Jump to content

Redirect for Google searches


Recommended Posts

  • Replies 52
  • Created
  • Last Reply

Top Posters In This Topic

Hello hjc1710 and :welcome:! My name is Maniac and I will be glad to help you solve your malware problem.

Please note:

  • If you are a paying customer, you have the privilege to contact the help desk at Consumer Support or here (http://helpdesk.malwarebytes.org/home). If you choose this option to get help, please let me know.
  • I recommend you to keep the instructions I will be giving you so that they are available to you at any time. You can save them in a text file or print them.
  • Make sure you read all of the instructions and fixes thoroughly before continuing with them.
  • Follow my instructions strictly and don’t hesitate to stop and ask me if you have any questions.
  • Post your log files, don't attach them. Every log file should be copy/pasted in your next reply.

Step 1

Please unisntall the following applications:

DC++ 0.799

Uniblue RegistryBooster 2010

Uniblue System Tweaker

Vuze

Vuze_Remote Toolbar

Step 2

Download OTL to your Desktop

  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
  • Please tick the Scan All users. Copy and Paste the following code into the textbox:
    %USERPROFILE%\*.*
    %USERPROFILE%\AppData\Local\*.*
    %USERPROFILE%\AppData\Roaming\*.*
    %windir%\temp\*.*


  • Next, push the RunScan button.
    • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
    • Please copy (Edit->Select All, Edit->Copy) the contents of these files, one at a time and post them in your topic.

Link to post
Share on other sites

Small notes: I've had all 3 of those programs for at least 6 months (some 2 years or so) before this happened. I'm pretty cautious about what I torrent and what I grab over DC++. I've, of course, uninstalled them. Just thought maybe this would help.

Anyway, GeeksToGo came back, here are the OTL logs:

OTL.txt

OTL logfile created on: 7/9/2012 6:05:02 PM - Run 1

OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Hayden\Desktop\downloads

64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7600.16385)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

11.99 Gb Total Physical Memory | 7.60 Gb Available Physical Memory | 63.34% Memory free

23.98 Gb Paging File | 19.42 Gb Available in Paging File | 80.98% Paging File free

Paging file location(s): c:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 931.41 Gb Total Space | 82.37 Gb Free Space | 8.84% Space Free | Partition Type: NTFS

Drive D: | 641.38 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Drive L: | 931.39 Gb Total Space | 467.34 Gb Free Space | 50.18% Space Free | Partition Type: NTFS

Computer Name: HAYDEN-PC | User Name: Hayden | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/07/09 18:02:55 | 000,595,968 | ---- | M] (OldTimer Tools) -- C:\Users\Hayden\Desktop\downloads\OTL.exe

PRC - [2012/06/24 21:47:42 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\SysWOW64\NLSSRV32.EXE

PRC - [2012/06/13 16:53:48 | 001,014,112 | ---- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) -- C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe

PRC - [2012/06/05 16:55:32 | 000,144,896 | ---- | M] (Motorola Mobility Inc.) -- C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoCast.exe

PRC - [2012/06/05 16:55:28 | 000,240,056 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe

PRC - [2012/06/05 11:48:30 | 000,087,400 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe

PRC - [2012/06/04 19:46:02 | 000,116,632 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe

PRC - [2012/05/30 15:01:36 | 000,932,528 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe

PRC - [2012/05/25 10:48:55 | 000,039,816 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\GoToMeeting\952\g2mstart.exe

PRC - [2012/05/25 10:48:55 | 000,039,816 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\GoToMeeting\952\g2mlauncher.exe

PRC - [2012/05/25 10:48:55 | 000,039,816 | ---- | M] (Citrix Online, a division of Citrix Systems, Inc.) -- C:\Program Files (x86)\Citrix\GoToMeeting\952\g2mcomm.exe

PRC - [2012/05/24 13:39:22 | 027,112,840 | ---- | M] (Dropbox, Inc.) -- C:\Users\Hayden\AppData\Roaming\Dropbox\bin\Dropbox.exe

PRC - [2012/05/03 13:07:40 | 000,217,256 | ---- | M] (Visicom Media Inc. (Powered by Panda Security)) -- C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe

PRC - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe

PRC - [2012/04/04 15:56:38 | 000,462,408 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe

PRC - [2012/03/25 07:04:45 | 000,180,648 | ---- | M] (Google Inc.) -- C:\Users\Hayden\AppData\Local\Google\Update\1.3.21.111\GoogleCrashHandler.exe

PRC - [2012/01/26 12:47:32 | 002,077,536 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgtray.exe

PRC - [2012/01/03 08:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe

PRC - [2011/12/06 06:59:12 | 000,212,480 | ---- | M] () -- C:\Program Files (x86)\Subsonic\subsonic-service.exe

PRC - [2011/12/06 06:59:08 | 000,206,336 | ---- | M] () -- C:\Program Files (x86)\Subsonic\subsonic-agent.exe

PRC - [2011/11/14 12:48:52 | 000,161,792 | ---- | M] (CodeLathe LLC) -- C:\Users\Hayden\AppData\Roaming\Tonido\tonido.exe

PRC - [2011/09/10 04:43:18 | 000,018,432 | ---- | M] (Apache Software Foundation) -- C:\xampp\apache\bin\httpd.exe

PRC - [2011/09/10 04:43:18 | 000,018,432 | ---- | M] (Apache Software Foundation) -- c:\xampp\apache\bin\httpd.exe

PRC - [2011/09/09 12:46:10 | 008,158,720 | ---- | M] () -- c:\xampp\mysql\bin\mysqld.exe

PRC - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) -- C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe

PRC - [2011/08/21 17:55:44 | 000,858,696 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDYT.exe

PRC - [2011/08/21 17:55:44 | 000,850,504 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDMovieViewer.exe

PRC - [2011/08/21 17:55:44 | 000,522,824 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsMono-8.00.048\Applets\x86\LCDMedia.exe

PRC - [2011/08/21 17:55:44 | 000,498,248 | ---- | M] (Logitech Inc.) -- C:\Program Files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDWebCam.exe

PRC - [2011/08/02 17:13:53 | 001,242,448 | ---- | M] (Valve Corporation) -- C:\Program Files (x86)\Steam\Steam.exe

PRC - [2011/06/07 14:29:16 | 000,630,272 | ---- | M] (FileZilla Project) -- C:\xampp\FileZillaFTP\FileZillaServer.exe

PRC - [2011/05/25 08:22:42 | 000,925,696 | ---- | M] (full phat products) -- C:\Program Files (x86)\full phat\Snarl\snarl.exe

PRC - [2011/05/02 07:18:28 | 000,139,264 | ---- | M] () -- C:\xampp\xampp-control.exe

PRC - [2011/04/22 12:27:22 | 000,073,216 | ---- | M] (Jonus Conrad & Noer.IT) -- C:\Program Files (x86)\full phat\Snarl\extensions\AudioMon\snarl-audiomon.exe

PRC - [2010/11/24 11:01:03 | 000,725,344 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgcsrvx.exe

PRC - [2010/08/31 23:26:04 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Program Files (x86)\Windows Media Player\wmplayer.exe

PRC - [2010/07/21 08:48:09 | 000,921,952 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgemc.exe

PRC - [2010/06/22 09:01:43 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) -- C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe

PRC - [2010/02/12 10:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe

PRC - [2009/12/21 08:00:50 | 000,081,920 | ---- | M] (Realtime Soft Ltd) -- C:\Program Files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe

PRC - [2009/08/26 22:18:42 | 000,115,200 | ---- | M] () -- C:\Users\Hayden\Desktop\downloads\SirReal\LCDSirReal.exe

PRC - [2009/07/14 00:28:00 | 000,024,576 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysWOW64\Ctxfihlp.exe

PRC - [2009/07/14 00:22:08 | 001,263,616 | ---- | M] (Creative Technology Ltd) -- C:\Windows\SysWOW64\CTxfispi.exe

PRC - [2009/04/02 12:27:26 | 000,090,112 | ---- | M] () -- C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe

PRC - [2008/08/06 16:31:44 | 000,233,576 | ---- | M] (Creative Technology Ltd) -- C:\Program Files (x86)\Creative\Volume Panel\VolPanlu.exe

========== Modules (No Company Name) ==========

MOD - [2012/07/07 19:32:24 | 000,557,056 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Temp\zumotaglib.dll9112996181380918788.lib

MOD - [2012/07/07 19:29:24 | 000,159,744 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Temp\ZumoLocalGateway.dll5659253390722255869.lib

MOD - [2012/07/07 19:29:19 | 000,311,808 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Temp\WindowsFolderWatcher.dll591587765627901584.lib

MOD - [2012/07/07 19:23:30 | 000,509,440 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Temp\sqlite-3.6.20-sqlitejdbc.dll

MOD - [2012/07/07 19:22:30 | 000,203,776 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Temp\WindowsAPI.dll5682529775697862198.lib

MOD - [2012/06/28 05:28:56 | 000,438,296 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppgooglenaclpluginchrome.dll

MOD - [2012/06/28 05:28:54 | 003,972,120 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll

MOD - [2012/06/28 05:27:40 | 000,554,520 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Google\Chrome\Application\20.0.1132.47\libglesv2.dll

MOD - [2012/06/28 05:27:38 | 000,117,784 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Google\Chrome\Application\20.0.1132.47\libegl.dll

MOD - [2012/06/28 05:27:29 | 000,140,328 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Google\Chrome\Application\20.0.1132.47\avutil-51.dll

MOD - [2012/06/28 05:27:28 | 000,262,184 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Google\Chrome\Application\20.0.1132.47\avformat-54.dll

MOD - [2012/06/28 05:27:26 | 002,386,984 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Google\Chrome\Application\20.0.1132.47\avcodec-54.dll

MOD - [2012/06/28 03:27:26 | 009,252,040 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll

MOD - [2012/06/19 21:04:00 | 020,313,384 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\libcef.dll

MOD - [2012/06/19 21:04:00 | 000,214,528 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\mssvoice.asi

MOD - [2012/06/19 21:04:00 | 000,095,744 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\mssmp3.asi

MOD - [2012/06/19 21:03:33 | 000,895,312 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\chromehtml.dll

MOD - [2012/06/19 21:03:32 | 000,123,192 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avutil-51.dll

MOD - [2012/06/19 21:03:31 | 001,099,576 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avcodec-53.dll

MOD - [2012/06/19 21:03:31 | 000,190,776 | ---- | M] () -- C:\Program Files (x86)\Steam\bin\avformat-53.dll

MOD - [2012/06/05 16:55:32 | 000,207,872 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmatroska.dll

MOD - [2012/06/05 16:55:32 | 000,150,528 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmpegdemux.dll

MOD - [2012/06/05 16:55:32 | 000,132,608 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstogg.dll

MOD - [2012/06/05 16:55:32 | 000,075,776 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvideoscale.dll

MOD - [2012/06/05 16:55:32 | 000,061,952 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgsttypefindfunctions.dll

MOD - [2012/06/05 16:55:32 | 000,059,904 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvideobox.dll

MOD - [2012/06/05 16:55:32 | 000,054,784 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstsmpte.dll

MOD - [2012/06/05 16:55:32 | 000,053,760 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvorbis.dll

MOD - [2012/06/05 16:55:32 | 000,051,712 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstsubparse.dll

MOD - [2012/06/05 16:55:32 | 000,050,688 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstwavpack.dll

MOD - [2012/06/05 16:55:32 | 000,047,616 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmpegaudioparse.dll

MOD - [2012/06/05 16:55:32 | 000,042,496 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstwavparse.dll

MOD - [2012/06/05 16:55:32 | 000,039,936 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmpegtsmux.dll

MOD - [2012/06/05 16:55:32 | 000,035,328 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstreplaygain.dll

MOD - [2012/06/05 16:55:32 | 000,034,304 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvolume.dll

MOD - [2012/06/05 16:55:32 | 000,032,768 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvideocrop.dll

MOD - [2012/06/05 16:55:32 | 000,029,184 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstpng.dll

MOD - [2012/06/05 16:55:32 | 000,025,088 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmultipart.dll

MOD - [2012/06/05 16:55:32 | 000,024,576 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstvideorate.dll

MOD - [2012/06/05 16:55:32 | 000,024,576 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmpegvideoparse.dll

MOD - [2012/06/05 16:55:32 | 000,020,480 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmultifile.dll

MOD - [2012/06/05 16:55:32 | 000,015,360 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstmulaw.dll

MOD - [2012/06/05 16:55:32 | 000,013,312 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgsty4menc.dll

MOD - [2012/06/05 16:55:32 | 000,011,264 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstshift.dll

MOD - [2012/06/05 16:55:30 | 002,009,600 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstfluh264dec.dll

MOD - [2012/06/05 16:55:30 | 001,694,208 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstfluaacdec.dll

MOD - [2012/06/05 16:55:30 | 001,563,136 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflump3enc.dll

MOD - [2012/06/05 16:55:30 | 001,520,128 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libvorbisenc-2.dll

MOD - [2012/06/05 16:55:30 | 001,396,736 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libxml2-2.dll

MOD - [2012/06/05 16:55:30 | 001,376,256 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflump3dec.dll

MOD - [2012/06/05 16:55:30 | 000,531,968 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumpeg4video.dll

MOD - [2012/06/05 16:55:30 | 000,363,008 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumpeg2video.dll

MOD - [2012/06/05 16:55:30 | 000,276,480 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstisomp4.dll

MOD - [2012/06/05 16:55:30 | 000,212,480 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstcoreelements.dll

MOD - [2012/06/05 16:55:30 | 000,196,608 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libwavpack-1.dll

MOD - [2012/06/05 16:55:30 | 000,187,904 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstffmpegcolorspace.dll

MOD - [2012/06/05 16:55:30 | 000,162,304 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libvorbis-0.dll

MOD - [2012/06/05 16:55:30 | 000,123,904 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstavi.dll

MOD - [2012/06/05 16:55:30 | 000,122,880 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstfluasfdemux.dll

MOD - [2012/06/05 16:55:30 | 000,119,296 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumpegdemux.dll

MOD - [2012/06/05 16:55:30 | 000,091,136 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstdshowdecwrapper.dll

MOD - [2012/06/05 16:55:30 | 000,088,064 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflummssrc.dll

MOD - [2012/06/05 16:55:30 | 000,086,016 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstdecodebin2.dll

MOD - [2012/06/05 16:55:30 | 000,085,504 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\z.dll

MOD - [2012/06/05 16:55:30 | 000,078,848 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstaudioconvert.dll

MOD - [2012/06/05 16:55:30 | 000,075,776 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflv.dll

MOD - [2012/06/05 16:55:30 | 000,073,216 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstdshowsrcwrapper.dll

MOD - [2012/06/05 16:55:30 | 000,069,120 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflac.dll

MOD - [2012/06/05 16:55:30 | 000,059,904 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstjpeg.dll

MOD - [2012/06/05 16:55:30 | 000,052,224 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstaudioresample.dll

MOD - [2012/06/05 16:55:30 | 000,048,640 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstalpha.dll

MOD - [2012/06/05 16:55:30 | 000,038,400 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstaiff.dll

MOD - [2012/06/05 16:55:30 | 000,037,888 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstgio.dll

MOD - [2012/06/05 16:55:30 | 000,036,864 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumch264enc.dll

MOD - [2012/06/05 16:55:30 | 000,035,840 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstinterleave.dll

MOD - [2012/06/05 16:55:30 | 000,034,304 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstid3tag.dll

MOD - [2012/06/05 16:55:30 | 000,033,280 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstflumcaacenc.dll

MOD - [2012/06/05 16:55:30 | 000,032,256 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstid3demux.dll

MOD - [2012/06/05 16:55:30 | 000,032,256 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstautoconvert.dll

MOD - [2012/06/05 16:55:30 | 000,030,208 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstadder.dll

MOD - [2012/06/05 16:55:30 | 000,029,696 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstgdp.dll

MOD - [2012/06/05 16:55:30 | 000,029,184 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstautodetect.dll

MOD - [2012/06/05 16:55:30 | 000,026,624 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstequalizer.dll

MOD - [2012/06/05 16:55:30 | 000,020,480 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstaudiorate.dll

MOD - [2012/06/05 16:55:30 | 000,020,480 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstamrnb.dll

MOD - [2012/06/05 16:55:30 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstlevel.dll

MOD - [2012/06/05 16:55:30 | 000,019,456 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstauparse.dll

MOD - [2012/06/05 16:55:30 | 000,018,944 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstalaw.dll

MOD - [2012/06/05 16:55:30 | 000,017,920 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstalphacolor.dll

MOD - [2012/06/05 16:55:30 | 000,016,896 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstcutter.dll

MOD - [2012/06/05 16:55:30 | 000,015,360 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstapetag.dll

MOD - [2012/06/05 16:55:30 | 000,014,848 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstamrwbdec.dll

MOD - [2012/06/05 16:55:30 | 000,014,848 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstadpcmdec.dll

MOD - [2012/06/05 16:55:30 | 000,011,776 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\plugins\libgstcoreindexers.dll

MOD - [2012/06/05 16:55:28 | 000,699,392 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstreamer-0.10.dll

MOD - [2012/06/05 16:55:28 | 000,471,552 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\liborc-0.4-0.dll

MOD - [2012/06/05 16:55:28 | 000,331,264 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libFLAC-8.dll

MOD - [2012/06/05 16:55:28 | 000,276,992 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libjpeg-8.dll

MOD - [2012/06/05 16:55:28 | 000,253,440 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstbase-0.10.dll

MOD - [2012/06/05 16:55:28 | 000,248,352 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libopencore-amrnb.0.1.1.dll

MOD - [2012/06/05 16:55:28 | 000,240,056 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe

MOD - [2012/06/05 16:55:28 | 000,190,976 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libpng14-14.dll

MOD - [2012/06/05 16:55:28 | 000,133,120 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgsttag-0.10.dll

MOD - [2012/06/05 16:55:28 | 000,126,976 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstcontroller-0.10.dll

MOD - [2012/06/05 16:55:28 | 000,123,947 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libopencore-amrwb.0.1.1.dll

MOD - [2012/06/05 16:55:28 | 000,109,568 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstaudio-0.10.dll

MOD - [2012/06/05 16:55:28 | 000,098,304 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstpbutils-0.10.dll

MOD - [2012/06/05 16:55:28 | 000,069,632 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstrtp-0.10.dll

MOD - [2012/06/05 16:55:28 | 000,053,760 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstinterfaces-0.10.dll

MOD - [2012/06/05 16:55:28 | 000,041,984 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstriff-0.10.dll

MOD - [2012/06/05 16:55:28 | 000,038,912 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstvideo-0.10.dll

MOD - [2012/06/05 16:55:28 | 000,023,552 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libogg-0.dll

MOD - [2012/06/05 16:55:28 | 000,018,944 | ---- | M] () -- C:\Program Files (x86)\Motorola Mobility\MotoCast\bin\libgstdataprotocol-0.10.dll

MOD - [2012/05/30 15:01:36 | 000,932,528 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe

MOD - [2012/03/16 15:42:58 | 000,315,392 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libtidy.dll

MOD - [2012/03/16 15:42:56 | 000,433,664 | ---- | M] () -- C:\Program Files (x86)\Evernote\Evernote\libxml2.dll

MOD - [2011/12/06 06:59:08 | 000,206,336 | ---- | M] () -- C:\Program Files (x86)\Subsonic\subsonic-agent.exe

MOD - [2011/11/14 13:02:36 | 000,246,272 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Tonido\plugins\explorer\explorer.dll

MOD - [2011/11/14 12:59:16 | 000,429,056 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Tonido\plugins\search\search.dll

MOD - [2011/11/14 12:53:26 | 001,058,304 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Tonido\plugins\webshare\webshare.dll

MOD - [2011/11/14 12:48:18 | 003,194,880 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Tonido\core.dll

MOD - [2011/10/13 22:49:12 | 008,522,400 | ---- | M] () -- C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

MOD - [2011/05/23 02:46:31 | 000,645,632 | ---- | M] () -- C:\Windows\SysWOW64\xvidcore.dll

MOD - [2011/05/02 07:18:28 | 000,139,264 | ---- | M] () -- C:\xampp\xampp-control.exe

MOD - [2009/09/11 03:40:56 | 000,503,808 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Tonido\gdbuild.dll

MOD - [2009/09/11 02:46:36 | 000,272,896 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Tonido\PocoUtil.dll

MOD - [2009/09/11 02:45:56 | 001,148,416 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Tonido\PocoFoundation.dll

MOD - [2009/09/11 02:43:20 | 000,161,792 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Tonido\PocoNetSSL.dll

MOD - [2009/09/11 02:42:38 | 000,229,888 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Tonido\PocoZip.dll

MOD - [2009/09/11 02:42:34 | 000,514,048 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Tonido\PocoXML.dll

MOD - [2009/09/11 02:42:26 | 000,636,928 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Tonido\PocoNet.dll

MOD - [2009/08/26 22:18:42 | 000,115,200 | ---- | M] () -- C:\Users\Hayden\Desktop\downloads\SirReal\LCDSirReal.exe

MOD - [2009/07/14 00:28:04 | 000,002,560 | ---- | M] () -- C:\Windows\SysWOW64\CTXFIRES.DLL

MOD - [2009/06/29 10:54:08 | 000,164,864 | ---- | M] () -- C:\Windows\SysWOW64\APOMngr.DLL

MOD - [2009/02/06 18:52:24 | 000,073,728 | ---- | M] () -- C:\Windows\SysWOW64\CmdRtr.DLL

========== Win32 Services (SafeList) ==========

SRV:64bit: - [2012/06/24 21:47:38 | 000,216,072 | ---- | M] (Nitro PDF Software) [Auto | Running] -- C:\Program Files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe -- (NitroDriverReadSpool2)

SRV:64bit: - [2012/04/05 21:16:02 | 000,236,544 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)

SRV:64bit: - [2011/04/01 20:17:08 | 000,067,400 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\IIS\Microsoft Web Deploy\MsDepSvc.exe -- (MsDepSvc)

SRV:64bit: - [2010/09/22 19:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)

SRV:64bit: - [2009/08/17 10:52:26 | 000,116,224 | ---- | M] (WDC) [Auto | Running] -- C:\Program Files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe -- (WDDMService.exe)

SRV:64bit: - [2009/07/13 20:41:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)

SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)

SRV:64bit: - [2009/07/13 20:39:56 | 000,010,752 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\inetsrv\WMSvc.exe -- (WMSVC)

SRV:64bit: - [2009/07/13 20:39:13 | 000,015,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\inetsrv\inetinfo.exe -- (IISADMIN)

SRV:64bit: - [2008/07/29 13:20:28 | 004,737,024 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Microsoft Visual Studio 9.0\Common7\IDE\Remote Debugger\x64\msvsmon.exe -- (msvsmon90)

SRV - [2012/07/07 01:02:12 | 000,113,120 | ---- | M] (Mozilla Foundation) [On_Demand | Stopped] -- C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe -- (MozillaMaintenance)

SRV - [2012/06/24 21:47:42 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) [Auto | Running] -- C:\Windows\SysWOW64\NLSSRV32.EXE -- (nlsX86cc)

SRV - [2012/06/05 11:48:30 | 000,087,400 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Motorola Media Link\Lite\NServiceEntry.exe -- (DeviceMonitorService)

SRV - [2012/06/04 19:46:02 | 000,116,632 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe -- (Motorola Device Manager)

SRV - [2012/04/04 15:56:40 | 000,654,408 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)

SRV - [2012/01/03 08:10:42 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)

SRV - [2011/12/07 00:33:35 | 000,419,624 | ---- | M] (Valve Corporation) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Steam\SteamService.exe -- (Steam Client Service)

SRV - [2011/12/06 06:59:12 | 000,212,480 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Subsonic\subsonic-service.exe -- (Subsonic)

SRV - [2011/11/08 13:59:00 | 000,014,216 | ---- | M] (Hi-Rez Studios) [Auto | Running] -- C:\Program Files (x86)\Hi-Rez Studios\HiPatchService.exe -- (HiPatchService)

SRV - [2011/09/10 04:43:18 | 000,018,432 | ---- | M] (Apache Software Foundation) [Auto | Running] -- c:\xampp\apache\bin\httpd.exe -- (Apache2.2)

SRV - [2011/09/09 12:46:10 | 008,158,720 | ---- | M] () [Auto | Running] -- c:\xampp\mysql\bin\mysqld.exe -- (mysql)

SRV - [2011/09/02 16:06:38 | 000,065,657 | ---- | M] (Motorola) [Auto | Running] -- C:\Program Files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe -- (PST Service)

SRV - [2011/06/07 14:29:16 | 000,630,272 | ---- | M] (FileZilla Project) [Auto | Running] -- C:\xampp\FileZillaFTP\FileZillaServer.exe -- (FileZilla Server)

SRV - [2010/07/21 08:48:09 | 000,921,952 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG9\avgemc.exe -- (avg9emc)

SRV - [2010/06/22 09:01:43 | 000,308,136 | ---- | M] (AVG Technologies CZ, s.r.o.) [Auto | Running] -- C:\Program Files (x86)\AVG\AVG9\avgwdsvc.exe -- (avg9wd)

SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)

SRV - [2010/02/19 13:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)

SRV - [2010/02/12 10:23:12 | 000,286,720 | ---- | M] (Creative Technology Ltd) [Auto | Running] -- C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe -- (CTAudSvcService)

SRV - [2009/10/31 00:55:19 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe -- (Creative ALchemy AL6 Licensing Service)

SRV - [2009/10/30 22:14:29 | 000,079,360 | ---- | M] (Creative Labs) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe -- (Creative Audio Engine Licensing Service)

SRV - [2009/07/13 20:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (WAS)

SRV - [2009/07/13 20:15:31 | 000,396,288 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\SysWOW64\inetsrv\iisw3adm.dll -- (W3SVC)

SRV - [2009/07/13 20:14:53 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\inetsrv\apphostsvc.dll -- (AppHostSvc)

SRV - [2009/06/16 09:58:08 | 000,020,480 | ---- | M] (Memeo) [Auto | Stopped] -- C:\Program Files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe -- (WDSmartWareBackgroundService)

SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)

SRV - [2009/04/02 12:27:26 | 000,090,112 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe -- (AsSysCtrlService)

========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/04/06 00:22:40 | 011,174,400 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (amdkmdag)

DRV:64bit: - [2012/04/05 20:10:44 | 000,343,040 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmpag.sys -- (amdkmdap)

DRV:64bit: - [2012/04/04 15:56:40 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)

DRV:64bit: - [2012/02/23 07:32:04 | 000,095,760 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AtihdW76.sys -- (AtiHDAudioService)

DRV:64bit: - [2011/12/19 14:45:22 | 000,146,736 | ---- | M] (Oracle Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\VBoxNetAdp.sys -- (VBoxNetAdp)

DRV:64bit: - [2011/09/13 08:48:05 | 000,035,664 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | System | Running] -- C:\Windows\SysNative\drivers\avgmfx64.sys -- (AvgMfx64)

DRV:64bit: - [2011/05/10 08:06:08 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)

DRV:64bit: - [2011/05/06 08:01:42 | 000,317,520 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgtdia.sys -- (AvgTdiA)

DRV:64bit: - [2011/03/11 01:22:41 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)

DRV:64bit: - [2011/03/11 01:22:40 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)

DRV:64bit: - [2010/12/12 16:45:27 | 000,022,408 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGBusEnum.sys -- (LGBusEnum)

DRV:64bit: - [2010/12/12 16:45:27 | 000,016,008 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGVirHid.sys -- (LGVirHid)

DRV:64bit: - [2010/11/22 16:22:38 | 000,023,040 | ---- | M] (Sagatek Co. Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\MO3v2Driver.sys -- (SSMO3v2Filter)

DRV:64bit: - [2010/09/23 01:36:48 | 000,048,488 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\fssfltr.sys -- (fssfltr)

DRV:64bit: - [2010/09/12 01:24:54 | 000,503,352 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)

DRV:64bit: - [2010/08/12 19:26:16 | 001,310,720 | ---- | M] (C-Media Electronics Inc) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CM10864.sys -- (USBPNPA)

DRV:64bit: - [2010/07/07 22:21:18 | 001,612,888 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ha20x22k.sys -- (ha20x22k)

DRV:64bit: - [2010/07/07 22:21:06 | 001,567,832 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ha20x2k.sys -- (ha20x2k)

DRV:64bit: - [2010/07/07 22:20:56 | 000,118,360 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\emupia2k.sys -- (emupia)

DRV:64bit: - [2010/07/07 22:20:48 | 000,213,080 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctsfm2k.sys -- (ctsfm2k)

DRV:64bit: - [2010/07/07 22:20:40 | 000,015,960 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctprxy2k.sys -- (ctprxy2k)

DRV:64bit: - [2010/07/07 22:16:32 | 000,179,288 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctoss2k.sys -- (ossrv)

DRV:64bit: - [2010/07/07 22:16:24 | 000,697,816 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\ctaud2k.sys -- (ctaud2k) Creative Audio Driver (WDM)

DRV:64bit: - [2010/07/07 22:16:14 | 000,580,696 | ---- | M] (Creative Technology Ltd) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ctac32k.sys -- (ctac32k)

DRV:64bit: - [2010/07/07 22:16:06 | 001,445,976 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX.SYS)

DRV:64bit: - [2010/07/07 22:16:06 | 001,445,976 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTEXFIFX.sys -- (CTEXFIFX)

DRV:64bit: - [2010/07/07 22:15:56 | 000,095,320 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT.SYS)

DRV:64bit: - [2010/07/07 22:15:56 | 000,095,320 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CTHWIUT.sys -- (CTHWIUT)

DRV:64bit: - [2010/07/07 22:15:50 | 000,230,488 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT.SYS)

DRV:64bit: - [2010/07/07 22:15:50 | 000,230,488 | ---- | M] (Creative Technology Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\CT20XUT.sys -- (CT20XUT)

DRV:64bit: - [2010/06/22 09:01:42 | 000,269,904 | ---- | M] (AVG Technologies CZ, s.r.o.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\avgldx64.sys -- (AvgLdx64)

DRV:64bit: - [2010/05/21 19:30:17 | 000,066,728 | ---- | M] (Eugene V. Muzychenko) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vrtaucbl.sys -- (EuMusDesignVirtualAudioCableWdm) Virtual Audio Cable (WDM)

DRV:64bit: - [2010/04/27 18:57:20 | 000,016,200 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmVirHid.sys -- (WmVirHid)

DRV:64bit: - [2010/04/27 18:57:12 | 000,026,440 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmBEnum.sys -- (WmBEnum)

DRV:64bit: - [2010/04/27 16:03:12 | 000,077,512 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\WmXlCore.sys -- (WmXlCore)

DRV:64bit: - [2010/04/27 16:02:42 | 000,043,976 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\WmFilter.sys -- (WmFilter)

DRV:64bit: - [2010/04/03 10:30:40 | 000,313,696 | ---- | M] (Microsoft Corporation) [File_System | Disabled | Stopped] -- C:\Windows\SysNative\drivers\RsFx0150.sys -- (RsFx0150)

DRV:64bit: - [2010/03/29 12:06:53 | 000,056,008 | ---- | M] (AVG Technologies CZ, s.r.o.) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\avgrkx64.sys -- (AvgRkx64)

DRV:64bit: - [2009/09/28 10:22:00 | 000,395,264 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\yk62x64.sys -- (yukonw7)

DRV:64bit: - [2009/09/22 20:46:18 | 000,066,304 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcnfltr.sys -- (vpcnfltr)

DRV:64bit: - [2009/09/22 20:46:17 | 000,359,552 | ---- | M] (Microsoft Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\vpcvmm.sys -- (vpcvmm)

DRV:64bit: - [2009/09/22 20:32:39 | 000,095,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpcusb.sys -- (vpcusb)

DRV:64bit: - [2009/09/22 20:32:33 | 000,187,904 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\vpchbus.sys -- (vpcbus)

DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)

DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)

DRV:64bit: - [2009/07/13 20:47:48 | 000,077,888 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)

DRV:64bit: - [2009/07/13 20:47:48 | 000,023,104 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)

DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)

DRV:64bit: - [2009/07/01 11:54:54 | 000,030,728 | ---- | M] (Logitech Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LGPBTDD.sys -- (LGPBTDD)

DRV:64bit: - [2009/06/17 09:54:30 | 000,057,872 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)

DRV:64bit: - [2009/06/17 09:54:22 | 000,055,312 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)

DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)

DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)

DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)

DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)

DRV:64bit: - [2009/04/08 15:28:46 | 000,068,992 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\xusb21.sys -- (xusb21)

DRV:64bit: - [2009/03/18 17:35:42 | 000,033,856 | -H-- | M] (LogMeIn, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hamachi.sys -- (hamachi)

DRV:64bit: - [2009/03/09 15:08:14 | 000,008,192 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ASACPI.sys -- (MTsensor)

DRV:64bit: - [2009/02/13 12:02:52 | 000,014,464 | ---- | M] (Western Digital Technologies) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wdcsam64.sys -- (WDC_SAM)

DRV:64bit: - [2008/04/16 15:49:34 | 000,028,416 | ---- | M] (Research In Motion Limited) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\RimUsb_AMD64.sys -- (RimUsb)

DRV - [2012/05/29 11:56:53 | 000,019,952 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Program Files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys -- (RivaTuner64)

DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)

DRV - [2008/11/14 02:11:42 | 000,020,512 | ---- | M] (Realtime Soft Ltd) [Kernel | Auto | Running] -- C:\Program Files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys -- (UltraMonUtility)

DRV - [1999/09/10 13:06:00 | 000,025,244 | ---- | M] (Adaptec) [Kernel | System | Stopped] -- C:\Windows\SysWow64\drivers\ASPI32.SYS -- (ASPI32)

========== Standard Registry (SafeList) ==========

========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}

IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&FORM=IE8SRC

IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://blekko.com/ws/?source={SourceID}&toolbarid=TOOLBARNAMESPACE&u=USERGUID&tbp=homepage

IE - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us

IE - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 85 31 47 3E 93 86 CA 01 [binary data]

IE - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found

IE - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\..\SearchScopes,DefaultScope = {E519AA1F-E8A8-47ED-92E3-BCFB65055819}

IE - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/search?q={searchTerms}&src=IE-SearchBox&FORM=IE8SRC

IE - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\..\SearchScopes\{3BD44F0E-0596-4008-AEE0-45D47E3A8F0E}: "URL" = ${ChromeSearchURLIE}

IE - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\..\SearchScopes\{E519AA1F-E8A8-47ED-92E3-BCFB65055819}: "URL" = http://search.comcast.net/search?cat=Web&con=toolbar&q={searchTerms}

IE - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local;192.168.*.*

========== FireFox ==========

FF - user.js - File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_0_1.dll File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.2.1: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.2.1: C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\new_plugin\npjp2.dll (Oracle Corporation)

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.4: C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll ()

FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw.dll (Adobe Systems, Inc.)

