34 | 000,000,000 | —D | C] – C:\ProgramData\Samsung
[2013/09/06 19:04:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\Samsung Electronics
[2013/09/04 19:28:29 | 000,888,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\autochk.exe
[2013/09/04 19:28:29 | 000,542,208 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\untfs.dll
[2013/09/04 19:28:28 | 000,482,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\untfs.dll
[2013/09/04 19:28:27 | 000,793,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\autochk.exe
[2013/09/03 15:15:23 | 013,644,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Windows.UI.Xaml.dll
[2013/09/03 15:15:14 | 010,788,864 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Windows.UI.Xaml.dll
[2013/09/03 15:15:08 | 001,131,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentServer.dll
[2013/09/03 15:15:03 | 010,116,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\twinui.dll
[2013/09/03 15:14:54 | 000,470,528 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netprofmsvc.dll
[2013/09/03 15:14:49 | 008,857,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\twinui.dll
[2013/09/03 15:14:47 | 002,305,024 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\authui.dll
[2013/09/03 15:14:46 | 000,760,320 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapi.dll
[2013/09/03 15:14:44 | 002,035,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\authui.dll
[2013/09/03 15:14:42 | 000,014,848 | —- | C] (Microsoft) – C:\Windows\SysWow64\rars.rs
[2013/09/03 15:14:41 | 000,014,848 | —- | C] (Microsoft) – C:\Windows\SysNative\rars.rs
[2013/09/03 15:14:40 | 000,446,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\USBHUB3.SYS
[2013/09/03 15:14:40 | 000,328,192 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ubpm.dll
[2013/09/03 15:14:39 | 000,389,120 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\BCP47Langs.dll
[2013/09/03 15:14:39 | 000,330,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\stobject.dll
[2013/09/03 15:14:39 | 000,247,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\ubpm.dll
[2013/09/03 15:14:38 | 000,621,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapi.dll
[2013/09/03 15:14:37 | 000,708,096 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AppXDeploymentExtensions.dll
[2013/09/03 15:14:36 | 000,812,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\Magnify.exe
[2013/09/03 15:14:36 | 000,169,984 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\netplwiz.dll
[2013/09/03 15:14:35 | 000,560,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfmp4srcsnk.dll
[2013/09/03 15:14:35 | 000,093,696 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\psmsrv.dll
[2013/09/03 15:14:34 | 000,151,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\netplwiz.dll
[2013/09/03 15:14:32 | 000,501,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DevicePairing.dll
[2013/09/03 15:14:32 | 000,284,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\spaceport.sys
[2013/09/03 15:14:31 | 000,058,312 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuauclt.exe
[2013/09/03 15:14:30 | 000,419,840 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\intl.cpl
[2013/09/03 15:14:29 | 000,120,736 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\AuthHost.exe
[2013/09/03 15:14:28 | 001,619,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wucltux.dll
[2013/09/03 15:14:28 | 000,758,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\Magnify.exe
[2013/09/03 15:14:27 | 000,449,536 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\DevicePairing.dll
[2013/09/03 15:14:26 | 000,122,368 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\biwinrt.dll
[2013/09/03 15:14:24 | 000,251,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\WUSettingsProvider.dll
[2013/09/03 15:14:24 | 000,092,160 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\biwinrt.dll
[2013/09/03 15:14:22 | 000,389,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\intl.cpl
[2013/09/03 15:14:22 | 000,179,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\bisrv.dll
[2013/09/03 15:14:20 | 000,411,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfmp4srcsnk.dll
[2013/09/03 15:14:20 | 000,173,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\storewuauth.dll
[2013/09/03 15:14:19 | 000,141,824 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuwebv.dll
[2013/09/03 15:14:19 | 000,125,952 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuwebv.dll
[2013/09/03 15:14:19 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wudriver.dll
[2013/09/03 15:14:18 | 000,309,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\BCP47Langs.dll
[2013/09/03 15:14:18 | 000,083,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wudriver.dll
[2013/09/03 15:14:17 | 000,039,424 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wuapp.exe
[2013/09/03 15:14:17 | 000,017,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\muifontsetup.dll
[2013/09/03 15:14:16 | 000,034,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\wuapp.exe
[2013/09/03 15:14:15 | 000,014,336 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\muifontsetup.dll
[2013/09/03 13:07:30 | 000,247,216 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdFilter.sys
[2013/09/03 13:07:29 | 000,036,288 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\WdBoot.sys
[2013/09/03 11:35:32 | 000,000,000 | —D | C] – C:\Windows\SysNative\MRT
[2013/09/03 11:29:41 | 001,314,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\rpcrt4.dll
[2013/09/02 15:13:06 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2013/09/02 15:11:19 | 000,000,000 | —D | C] – C:\Program Files\iPod
[2013/09/02 15:11:16 | 000,000,000 | —D | C] – C:\Program Files\iTunes
[2013/09/02 15:11:16 | 000,000,000 | —D | C] – C:\Program Files (x86)\iTunes
[2013/09/02 15:11:16 | 000,000,000 | —D | C] – C:\ProgramData\34BE82C4-E596-4e99-A191-52C6199EBF69
[2013/09/02 11:52:06 | 000,915,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\uxtheme.dll
[2013/09/02 11:52:06 | 000,053,760 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\UXInit.dll
[2013/09/02 11:52:05 | 000,044,032 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\UXInit.dll
[2013/09/02 11:52:05 | 000,033,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iernonce.dll
[2013/09/02 11:52:04 | 000,061,440 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesetup.dll
[2013/09/02 11:51:47 | 000,109,056 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\iesysprep.dll
[2013/09/02 11:51:47 | 000,051,712 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ie4uinit.exe
[2013/09/02 11:51:47 | 000,039,936 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iernonce.dll
[2013/09/02 11:51:41 | 000,603,136 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\msfeeds.dll
[2013/09/02 11:51:37 | 000,067,072 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesetup.dll
[2013/09/02 11:51:35 | 000,136,704 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\iesysprep.dll
[2013/09/02 11:51:09 | 000,855,552 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript.dll
[2013/09/02 11:49:00 | 000,690,688 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\jscript.dll
[2013/09/02 11:48:58 | 003,958,784 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\jscript9.dll
[2013/09/02 08:37:44 | 001,889,280 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\crypt32.dll
[2013/09/02 08:37:39 | 000,337,408 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\wintrust.dll
[2013/09/02 08:37:38 | 000,124,416 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\apprepapi.dll
[2013/09/02 08:37:38 | 000,087,040 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apprepapi.dll
[2013/09/02 08:37:37 | 000,098,304 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\apprepsync.dll
[2013/09/02 08:37:36 | 000,074,240 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\apprepsync.dll
[2013/09/02 05:37:26 | 000,030,720 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\cryptdlg.dll
[2013/09/02 05:37:26 | 000,025,088 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\cryptdlg.dll
[2013/09/01 23:52:07 | 000,595,968 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\qedit.dll
[2013/09/01 23:52:06 | 000,496,640 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\qedit.dll
[2013/09/01 19:26:44 | 000,800,824 | —- | C] (Microsoft Corporation) – C:\Users\Regina\AppData\Roaming\DPInst.exe
[2013/09/01 19:26:44 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Users\Regina\AppData\Roaming\gacutil.exe
[2013/09/01 19:26:44 | 000,036,352 | —- | C] (Microsoft Corporation) – C:\Users\Regina\AppData\Roaming\PnPutil.exe
[2013/09/01 18:40:50 | 000,000,000 | —D | C] – C:\Users\Regina\AppData\Local\ElevatedDiagnostics
[2013/08/24 16:46:00 | 001,838,080 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DWrite.dll
[2013/08/24 09:10:10 | 001,842,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\dwmcore.dll
[2013/08/24 09:10:09 | 001,453,568 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfcore.dll
[2013/08/24 09:10:09 | 000,364,544 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\XpsGdiConverter.dll
[2013/08/24 09:10:08 | 000,850,944 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\mfasfsrcsnk.dll
[2013/08/24 09:10:07 | 002,106,176 | —- | C] (Microsoft Corporation) – C:\Windows\SysWow64\explorer.exe
[2013/08/24 09:09:55 | 000,337,152 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\USBXHCI.SYS
[2013/08/24 09:09:55 | 000,213,248 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\UCX01000.SYS
[2013/08/24 09:09:55 | 000,194,816 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\sdbus.sys
[2013/08/24 09:09:54 | 000,125,184 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\dumpsd.sys
[2013/08/24 09:09:53 | 000,190,976 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\vdsutil.dll
[2013/08/24 09:09:51 | 006,987,008 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\ntoskrnl.exe
[2013/08/24 09:09:49 | 001,527,808 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfcore.dll
[2013/08/24 09:09:49 | 001,048,576 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mfasfsrcsnk.dll
[2013/08/24 09:09:48 | 000,583,168 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\mscms.dll
[2013/08/24 09:09:48 | 000,080,896 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\MbaeParserTask.exe
[2013/08/24 09:09:47 | 002,391,280 | —- | C] (Microsoft Corporation) – C:\Windows\explorer.exe
[2013/08/24 09:09:47 | 000,729,600 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\samsrv.dll
[2013/08/24 09:09:47 | 000,207,872 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\DeviceSetupManager.dll
[2013/08/24 09:09:47 | 000,106,496 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\samlib.dll
[2013/08/24 09:09:46 | 002,219,520 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\dwmcore.dll
[2013/08/24 09:09:46 | 000,523,264 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\XpsGdiConverter.dll
[2013/08/24 09:09:45 | 001,093,904 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.exe
[2013/08/24 09:09:44 | 001,403,296 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.efi
[2013/08/24 09:09:44 | 001,271,584 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winload.exe