FF - HKLM\Software\MozillaPlugins\@comrade.gamespy.com/comrade: C:\Program Files (x86)\GameSpy\Comrade\npcomrade.dll (IGN Entertainment)

FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.4.1: C:\Windows\SysWOW64\npDeployJava1.dll (Oracle Corporation)

FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.4.1: C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll (Oracle Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found

FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)

FF - HKLM\Software\MozillaPlugins\@microsoft.com/wpi,version=1.4: C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll ()

FF - HKLM\Software\MozillaPlugins\@millisecond.com/npInquisit,version=3.0: C:\Users\Hayden\Documents\Millisecond Software\Inquisit 3.0 Mozilla Plugin\npInquisit_3040.dll (Millisecond Software)

FF - HKLM\Software\MozillaPlugins\@nitropdf.com/NitroPDF: C:\Program Files (x86)\Nitro PDF\Reader 2\npnitromozilla.dll File not found

FF - HKLM\Software\MozillaPlugins\@pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKLM\Software\MozillaPlugins\@rayv.com/rayvplugin: C:\Program Files (x86)\RayV\RayV\plugins\nprayvplugin.dll (RayV)

FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=2.0.1: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (VideoLAN)

FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)

FF - HKCU\Software\MozillaPlugins\@millisecond.com/npInquisit,version=3.0: C:\Users\Hayden\Documents\Millisecond Software\Inquisit 3.0 Mozilla Plugin\npInquisit_3040.dll (Millisecond Software)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Hayden\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Hayden\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll (Google Inc.)

FF - HKCU\Software\MozillaPlugins\pandonetworks.com/PandoWebPlugin: C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll (Pando Networks)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/23 21:25:42 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/07/07 01:02:12 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Thunderbird\components [2012/06/18 22:44:22 | 000,000,000 | ---D | M]

FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Thunderbird 13.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Thunderbird\plugins

FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\smartwebprinting@hp.com: C:\Program Files (x86)\HP\Digital Imaging\Smart Web Printing\MozillaAddOn3 [2012/05/23 21:25:42 | 000,000,000 | ---D | M]

[2011/09/29 21:01:08 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hayden\AppData\Roaming\Mozilla\Extensions

[2012/07/07 01:38:05 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions

[2012/07/01 02:32:37 | 000,000,000 | ---D | M] (blekko search bar) -- C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}

[2012/04/06 17:39:44 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

[2012/05/19 15:47:57 | 001,335,949 | ---- | M] () (No name found) -- C:\USERS\HAYDEN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\OM1TISBE.DEFAULT\EXTENSIONS\FIREBUG@SOFTWARE.JOEHEWITT.COM.XPI

[2012/05/19 15:47:57 | 000,044,607 | ---- | M] () (No name found) -- C:\USERS\HAYDEN\APPDATA\ROAMING\MOZILLA\FIREFOX\PROFILES\OM1TISBE.DEFAULT\EXTENSIONS\WORKSPACE@ANTENNASOFT.NET.XPI

[2012/07/07 01:02:12 | 000,085,472 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll

[2012/02/22 20:11:15 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml

[2012/02/22 20:11:15 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)

CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}

CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},

CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer

CHR - plugin: Native Client (Enabled) = C:\Users\Hayden\AppData\Local\Google\Chrome\Application\20.0.1132.47\ppGoogleNaClPluginChrome.dll

CHR - plugin: Chrome PDF Viewer (Disabled) = C:\Users\Hayden\AppData\Local\Google\Chrome\Application\20.0.1132.47\pdf.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Hayden\AppData\Local\Google\Chrome\Application\20.0.1132.47\gcswf32.dll

CHR - plugin: Shockwave Flash (Disabled) = C:\Users\Hayden\AppData\Local\Google\Chrome\User Data\PepperFlash\11.1.31.203\pepflashplayer.dll

CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll

CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll

CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll

CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll

CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll

CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll

CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll

CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll

CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MIF5BA~1\Office14\NPAUTHZ.DLL

CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~2\MIF5BA~1\Office14\NPSPWRAP.DLL

CHR - plugin: Comrade Plugin (Enabled) = C:\Program Files (x86)\GameSpy\Comrade\npcomrade.dll

CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.1.10111.0\npctrl.dll

CHR - plugin: Java Platform SE 7 U4 (Enabled) = C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll

CHR - plugin: Java Deployment Toolkit 7.0.40.255 (Enabled) = C:\Windows\SysWOW64\npDeployJava1.dll

CHR - plugin: Pando Web Plugin (Enabled) = C:\Program Files (x86)\Pando Networks\Media Booster\npPandoWebPlugin.dll

CHR - plugin: RayV Plugin (Enabled) = C:\Program Files (x86)\RayV\RayV\plugins\nprayvplugin.dll

CHR - plugin: VLC Web Plugin (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll

CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

CHR - plugin: WPI Detector 1.4 (Enabled) = C:\Program Files\Microsoft\Web Platform Installer\\npwpidetector.dll

CHR - plugin: Google Update (Enabled) = C:\Users\Hayden\AppData\Local\Google\Update\1.3.21.111\npGoogleUpdate3.dll

CHR - plugin: Inquisit Web Edition (Enabled) = C:\Users\Hayden\Documents\Millisecond Software\Inquisit 3.0 Mozilla Plugin\npInquisit_3040.dll

CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll

CHR - Extension: Entanglement = C:\Users\Hayden\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\

CHR - Extension: TooManyTabs for Chrome = C:\Users\Hayden\AppData\Local\Google\Chrome\User Data\Default\Extensions\amigcgbheognjmfkaieeeadojiibgbdp\1.9.2_0\

CHR - Extension: Session Manager = C:\Users\Hayden\AppData\Local\Google\Chrome\User Data\Default\Extensions\bbcnbpafconjjigibnhbfmmgdbbkcjfi\0.4_0\

CHR - Extension: YouTube = C:\Users\Hayden\AppData\Local\Google\Chrome\User Data\Default\Extensions\blpcfgokakmgnkcojhhkbfbldkacnbeo\4.2.5_0\

CHR - Extension: Add to Amazon Wish List = C:\Users\Hayden\AppData\Local\Google\Chrome\User Data\Default\Extensions\ciagpekplgpbepdgggflgmahnjgiaced\1.0.0.8_0\

CHR - Extension: Google Search = C:\Users\Hayden\AppData\Local\Google\Chrome\User Data\Default\Extensions\coobgpohoikkiipiblmjeljniedjpjpf\0.0.0.19_0\

CHR - Extension: Offline Google Mail = C:\Users\Hayden\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk\1.18_0\

CHR - Extension: Boomerang for Gmail = C:\Users\Hayden\AppData\Local\Google\Chrome\User Data\Default\Extensions\mdkdbdadolokifeomchamhifddohomii\1.0_0\

CHR - Extension: Page Monitor = C:\Users\Hayden\AppData\Local\Google\Chrome\User Data\Default\Extensions\pemhgklkefakciniebenbfclihhmmfcd\3.2.7_0\

CHR - Extension: Evernote Web Clipper = C:\Users\Hayden\AppData\Local\Google\Chrome\User Data\Default\Extensions\pioclpoplcdbaefihamjohnefbikjilc\5.5.1_0\

CHR - Extension: Gmail = C:\Users\Hayden\AppData\Local\Google\Chrome\User Data\Default\Extensions\pjkljhegncpnkpknbcohdijeoejaedia\7_0\

O1 HOSTS File: ([2012/07/07 19:20:17 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts

O1 - Hosts: 127.0.0.1 localhost

O2:64bit: - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssiea.dll (AVG Technologies CZ, s.r.o.)

O2:64bit: - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Oracle\JavaFX 2.0 Runtime\bin\jp2ssv.dll (Oracle Corporation)

O2 - BHO: (AVG Safe Search) - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (AVG Technologies CZ, s.r.o.)

O2 - BHO: (Java Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\ssv.dll (Oracle Corporation)

O2 - BHO: (Java Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Oracle\JavaFX 2.1 Runtime\bin\jp2ssv.dll (Oracle Corporation)

O3 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\..\Toolbar\WebBrowser: (no name) - {BA14329E-9550-4989-B3F2-9732E92D17CC} - No CLSID value found.

O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)

O4:64bit: - HKLM..\Run: [Cm108Sound] C:\Windows\Syswow64\cm108.dll (C-Media Corporation)

O4:64bit: - HKLM..\Run: [Launch LCore] C:\Program Files\Logitech Gaming Software\LCore.exe (Logitech Inc.)

O4:64bit: - HKLM..\Run: [start WingMan Profiler] C:\Program Files\Logitech\Gaming Software\LWEMon.exe (Logitech Inc.)

O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [AMD AVT] C:\Windows\SysWow64\cmd.exe (Microsoft Corporation)

O4 - HKLM..\Run: [Anti-phishing Domain Advisor] C:\ProgramData\Anti-phishing Domain Advisor\visicom_antiphishing.exe (Visicom Media Inc. (Powered by Panda Security))

O4 - HKLM..\Run: [ATICustomerCare] C:\Program Files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe (Advanced Micro Devices, Inc.)

O4 - HKLM..\Run: [AVG9_TRAY] C:\Program Files (x86)\AVG\AVG9\avgtray.exe (AVG Technologies CZ, s.r.o.)

O4 - HKLM..\Run: [CTxfiHlp] C:\Windows\SysWow64\Ctxfihlp.exe (Creative Technology Ltd)

O4 - HKLM..\Run: [KeePass 2 PreLoad] C:\Program Files (x86)\KeePass Password Safe 2\KeePass.exe (Dominik Reichl)

O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)

O4 - HKLM..\Run: [startCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)

O4 - HKLM..\Run: [switchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe (Adobe Systems Incorporated)

O4 - HKLM..\Run: [VolPanel] C:\Program Files (x86)\Creative\Volume Panel\VolPanlu.exe (Creative Technology Ltd)

O4 - HKU\.DEFAULT..\Run: [MotoCast] C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk ()

O4 - HKU\S-1-5-18..\Run: [MotoCast] C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk ()

O4 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000..\Run: [AlcoholAutomount] C:\Program Files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe (Alcohol Soft Development Team)

O4 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000..\Run: [GoToMeeting] C:\Program Files (x86)\Citrix\GoToMeeting\952\g2mstart.exe (Citrix Online, a division of Citrix Systems, Inc.)

O4 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000..\Run: [MotoCast] C:\Program Files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk ()

O4 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000..\Run: [MusicManager] C:\Users\Hayden\AppData\Local\Programs\Google\MusicManager\MusicManager.exe (Google Inc.)

O4 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000..\Run: [Pando Media Booster] C:\Program Files (x86)\Pando Networks\Media Booster\PMB.exe ()

O4 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000..\Run: [snarl] C:\Program Files (x86)\full phat\Snarl\snarl.exe (full phat products)

O4 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000..\Run: [spotify Web Helper] C:\Users\Hayden\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe ()

O4 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000..\Run: [steam] C:\Program Files (x86)\Steam\steam.exe (Valve Corporation)

O4 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000..\Run: [Tonido] C:\Users\Hayden\AppData\Roaming\Tonido\launcher.exe (CodeLathe LLC)

O4 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000..\Run: [Xvid] C:\Program Files (x86)\XviD\CheckUpdate.exe ()

O4 - Startup: C:\Users\Hayden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\CurseClientStartup.ccip ()

O4 - Startup: C:\Users\Hayden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Hayden\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)

O4 - Startup: C:\Users\Hayden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files (x86)\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)

O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0

O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: HideShutdownScripts = 0

O7 - HKU\.DEFAULT\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-18\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-19\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-20\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Policies\Microsoft\Internet Explorer\Control Panel present

O7 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: MaxRecentDocs = 99

O7 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 91 00 00 00 [binary data]

O7 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0

O8:64bit: - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~1\MIF5BA~1\Office14\ONBttnIE.dll/105 File not found

O8:64bit: - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)

O8:64bit: - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000 File not found

O8 - Extra context menu item: &Verzenden naar OneNote - res://C:\PROGRA~1\MIF5BA~1\Office14\ONBttnIE.dll/105 File not found

O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)

O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MIF5BA~1\Office14\EXCEL.EXE/3000 File not found

O9 - Extra Button: @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)

O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files (x86)\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)

O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000009 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)

O10 - NameSpace_Catalog5\Catalog_Entries\000000000009 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)

O15 - HKU\.DEFAULT\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: freerealms.com ([]* in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: soe.com ([]* in Trusted sites)

O15 - HKU\.DEFAULT\..Trusted Domains: sony.com ([]* in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: freerealms.com ([]* in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: soe.com ([]* in Trusted sites)

O15 - HKU\S-1-5-18\..Trusted Domains: sony.com ([]* in Trusted sites)

O15 - HKU\S-1-5-19\..Trusted Domains: clonewarsadventures.com ([]* in )

O15 - HKU\S-1-5-19\..Trusted Domains: freerealms.com ([]* in )

O15 - HKU\S-1-5-19\..Trusted Domains: soe.com ([]* in )

O15 - HKU\S-1-5-19\..Trusted Domains: sony.com ([]* in )

O15 - HKU\S-1-5-20\..Trusted Domains: clonewarsadventures.com ([]* in )

O15 - HKU\S-1-5-20\..Trusted Domains: freerealms.com ([]* in )

O15 - HKU\S-1-5-20\..Trusted Domains: soe.com ([]* in )

O15 - HKU\S-1-5-20\..Trusted Domains: sony.com ([]* in )

O15 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\..Trusted Domains: clonewarsadventures.com ([]* in Trusted sites)

O15 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\..Trusted Domains: freerealms.com ([]* in Trusted sites)

O15 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\..Trusted Domains: soe.com ([]* in Trusted sites)

O15 - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\..Trusted Domains: sony.com ([]* in Trusted sites)

O16:64bit: - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 10.2.1)

O16:64bit: - DPF: {CAFEEFAC-0016-0000-0032-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_32-windows-i586.cab (Java Plug-in 1.6.0_32)

O16:64bit: - DPF: {CAFEEFAC-0017-0000-0002-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02)

O16:64bit: - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.7.0/jinstall-1_7_0_02-windows-i586.cab (Java Plug-in 1.7.0_02)

O16 - DPF: {140E4DF8-9E14-4A34-9577-C77561ED7883} http://content.systemrequirementslab.com.s3.amazonaws.com/global/bin/srldetect_cyri_4.1.72.0.cab (SysInfo Class)

O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 10.4.1)

O16 - DPF: {CAFEEFAC-0016-0000-0030-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 1.6.0_30)

O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/update/1.6.0/jinstall-1_6_0_30-windows-i586.cab (Java Plug-in 10.4.1)

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab (Reg Error: Key error.)

O16 - DPF: {EF0D1A14-1033-41A2-A589-240C01EDC078} http://dl.pplive.com/PluginSetup.cab (PPLive Lite Class)

O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} http://ccfiles.creative.com/Web/softwareupdate/su2/ocx/15109/CTPID.cab (Creative Software AutoUpdate Support Package)

O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.254

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{10CA6D3A-A668-46A4-8C13-85D6687E1361}: DhcpNameServer = 192.168.1.254

O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{990CE7FE-1950-487C-949D-158AB7F09A2C}: DhcpNameServer = 192.168.1.254

O18:64bit: - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgppa.dll (AVG Technologies CZ, s.r.o.)

O18:64bit: - Protocol\Handler\livecall - No CLSID value found

O18:64bit: - Protocol\Handler\ms-help {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll File not found

O18:64bit: - Protocol\Handler\msnim - No CLSID value found

O18:64bit: - Protocol\Handler\mso-offdap11 - No CLSID value found

O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found

O18:64bit: - Protocol\Handler\wlpg - No CLSID value found

O18 - Protocol\Handler\linkscanner {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG9\avgpp.dll (AVG Technologies CZ, s.r.o.)

O20:64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)

O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O20 - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)

O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)

O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found

O32 - HKLM CDRom: AutoRun - 1

O32 - AutoRun File - [2003/08/27 03:47:12 | 000,000,000 | ---D | M] - D:\AutoRun -- [ CDFS ]

O32 - AutoRun File - [2003/08/27 03:47:12 | 000,000,059 | R--- | M] () - D:\autorun.inf -- [ CDFS ]

O34 - HKLM BootExecute: (autocheck autochk *)

O35:64bit: - HKLM\..comfile [open] -- "%1" %*

O35:64bit: - HKLM\..exefile [open] -- "%1" %*

O35 - HKLM\..comfile [open] -- "%1" %*

O35 - HKLM\..exefile [open] -- "%1" %*

O37:64bit: - HKLM\...com [@ = ComFile] -- "%1" %*

O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*

O37 - HKLM\...com [@ = ComFile] -- "%1" %*

O37 - HKLM\...exe [@ = exefile] -- "%1" %*

O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)

O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/07/09 17:27:54 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\KeePass Password Safe 2

[2012/07/07 19:20:46 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN

[2012/07/07 19:00:43 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe

[2012/07/07 19:00:43 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe

[2012/07/07 19:00:43 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe

[2012/07/07 19:00:40 | 000,000,000 | ---D | C] -- C:\Qoobox

[2012/07/07 19:00:17 | 000,000,000 | ---D | C] -- C:\Windows\erdnt

[2012/07/07 17:36:54 | 000,000,000 | ---D | C] -- C:\TDSSKiller_Quarantine

[2012/07/07 13:57:01 | 000,000,000 | ---D | C] -- C:\Users\Hayden\AppData\Roaming\Malwarebytes

[2012/07/07 13:56:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware

[2012/07/07 13:56:56 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys

[2012/07/07 13:56:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware

[2012/07/07 13:56:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes

[2012/07/06 14:18:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Subsonic

[2012/07/06 14:18:44 | 000,000,000 | ---D | C] -- C:\subsonic

[2012/07/06 14:18:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Subsonic

[2012/07/02 13:01:21 | 000,000,000 | ---D | C] -- C:\Users\Hayden\.pdfsam

[2012/07/02 11:17:52 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\pdfsam

[2012/07/02 11:17:52 | 000,000,000 | ---D | C] -- C:\Users\Hayden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PDF Split And Merge

[2012/07/02 11:07:06 | 000,000,000 | ---D | C] -- C:\Users\Hayden\AppData\Roaming\ParmisPDF

[2012/07/02 10:49:07 | 000,000,000 | ---D | C] -- C:\Users\Hayden\AppData\Roaming\PrimoPDF

[2012/07/02 10:48:32 | 000,000,000 | ---D | C] -- C:\Users\Hayden\AppData\Roaming\OpenCandy

[2012/07/02 00:37:46 | 000,000,000 | ---D | C] -- C:\Users\Hayden\Documents\SimCity 4

[2012/07/02 00:37:41 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Maxis

[2012/07/02 00:32:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Maxis

[2012/07/01 17:08:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote

[2012/07/01 02:33:27 | 000,000,000 | ---D | C] -- C:\Users\Hayden\AppData\Roaming\EAC

[2012/07/01 02:33:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Exact Audio Copy

[2012/07/01 02:33:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Exact Audio Copy

[2012/07/01 02:32:36 | 000,000,000 | ---D | C] -- C:\Users\Hayden\AppData\Local\blekkotb_031

[2012/07/01 02:32:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\blekkotb_031

[2012/07/01 02:32:35 | 000,000,000 | ---D | C] -- C:\ProgramData\Anti-phishing Domain Advisor

[2012/06/27 17:19:19 | 000,000,000 | ---D | C] -- C:\Users\Hayden\AppData\Roaming\Nitro PDF

[2012/06/27 17:18:28 | 000,029,704 | ---- | C] (Nitro PDF Software) -- C:\Windows\SysNative\nitrolocalmon2.dll

[2012/06/27 17:18:28 | 000,017,936 | ---- | C] (Nitro PDF Software) -- C:\Windows\SysNative\nitrolocalui2.dll

[2012/06/27 17:18:14 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Nitro PDF

[2012/06/27 17:18:13 | 000,000,000 | ---D | C] -- C:\ProgramData\Nitro PDF

[2012/06/27 17:18:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Nitro PDF

[2012/06/27 17:18:13 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Nitro PDF

[2012/06/27 14:50:17 | 000,000,000 | ---D | C] -- C:\Users\Hayden\.cpan

[2012/06/26 18:07:26 | 000,000,000 | ---D | C] -- C:\Users\Hayden\Documents\WebOps Projects (Notepad++)

[2012/06/24 21:47:42 | 000,069,640 | ---- | C] (Nalpeiron Ltd.) -- C:\Windows\SysWow64\NLSSRV32.EXE

[2012/06/24 19:35:23 | 000,000,000 | ---D | C] -- C:\ProgramData\phpDesigner

[2012/06/19 20:45:42 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Motorola Media Link

[2012/06/13 20:07:58 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Ken Ward's Makeup

[2012/06/09 20:21:19 | 000,000,000 | ---D | C] -- C:\Users\Hayden\AppData\Roaming\Audacity

[2012/06/09 20:19:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Audacity

[8 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

[6 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/07/09 17:59:31 | 000,000,600 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\winscp.rnd

[2012/07/09 17:22:00 | 000,000,912 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000UA.job

[2012/07/09 07:22:00 | 000,000,860 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000Core.job

[2012/07/07 19:35:47 | 000,020,544 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0

[2012/07/07 19:35:46 | 000,020,544 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0

[2012/07/07 19:20:23 | 000,065,536 | ---- | M] () -- C:\Windows\SysNative\Ikeext.etl

[2012/07/07 19:20:17 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts

[2012/07/07 19:19:26 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat

[2012/07/07 19:18:49 | 1066,749,950 | -HS- | M] () -- C:\hiberfil.sys

[2012/07/07 19:17:50 | 000,062,308 | ---- | M] () -- C:\Windows\SysNative\BMXStateBkp-{00000001-00000000-00000000-00001102-0000000B-00431102}.rfx

[2012/07/07 19:17:50 | 000,062,308 | ---- | M] () -- C:\Windows\SysNative\BMXState-{00000001-00000000-00000000-00001102-0000000B-00431102}.rfx

[2012/07/07 19:17:50 | 000,000,820 | ---- | M] () -- C:\Windows\SysNative\DVCState-{00000001-00000000-00000000-00001102-0000000B-00431102}.rfx

[2012/07/07 13:56:58 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2012/07/07 03:48:03 | 101,270,096 | ---- | M] () -- C:\Windows\SysNative\drivers\Avg\incavi.avm

[2012/07/06 14:18:47 | 000,001,925 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Subsonic.lnk

[2012/07/05 21:50:31 | 000,000,600 | ---- | M] () -- C:\Users\Hayden\AppData\Local\PUTTY.RND

[2012/07/04 15:19:55 | 000,000,221 | ---- | M] () -- C:\Users\Hayden\Desktop\Tribes Ascend.url

[2012/07/02 11:21:29 | 000,085,965 | ---- | M] () -- C:\Users\Hayden\Documents\1_pdfsam_test.pdf

[2012/07/02 11:21:29 | 000,079,683 | ---- | M] () -- C:\Users\Hayden\Documents\4_pdfsam_test.pdf

[2012/07/02 11:21:29 | 000,079,562 | ---- | M] () -- C:\Users\Hayden\Documents\3_pdfsam_test.pdf

[2012/07/02 11:12:40 | 000,092,754 | ---- | M] () -- C:\Users\Hayden\Documents\test0002.pdf

[2012/07/02 11:12:40 | 000,091,159 | ---- | M] () -- C:\Users\Hayden\Documents\test0001.pdf

[2012/07/02 11:12:40 | 000,091,118 | ---- | M] () -- C:\Users\Hayden\Documents\test0004.pdf

[2012/07/02 11:12:40 | 000,090,995 | ---- | M] () -- C:\Users\Hayden\Documents\test0003.pdf

[2012/07/02 11:11:14 | 000,101,412 | ---- | M] () -- C:\Users\Hayden\Documents\test.pdf

[2012/07/02 10:53:20 | 000,024,164 | ---- | M] () -- C:\Users\Hayden\Documents\Batch Print Invoices.pdf

[2012/07/02 00:32:13 | 000,000,528 | ---- | M] () -- C:\Windows\eReg.dat

[2012/07/01 02:33:18 | 000,001,070 | ---- | M] () -- C:\Users\Public\Desktop\Exact Audio Copy.lnk

[2012/06/30 03:23:17 | 000,002,403 | ---- | M] () -- C:\Users\Hayden\Desktop\Google Chrome.lnk

[2012/06/27 17:18:18 | 000,002,059 | ---- | M] () -- C:\Users\Public\Desktop\Nitro Pro 7.lnk

[2012/06/26 23:11:30 | 000,087,712 | ---- | M] () -- C:\Users\Hayden\Documents\AdminEditOrder.asp

[2012/06/26 22:56:49 | 000,057,951 | ---- | M] () -- C:\Users\Hayden\Documents\OrdInvoice.asp

[2012/06/24 21:47:42 | 000,069,640 | ---- | M] (Nalpeiron Ltd.) -- C:\Windows\SysWow64\NLSSRV32.EXE

[2012/06/24 21:47:08 | 000,029,704 | ---- | M] (Nitro PDF Software) -- C:\Windows\SysNative\nitrolocalmon2.dll

[2012/06/24 17:44:15 | 000,289,422 | ---- | M] () -- C:\Users\Hayden\Documents\NewDatabase.kdbx

[2012/06/24 17:35:14 | 000,000,942 | ---- | M] () -- C:\Users\Hayden\Desktop\JetBrains PhpStorm 4.0.1.lnk

[2012/06/24 17:06:40 | 000,003,745 | ---- | M] () -- C:\Users\Hayden\Documents\ChurKirbys sequences part 2.m3u

[2012/06/18 18:49:41 | 000,000,219 | ---- | M] () -- C:\Users\Hayden\Desktop\Counter-Strike Source.url

[2012/06/12 00:44:33 | 000,008,901 | ---- | M] () -- C:\Users\Hayden\Documents\hayden taxes.ods

[2012/06/09 20:19:43 | 000,001,007 | ---- | M] () -- C:\Users\Hayden\Desktop\Audacity.lnk

[8 C:\Windows\SysNative\*.tmp files -> C:\Windows\SysNative\*.tmp -> ]

[6 C:\Windows\SysWow64\*.tmp files -> C:\Windows\SysWow64\*.tmp -> ]

[3 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/07/09 17:27:54 | 000,001,117 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\KeePass 2.lnk

[2012/07/07 19:00:43 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe

[2012/07/07 19:00:43 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe

[2012/07/07 19:00:43 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe

[2012/07/07 19:00:43 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe

[2012/07/07 19:00:43 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe

[2012/07/07 13:56:58 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk

[2012/07/06 14:18:47 | 000,001,925 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Subsonic.lnk

[2012/07/04 15:19:55 | 000,000,221 | ---- | C] () -- C:\Users\Hayden\Desktop\Tribes Ascend.url

[2012/07/02 11:20:31 | 000,079,683 | ---- | C] () -- C:\Users\Hayden\Documents\4_pdfsam_test.pdf

[2012/07/02 11:20:31 | 000,079,562 | ---- | C] () -- C:\Users\Hayden\Documents\3_pdfsam_test.pdf

[2012/07/02 11:20:30 | 000,085,965 | ---- | C] () -- C:\Users\Hayden\Documents\1_pdfsam_test.pdf

[2012/07/02 11:12:40 | 000,092,754 | ---- | C] () -- C:\Users\Hayden\Documents\test0002.pdf

[2012/07/02 11:12:40 | 000,091,159 | ---- | C] () -- C:\Users\Hayden\Documents\test0001.pdf

[2012/07/02 11:12:40 | 000,091,118 | ---- | C] () -- C:\Users\Hayden\Documents\test0004.pdf

[2012/07/02 11:12:40 | 000,090,995 | ---- | C] () -- C:\Users\Hayden\Documents\test0003.pdf

[2012/07/02 11:11:14 | 000,101,412 | ---- | C] () -- C:\Users\Hayden\Documents\test.pdf

[2012/07/02 10:53:20 | 000,024,164 | ---- | C] () -- C:\Users\Hayden\Documents\Batch Print Invoices.pdf

[2012/07/02 10:48:32 | 000,095,008 | ---- | C] () -- C:\Windows\SysNative\Primomonnt.dll

[2012/07/02 00:32:13 | 000,000,528 | ---- | C] () -- C:\Windows\eReg.dat

[2012/07/01 02:33:18 | 000,001,070 | ---- | C] () -- C:\Users\Public\Desktop\Exact Audio Copy.lnk

[2012/06/27 17:18:18 | 000,002,059 | ---- | C] () -- C:\Users\Public\Desktop\Nitro Pro 7.lnk

[2012/06/27 17:18:16 | 000,002,557 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Nitro Pro 7.lnk

[2012/06/26 23:11:08 | 000,087,712 | ---- | C] () -- C:\Users\Hayden\Documents\AdminEditOrder.asp

[2012/06/26 22:56:08 | 000,057,951 | ---- | C] () -- C:\Users\Hayden\Documents\OrdInvoice.asp

[2012/06/24 18:07:44 | 000,289,422 | ---- | C] () -- C:\Users\Hayden\Documents\NewDatabase.kdbx

[2012/06/24 17:06:40 | 000,003,745 | ---- | C] () -- C:\Users\Hayden\Documents\ChurKirbys sequences part 2.m3u

[2012/06/18 18:49:41 | 000,000,219 | ---- | C] () -- C:\Users\Hayden\Desktop\Counter-Strike Source.url

[2012/06/09 20:19:43 | 000,001,019 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Audacity.lnk

[2012/06/09 20:19:43 | 000,001,007 | ---- | C] () -- C:\Users\Hayden\Desktop\Audacity.lnk

[2012/05/23 21:21:58 | 000,165,715 | ---- | C] () -- C:\Windows\hpoins28.dat

[2012/05/23 21:21:57 | 000,000,442 | ---- | C] () -- C:\Windows\hpomdl28.dat

[2012/04/05 20:29:34 | 000,204,952 | ---- | C] () -- C:\Windows\SysWow64\ativvsvl.dat

[2012/04/05 20:29:34 | 000,157,144 | ---- | C] () -- C:\Windows\SysWow64\ativvsva.dat

[2012/03/09 14:06:14 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\kdbsdk32.dll