[2013/08/24 09:09:44 | 001,217,352 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\winresume.efi
[2013/08/24 09:09:36 | 000,037,632 | —- | C] (Microsoft Corporation) – C:\Windows\SysNative\drivers\BthAvrcpTg.sys
[2013/08/19 20:46:37 | 000,000,000 | —D | C] – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Silverlight
[2013/08/19 20:41:57 | 000,000,000 | —D | C] – C:\Program Files\Microsoft Silverlight
[2013/08/19 20:41:57 | 000,000,000 | —D | C] – C:\Program Files (x86)\Microsoft Silverlight
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files - Modified Within 30 Days ==========
[2013/09/11 07:52:26 | 000,001,421 | —- | M] () – C:\Users\Regina\Desktop\OTL - Shortcut.lnk
[2013/09/11 07:08:15 | 000,067,584 | –S- | M] () – C:\Windows\bootstat.dat
[2013/09/11 07:06:09 | 268,435,456 | -HS- | M] () – C:\swapfile.sys
[2013/09/11 07:06:08 | 3068,764,160 | -HS- | M] () – C:\hiberfil.sys
[2013/09/10 20:48:02 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2013/09/10 19:52:33 | 000,931,243 | —- | M] () – C:\Users\Regina\AppData\Local\census.cache
[2013/09/10 19:52:13 | 000,085,354 | —- | M] () – C:\Users\Regina\AppData\Local\ars.cache
[2013/09/10 07:07:19 | 000,002,377 | —- | M] () – C:\Users\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/09/10 07:07:19 | 000,002,375 | —- | M] () – C:\Users\Regina\Desktop\Google Chrome.lnk
[2013/09/09 20:12:13 | 000,003,924 | —- | M] () – C:\Users\Regina\Documents\cc_20130909_201207.reg
[2013/09/09 14:11:47 | 000,281,088 | —- | M] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/09/09 13:10:40 | 000,009,670 | —- | M] () – C:\Users\Regina\Documents\cc_20130909_131036.reg
[2013/09/09 12:42:46 | 000,002,981 | —- | M] () – C:\Users\Regina\Desktop\HiJackThis.lnk
[2013/09/09 12:30:48 | 001,402,880 | —- | M] () – C:\Users\Regina\Desktop\HiJackThis.msi
[2013/09/09 12:27:34 | 000,688,992 | R— | M] (Swearware) – C:\Users\Regina\Desktop\dds.com
[2013/09/09 12:00:49 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\config.nt
[2013/09/09 11:33:47 | 000,007,605 | —- | M] () – C:\Users\Regina\AppData\Local\Resmon.ResmonCfg
[2013/09/08 22:52:44 | 000,000,000 | —- | M] () – C:\Windows\SysNative\olepro32.dll
[2013/09/08 22:52:33 | 000,000,000 | —- | M] () – C:\Windows\SysNative\atiuxpag.dll
[2013/09/08 22:52:33 | 000,000,000 | —- | M] () – C:\Windows\SysNative\atidxx32.dll
[2013/09/08 22:52:33 | 000,000,000 | —- | M] () – C:\Windows\SysNative\aticfx32.dll
[2013/09/08 21:15:57 | 000,001,184 | —- | M] () – C:\Users\Public\Desktop\Install Microsoft Mouse and Keyboard Center.lnk
[2013/09/08 16:01:50 | 000,005,111 | —- | M] () – C:\Windows\wininit.ini
[2013/09/08 12:43:54 | 000,001,387 | —- | M] () – C:\Users\Public\Desktop\Spybot-S&D; Start Center.lnk
[2013/09/06 19:02:42 | 000,848,230 | —- | M] () – C:\Windows\SysNative\PerfStringBackup.INI
[2013/09/06 19:02:42 | 000,719,418 | —- | M] () – C:\Windows\SysNative\perfh009.dat
[2013/09/06 19:02:42 | 000,132,748 | —- | M] () – C:\Windows\SysNative\perfc009.dat
[2013/09/02 15:13:07 | 000,001,787 | —- | M] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/09/01 23:27:14 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\taskhost.exe
[2013/09/01 23:27:12 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\RuntimeBroker.exe
[2013/09/01 23:27:12 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\printfilterpipelinesvc.exe
[2013/09/01 23:27:12 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\atieclxx.exe
[2013/09/01 23:24:57 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\taskhostex.exe
[2013/09/01 23:24:57 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\conhost.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\winlogon.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\spoolsv.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\services.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\lsass.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\dasHost.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\atiesrxx.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\wininit.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\smss.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\dwm.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | M] () – C:\Windows\SysWow64\csrss.exe
[2013/09/01 20:35:58 | 000,008,500 | —- | M] () – C:\Users\Regina\Documents\cc_20130901_203552.reg
[2013/09/01 19:26:44 | 000,800,824 | —- | M] (Microsoft Corporation) – C:\Users\Regina\AppData\Roaming\DPInst.exe
[2013/09/01 19:26:44 | 000,106,496 | —- | M] (Microsoft Corporation) – C:\Users\Regina\AppData\Roaming\gacutil.exe
[2013/09/01 19:26:44 | 000,036,352 | —- | M] (Microsoft Corporation) – C:\Users\Regina\AppData\Roaming\PnPutil.exe
[2013/09/01 19:26:44 | 000,000,181 | —- | M] () – C:\Users\Regina\AppData\Roaming\gacutil.exe.config
[2013/09/01 19:13:59 | 000,000,460 | —- | M] () – C:\Users\Regina\Documents\cc_20130901_191353.reg
[2013/09/01 19:10:10 | 000,000,826 | —- | M] () – C:\Users\Public\Desktop\CCleaner.lnk
[2013/08/30 13:01:23 | 000,002,457 | —- | M] () – C:\Users\Regina\Documents\To Do List.rtf
[2013/08/30 02:48:10 | 001,030,952 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSnx.sys
[2013/08/30 02:48:10 | 000,378,944 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswSP.sys
[2013/08/30 02:48:10 | 000,204,880 | —- | M] () – C:\Windows\SysNative\drivers\aswVmm.sys
[2013/08/30 02:48:10 | 000,072,016 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswRdr2.sys
[2013/08/30 02:48:10 | 000,065,336 | —- | M] () – C:\Windows\SysNative\drivers\aswRvrt.sys
[2013/08/30 02:48:10 | 000,064,288 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswTdi.sys
[2013/08/30 02:48:09 | 000,080,816 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswMonFlt.sys
[2013/08/30 02:48:09 | 000,033,400 | —- | M] (AVAST Software) – C:\Windows\SysNative\drivers\aswFsBlk.sys
[2013/08/30 02:47:40 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2013/08/30 02:47:14 | 000,287,840 | —- | M] (AVAST Software) – C:\Windows\SysNative\aswBoot.exe
[2013/08/26 18:56:10 | 000,002,156 | —- | M] () – C:\Users\Regina\Documents\resume.rtf
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
========== Files Created - No Company Name ==========
[2013/09/11 07:52:08 | 000,001,421 | —- | C] () – C:\Users\Regina\Desktop\OTL - Shortcut.lnk
[2013/09/10 20:48:02 | 000,000,000 | —- | C] () – C:\autoexec.bat
[2013/09/10 07:07:19 | 000,002,377 | —- | C] () – C:\Users\Regina\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2013/09/10 07:07:19 | 000,002,375 | —- | C] () – C:\Users\Regina\Desktop\Google Chrome.lnk
[2013/09/09 20:12:09 | 000,003,924 | —- | C] () – C:\Users\Regina\Documents\cc_20130909_201207.reg
[2013/09/09 14:11:33 | 000,281,088 | —- | C] () – C:\Windows\SysNative\FNTCACHE.DAT
[2013/09/09 13:10:38 | 000,009,670 | —- | C] () – C:\Users\Regina\Documents\cc_20130909_131036.reg
[2013/09/09 12:42:46 | 000,002,981 | —- | C] () – C:\Users\Regina\Desktop\HiJackThis.lnk
[2013/09/09 12:30:37 | 001,402,880 | —- | C] () – C:\Users\Regina\Desktop\HiJackThis.msi
[2013/09/09 11:33:47 | 000,007,605 | —- | C] () – C:\Users\Regina\AppData\Local\Resmon.ResmonCfg
[2013/09/08 22:52:44 | 000,000,000 | —- | C] () – C:\Windows\SysNative\olepro32.dll
[2013/09/08 22:52:33 | 000,000,000 | —- | C] () – C:\Windows\SysNative\atiuxpag.dll
[2013/09/08 22:52:33 | 000,000,000 | —- | C] () – C:\Windows\SysNative\atidxx32.dll
[2013/09/08 22:52:33 | 000,000,000 | —- | C] () – C:\Windows\SysNative\aticfx32.dll
[2013/09/08 21:15:57 | 000,001,184 | —- | C] () – C:\Users\Public\Desktop\Install Microsoft Mouse and Keyboard Center.lnk
[2013/09/08 14:31:38 | 000,005,111 | —- | C] () – C:\Windows\wininit.ini
[2013/09/08 12:43:54 | 000,001,399 | —- | C] () – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Spybot-S&D; Start Center.lnk
[2013/09/08 12:43:54 | 000,001,387 | —- | C] () – C:\Users\Public\Desktop\Spybot-S&D; Start Center.lnk
[2013/09/02 15:13:07 | 000,001,787 | —- | C] () – C:\Users\Public\Desktop\iTunes.lnk
[2013/09/02 00:37:29 | 000,931,243 | —- | C] () – C:\Users\Regina\AppData\Local\census.cache
[2013/09/02 00:36:28 | 000,085,354 | —- | C] () – C:\Users\Regina\AppData\Local\ars.cache
[2013/09/01 23:27:14 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\taskhost.exe
[2013/09/01 23:27:12 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\RuntimeBroker.exe
[2013/09/01 23:27:12 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\printfilterpipelinesvc.exe
[2013/09/01 23:27:12 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\atieclxx.exe
[2013/09/01 23:24:57 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\taskhostex.exe
[2013/09/01 23:24:57 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\conhost.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\winlogon.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\spoolsv.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\services.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\lsass.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\dasHost.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\atiesrxx.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\wininit.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\smss.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\dwm.exe
[2013/09/01 23:24:55 | 000,000,000 | —- | C] () – C:\Windows\SysWow64\csrss.exe
[2013/09/01 20:35:56 | 000,008,500 | —- | C] () – C:\Users\Regina\Documents\cc_20130901_203552.reg
[2013/09/01 19:26:44 | 000,000,181 | —- | C] () – C:\Users\Regina\AppData\Roaming\gacutil.exe.config
[2013/09/01 19:13:57 | 000,000,460 | —- | C] () – C:\Users\Regina\Documents\cc_20130901_191353.reg
[2013/08/28 19:52:28 | 000,002,457 | —- | C] () – C:\Users\Regina\Documents\To Do List.rtf
[2013/08/26 18:56:10 | 000,002,156 | —- | C] () – C:\Users\Regina\Documents\resume.rtf
[2013/08/24 09:09:54 | 000,386,642 | —- | C] () – C:\Windows\SysNative\ApnDatabase.xml
[2013/03/07 14:49:56 | 000,000,036 | —- | C] () – C:\Users\Regina\AppData\Local\housecall.guid.cache
[2013/01/11 10:27:59 | 000,083,968 | —- | C] () – C:\Windows\SysWow64\OEMLicense.dll
[2012/09/03 16:59:49 | 000,451,072 | —- | C] () – C:\Windows\SysWow64\ISSRemoveSP.exe
[2012/09/03 16:44:30 | 000,000,000 | —- | C] () – C:\Windows\ativpsrm.bin
[2012/08/14 10:06:37 | 000,204,952 | —- | C] () – C:\Windows\SysWow64\ativvsvl.dat
[2012/08/14 10:06:37 | 000,157,144 | —- | C] () – C:\Windows\SysWow64\ativvsva.dat
[2012/08/14 10:06:37 | 000,003,917 | —- | C] () – C:\Windows\SysWow64\atipblag.dat
[2012/07/26 03:13:10 | 000,215,943 | —- | C] () – C:\Windows\SysWow64\dssec.dat
[2012/07/26 03:13:09 | 000,000,741 | —- | C] () – C:\Windows\SysWow64\NOISE.DAT
[2012/07/26 02:21:26 | 000,067,584 | –S- | C] () – C:\Windows\bootstat.dat
[2012/07/25 20:17:42 | 000,043,520 | —- | C] () – C:\Windows\SysWow64\BWContextHandler.dll
[2012/07/25 15:37:29 | 000,043,131 | —- | C] () – C:\Windows\mib.bin
[2012/07/25 15:28:31 | 000,364,544 | —- | C] () – C:\Windows\SysWow64\msjetoledb40.dll
[2012/06/02 09:31:19 | 000,673,088 | —- | C] () – C:\Windows\SysWow64\mlang.dat
[2012/05/10 17:35:16 | 000,029,184 | —- | C] () – C:\Windows\SysWow64\kdbsdk32.dll
========== ZeroAccess Check ==========
[2012/09/03 17:30:15 | 000,000,227 | RHS- | M] () – C:\Windows\assembly\Desktop.ini