[2012/02/22 20:05:34 | 000,143,360 | ---- | C] () -- C:\Windows\Vmix108.dll

[2012/02/22 20:05:34 | 000,000,338 | ---- | C] () -- C:\Windows\Cm108.ini.cfl

[2012/02/22 20:04:55 | 000,002,029 | ---- | C] () -- C:\Windows\Cm108.ini.cfg

[2012/02/22 20:04:55 | 000,000,252 | ---- | C] () -- C:\Windows\Cm108.ini.imi

[2012/02/22 20:04:53 | 000,001,353 | ---- | C] () -- C:\Windows\cm108.ini

[2012/02/17 19:10:56 | 000,000,201 | ---- | C] () -- C:\Users\Hayden\.gitconfig

[2011/12/25 19:54:47 | 000,003,190 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Windows Media Audio 10 Codec.dat

[2011/12/23 02:12:28 | 000,197,688 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat

[2011/11/03 20:29:21 | 000,001,521 | ---- | C] () -- C:\Users\Hayden\.bash_history

[2011/11/03 20:29:19 | 000,000,939 | ---- | C] () -- C:\Users\Hayden\.gitk

[2011/10/30 23:46:16 | 000,001,702 | ---- | C] () -- C:\Users\Hayden\_viminfo

[2011/10/25 22:21:34 | 000,056,832 | ---- | C] () -- C:\Windows\SysWow64\OVDecoder.dll

[2011/09/23 23:18:44 | 000,000,600 | ---- | C] () -- C:\Users\Hayden\AppData\Roaming\winscp.rnd

[2011/09/23 22:05:41 | 000,000,600 | ---- | C] () -- C:\Users\Hayden\AppData\Local\PUTTY.RND

[2011/09/12 17:06:16 | 000,003,917 | ---- | C] () -- C:\Windows\SysWow64\atipblag.dat

[2011/07/17 22:57:04 | 000,017,857 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall-dBpoweramp Music Converter.dat

[2011/07/12 22:42:05 | 000,007,606 | ---- | C] () -- C:\Users\Hayden\AppData\Local\Resmon.ResmonCfg

[2011/07/12 22:07:16 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat

[2011/06/23 16:33:36 | 000,415,408 | ---- | C] () -- C:\Windows\SysWow64\SpoonUninstall.exe

[2011/06/16 15:31:09 | 000,645,632 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll

[2011/06/16 15:31:09 | 000,240,640 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll

[2011/04/09 18:55:28 | 000,179,261 | ---- | C] () -- C:\Windows\SysWow64\xlive.dll.cat

[2011/01/07 17:46:00 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin

[2010/12/18 15:46:19 | 000,641,021 | ---- | C] () -- C:\Windows\unins000.exe

[2010/12/18 15:46:19 | 000,187,904 | ---- | C] () -- C:\Windows\SysWow64\Lame.exe

[2010/12/18 15:46:19 | 000,166,912 | ---- | C] () -- C:\Windows\SysWow64\Lame_enc.dll

[2010/12/18 15:46:19 | 000,001,680 | ---- | C] () -- C:\Windows\unins000.dat

[2010/12/08 03:08:59 | 000,000,000 | ---- | C] () -- C:\Windows\PowerReg.dat

[2010/08/27 18:50:54 | 000,000,172 | ---- | C] () -- C:\Windows\ODBC.INI

[2010/08/27 18:50:08 | 000,940,702 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI

[2010/02/25 20:56:00 | 000,000,040 | ---- | C] () -- C:\ProgramData\ra3.ini

========== Custom Scans ==========

< %USERPROFILE%\*.* >

[2011/11/20 14:05:50 | 000,001,521 | ---- | M] () -- C:\Users\Hayden\.bash_history

[2012/02/17 19:11:06 | 000,000,201 | ---- | M] () -- C:\Users\Hayden\.gitconfig

[2012/05/24 23:35:39 | 000,000,939 | ---- | M] () -- C:\Users\Hayden\.gitk

[2012/07/09 18:12:01 | 012,320,768 | ---- | M] () -- C:\Users\Hayden\ntuser.dat

[2012/07/09 18:12:00 | 000,262,144 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat.LOG1

[2009/10/30 17:31:30 | 000,000,000 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat.LOG2

[2009/10/30 17:43:18 | 000,065,536 | -HS- | M] () -- C:\Users\Hayden\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TM.blf

[2009/10/30 17:43:18 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000001.regtrans-ms

[2009/10/30 17:43:18 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\NTUSER.DAT{016888bd-6c6f-11de-8d1d-001e0bcde3ec}.TMContainer00000000000000000002.regtrans-ms

[2010/08/25 05:15:52 | 000,065,536 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{0de26f32-aed3-11df-85f2-002618086de8}.TM.blf

[2010/08/25 05:15:52 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{0de26f32-aed3-11df-85f2-002618086de8}.TMContainer00000000000000000001.regtrans-ms

[2010/08/25 05:15:52 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{0de26f32-aed3-11df-85f2-002618086de8}.TMContainer00000000000000000002.regtrans-ms

[2010/06/11 05:20:09 | 000,065,536 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{1f3646e8-6dd0-11df-bbd5-002618086de8}.TM.blf

[2010/06/11 05:20:09 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{1f3646e8-6dd0-11df-bbd5-002618086de8}.TMContainer00000000000000000001.regtrans-ms

[2010/06/11 05:20:09 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{1f3646e8-6dd0-11df-bbd5-002618086de8}.TMContainer00000000000000000002.regtrans-ms

[2010/03/04 17:28:37 | 000,065,536 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{396de841-27dd-11df-9ff2-002618086de9}.TM.blf

[2010/03/04 17:28:37 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{396de841-27dd-11df-9ff2-002618086de9}.TMContainer00000000000000000001.regtrans-ms

[2010/03/04 17:28:37 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{396de841-27dd-11df-9ff2-002618086de9}.TMContainer00000000000000000002.regtrans-ms

[2009/12/19 14:37:32 | 000,065,536 | -HS- | M] () -- C:\Users\Hayden\NTUSER.DAT{4cc835cb-ecd5-11de-af22-002618086de8}.TM.blf

[2009/12/19 14:37:32 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\NTUSER.DAT{4cc835cb-ecd5-11de-af22-002618086de8}.TMContainer00000000000000000001.regtrans-ms

[2009/12/19 14:37:32 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\NTUSER.DAT{4cc835cb-ecd5-11de-af22-002618086de8}.TMContainer00000000000000000002.regtrans-ms

[2012/05/29 21:58:32 | 001,048,576 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{84b07aa9-7be5-11e0-8774-002618086de8}.TxR.0.regtrans-ms

[2012/05/29 21:58:32 | 001,048,576 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{84b07aa9-7be5-11e0-8774-002618086de8}.TxR.1.regtrans-ms

[2012/05/29 21:58:32 | 001,048,576 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{84b07aa9-7be5-11e0-8774-002618086de8}.TxR.2.regtrans-ms

[2012/05/29 21:58:32 | 000,065,536 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{84b07aa9-7be5-11e0-8774-002618086de8}.TxR.blf

[2011/05/16 18:51:27 | 000,065,536 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{84b07aaa-7be5-11e0-8774-002618086de8}.TM.blf

[2011/05/16 18:51:27 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{84b07aaa-7be5-11e0-8774-002618086de8}.TMContainer00000000000000000001.regtrans-ms

[2011/05/16 18:51:27 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{84b07aaa-7be5-11e0-8774-002618086de8}.TMContainer00000000000000000002.regtrans-ms

[2010/02/26 04:29:38 | 000,065,536 | -HS- | M] () -- C:\Users\Hayden\NTUSER.DAT{9c7a8c93-22b8-11df-a126-002618086de9}.TM.blf

[2010/02/26 04:29:38 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\NTUSER.DAT{9c7a8c93-22b8-11df-a126-002618086de9}.TMContainer00000000000000000001.regtrans-ms

[2010/02/26 04:29:38 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\NTUSER.DAT{9c7a8c93-22b8-11df-a126-002618086de9}.TMContainer00000000000000000002.regtrans-ms

[2010/08/13 06:01:39 | 000,065,536 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{a98c4342-a6b1-11df-b78a-002618086de8}.TM.blf

[2010/08/13 06:01:39 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{a98c4342-a6b1-11df-b78a-002618086de8}.TMContainer00000000000000000001.regtrans-ms

[2010/08/13 06:01:39 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{a98c4342-a6b1-11df-b78a-002618086de8}.TMContainer00000000000000000002.regtrans-ms

[2010/09/08 17:33:28 | 000,065,536 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{d471f896-bb8a-11df-82e9-002618086de8}.TM.blf

[2010/09/08 17:33:28 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{d471f896-bb8a-11df-82e9-002618086de8}.TMContainer00000000000000000001.regtrans-ms

[2010/09/08 17:33:28 | 000,524,288 | -HS- | M] () -- C:\Users\Hayden\ntuser.dat{d471f896-bb8a-11df-82e9-002618086de8}.TMContainer00000000000000000002.regtrans-ms

[2009/10/30 17:31:30 | 000,000,020 | -HS- | M] () -- C:\Users\Hayden\ntuser.ini

[2011/09/08 23:33:31 | 000,044,544 | -HS- | M] () -- C:\Users\Hayden\Thumbs.db

[2012/05/24 23:37:18 | 000,001,702 | ---- | M] () -- C:\Users\Hayden\_viminfo

< %USERPROFILE%\AppData\Local\*.* >

[2012/05/23 21:37:13 | 000,114,352 | ---- | M] () -- C:\Users\Hayden\AppData\Local\GDIPFONTCACHEV1.DAT

[2012/07/07 19:17:31 | 001,460,494 | -H-- | M] () -- C:\Users\Hayden\AppData\Local\IconCache.db

[2012/07/05 21:50:31 | 000,000,600 | ---- | M] () -- C:\Users\Hayden\AppData\Local\PUTTY.RND

[2011/07/12 22:42:05 | 000,007,606 | ---- | M] () -- C:\Users\Hayden\AppData\Local\Resmon.ResmonCfg

< %USERPROFILE%\AppData\Roaming\*.* >

[2012/07/09 18:00:00 | 000,788,656 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\Clock+.log

[2012/07/07 19:22:12 | 000,084,904 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\ez_style_engine.log

[2012/07/07 19:22:44 | 000,020,897 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\TMinus.log

[2012/07/09 17:59:31 | 000,000,600 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\winscp.rnd

[2012/07/07 19:23:53 | 000,011,443 | ---- | M] () -- C:\Users\Hayden\AppData\Roaming\wlanmonitor.log

< %windir%\temp\*.* >

[2012/07/09 17:31:17 | 000,001,844 | ---- | M] () -- C:\Windows\temp\hpqddsvc.log

========== Alternate Data Streams ==========

@Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:05EE1EEF

< End of report >

Link to post
Share on other sites

Post was too long for both. In fact, Extras.txt was too long for one post, split it on the HKEY-64 reg section.

Extras.txt:

OTL Extras logfile created on: 7/9/2012 6:05:02 PM - Run 1

OTL by OldTimer - Version 3.2.53.1 Folder = C:\Users\Hayden\Desktop\downloads

64bit- Professional (Version = 6.1.7600) - Type = NTWorkstation

Internet Explorer (Version = 8.0.7600.16385)

Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

11.99 Gb Total Physical Memory | 7.60 Gb Available Physical Memory | 63.34% Memory free

23.98 Gb Paging File | 19.42 Gb Available in Paging File | 80.98% Paging File free

Paging file location(s): c:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)

Drive C: | 931.41 Gb Total Space | 82.37 Gb Free Space | 8.84% Space Free | Partition Type: NTFS

Drive D: | 641.38 Mb Total Space | 0.00 Mb Free Space | 0.00% Space Free | Partition Type: CDFS

Drive L: | 931.39 Gb Total Space | 467.34 Gb Free Space | 50.18% Space Free | Partition Type: NTFS

Computer Name: HAYDEN-PC | User Name: Hayden | Logged in as Administrator.

Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans

Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========

========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.html[@ = Notepad++_file] -- C:\Program Files (x86)\Notepad++\notepad++.exe (Don HO don.h@free.fr)

.ini[@ = Notepad++_file] -- C:\Program Files (x86)\Notepad++\notepad++.exe (Don HO don.h@free.fr)

.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

.js[@ = Notepad++_file] -- C:\Program Files (x86)\Notepad++\notepad++.exe (Don HO don.h@free.fr)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]

.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)

.html [@ = Notepad++_file] -- C:\Program Files (x86)\Notepad++\notepad++.exe (Don HO don.h@free.fr)

.ini [@ = Notepad++_file] -- C:\Program Files (x86)\Notepad++\notepad++.exe (Don HO don.h@free.fr)

.js [@ = Notepad++_file] -- C:\Program Files (x86)\Notepad++\notepad++.exe (Don HO don.h@free.fr)

[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\SOFTWARE\Classes\<extension>]

.html [@ = ChromeHTML] -- Reg Error: Key error. File not found

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

htmlfile [edit] -- Reg Error: Key error.

htmlfile [print] -- rundll32.exe %SystemRoot%\system32\mshtml.dll,PrintHTML "%1" (Microsoft Corporation)

inffile [install] -- %SystemRoot%\System32\rundll32.exe setupapi,InstallHinfSection DefaultInstall 132 %1 (Microsoft Corporation)

InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)

InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()

Directory [bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)

Directory [cmd] -- cmd.exe /k cd "%1" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [git_shell] -- wscript "C:\Program Files (x86)\Git\Git Bash.vbs" "%1"

Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()

Directory [tralih] -- "C:\Program Files (x86)\Trader's Little Helper\tralih.exe" /0 "%1" ()

Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)

Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)

Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]

batfile [open] -- "%1" %*

cmdfile [open] -- "%1" %*

comfile [open] -- "%1" %*

cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)

exefile [open] -- "%1" %*

helpfile [open] -- Reg Error: Key error.

htmlfile [edit] -- Reg Error: Key error.

piffile [open] -- "%1" %*

regfile [merge] -- Reg Error: Key error.

scrfile [config] -- "%1"

scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l

scrfile [open] -- "%1" /S

txtfile [edit] -- Reg Error: Key error.

Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1

Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()

Directory [bridge] -- C:\Program Files (x86)\Adobe\Adobe Bridge CS5\Bridge.exe "%L" (Adobe Systems, Inc.)

Directory [cmd] -- cmd.exe /k cd "%1" (Microsoft Corporation)

Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Directory [git_shell] -- wscript "C:\Program Files (x86)\Git\Git Bash.vbs" "%1"

Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()

Directory [tralih] -- "C:\Program Files (x86)\Trader's Little Helper\tralih.exe" /0 "%1" ()

Directory [Winamp.Bookmark] -- "C:\Program Files (x86)\Winamp\winamp.exe" /BOOKMARK "%1" (Nullsoft, Inc.)

Directory [Winamp.Enqueue] -- "C:\Program Files (x86)\Winamp\winamp.exe" /ADD "%1" (Nullsoft, Inc.)

Directory [Winamp.Play] -- "C:\Program Files (x86)\Winamp\winamp.exe" "%1" (Nullsoft, Inc.)

Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

Folder [explore] -- Reg Error: Value error.

Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"cval" = 1

"FirewallDisableNotify" = 0

"AntiVirusDisableNotify" = 0

"UpdatesDisableNotify" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]

"AntiVirusOverride" = 0

"AntiSpywareOverride" = 0

"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

"FirewallDisableNotify" = 0

"AntiVirusDisableNotify" = 0

"UpdatesDisableNotify" = 0

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== System Restore Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore]

"DisableSR" = 0

========== Firewall Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\DomainProfile]

[HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\WindowsFirewall\StandardProfile]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]

"DisableNotifications" = 0

"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\GloballyOpenPorts\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]

"DisableNotifications" = 0

"EnableFirewall" = 1

========== Authorized Applications List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List]

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List]

========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{0BF00BEA-CB54-4ED7-BD6D-BF1C254E1EEB}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{11FEE81B-0569-4BAC-9E0F-BE9F39AEF7FD}" = lport=138 | protocol=17 | dir=in | app=system |

"{15AE2922-BD77-4D56-A335-8DFDB32FD963}" = rport=137 | protocol=17 | dir=out | app=system |

"{16BB8E0E-121E-410B-854B-C1A076CFE6FC}" = lport=445 | protocol=6 | dir=in | app=system |

"{2442A0C0-3C6D-43E3-BB03-1540D2DAB9AC}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | name=@firewallapi.dll,-28539 |

"{277A4053-001A-4BE8-B3E9-3635E1222BA6}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |

"{285AC358-9C8E-4B03-ACB9-FC330B575C75}" = lport=8382 | protocol=17 | dir=in | name=league of legends launcher |

"{3205BE32-38AC-49F8-BE3A-156C1BB0B784}" = lport=8378 | protocol=17 | dir=in | name=league of legends launcher |

"{37A0F0A0-CD44-4FFB-8FC9-486AC3B3A8A0}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{3BB436AD-E47E-4EB4-A389-4008665F6081}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |

"{3F5E58A8-16AA-4BA8-86AE-B80223D0A273}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{3FF557DB-429E-435A-B446-78088FC1B380}" = lport=8379 | protocol=6 | dir=in | name=league of legends launcher |

"{477640D1-2234-4CA9-9DC4-061338A3C76D}" = rport=138 | protocol=17 | dir=out | app=system |

"{49469242-96EE-4875-8C53-BE79561D2B18}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{4C1CBBEF-E020-40A6-B60E-450D883A4B35}" = rport=10243 | protocol=6 | dir=out | app=system |

"{4EC3DEDA-C6BE-4880-A043-D35A870C92C6}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{59656FA3-7935-4037-80ED-8866D66CABFA}" = lport=8380 | protocol=17 | dir=in | name=league of legends launcher |

"{5AE3D3E4-51CC-477C-BA2A-C37BD6D531C9}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |

"{5F1E3FB1-2CFE-4C1E-B520-3BB2F7963BAC}" = lport=139 | protocol=6 | dir=in | app=system |

"{68D5C033-4587-46C8-A7E5-2F96DD00CD58}" = lport=10243 | protocol=6 | dir=in | app=system |

"{72CCFAAC-936B-4C68-9F0A-176BFEE1771F}" = lport=8378 | protocol=6 | dir=in | name=league of legends launcher |

"{77F904E0-6146-41C4-9F82-5C51069D6662}" = rport=445 | protocol=6 | dir=out | app=system |

"{7F2AFE67-2235-42BE-AE78-4FD84C156DE5}" = lport=8383 | protocol=6 | dir=in | name=league of legends launcher |

"{82F6F1D7-806A-4955-A7C9-CCB646D5BD51}" = lport=57166 | protocol=6 | dir=in | name=pando media booster |

"{89EA3984-5145-41B8-B512-C1B96AB2F6DE}" = lport=8379 | protocol=17 | dir=in | name=league of legends launcher |

"{8E5E4640-E509-42AC-9139-2A6C13573737}" = lport=137 | protocol=17 | dir=in | app=system |

"{958326FC-4DC4-4E90-AD50-27098FC14D10}" = lport=57166 | protocol=17 | dir=in | name=pando media booster |

"{96059D44-2A76-4BBB-A7CB-ACB24DBE4294}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |

"{A5BAA3BB-C947-4823-A6EC-7880D0379785}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |

"{B330C934-B8A8-4C4C-90D3-386C91575F2D}" = lport=57166 | protocol=17 | dir=in | name=pando media booster |

"{C05A7E4A-1BCC-4B92-BF6B-0406E3EB040B}" = lport=8382 | protocol=6 | dir=in | name=league of legends launcher |

"{C491EC9F-C94A-4FA2-AD72-B55D8B3542C7}" = lport=8383 | protocol=17 | dir=in | name=league of legends launcher |

"{C84FEEE5-7F34-4AD1-AAAE-EF1952C25B5B}" = lport=8381 | protocol=17 | dir=in | name=league of legends launcher |

"{E1B4FE1B-095D-4EB5-AF9A-B4492FAB52B3}" = lport=8381 | protocol=6 | dir=in | name=league of legends launcher |

"{E5258113-BDD6-46CD-BA94-AEFF7158D79C}" = lport=2869 | protocol=6 | dir=in | app=system |

"{E5C1A033-CD71-4F84-B240-F8150E3C8ACC}" = lport=3724 | protocol=6 | dir=in | name=blizzard downloader: 3724 |

"{EBBC71E3-2494-441F-A3CE-603EA3B2288A}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |

"{EC68E42B-88F9-455D-AFDC-4DE978A6023D}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |

"{F959349A-92EE-4ABE-8A68-C8226EAF9F20}" = lport=57166 | protocol=6 | dir=in | name=pando media booster |

"{FB9FBD8C-AC45-4C0D-9CC0-2D86E207401F}" = rport=139 | protocol=6 | dir=out | app=system |

"{FC47D23B-2DBA-4474-AE60-C2C7E366255B}" = lport=8380 | protocol=6 | dir=in | name=league of legends launcher |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]

"{002B5F5A-274B-4894-8EE7-175AA232512A}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |

"{00D0BAD0-A8F3-469F-B07A-BDC4931A7A28}" = protocol=6 | dir=in | app=c:\program files (x86)\subsonic\subsonic-service.exe |

"{0208BF5D-9D87-47E1-AEFF-3A15F986D463}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |

"{02E15E9E-DB68-4BE8-99AA-841E52DFD2DD}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\greed corp\game.exe |

"{037A2BC4-9DCB-4576-9998-688544CFED3F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sam and max episode 1\sammax101.exe |

"{038C661E-1695-411A-A1CD-84195FB1EF23}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |

"{03D41720-C30D-46D3-890E-31694EF92564}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{03F9DE58-EF86-4655-AA60-7A0709AE09B2}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |

"{0525F81B-5F63-4310-BD4D-367908205EEE}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\starcraft ii.exe |

"{0654988B-E320-4243-A937-646F850D4447}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bit.trip runner\runner.exe |

"{066414B0-CDEA-4B32-8B3F-E82CFC167620}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warhammer 40,000 space marine\spacemarine.exe |

"{069E2031-A7E1-43A6-A9ED-A01D1332E1EA}" = protocol=1 | dir=out | name=@firewallapi.dll,-28544 |

"{06EA6B52-87B3-4F62-8BC1-E808AB22696D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe |

"{08114DA3-DDEC-438A-AED8-9782C49E2F27}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine\trine_launcher.exe |

"{08F45382-06EC-46D4-8F0D-4F9BF71A4CAF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\droplitz\cascade.exe |

"{0944F576-63C3-4FE5-B44F-4EBC4192728F}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.998\agent.exe |

"{099B7E4E-6CA2-440A-BB61-E385E1475522}" = protocol=17 | dir=in | app=c:\users\hayden\appdata\roaming\dropbox\bin\dropbox.exe |

"{0A6928C5-E3E4-40CA-AE1C-5A24A6262D7C}" = protocol=17 | dir=in | app=c:\world of warcraft\backgrounddownloader.exe |

"{0C699D54-8282-4A3C-A9DD-B715B2666D4F}" = protocol=6 | dir=in | app=c:\program files (x86)\rayv\rayv\rayv.dll |

"{0D19E2F5-8B99-435B-BDF9-89CB5C98F594}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\frozen synapse\frozensynapse.exe |

"{0DB6548C-FAF1-4287-89D8-CA313EF86AE8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\beathazard.exe |

"{0DE5B871-6D26-4792-A472-E40E81662D34}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword.exe |

"{0F2250D3-B75D-4588-8934-3BEEC6BF063D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |

"{10ABD721-CC49-49CB-AD10-0A4146D87437}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |

"{111A3190-EA79-4B73-9B45-256C77929033}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |

"{112D05DD-BA0F-420A-AC97-DD821DE4F3CF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\runme.exe |

"{1246C013-512F-43F7-AA82-BCD74C8D2055}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\zwei024\counter-strike source\hl2.exe |

"{12F29177-16F8-484F-9BC3-214F6159F3A2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer red alert 3\support\ea help\electronic_arts_technical_support.htm |

"{13A8ABC4-F4FE-4E66-9412-13ACCA5C14FA}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hoard\win32\reuben.exe |

"{14C1029E-0A29-424B-A417-C7884408FF7E}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqtra08.exe |

"{154A78A9-F818-43EE-9631-31BDEF58618C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tropico 4 - demo\tropico4-demo.exe |

"{15F50C51-A1CA-492F-9BEC-67036EBE6EE8}" = protocol=17 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |

"{15FB1869-74B1-44EC-AFA8-B23CCAF953C5}" = dir=in | app=c:\program files (x86)\motorola mobility\motocast\bin\motocast-thumbnailer.exe |

"{1626A4E1-2644-4B80-B3FD-31EEBED1182D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\custom.exe |

"{16D5A2CB-F88E-44B4-BB5D-53D92B5D0D23}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chime\chime.exe |

"{18B781A7-5E75-407E-B6EA-DB04CF92D6FB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeons\dungeonsstarter.exe |

"{1924F4C6-B825-4307-8AD2-59646D2AE216}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe |

"{1A986854-C3EF-4E50-9962-30485254ED62}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword.exe |

"{1A9F5427-3ED5-4704-BF4E-A32176347958}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpiscnapp.exe |

"{1AB49F4A-1F27-4B51-A092-FBE33F4F08CE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |

"{1AD40660-D715-4571-9DC5-BD8B11AC9D34}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |

"{1ADC62E7-8604-4E4A-BA6E-9C0D8BB02CD6}" = protocol=17 | dir=in | app=c:\program files (x86)\stardock games\sins of a solar empire\sins of a solar empire.exe |

"{1BEE8EB9-495F-4B47-8E59-D135CEC48BE5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cogs\cogs.exe |

"{1F6AF81B-E4BA-4C3E-BBB4-06593B233711}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\doc clock - the toasted sandwich of time\doc clock.exe |

"{1FA9095B-4453-4DA4-9F5A-5AB14074142A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\kane & lynch 2 - dog days demo\kl2.exe |

"{205DCC9D-C3C3-441E-96CA-F473DE68A7E7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine\trine_launcher.exe |

"{215D8445-BF8D-487C-97CE-C2C80CF8DDD8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\world of goo\worldofgoo.exe |

"{21643C83-BAD2-48EB-9ADE-62320EA9D937}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hoard\win32\reuben.exe |

"{216C90B0-42FC-495F-BBEE-3D3A6FDC4391}" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |

"{219491A6-6A2C-4C7C-A858-FA0CD64BF190}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |

"{21BF00E1-C6F1-456C-8405-61D4C8DE809F}" = protocol=17 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |

"{238C3131-8D38-4920-985B-7A4A1B2520B8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darwinia\darwinia.exe |

"{23CFCAA5-F2EE-4BC5-902C-A8787449282B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\shank\bin\shank.exe |

"{2416A7AB-D85D-4F1E-A032-70725746BC17}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\half-life\hl.exe |

"{25DCD63D-4BC4-41B2-9E5C-EBBE9A3BF592}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |

"{27005A99-BBD9-421D-98D8-1ED6AE03605F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\city of heroes going rogue\cohupdater.exe |

"{2709A78D-9B16-42D0-BDAA-8B3B8543ACBE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |

"{27BFA55B-A72B-41EE-A3EE-C19B7E41F301}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |

"{281D7031-C4CD-41FB-B647-E06382F84624}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warhammer 40,000 space marine\spacemarine.exe |

"{2889D35A-52D8-4E9E-8549-667BF01C986E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |

"{288BF58F-4F3F-4A55-9512-6760A4F71021}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\darwinia\darwinia.exe |

"{28B98414-F937-4D18-B4D9-695FB826A9E9}" = protocol=17 | dir=in | app=c:\program files (x86)\rayv\rayv\rayv.exe |

"{29C71869-A1E0-493F-A11E-FFFBABA33D32}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpsapp.exe |

"{2A094672-EBD8-40E4-9129-57B6F469D008}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |

"{2AFADC1B-4274-4775-8500-289A45290A49}" = protocol=6 | dir=in | app=c:\program files (x86)\rayv\rayv\rayv.exe |

"{2B5BC8B6-3B45-4D66-9039-EC25B6163D73}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |

"{2BA0829C-4CE9-43CE-846D-EFC71FA9BF54}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{2CB1C2A1-2272-432C-BA5F-B70F12B0C782}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty\codmp.exe |

"{2DE52AD4-5F2D-4B0B-92B2-AAE9FC64301D}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\warlords\civ4warlords_pitboss.exe |

"{308208AB-033D-4E04-9486-B36099F02C6D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |

"{30D7BDE6-C75E-429F-96BB-F1AA98E5DC93}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgplgtupl.exe |

"{30E071A7-7085-4FEB-924F-2049E6892462}" = protocol=6 | dir=in | app=c:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe |

"{3485E8C8-8891-4E92-9A16-F8859F5AB6B8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\metro 2033\metro2033.exe |

"{3539DC8C-B66F-4616-956E-1EDAB6543B80}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\doc clock - the toasted sandwich of time\doc clock.exe |

"{35A9519E-44FB-4611-A48F-77EDA3E2B7E6}" = dir=in | app=c:\program files (x86)\avg\avg9\avgemc.exe |

"{35BCD29D-5770-4953-B975-5A7C921E33BE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |

"{36D77782-1B40-4DE7-8170-30BDE4BADEEE}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{37B6B67D-85E5-486D-847F-4FCDBFCDD99A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |

"{37CA9A04-DCAB-4422-8226-3EB667A4D9E7}" = protocol=6 | dir=in | app=c:\world of warcraft\backgrounddownloader.exe |

"{38739EEA-37F3-4667-AF96-135EB25E2864}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeons\dungeonsstarter.exe |

"{3923ABEF-8C25-4E72-8A08-63EC82826F52}" = dir=in | app=c:\program files (x86)\motorola media link\lite\mml.exe |

"{3AB2FCAA-A148-4F82-8FF6-C6DED66AE724}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |

"{3B09239A-272A-405C-B280-B5C8574B9145}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |

"{3B52D8F5-13D7-4738-A9AF-CD34F1DD0805}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |

"{3B7F6BC4-F9D8-46D7-B2D4-E565C4148945}" = protocol=17 | dir=in | app=c:\program files (x86)\rayv\rayv\rayv.dll |

"{3CF53539-3D8D-4E25-8872-3CBE3B5097F1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warhammer 40,000 space marine\spacemarine.exe |

"{3D09F801-019D-4866-8277-19AAA73D9B04}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |

"{3D42A4EA-D5DA-4ACA-9506-7B1535B5BD86}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead island\deadislandgame.exe |

"{3D42C4FA-4C1D-4203-B3AB-2D3848D9D497}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ultimate doom\ultimate.bat |

"{3E618CBA-65B3-46BD-A117-0FE551607C87}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torchlight.exe |

"{3ED02E97-7ECB-46F2-AA71-C5D3F0498D66}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\city of heroes going rogue\cohupdater.exe |

"{3FB489A9-C035-464A-91AF-C3F2E002A39A}" = protocol=17 | dir=in | app=c:\program files (x86)\rayv\rayv\rayv.dll |

"{3FDF2912-9383-4EEC-8D11-0A4D676B65B5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock\builds\release\bioshock.exe |

"{40770B26-2422-4B4F-BD0F-38D4F21A97B8}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqgpc01.exe |

"{40D493EA-E9F5-4CA3-9D43-4B60AAB92930}" = protocol=6 | dir=in | app=c:\riot games\league of legends\air\lolclient.exe |

"{412E7EC5-6995-4CB0-A920-7BF3AAACC089}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv.exe |

"{416E0CDA-D012-4836-A8FB-5AA523659655}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqkygrp.exe |

"{41E4C205-726C-4ACB-8914-934952AB7232}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqcopy2.exe |

"{432B8562-AE40-4F76-8764-ECE647C3E411}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magicka\magicka.exe |

"{438EB413-5C94-4A85-A608-0758442EF0F2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\machinarium\machinarium.exe |

"{442E027B-4DF6-4091-A915-17A3CF797AFC}" = protocol=6 | dir=in | name=bt |

"{4432DE4C-EAED-4589-97D8-46B2AB29D209}" = protocol=6 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |

"{4465B532-1B99-47C9-ABF0-71CBE35A7359}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\pc gamer digital edition\freakshow.exe |

"{44B7C5A8-88DC-4D91-8B3C-E322F6FCD575}" = protocol=58 | dir=in | name=@firewallapi.dll,-28545 |

"{47647C22-0C57-482D-AB5D-A3378CA105FE}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0-enus-downloader.exe |

"{479156B5-F890-45D4-A071-A11DAA657A20}" = dir=in | app=c:\program files (x86)\avg\avg9\avgam.exe |

"{4826E6AC-DD1D-4F2E-A885-4ECB3D4CA51B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\city of heroes going rogue\installer\ncwlaunchersetup.exe |

"{48F6F927-E0F4-4E17-B6FF-8A19E0704D7F}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpfccopy.exe |