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll – [2013/03/06 01:31:28 | 019,758,592 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll – [2013/03/06 00:03:37 | 017,561,600 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll – [2012/07/25 22:05:38 | 001,004,544 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll – [2012/07/25 22:18:27 | 000,784,896 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Free
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll – [2012/07/25 22:07:41 | 000,455,680 | —- | M] (Microsoft Corporation)
"ThreadingModel" = Both
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
========== LOP Check ==========
[2013/01/11 18:26:32 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Awem
[2013/01/10 20:43:35 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\FloodLightGames
[2013/04/23 23:10:20 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Garmin
[2013/01/23 09:49:54 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\ICAClient
[2013/01/12 22:04:05 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Jewel Match 3
[2013/01/08 18:44:06 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\lm
[2013/03/17 22:28:52 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Rovio
[2013/04/12 17:28:52 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Samsung
[2013/01/20 11:05:48 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Temp
[2013/03/14 21:18:58 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\TFP
[2013/04/13 23:14:43 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\TuneUp Software
[2013/01/20 11:47:14 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\Visan
[2013/01/08 22:39:28 | 000,000,000 | —D | M] – C:\Users\Regina\AppData\Roaming\WildTangent
========== Purity Check ==========
========== Custom Scans ==========
< %USERPROFILE%\..|smtmp;true;true;true /FP >
< %temp%\smtmp\*.* /s > >
< MD5 for: EXPLORER.0.LOCALSETTINGUNIT >
[2013/04/04 17:26:37 | 000,000,357 | -HS- | M] () MD5=CB434B1A74F1B07A7A9F444F25D4AD59 – C:\Users\Regina\AppData\Local\Microsoft\Windows\Live\Roaming\LocalCache\windows-explorer\Explorer.0.localsettingunit
< MD5 for: EXPLORER.ADML >
[2012/07/26 02:49:05 | 000,003,671 | —- | M] () MD5=007B16AEF3E958080573CDB80648167D – C:\Windows\WinSxS\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.2.9200.16384_en-us_7bca26f6f419a854\Explorer.adml
[2012/07/26 02:49:05 | 000,003,671 | —- | M] () MD5=007B16AEF3E958080573CDB80648167D – C:\Windows\WinSxS\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.2.9200.16433_en-us_7bff382ef3f2006f\Explorer.adml
[2012/07/26 02:49:05 | 000,003,671 | —- | M] () MD5=007B16AEF3E958080573CDB80648167D – C:\Windows\WinSxS\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.2.9200.20534_en-us_7c89d5440d0eb990\Explorer.adml
< MD5 for: EXPLORER.ADMX >
[2012/06/02 09:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.16384_none_6e8451187a9a1607\Explorer.admx
[2012/06/02 09:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.16420_none_6ec1315e7a6d062c\Explorer.admx
[2012/06/02 09:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.16433_none_6eb962507a726e22\Explorer.admx
[2012/06/02 09:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.20521_none_6f4bce739389bf4d\Explorer.admx
[2012/06/02 09:32:35 | 000,003,836 | —- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 – C:\Windows\WinSxS\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.2.9200.20534_none_6f43ff65938f2743\Explorer.admx
< MD5 for: EXPLORER.EXE >
[2013/05/16 10:58:12 | 003,859,928 | —- | M] (Safer-Networking Ltd.) MD5=03250DB0886A23B1F6C077C5D9F152B0 – C:\Program Files (x86)\Spybot - Search & Destroy 2\explorer.exe
[2012/10/11 00:53:24 | 002,115,952 | —- | M] (Microsoft Corporation) MD5=0AD19A3CA61271BA872AD90771BA47DC – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_b592a71650d677ed\explorer.exe
[2012/10/11 03:09:58 | 002,380,944 | —- | M] (Microsoft Corporation) MD5=0DDFEAA2AA18D4295EF220EB666B2312 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20534_none_ab3dfcc41c75b5f2\explorer.exe
[2013/06/01 06:34:21 | 002,391,280 | —- | M] (Microsoft Corporation) MD5=0E8E6463F81C80AFBED533E0F1F8895D – C:\Windows\explorer.exe
[2013/06/01 06:34:21 | 002,391,280 | —- | M] (Microsoft Corporation) MD5=0E8E6463F81C80AFBED533E0F1F8895D – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16628_none_aac334d9034c59e1\explorer.exe
[2013/06/01 05:17:57 | 002,116,520 | —- | M] (Microsoft Corporation) MD5=15C505AD0118275E7363A539009EF3AF – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20733_none_b591aa9850d758e4\explorer.exe
[2012/07/25 22:50:01 | 002,114,936 | —- | M] (Microsoft Corporation) MD5=5B6ED1B57DBFF18D405A0260559B571E – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_b4d2f8c937e166b1\explorer.exe
[2012/07/25 23:49:13 | 002,380,440 | —- | M] (Microsoft Corporation) MD5=928791755FDDEA721B053535EF84FA17 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16384_none_aa7e4e770380a4b6\explorer.exe
[2012/10/11 00:56:41 | 002,115,952 | —- | M] (Microsoft Corporation) MD5=953ADECFF08202A01EFC6110214FDE02 – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_b5080a0137b9becc\explorer.exe
[2013/06/01 07:41:08 | 002,380,968 | —- | M] (Microsoft Corporation) MD5=D1FF6792A3B0FBD2F2F17DC936AF6177 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.20733_none_ab3d00461c7696e9\explorer.exe
[2012/10/11 02:35:16 | 002,380,944 | —- | M] (Microsoft Corporation) MD5=E13A31D5254C25406A7946BDD9B06364 – C:\Windows\WinSxS\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16433_none_aab35faf0358fcd1\explorer.exe
[2013/06/01 05:24:46 | 002,106,176 | —- | M] (Microsoft Corporation) MD5=EAFE46B0292D2BD2467835E2ACF717CC – C:\Windows\SysWOW64\explorer.exe
[2013/06/01 05:24:46 | 002,106,176 | —- | M] (Microsoft Corporation) MD5=EAFE46B0292D2BD2467835E2ACF717CC – C:\Windows\WinSxS\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.2.9200.16628_none_b517df2b37ad1bdc\explorer.exe
< MD5 for: EXPLORER.EXE.MUI >
[2012/07/26 02:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\en-US\explorer.exe.mui
[2012/07/26 02:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2012/07/26 02:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\WinSxS\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.2.9200.16384_en-us_5ebc2e81fd6600eb\explorer.exe.mui
[2012/07/26 02:48:57 | 000,020,480 | —- | M] (Microsoft Corporation) MD5=C25D32FEDB5AA6FF87B5A29D56D35FFA – C:\Windows\WinSxS\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.2.9200.16384_en-us_6910d8d431c6c2e6\explorer.exe.mui
< MD5 for: EXPLORER.EXE-03C49D11.PF >
[2013/09/10 20:07:24 | 000,182,764 | —- | M] () MD5=8E0A73A44D84CB2FDE358B420F219CAD – C:\Windows\Prefetch\EXPLORER.EXE-03C49D11.pf
< MD5 for: IEXPLORE.EXE >
[2012/10/11 01:34:54 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=06E77B5F6BB60E11A377B68BA4AA1DA7 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20534_none_2b74d7cd3a353a33\iexplore.exe
[2013/02/21 06:11:26 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=0A1FC149D1F01AEE5D66D42953CDD751 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20644_none_2b6b082b3a3c6f7b\iexplore.exe
[2013/02/21 06:11:26 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=0A1FC149D1F01AEE5D66D42953CDD751 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20703_none_2b5c4ddf3a480c6f\iexplore.exe
[2013/02/21 06:11:26 | 000,770,624 | —- | M] (Microsoft Corporation) MD5=0A1FC149D1F01AEE5D66D42953CDD751 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20742_none_2b6065cf3a44582a\iexplore.exe
[2012/10/11 02:33:47 | 000,775,168 | —- | M] (Microsoft Corporation) MD5=0A5074651C95792D32BCF536D64D0463 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20534_none_21202d7b05d47838\iexplore.exe
[2012/07/25 22:36:56 | 000,770,504 | —- | M] (Microsoft Corporation) MD5=1249974F2A658D07E2647DD9C3592B9E – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16384_none_425d1fb32079214f\iexplore.exe
[2013/07/26 01:23:39 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=133CEF30905806A35606652D409EEEBA – C:\Program Files\Internet Explorer\iexplore.exe
[2013/07/26 01:23:39 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=133CEF30905806A35606652D409EEEBA – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16660_none_37e66028ec3219f5\iexplore.exe
[2012/10/11 02:24:22 | 000,775,168 | —- | M] (Microsoft Corporation) MD5=13F97D5006C3E37D0A4AABC767C0E553 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16433_none_37f8bacaec24e2f1\iexplore.exe
[2012/07/25 23:58:31 | 000,775,112 | —- | M] (Microsoft Corporation) MD5=29CD24D8CA72FDB986B39277E70A48B6 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16384_none_38087560ec185f54\iexplore.exe
[2012/11/08 01:58:26 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=2F92EE7EE7E189EBDDADD5BEEB7E9DE0 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16453_none_37fabb5eec23159f\iexplore.exe
[2012/12/19 19:51:27 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=328569E3CA8BDB3FF74A3DBB8A1FE827 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20589_none_2b7967573a31390b\iexplore.exe
[2012/10/23 22:14:41 | 000,770,528 | —- | M] (Microsoft Corporation) MD5=39F90724C1A98648CCCDDF13631F2D4A – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16442_none_424e7c2f2084a4a2\iexplore.exe
[2013/02/05 00:23:09 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=4B20825770C794AF430529FCD962FDF5 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20624_none_2b6907973a3e3ccd\iexplore.exe
[2012/11/08 01:48:39 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=4B33704E4B071EC44806846CBE50EB2A – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20557_none_2121e9b705d2f7c9\iexplore.exe
[2013/02/04 17:49:56 | 000,775,136 | —- | M] (Microsoft Corporation) MD5=50BB41EF1CBC08E10CAB2993EEA15586 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16519_none_37eb619aec2f65fa\iexplore.exe
[2013/02/21 07:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16540_none_37ef2f80ec2bcb56\iexplore.exe
[2013/02/21 07:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16599_none_37f363eaec2830b2\iexplore.exe
[2013/02/21 07:59:57 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=6554208814632C25C77EE02355EB8E95 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16635_none_37e2ed62ec354e15\iexplore.exe
[2012/10/23 22:20:45 | 000,770,528 | —- | M] (Microsoft Corporation) MD5=79FF6755B94FF918441D8F8162E5AC9C – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20544_none_2b75d8173a34538a\iexplore.exe
[2013/07/25 22:49:06 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2013/07/25 22:49:06 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16660_none_423b0a7b2092dbf0\iexplore.exe
[2012/12/19 21:27:37 | 000,775,128 | —- | M] (Microsoft Corporation) MD5=7C4D4537048B255A851F19EA2C656BCB – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16484_none_37fda574ec207b45\iexplore.exe
[2012/11/07 23:52:27 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=7EBFC838C815C3DACA135837D8F7906E – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20557_none_2b7694093a33b9c4\iexplore.exe
[2013/07/26 00:47:06 | 000,775,256 | —- | M] (Microsoft Corporation) MD5=8D805B4EEEE0ECF6B604BE284978F135 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20768_none_210d336105e262a3\iexplore.exe
[2012/10/23 23:43:41 | 000,775,136 | —- | M] (Microsoft Corporation) MD5=8E1B68702CDB0DDC6597357766E941D9 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16442_none_37f9d1dcec23e2a7\iexplore.exe
[2013/02/05 01:45:26 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=97808A1A701DC42B07725F8C3D3BDF8D – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20624_none_21145d4505dd7ad2\iexplore.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\iexplore.exe
[2012/12/19 20:00:31 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=B8B50206CEA0791C26B63B753BCFB1D4 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16484_none_42524fc720813d40\iexplore.exe
[2012/10/11 00:41:41 | 000,770,560 | —- | M] (Microsoft Corporation) MD5=BCF25D644DF1288CD9A6524FF7AB23C8 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16433_none_424d651d2085a4ec\iexplore.exe
[2012/11/07 23:45:20 | 000,770,520 | —- | M] (Microsoft Corporation) MD5=D05965C02FD5781503968225B22189F4 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16453_none_424f65b12083d79a\iexplore.exe
[2012/12/19 21:55:26 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=D865B906C71BD10633BA0E9627050943 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20589_none_2124bd0505d07710\iexplore.exe
[2013/02/05 00:23:07 | 000,770,544 | —- | M] (Microsoft Corporation) MD5=DEAE808A574CF9FC667D6939387FC1CE – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16519_none_42400bed209027f5\iexplore.exe
[2013/02/21 06:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16540_none_4243d9d3208c8d51\iexplore.exe
[2013/02/21 06:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16599_none_42480e3d2088f2ad\iexplore.exe
[2013/02/21 06:28:11 | 000,770,608 | —- | M] (Microsoft Corporation) MD5=E4F6125ED5185F8FA37CC4F449B85526 – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.16635_none_423797b520961010\iexplore.exe
[2013/02/21 08:13:16 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=E61732C1203A6BCA2FFB91022CA48AC6 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20644_none_21165dd905dbad80\iexplore.exe
[2013/02/21 08:13:16 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=E61732C1203A6BCA2FFB91022CA48AC6 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20703_none_2107a38d05e74a74\iexplore.exe
[2013/02/21 08:13:16 | 000,775,216 | —- | M] (Microsoft Corporation) MD5=E61732C1203A6BCA2FFB91022CA48AC6 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20742_none_210bbb7d05e3962f\iexplore.exe
[2013/07/26 00:09:39 | 000,770,648 | —- | M] (Microsoft Corporation) MD5=E70D60B3A350BD09D86CDAD9CF55F36B – C:\Windows\WinSxS\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20768_none_2b61ddb33a43249e\iexplore.exe
[2012/10/24 01:08:39 | 000,775,152 | —- | M] (Microsoft Corporation) MD5=F78F14096EB41341C4D880CEA6D681A2 – C:\Windows\WinSxS\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.0.9200.20544_none_21212dc505d3918f\iexplore.exe
< MD5 for: IEXPLORE.EXE.MUI >
[2012/07/26 02:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C724BBF739D40D8AA3023943F3450A7 – C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2012/07/26 02:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C724BBF739D40D8AA3023943F3450A7 – C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2012/07/26 02:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C724BBF739D40D8AA3023943F3450A7 – C:\Windows\WinSxS\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.0.9200.16384_en-us_31b50ad823c5a03b\iexplore.exe.mui
[2012/07/26 02:49:06 | 000,005,632 | —- | M] (Microsoft Corporation) MD5=4C724BBF739D40D8AA3023943F3450A7 – C:\Windows\WinSxS\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.0.9200.16384_en-us_3c09b52a58266236\iexplore.exe.mui
< MD5 for: IEXPLORE.EXE-7A9337F2.PF >
[2013/09/10 06:44:51 | 000,082,454 | —- | M] () MD5=6CC4AC8F97E0D1D982E1AAA89D6465CA – C:\Windows\Prefetch\IEXPLORE.EXE-7A9337F2.pf
< MD5 for: IEXPLORE.EXE-F4FB5D2D.PF >
[2013/09/09 20:06:48 | 000,017,848 | —- | M] () MD5=C742E0E576EB853B09EFD9EA0FD7C479 – C:\Windows\Prefetch\IEXPLORE.EXE-F4FB5D2D.pf
< MD5 for: IEXPLORE.EXE-F4FB5D2F.PF >
[2013/09/10 06:49:58 | 000,213,296 | —- | M] () MD5=2ACFAA8D2925BF7E3FA5A1537E461D52 – C:\Windows\Prefetch\IEXPLORE.EXE-F4FB5D2F.pf
< MD5 for: SERVICES >
[2013/09/09 11:30:08 | 000,092,866 | —- | M] () MD5=2AF38A532752BB4FD1A5FE50AB3AF2BA – C:\Users\Regina\AppData\Roaming\Microsoft\MMC\services
[2012/07/26 00:26:47 | 000,017,463 | —- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 – C:\Windows\WinSxS\amd64_microsoft-windows-w..ucture-other-minwin_31bf3856ad364e35_6.2.9200.16384_none_8e0944daeed62829\services
< MD5 for: SERVICES.EXE >
[2012/09/20 01:33:11 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=581190907DA1CF8CB7B87B35FFE64A07 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.20521_none_98a9ea2e9f571eb2\services.exe
[2012/07/26 00:26:45 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=754A2CC1F32107EA87CBD305ABE3E618 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16384_none_97e26cd38667756c\services.exe
[2012/09/20 01:33:46 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=8F226143046435C75C033B0C52E90FFE – C:\Windows\SysNative\services.exe
[2012/09/20 01:33:46 | 000,410,624 | —- | M] (Microsoft Corporation) MD5=8F226143046435C75C033B0C52E90FFE – C:\Windows\WinSxS\amd64_microsoft-windows-s..cecontroller-minwin_31bf3856ad364e35_6.2.9200.16420_none_981f4d19863a6591\services.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Windows\SysWOW64\services.exe
< MD5 for: SERVICES.EXE.MUI >
[2012/07/26 02:48:33 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=8BCB19134E995FA62587DCE26E13B36C – C:\Windows\SysNative\en-US\services.exe.mui
[2012/07/26 02:48:33 | 000,018,944 | —- | M] (Microsoft Corporation) MD5=8BCB19134E995FA62587DCE26E13B36C – C:\Windows\WinSxS\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.2.9200.16384_en-us_c2c6ee7bafb963b8\services.exe.mui
< MD5 for: SERVICES.JS >
[2013/04/17 19:59:23 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingFinance_2.0.0.300_x64__8wekyb3d8bbwe\common\js\services.js
[2013/04/17 19:59:23 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingFinance_2.0.0.308_x64__8wekyb3d8bbwe\common\js\services.js
[2013/07/27 17:18:18 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingNews_2.0.0.273_x64__8wekyb3d8bbwe\common\js\services.js
[2013/07/27 17:18:18 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingNews_2.0.0.308_x64__8wekyb3d8bbwe\common\js\services.js
[2013/07/27 17:27:37 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingSports_2.0.0.273_x64__8wekyb3d8bbwe\common\js\services.js
[2013/07/27 17:27:37 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingSports_2.0.0.309_x64__8wekyb3d8bbwe\common\js\services.js
[2013/07/27 17:14:54 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingTravel_2.0.0.274_x64__8wekyb3d8bbwe\common\js\services.js
[2013/07/27 17:14:54 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingTravel_2.0.0.308_x64__8wekyb3d8bbwe\common\js\services.js
[2013/08/10 16:16:32 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingWeather_2.0.0.288_x64__8wekyb3d8bbwe\common\js\services.js
[2013/08/10 16:16:32 | 000,052,388 | —- | M] () MD5=170AC4B9F3DC60E0D38D7CC307CEFD12 – C:\Program Files\WindowsApps\Microsoft.BingWeather_2.0.0.310_x64__8wekyb3d8bbwe\common\js\services.js
[2013/05/10 19:34:46 | 000,007,138 | —- | M] () MD5=20D56CE4E843D60EE9EFBEF6D2A6E24E – C:\Program Files\WindowsApps\ChaChaSearch.ChaChaPushNotification_2.0.1.2_neutral__62vv7yjt7tgyp\js\services.js
[2013/05/10 19:34:46 | 000,007,138 | —- | M] () MD5=20D56CE4E843D60EE9EFBEF6D2A6E24E – C:\Program Files\WindowsApps\ChaChaSearch.ChaChaPushNotification_2.0.1.5_neutral__62vv7yjt7tgyp\js\services.js
[2012/07/26 02:54:02 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingFinance_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 02:53:53 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingNews_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 02:53:50 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingSports_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 02:54:33 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingTravel_1.2.0.145_x64__8wekyb3d8bbwe\platform\js\services.js
[2012/07/26 02:53:57 | 000,056,775 | —- | M] () MD5=33C1E65B760A9589F6DE37F64941E449 – C:\Program Files\WindowsApps\Microsoft.BingWeather_1.2.0.135_x64__8wekyb3d8bbwe\platform\js\services.js
[2013/01/09 21:49:56 | 000,069,359 | —- | M] () MD5=6AA9F10CF05F9848EFAA91062BBEB586 – C:\Program Files\WindowsApps\Microsoft.BingFinance_1.7.0.38_x64__8wekyb3d8bbwe\common\js\services.js
[2013/01/09 21:48:12 | 000,069,359 | —- | M] () MD5=6AA9F10CF05F9848EFAA91062BBEB586 – C:\Program Files\WindowsApps\Microsoft.BingNews_1.7.0.38_x64__8wekyb3d8bbwe\common\js\services.js
[2013/01/10 14:50:19 | 000,069,359 | —- | M] () MD5=6AA9F10CF05F9848EFAA91062BBEB586 – C:\Program Files\WindowsApps\Microsoft.BingTravel_1.7.0.26_x64__8wekyb3d8bbwe\Common\js\services.js
[2013/01/09 21:44:12 | 000,069,359 | —- | M] () MD5=6AA9F10CF05F9848EFAA91062BBEB586 – C:\Program Files\WindowsApps\Microsoft.BingWeather_1.7.0.26_x64__8wekyb3d8bbwe\common\js\services.js
[2013/01/09 21:02:15 | 000,006,271 | —- | M] () MD5=70C3BFEF8C7A6FEF764BB4B737935AC3 – C:\Program Files\WindowsApps\ChaChaSearch.ChaChaPushNotification_1.1.3.0_neutral__62vv7yjt7tgyp\js\services.js
[2013/01/23 19:27:38 | 000,069,359 | —- | M] () MD5=80CE8A6918A7BDB5328F93F4A3BB26B0 – C:\Program Files\WindowsApps\Microsoft.BingSports_1.8.0.51_x64__8wekyb3d8bbwe\common\js\services.js
[2012/07/31 22:27:04 | 000,004,761 | —- | M] () MD5=9D136FCA750DBB05B52AB77A35D536D6 – C:\Program Files\WindowsApps\ChaChaSearch.ChaChaPushNotification_1.0.0.32_neutral__62vv7yjt7tgyp\js\services.js
< MD5 for: SERVICES.LNK >
[2012/07/25 15:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 15:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2012/07/25 15:19:37 | 000,001,158 | —- | M] () MD5=5C11B0E362D426FD6E99B07705BA4A48 – C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_282d8a08cf7f1ada\services.lnk
< MD5 for: SERVICES.MOF >
[2012/06/02 09:35:05 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\SysNative\wbem\services.mof
[2012/06/02 09:35:05 | 000,002,866 | —- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 – C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.2.9200.16384_none_282967cc570d3701\services.mof
< MD5 for: SERVICES.MSC >
[2012/07/26 02:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysNative\en-US\services.msc
[2012/06/02 09:31:20 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysNative\services.msc
[2012/07/26 02:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysWOW64\en-US\services.msc
[2012/06/02 09:31:13 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\SysWOW64\services.msc
[2012/07/26 02:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.2.9200.16384_en-us_fd08be678622fdab\services.msc
[2012/06/02 09:31:20 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_282d8a08cf7f1ada\services.msc
[2012/06/02 09:31:13 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\wow64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.2.9200.16384_none_3282345b03dfdcd5\services.msc
[2012/07/26 02:48:57 | 000,092,746 | —- | M] () MD5=2D8D95469EC26AAA986AAD1CE424E631 – C:\Windows\WinSxS\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.2.9200.16384_en-us_a0ea22e3cdc58c75\services.msc