"{4A9746E6-C836-4A31-9552-01A226695A68}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |

"{4CA14DA9-DF21-4704-83BB-DFE061D1DCFC}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\borderlands\binaries\borderlands.exe |

"{4D3749B8-22CD-4D8F-972D-911580B3BF4A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex\system\deusex.exe |

"{4D68E4E1-0D31-41DF-A5C4-80E4E4FFF8FB}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\warlords\civ4warlords.exe |

"{4D8602FE-CE45-474F-BFC7-DBD56437A668}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\launcher.exe |

"{4DD551F4-B342-4060-B3BE-705664C4582F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\city of heroes going rogue\cohupdater.exe |

"{4DF8A5DF-8287-4DBA-9DD5-3A3356F0177D}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\runme.exe |

"{4E074A51-32D4-4BF0-BA69-2CF5F8D9A556}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v - demo\launcher.exe |

"{4EE0305A-2311-4952-9F0B-0BA92DB0A186}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\world of goo\worldofgoo.exe |

"{4EF119B8-51D9-4D87-877E-37AC26D3C586}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torched\editor.exe |

"{504D6ED2-DFB2-4B9F-89F8-05121ACB67E5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bit.trip runner\runner.exe |

"{523EF84B-BD10-40CA-BBF8-A8E4A5612A5A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\hirezbridge.exe |

"{53A8E138-61E9-4593-B4EC-F38093EAFE2A}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\docs\ea help\electronic_arts_technical_support.htm |

"{5490F4FF-C062-4904-8E3D-D9D6C50B6580}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock\builds\release\bioshock.exe |

"{54D1248F-3137-4767-AF44-D736E7828804}" = dir=in | app=c:\program files (x86)\hp\hp software update\hpwucli.exe |

"{54D2DEC5-C72F-4C7B-AE60-FD3666959986}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeons of dredmor\dungeons of dredmor.exe |

"{5551599A-965E-4F94-84AE-B864465E7BA5}" = protocol=6 | dir=in | app=c:\program files (x86)\subsonic\subsonic-agent.exe |

"{55845752-07BB-4336-B4FE-103B922F5B83}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |

"{561DEAF0-319C-4C29-91AC-341672553FE6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\launcherbin\hirezlauncherui.exe |

"{58058423-D8D9-4CF2-A4EE-D8E8689E511D}" = dir=in | app=c:\program files (x86)\avg\avg9\avgdiagex.exe |

"{58FC9970-59B9-4BAB-B6D1-470932540B71}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cogs\cogs.exe |

"{5948E542-C9FB-42B9-8EB3-E045F22B5A4C}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead island\deadislandgame.exe |

"{597BF9A1-E3EE-4711-BB35-D29B20E3EB69}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\beathazard.exe |

"{5A0CAAAB-C696-4413-A918-83775A807A18}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |

"{5A35F795-F9BB-412B-B153-169A73A1EC0F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tropico\tropico.exe |

"{5CF93739-4A40-4864-A894-1B8839C20BFA}" = dir=in | app=c:\program files (x86)\hp\digital imaging\smart web printing\smartwebprintexe.exe |

"{5D72C0E8-185D-470D-B61C-61002C6F0F8B}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v - demo\civilizationv.exe |

"{5DCE259E-4C13-4AE7-8CF4-2DCFC37BCE4A}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{5F0D0AB5-7A48-4F28-A934-8114BF8E3FD0}" = protocol=17 | dir=in | app=c:\program files (x86)\subsonic\subsonic-service.exe |

"{5F15A4B6-921F-4763-BE70-DD6BBCA7AF2E}" = protocol=6 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |

"{5F8FC459-3923-415D-BAD7-B242A6FAE984}" = dir=out | app=c:\program files (x86)\motorola mobility\motocast\motocast.exe |

"{6095D963-A70B-46DD-B4A3-73325454BDFD}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\blizzard downloader.exe |

"{60DB0925-131D-44C1-9565-50F633545D10}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torched\editor.exe |

"{60E06B79-C4F0-4482-AA6D-E0FAF8AFCB8E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |

"{610BA63E-67EC-498A-9F0E-BCEB4CB29E4B}" = protocol=17 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe |

"{61BA473F-0B2A-4A74-896B-872B1A42C149}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\unreal tournament\system\unrealtournament.exe |

"{635A654F-B158-4199-B9F3-4E191A283784}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\kane & lynch 2 - dog days demo\kl2.exe |

"{63ABD89E-1FDB-4A0D-BEB3-64082C773587}" = dir=in | app=c:\program files (x86)\skype\phone\skype.exe |

"{64A42F77-B930-45F9-89FA-8FD97D082125}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\sourcesdk\bin\sdklauncher.exe |

"{64B3485F-0237-49FF-AB16-8E6185F6C7D8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sacrifice\sacrifice.exe |

"{66C6B7B2-2451-4393-8BB7-1C4C89BBD104}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rage\rage.exe |

"{66FA5651-F244-45D3-B1F3-8343F2E8C8DA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |

"{67A9BE63-71CC-447C-B69A-3F0369DE1049}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |

"{69DCC6E3-33D6-45A9-A0A0-22E1E5285D08}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hoard\win32\reuben.exe |

"{6AA01BE3-994A-497F-A34C-EAC40A3B6E65}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10314-to-3.2.2.10482-enus-downloader.exe |

"{6AC63BA9-BEE5-4A0D-849B-928B9D48EC4C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swords and soldiers\swords and soldiers launcher.exe |

"{6AFC626F-9C95-4FA6-8756-DCBD15238C94}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |

"{6B20347C-238C-4A43-97E1-FA097A934FA9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer red alert 3\support\ea help\electronic_arts_technical_support.htm |

"{6B32E636-2485-40CB-A783-D2CF1622508C}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\warlords\civ4warlords.exe |

"{6B48F25D-34E0-4C05-B010-0D37F0FFE434}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\docs\ea help\electronic_arts_technical_support.htm |

"{6BBA8818-DD0F-487D-BA1C-696886D5B86F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torched\editor.exe |

"{6C20AD3F-0BF0-49EB-8603-82A10F0D9480}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |

"{6C2F70C7-6741-4145-ACEF-0AB2923F2273}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |

"{6D2E7CA3-C5C4-4ED6-A21F-413EA10B83F3}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0-enus-downloader.exe |

"{6D31FC02-CBBB-4642-9EF9-5C13F8EA5BED}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |

"{6DE31F61-DECC-4C76-B113-47567789B64D}" = dir=in | app=c:\program files (x86)\avg\avg9\avgnsa.exe |

"{6F5CDFE4-F8BF-43DC-A753-E135F3C8C362}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\runme.exe |

"{6FC22FE5-B220-4BA4-82EC-65A10ED3D0D2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\chime\chime.exe |

"{6FD7F077-0131-4E8B-B98E-9A97F33E8350}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\counter-strike source\hl2.exe |

"{7035776E-5DA9-4CCB-AB53-0C1C50F4BEC5}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\warhammer 40,000 space marine\spacemarine.exe |

"{7080791F-A7A6-499F-A813-FA73A89FA6E3}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |

"{70F2984A-E2BE-4E6A-B5DD-3ABD73F86862}" = protocol=6 | dir=out | app=system |

"{7184CDAA-8402-446A-A15C-5B54FAD5D90A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tribes\binaries\win32\hirezbridge.exe |

"{71C7EE90-80F8-41BE-AA09-5A1629AB9431}" = dir=in | app=c:\program files (x86)\motorola mobility\motocast\motocast.exe |

"{7290B4D9-EDBB-4C1B-B0E4-ADFEC34270F6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\globalagenda.exe |

"{73450FFA-1624-401A-96F5-91FC90196D3E}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |

"{738438D8-5529-4531-8C70-BBE7505B9813}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgm.exe |

"{75143EC0-1825-41BF-B9FF-6E8E383858C9}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\darwinia\darwinia.exe |

"{7664A0C5-6447-46A1-940F-D385D53D2444}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\recettear\recettear.exe |

"{76A991DE-1CD7-4AA2-9862-798EEC22700E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\counter-strike source\hl2.exe |

"{776A0A85-9287-4ACC-8D2A-F823026D0CBF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe |

"{77C2A9E2-EB9B-4261-853B-B979B3DC8076}" = protocol=6 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.2.10482-to-3.2.2.10505-enus-downloader.exe |

"{79B1749B-F1BA-45D4-96CA-C7938C60A881}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\launcher.exe |

"{79E2E1CA-35B1-4060-B729-857E7F70CC8B}" = protocol=17 | dir=in | app=c:\users\hayden\appdata\local\apps\2.0\9qato2qe.d4r\ob4wo6gp.mxn\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\curseclient.exe |

"{7B30A6CD-A3BE-4518-9889-A1C4BCB863D5}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeons\dungeonsstarter.exe |

"{7B8535D0-F4C8-49A5-B7AA-16A198A4F592}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |

"{7BE4F349-0E00-4FAC-9E28-687D1ABF20E3}" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |

"{7C64AEA9-5E10-41BB-A35A-52782A2076FC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bit.trip beat\beat.exe |

"{7D031514-28FA-44F2-89C2-EBDA6D150B26}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\launcher.exe |

"{7DB814EB-FB6E-413D-B8C9-885A8F313D62}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\metro 2033\metro2033.exe |

"{7E5E8E56-9CE6-4548-9D5A-7ECD1C11A62D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tropico 4 - demo\tropico4-demo.exe |

"{7F27A64B-0DA2-44F4-8649-CA00EAAA24DA}" = protocol=17 | dir=in | app=c:\program files (x86)\subsonic\subsonic-agent.exe |

"{7F995416-1CC6-473D-AF94-BC6806C3E715}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{7FA84D5A-31AE-4625-8809-B39E479B4FE2}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hardreset\hardreset.exe |

"{80505DB2-6856-4F67-9C36-6055620BE915}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\magicka\magicka.exe |

"{80BFAA3A-1927-4902-87B7-E418F3ABF2D0}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqsudi.exe |

"{81AD3CDA-C1B3-4379-84EE-CF38B7B7149E}" = protocol=17 | dir=in | app=c:\program files (x86)\paradox interactive\majesty 2\majesty2.exe |

"{8232C557-B7DD-4B33-8640-4AE5E5A97D2E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\city of heroes going rogue\cohupdater.exe |

"{83973EAB-79CF-417D-9038-6348F0BA7992}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\beathazard.exe |

"{83CF1D77-0597-4D8C-9A0B-48E68827EF2E}" = protocol=17 | dir=in | app=c:\program files (x86)\subsonic\elevate.exe |

"{84EF8A67-8AA8-4138-9F30-69DDE1BDE9C6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\darwinia\darwinia.exe |

"{853EB62E-21D3-46C6-8BAC-4A471BB47D6A}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\warlords\civ4warlords_pitboss.exe |

"{856A8B7E-807D-4EF0-B3AE-B1927AB73918}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\zwei024\counter-strike source\hl2.exe |

"{86ECFA93-B6F7-40F3-9ACF-B6D9D08C8E7E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe |

"{870115EF-8DE2-41C6-98FA-8EAFBC0C5AA4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty\codmp.exe |

"{87219CBC-79C5-4C57-A945-313190CF2BFE}" = protocol=17 | dir=in | app=c:\program files (x86)\curse\curseclient.exe |

"{87343F11-1418-4680-B33B-C6A685F70C7B}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{87C53412-380A-440E-A94B-9FCCF7C37B95}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{88247358-24F9-41D6-9788-5B2B3F64B6B1}" = protocol=6 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |

"{88340169-5704-4E9C-9965-A55F355A85A0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |

"{8854D9D1-DCB3-4F36-863E-1A933E10B8B2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the medic\smp.exe |

"{88EBE59E-F97B-41FD-9B53-077EE37A3A4F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war ii - retribution\dow2.exe |

"{8C70046C-E349-445D-BEC7-401FF0DBF159}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\launcher.exe |

"{8C88D4C5-AEC7-4B10-8672-02D83F7C01D6}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |

"{8C8F504A-9608-4149-8B9A-8B2B89167683}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |

"{8E05EEC5-277A-46C5-8D77-917DE1321FE0}" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |

"{8E1090BB-CF86-492D-B6F5-D7BA654F1623}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |

"{8E6B293B-AFE4-4372-8E1F-359C54F160E0}" = protocol=6 | dir=in | app=c:\program files (x86)\stardock games\sins of a solar empire\sins of a solar empire.exe |

"{8E936FB6-5F31-441A-B6C0-519113A5320F}" = protocol=6 | dir=in | app=c:\program files (x86)\rayv\rayv\rayv.dll |

"{8F1B5D67-1AE0-4E5E-9A6B-5571FB89780C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\defensegridtheawakening\defensegrid.exe |

"{91595C4A-3B3A-4870-8544-90894941685F}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |

"{9179331B-7086-4CCB-89A3-E75B58C51CEB}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\sourcesdk\bin\sdklauncher.exe |

"{9449ACFA-247A-4C64-9C68-44B721A6BBE1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\r.u.s.e. demo\ruse.exe |

"{94586B68-2260-4542-A5AF-C4EECB745225}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |

"{9577BA44-E27C-44B8-9FC7-87AD8BB17DE1}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\rage\rage.exe |

"{95EA0F07-D91D-4ECA-A4D9-E84291967C28}" = protocol=6 | dir=in | app=c:\users\hayden\appdata\roaming\dropbox\bin\dropbox.exe |

"{97705857-9CA6-40FF-8EE9-4E18B79F1F16}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lumines\lumines.exe |

"{9850623C-33AD-4724-8738-BDD5B123635E}" = protocol=17 | dir=in | app=c:\program files (x86)\rayv\rayv\rayv.exe |

"{9858CD9A-F289-4344-90B4-97D81E813133}" = protocol=6 | dir=in | app=c:\programdata\battle.net\agent\agent.976\agent.exe |

"{9A0EA396-3E65-45DD-BE6F-C5A0E93BE803}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\half-life source\hl2.exe |

"{9AD86FCE-F7EB-44AB-AE44-80E607D50BA5}" = protocol=17 | dir=in | app=c:\users\public\documents\blizzard entertainment\world of warcraft\wow-3.2.0.10192-to-3.2.0.10314-enus-downloader.exe |

"{9BCEC170-86C0-4EDD-A77B-1F076B788B82}" = dir=in | app=c:\program files (x86)\common files\hp\digital imaging\bin\hpqphotocrm.exe |

"{9D508674-1627-4683-992E-560C094570C8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\swords and soldiers\swords and soldiers launcher.exe |

"{9D62FC88-31CE-4A5D-B806-90C66A0E3A5B}" = dir=in | app=c:\program files (x86)\avg\avg9\avgupd.exe |

"{9D6C50C7-7DD6-40C4-A73D-5AFF452F9531}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\docs\ea help\electronic_arts_technical_support.htm |

"{9D6DF8DA-AAC8-4410-A42A-12B328B712FE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\pc gamer digital edition\freakshow.exe |

"{9DD705E7-84FD-4D47-9FD6-D87F49B77097}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout 3 goty\falloutlauncher.exe |

"{9E6F6822-BE37-4672-903E-DF7FF8D15717}" = protocol=6 | dir=in | app=c:\program files (x86)\subsonic\elevate.exe |

"{9F5DE8B3-DA53-4FF9-B3B6-53A37EC3CDB8}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v - demo\launcher.exe |

"{A0A9CBCD-A0C9-4504-8A93-717FCC0F7AB0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bastion\bastion.exe |

"{A0CE1CDC-FEF6-4877-B39A-F3F1B633B01D}" = protocol=17 | dir=in | app=c:\users\hayden\appdata\roaming\dropbox\bin\dropbox.exe |

"{A102CFC3-22F8-4A61-B7BA-FDA24D4E5413}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine\trine_launcher.exe |

"{A10C5F24-6707-4C4A-9C19-59B2F1A721D2}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\half-life\hl.exe |

"{A174977D-9292-4888-BE00-26EBCDD5E8BE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ultimate doom\ultimate + mouse.bat |

"{A334A225-55F4-4A24-9000-CDDC8ABC80EE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\srcds.exe |

"{A456AC66-CD83-4355-8E08-21DB94FF099B}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer red alert 3\runme.exe |

"{A57C343D-4C18-439B-BE61-C1380A6C8798}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

"{A5D516EE-BC4F-4B9E-8966-AB5BE9CEBBCF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war 2\dow2.exe |

"{A677E1F0-A3CA-4EB2-A9D4-FE1D3FDDE8FA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\plants vs zombies\plantsvszombies.exe |

"{A7A03422-1BA1-4CBA-A7FC-77D6D2687D9D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\insideastarfilledsky\starfilledsky.exe |

"{A83BF519-B48C-44EB-A778-74B5E59B4D00}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe |

"{A87F97CD-544A-4065-8196-8E06D2068EAF}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\r.u.s.e. demo\ruse.exe |

"{A8DBDE8A-AEB5-4648-BFAF-7ACF9C038517}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cthulhu saves the world\cstw.exe |

"{A9507136-6964-459A-A7EA-D67CF7FFA7C7}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\dead space.exe |

"{A9A0461B-318E-451E-A862-0CF978D8E0E0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\beathazard.exe |

"{AA424310-1561-4E18-AFB8-EF1362256424}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |

"{AA5499CA-0802-4213-8526-95A7B6ED0834}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\sourcesdk\bin\sdklauncher.exe |

"{AB14E454-6430-4334-88A9-3EED73776A38}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\peggle deluxe\peggle.exe |

"{AB6B8062-CC9F-4502-BEE2-132A49AE912A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sacrifice\sacrifice.exe |

"{AC745FD4-BAFA-4024-B7CB-E65D1AC05977}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeons of dredmor\dungeons of dredmor.exe |

"{ACE72642-F1A8-4018-A7F0-957E38E0E071}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2launcher.exe |

"{AD0F3BCD-F7C8-4B06-937F-985A5D858028}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty\codsp.exe |

"{AD2DCABD-3E60-4F14-A372-BC715C1DD980}" = protocol=6 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |

"{AE4625A1-94AE-44BE-9EE0-87EB64715821}" = protocol=17 | dir=in | app=c:\users\hayden\appdata\roaming\spotify\spotify.exe |

"{AE62177F-4338-4156-B60D-4B049A4B3A2F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\lumines\lumines.exe |

"{AE774292-B970-43D9-977D-06B222A05295}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |

"{AEA7BC27-8628-4A01-9AA9-D92C034F22A0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ultimate doom\ultimate + mouse.bat |

"{AFC4CAC2-9D1B-4F43-BE45-069804929A32}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqste08.exe |

"{AFE4BAB0-912B-4A50-B401-4B471F4B9EB9}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\opposing force\hl.exe |

"{B259915C-F76A-4387-BC9C-17081B3EA58D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sam and max episode 1\sammax101.exe |

"{B49A0053-0947-4FB0-9801-465952BEF687}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\globalagenda.exe |

"{B4AA605E-DB44-42BB-8C79-01773E515A89}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |

"{B50159CB-A4B3-4DBE-AB72-7A365FCF9145}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |

"{B5E375FE-B010-46E2-9EBF-0220721B0F91}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\city of heroes going rogue\installer\ncwlaunchersetup.exe |

"{B61DC218-9540-417C-99C9-0BE5944E7BA1}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii.exe |

"{B62A0A18-6048-46EE-818A-B20F3B6DD918}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\unreal tournament\system\unrealtournament.exe |

"{B6A88F66-44DA-4CD2-9546-5CCD9742156E}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hardreset\hardreset.exe |

"{B6BB052B-0781-4F84-9F31-1B003974BB14}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\the witcher 2\launcher.exe |

"{B6CE1E18-9AA9-496C-A7B1-30202A14DF4F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex - human revolution\dxhr.exe |

"{B717E584-3287-46C2-8823-56D648FB48C1}" = protocol=6 | dir=in | app=c:\program files (x86)\rayv\rayv\rayv.exe |

"{B79C4166-0CC9-43CE-A8C1-F62A7BD3D9A0}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.954\agent.exe |

"{B8818F2E-6E37-45C7-A628-0CF0C14C249D}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steam.exe |

"{B8DEDAD1-4976-420A-B803-04166B4C9AD3}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\droplitz\cascade.exe |

"{B8EDB48E-F229-4004-9AC1-C040A1838AB4}" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |

"{B95BC13A-1B5A-4ED8-BB43-57BE2D15CC74}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\frozen synapse\frozensynapse.exe |

"{B9D38089-E963-4524-B78D-6D1E144A6740}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daorigins.exe |

"{BAE77CF8-4EDF-489B-B072-20E302CE470C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\audiosurf\engine\questviewer.exe |

"{BBFAD126-2F66-46E1-8E82-DBC6FF14957E}" = protocol=6 | dir=in | app=c:\users\hayden\appdata\local\apps\2.0\9qato2qe.d4r\ob4wo6gp.mxn\curs..tion_eee711038731a406_0004.0000_d322ecea565577c8\curseclient.exe |

"{BCC1EBF8-306C-4231-8ADC-C22650748C5A}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout new vegas\falloutnvlauncher.exe |

"{BE1B2EFA-E280-46CB-AEA3-16C4DB94944C}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torchlight.exe |

"{C058B413-4A1D-487D-8631-433BC679D985}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\cthulhu saves the world\cstw.exe |

"{C1C133B4-51C5-4986-A8AB-4229D575B507}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead 2\left4dead2.exe |

"{C2167389-AFCF-4626-ABC4-3F75A0F312D8}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\tropico\tropico.exe |

"{C31F73AE-0513-4ADB-AED0-CFBA8ED8485B}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqpse.exe |

"{C34F89D5-2DE9-4BE6-B2F4-1BA7FDD95996}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\binaries\masseffect.exe |

"{C421F7AE-D670-48E2-B596-71F6EA425317}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\call of duty\codsp.exe |

"{C52090FD-ABD6-4987-A001-2E4B56ABE046}" = protocol=6 | dir=in | app=c:\users\hayden\appdata\roaming\tonido\tonido.exe |

"{C60DDFA4-C7C6-4341-A6FD-9AFAF3CF2F61}" = protocol=6 | dir=in | app=c:\users\hayden\appdata\roaming\dropbox\bin\dropbox.exe |

"{C68DDFFD-97FB-4B70-A89E-38586AB5D9CF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\hoard\win32\reuben.exe |

"{C6A949AA-7220-4B0F-B720-B045CC19882D}" = dir=out | app=c:\program files (x86)\motorola mobility\motocast\bin\motocast-thumbnailer.exe |

"{C71BC8B8-5004-40F9-A8A4-F1BE6C986F13}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\half-life source\hl2.exe |

"{C7305834-A901-46F4-8EC5-C73F27E8CF56}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\killingfloor\system\killingfloor.exe |

"{C7682CD2-091E-497E-9F55-4018A6D49E24}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\blizzard downloader.exe |

"{C8824D16-3AB5-405A-98D2-9BA7EC63AD03}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\peggle deluxe\peggle.exe |

"{C8C1B513-AE8A-46A1-8326-9CD6A486E7DE}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\fallout 3 goty\falloutlauncher.exe |

"{C924D683-E42B-4CA0-BFB2-19C8FD409652}" = protocol=17 | dir=in | app=c:\programdata\battle.net\agent\agent.524\agent.exe |

"{C9656551-4C37-4C60-A482-941D51121CF4}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\left 4 dead\left4dead.exe |

"{C9D1E1F7-D1B8-4FEE-ABB3-7F7142E1528E}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.patch.exe |

"{CA79B09C-8503-41DB-9B3E-2A294B9EC779}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hposid01.exe |

"{CABBF71E-95A1-464E-A4FF-5B55D5593001}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\machinarium\machinarium.exe |

"{CB9732D9-557A-457A-B0F5-1D15E5A0BC42}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dawn of war ii - retribution\dow2.exe |

"{CCD284BA-0B50-48CA-BFE0-512CD3C7611E}" = protocol=6 | dir=in | app=c:\users\hayden\appdata\roaming\spotify\spotify.exe |

"{CCE35C12-5AD6-44BE-9351-1E8FC92EA438}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |

"{CD03D0FD-6403-43C1-959B-E855DBC003CA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\insideastarfilledsky\starfilledsky.exe |

"{CDECA150-228F-4496-8A46-7DFE04416640}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bit.trip beat\beat.exe |

"{D1E41161-6178-469F-B341-A0AB9E5A3CFD}" = protocol=6 | dir=in | app=c:\program files (x86)\curse\curseclient.exe |

"{D318E688-9644-455F-A731-DFF60CC55E53}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstra.exe |

"{D34BA142-B786-40EE-820A-F36260480EB0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\command and conquer red alert 3\runme.exe |

"{D3DBC249-ED4A-49D2-9933-4A15B2360CCC}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\mass effect\binaries\masseffect.exe |

"{D466DD28-4795-4845-B529-1D040AB99789}" = protocol=17 | dir=in | app=c:\windows\syswow64\pnkbstrb.exe |

"{D533246E-739C-4BBE-88D7-A0ECAA54A95A}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |

"{D5F5BC80-30B5-4D42-9EC0-EDE3F0FEEB16}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |

"{D62D0927-E1FF-449C-8542-E410356FB471}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\ultimate doom\ultimate.bat |

"{D6FD309A-71CB-4107-B0D3-4E80D804E801}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\trine\trine_launcher.exe |

"{D6FFBAD2-0D88-4C9A-97F8-A4523798628A}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword_pitboss.exe |

"{D766C7EE-86B5-480E-AC30-DBB0E41BE3FE}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\global agenda live\binaries\launcherbin\hirezlauncherui.exe |

"{D8572160-4C94-4FE8-B6E5-961CB95D89A2}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\beyond the sword\civ4beyondsword_pitboss.exe |

"{D86CD519-9050-4D1E-9652-57E14FCD5810}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\shank\bin\shank.exe |

"{D87E3B6A-FA8F-482C-A34E-72349C2794B7}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\sourcesdk\bin\sdklauncher.exe |

"{DADFD6C8-E594-4026-AC9E-4126BE37B892}" = protocol=17 | dir=in | app=c:\users\hayden\appdata\local\apps\2.0\9qato2qe.d4r\ob4wo6gp.mxn\curs..tion_eee711038731a406_0004.0000_d322ecea565577c8\curseclient.exe |

"{DAF1FFE8-F76B-4514-AEC3-3DD3476E53D6}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |

"{DB37A7A6-8C1B-4B86-A428-242E08C209EE}" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\starcraft ii.exe |

"{DBFF2C3D-252D-46C0-9E9F-432797EA95C1}" = protocol=17 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\civilization4.exe |

"{DD4AC687-F2BA-42CE-818D-7B4AB125E473}" = protocol=1 | dir=in | name=@firewallapi.dll,-28543 |

"{DF4FE312-25B9-4AE0-B772-57D25DA0E0E0}" = protocol=17 | dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |

"{DF8606E2-E0F2-4952-8FF9-FEAE4868E7B0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\beat hazard\runme.exe |

"{E1205103-3116-460B-ABC0-A2F3CE0451DF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dota 2 beta\dota.exe |

"{E1C083B1-0897-4951-8338-A59E0B827251}" = protocol=17 | dir=in | app=c:\program files (x86)\diablo iii\diablo iii.exe |

"{E1DC6953-46BC-4C11-8B34-5030F0F6A6F1}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steam.exe |

"{E2417AF9-6495-42DC-8368-42A08E1E1B6D}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |

"{E264B58C-376A-406C-85C5-61C34F8B96E0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |

"{E4D51260-245E-40AD-B612-A2F9BF1E5AB1}" = protocol=6 | dir=in | app=c:\program files (x86)\paradox interactive\majesty 2\majesty2.exe |

"{E5510507-DBC7-4241-A735-55D8DD0C0976}" = protocol=6 | dir=in | app=c:\program files (x86)\2k games\firaxis games\sid meier's civilization iv colonization\colonization.exe |

"{E64D8CF9-BE30-4ABB-8DBA-2AD3F9F38DDF}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\greed corp\game.exe |

"{E6D29BA0-D2E4-41A4-AE77-BF8D53CFF171}" = protocol=6 | dir=in | app=c:\program files (x86)\ventrilo\ventrilo.exe |

"{EA0F07EA-2697-452F-B436-A5851830A3B0}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\support\ea help\electronic_arts_technical_support.htm |

"{EA9AFB05-F88A-4076-8B78-FBF5C5970D32}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2launcher.exe |

"{EB1D6093-3A60-416E-AD68-DB5A918A111E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\portal 2\portal2.exe |

"{EC336689-8AA7-43C0-B870-648D6A954F80}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv.exe |

"{EC76F486-72CE-4FC7-8879-AE40102A5035}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\team fortress 2 meet the medic\smp.exe |

"{ED81AF03-F71F-4EEA-99C4-40A04995AFA6}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v - demo\civilizationv.exe |

"{EE1A5FE5-BCF2-4814-A066-E83A5DA52B0F}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\amd driver updater, vista and 7, 64 bit\setup.exe |

"{EEB7A444-698B-487C-978F-69D8D6E31B17}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\deus ex\system\deusex.exe |

"{EFF32F75-96C4-4BD4-9DF9-25F1E64ED273}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\launcher.exe |

"{F19ED36B-A8FE-4C8E-B4BD-4CD6843A738B}" = protocol=17 | dir=in | app=c:\users\hayden\appdata\roaming\tonido\tonido.exe |

"{F1E4DE50-3262-48BF-8940-608B6A648186}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\daupdatersvc.service.exe |

"{F26BEFFC-8B59-4CD6-89E2-14B03DEC5269}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeons\dungeonsstarter.exe |

"{F4223311-E8ED-499D-87CB-3020B2F3FBF1}" = dir=in | app=c:\program files (x86)\pando networks\media booster\pmb.exe |

"{F4E0E026-6D97-42C4-923B-82FC0F99A566}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |

"{F51E9086-8790-4925-BECD-2523CD6A7130}" = protocol=17 | dir=in | app=c:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe |

"{F5591C11-FC6D-4220-B298-AE4476884C8E}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\torchlight\torched\editor.exe |

"{F6B64405-8AC9-42F9-893B-E7C70F6A5D99}" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\killingfloor\system\killingfloor.exe |

"{F70B5308-2381-47C8-ADDE-853BF2A4ACFA}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dead space\dead space.exe |

"{F7A3BC42-B78A-496C-9E5E-5135A6AA7359}" = protocol=6 | dir=in | app=c:\users\hayden\appdata\local\apps\2.0\9qato2qe.d4r\ob4wo6gp.mxn\curs..tion_eee711038731a406_0004.0000_efb506202a7c3b08\curseclient.exe |

"{F7B22FC9-9DDE-45EC-80AC-9F2306B1B634}" = protocol=17 | dir=in | app=c:\riot games\league of legends\game\league of legends.exe |

"{F7C63DEF-9136-417A-B778-A510E350F2F6}" = protocol=58 | dir=out | name=@firewallapi.dll,-28546 |

"{F90F3CA1-6E24-4004-85D0-C6FA6F315364}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\opposing force\hl.exe |

"{FA726E65-C368-41A3-B6F9-6667B8903CA6}" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\launcher.exe |

"{FB8EF8C1-7665-4645-9821-82E843086247}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |

"{FC1B4D38-9D25-4DE0-A85B-BA547E9BDDB0}" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dragon age origins\daoriginslauncher.exe |

"{FDC25E92-79E9-4210-81D6-A7FE73E85411}" = protocol=6 | dir=in | app=c:\program files (x86)\firaxis games\sid meier's civilization 4\civilization4.exe |

"{FE394A0D-1F8F-4FBF-97F1-8F0E1D27621D}" = dir=in | app=c:\program files (x86)\hp\digital imaging\bin\hpqusgh.exe |

"TCP Query User{058FB9FA-D855-4AFC-B623-947C6A0CE280}C:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe |

"TCP Query User{07E04B83-428A-479A-B592-8323307A707B}C:\users\hayden\appdata\local\aptana studio 3\aptanastudio3.exe" = protocol=6 | dir=in | app=c:\users\hayden\appdata\local\aptana studio 3\aptanastudio3.exe |

"TCP Query User{0BD62D9D-F474-46F7-95CD-D6FA302A552E}C:\xampp\apache\bin\httpd.exe" = protocol=6 | dir=in | app=c:\xampp\apache\bin\httpd.exe |

"TCP Query User{11138324-0516-4D0E-BFDC-7D5D8D7A62D6}C:\program files (x86)\steam\steamapps\common\worms reloaded\wormsreloaded.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\worms reloaded\wormsreloaded.exe |

"TCP Query User{1244BB72-436C-4259-985A-DD6FC3032792}C:\program files (x86)\steam\steamapps\zmarine44\opposing force\hl.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\opposing force\hl.exe |

"TCP Query User{16B24B2A-1C9D-4170-B368-E9696315DBE2}C:\program files (x86)\vuze\azureus.exe" = protocol=6 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |

"TCP Query User{1A991959-912E-4A16-AC77-FD2AD396014A}C:\program files (x86)\steam\steamapps\captialone\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\captialone\team fortress 2\hl2.exe |

"TCP Query User{2648181E-C087-4C26-A012-E561896C43B1}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe |

"TCP Query User{2752A792-E62A-411C-A19E-8320B5873F41}C:\program files (x86)\phpdesigner 8\phpdesigner.exe" = protocol=6 | dir=in | app=c:\program files (x86)\phpdesigner 8\phpdesigner.exe |

"TCP Query User{2C333BA7-AE34-4E0E-B3A7-F257A9988815}C:\program files (x86)\mirc\mirc.exe" = protocol=6 | dir=in | app=c:\program files (x86)\mirc\mirc.exe |

"TCP Query User{2DF9425C-79D5-4D4B-872F-7B49C91FE3C5}C:\program files (x86)\netbeans 7.0.1\bin\netbeans.exe" = protocol=6 | dir=in | app=c:\program files (x86)\netbeans 7.0.1\bin\netbeans.exe |

"TCP Query User{2FFFCA71-3181-4440-84EF-31D1F9451F7E}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14356\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14356\sc2.exe |

"TCP Query User{3375FF3A-A01E-471C-AF9D-47CA1B23564A}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15250\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15250\sc2.exe |

"TCP Query User{351BF1E3-838E-41E7-865C-5A3846AF81F7}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15392\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15392\sc2.exe |

"TCP Query User{3CF6C440-F7EF-4413-B728-F1432D5554D8}C:\program files (x86)\java\jdk1.7.0\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jdk1.7.0\bin\java.exe |

"TCP Query User{47DEF718-AB7A-4D71-8748-7E1982D633D8}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |

"TCP Query User{4BDF8CFF-8D9E-4A8E-BE3E-49B6E42B263D}C:\program files (x86)\diablo ii\game.exe" = protocol=6 | dir=in | app=c:\program files (x86)\diablo ii\game.exe |

"TCP Query User{519A9B4C-7934-40D4-ABBD-6ADC519A030C}C:\program files (x86)\gamespy\comrade\comrade.exe" = protocol=6 | dir=in | app=c:\program files (x86)\gamespy\comrade\comrade.exe |

"TCP Query User{550A7DFB-3829-4C7F-A8E8-9B43586D5526}C:\program files (x86)\dc++\dcplusplus.exe" = protocol=6 | dir=in | app=c:\program files (x86)\dc++\dcplusplus.exe |

"TCP Query User{58E302BA-6544-404B-B4FF-0F34DB3487A1}C:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe |

"TCP Query User{595B8712-E1EC-4557-8118-3C8A0344F001}C:\program files (x86)\curse\curseclient.exe" = protocol=6 | dir=in | app=c:\program files (x86)\curse\curseclient.exe |

"TCP Query User{5D8280B9-30E7-47F6-8487-5754591BCB93}C:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe" = protocol=6 | dir=in | app=c:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe |

"TCP Query User{65562D01-9076-4F7B-B383-04191231C1FF}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe |

"TCP Query User{70AE3CFD-2D59-4CCE-8E33-8AF69C58F9F9}C:\program files (x86)\jetbrains\phpstorm 4.0.1\bin\phpstorm.exe" = protocol=6 | dir=in | app=c:\program files (x86)\jetbrains\phpstorm 4.0.1\bin\phpstorm.exe |

"TCP Query User{734A3010-0BBC-4809-934A-7EA4BD5524C8}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14133\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14133\sc2.exe |

"TCP Query User{81D31041-36C7-4FC2-9224-D79B53E1BE91}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14803\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14803\sc2.exe |

"TCP Query User{85FB2CAC-C46F-4060-A1CB-EE7ED5AD992D}C:\program files (x86)\netbeans 7.1.1\bin\netbeans.exe" = protocol=6 | dir=in | app=c:\program files (x86)\netbeans 7.1.1\bin\netbeans.exe |

"TCP Query User{8BE50E18-901B-4F63-BE25-F7D922AD43EB}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14621\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14621\sc2.exe |

"TCP Query User{90F5220B-EA28-477A-9F58-131B127B65FB}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15097\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15097\sc2.exe |

"TCP Query User{A07426D4-B121-4A2E-92E2-B12D4CB69BD2}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=6 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |

"TCP Query User{A47A433E-EB92-43A4-A1EF-859FB2851E82}C:\program files (x86)\star wars - the old republic\he27\retailclient\swtor.exe" = protocol=6 | dir=in | app=c:\program files (x86)\star wars - the old republic\he27\retailclient\swtor.exe |

"TCP Query User{A94DD224-9238-4227-B1A2-92DDADE4E866}C:\ruby192\bin\ruby.exe" = protocol=6 | dir=in | app=c:\ruby192\bin\ruby.exe |

"TCP Query User{AA9F0582-30AF-42C4-BD55-E462DF73533A}C:\program files (x86)\electronic arts\bioware\star wars - the old republic\betatest\retailclient\swtor.exe" = protocol=6 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\betatest\retailclient\swtor.exe |

"TCP Query User{B733A598-3AD4-486D-8FF4-45F150904E34}C:\world of warcraft\launcher.exe" = protocol=6 | dir=in | app=c:\world of warcraft\launcher.exe |

"TCP Query User{BBCAE358-E6CE-4193-A714-A5A42A9FBE9C}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14593\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14593\sc2.exe |

"TCP Query User{BDFF6057-D401-40DB-A6C6-56E444AF4F3E}C:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe |

"TCP Query User{C22F0EE3-AFDE-43FC-A7DF-80A48BCA6E8C}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15343\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15343\sc2.exe |

"TCP Query User{C60949C8-2BA7-449B-9A46-1289CBBA546B}C:\program files (x86)\microsoft games\project s\spartan.exe" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft games\project s\spartan.exe |

"TCP Query User{C7356309-5058-4BF9-8401-D4CAA62ABD15}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15655\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15655\sc2.exe |

"TCP Query User{CD55CB02-4FEF-4B99-B7FE-CD9B3930276D}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15133\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15133\sc2.exe |

"TCP Query User{CED0C7CC-8380-41A0-A357-60B797BF32A3}C:\python27\python.exe" = protocol=6 | dir=in | app=c:\python27\python.exe |

"TCP Query User{D4F58846-0C77-4E6C-99FB-60A4557B04E9}C:\program files (x86)\steam\steamapps\zmarine44\team fortress 2\hl2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\team fortress 2\hl2.exe |

"TCP Query User{D54667CA-6F66-415F-A87F-8F9B34BCBC06}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |

"TCP Query User{D983D7CD-67DD-40EC-98C4-FE61B0AE0CCE}C:\program files (x86)\java\jdk1.7.0\jre\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files (x86)\java\jdk1.7.0\jre\bin\javaw.exe |

"TCP Query User{DC5F14DB-2606-45AD-BB00-9D26624DE6FC}C:\program files (x86)\outspark\divine souls\client.exe" = protocol=6 | dir=in | app=c:\program files (x86)\outspark\divine souls\client.exe |

"TCP Query User{E45C3EFA-C82E-4A9A-A442-2A72BD58EE66}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14259\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14259\sc2.exe |

"TCP Query User{EF180741-6E13-47C0-AA81-EA08DB525FB0}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15449\sc2.exe" = protocol=6 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15449\sc2.exe |

"TCP Query User{FF95338A-60DF-4405-B1C5-D25C48F31CBB}C:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe" = protocol=6 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |

"UDP Query User{02CB386B-FCF2-4B67-A0A1-9347E21F1F0D}C:\program files (x86)\java\jdk1.7.0\jre\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jdk1.7.0\jre\bin\javaw.exe |

"UDP Query User{06E49B01-E543-44DD-8B4C-18C28D8F8DC6}C:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\sid meier's civilization v\civilizationv_dx11.exe |

"UDP Query User{17460285-FF02-4F3F-BAED-FADF62B882D4}C:\program files (x86)\steam\steamapps\common\worms reloaded\wormsreloaded.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\worms reloaded\wormsreloaded.exe |

"UDP Query User{2224E803-B9D7-41D4-9C82-F0C2D669697B}C:\xampp\apache\bin\httpd.exe" = protocol=17 | dir=in | app=c:\xampp\apache\bin\httpd.exe |

"UDP Query User{28063E9C-61CF-4D27-8037-DF67ABF5D0DB}C:\program files (x86)\steam\steamapps\zmarine44\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\team fortress 2\hl2.exe |

"UDP Query User{311002A8-B686-4D7C-80DE-256D027DA704}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14803\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14803\sc2.exe |

"UDP Query User{3604658F-0F11-4133-8FCE-FB75E8B3C5E4}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14133\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14133\sc2.exe |

"UDP Query User{39010A54-94AC-417A-AB84-01578D60304B}C:\program files (x86)\steam\steamapps\captialone\team fortress 2\hl2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\captialone\team fortress 2\hl2.exe |

"UDP Query User{3D1211E2-E622-43B2-A765-28BE7560DAC2}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15250\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15250\sc2.exe |

"UDP Query User{425D45D5-F7AE-4812-A3A2-07EDECF7EE3D}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14259\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14259\sc2.exe |

"UDP Query User{4643DD76-0D77-4D8F-B686-AFC7E2ECDB8F}C:\python27\python.exe" = protocol=17 | dir=in | app=c:\python27\python.exe |

"UDP Query User{4685CCA4-025F-40D0-8B1D-049D2D2E06D0}C:\program files (x86)\world of warcraft\backgrounddownloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\backgrounddownloader.exe |

"UDP Query User{490FC367-7EBC-4BAE-A0B4-3F7C0233D8B0}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15343\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15343\sc2.exe |

"UDP Query User{4C593327-6B35-435A-B0EB-C7D45BBE19A0}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15133\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15133\sc2.exe |

"UDP Query User{4CFBEB2A-EC34-4314-97CB-BE7693776866}C:\program files (x86)\jetbrains\phpstorm 4.0.1\bin\phpstorm.exe" = protocol=17 | dir=in | app=c:\program files (x86)\jetbrains\phpstorm 4.0.1\bin\phpstorm.exe |

"UDP Query User{4E277664-852A-4DB7-B732-ED37D16159C5}C:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\mp\builds\binaries\bioshock2.exe |

"UDP Query User{585A996A-E4C1-4212-92BD-98FF49042C9B}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14356\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14356\sc2.exe |

"UDP Query User{5C1B0E8B-8A97-4045-AC06-0D56EC92A353}C:\program files (x86)\outspark\divine souls\client.exe" = protocol=17 | dir=in | app=c:\program files (x86)\outspark\divine souls\client.exe |

"UDP Query User{64A6943E-6D36-48EF-AA99-BADA0C955445}C:\program files (x86)\java\jdk1.7.0\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jdk1.7.0\bin\java.exe |

"UDP Query User{6F14E29C-6904-47A7-BDCD-9BE0BDD2355D}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15392\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15392\sc2.exe |

"UDP Query User{7076377E-5C3F-41E2-8D0E-BDBCE5839E54}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14621\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14621\sc2.exe |

"UDP Query User{7AC09F52-A908-4350-9362-23D51DC6C92C}C:\ruby192\bin\ruby.exe" = protocol=17 | dir=in | app=c:\ruby192\bin\ruby.exe |

"UDP Query User{8026FB35-68C2-4F9B-B2AE-5B672A65231F}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15655\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15655\sc2.exe |

"UDP Query User{80551028-1CA0-459E-9C63-03AB271BF5A5}C:\program files (x86)\netbeans 7.1.1\bin\netbeans.exe" = protocol=17 | dir=in | app=c:\program files (x86)\netbeans 7.1.1\bin\netbeans.exe |

"UDP Query User{815CB3CB-2BE9-4F7E-9F22-26D6A6CB3F01}C:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe" = protocol=17 | dir=in | app=c:\program files (x86)\world of warcraft\temp\wow-4.2.1.2736-enus-tools-downloader.exe |

"UDP Query User{877EBF19-FAE9-48AE-9051-62DDB3B6E3E4}C:\world of warcraft\launcher.exe" = protocol=17 | dir=in | app=c:\world of warcraft\launcher.exe |

"UDP Query User{8A18FA70-87D8-4223-84B9-40102B6CA8C9}C:\program files (x86)\gamespy\comrade\comrade.exe" = protocol=17 | dir=in | app=c:\program files (x86)\gamespy\comrade\comrade.exe |

"UDP Query User{8AE1435D-AAAB-4765-AE05-E8F08737F807}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14593\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base14593\sc2.exe |

"UDP Query User{8B738294-C7B7-4084-B054-D53917D4B3D1}C:\program files (x86)\microsoft games\project s\spartan.exe" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft games\project s\spartan.exe |

"UDP Query User{901DA8AD-474F-4952-BB42-A51CE818665E}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15449\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15449\sc2.exe |

"UDP Query User{90EA2130-EC01-4884-8238-74B9DF35811A}C:\program files (x86)\star wars - the old republic\he27\retailclient\swtor.exe" = protocol=17 | dir=in | app=c:\program files (x86)\star wars - the old republic\he27\retailclient\swtor.exe |

"UDP Query User{9854B38B-E957-4740-A060-B83F6892820A}C:\program files (x86)\vuze\azureus.exe" = protocol=17 | dir=in | app=c:\program files (x86)\vuze\azureus.exe |

"UDP Query User{A278A962-CEEA-4CC7-9ACC-1F3A90E6C0D3}C:\program files (x86)\electronic arts\bioware\star wars - the old republic\betatest\retailclient\swtor.exe" = protocol=17 | dir=in | app=c:\program files (x86)\electronic arts\bioware\star wars - the old republic\betatest\retailclient\swtor.exe |

"UDP Query User{A7FFCBB8-BCE4-42C9-B54D-70C796CF88ED}C:\program files (x86)\netbeans 7.0.1\bin\netbeans.exe" = protocol=17 | dir=in | app=c:\program files (x86)\netbeans 7.0.1\bin\netbeans.exe |

"UDP Query User{B1BD3D74-9DCC-42CD-BC5E-1BBDD0EFBEAE}C:\program files (x86)\curse\curseclient.exe" = protocol=17 | dir=in | app=c:\program files (x86)\curse\curseclient.exe |

"UDP Query User{B380D222-17FA-449A-A533-8C954EA29A55}C:\program files (x86)\diablo ii\game.exe" = protocol=17 | dir=in | app=c:\program files (x86)\diablo ii\game.exe |

"UDP Query User{B3DE461D-B9CD-4E62-A5A3-37DB5459F150}C:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\dungeon defenders\binaries\win32\dundefgame.exe |

"UDP Query User{C99C57CF-B216-4A0A-8BF2-CF1E332E189D}C:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe" = protocol=17 | dir=in | app=c:\program files (x86)\veoh networks\veohwebplayer\veohwebplayer.exe |

"UDP Query User{CCA89EF6-CB54-4146-B336-6D908AE6A8BC}C:\program files (x86)\dc++\dcplusplus.exe" = protocol=17 | dir=in | app=c:\program files (x86)\dc++\dcplusplus.exe |

"UDP Query User{CE2C6353-5A65-47A3-B6EC-09E12C97CBD9}C:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\bioshock 2\sp\builds\binaries\bioshock2.exe |

"UDP Query User{CEE4F236-9BED-46EF-AB71-BE5B5822BE01}C:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15097\sc2.exe" = protocol=17 | dir=in | app=c:\program files (x86)\starcraft ii\starcraft ii beta\versions\base15097\sc2.exe |

"UDP Query User{D6B7A2F1-0353-40FA-874B-99AF531F225A}C:\program files (x86)\phpdesigner 8\phpdesigner.exe" = protocol=17 | dir=in | app=c:\program files (x86)\phpdesigner 8\phpdesigner.exe |

"UDP Query User{E700499E-72F7-458C-8171-B0BD5737BA76}C:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\alien swarm\swarm.exe |

"UDP Query User{EB6A017E-735A-4382-B005-6998D0E97B5F}C:\program files (x86)\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files (x86)\java\jre6\bin\java.exe |

"UDP Query User{F0427818-318A-4427-84FC-A118B334E5BF}C:\users\hayden\appdata\local\aptana studio 3\aptanastudio3.exe" = protocol=17 | dir=in | app=c:\users\hayden\appdata\local\aptana studio 3\aptanastudio3.exe |

"UDP Query User{F3D39519-5D40-4AA6-8602-D4D7727EB824}C:\program files (x86)\mirc\mirc.exe" = protocol=17 | dir=in | app=c:\program files (x86)\mirc\mirc.exe |

"UDP Query User{F50CD235-4523-4389-8BBA-BCE6708973A3}C:\program files (x86)\steam\steamapps\zmarine44\opposing force\hl.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\zmarine44\opposing force\hl.exe |

"UDP Query User{F7FD4969-A8D0-440E-8F89-A552391D03AC}C:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe" = protocol=17 | dir=in | app=c:\program files (x86)\steam\steamapps\common\terraria\terrariaserver.exe |

Link to post
Share on other sites

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{034106B5-54B7-467F-B477-5B7DBB492624}" = Microsoft Sync Framework Services v1.0 SP1 (x64)

"{0C270C59-8706-42B8-A2AD-6E5EE18BC90B}" = SQL Server 2008 R2 Reporting Services

"{0F37D969-1260-419E-B308-EF7D29ABDE20}" = Web Deployment Tool

"{1111706F-666A-4037-7777-202648764D10}" = JavaFX 2.0.2 (64-bit)

"{119B2F5A-2A06-DB96-FF28-992EC2A10BDF}" = AMD Accelerated Video Transcoding

"{1330309E-64D3-43F4-AA18-BC856182B5DB}" = SQL Server 2008 R2 BI Development Studio

"{1374CC63-B520-4f3f-98E8-E9020BF01CFF}" = Windows XP Mode

"{1444D2EE-C7AD-44A8-844F-2634B49353D1}" = Logitech Gaming Software 5.10

"{1AAF3A3B-7B32-4DDF-8ABB-438DAEB46EEC}" = Windows Live Family Safety

"{1AB7EDC5-D891-34C5-9FF1-BE6A85ACC44B}" = Microsoft Team Foundation Server 2010 Object Model - ENU

"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant

"{1C7C8AAF-A16D-32E8-89E5-F6D165DE0BCE}" = Microsoft Visual C++ 2010 x64 Runtime - 10.0.40219

"{1D1CEEF8-3741-45BD-8E77-963E1DEBDDD3}" = Microsoft Sync Services for ADO.NET v2.0 SP1 (x64)

"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219

"{1E6ED082-E32D-4B2B-8B6A-70B094815135}" = Microsoft SQL Server System CLR Types (x64)

"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64

"{2180B33F-3225-423E-BBC1-7798CFD3CD1F}" = Microsoft SQL Server 2008 R2 Native Client

"{2222706F-666A-4037-7777-202648764D10}" = JavaFX 2.0.2 SDK (64-bit)

"{23170F69-40C1-2702-0465-000001000000}" = 7-Zip 4.65 (x64 edition)

"{234F6B0D-10AE-4BB7-B2F3-E48D4861952D}" = SQL Server 2008 R2 Common Files

"{2453DBC8-ACC4-4711-BD03-0C15353AA3D8}" = SQL Server 2008 R2 Reporting Services

"{26A24AE4-039D-4CA4-87B4-2F86416032FF}" = Java 6 Update 32 (64-bit)

"{26A24AE4-039D-4CA4-87B4-2F86417002FF}" = Java 7 Update 2 (64-bit)

"{288D79EE-A2D1-42AF-9597-B0ADCC23A8ED}" = Microsoft SQL Server VSS Writer

"{29C93182-34F6-3275-A18D-59326851CD57}" = Microsoft Windows SDK for Visual Studio 2008 .NET Framework Tools

"{2BFA9B05-7418-4EDE-A6FC-620427BAAAA3}" = Crystal Reports Basic Runtime for Visual Studio 2008 (x64)

"{2D2601B6-157F-4F88-B66B-B52DB21EAB2D}" = SQL Server 2008 R2 Client Tools

"{2E8D6204-D656-8355-1ED3-2988AC52EB0F}" = ccc-utility64

"{312E8540-0799-45D5-A02E-DFB8FCA93CCA}" = SQL Server 2008 R2 BI Development Studio

"{350AA351-21FA-3270-8B7A-835434E766AD}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.21022

"{36F70DEE-1EBF-4707-AFA2-E035EEAEBAA1}" = SQL Server 2008 R2 Common Files

"{439760BC-7737-4386-9B1D-A90A3E8A22EA}" = Apple Mobile Device Support

"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64

"{46A5FBE9-ADB3-4493-A1CC-B4CFFD24D26A}" = Windows Live Family Safety

"{503F672D-6C84-448A-8F8F-4BC35AC83441}" = AMD APP SDK Runtime

"{5134B35A-B559-4762-94A4-FD4918977953}" = Microsoft Web Deploy 2.0

"{51E5BC99-A087-4CFF-8D93-462903EA7E12}" = SQL Server 2008 R2 Management Studio

"{5831C6D6-309D-DBB5-14F7-FEE57086CEE7}" = AMD Catalyst Install Manager

"{5DE154DF-A55E-4FA5-BE59-32E78FCACF3E}" = Microsoft Windows SDK for Visual Studio 2008 Headers and Libraries

"{62EED300-E841-4083-A1D6-60B906271804}" = Microsoft Windows SDK for Visual Studio 2008 Tools

"{63CE6C32-1EB3-4C51-89FC-9FD96A661A9C}" = AMD Media Foundation Decoders

"{64A3A4F4-B792-11D6-A78A-00B0D0170020}" = Java SE Development Kit 7 Update 2 (64-bit)

"{64D5BBC6-5270-3711-AA39-31C1087AF4E6}" = Microsoft Visual Studio 2008 Remote Debugger - ENU

"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources

"{662014D2-0450-37ED-ABAE-157C88127BEB}" = Visual Studio 2010 Prerequisites - English

"{690285C2-2481-44FB-8402-162EA970A6DD}" = Logitech Gaming Software 8.00

"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)

"{6D10FB2C-82A9-40F2-91D0-7BE64CF0DAF2}" = Microsoft SQL Server 2008 R2 Setup (English)

"{6E2EE862-FEF9-408A-90BB-F5B4EC129C8E}" = SQL Server 2008 R2 Analysis Services

"{72AB7E6F-BC24-481E-8C45-1AB5B3DD795D}" = SQL Server 2008 R2 Management Studio

"{81455DEB-FC7E-3EE5-85CA-2EBDD9FD61EB}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x64

"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17

"{82D52DEB-4262-2846-07E5-2D5A6C3C9A01}" = ATI AVIVO64 Codecs

"{8424B163-D1E0-48B7-88A2-C7A61767B3D7}" = Microsoft SQL Server Compact 4.0 x64 ENU

"{8438EC02-B8A9-462D-AC72-1B521349C001}" = Microsoft Sync Framework Runtime v1.0 SP1 (x64)

"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources

"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64

"{866FADAA-D878-8B7A-738D-E6659493108D}" = ATI Problem Report Wizard

"{8E34682C-8118-31F1-BC4C-98CD9675E1C2}" = Microsoft .NET Framework 4 Extended

"{90140000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2010

"{90140000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2010

"{90140000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2010

"{90A80D89-A0E4-33C1-B13D-B93CB3496867}" = Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU

"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64

"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64

"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting

"{9aa5f39c-a8de-46b0-919a-0248f8bc8490}" = Microsoft Windows SDK for Visual Studio 2008 SDK Reference Assemblies and IntelliSense

"{9ACF3FDB-C8E6-444C-8C64-13A221F7BFFD}" = Microsoft SQL Server Native Client

"{9B2C4509-2B9F-4303-BA74-E2F9BB773F03}" = Oracle VM VirtualBox 4.1.8

"{9BAC619B-B811-4318-8C27-B11DDF3F1719}" = WD SmartWare

"{9DFA5914-C275-42E0-810E-C88E46A7F9EA}" = SQL Server 2008 R2 Full text search

"{A00C9114-40E6-4C70-A619-7DF264B23485}" = HP Deskjet F4200 All-In-One Driver Software 13.0 Rel. 3

"{A2122A9C-A699-4365-ADF8-68FEAC125D61}" = SQL Server 2008 R2 Database Engine Shared

"{A278382D-4F1B-4D47-9885-8523F7261E8D}_is1" = PDF-Viewer

"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64

"{A992BBAA-723D-4574-A07F-983BF8FAA3E1}" = Microsoft Windows SDK for Visual Studio 2008 Win32 Tools

"{B40EE88B-400A-4266-A17B-E3DE64E94431}" = Microsoft SQL Server 2008 Setup Support Files

"{B49673F8-7AB6-4A14-8213-C8A7BE370010}" = UltraMon

"{B5FE23CC-0151-4595-84C3-F1DE6F44FE9B}" = SQL Server 2008 R2 Client Tools

"{B95653AB-0E7F-204A-3226-17E9F38E6951}" = AMD Drag and Drop Transcoding

"{BB57A765-FFFE-498B-8C1E-6C9CE2AB92BA}" = Microsoft SQL Server 2008 R2 RsFx Driver

"{C616FD4F-11F5-11E0-A38F-0013D3D69929}" = Vegas Pro 10.0 (64-bit)

"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64

"{C942A025-A840-4BF2-8987-849C0DD44574}" = SQL Server 2008 R2 Database Engine Shared

"{C9608300-11F5-11E0-A64B-0013D3D69929}" = MSVCRT Redists

"{CA0D2F09-F811-48D4-843E-C87696C6A9D9}" = Bonjour

"{CB0FD760-C6C6-3AF6-AD18-FE3B3B78727D}" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)

"{CC4878C0-4A6A-49CD-AAA7-DD3FCB06CC84}" = Microsoft Web Platform Installer 3.0

"{CD7B010C-307E-47A6-856C-D059F0D1F72C}" = Nitro Pro 7

"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector

"{D3E39E77-0EB4-36FB-B97A-8C8AB21B9A45}" = Visual Studio .NET Prerequisites - English

"{D4AD39AD-091E-4D33-BB2B-59F6FCB8ADC3}" = Microsoft SQL Server Compact 3.5 SP2 x64 ENU

"{D57519D3-2E37-3E34-94AF-4D59BFAB87E6}" = Microsoft Visual Studio 2010 Office Developer Tools (x64)

"{D81C035E-D0A5-11DF-9450-0013D3D69929}" = MSVCRT Redists

"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter

"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client

"{DFB3AD2B-4EE2-3077-BF1D-3CA164BC5336}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for .NET Framework - enu

"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service

"{E5748D30-7E6D-3A8E-BFE6-C1D02C6DDABB}" = Microsoft Help Viewer 1.1

"{EAEBF166-B06A-4D7F-BAF7-6615303D5C7C}" = Microsoft SQL Server 2008 R2 Management Objects (x64)

"{EE936C7A-EA40-31D5-9B65-8E3E089C3828}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x64 9.0.30729.4148

"{EEB3F6BB-318D-4CE5-989F-8191FCBFB578}" = Ventrilo Client for Windows x64

"{EF8B1A2E-9CCB-3AB2-91E3-4EEDAB1294E1}" = Microsoft Device Emulator (64 bit) version 3.0 - ENU

"{F01EC9B9-21B4-441E-958A-1E01098B03BE}" = SQL Server 2008 R2 Analysis Services

"{F31183CF-E10F-4DE1-BB59-6C0FF38E481E}" = Sql Server Customer Experience Improvement Program

"{F5079164-1DB9-3BDA-853B-F78AF67CE071}" = Microsoft Visual C++ 2010 x64 Designtime - 10.0.30319

"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile

"{F5C819A5-E068-4f7d-B91A-1BD18702AFFB}" = Microsoft Windows SDK for Visual Studio 2008 SP1 Express Tools for Win32

"{FA7394B8-CE65-4F9E-AC99-F372AD365424}" = SQL Server 2008 R2 Database Engine Services

"{FBD367D1-642F-47CF-B79B-9BE48FB34007}" = SQL Server 2008 R2 Database Engine Services

"{FD9C13F5-1BF8-4C63-89D2-FE955C9DABD8}" = Motorola Mobile Drivers Installation 5.6.0

"{FF21C3E6-97FD-474F-9518-8DCBE94C2854}" = 64 Bit HP CIO Components Installer

"Adobe Flash Player Plugin" = Adobe Flash Player 11 Plugin 64-bit

"C-Media CM108 Like Sound Driver" = USB PnP Sound Device

"HP Imaging Device Functions" = HP Imaging Device Functions 13.0

"HP Photosmart Essential" = HP Photosmart Essential 3.5

"HP Smart Web Printing" = HP Smart Web Printing 4.51

"HP Solution Center & Imaging Support Tools" = HP Solution Center 13.0

"HPExtendedCapabilities" = HP Customer Participation Program 13.0

"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile

"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended

"Microsoft Help Viewer 1.1" = Microsoft Help Viewer 1.1

"Microsoft SQL Server 10" = Microsoft SQL Server 2008 R2 (64-bit)

"Microsoft SQL Server 2008 R2" = Microsoft SQL Server 2008 R2 (64-bit)

"Microsoft Team Foundation Server 2010 Object Model - ENU" = Microsoft Team Foundation Server 2010 Object Model - ENU

"Microsoft Visual Studio 2008 Remote Debugger - ENU" = Microsoft Visual Studio 2008 Remote Debugger - ENU

"Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU" = Microsoft Visual Studio 2008 Remote Debugger Light (x64) - ENU

"Microsoft Visual Studio 2010 Tools for Office Runtime (x64)" = Microsoft Visual Studio 2010 Tools for Office Runtime (x64)

"Virtual Audio Cable 4.10" = Virtual Audio Cable 4.10

"WinRAR archiver" = WinRAR archiver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{002D9D5E-29BA-3E6D-9BC4-3D7D6DBC735C}" = Microsoft Visual C++ 2008 ATL Update kb973924 - x86 9.0.30729.4148

"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86

"{03D4C700-2BFE-43E0-A0B4-9512B43C5B9F}" = Catalyst Control Center - Branding

"{048298C9-A4D3-490B-9FF9-AB023A9238F3}" = Steam

"{05855322-BE43-41FE-B583-D3AE0C326D58}" = Microsoft Silverlight 4 SDK

"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86

"{095F7535-4221-4627-AC60-A97A5EBAF132}" = Minutor

"{09C52940-A4D1-4409-A7CC-1AAE630CF578}" = Microsoft SQL Server 2008 R2 Transact-SQL Language Service

"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer

"{0BE273CD-AAB9-361B-8C32-D955EAC929E3}" = Microsoft Visual Studio 2010 SharePoint Developer Tools

"{0BE73D3C-B5AF-11E1-933A-984BE15F174E}" = Evernote v. 4.5.7

"{0D2DBE8A-43D0-7830-7AE7-CA6C99A832E7}" = Adobe Community Help

"{0E3DFC64-CC49-4BE2-8C9C-58EF129675DB}" = Microsoft Sync Framework SDK v1.0 SP1

"{0EF5BEA9-B9D3-46d7-8958-FB69A0BAEACC}" = Status

"{0F367CA3-3B2F-43F9-A44A-25A8EE69E45D}" = Scan

"{11083C7A-D0D6-4DA4-8C3A-74B8389EC07B}" = ATI Catalyst Registration

"{1111706F-666A-4037-7777-210328764D10}" = JavaFX 2.1.0

"{112C23F2-C036-4D40-BED4-0CB47BF5555C}" = Visual Studio 2010 Tools for SQL Server Compact 3.5 SP2 ENU

"{14DD7530-CCD2-3798-B37D-3839ED6A441C}" = Microsoft Visual Studio 2010 ADO.NET Entity Framework Tools

"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5

"{175F0111-2968-4935-8F70-33108C6A4DE3}" = MarketResearch

"{1803A630-3C38-4D2B-9B9A-0CB37243539C}" = Microsoft ASP.NET MVC 2

"{196467F1-C11F-4F76-858B-5812ADC83B94}" = MSXML 4.0 SP3 Parser

"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker

"{19BFDA5D-1FE2-4F25-97F9-1A79DD04EE20}" = Microsoft XNA Framework Redistributable 3.1

"{19D614EB-D62A-AEE7-2391-E74126601D59}" = CCC Help Italian

"{1A2DDF67-3FA4-451C-8BF1-21CA4E546AEF}" = Motorola Device Software Update

"{1AA5BD63-6614-44B2-88A7-605191EDB835}" = Dotfuscator Software Services - Community Edition