< MD5 for: SERVICES.PTXML >
[2012/07/25 15:30:54 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2012/07/25 15:30:54 | 000,001,061 | —- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 – C:\Windows\WinSxS\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.2.9200.16384_none_282967cc570d3701\Services.ptxml
< MD5 for: SERVICES.SBS >
[2011/03/01 00:00:00 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files (x86)\Spybot - Search & Destroy 2\Includes\Services.sbs
[2011/03/01 02:58:46 | 000,034,818 | —- | M] () MD5=62AFD4B2025CE6D4706B36F4C4808F9B – C:\Program Files (x86)\Spybot - Search & Destroy 2\Updates\Extracts\Services.sbs
< MD5 for: SERVICES.SBS-20110301.CAB >
[2013/09/08 12:48:51 | 000,041,248 | —- | M] () MD5=149FF3413EED31253183D6E65E383138 – C:\Program Files (x86)\Spybot - Search & Destroy 2\Updates\Downloads\Services.sbs-20110301.cab
< MD5 for: WINLOGON.ADML >
[2012/07/26 02:49:05 | 000,008,017 | —- | M] () MD5=C270056255498A723E7331EFF1AA162F – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.2.9200.16384_en-us_edcdb8ec66a62fc0\WinLogon.adml
< MD5 for: WINLOGON.ADMX >
[2012/06/02 09:34:22 | 000,005,237 | —- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.2.9200.16384_none_d3d704270306719d\WinLogon.admx
< MD5 for: WINLOGON.EXE >
[2012/09/20 01:33:55 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=1F84B5F8DBDFFD36DF143C61CE25F12A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16420_none_c8c988c15e88a211\winlogon.exe
[2012/09/20 01:33:17 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=6522E98C94A2A81AE11EB66D2AF5743A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20521_none_c95425d677a55b32\winlogon.exe
[2012/07/25 22:08:50 | 000,516,608 | —- | M] (Microsoft Corporation) MD5=93AB226C07A9789B2EC7B41F73602F76 – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16384_none_c88ca87b5eb5b1ec\winlogon.exe
[2013/04/04 14:50:32 | 000,218,184 | —- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC – C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe
[2012/10/11 00:46:58 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E – C:\Windows\SysNative\winlogon.exe
[2012/10/11 00:46:58 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=BCF2036A0DD579E47C008C133550283E – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.16433_none_c8c1b9b35e8e0a07\winlogon.exe
[2012/10/11 00:45:27 | 000,517,120 | —- | M] (Microsoft Corporation) MD5=CBFD56B4EC07CB056A6ABD55DD33671F – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.2.9200.20534_none_c94c56c877aac328\winlogon.exe
[2013/09/01 23:24:56 | 000,000,000 | —- | M] () MD5=D41D8CD98F00B204E9800998ECF8427E – C:\Windows\SysWOW64\winlogon.exe
< MD5 for: WINLOGON.EXE.MUI >
[2012/07/26 02:48:51 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=B9094B7088CD579E5AED57A693F9BFBD – C:\Windows\SysNative\en-US\winlogon.exe.mui
[2012/07/26 02:48:51 | 000,024,064 | —- | M] (Microsoft Corporation) MD5=B9094B7088CD579E5AED57A693F9BFBD – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.2.9200.16384_en-us_23c238ef8ddaa831\winlogon.exe.mui
< MD5 for: WINLOGON.MFL >
[2012/07/26 02:48:52 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2012/07/26 02:48:52 | 000,001,080 | —- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.2.9200.16384_en-us_81848abaa91301c6\winlogon.mfl
< MD5 for: WINLOGON.MOF >
[2012/07/25 15:30:16 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\SysNative\wbem\winlogon.mof
[2012/07/25 15:30:16 | 000,003,192 | —- | M] () MD5=DF722B96F32A61783BC310FACF10240B – C:\Windows\WinSxS\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.2.9200.16384_none_d9027134ffac135f\winlogon.mof
< %SYSTEMDRIVE%\*.* >
[2013/09/10 20:48:02 | 000,000,000 | —- | M] () – C:\autoexec.bat
[2012/06/02 09:30:55 | 000,000,001 | -HS- | M] () – C:\BOOTNXT
[2013/09/11 07:06:08 | 3068,764,160 | -HS- | M] () – C:\hiberfil.sys
[2013/01/21 17:09:41 | 000,000,040 | —- | M] () – C:\log.txt
[2013/09/11 07:06:09 | 671,088,640 | -HS- | M] () – C:\pagefile.sys
[2013/09/11 07:06:09 | 268,435,456 | -HS- | M] () – C:\swapfile.sys
< %systemroot%\Fonts\*.com >
[2012/08/03 00:14:00 | 000,026,040 | —- | M] () – C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2012/08/03 00:14:00 | 000,026,489 | —- | M] () – C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2012/08/03 00:14:00 | 000,029,779 | —- | M] () – C:\Windows\Fonts\GlobalSerif.CompositeFont
[2012/08/03 00:14:00 | 000,043,318 | —- | M] () – C:\Windows\Fonts\GlobalUserInterface.CompositeFont
< %systemroot%\Fonts\*.dll >
< %systemroot%\Fonts\*.ini >
[2012/07/26 03:11:41 | 000,000,065 | —- | M] () – C:\Windows\Fonts\desktop.ini
< %systemroot%\Fonts\*.ini2 >
< %systemroot%\Fonts\*.exe >
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
< %systemroot%\REPAIR\*.bak1 >
< %systemroot%\REPAIR\*.ini >
< %systemroot%\system32\*.jpg >
< %systemroot%\*.jpg >
< %systemroot%\*.png >
< %systemroot%\*.scr >
[2013/08/30 02:47:40 | 000,041,664 | —- | M] (AVAST Software) – C:\Windows\avastSS.scr
[2 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
< %systemroot%\*._sy >
< %APPDATA%\Adobe\Update\*.* >
< %ALLUSERSPROFILE%\Favorites\*.* >
< %APPDATA%\Microsoft\*.* >
< %PROGRAMFILES%\*.* >
[2012/07/26 03:11:35 | 000,000,174 | -HS- | M] () – C:\Program Files (x86)\desktop.ini
< %APPDATA%\Update\*.* >
< %systemroot%\*. /mp /s >
< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is Acer
Volume Serial Number is EC20-BBE4
Directory of C:\
07/26/2012 02:22 AM Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/26/2012 02:22 AM Application Data [C:\ProgramData]
07/26/2012 02:22 AM Desktop [C:\Users\Public\Desktop]
07/26/2012 02:22 AM Documents [C:\Users\Public\Documents]
07/26/2012 02:22 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/26/2012 02:22 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/26/2012 02:22 AM All Users [C:\ProgramData]
07/26/2012 02:22 AM Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/26/2012 02:22 AM Application Data [C:\ProgramData]
07/26/2012 02:22 AM Desktop [C:\Users\Public\Desktop]
07/26/2012 02:22 AM Documents [C:\Users\Public\Documents]
07/26/2012 02:22 AM Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/26/2012 02:22 AM Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/26/2012 02:22 AM Application Data [C:\Users\Default\AppData\Roaming]
07/26/2012 02:22 AM Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/26/2012 02:22 AM Local Settings [C:\Users\Default\AppData\Local]
07/26/2012 02:22 AM My Documents [C:\Users\Default\Documents]
07/26/2012 02:22 AM NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/26/2012 02:22 AM PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/26/2012 02:22 AM Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/26/2012 02:22 AM SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/26/2012 02:22 AM Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/26/2012 02:22 AM Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/26/2012 02:22 AM Application Data [C:\Users\Default\AppData\Local]
07/26/2012 02:22 AM History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/26/2012 02:22 AM Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Default\Documents
07/26/2012 02:22 AM My Music [C:\Users\Default\Music]
07/26/2012 02:22 AM My Pictures [C:\Users\Default\Pictures]
07/26/2012 02:22 AM My Videos [C:\Users\Default\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/26/2012 02:22 AM My Music [C:\Users\Public\Music]
07/26/2012 02:22 AM My Pictures [C:\Users\Public\Pictures]
07/26/2012 02:22 AM My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Regina
01/08/2013 06:42 PM Application Data [C:\Users\Regina\AppData\Roaming]
01/08/2013 06:42 PM Cookies [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Cookies]
01/08/2013 06:42 PM Local Settings [C:\Users\Regina\AppData\Local]
01/08/2013 06:42 PM My Documents [C:\Users\Regina\Documents]
01/08/2013 06:42 PM NetHood [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/08/2013 06:42 PM PrintHood [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
01/08/2013 06:42 PM Recent [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Recent]
01/08/2013 06:42 PM SendTo [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\SendTo]
01/08/2013 06:42 PM Start Menu [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Start Menu]
01/08/2013 06:42 PM Templates [C:\Users\Regina\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Regina\AppData\Local
01/08/2013 06:42 PM Application Data [C:\Users\Regina\AppData\Local]
01/08/2013 06:42 PM History [C:\Users\Regina\AppData\Local\Microsoft\Windows\History]
01/08/2013 06:42 PM Temporary Internet Files [C:\Users\Regina\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Regina\Documents
01/08/2013 06:42 PM My Music [C:\Users\Regina\Music]
01/08/2013 06:42 PM My Pictures [C:\Users\Regina\Pictures]
01/08/2013 06:42 PM My Videos [C:\Users\Regina\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
48 Dir(s) 293,247,643,648 bytes free
< %systemroot%\System32\config\*.sav >
< %PROGRAMFILES%\bak. /s >
< %systemroot%\system32\bak. /s >
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
< %systemroot%\system32\config\systemprofile\*.dat /x >
< %systemroot%\*.config >
< %systemroot%\system32\*.db >
< %PROGRAMFILES%\Internet Explorer\*.dat >
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2013/02/18 20:05:14 | 000,000,319 | -HS- | M] () – C:\Users\Regina\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
< %USERPROFILE%\Desktop\*.exe >
< %PROGRAMFILES%\Common Files\*.* >
< %systemroot%\*.src >
< %systemroot%\install\*.* >
< %systemroot%\system32\DLL\*.* >
< %systemroot%\system32\HelpFiles\*.* >
< %systemroot%\system32\rundll\*.* >
< %systemroot%\winn32\*.* >
< %systemroot%\Java\*.* >
< %systemroot%\system32\test\*.* >
< %systemroot%\system32\Rundll32\*.* >
< %systemroot%\AppPatch\Custom\*.* >
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
< End of report >
OTL Extras logfile created on: 9/11/2013 7:54:16 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Regina\Downloads
64bit- An unknown product (Version = 6.2.9200) - Type = NTWorkstation
Internet Explorer (Version = 9.10.9200.16660)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
3.57 Gb Total Physical Memory | 2.39 Gb Available Physical Memory | 66.85% Memory free
4.20 Gb Paging File | 2.93 Gb Available in Paging File | 69.75% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 444.19 Gb Total Space | 273.11 Gb Free Space | 61.49% Space Free | Partition Type: NTFS
Computer Name: CARTER | User Name: Regina | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Extra Registry (SafeList) ==========
========== File Associations ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.html[@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] – C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\]
.cpl [@ = cplfile] – C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] – C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
========== Shell Spawning ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] – "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\\shell\[command]\command]
batfile [open] – "%1" %*
cmdfile [open] – "%1" %*
comfile [open] – "%1" %*
cplfile [cplopen] – %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] – "%1" %*
helpfile [open] – Reg Error: Key error.