"{1C373820-B9C8-0F7F-8F84-FC1B76A85F27}" = CCC Help Portuguese

"{1C4551A6-4743-4093-91E4-1477CD655043}" = NVIDIA PhysX

"{1EC71BFB-01A3-4239-B6AF-B1AE656B15C0}" = TrayApp

"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148

"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update

"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions

"{2012098D-EEE9-4769-8DD3-B038050854D4}" = Microsoft Silverlight 3 SDK

"{22025051-1991-48EB-8BE8-7A3329DAE7ED}" = IIS 7.5 Express

"{241F2BF7-69EB-42A4-9156-96B2426C7504}" = Microsoft SQL Server Compact 3.5 for Devices ENU

"{26A24AE4-039D-4CA4-87B4-2F83216027FF}" = Java 6 Update 30

"{26A24AE4-039D-4CA4-87B4-2F83217004FF}" = Java 7 Update 4

"{2750B389-A2D2-4953-99CA-27C1F2A8E6FD}" = Microsoft SQL Server 2005 Tools Express Edition

"{28DB8373-C1BB-444F-A427-A55585A12ED7}" = Motorola Device Manager

"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections

"{291B3A3B-F808-45B8-8113-DF232FCB6C82}" = Microsoft .NET Compact Framework 3.5

"{2AFFFDD7-ED85-4A90-8C52-5DA9EBDC9B8F}" = Microsoft SQL Server 2005 Express Edition (SQLEXPRESS)

"{2BFC7AA0-544C-4E3A-8796-67F3BE655BE9}" = Microsoft XNA Framework Redistributable 4.0

"{2D35BC33-7D08-D529-DF91-8A15FBF2600E}" = CCC Help Polish

"{2E295B5B-1AD4-4d36-97C2-A316084722CF}" = Python 2.7.2

"{2E5C075E-11AB-4BDD-918C-7B9A68953FF8}" = Microsoft SQL Server Compact 3.5 Design Tools ENU

"{2EEA7AA4-C203-4b90-A34F-19FB7EF1C81C}" = BufferChm

"{2EFA4E4C-7B5F-48F7-A1C0-1AA882B7A9C3}" = HP Update

"{2F8B731A-5F2D-3EA8-8B25-C3E5E43F4BDB}" = Microsoft Visual C++ Compilers 2010 Standard - enu - x86

"{2FDBBCEA-62DB-45F4-B6E5-0E1FB2A1F29D}" = Visual C++ 8.0 Runtime Setup Package (x64)

"{2FF8C687-DB7D-4adc-A5DC-57983EC25046}" = DeviceDiscovery

"{32A3A4F4-B792-11D6-A78A-00B0D0170000}" = Java SE Development Kit 7

"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery

"{337788D1-43D1-9A0F-9787-DD00DB512D41}" = Catalyst Control Center Localization All

"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery

"{361AA6F2-124E-4E98-9402-83B1445B8448}" = GameSpy Comrade

"{363CEA5C-C9D0-45DD-9511-A461DBDEE94B}" = DJ_AIO_03_F4200_Software_Min

"{378397D6-FD32-4092-A854-6A75CB7EDA46}" = MOTOROLA MEDIA LINK

"{38468127-9E6F-4FC9-B5F7-42D4AD437D96}" = Unigine Heaven Benchmark v2.1

"{388E4B09-3E71-4649-8921-F44A3A2954A7}" = Microsoft Visual Studio 2005 Tools for Office Runtime

"{3A9FC03D-C685-4831-94CF-4EDFD3749497}" = Microsoft SQL Server Compact 3.5 SP2 ENU

"{3C3D696B-0DB7-3C6D-A356-3DB8CE541918}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729

"{3C87E0FF-BC0A-4F5E-951B-68DC3F8DF1FC}" = Hi-Command

"{3C92B2E6-380D-4fef-B4DF-4A3B4B669771}" = Copy

"{40416836-56CC-4C0E-A6AF-5C34BADCE483}" = Microsoft ASP.NET MVC 2 - Visual Studio 2010 Tools

"{43CDF946-F5D9-4292-B006-BA0D92013021}" = WebReg

"{4725833D-4325-5C34-57D4-1FE23E5AE578}" = CCC Help Chinese Standard

"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater

"{4A70EF07-7F88-4434-BB61-D1DE8AE93DD4}" = SolutionCenter

"{4B271648-43CB-DD31-FF24-E7B06D3EE72A}" = Catalyst Control Center InstallProxy

"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace

"{4DC37F33-7AEC-A4CB-56B1-69A402828763}" = CCC Help Japanese

"{4E7C28C7-D5DA-4E9F-A1CA-60490B54AE35}" = UnloadSupport

"{4ECF4BDC-8387-329A-ABE9-CF5798F84BB2}" = Microsoft Visual Studio Tools for Applications 2.0 - ENU

"{50816F92-1652-4A7C-B9BC-48F682742C4B}" = Messenger Companion

"{53F5C3EE-05ED-4830-994B-50B2F0D50FCE}" = Microsoft SQL Server Setup Support Files (English)

"{5401CEE8-3C2D-4835-A802-213306537FF4}" = MotoCast

"{5454085C-840F-4070-8FAA-441000018301}" = BioShock 2

"{5454085C-840F-4070-8FAA-441000028301}" = BioShock 2

"{557090F6-9174-B562-71CF-70FD6C7F9895}" = Application Profiles

"{5710DAC2-8F2A-503C-CFC2-A973ADE0EA4C}" = CCC Help Czech

"{57752979-A1C9-4C02-856B-FBB27AC4E02C}" = QuickTime

"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack

"{5A13987D-55F4-4271-A40E-76AC9B1B38FD}" = OpenOffice.org 3.2

"{5C763682-4C40-86DA-9C46-31924D7D2C34}" = CCC Help Thai

"{5D9ED403-94DE-3BA0-B1D6-71F4BDA412E6}" = Microsoft Visual C++ 2010 x86 Runtime - 10.0.40219

"{5DA8F6CD-C70E-39D8-8430-3D9808D6BD17}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30411

"{5F8E2CBB-949D-4175-AC98-5ADE7F6C9697}" = NCsoft Launcher

"{60E5022D-FA4B-C6A2-1E80-B46EC39096F3}" = CCC Help Chinese Traditional

"{60F34FDF-267C-408F-290E-EC90D841C8CB}" = CCC Help German

"{631471BE-DEAB-454B-A9AC-CE3EB42C28B3}" = Microsoft ASP.NET Web Pages

"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86

"{63FF21C9-A810-464F-B60A-3111747B1A6D}" = GPBaseService2

"{66B79AE1-C6E2-B958-689C-D0812DE86BAB}" = CCC Help Greek

"{6753B40C-0FBD-3BED-8A9D-0ACAC2DCD85D}" = Microsoft Document Explorer 2008

"{681B698F-C997-42C3-B184-B489C6CA24C9}" = HPPhotoSmartDiscLabelContent1

"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE

"{6B39BE0F-0F5E-A8FA-33E4-8481AE39D96C}" = CCC Help Russian

"{6BBA26E9-AB03-4FE7-831A-3535584CA002}" = Toolbox

"{6C9F6D23-E9AD-43C9-B43A-011562AAF876}" = Windows Mobile 5.0 SDK R2 for Pocket PC

"{6CDEAD7E-F8D8-37F7-AB6F-1E22716E30F3}" = Microsoft Visual Studio Macro Tools

"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.1.0.0

"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable

"{71929EC1-FDB2-4A67-AAAD-936E4539FA84}_is1" = Driver Sweeper 2.1.0

"{77F1F8AD-51B8-4490-AEEC-BF480073E0FC}" = Microsoft SQL Server 2008 R2 Management Objects

"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update

"{78A96B4C-A643-4D0F-98C2-A8E16A6669F9}" = Windows Live Messenger Companion Core

"{7A56D81D-6406-40E7-9184-8AC1769C4D69}" = Microsoft SQL Server 2008 R2 Data-Tier Application Project

"{7C503E58-B2BC-11D5-978A-0050BA84F5F7}" = Neverwinter Nights

"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger

"{81E2D8D7-F104-4EB9-97A7-98996A611FF6}" = Sid Meier's Civilization 4 - Beyond the Sword

"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable

"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform

"{85467CBC-7A39-33C9-8940-D72D9269B84F}" = Microsoft Visual F# 2.0 Runtime

"{877B76B2-F83F-4F5A-B28D-3F398641ADB6}" = Microsoft SQL Server System CLR Types

"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight

"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime

"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT

"{8E19F2AF-7145-51DE-E395-7729A9374973}" = Catalyst Control Center Graphics Previews Common

"{8FB53850-246A-3507-8ADE-0060093FFEA6}" = Visual Studio Tools for the Office system 3.0 Runtime

"{90120000-0021-0000-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer 2007

"{90120000-0021-0000-0000-0000000FF1CE}_VisualWebDeveloper_{3D019598-7B59-447A-80AE-815B703B84FF}" = Security Update for Microsoft Office system 2007 (972581)

"{90120000-0021-0409-0000-0000000FF1CE}" = Microsoft Office Visual Web Developer MUI (English) 2007

"{90120000-0021-0409-0000-0000000FF1CE}_VisualWebDeveloper_{E1044ED2-E4AD-4B39-B500-31109750F6B4}" = Microsoft Office SharePoint Designer 2007 Service Pack 2 (SP2)

"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007

"{90120000-006E-0409-0000-0000000FF1CE}_VisualWebDeveloper_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90120000-00A4-0409-0000-0000000FF1CE}" = Microsoft Office 2003 Web Components

"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007

"{90120000-0115-0409-0000-0000000FF1CE}_VisualWebDeveloper_{DE5A002D-8122-4278-A7EE-3121E7EA254E}" = Microsoft Office 2007 Service Pack 2 (SP2)

"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010

"{90140000-001F-0409-0000-0000000FF1CE}_Office14.VISIOR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010

"{90140000-001F-040C-0000-0000000FF1CE}_Office14.VISIOR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010

"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.VISIOR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-002A-0000-1000-0000000FF1CE}_Office14.VISIOR_{967EF02C-5C7E-4718-8FCB-BDC050190CCF}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-002A-0409-1000-0000000FF1CE}_Office14.VISIOR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010

"{90140000-002C-0409-0000-0000000FF1CE}_Office14.VISIOR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0054-0409-0000-0000000FF1CE}" = Microsoft Office Visio MUI (English) 2010

"{90140000-0054-0409-0000-0000000FF1CE}_Office14.VISIOR_{CDC4310F-8189-485F-B47D-D972217CE173}" = Microsoft Office 2010 Language Pack Service Pack 1 (SP1)

"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010

"{90140000-006E-0409-0000-0000000FF1CE}_Office14.VISIOR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010

"{90140000-0115-0409-0000-0000000FF1CE}_Office14.VISIOR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{90140000-0116-0409-1000-0000000FF1CE}_Office14.VISIOR_{D6C6B46A-6CE1-4561-84A0-EFD58B8AB979}" = Microsoft Office 2010 Service Pack 1 (SP1)

"{91140000-0057-0000-0000-0000000FF1CE}" = Microsoft Office Visio 2010

"{91140000-0057-0000-0000-0000000FF1CE}_Office14.VISIOR_{01D8AE4B-A04D-47E5-81BF-E3F98B81B8C3}" = Microsoft Visio 2010 Service Pack 1 (SP1)

"{91CB5B8B-4EC8-DBA1-A88D-99FD480567B0}" = CCC Help English

"{92482FB3-C05B-41C6-89E7-75D985602A6E}" = System Requirements Lab

"{924FBAC4-60D2-7981-3C3E-979DF9CBB346}" = CCC Help Finnish

"{92606477-9366-4D3B-8AE3-6BE4B29727AB}" = League of Legends

"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86

"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker

"{94CAC2F1-C856-47F4-AF24-65A1E75AEDB9}" = MotoHelper MergeModules

"{95120000-00B9-0409-0000-0000000FF1CE}" = Microsoft Application Error Reporting

"{9656F3AC-6BA9-43F0-ABED-F214B5DAB27B}" = Windows Mobile 5.0 SDK R2 for Smartphone

"{980A182F-E0A2-4A40-94C1-AE0C1235902E}" = Pando Media Booster

"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17

"{9A33B83D-FFC4-44CF-BEEF-632DECEF2FCD}" = Microsoft SQL Server Database Publishing Wizard 1.2

"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail

"{9DC939DC-B7A4-D0E2-C582-A442DF1B3EBE}" = CCC Help Spanish

"{9E051993-7665-FE91-148D-3B0855E57F70}" = Amazon MP3 Uploader

"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh

"{A1BD938B-F006-6E6D-70B2-47E1DD56F7DE}" = CCC Help Swedish

"{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection

"{A5630CB0-6D3C-4C93-9A51-03BEB835A982}" = NuGet

"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer

"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5

"{A7A34FC9-DF24-4A36-00AD-D4EFE94CC116}" = SimCity 4 Deluxe

"{A84BD759-4C74-4F66-9038-D51E90D19F47}" = Sid Meier's Civilization 4 - Warlords

"{A8589680-35C1-4732-ACCA-09B78921ECE3}" = Sid Meier's Civilization 4

"{A879B90E-B62C-4DA4-9C3F-79A1A6CFAAF9}" = Microsoft ASP.NET Web Pages - Visual Studio 2010 Tools

"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common

"{AA467959-A1D6-4F45-90CD-11DC57733F32}" = Crystal Reports Basic for Visual Studio 2008

"{AA59DDE4-B672-4621-A016-4C248204957A}" = Skype™ 5.5

"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer

"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer

"{AB67580-257C-45FF-B8F4-C8C30682091A}_is1" = SIW version 2010.03.10

"{AC2C1BDB-1E91-4F94-B99C-E716FE2E9C75}_is1" = MinGW-Get version 0.3-alpha-2.1

"{AC41D924-8C68-4BD5-A7A1-0AE4176C31A6}" = Crystal Reports for Visual Studio

"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)

"{ACE28263-76A4-4BF5-B6F4-8BD719595969}" = Microsoft SQL Server Database Publishing Wizard 1.4

"{B3575D00-27EF-49C2-B9E0-14B3D954E992}" = Apple Application Support

"{B7E38540-E355-3503-AFD7-635B2F2F76E1}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4974

"{B8C3B479-1716-11D5-968A-0050BA84F5F7}" = Baldur's Gate II - Throne of Bhaal

"{BA0C9AAF-1327-3F06-B49C-349B4BE8F740}" = Microsoft Visual Studio 2008 Shell (integrated mode) - ENU

"{BABF7852-C2DD-6A8A-9956-101720C715C7}" = CCC Help Turkish

"{BB7C2A56-9706-43B8-5A8C-210AF5816106}" = CCC Help French

"{BC537AE0-88AF-47ED-B762-33B0D62B5188}" = Microsoft SQL Server 2008 R2 Data-Tier Application Framework

"{BD7204BA-DD64-499E-9B55-6A282CDF4FA4}" = Destinations

"{BF9BF038-FE03-429D-9B26-2FA0FD756052}" = Microsoft SQL Server Browser

"{C2524280-A5CF-4458-B809-167F13FAB56D}" = F4200

"{C28422FB-F2CD-427A-ADED-9F281745CDB2}" = Secure Download Manager

"{C3592426-531E-4110-911D-BFECE2CE284C}" = osu!

"{C43326F5-F135-4551-8270-7F7ABA0462E1}" = HPProductAssistant

"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail

"{CAE4213F-F797-439D-BD9E-79B71D115BE3}" = HPPhotoGadget

"{CDCA3C32-FCE7-40E8-8CB5-7B0E87ADDFC9}_is1" = Majesty 2: The Fantasy Kingdom Sim

"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform

"{CFBCE791-2D53-4FCE-B3FB-D6E01F4112E8}" = Sid Meier's Civilization 4

"{CFC2CB60-5654-05A7-4D30-C661800A3A92}" = CCC Help Korean

"{CFEF48A8-BFB8-3EAC-8BA5-DE4F8AA267CE}" = Microsoft .NET Framework 4 Multi-Targeting Pack

"{D04CE005-D1D2-80F3-84C8-B3524FCD39C3}" = CCC Help Norwegian

"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64

"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86

"{D21BC5B2-CBAC-48FA-A701-B5A63C1CA7B8}" = Microsoft SQL Server 2008 R2 Policies

"{D25C502E-FF51-424C-8C38-8596FE47D0CD}" = Visual Studio 2010 SP1 Tools for SQL Server Compact 4.0 ENU

"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common

"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform

"{D544AE4C-4152-225B-A897-6756C8986B14}" = Catalyst Control Center

"{D6B15AE6-B052-363E-B6BB-C4714CBA6509}" = Microsoft Visual Studio 2010 Professional - ENU

"{D79113E7-274C-470B-BD46-01B10219DF6A}" = HPPhotosmartEssential

"{D8087907-E255-3A41-A46D-D0F798709C71}" = Microsoft Visual C++ 2008 Express Edition with SP1 - ENU

"{D81E9069-3CCC-4405-3751-71E4AFEACC52}" = CCC Help Hungarian

"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86

"{D9E6001A-5DC3-4620-AF7A-80B6CD48645D}" = WCF RIA Services V1.0 SP1

"{DC635845-46D3-404B-BCB1-FC4A91091AFA}" = SmartWebPrinting

"{DCDEC776-BADD-48B9-8F9A-DFF513C3D7FA}" = Microsoft ASP.NET MVC 3

"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources

"{DDFD8348-058C-4F4B-85E5-6D740D4AB3FE}" = Microsoft SQL Server Compact 3.5 SP2 Query Tools ENU

"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player

"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh

"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10

"{E3CA67A5-53E8-602E-D17A-45EFDE3DDD53}" = HydraVision

"{E9355E4F-CA53-42EB-9392-2F288E3CD3F9}_is1" = Tonido 2.35.0.16173

"{E93FF166-DF14-2537-8FB4-96BB5810A96C}" = CCC Help Danish

"{EA450D5D-95EA-4FD0-B8B0-6D8E68FBE2C7}" = Impulse

"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger

"{ED780CA9-0687-3C12-B439-3369F224941F}" = Microsoft Visual Studio 2010 Service Pack 1

"{EDDF99D9-9FE3-4871-A7DB-D1522C51EE9A}" = Microsoft .NET Compact Framework 2.0 SP2

"{EF36A836-BF89-4A4F-B079-057B0C68C1E0}" = Sid Meier's Civilization IV Colonization

"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]

"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219

"{F2508213-9989-4E85-A078-72BE483917EF}" = Microsoft Games for Windows - LIVE Redistributable

"{F94CFF0E-600E-4E1C-A0A5-5053C1816A9F}" = League of Legends

"{FA9827E1-8A8E-C176-4923-0840A67ED4DE}" = CCC Help Dutch

"{FC909837-27D0-4FB4-8653-00F63EB70D74}" = Microsoft ASP.NET MVC 3 - Visual Studio 2010 Tools Update

"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials

"{FE23D063-934D-4829-A0D8-00634CE79B4A}" = Adobe AIR

"{FF66E9F6-83E7-3A3E-AF14-8DE9A809A6A4}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.21022

"3DMIDI" = Creative 3DMIDI Player

"Adobe AIR" = Adobe AIR

"Adobe Flash Player ActiveX" = Adobe Flash Player 10 ActiveX

"Adobe Shockwave Player" = Adobe Shockwave Player 11.5

"ALchemy" = Creative ALchemy

"Anti-phishing Domain Advisor" = Anti-phishing Domain Advisor

"Aptana Studio 3" = Aptana Studio 3

"Audacity_is1" = Audacity 2.0

"AudioCS" = Creative Audio Control Panel

"AVG9Uninstall" = AVG 9.0

"Baldur's Gate & Tales of the Sword Coast" = Baldur's Gate & Tales of the Sword Coast

"Baldur's Gate Tutu" = Baldur's Gate Tutu

"BSPlayerf" = BS.Player FREE

"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help

"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player

"com.amazon.music.uploader" = Amazon MP3 Uploader

"Console Launcher" = Creative Console Launcher

"Creative Sound Blaster Properties x64 Edition" = Creative Sound Blaster Properties x64 Edition

"Creative Volume Panel" = Volume Panel

"dBpoweramp Music Converter" = dBpoweramp Music Converter

"dBpoweramp Windows Media Audio 10 Codec" = dBpoweramp Windows Media Audio 10 Codec

"Diablo II" = Diablo II

"Diablo III" = Diablo III

"Diagnostics 4_5" = Creative Diagnostics

"Exact Audio Copy" = Exact Audio Copy 1.0beta3

"Fraps" = Fraps (remove only)

"GalCiv II - Ultimate Edition" = GalCiv II - Ultimate Edition

"Git_is1" = Git version 1.7.6-preview20110708

"HxD Hex Editor_is1" = HxD Hex Editor version 1.7.7.0

"Impulse" = Impulse

"IrfanView" = IrfanView (remove only)

"KeePassPasswordSafe2_is1" = KeePass Password Safe 2.19

"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.61.0.1400

"MatrixEngine 1.0" = MatrixEngine

"MDK_is1" = MDK

"melon" = melon 3.74

"Microsoft Document Explorer 2008" = Microsoft Document Explorer 2008

"Microsoft Report Viewer Redistributable 2008 (KB971119)" = Microsoft Report Viewer Redistributable 2008 SP1

"Microsoft SQL Server 2005" = Microsoft SQL Server 2005

"Microsoft Visual C++ 2008 Express Edition with SP1 - ENU" = Microsoft Visual C++ 2008 Express Edition with SP1 - ENU

"Microsoft Visual Studio 2005 Tools for Office Runtime" = Visual Studio 2005 Tools for Office Second Edition Runtime

"Microsoft Visual Studio 2010 Professional - ENU" = Microsoft Visual Studio 2010 Professional - ENU

"Microsoft Visual Studio 2010 Service Pack 1" = Microsoft Visual Studio 2010 Service Pack 1

"Microsoft Visual Studio Macro Tools" = Microsoft Visual Studio Macro Tools

"Mozilla Firefox 13.0.1 (x86 en-US)" = Mozilla Firefox 13.0.1 (x86 en-US)

"Mozilla Thunderbird 13.0.1 (x86 en-US)" = Mozilla Thunderbird 13.0.1 (x86 en-US)

"MozillaMaintenanceService" = Mozilla Maintenance Service

"nbi-glassfish-mod-3.1.1.12.0" = GlassFish Server Open Source Edition 3.1.1

"nbi-glassfish-mod-3.1.2.23.0" = GlassFish Server Open Source Edition 3.1.2

"nbi-nb-base-7.1.1.0.0" = NetBeans IDE 7.1.1

"Notepad++" = Notepad++

"numpy-py2.7" = Python 2.7 numpy-1.6.1

"Office14.VISIOR" = Microsoft Visio Professional 2010

"OpenAL" = OpenAL

"PhpStorm 4.0.1" = JetBrains PhpStorm 4.0.1

"PLT-4.2.5" = PLT Scheme v4.2.5

"PunkBusterSvc" = PunkBuster Services

"py2exe-py2.6" = Python 2.6 py2exe-0.6.9

"py2exe-py2.7" = Python 2.7 py2exe-0.6.9

"PyCharm 1.5.3" = JetBrains PyCharm 1.5.3

"Racket-5.1.3" = Racket v5.1.3

"Rainmeter" = Rainmeter

"RayV" = RayV-MIM

"Renegade" = Command & Conquer Renegade

"RivaTuner" = RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition

"scipy-py2.7" = Python 2.7 scipy-0.10.0b2

"SFBM" = SoundFont Bank Manager

"Sins of a Solar Empire" = Sins of a Solar Empire

"Snarl" = Snarl 2.4.1

"StarCraft" = StarCraft

"StarCraft II" = StarCraft II

"Steam App 105600" = Terraria

"Steam App 107100" = Bastion

"Steam App 107310" = Cthulhu Saves the World

"Steam App 11900" = Lumines

"Steam App 12900" = Audiosurf

"Steam App 13240" = Unreal Tournament

"Steam App 15620" = Warhammer® 40,000„¢: Dawn of War® II

"Steam App 17080" = Tribes: Ascend

"Steam App 17480" = Command and Conquer: Red Alert 3

"Steam App 200269" = Batman: Arkham City

"Steam App 20930" = The Witcher 2: Bonus Content

"Steam App 211" = Source SDK

"Steam App 215" = Source SDK Base

"Steam App 218" = Source SDK Base 2007

"Steam App 220" = Half-Life 2

"Steam App 2280" = The Ultimate Doom

"Steam App 240" = Counter-Strike: Source

"Steam App 28050" = Deus Ex: Human Revolution

"Steam App 300" = Day of Defeat: Source

"Steam App 35480" = Dwarfs!?

"Steam App 35700" = Trine

"Steam App 3590" = Plants Vs Zombies

"Steam App 400" = Portal

"Steam App 40930" = The Misadventures of P.B. Winterbottom

"Steam App 41500" = Torchlight

"Steam App 48000" = LIMBO

"Steam App 49600" = Beat Hazard

"Steam App 50" = Half-Life: Opposing Force

"Steam App 570" = Dota 2

"Steam App 57650" = DUNGEONS - Steam Special Edition

"Steam App 620" = Portal 2

"Steam App 63000" = HOARD

"Steam App 8850" = BioShock 2

"Steam App 8930" = Sid Meier's Civilization V

"Steam App 98400" = Hard Reset

"Steam App 98800" = Dungeons of Dredmor

"Subsonic" = Subsonic

"SWI-Prolog" = SWI-Prolog (remove only)

"TradersLittleHelper_is1" = Trader's Little Helper 2.7.0

"Veoh Web Player Beta" = Veoh Web Player

"Visual Studio Tools for the Office system 3.0 Runtime" = Visual Studio Tools for the Office system 3.0 Runtime

"VisualWebDeveloper" = Microsoft Visual Studio Web Authoring Component

"VLC media player" = VLC media player 2.0.1

"WaveStudio 7" = Creative WaveStudio 7

"Winamp" = Winamp

"WinLiveSuite" = Windows Live Essentials

"winscp3_is1" = WinSCP 4.3.5

"World of Warcraft" = World of Warcraft

"wxPython2.8-ansi-py27_is1" = wxPython 2.8.12.1 (ansi) for Python 2.7

"xampp" = XAMPP 1.7.7

"XviD & MP3 Codec Pack_is1" = XviD & MP3 Codec Pack (remove only)

"Xvid Video Codec 1.3.1" = Xvid Video Codec

"Zen Puzzle Garden" = Zen Puzzle Garden 1.29

"Zwei-Stein_is1" = Zwei-Stein Video Compositor 3.01 (Beta 2).

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]

"{BD5F3A9C-22D5-4C1D-AEA0-ED1BE83A1E67}_is1" = Ruby 1.9.2-p290

"Dropbox" = Dropbox

"Google Chrome" = Google Chrome

"GoToMeeting" = GoToMeeting 5.2.0.952

"MusicManager" = Music Manager

"pdfsam" = pdfsam

"Spotify" = Spotify

"Winamp Detect" = Winamp Detector Plug-in

========== Last 20 Event Log Errors ==========

[ Application Events ]

Error - 5/30/2012 1:43:14 AM | Computer Name = Hayden-PC | Source = SQLBrowser | ID = 5111816

Description = The SQLBrowser service was unable to process a client request.

Error - 5/30/2012 1:43:15 AM | Computer Name = Hayden-PC | Source = SQLBrowser | ID = 5111816

Description = The SQLBrowser service was unable to process a client request.

Error - 5/30/2012 1:43:15 AM | Computer Name = Hayden-PC | Source = SQLBrowser | ID = 5111816

Description = The SQLBrowser service was unable to process a client request.

Error - 5/30/2012 1:43:21 AM | Computer Name = Hayden-PC | Source = SQLBrowser | ID = 5111816

Description = The SQLBrowser service was unable to process a client request.

Error - 5/30/2012 1:43:21 AM | Computer Name = Hayden-PC | Source = SQLBrowser | ID = 5111816

Description = The SQLBrowser service was unable to process a client request.

Error - 5/30/2012 1:43:53 AM | Computer Name = Hayden-PC | Source = SQLBrowser | ID = 5111816

Description = The SQLBrowser service was unable to process a client request.

Error - 5/30/2012 1:43:53 AM | Computer Name = Hayden-PC | Source = SQLBrowser | ID = 5111816

Description = The SQLBrowser service was unable to process a client request.

Error - 5/30/2012 1:44:05 AM | Computer Name = Hayden-PC | Source = SQLBrowser | ID = 5111816

Description = The SQLBrowser service was unable to process a client request.

Error - 5/30/2012 1:44:05 AM | Computer Name = Hayden-PC | Source = SQLBrowser | ID = 5111816

Description = The SQLBrowser service was unable to process a client request.

Error - 5/30/2012 1:44:11 AM | Computer Name = Hayden-PC | Source = SQLBrowser | ID = 5111816

Description = The SQLBrowser service was unable to process a client request.

[ System Events ]

Error - 7/7/2012 8:20:22 PM | Computer Name = Hayden-PC | Source = Service Control Manager | ID = 7000

Description = The LMIGuardianSvc service failed to start due to the following error:

%%2

Error - 7/7/2012 8:20:26 PM | Computer Name = Hayden-PC | Source = Service Control Manager | ID = 7000

Description = The Web Deployment Agent Service service failed to start due to the

following error: %%31

Error - 7/7/2012 8:20:34 PM | Computer Name = Hayden-PC | Source = Service Control Manager | ID = 7024

Description = The Apache2.2 service terminated with service-specific error %%1.

Error - 7/7/2012 8:21:13 PM | Computer Name = Hayden-PC | Source = Service Control Manager | ID = 7009

Description = A timeout was reached (30000 milliseconds) while waiting for the SQL

Server (MSSQL) service to connect.

Error - 7/7/2012 8:21:13 PM | Computer Name = Hayden-PC | Source = Service Control Manager | ID = 7000

Description = The SQL Server (MSSQL) service failed to start due to the following

error: %%1053

Error - 7/7/2012 8:22:10 PM | Computer Name = Hayden-PC | Source = Service Control Manager | ID = 7009

Description = A timeout was reached (30000 milliseconds) while waiting for the SQL

Server Reporting Services (MSSQL) service to connect.

Error - 7/7/2012 8:22:10 PM | Computer Name = Hayden-PC | Source = Service Control Manager | ID = 7000

Description = The SQL Server Reporting Services (MSSQL) service failed to start

due to the following error: %%1053

Error - 7/7/2012 8:22:30 PM | Computer Name = Hayden-PC | Source = Service Control Manager | ID = 7023

Description = The Windows Defender service terminated with the following error:

%%126

Error - 7/7/2012 8:23:50 PM | Computer Name = Hayden-PC | Source = Service Control Manager | ID = 7026

Description = The following boot-start or system-start driver(s) failed to load:

ASPI32

Error - 7/7/2012 8:29:06 PM | Computer Name = Hayden-PC | Source = Service Control Manager | ID = 7022

Description = The Windows Update service hung on starting.

< End of report >

Link to post
Share on other sites

Small notes: I've had all 3 of those programs for at least 6 months (some 2 years or so) before this happened. I'm pretty cautious about what I torrent and what I grab over DC++. I've, of course, uninstalled them. Just thought maybe this would help.

I understand, but our rules here state that we can't assist, if not eliminate this type of software. The problem is that the source is undetermined ie it is not known whether the software is modified, whether the song was inject with malicious code or in a picture can never be trusted on such a source.

http://forums.malwarebytes.org/index.php?showtopic=97700

Sorry, it is for your own good.

Run OTL

  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    :OTL
    IE - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://blekko.com/ws/?source={SourceID}&toolbarid=TOOLBARNAMESPACE&u=USERGUID&tbp=homepage
    IE - HKU\S-1-5-21-645954481-4171391755-2920796181-1000\..\URLSearchHook: {ba14329e-9550-4989-b3f2-9732e92d17cc} - No CLSID value found
    [2012/07/01 02:32:37 | 000,000,000 | ---D | M] (blekko search bar) -- C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}
    [2012/07/01 02:32:36 | 000,000,000 | ---D | C] -- C:\Users\Hayden\AppData\Local\blekkotb_031
    [2012/07/01 02:32:36 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\blekkotb_031
    @Alternate Data Stream - 133 bytes -> C:\ProgramData\TEMP:05EE1EEF

    :files
    ipconfig /flushdns /c

    :Commands
    [emptytemp]
    [clearallrestorepoints]


  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Please post the OTL fix log in your next reply.

Note: A copy of an OTL fix log is saved in a text file at C:\_OTL\MovedFiles

Link to post
Share on other sites

Oh, I wasn't questioning you or disagreeing. I have a background in CS and I know the issues they can cause, messing up AV, adding new threats, etc. I was just providing more info, because I know that can also be helpful :).

OTL Log:

All processes killed

========== OTL ==========

HKU\S-1-5-21-645954481-4171391755-2920796181-1000\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!

Registry value HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Microsoft\Internet Explorer\URLSearchHooks\\{ba14329e-9550-4989-b3f2-9732e92d17cc} deleted successfully.

Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{ba14329e-9550-4989-b3f2-9732e92d17cc}\ not found.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\components folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\searchbar folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\options folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\weatherbutton\panels\images folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\weatherbutton\panels folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\weatherbutton\icons folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\weatherbutton folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\uwa folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\radio\images folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\radio\css folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\radio folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\panels\js folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\panels\images folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\panels\default\scripts folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\panels\default\images folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\panels\default\css folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\panels\default folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\panels\css folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\panels folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib\debugbar folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin\lib folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\skin folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\locale\lib folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\locale folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\data\weather folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\data\search folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\data\rss folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\data\dynamicElements folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\data folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\widgets\net.vmn.www.TwitterShortcut folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\widgets\net.vmn.www.FacebookShortcut folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\scripts folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\css folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\widgets\net.vmn.www.BlekkoMap\skin folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\widgets\net.vmn.www.BlekkoMap\images folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\widgets\net.vmn.www.BlekkoMap\css folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\widgets\net.vmn.www.BlekkoMap folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\widgets folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\newtab\images folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\newtab folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\modules folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content\lib folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome\content folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61}\chrome folder moved successfully.

C:\Users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\extensions\{8769adce-dba5-48e9-afb5-67b12cdf2e61} folder moved successfully.

C:\Users\Hayden\AppData\Local\blekkotb_031\data folder moved successfully.

C:\Users\Hayden\AppData\Local\blekkotb_031 folder moved successfully.

C:\Program Files (x86)\blekkotb_031\components folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\searchbar folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\options folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\weatherbutton\panels\images folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\weatherbutton\panels folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\weatherbutton\icons folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\weatherbutton folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\uwa folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\radio\images folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\radio\css folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\radio folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\panels\js folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\panels\images folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\panels\default\scripts folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\panels\default\images folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\panels\default\css folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\panels\default folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\panels\css folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\panels folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib\debugbar folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin\lib folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\skin folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\locale\lib folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\locale folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\data\weather folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\data\search folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\data\rss folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\data\dynamicElements folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\data folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\widgets\net.vmn.www.TwitterShortcut folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\widgets\net.vmn.www.FacebookShortcut folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\scripts folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\images folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\widgets\net.vmn.www.BlekkoMap\skin\css folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\widgets\net.vmn.www.BlekkoMap\skin folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\widgets\net.vmn.www.BlekkoMap\images folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\widgets\net.vmn.www.BlekkoMap\css folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\widgets\net.vmn.www.BlekkoMap folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\widgets folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\newtab\images folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\newtab folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\modules folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content\lib folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome\content folder moved successfully.

C:\Program Files (x86)\blekkotb_031\chrome folder moved successfully.

C:\Program Files (x86)\blekkotb_031 folder moved successfully.

ADS C:\ProgramData\TEMP:05EE1EEF deleted successfully.

========== FILES ==========

< ipconfig /flushdns /c >

Windows IP Configuration

Successfully flushed the DNS Resolver Cache.

C:\Users\Hayden\Desktop\downloads\cmd.bat deleted successfully.

C:\Users\Hayden\Desktop\downloads\cmd.txt deleted successfully.

========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: AppData

->Temp folder emptied: 0 bytes

User: Classic .NET AppPool

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes

->Flash cache emptied: 41620 bytes

User: Default

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes

->Flash cache emptied: 56475 bytes

User: Default User

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 0 bytes

->Flash cache emptied: 0 bytes

User: Hayden

->Temp folder emptied: 9388614 bytes

->Temporary Internet Files folder emptied: 16496442 bytes

->Java cache emptied: 272372 bytes

->FireFox cache emptied: 356269739 bytes

->Google Chrome cache emptied: 405195710 bytes

->Flash cache emptied: 1425571 bytes

User: LogMeInRemoteUser

->Temp folder emptied: 0 bytes

->Temporary Internet Files folder emptied: 67 bytes

->Flash cache emptied: 41620 bytes

User: Public

->Temp folder emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes

%systemroot% .tmp files removed: 356352 bytes

%systemroot%\System32 .tmp files removed: 872873 bytes

%systemroot%\System32 (64bit) .tmp files removed: 1456548 bytes

%systemroot%\System32\drivers .tmp files removed: 0 bytes

Windows Temp folder emptied: 97037 bytes

%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 84927 bytes

RecycleBin emptied: 1117 bytes

Total Files Cleaned = 755.00 mb

Restore point Set: OTL Restore Point

OTL by OldTimer - Version 3.2.53.1 log created on 07102012_180508

Files\Folders moved on Reboot...

C:\Users\Hayden\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.

File\Folder C:\Users\Hayden\AppData\Local\Temp\~DF20B58D02EECD7777.TMP not found!

C:\Windows\temp\subsonic\ehcache\chatCache.data moved successfully.

C:\Windows\temp\subsonic\ehcache\musicFolderCache.data moved successfully.

File\Folder C:\Windows\temp\hsperfdata_HAYDEN-PC$\4376 not found!

C:\Windows\temp\e4j7DF5.tmp_dir\exe4jlib.jar moved successfully.

PendingFileRenameOperations files...

File C:\Users\Hayden\AppData\Local\Temp\FXSAPIDebugLogFile.txt not found!

File C:\Users\Hayden\AppData\Local\Temp\~DF20B58D02EECD7777.TMP not found!

File C:\Windows\temp\subsonic\ehcache\chatCache.data not found!

File C:\Windows\temp\subsonic\ehcache\musicFolderCache.data not found!

File C:\Windows\temp\hsperfdata_HAYDEN-PC$\4376 not found!

File C:\Windows\temp\e4j7DF5.tmp_dir\exe4jlib.jar not found!

Registry entries deleted on Reboot...

Link to post
Share on other sites

Of course is helpful, thank you. :)

Please visit this webpage for download links, and instructions for running the tool:

http://www.bleepingcomputer.com/combofix/how-to-use-combofix

* Ensure you have disabled all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

Please include the C:\ComboFix.txt in your next reply for further review.

Note: If you encounter a message "illegal operation attempted on registry key that has been marked for deletion" and no programs will run - please just reboot and that will resolve that error.

Link to post
Share on other sites

Here is the first half of the ComboFix log:

ComboFix 12-07-11.03 - Hayden 07/11/2012 19:44:33.2.8 - x64

Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.12279.8329 [GMT -5:00]

Running from: c:\users\Hayden\Desktop\ComboFix.exe

AV: AVG Anti-Virus *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

SP: AVG Anti-Virus *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\windows\SysWow64\SET16C5.tmp

c:\windows\SysWow64\SETB56.tmp

c:\windows\SysWow64\SETEE75.tmp

c:\windows\SysWow64\SETF25D.tmp

.

.

((((((((((((((((((((((((( Files Created from 2012-06-12 to 2012-07-12 )))))))))))))))))))))))))))))))

.

.

2012-07-12 01:02 . 2012-07-12 01:02 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp

2012-07-12 01:02 . 2012-07-12 01:02 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-07-12 01:02 . 2012-07-12 01:02 -------- d-----w- c:\users\Classic .NET AppPool\AppData\Local\temp

2012-07-10 23:48 . 2012-07-10 23:48 -------- d-----w- c:\programdata\ATI

2012-07-10 23:47 . 2012-07-10 23:47 -------- d-----w- c:\program files (x86)\AMD APP

2012-07-10 23:41 . 2012-07-10 23:41 -------- d-----w- c:\windows\LastGood.Tmp

2012-07-10 23:20 . 2012-07-10 23:21 -------- d-----w- c:\users\Hayden\AppData\Local\blekkotb_031

2012-07-10 23:00 . 2012-07-10 23:00 -------- d-----w- C:\_OTL

2012-07-09 22:27 . 2012-07-09 22:27 -------- d-----w- c:\program files (x86)\KeePass Password Safe 2

2012-07-07 22:36 . 2012-07-07 22:36 -------- d-----w- C:\TDSSKiller_Quarantine

2012-07-07 18:57 . 2012-07-07 18:57 -------- d-----w- c:\users\Hayden\AppData\Roaming\Malwarebytes

2012-07-07 18:56 . 2012-07-07 18:56 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-07-07 18:56 . 2012-07-07 18:56 -------- d-----w- c:\programdata\Malwarebytes

2012-07-07 18:56 . 2012-04-04 20:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-07-07 06:02 . 2012-07-07 06:02 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll

2012-07-07 06:02 . 2012-07-07 06:02 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll

2012-07-06 19:18 . 2012-07-11 00:43 -------- d-----w- C:\subsonic

2012-07-06 19:18 . 2012-07-06 19:18 -------- d-----w- c:\program files (x86)\Subsonic

2012-07-02 18:01 . 2012-07-02 18:01 -------- d-----w- c:\users\Hayden\.pdfsam

2012-07-02 16:17 . 2012-07-02 16:17 -------- d-----w- c:\program files (x86)\pdfsam

2012-07-02 16:07 . 2012-07-04 20:37 -------- d-----w- c:\users\Hayden\AppData\Roaming\ParmisPDF

2012-07-02 15:49 . 2012-07-02 15:49 -------- d-----w- c:\users\Hayden\AppData\Roaming\PrimoPDF

2012-07-02 15:48 . 2012-07-02 15:48 -------- d-----w- c:\users\Hayden\AppData\Roaming\OpenCandy

2012-07-02 15:48 . 2011-02-28 22:37 95008 ----a-w- c:\windows\system32\Primomonnt.dll

2012-07-02 05:32 . 2012-07-02 05:32 -------- d-----w- c:\program files (x86)\Maxis

2012-07-01 07:33 . 2012-07-01 07:33 -------- d-----w- c:\users\Hayden\AppData\Roaming\EAC

2012-07-01 07:33 . 2012-07-01 07:33 -------- d-----w- c:\program files (x86)\Exact Audio Copy

2012-07-01 07:32 . 2012-07-01 07:32 -------- d-----w- c:\programdata\Anti-phishing Domain Advisor

2012-06-27 22:19 . 2012-07-11 01:44 -------- d-----w- c:\users\Hayden\AppData\Roaming\Nitro PDF

2012-06-27 22:18 . 2012-06-25 02:47 29704 ----a-w- c:\windows\system32\nitrolocalmon2.dll

2012-06-27 22:18 . 2012-04-12 03:55 17936 ----a-w- c:\windows\system32\nitrolocalui2.dll

2012-06-27 22:18 . 2012-07-04 20:39 -------- d-----w- c:\program files\Common Files\Nitro PDF

2012-06-27 22:18 . 2012-07-04 20:39 -------- d-----w- c:\program files (x86)\Nitro PDF

2012-06-27 22:18 . 2012-07-02 15:51 -------- d-----w- c:\programdata\Nitro PDF

2012-06-27 22:18 . 2012-06-27 22:18 -------- d-----w- c:\program files (x86)\Common Files\Nitro PDF

2012-06-27 19:50 . 2012-06-27 20:00 -------- d-----w- c:\users\Hayden\.cpan

2012-06-25 00:35 . 2012-06-25 00:35 -------- d-----w- c:\programdata\phpDesigner

2012-06-20 01:45 . 2012-06-20 01:45 -------- d-----w- c:\program files (x86)\Motorola Media Link

2012-06-14 01:07 . 2012-06-14 01:46 -------- d-----w- c:\program files (x86)\Ken Ward's Makeup

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-06-25 02:47 . 2012-06-25 02:47 69640 ----a-w- c:\windows\SysWow64\NLSSRV32.EXE

2012-06-18 08:12 . 2012-07-11 13:55 9013136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{62557726-8C65-44B0-9075-1C9B1E2B9EA9}\mpengine.dll

2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys

2012-06-11 18:50 . 2012-06-11 18:50 187392 ----a-w- c:\windows\system32\clinfo.exe

2012-06-11 18:50 . 2012-06-11 18:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll

2012-06-11 18:50 . 2012-06-11 18:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll

2012-06-11 18:50 . 2012-06-11 18:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll

2012-06-11 18:50 . 2012-06-11 18:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll

2012-06-11 18:50 . 2012-06-11 18:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll

2012-06-11 18:49 . 2012-06-11 18:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll

2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll

2012-06-11 18:29 . 2011-10-26 02:16 24826368 ----a-w- c:\windows\system32\atio6axx.dll

2012-06-11 18:00 . 2012-06-11 18:00 20467712 ----a-w- c:\windows\SysWow64\atioglxx.dll

2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe

2012-06-11 17:24 . 2011-12-06 03:17 924160 ----a-w- c:\windows\SysWow64\aticfx32.dll

2012-06-11 17:23 . 2011-10-26 02:04 1090560 ----a-w- c:\windows\system32\aticfx64.dll

2012-06-11 17:20 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll

2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe

2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe

2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll

2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll

2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll

2012-06-11 17:17 . 2012-06-11 17:17 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll

2012-06-11 17:16 . 2012-06-11 17:16 6301696 ----a-w- c:\windows\SysWow64\atidxx32.dll

2012-06-11 17:01 . 2012-06-11 17:01 6914560 ----a-w- c:\windows\system32\atidxx64.dll

2012-06-11 16:51 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll

2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll

2012-06-11 16:45 . 2012-06-11 16:45 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll

2012-06-11 16:45 . 2011-12-06 02:33 5480448 ----a-w- c:\windows\SysWow64\atiumdag.dll

2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll

2012-06-11 16:45 . 2012-06-11 16:45 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll

2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll

2012-06-11 16:43 . 2011-12-06 02:28 4729344 ----a-w- c:\windows\SysWow64\atiumdva.dll

2012-06-11 16:40 . 2012-06-11 16:40 13277696 ----a-w- c:\windows\SysWow64\aticaldd.dll

2012-06-11 16:36 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll

2012-06-11 16:27 . 2011-10-26 01:22 539136 ----a-w- c:\windows\system32\atiadlxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll

2012-06-11 16:26 . 2011-10-26 01:22 17920 ----a-w- c:\windows\system32\atig6pxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll

2012-06-11 16:26 . 2011-10-26 01:22 41984 ----a-w- c:\windows\system32\atig6txx.dll

2012-06-11 16:26 . 2012-06-11 16:26 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys

2012-06-11 16:25 . 2010-11-26 02:16 54784 ----a-w- c:\windows\system32\atiuxp64.dll

2012-06-11 16:25 . 2012-06-11 16:25 42496 ----a-w- c:\windows\SysWow64\atiuxpag.dll

2012-06-11 16:25 . 2012-06-11 16:25 45056 ----a-w- c:\windows\system32\atiu9p64.dll

2012-06-11 16:24 . 2010-11-26 02:15 32768 ----a-w- c:\windows\SysWow64\atiu9pag.dll

2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll

2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll

2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll

2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll

2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll

2012-05-31 17:25 . 2009-10-30 23:04 279656 ------w- c:\windows\system32\MpSigStub.exe

.

.

((((((((((((((((((((((((((((( SnapShot@2012-07-08_00.20.30 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-10-30 23:27 . 2012-07-12 01:11 92014 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-07-12 01:11 31750 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2009-10-30 22:49 . 2012-07-12 01:11 15962 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-645954481-4171391755-2920796181-1000_UserData.bin

- 2009-07-14 05:30 . 2012-06-24 23:09 86016 c:\windows\system32\DriverStore\infpub.dat

+ 2009-07-14 05:30 . 2012-07-10 23:42 86016 c:\windows\system32\DriverStore\infpub.dat

+ 2012-06-11 18:35 . 2012-06-11 18:35 70144 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\coinst_8.98.dll

+ 2012-06-11 16:25 . 2012-06-11 16:25 42496 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiuxpag.dll

+ 2012-06-11 16:25 . 2012-06-11 16:25 54784 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiuxp64.dll

+ 2012-06-11 16:24 . 2012-06-11 16:24 32768 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiu9pag.dll

+ 2012-06-11 16:25 . 2012-06-11 16:25 45056 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiu9p64.dll

+ 2012-06-11 16:34 . 2012-06-11 16:34 74240 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atisamu64.dll

+ 2012-06-11 16:34 . 2012-06-11 16:34 71168 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atisamu32.dll

+ 2009-06-22 15:34 . 2009-06-22 15:34 51200 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ATIODCLI.exe

+ 2012-06-11 17:17 . 2012-06-11 17:17 21504 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atimuixx.dll

+ 2012-06-11 16:23 . 2012-06-11 16:23 56320 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atimpc64.dll

+ 2012-06-11 16:23 . 2012-06-11 16:23 56832 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atimpc32.dll

+ 2012-06-11 16:26 . 2012-06-11 16:26 14848 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiglpxx.dll

+ 2012-06-11 16:26 . 2012-06-11 16:26 33280 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atigktxx.dll

+ 2012-06-11 16:26 . 2012-06-11 16:26 41984 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atig6txx.dll

+ 2012-06-11 16:26 . 2012-06-11 16:26 17920 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atig6pxx.dll

+ 2012-06-11 17:17 . 2012-06-11 17:17 59392 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiedu64.dll

+ 2012-06-11 16:45 . 2012-06-11 16:45 51200 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticalrt64.dll

+ 2012-06-11 16:45 . 2012-06-11 16:45 46080 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticalrt.dll

+ 2012-06-11 16:45 . 2012-06-11 16:45 44544 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticalcl64.dll

+ 2012-06-11 16:45 . 2012-06-11 16:45 44032 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticalcl.dll

+ 2012-06-11 16:24 . 2012-06-11 16:24 53248 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ati2erec.dll

+ 2012-06-11 17:17 . 2012-06-11 17:17 43520 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ati2edxx.dll

+ 2012-06-11 16:34 . 2012-06-11 16:34 77312 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\amdave64.dll

+ 2012-06-11 16:34 . 2012-06-11 16:34 77312 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\amdave32.dll

+ 2009-10-31 00:26 . 2012-07-11 00:47 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-31 00:26 . 2012-07-07 06:00 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2012-07-10 23:27 . 2012-07-11 00:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-10-31 00:26 . 2012-07-07 06:00 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-07-14 04:54 . 2012-07-07 06:00 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-07-14 04:54 . 2012-07-11 00:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-08 00:25 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-10-30 22:48 . 2012-07-12 01:10 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-08 00:25 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-08 00:25 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-08 00:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-30 22:48 . 2012-07-08 00:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{FD85D9C0-783A-77B7-8EF8-326EC6C154D1}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{F648F088-B270-CF18-6486-AF8B1FE6BC09}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{EE253E80-C298-4A31-BB22-7280DC8C7177}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 10134 c:\windows\Installer\{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{DE123FE9-B7F6-A75A-920D-3937FB9F06E4}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{DD8ACFF8-098E-130C-2799-BCA4D41EBAB2}\ARPPRODUCTICON.exe

+ 2012-07-10 23:47 . 2012-07-10 23:47 88102 c:\windows\Installer\{C8388DCB-6F85-C11F-C9F4-D636960E60F5}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{B2B5B39B-4E8C-AC78-7FF1-7055C338D243}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{AD219F94-16F2-937F-076A-F22DAA8D0A0B}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{A8B72907-B3F5-4C18-2D2B-F5E786A520DF}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{A561BB5F-5A85-5D88-E520-0A4512D5E6C0}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{A1400F57-65CC-0C22-6461-948EA2837670}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{9DA5221E-15DE-5B0F-D7BE-CCC7305575DD}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{8BDD3EC9-27E9-E490-7607-AF97FA678046}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{883CCFC7-CA6B-5531-704B-F9A64546B309}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{85BB7CA7-6B0D-0B27-F4FF-B3D04282B3D1}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{812FF572-F216-EBA0-123E-636C1B6EBC5B}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{633414E3-AA2A-CD04-5976-E91F5F871396}\ARPPRODUCTICON.exe

+ 2012-07-10 23:47 . 2012-07-10 23:47 88102 c:\windows\Installer\{59B69525-1383-C84A-38EF-F442B63E69BC}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{586A5957-F21B-C8AD-F5C2-11D4D7DA5340}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{51054867-140B-8FBF-73A8-75386276BD98}\ARPPRODUCTICON.exe

- 2012-05-19 22:18 . 2012-05-19 22:18 10134 c:\windows\Installer\{503F672D-6C84-448A-8F8F-4BC35AC83441}\ARPPRODUCTICON.exe

+ 2012-07-10 23:47 . 2012-07-10 23:47 10134 c:\windows\Installer\{503F672D-6C84-448A-8F8F-4BC35AC83441}\ARPPRODUCTICON.exe

+ 2012-07-10 23:40 . 2012-07-10 23:40 88102 c:\windows\Installer\{47F9B7C3-F172-940F-D0C4-203C7914E5D2}\NewShortcut5_3B1A0823966A48909E77539C330FBF6E.exe

+ 2012-07-10 23:40 . 2012-07-10 23:40 88102 c:\windows\Installer\{47F9B7C3-F172-940F-D0C4-203C7914E5D2}\NewShortcut4_3B1A0823966A48909E77539C330FBF6E.exe

+ 2012-07-10 23:40 . 2012-07-10 23:40 88102 c:\windows\Installer\{47F9B7C3-F172-940F-D0C4-203C7914E5D2}\NewShortcut3_3B1A0823966A48909E77539C330FBF6E.exe

+ 2012-07-10 23:40 . 2012-07-10 23:40 88102 c:\windows\Installer\{47F9B7C3-F172-940F-D0C4-203C7914E5D2}\NewShortcut2_3B1A0823966A48909E77539C330FBF6E.exe

+ 2012-07-10 23:40 . 2012-07-10 23:40 88102 c:\windows\Installer\{47F9B7C3-F172-940F-D0C4-203C7914E5D2}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{462C2036-3055-4369-D30B-8DA032331EAB}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{3B3D81AB-51E2-695F-7E57-1CC30049F2A3}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{347966F8-E71A-E1A5-95E4-3A1C215383F6}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{2993B157-97AE-7981-F29A-E6575F991CDB}\ARPPRODUCTICON.exe

+ 2012-07-10 23:40 . 2012-07-10 23:40 88102 c:\windows\Installer\{224828D6-DCA7-FDF3-3B85-085298AEC919}\ARPPRODUCTICON.exe

+ 2012-07-10 23:47 . 2012-07-10 23:47 88102 c:\windows\Installer\{12A00DC2-1226-D9F2-13DA-F974111D439E}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{112DDD07-E419-2498-1E9E-2157F82AF5AA}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{079A4EB2-9A74-7B86-12C2-00B52E395801}\ARPPRODUCTICON.exe

+ 2011-09-12 22:06 . 2011-09-12 22:06 3917 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atipblag.dat

- 2012-07-08 00:19 . 2012-07-08 00:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-07-12 01:04 . 2012-07-12 01:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2012-07-08 00:19 . 2012-07-08 00:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2012-07-12 01:04 . 2012-07-12 01:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2009-07-14 05:30 . 2012-06-24 23:09 143360 c:\windows\system32\DriverStore\infstrng.dat

+ 2009-07-14 05:30 . 2012-07-10 23:42 143360 c:\windows\system32\DriverStore\infstrng.dat

- 2009-07-14 05:30 . 2012-05-24 20:05 143360 c:\windows\system32\DriverStore\infstor.dat

+ 2009-07-14 05:30 . 2012-07-10 23:41 143360 c:\windows\system32\DriverStore\infstor.dat

+ 2012-06-11 16:50 . 2012-06-11 16:50 204952 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ativvsvl.dat

+ 2012-06-11 16:50 . 2012-06-11 16:50 157144 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ativvsva.dat

+ 2012-06-11 17:17 . 2012-06-11 17:17 120320 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atitmm64.dll

+ 2010-08-27 18:33 . 2010-08-27 18:33 332800 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ATIODE.exe

+ 2012-06-11 16:26 . 2012-06-11 16:26 367616 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atikmpag.sys

+ 2012-04-12 19:30 . 2012-04-12 19:30 637743 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiicdxx.dat

+ 2012-06-11 17:19 . 2012-06-11 17:19 239616 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiesrxx.exe

+ 2012-06-11 17:19 . 2012-06-11 17:19 532992 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atieclxx.exe

+ 2012-06-11 17:20 . 2012-06-11 17:20 442368 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ATIDEMGX.dll

+ 2012-06-11 17:24 . 2012-06-11 17:24 924160 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticfx32.dll

+ 2009-05-11 21:35 . 2009-05-11 21:35 118784 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atibtmon.exe

+ 2012-06-11 17:25 . 2012-06-11 17:25 163840 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiapfxx.exe

+ 2012-06-11 16:26 . 2012-06-11 16:26 368640 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiadlxy.dll

+ 2012-06-11 16:27 . 2012-06-11 16:27 539136 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiadlxx.dll

+ 2012-04-12 19:30 . 2012-04-12 19:30 637743 c:\windows\system32\atiicdxx.dat

+ 2009-07-14 05:01 . 2012-07-12 01:02 515388 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2009-07-14 05:01 . 2012-07-08 00:17 515388 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

+ 2012-07-04 19:03 . 2012-07-04 19:03 388608 c:\windows\Installer\190bc8.msi

+ 2012-07-04 19:02 . 2012-07-04 19:02 919552 c:\windows\Installer\190bc2.msi

+ 2012-07-04 19:02 . 2012-07-04 19:02 798208 c:\windows\Installer\190bbc.msi

+ 2012-07-04 19:02 . 2012-07-04 19:02 782848 c:\windows\Installer\190bb6.msi

+ 2012-07-04 19:02 . 2012-07-04 19:02 792064 c:\windows\Installer\190bb0.msi

+ 2012-07-04 19:02 . 2012-07-04 19:02 876032 c:\windows\Installer\190baa.msi

+ 2012-07-04 19:01 . 2012-07-04 19:01 772096 c:\windows\Installer\190ba4.msi

+ 2012-07-04 19:01 . 2012-07-04 19:01 903168 c:\windows\Installer\190b9e.msi

+ 2012-07-04 19:01 . 2012-07-04 19:01 785408 c:\windows\Installer\190b98.msi

+ 2012-07-04 19:01 . 2012-07-04 19:01 803840 c:\windows\Installer\190b92.msi

+ 2012-07-04 19:01 . 2012-07-04 19:01 767488 c:\windows\Installer\190b8c.msi

+ 2012-07-04 19:01 . 2012-07-04 19:01 773632 c:\windows\Installer\190b86.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 819712 c:\windows\Installer\190b80.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 839168 c:\windows\Installer\190b7a.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 783872 c:\windows\Installer\190b74.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 813056 c:\windows\Installer\190b6e.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 795648 c:\windows\Installer\190b68.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 774656 c:\windows\Installer\190b62.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 787968 c:\windows\Installer\190b5c.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 727552 c:\windows\Installer\190b56.msi

+ 2012-07-04 18:59 . 2012-07-04 18:59 926720 c:\windows\Installer\190b50.msi

+ 2012-07-04 18:59 . 2012-07-04 18:59 803840 c:\windows\Installer\190b4a.msi

+ 2012-07-04 18:59 . 2012-07-04 18:59 778240 c:\windows\Installer\190b44.msi

+ 2012-07-04 18:59 . 2012-07-04 18:59 808448 c:\windows\Installer\190b3e.msi

+ 2012-05-04 20:52 . 2012-05-04 20:52 507392 c:\windows\Installer\190b32.msi

+ 2012-07-04 19:02 . 2012-07-04 19:02 622592 c:\windows\Installer\190922.msi

+ 2012-06-11 16:43 . 2012-06-11 16:43 4729344 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiumdva.dll

+ 2012-06-11 16:45 . 2012-06-11 16:45 5480448 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiumdag.dll

+ 2012-06-11 16:51 . 2012-06-11 16:51 4246528 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiumd6a.dll

+ 2012-06-11 16:36 . 2012-06-11 16:36 6605824 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiumd64.dll

+ 2012-06-11 17:01 . 2012-06-11 17:01 6914560 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atidxx64.dll

+ 2012-06-11 17:16 . 2012-06-11 17:16 6301696 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atidxx32.dll

+ 2012-06-11 17:23 . 2012-06-11 17:23 1090560 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticfx64.dll

+ 2010-01-23 09:16 . 2012-07-12 01:02 1350152 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat

+ 2012-07-04 19:10 . 2012-07-04 19:10 1787904 c:\windows\Installer\190bdf.msi

+ 2012-07-04 19:04 . 2012-07-04 19:04 1884672 c:\windows\Installer\190b38.msi

+ 2012-07-04 19:10 . 2012-07-04 19:10 8307200 c:\windows\Installer\190929.msi

+ 2012-07-09 22:28 . 2012-07-09 22:28 5561856 c:\windows\assembly\NativeImages_v4.0.30319_32\KeePass\70c2c3ca25f2127e9bc48ac55e25a75e\KeePass.ni.exe

- 2012-06-24 23:13 . 2012-06-24 23:13 5561856 c:\windows\assembly\NativeImages_v4.0.30319_32\KeePass\70c2c3ca25f2127e9bc48ac55e25a75e\KeePass.ni.exe

- 2009-07-14 02:34 . 2012-07-06 08:54 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

+ 2009-07-14 02:34 . 2012-07-11 10:16 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

+ 2012-06-11 18:00 . 2012-06-11 18:00 20467712 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atioglxx.dll

+ 2012-06-11 18:29 . 2012-06-11 18:29 24826368 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atio6axx.dll

+ 2012-06-11 18:59 . 2012-06-11 18:59 10248192 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atikmdag.sys

+ 2012-06-11 16:45 . 2012-06-11 16:45 15703040 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticaldd64.dll

+ 2012-06-11 16:40 . 2012-06-11 16:40 13277696 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticaldd.dll

+ 2010-02-26 09:22 . 2012-07-12 01:03 24081248 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-645954481-4171391755-2920796181-1000-12288.dat

+ 2012-07-04 19:11 . 2012-07-04 19:11 16912384 c:\windows\Installer\190bf2.msi

+ 2012-07-04 18:57 . 2012-07-04 18:57 14294528 c:\windows\Installer\190bcf.msi

.