htafile [open] – "%1" %*
htmlfile – Reg Error: Key error.
htmlfile [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [print] – "%systemroot%\system32\rundll32.exe" "%systemroot%\system32\mshtml.dll",PrintHTML "%1"
http [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] – %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] – "%1" %*
regfile [merge] – Reg Error: Key error.
scrfile [config] – "%1"
scrfile [install] – rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] – "%1" /S
txtfile – Reg Error: Key error.
Unknown [openas] – %SystemRoot%\system32\OpenWith.exe "%1" (Microsoft Corporation)
Directory [cmd] – cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] – Reg Error: Value error.
Drive [find] – %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] – "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] – Reg Error: Value error.
========== Security Center Settings ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = CE 37 E6 AF FF 6A CD 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
========== Firewall Settings ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0
========== Authorized Applications List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D; 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D; 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D; 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D; 2 Background update service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDTray.exe:*:Enabled:Spybot-S&D; 2 Tray Icon – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDFSSvc.exe:*:Enabled:Spybot-S&D; 2 Scanner Service – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdate.exe:*:Enabled:Spybot-S&D; 2 Updater – (Safer-Networking Ltd.)
"C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe" = C:\Program Files (x86)\Spybot - Search & Destroy 2\SDUpdSvc.exe:*:Enabled:Spybot-S&D; 2 Background update service – (Safer-Networking Ltd.)
========== Vista Active Open Ports Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{00929A60-540C-4D0F-893F-8050E6859F7B}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{082378E6-9FA0-47C7-8328-3F91166DDE0B}" = rport=138 | protocol=17 | dir=out | app=system |
"{2649ADDC-EB10-4805-8498-ED1A7965EFAD}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{29698EC3-320C-4F26-A764-49BCD72270FF}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{29D8DF66-0D28-4B93-81EA-F19A22AF3D36}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |
"{35D7BA01-1022-451D-9F09-CD0D9967BA24}" = lport=10243 | protocol=6 | dir=in | app=system |
"{36FBD585-394C-461B-AD3E-A6FEE174B2FD}" = rport=139 | protocol=6 | dir=out | app=system |
"{3B1427D7-957E-4517-ACB9-48B6484F261F}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{52DA214C-3A7F-48C1-B7D9-01E516A4ED66}" = lport=139 | protocol=6 | dir=in | app=system |
"{53E29F7C-1F5A-4FCD-A812-A05E50E1AE31}" = rport=10243 | protocol=6 | dir=out | app=system |
"{5BBA4783-4C4D-4599-AEBA-0ABC30E3C6EB}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{799570D7-7314-43A1-A363-A3DA1E08CDA8}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{7ADA710A-FCF2-4C2D-820C-C3E5A27A732C}" = lport=9322 | protocol=6 | dir=in | name=ekdiscovery |
"{7DEF645C-7BE3-41A8-83B9-24547379B544}" = lport=445 | protocol=6 | dir=in | app=system |
"{7E729806-295F-411F-BD22-C2E01CC4BB63}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{7FCC2E3F-847A-495F-8E34-A21817816A5E}" = lport=137 | protocol=17 | dir=in | app=system |
"{827E3C62-D14A-4AAA-9307-BC154157DA53}" = lport=2869 | protocol=6 | dir=in | app=system |
"{84B53E96-CF58-45D5-A27B-B1809F628D3B}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{862B86DD-FA75-4AFF-A8D7-BA5C5B8FB91C}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{8A5C3610-A60E-47D9-9DD0-71AF980444C8}" = rport=137 | protocol=17 | dir=out | app=system |
"{AF6652CF-F6D2-4B14-A4C6-8B66A33B7089}" = rport=445 | protocol=6 | dir=out | app=system |
"{C512ED72-D254-4002-8C5E-B65B27E224EA}" = lport=5353 | protocol=17 | dir=in | name=bonjour port 5353 |
"{E5B69F96-62C8-40F5-9839-6067470F8A7B}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |
"{FC514E29-9B87-4B05-8DCE-9DE56C490F7B}" = lport=138 | protocol=17 | dir=in | app=system |
========== Vista Active Application Exception List ==========
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01FE2170-27E2-48B6-B1BD-0D917321F551}" = dir=out | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{028091E3-F294-4980-A98C-43621C690494}" = dir=in | app=c:\program files (x86)\nti\acer backup manager\ischedulesvc.exe |
"{063FB4AA-5975-4194-A2A2-FA8786540DC2}" = dir=out | name=word search |
"{0825F47A-A01F-4682-A339-D9B4785F0C8B}" = dir=out | name=ebay |
"{0B41E1AC-B176-44CB-8EBA-56EA67D71430}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe |
"{110DBBD2-13B9-4F2D-A240-DA367661BEB5}" = dir=in | name=@{microsoft.reader_6.2.9200.20623_x64__8wekyb3d8bbwe?ms-resource://microsoft.reader/resources/shortdisplayname} |
"{12220FA2-64FD-4F5B-944C-A3D926A531F6}" = dir=in | name=skype |
"{1361992B-DAB4-4AEC-AB66-B907822F5742}" = dir=out | name=@{microsoft.bingnews_1.7.0.38_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingnews/resources/news} |
"{143163B5-94D9-4C0A-89C0-2310EDD3B4AD}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |
"{1A839730-329C-466B-AB3F-2D7B28C84A6B}" = dir=out | name=drag race online |
"{1FAFC1F6-9A9E-467A-B32E-BFF50EDF9EB1}" = dir=in | name=drivehq filemanager |
"{22397173-91A6-4D2F-8FAE-142C974F6EB8}" = dir=out | name=stumbleupon |
"{22F47221-98CE-4D42-8115-FF4FF4D795CA}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\dmcdaemon.exe |
"{239577D0-E7B4-4A50-BEEA-A7603F8305EA}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{23BF3870-D9DA-4F2B-AC57-13BF2BAED664}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{255F5B22-8D78-4D93-B411-C2B905728468}" = dir=out | name=netflix |
"{27AF884A-9D42-4159-8981-033569C0A0F4}" = dir=in | app=c:\program files (x86)\samsung\allshare\allshareagent.exe |
"{28A42902-A8E9-4904-8A05-606CB2946558}" = dir=out | name=social jogger |
"{29242695-A779-4C70-BBF0-8BDE516545FF}" = dir=out | name=shark dash |
"{2BA19AEA-EEF9-49DE-A15F-557B32A288EB}" = dir=out | name=piano8 |
"{2BFB88B2-58B9-4191-BEF0-6572CED5669D}" = dir=in | app=c:\program files (x86)\nti\acer backup manager\backupmanager.exe |
"{2D94F3F8-6FDC-4E5C-9356-703272F0ABF5}" = dir=out | name=deal or no deal+ |
"{3A7690D6-CB12-46A7-AEFF-61EB6E423183}" = dir=in | app=c:\program files (x86)\acer\clear.fi sdk21\video\videoplayer.exe |
"{3AD2D436-1B9A-4333-A692-A1F570677540}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe |
"{3B6E4396-8001-497C-9944-4E2DA505A775}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{3D39256B-9D5A-484E-B0FB-B03235A6EC7A}" = dir=in | name=ebay |
"{41A68EBE-C91E-4BEB-A4A0-8BAC979978BA}" = dir=out | name=chacha |
"{421D1E91-FCB1-4E61-BD82-44AFBFD12638}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |
"{4370A49C-F8EF-4C66-8C7C-FD47C9BFACAD}" = dir=in | app=c:\program files (x86)\nti\acer backup manager\fileexplorer.exe |
"{45CA8BF8-74FC-4829-878C-4D8999A5A001}" = dir=out | name=dog sounds |
"{4765DEF9-ADC3-46CA-9C3D-2D095E6C5144}" = dir=in | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{483C0C00-75B4-486D-A2A6-04F3A4F0D58C}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |
"{4DC69ED9-489F-49CC-9CAA-5D6DE18566EF}" = dir=out | name=@{microsoft.microsoftskydrive_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.microsoftskydrive/resources/shortproductname} |
"{4E6B9D69-053E-4E87-BCE8-28D2F16C5962}" = protocol=6 | dir=in | app=c:\programdata\kodak\installer\setup.exe |
"{56ACC02B-2B24-4604-9432-61BD3B4C0B1F}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe |
"{58F0606E-8B82-4F93-8104-FD1705BB01FB}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe |
"{59ACD79A-8FE0-4BB9-A7D8-CC4A079FB31C}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{5B3A091C-6F7B-4374-BFF7-76BBDB6FB3E1}" = protocol=17 | dir=in | app=c:\programdata\kodak\installer\setup.exe |
"{5B54CB76-EB22-4040-ACBB-6CD95C494B94}" = dir=out | name=encyclopaedia britannica |
"{5EB662BD-B55D-4846-B3E5-25208D86E111}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{5FF6B2D4-A961-47AB-9661-7268B7F42170}" = dir=out | name=fresh paint |
"{5FFDFE27-B877-4F59-8CE6-30BB8904F207}" = dir=out | name=@{microsoft.xboxlivegames_1.2.143.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.xboxlivegames/resources/34150} |
"{6149CB6D-3700-4372-A6B9-E905108A4484}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{61D0B53A-6D13-4556-B98D-1382D1B1B982}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\clear.fi media\dmcdaemon.exe |
"{63BC5F3F-6D38-438C-9927-3AFE585664F7}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6480C03A-CAD1-46CC-B679-4D59B8FB3E93}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{6529267A-A9C0-4843-8CE3-8D13E18E5251}" = dir=out | name=acer crystal eye |
"{688C0821-D67C-4C65-9B06-4C045A5F6A08}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{69EE3068-FFB8-4EA8-AFB1-48D87B1E7130}" = dir=out | name=windows_ie_ac_001 |
"{6A2696D4-CC45-4788-938F-435B3420402C}" = dir=out | name=family guy soundboard |
"{6B2863F9-5CB2-4A58-AC04-015D9D515510}" = protocol=6 | dir=out | app=system |
"{6BF39DE6-8DFE-4B3A-B99D-6B8F50C1675C}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\acer cloud\ccd.exe |
"{6CA5294F-D314-48BC-BE79-1B2D8AB94E42}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{6D2D0B06-A70C-4AB6-840A-64B3BC481942}" = dir=out | name=@{microsoft.bingweather_1.7.0.26_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingweather/resources/apptitle} |
"{6E554D2D-E946-461A-9FAA-A172AD335C66}" = dir=out | name=kindle |
"{7021E4FB-DFC3-400A-BA7F-D706D2DDAC50}" = dir=out | name=@{7289elapietro.paint4kids_2.8.1.139_neutral__69wh28dtbwp4w?ms-resource://7289elapietro.paint4kids/resources/appname} |
"{704A3DA1-E90B-4AD8-8EFE-399E9A1C603F}" = dir=out | name=evernote touch |
"{71315664-804C-49B6-986E-BAB15C25B38B}" = dir=out | name=angry birds space |
"{717C54AF-BA54-4D53-9AA0-8F206C530423}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{79A88146-F858-4013-88FD-9D494DC47418}" = dir=out | name=@{microsoft.bing_1.5.1.259_x64__8wekyb3d8bbwe?ms-resource://microsoft.bing/resources/app_name} |
"{808F1451-4108-46FD-ADBB-F17324B5F0BD}" = dir=out | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{847F8450-6DD6-4ECF-B1A5-C9A703DDBA66}" = dir=out | name=special force anti-terrorism |
"{8685FA38-568A-4B42-A49E-51ACF67FE0B0}" = dir=out | name=@{microsoft.bingfinance_1.7.0.38_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingfinance/resources/apptitle} |
"{8864B097-D523-4456-BB94-3AD19CC38B63}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{917B1786-4EB6-4AA7-921E-98897FF9D6B4}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{95C5EF66-31EE-4004-93E6-B1DCE00A0FCF}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi photo\windowsupnp.exe |
"{978E988B-3934-4D4A-AAF5-F099EAD0B6A8}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{9A6508D3-FDB1-49B5-804B-827BD344D1AF}" = dir=out | name=the treasures of montezuma 3 |
"{9C8A6BFE-92DA-4FCC-BBE5-E1548839B027}" = dir=out | name=@{microsoft.bingsports_1.8.0.51_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingsports/resources/bingsports} |
"{A0CDB13C-78F8-46A0-8C40-594110E7DFC5}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{A15546F0-1B45-4B61-87AB-C284D8CBEBB1}" = dir=out | name=drivehq filemanager |
"{A40FAF15-DCCC-46DC-B350-CE3D52400AF5}" = dir=out | name=acer explorer |
"{ADE4A962-DC55-4118-842A-498A466F211C}" = dir=in | name=newsxpresso |
"{B085D162-875C-4177-8976-7857957F2D98}" = dir=out | name=real cat sounds |
"{B9045028-8375-4B6A-A9D0-50B6E5AFC911}" = dir=out | name=skitch touch |
"{B93617FC-7C77-4A76-B7BB-7754952201FE}" = dir=out | name=@{microsoft.bingmaps_1.5.1.240_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingmaps/resources/appdisplayname} |
"{B973C7D2-2D3A-4646-8440-EF47DD6F7B9F}" = dir=out | name=amazon |
"{BAB46863-F665-40A1-B38F-759B4080804A}" = dir=out | name=@{microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{BC334CBF-B088-4C76-9478-DBB921BA094E}" = dir=out | name=@{microsoft.zunevideo_1.2.150.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunevideo/resources/33270} |
"{BE8E4AFE-0C8D-4B16-B4C5-A5131B723725}" = dir=out | name=@{microsoft.zunemusic_1.2.150.0_x64__8wekyb3d8bbwe?ms-resource://microsoft.zunemusic/resources/33273} |
"{C29FC607-640F-4CE6-8ADC-24F031754B03}" = dir=out | name=skype |
"{C321BDF4-A70B-48CC-9AC2-1EBD8FE42CFC}" = dir=out | name=kick the can |
"{C4C597E5-F7A5-43A6-BDA9-75C1CA8062D9}" = dir=out | name=taptiles |
"{C5B09ABC-45D4-4499-B909-07D3BA3DFF35}" = protocol=17 | dir=in | app=c:\program files (x86)\acer\acer cloud\ccd.exe |
"{C8C8A043-B6BA-48F0-9610-F99113F62953}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |
"{C8FAB5D6-AC89-4F01-8539-DD4817B53E74}" = dir=in | app=c:\program files (x86)\samsung\allshare\allshare.exe |
"{CAAC6B64-1BB6-478B-966E-B8451A1C00A1}" = dir=out | name=tomb hunter |
"{CBD272D6-CB0F-4B1B-8853-9B973B1A0E09}" = dir=in | app=c:\program files (x86)\samsung\allshare\allsharedms\allsharedms.exe |
"{D0BDEF29-9BD1-483F-A86F-48BDB8C1F141}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{D39EDE1F-DA37-4CE4-9DC7-EF8ED91E4D69}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{D56012D6-2AA5-4D7D-8A3C-ABD2C33B3AF2}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{D59A2EDF-A3FD-41A0-A700-AD1739FB3DD7}" = dir=out | name=newsxpresso |
"{D5F3B473-014A-4D8B-BC69-6B73B4570B8A}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{D6DDD32E-CCE5-4031-9C8A-0F44947C1C7D}" = dir=out | name=7digital music store |
"{D77EF8B8-2C3C-4A65-A0A0-26C41BAB3ACA}" = dir=in | name=@{microsoft.windowscommunicationsapps_17.0.1114.318_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowscommunicationsapps/resources/communicationspackagename} |
"{DD2B056D-08D3-462A-8016-6FAC87771E7B}" = dir=in | name=acer explorer |
"{E128FC6F-2990-4BEB-AF0E-1521D0D4C346}" = dir=out | name=@{microsoft.windowsphotos_16.4.4388.928_x64__8wekyb3d8bbwe?ms-resource://microsoft.windowsphotos/photo/residappname} |
"{E2FDA25A-5C0B-40C2-BE88-933D8B452ECD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{E5049241-1C0B-4090-AB8B-D73B5BCE17AD}" = dir=in | name=evernote touch |
"{E606C57B-70F6-4723-99FE-D5C1A0DD4836}" = dir=out | name=@{microsoft.bingtravel_1.7.0.26_x64__8wekyb3d8bbwe?ms-resource://microsoft.bingtravel/resources/apptitle} |
"{E7985E1D-C36F-4787-80A8-6350D07E9266}" = dir=in | name=@{c:\windows\winstore\resources.pri?ms-resource://winstore/resources/displayname} |
"{E7F9229F-BC69-4916-A021-D4591209BD77}" = protocol=6 | dir=in | app=c:\program files (x86)\acer\clear.fi media\windowsupnpmv.exe |
"{FD5899D2-A56D-404E-946C-DB21CF24B8BB}" = dir=out | name=icookbook se |
"TCP Query User{F55858F7-A60F-4497-8232-646BE5B41187}C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe" = protocol=6 | dir=in | app=c:\program files (x86)\spybot - search & destroy 2\sdupdate.exe |
"UDP Query User{3D7780EF-AB64-4235-889B-039BD7FE3322}C:\program files (x86)\spybot - search & destroy 2\sdupdate.exe" = protocol=17 | dir=in | app=c:\program files (x86)\spybot - search & destroy 2\sdupdate.exe |
========== HKEY_LOCAL_MACHINE Uninstall List ==========
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{07F2005A-8CAC-4A4B-83A2-DA98A722CA61}" = Acer Recovery Management
"{0B78ECB0-1A6B-4E6D-89D7-0E7CE77F0427}" = MyWinLocker
"{1F557316-CFC0-41BD-AFF7-8BC49CE444D7}" = Shredder
"{237D687E-9E50-4A30-B810-262764CC491B}" = Garmin Communicator Plugin x64
"{2F1EB597-74DA-2C71-C065-BF4C6B89062C}" = AMD Accelerated Video Transcoding
"{2F72F540-1F60-4266-9506-952B21D6640D}" = Apple Mobile Device Support
"{3F62D2FD-13C1-49A2-8B5D-47623D9460D7}" = Acer Device Fast-lane
"{427174C0-096E-40D9-9684-9C109BEE2CBF}" = iTunes
"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7BABDF85-566A-FCC6-E6FE-12DCFF3F9FEB}" = AMD Catalyst Install Manager
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{91F52DE4-B789-42B0-9311-A349F10E5479}" = Acer Power Management
"{CE02F046-9083-701A-0996-96190306DD5E}" = ccc-utility64
"{DA5E371C-6333-3D8A-93A4-6FD5B20BCC6E}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.30319
"{EF79C448-6946-4D71-8134-03407888C054}" = Shared C Run-time for x64
"CCleaner" = CCleaner
"Elantech" = ETDWare PS/2-X64 11.6.11.002_WHQL
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0CB90E9C-E1C9-4A83-04D3-BF7A6CB9C376}" = CCC Help Japanese
"{0CCE1791-4AD2-0202-2FE9-308D47482C46}" = CCC Help Spanish
"{0F4A9F62-336C-A3DB-3DCB-5E35CCF908D3}" = CCC Help Finnish
"{136F0577-FF5A-3978-4535-3F8034697982}" = AMD VISION Engine Control Center
"{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1FCC073B-CC01-4443-AD20-E559F66E6E83}" = Office Addin 2003
"{234378F3-28CC-9038-8732-DE44FCD53384}" = CCC Help German
"{25347987-6E58-A41F-19D8-D55EACF69DAF}" = CCC Help French
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR81Family Gigabit/Fast Ethernet Driver
"{32DD0880-9000-988D-28FA-CBEC75ADE655}" = CCC Help Swedish
"{33FA327B-E7E2-4E38-BF1A-67DCE285BD5C}" = Catalyst Control Center - Branding
"{35DA427D-BB23-49B8-9AFD-CFFCFE3B708D}" = clear.fi SDK- Movie 2
"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime
"{39F15B50-A977-4CA6-B1C3-6A8724CDA025}" = MyWinLocker 4
"{3D9CB654-99AD-4301-89C6-0D12A790767C}" = Identity Card
"{3EADFC9D-5747-1F40-B2C9-35EDB21C3B7A}" = CCC Help Portuguese
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{4993BB61-D98D-8AC1-3F15-1DF54E51192C}" = CCC Help Danish
"{4B79E2D3-C5CF-3A41-929E-4FD8D90EE1C3}" = CCC Help Korean
"{5D09C772-ECB3-442B-9CC6-B4341C78FDC2}" = Apple Application Support
"{647BB978-2876-487B-9B0E-FDB73F0EA4A2}" = Garmin Communicator Plugin
"{65135558-F1AE-4B9B-8C0B-180730ACA261}" = Garmin Express
"{679F4771-F0E8-BB49-1CB7-6FEEA109DE6A}" = CCC Help Thai
"{698B2C9E-A1B6-37F7-C1E1-EEE252ADC1D0}" = CCC Help Czech
"{6D2BBE1D-E600-4695-BA37-0B0E605542CC}" = Office Addin
"{6EC7E0E1-5BCA-A74E-CA99-79E765BB271E}" = Catalyst Control Center Localization All
"{700EC2DC-84AC-1C3E-0106-CB11B5B4F7D3}" = CCC Help Dutch
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-acer" = WildTangent Games App
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-wildgames" = WildTangent Games App
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{74D10916-2A98-A824-3CA2-9668D64A0231}" = CCC Help Greek
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{876AB032-B2A4-41FF-AF87-DBC78454C1B0}" = Garmin Update Service
"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime
"{9100F286-8053-6382-2DF1-8F50F9E17597}" = CCC Help Italian
"{93765DFA-8A67-41FB-9FC0-B12341CA65F3}" = Elevated Installer
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9B46C84F-4985-42F7-9AFC-437B53C84397}" = Bad Piggies
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D3D8C60-A55F-4123-B2B9-173F09590E16}" = REALTEK Wireless LAN Driver
"{9DDDF20E-9FD1-4434-A43E-E7889DBC9420}" = Backup Manager v4
"{A0E1F04B-9B85-5EEB-86C4-435567588EC3}" = CCC Help Norwegian
"{A3DD31D0-9B99-7222-B038-7D7EF43ED72C}" = Catalyst Control Center InstallProxy
"{A5AD0B17-F34D-49BE-A157-C8B3D52ACD13}" = AcerCloud
"{A6ACFAF3-71E6-88DC-083B-C21F15D2C334}" = CCC Help Russian
"{A81456C9-8CAA-4424-BB9D-E330FDDA717E}" = Samsung Simple Upgrade Tool for SCH-I500 EH09
"{B4092C6D-E886-4CB2-BA68-FE5A99D31DE7}_is1" = Spybot - Search & Destroy
"{B58AC487-F6E9-336E-204C-DD48F0057CDD}" = CCC Help English
"{B5AD89F2-03D3-4206-8487-018298007DD0}" = clear.fi Photo
"{B860F5DA-9908-FF57-005C-3BBABDB60E7A}" = CCC Help Chinese Standard
"{C1594429-8296-4652-BF54-9DBE4932A44C}" = Realtek PCIE Card Reader
"{C233BCC3-29C4-49C0-B955-0A94509FC4FC}" = Garmin Express Tray
"{C2695E83-CF1D-43D1-84FE-B3BEC561012A}" = Shredder
"{CA4FE8B0-298C-4E5D-A486-F33B126D6A0A}" = AcerCloud Docs
"{D0F2B581-5AE4-70B3-95D0-E761BC89E686}" = CCC Help Hungarian
"{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"{D3EAAC35-98A9-8231-2648-0C3BB84606A6}" = CCC Help Polish
"{DA5BDB2A-12F0-4343-8351-21AAEB293990}" = PreReq
"{DF47ACA3-7C78-4C08-8007-AC682563C9F1}" = Samsung AllShare
"{e47a5c85-88a2-47d2-b380-fc2e763c2e6d}" = Garmin Express
"{E99A5F3B-50D0-F66F-6FDB-C0DC1B90973E}" = CCC Help Turkish
"{E9AF1707-3F3A-49E2-8345-4F2D629D0876}" = clear.fi Media
"{EB8920E9-5534-2E03-BE4B-B050C9736676}" = Catalyst Control Center Graphics Previews Common
"{EBA33CAD-E071-48d5-A168-FBA4EEB42E93}" = clear.fi SDK - Video 2
"{EE26E302-876A-48D9-9058-3129E5B99999}" = Live Updater
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F2F8656A-BDEC-0852-D9FB-8088B9357EA5}" = CCC Help Chinese Traditional
"avast" = avast! Free Antivirus
"InstallShield_{17DF9714-60C9-43C9-A9C2-32BCAED44CBE}" = MyWinLocker Suite
"InstallShield_{9DDDF20E-9FD1-4434-A43E-E7889DBC9420}" = Acer Backup Manager
"InstallShield_{A81456C9-8CAA-4424-BB9D-E330FDDA717E}" = Samsung Simple Upgrade Tool for SCH-I500 EH09
"InstallShield_{D3D5C4E8-040F-4C6F-8105-41D43CF94F44}" = NTI Media Maker 9
"InstallShield_{DF47ACA3-7C78-4C08-8007-AC682563C9F1}" = Samsung AllShare
"LManager" = Launch Manager
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime
"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime
"WildTangent wildgames Master Uninstall" = WildTangent Games
"WTA-060ae6b0-2d42-4a1a-b236-a73fe2e491a7" = Penguins!
"WTA-2d7fdb82-c38c-4ed9-8547-860ca22c3a1a" = Peggle Nights
"WTA-3ff7da3a-cdba-4ca5-847b-dcd3f24cf195" = Jewel Match 3
"WTA-6437089d-43db-4138-bad3-ca1751586a6d" = Tales of Lagoona
"WTA-7f763398-b50e-4ceb-a417-410d9597e147" = Polar Bowler
"WTA-80fff23a-de75-4b51-890f-51f2c5ea205c" = Cradle Of Egypt Collector's Edition
"WTA-81dbd76b-3727-48ab-8245-53fb940f2d30" = Zuma's Revenge
"WTA-8937668d-53e7-420f-884c-ac073c964511" = Agatha Christie - Death on the Nile
"WTA-d5ab2698-2035-4194-9fb9-85ec8094147d" = Final Drive: Nitro
"WTA-dff0051a-5cfe-4847-8156-8d2c7928a4ec" = Polar Golfer
"WTA-e620d2e6-d682-4882-b2bb-1e07b73a3f65" = Mystery P.I. - Curious Case of Counterfeit Cove
"WTA-eaa449b7-f52f-4a15-bf27-0f433d595ae2" = Aloha TriPeaks
"WTA-f6862d50-5000-48f8-a1fb-596e5a337cc0" = Bejeweled 3
"WTA-f86d7cc9-c6c7-4381-bd4c-4eefa715957a" = Plants vs. Zombies - Game of the Year
"WTA-f9cc76d0-83bf-466e-a0fa-6d53946c6712" = Dora's World Adventure
"WTA-fd48042d-469e-47f6-9498-0b7e56e3d235" = Delicious: Emily's True Love Premium Edition
========== HKEY_CURRENT_USER Uninstall List ==========
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Google Chrome" = Google Chrome
========== Last 20 Event Log Errors ==========
[ Application Events ]
Error - 9/8/2013 3:19:49 PM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\PowerPointAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.Manifest" on line 4.
The
element asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
Error - 9/8/2013 3:21:20 PM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\ExcelAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\ExcelAddIn2003.dll.Manifest" on line 4. The element
asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
Error - 9/8/2013 3:21:20 PM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\WordAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\WordAddIn2003.dll.Manifest" on line 4. The element
asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
Error - 9/8/2013 3:21:20 PM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\PowerPointAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.Manifest" on line 4.
The
element asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
Error - 9/8/2013 3:33:01 PM | Computer Name = Carter | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image
of service Datamngr Coordinator since QueryServiceConfig API failed System Error:
The
system cannot find the file specified. .
Error - 9/8/2013 3:33:47 PM | Computer Name = Carter | Source = Microsoft-Windows-CAPI2 | ID = 513
Description = Cryptographic Services failed while processing the OnIdentity() call
in the System Writer Object. Details: AddWin32ServiceFiles: Unable to back up image
of service Datamngr Coordinator since QueryServiceConfig API failed System Error:
The
system cannot find the file specified. .
Error - 9/8/2013 8:26:30 PM | Computer Name = Carter | Source = Application Error | ID = 1000
Description = Faulting application name: DllHost.exe, version: 6.2.9200.16384, time
stamp: 0x50108850 Faulting module name: ntdll.dll, version: 6.2.9200.16579, time
stamp: 0x51637f77 Exception code: 0xc0000005 Fault offset: 0x000000000006daa4 Faulting
process id: 0x840 Faulting application start time: 0x01ceacf33991bab9 Faulting application
path: C:\Windows\system32\DllHost.exe Faulting module path: C:\Windows\SYSTEM32\ntdll.dll
Report
Id: 7854c8e7-18e6-11e3-bede-b888e35b0690 Faulting package full name: Faulting package-relative
application ID:
Error - 9/9/2013 4:01:11 AM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\ExcelAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\ExcelAddIn2003.dll.Manifest" on line 4. The element
asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
Error - 9/9/2013 4:01:11 AM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\WordAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\WordAddIn2003.dll.Manifest" on line 4. The element
asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
Error - 9/9/2013 4:01:11 AM | Computer Name = Carter | Source = SideBySide | ID = 16842824
Description = Activation context generation failed for "C:\Program Files (x86)\Acer\Office
Addin 2003\PowerPointAddIn2003.dll.Manifest".Error in manifest or policy file "C:\Program
Files (x86)\Acer\Office Addin 2003\PowerPointAddIn2003.dll.Manifest" on line 4.
The
element asmv2:clrClassInvocation appears as a child of element urn:schemas-microsoft-com:asm.v1^entryPoint
which is not supported by this version of Windows.
[ Spybot - Search and Destroy Events ]
Error - 9/8/2013 3:32:46 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 3:33:31 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 3:34:26 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 3:34:31 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 3:35:08 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 3:35:17 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 3:36:07 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 5:00:27 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 5:01:55 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
Error - 9/8/2013 9:22:42 PM | Computer Name = Carter | Source = SDCleaner | ID = 100
Description = LoadCleaningInstructions
[ System Events ]
Error - 9/10/2013 4:49:35 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:49:35 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:50:42 PM | Computer Name = Carter | Source = DCOM | ID = 10005
Description =
Error - 9/10/2013 4:51:44 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:51:44 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:51:44 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:52:35 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:52:35 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:52:35 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
Error - 9/10/2013 4:54:42 PM | Computer Name = Carter | Source = Service Control Manager | ID = 7001
Description =
< End of report >