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]

@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-02 1242448]

"AlcoholAutomount"="c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]

"Xvid"="c:\program files (x86)\XviD\CheckUpdate.exe" [2011-01-17 8192]

"Snarl"="c:\program files (x86)\full phat\Snarl\snarl.exe" [2011-05-25 925696]

"Tonido"="c:\users\Hayden\AppData\Roaming\Tonido\launcher.exe" [2011-11-14 100864]

"MusicManager"="c:\users\Hayden\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [2012-06-01 13806592]

"GoToMeeting"="c:\program files (x86)\Citrix\GoToMeeting\952\g2mstart.exe" [2012-05-25 39816]

"Spotify Web Helper"="c:\users\Hayden\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-30 932528]

"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]

"GoogleChromeAutoLaunch_7BA29E3153B77E65C37077A2469120EB"="c:\users\Hayden\AppData\Local\Google\Chrome\Application\chrome.exe" [2012-07-10 1250328]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]

"AVG9_TRAY"="c:\progra~2\AVG\AVG9\avgtray.exe" [2012-01-26 2077536]

"VolPanel"="c:\program files (x86)\Creative\Volume Panel\VolPanlu.exe" [2008-08-06 233576]

"CTxfiHlp"="CTXFIHLP.EXE" [2009-07-14 24576]

"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]

"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]

"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]

"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]

"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2012-05-03 217256]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-05-01 1895424]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]

.

c:\users\Hayden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

CurseClientStartup.ccip [2010-12-7 0]

Dropbox.lnk - c:\users\Hayden\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]

EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2012-6-13 1014112]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]

Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2011-8-21 102912]

Subsonic.lnk - c:\program files (x86)\Subsonic\subsonic-agent.exe [2011-12-6 206336]

UltraMon.lnk - c:\windows\Installer\{B49673F8-7AB6-4A14-8213-C8A7BE370010}\IcoUltraMon.ico [2010-8-23 29310]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

"HideShutdownScripts"= 0 (0x0)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"MaxRecentDocs"= 99 (0x63)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2011-09-10 18432]

R2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-04-02 90112]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [x]

R2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-02 67400]

R2 MSSQL$MSSQL;SQL Server (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\sqlservr.exe [2010-04-03 61913952]

R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]

R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2009-10-31 79360]

R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-31 79360]

R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-08 230488]

R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]

R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-08 95320]

R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [x]

R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-07 113120]

R3 MSSQLFDLauncher$MSSQL;SQL Full-text Filter Daemon Launcher (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\fdlauncher.exe [2010-04-03 32096]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]

R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2012-05-29 19952]

R3 SQLAgent$MSSQL;SQL Server Agent (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\SQLAGENT.EXE [2010-04-03 428384]

R3 SSMO3v2Filter;MMO3v2 Mouse;c:\windows\system32\drivers\MO3v2Driver.sys [2010-11-22 23040]

R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]

R3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM10864.sys [2010-08-13 1310720]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-10 1255736]

R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]

R3 WMSVC;Web Management Service;c:\windows\system32\inetsrv\wmsvc.exe [2009-07-14 10752]

R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]

R4 RsFx0150;RsFx0150 Driver;c:\windows\system32\DRIVERS\RsFx0150.sys [2010-04-03 313696]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

S0 AvgRkx64;avgrkx64.sys;c:\windows\System32\Drivers\avgrkx64.sys [2010-03-29 56008]

S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-12 503352]

S1 AvgLdx64;AVG AVI Loader Driver x64;c:\windows\System32\Drivers\avgldx64.sys [2010-06-22 269904]

S1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;c:\windows\System32\Drivers\avgmfx64.sys [2011-09-13 35664]

S1 AvgTdiA;AVG Network Redirector x64;c:\windows\System32\Drivers\avgtdia.sys [2011-05-06 317520]

S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]

S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]

S2 avg9emc;AVG E-mail Scanner;c:\program files (x86)\AVG\AVG9\avgemc.exe [2010-07-21 921952]

S2 avg9wd;AVG WatchDog;c:\program files (x86)\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]

S2 DeviceMonitorService;DeviceMonitorService;c:\program files (x86)\Motorola Media Link\Lite\NServiceEntry.exe [2012-06-05 87400]

S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2011-11-08 14216]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

S2 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-06-05 116632]

S2 MSOLAP$MSSQL;SQL Server Analysis Services (MSSQL);c:\program files\Microsoft SQL Server\MSAS10_50.MSSQL\OLAP\bin\msmdsrv.exe [2010-04-03 54568288]

S2 NitroDriverReadSpool2;NitroPDFDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe [2012-06-25 216072]

S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\NLSSRV32.EXE [2012-06-25 69640]

S2 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2011-09-02 65657]

S2 ReportServer$MSSQL;SQL Server Reporting Services (MSSQL);c:\program files\Microsoft SQL Server\MSRS10_50.MSSQL\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2010-04-03 2175328]

S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2008-11-14 20512]

S2 WDDMService.exe;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-08-17 116224]

S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]

S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]

S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-08 230488]

S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]

S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-08 95320]

S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys [2010-05-22 66728]

S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-08 1612888]

S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2010-12-12 22408]

S3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys [2009-07-01 30728]

S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2010-12-12 16008]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 24904]

S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]

S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]

S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-09-28 395264]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

iissvcs REG_MULTI_SZ w3svc was

apphost REG_MULTI_SZ apphostsvc

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

Link to post
Share on other sites

<p> </p>

<div>Contents of the 'Scheduled Tasks' folder</div>

<div>.</div>

<div>2012-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000Core.job</div>

<div>- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]</div>

<div>.</div>

<div>2012-07-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000UA.job</div>

<div>- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]</div>

<div>.</div>

<div>.</div>

<div>--------- X64 Entries -----------</div>

<div>.</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]</div>

<div>@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space: pre; "> </span>97792<span class="Apple-tab-span" style="white-space: pre; "> </span>----a-w-<span class="Apple-tab-span" style="white-space: pre; "> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]</div>

<div>@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space: pre; "> </span>97792<span class="Apple-tab-span" style="white-space: pre; "> </span>----a-w-<span class="Apple-tab-span" style="white-space: pre; "> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]</div>

<div>@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space: pre; "> </span>97792<span class="Apple-tab-span" style="white-space: pre; "> </span>----a-w-<span class="Apple-tab-span" style="white-space: pre; "> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]</div>

<div>@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space: pre; "> </span>97792<span class="Apple-tab-span" style="white-space: pre; "> </span>----a-w-<span class="Apple-tab-span" style="white-space: pre; "> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]</div>

<div>"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-06-15 110360]</div>

<div>"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]</div>

<div>"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]</div>

<div>"Cm108Sound"="c:\windows\Syswow64\cm108.dll" [2010-10-13 8757248]</div>

<div>.</div>

<div>------- Supplementary Scan -------</div>

<div>.</div>

<div>uStart Page = </div>

<div>mLocal Page = c:\windows\SysWOW64\blank.htm</div>

<div>uInternet Settings,ProxyOverride = *.local;192.168.*.*</div>

<div>IE: &Verzenden naar OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105</div>

<div>IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204</div>

<div>IE: E&xporteren naar Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000</div>

<div>Trusted Zone: clonewarsadventures.com</div>

<div>Trusted Zone: freerealms.com</div>

<div>Trusted Zone: soe.com</div>

<div>Trusted Zone: sony.com</div>

<div>TCP: DhcpNameServer = 192.168.1.254</div>

<div>DPF: {EF0D1A14-1033-41A2-A589-240C01EDC078} - hxxp://dl.pplive.com/PluginSetup.cab</div>

<div>FF - ProfilePath - c:\users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\</div>

<div>.</div>

<div>- - - - ORPHANS REMOVED - - - -</div>

<div>.</div>

<div>WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)</div>

<div>.</div>

<div>.</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MsDepSvc]</div>

<div>"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"</div>

<div>.</div>

<div>--------------------- LOCKED REGISTRY KEYS ---------------------</div>

<div>.</div>

<div>[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]</div>

<div>@Denied: (2) (S-1-5-21-645954481-4171391755-2920796181-1000)</div>

<div>@Denied: (2) (LocalSystem)</div>

<div>"Progid"="ThunderbirdEML"</div>

<div>.</div>

<div>[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]</div>

<div>@Denied: (2) (LocalSystem)</div>

<div>"Progid"="WindowsLiveMail.VCard.1"</div>

<div>.</div>

<div>[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\SecuROM\License information*]</div>

<div>"datasecu"=hex:97,d2,c9,85,02,71,88,e1,fc,ae,42,fe,02,8d,8e,24,19,8e,34,38,98,</div>

<div>   bf,29,19,59,bb,61,f1,77,18,e7,bc,4a,35,98,08,f1,6c,21,76,ba,c6,fb,cc,72,f4,\</div>

<div>"rkeysecu"=hex:79,fe,52,e1,00,f1,26,9b,6e,10,c9,f7,ce,d0,27,3d</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]</div>

<div>@Denied: (A 2) (Everyone)</div>

<div>@="FlashBroker"</div>

<div>"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe,-101"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]</div>

<div>"Enabled"=dword:00000001</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]</div>

<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]</div>

<div>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]</div>

<div>@Denied: (A 2) (Everyone)</div>

<div>@="Shockwave Flash Object"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]</div>

<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"</div>

<div>"ThreadingModel"="Apartment"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]</div>

<div>@="0"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]</div>

<div>@="ShockwaveFlash.ShockwaveFlash.10"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]</div>

<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]</div>

<div>@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]</div>

<div>@="1.0"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]</div>

<div>@="ShockwaveFlash.ShockwaveFlash"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]</div>

<div>@Denied: (A 2) (Everyone)</div>

<div>@="Macromedia Flash Factory Object"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]</div>

<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"</div>

<div>"ThreadingModel"="Apartment"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]</div>

<div>@="FlashFactory.FlashFactory.1"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]</div>

<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]</div>

<div>@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]</div>

<div>@="1.0"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]</div>

<div>@="FlashFactory.FlashFactory"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]</div>

<div>@Denied: (A 2) (Everyone)</div>

<div>@="IFlashBroker4"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]</div>

<div>@="{00020424-0000-0000-C000-000000000046}"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]</div>

<div>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"</div>

<div>"Version"="1.0"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]</div>

<div>@Denied: (A) (Everyone)</div>

<div>"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}]</div>

<div>@Denied: (A) (Everyone)</div>

<div>"Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane]</div>

<div>@Denied: (A) (Everyone)</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane\0]</div>

<div>"Key"="ActionsPane"</div>

<div>"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]</div>

<div>@Denied: (A) (Everyone)</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]</div>

<div>"Key"="ActionsPane3"</div>

<div>"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]</div>

<div>@Denied: (Full) (Everyone)</div>

<div>.</div>

<div>------------------------ Other Running Processes ------------------------</div>

<div>.</div>

<div>c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe</div>

<div>c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe</div>

<div>c:\program files (x86)\Bonjour\mDNSResponder.exe</div>

<div>c:\xampp\filezillaftp\filezillaserver.exe</div>

<div>c:\program files (x86)\Windows Media Player\wmplayer.exe</div>

<div>c:\windows\SysWOW64\rundll32.exe</div>

<div>c:\users\Hayden\AppData\Roaming\Tonido\tonido.exe</div>

<div>c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe</div>

<div>c:\program files (x86)\Motorola Mobility\MotoCast\MotoCast.exe</div>

<div>c:\program files (x86)\AVG\AVG9\avgtray.exe</div>

<div>c:\windows\SysWOW64\Ctxfihlp.exe</div>

<div>c:\windows\SysWOW64\CTXFISPI.EXE</div>

<div>c:\xampp\mysql\bin\mysqld.exe</div>

<div>c:\program files (x86)\full phat\Snarl\extensions\AudioMon\snarl-audiomon.exe</div>

<div>c:\program files (x86)\Citrix\GoToMeeting\952\g2mcomm.exe</div>

<div>c:\program files (x86)\Citrix\GoToMeeting\952\g2mlauncher.exe</div>

<div>c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe</div>

<div>c:\program files (x86)\AVG\AVG9\avgcsrvx.exe</div>

<div>c:\program files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe</div>

<div>c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDMovieViewer.exe</div>

<div>c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDWebCam.exe</div>

<div>c:\program files\Logitech Gaming Software\plugins\LCDAppletsMono-8.00.048\Applets\x86\LCDMedia.exe</div>

<div>c:\users\Hayden\Desktop\downloads\SirReal\LCDSirReal.exe</div>

<div>c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDYT.exe</div>

<div>c:\program files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe</div>

<div>c:\program files (x86)\HP\Digital Imaging\bin\hpqbam08.exe</div>

<div>c:\program files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe</div>

<div>c:\program files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe</div>

<div>.</div>

<div>**************************************************************************</div>

<div>.</div>

<div>Completion time: 2012-07-11  20:29:55 - machine was rebooted</div>

<div>ComboFix-quarantined-files.txt  2012-07-12 01:29</div>

<div>ComboFix2.txt  2012-07-08 00:33</div>

<div>.</div>

<div>Pre-Run: 88,333,967,360 bytes free</div>

<div>Post-Run: 88,599,154,688 bytes free</div>

<div>.</div>

<div>- - End Of File - - 01354FEA945C4CCE7AEAB1B72CAF7589</div>

<div> </div>

Link to post
Share on other sites

Well that was a bust. My bad, delete those if you can, take two. ComboFix.log:

ComboFix 12-07-11.03 - Hayden 07/11/2012 19:44:33.2.8 - x64

Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.12279.8329 [GMT -5:00]

Running from: c:\users\Hayden\Desktop\ComboFix.exe

AV: AVG Anti-Virus *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

SP: AVG Anti-Virus *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\windows\SysWow64\SET16C5.tmp

c:\windows\SysWow64\SETB56.tmp

c:\windows\SysWow64\SETEE75.tmp

c:\windows\SysWow64\SETF25D.tmp

.

.

((((((((((((((((((((((((( Files Created from 2012-06-12 to 2012-07-12 )))))))))))))))))))))))))))))))

.

.

2012-07-12 01:02 . 2012-07-12 01:02 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp

2012-07-12 01:02 . 2012-07-12 01:02 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-07-12 01:02 . 2012-07-12 01:02 -------- d-----w- c:\users\Classic .NET AppPool\AppData\Local\temp

2012-07-10 23:48 . 2012-07-10 23:48 -------- d-----w- c:\programdata\ATI

2012-07-10 23:47 . 2012-07-10 23:47 -------- d-----w- c:\program files (x86)\AMD APP

2012-07-10 23:41 . 2012-07-10 23:41 -------- d-----w- c:\windows\LastGood.Tmp

2012-07-10 23:20 . 2012-07-10 23:21 -------- d-----w- c:\users\Hayden\AppData\Local\blekkotb_031

2012-07-10 23:00 . 2012-07-10 23:00 -------- d-----w- C:\_OTL

2012-07-09 22:27 . 2012-07-09 22:27 -------- d-----w- c:\program files (x86)\KeePass Password Safe 2

2012-07-07 22:36 . 2012-07-07 22:36 -------- d-----w- C:\TDSSKiller_Quarantine

2012-07-07 18:57 . 2012-07-07 18:57 -------- d-----w- c:\users\Hayden\AppData\Roaming\Malwarebytes

2012-07-07 18:56 . 2012-07-07 18:56 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-07-07 18:56 . 2012-07-07 18:56 -------- d-----w- c:\programdata\Malwarebytes

2012-07-07 18:56 . 2012-04-04 20:56 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-07-07 06:02 . 2012-07-07 06:02 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll

2012-07-07 06:02 . 2012-07-07 06:02 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll

2012-07-06 19:18 . 2012-07-11 00:43 -------- d-----w- C:\subsonic

2012-07-06 19:18 . 2012-07-06 19:18 -------- d-----w- c:\program files (x86)\Subsonic

2012-07-02 18:01 . 2012-07-02 18:01 -------- d-----w- c:\users\Hayden\.pdfsam

2012-07-02 16:17 . 2012-07-02 16:17 -------- d-----w- c:\program files (x86)\pdfsam

2012-07-02 16:07 . 2012-07-04 20:37 -------- d-----w- c:\users\Hayden\AppData\Roaming\ParmisPDF

2012-07-02 15:49 . 2012-07-02 15:49 -------- d-----w- c:\users\Hayden\AppData\Roaming\PrimoPDF

2012-07-02 15:48 . 2012-07-02 15:48 -------- d-----w- c:\users\Hayden\AppData\Roaming\OpenCandy

2012-07-02 15:48 . 2011-02-28 22:37 95008 ----a-w- c:\windows\system32\Primomonnt.dll

2012-07-02 05:32 . 2012-07-02 05:32 -------- d-----w- c:\program files (x86)\Maxis

2012-07-01 07:33 . 2012-07-01 07:33 -------- d-----w- c:\users\Hayden\AppData\Roaming\EAC

2012-07-01 07:33 . 2012-07-01 07:33 -------- d-----w- c:\program files (x86)\Exact Audio Copy

2012-07-01 07:32 . 2012-07-01 07:32 -------- d-----w- c:\programdata\Anti-phishing Domain Advisor

2012-06-27 22:19 . 2012-07-11 01:44 -------- d-----w- c:\users\Hayden\AppData\Roaming\Nitro PDF

2012-06-27 22:18 . 2012-06-25 02:47 29704 ----a-w- c:\windows\system32\nitrolocalmon2.dll

2012-06-27 22:18 . 2012-04-12 03:55 17936 ----a-w- c:\windows\system32\nitrolocalui2.dll

2012-06-27 22:18 . 2012-07-04 20:39 -------- d-----w- c:\program files\Common Files\Nitro PDF

2012-06-27 22:18 . 2012-07-04 20:39 -------- d-----w- c:\program files (x86)\Nitro PDF

2012-06-27 22:18 . 2012-07-02 15:51 -------- d-----w- c:\programdata\Nitro PDF

2012-06-27 22:18 . 2012-06-27 22:18 -------- d-----w- c:\program files (x86)\Common Files\Nitro PDF

2012-06-27 19:50 . 2012-06-27 20:00 -------- d-----w- c:\users\Hayden\.cpan

2012-06-25 00:35 . 2012-06-25 00:35 -------- d-----w- c:\programdata\phpDesigner

2012-06-20 01:45 . 2012-06-20 01:45 -------- d-----w- c:\program files (x86)\Motorola Media Link

2012-06-14 01:07 . 2012-06-14 01:46 -------- d-----w- c:\program files (x86)\Ken Ward's Makeup

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-06-25 02:47 . 2012-06-25 02:47 69640 ----a-w- c:\windows\SysWow64\NLSSRV32.EXE

2012-06-18 08:12 . 2012-07-11 13:55 9013136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{62557726-8C65-44B0-9075-1C9B1E2B9EA9}\mpengine.dll

2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys

2012-06-11 18:50 . 2012-06-11 18:50 187392 ----a-w- c:\windows\system32\clinfo.exe

2012-06-11 18:50 . 2012-06-11 18:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll

2012-06-11 18:50 . 2012-06-11 18:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll

2012-06-11 18:50 . 2012-06-11 18:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll

2012-06-11 18:50 . 2012-06-11 18:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll

2012-06-11 18:50 . 2012-06-11 18:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll

2012-06-11 18:49 . 2012-06-11 18:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll

2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll

2012-06-11 18:29 . 2011-10-26 02:16 24826368 ----a-w- c:\windows\system32\atio6axx.dll

2012-06-11 18:00 . 2012-06-11 18:00 20467712 ----a-w- c:\windows\SysWow64\atioglxx.dll

2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe

2012-06-11 17:24 . 2011-12-06 03:17 924160 ----a-w- c:\windows\SysWow64\aticfx32.dll

2012-06-11 17:23 . 2011-10-26 02:04 1090560 ----a-w- c:\windows\system32\aticfx64.dll

2012-06-11 17:20 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll

2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe

2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe

2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll

2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll

2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll

2012-06-11 17:17 . 2012-06-11 17:17 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll

2012-06-11 17:16 . 2012-06-11 17:16 6301696 ----a-w- c:\windows\SysWow64\atidxx32.dll

2012-06-11 17:01 . 2012-06-11 17:01 6914560 ----a-w- c:\windows\system32\atidxx64.dll

2012-06-11 16:51 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll

2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll

2012-06-11 16:45 . 2012-06-11 16:45 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll

2012-06-11 16:45 . 2011-12-06 02:33 5480448 ----a-w- c:\windows\SysWow64\atiumdag.dll

2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll

2012-06-11 16:45 . 2012-06-11 16:45 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll

2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll

2012-06-11 16:43 . 2011-12-06 02:28 4729344 ----a-w- c:\windows\SysWow64\atiumdva.dll

2012-06-11 16:40 . 2012-06-11 16:40 13277696 ----a-w- c:\windows\SysWow64\aticaldd.dll

2012-06-11 16:36 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll

2012-06-11 16:27 . 2011-10-26 01:22 539136 ----a-w- c:\windows\system32\atiadlxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll

2012-06-11 16:26 . 2011-10-26 01:22 17920 ----a-w- c:\windows\system32\atig6pxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll

2012-06-11 16:26 . 2011-10-26 01:22 41984 ----a-w- c:\windows\system32\atig6txx.dll

2012-06-11 16:26 . 2012-06-11 16:26 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys

2012-06-11 16:25 . 2010-11-26 02:16 54784 ----a-w- c:\windows\system32\atiuxp64.dll

2012-06-11 16:25 . 2012-06-11 16:25 42496 ----a-w- c:\windows\SysWow64\atiuxpag.dll

2012-06-11 16:25 . 2012-06-11 16:25 45056 ----a-w- c:\windows\system32\atiu9p64.dll

2012-06-11 16:24 . 2010-11-26 02:15 32768 ----a-w- c:\windows\SysWow64\atiu9pag.dll

2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll

2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll

2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll

2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll

2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll

2012-05-31 17:25 . 2009-10-30 23:04 279656 ------w- c:\windows\system32\MpSigStub.exe

.

.

((((((((((((((((((((((((((((( SnapShot@2012-07-08_00.20.30 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-10-30 23:27 . 2012-07-12 01:11 92014 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-07-12 01:11 31750 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2009-10-30 22:49 . 2012-07-12 01:11 15962 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-645954481-4171391755-2920796181-1000_UserData.bin

- 2009-07-14 05:30 . 2012-06-24 23:09 86016 c:\windows\system32\DriverStore\infpub.dat

+ 2009-07-14 05:30 . 2012-07-10 23:42 86016 c:\windows\system32\DriverStore\infpub.dat

+ 2012-06-11 18:35 . 2012-06-11 18:35 70144 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\coinst_8.98.dll

+ 2012-06-11 16:25 . 2012-06-11 16:25 42496 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiuxpag.dll

+ 2012-06-11 16:25 . 2012-06-11 16:25 54784 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiuxp64.dll

+ 2012-06-11 16:24 . 2012-06-11 16:24 32768 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiu9pag.dll

+ 2012-06-11 16:25 . 2012-06-11 16:25 45056 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiu9p64.dll

+ 2012-06-11 16:34 . 2012-06-11 16:34 74240 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atisamu64.dll

+ 2012-06-11 16:34 . 2012-06-11 16:34 71168 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atisamu32.dll

+ 2009-06-22 15:34 . 2009-06-22 15:34 51200 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ATIODCLI.exe

+ 2012-06-11 17:17 . 2012-06-11 17:17 21504 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atimuixx.dll

+ 2012-06-11 16:23 . 2012-06-11 16:23 56320 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atimpc64.dll

+ 2012-06-11 16:23 . 2012-06-11 16:23 56832 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atimpc32.dll

+ 2012-06-11 16:26 . 2012-06-11 16:26 14848 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiglpxx.dll

+ 2012-06-11 16:26 . 2012-06-11 16:26 33280 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atigktxx.dll

+ 2012-06-11 16:26 . 2012-06-11 16:26 41984 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atig6txx.dll

+ 2012-06-11 16:26 . 2012-06-11 16:26 17920 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atig6pxx.dll

+ 2012-06-11 17:17 . 2012-06-11 17:17 59392 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiedu64.dll

+ 2012-06-11 16:45 . 2012-06-11 16:45 51200 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticalrt64.dll

+ 2012-06-11 16:45 . 2012-06-11 16:45 46080 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticalrt.dll

+ 2012-06-11 16:45 . 2012-06-11 16:45 44544 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticalcl64.dll

+ 2012-06-11 16:45 . 2012-06-11 16:45 44032 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticalcl.dll

+ 2012-06-11 16:24 . 2012-06-11 16:24 53248 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ati2erec.dll

+ 2012-06-11 17:17 . 2012-06-11 17:17 43520 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ati2edxx.dll

+ 2012-06-11 16:34 . 2012-06-11 16:34 77312 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\amdave64.dll

+ 2012-06-11 16:34 . 2012-06-11 16:34 77312 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\amdave32.dll

+ 2009-10-31 00:26 . 2012-07-11 00:47 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-31 00:26 . 2012-07-07 06:00 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2012-07-10 23:27 . 2012-07-11 00:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-10-31 00:26 . 2012-07-07 06:00 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-07-14 04:54 . 2012-07-07 06:00 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-07-14 04:54 . 2012-07-11 00:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-08 00:25 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-10-30 22:48 . 2012-07-12 01:10 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-08 00:25 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-08 00:25 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-08 00:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-30 22:48 . 2012-07-08 00:25 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{FD85D9C0-783A-77B7-8EF8-326EC6C154D1}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{F648F088-B270-CF18-6486-AF8B1FE6BC09}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{EE253E80-C298-4A31-BB22-7280DC8C7177}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 10134 c:\windows\Installer\{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{DE123FE9-B7F6-A75A-920D-3937FB9F06E4}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{DD8ACFF8-098E-130C-2799-BCA4D41EBAB2}\ARPPRODUCTICON.exe

+ 2012-07-10 23:47 . 2012-07-10 23:47 88102 c:\windows\Installer\{C8388DCB-6F85-C11F-C9F4-D636960E60F5}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{B2B5B39B-4E8C-AC78-7FF1-7055C338D243}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{AD219F94-16F2-937F-076A-F22DAA8D0A0B}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{A8B72907-B3F5-4C18-2D2B-F5E786A520DF}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{A561BB5F-5A85-5D88-E520-0A4512D5E6C0}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{A1400F57-65CC-0C22-6461-948EA2837670}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{9DA5221E-15DE-5B0F-D7BE-CCC7305575DD}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{8BDD3EC9-27E9-E490-7607-AF97FA678046}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{883CCFC7-CA6B-5531-704B-F9A64546B309}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{85BB7CA7-6B0D-0B27-F4FF-B3D04282B3D1}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{812FF572-F216-EBA0-123E-636C1B6EBC5B}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{633414E3-AA2A-CD04-5976-E91F5F871396}\ARPPRODUCTICON.exe

+ 2012-07-10 23:47 . 2012-07-10 23:47 88102 c:\windows\Installer\{59B69525-1383-C84A-38EF-F442B63E69BC}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{586A5957-F21B-C8AD-F5C2-11D4D7DA5340}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{51054867-140B-8FBF-73A8-75386276BD98}\ARPPRODUCTICON.exe

- 2012-05-19 22:18 . 2012-05-19 22:18 10134 c:\windows\Installer\{503F672D-6C84-448A-8F8F-4BC35AC83441}\ARPPRODUCTICON.exe

+ 2012-07-10 23:47 . 2012-07-10 23:47 10134 c:\windows\Installer\{503F672D-6C84-448A-8F8F-4BC35AC83441}\ARPPRODUCTICON.exe

+ 2012-07-10 23:40 . 2012-07-10 23:40 88102 c:\windows\Installer\{47F9B7C3-F172-940F-D0C4-203C7914E5D2}\NewShortcut5_3B1A0823966A48909E77539C330FBF6E.exe

+ 2012-07-10 23:40 . 2012-07-10 23:40 88102 c:\windows\Installer\{47F9B7C3-F172-940F-D0C4-203C7914E5D2}\NewShortcut4_3B1A0823966A48909E77539C330FBF6E.exe

+ 2012-07-10 23:40 . 2012-07-10 23:40 88102 c:\windows\Installer\{47F9B7C3-F172-940F-D0C4-203C7914E5D2}\NewShortcut3_3B1A0823966A48909E77539C330FBF6E.exe

+ 2012-07-10 23:40 . 2012-07-10 23:40 88102 c:\windows\Installer\{47F9B7C3-F172-940F-D0C4-203C7914E5D2}\NewShortcut2_3B1A0823966A48909E77539C330FBF6E.exe

+ 2012-07-10 23:40 . 2012-07-10 23:40 88102 c:\windows\Installer\{47F9B7C3-F172-940F-D0C4-203C7914E5D2}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{462C2036-3055-4369-D30B-8DA032331EAB}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{3B3D81AB-51E2-695F-7E57-1CC30049F2A3}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{347966F8-E71A-E1A5-95E4-3A1C215383F6}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{2993B157-97AE-7981-F29A-E6575F991CDB}\ARPPRODUCTICON.exe

+ 2012-07-10 23:40 . 2012-07-10 23:40 88102 c:\windows\Installer\{224828D6-DCA7-FDF3-3B85-085298AEC919}\ARPPRODUCTICON.exe

+ 2012-07-10 23:47 . 2012-07-10 23:47 88102 c:\windows\Installer\{12A00DC2-1226-D9F2-13DA-F974111D439E}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{112DDD07-E419-2498-1E9E-2157F82AF5AA}\ARPPRODUCTICON.exe

+ 2012-07-10 23:46 . 2012-07-10 23:46 88102 c:\windows\Installer\{079A4EB2-9A74-7B86-12C2-00B52E395801}\ARPPRODUCTICON.exe

+ 2011-09-12 22:06 . 2011-09-12 22:06 3917 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atipblag.dat

- 2012-07-08 00:19 . 2012-07-08 00:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-07-12 01:04 . 2012-07-12 01:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

- 2012-07-08 00:19 . 2012-07-08 00:19 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2012-07-12 01:04 . 2012-07-12 01:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2009-07-14 05:30 . 2012-06-24 23:09 143360 c:\windows\system32\DriverStore\infstrng.dat

+ 2009-07-14 05:30 . 2012-07-10 23:42 143360 c:\windows\system32\DriverStore\infstrng.dat

- 2009-07-14 05:30 . 2012-05-24 20:05 143360 c:\windows\system32\DriverStore\infstor.dat

+ 2009-07-14 05:30 . 2012-07-10 23:41 143360 c:\windows\system32\DriverStore\infstor.dat

+ 2012-06-11 16:50 . 2012-06-11 16:50 204952 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ativvsvl.dat

+ 2012-06-11 16:50 . 2012-06-11 16:50 157144 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ativvsva.dat

+ 2012-06-11 17:17 . 2012-06-11 17:17 120320 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atitmm64.dll

+ 2010-08-27 18:33 . 2010-08-27 18:33 332800 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ATIODE.exe

+ 2012-06-11 16:26 . 2012-06-11 16:26 367616 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atikmpag.sys

+ 2012-04-12 19:30 . 2012-04-12 19:30 637743 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiicdxx.dat

+ 2012-06-11 17:19 . 2012-06-11 17:19 239616 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiesrxx.exe

+ 2012-06-11 17:19 . 2012-06-11 17:19 532992 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atieclxx.exe

+ 2012-06-11 17:20 . 2012-06-11 17:20 442368 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\ATIDEMGX.dll

+ 2012-06-11 17:24 . 2012-06-11 17:24 924160 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticfx32.dll

+ 2009-05-11 21:35 . 2009-05-11 21:35 118784 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atibtmon.exe

+ 2012-06-11 17:25 . 2012-06-11 17:25 163840 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiapfxx.exe

+ 2012-06-11 16:26 . 2012-06-11 16:26 368640 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiadlxy.dll

+ 2012-06-11 16:27 . 2012-06-11 16:27 539136 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiadlxx.dll

+ 2012-04-12 19:30 . 2012-04-12 19:30 637743 c:\windows\system32\atiicdxx.dat

+ 2009-07-14 05:01 . 2012-07-12 01:02 515388 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2009-07-14 05:01 . 2012-07-08 00:17 515388 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

+ 2012-07-04 19:03 . 2012-07-04 19:03 388608 c:\windows\Installer\190bc8.msi

+ 2012-07-04 19:02 . 2012-07-04 19:02 919552 c:\windows\Installer\190bc2.msi

+ 2012-07-04 19:02 . 2012-07-04 19:02 798208 c:\windows\Installer\190bbc.msi

+ 2012-07-04 19:02 . 2012-07-04 19:02 782848 c:\windows\Installer\190bb6.msi

+ 2012-07-04 19:02 . 2012-07-04 19:02 792064 c:\windows\Installer\190bb0.msi

+ 2012-07-04 19:02 . 2012-07-04 19:02 876032 c:\windows\Installer\190baa.msi

+ 2012-07-04 19:01 . 2012-07-04 19:01 772096 c:\windows\Installer\190ba4.msi

+ 2012-07-04 19:01 . 2012-07-04 19:01 903168 c:\windows\Installer\190b9e.msi

+ 2012-07-04 19:01 . 2012-07-04 19:01 785408 c:\windows\Installer\190b98.msi

+ 2012-07-04 19:01 . 2012-07-04 19:01 803840 c:\windows\Installer\190b92.msi

+ 2012-07-04 19:01 . 2012-07-04 19:01 767488 c:\windows\Installer\190b8c.msi

+ 2012-07-04 19:01 . 2012-07-04 19:01 773632 c:\windows\Installer\190b86.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 819712 c:\windows\Installer\190b80.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 839168 c:\windows\Installer\190b7a.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 783872 c:\windows\Installer\190b74.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 813056 c:\windows\Installer\190b6e.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 795648 c:\windows\Installer\190b68.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 774656 c:\windows\Installer\190b62.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 787968 c:\windows\Installer\190b5c.msi

+ 2012-07-04 19:00 . 2012-07-04 19:00 727552 c:\windows\Installer\190b56.msi

+ 2012-07-04 18:59 . 2012-07-04 18:59 926720 c:\windows\Installer\190b50.msi

+ 2012-07-04 18:59 . 2012-07-04 18:59 803840 c:\windows\Installer\190b4a.msi

+ 2012-07-04 18:59 . 2012-07-04 18:59 778240 c:\windows\Installer\190b44.msi

+ 2012-07-04 18:59 . 2012-07-04 18:59 808448 c:\windows\Installer\190b3e.msi

+ 2012-05-04 20:52 . 2012-05-04 20:52 507392 c:\windows\Installer\190b32.msi

+ 2012-07-04 19:02 . 2012-07-04 19:02 622592 c:\windows\Installer\190922.msi

+ 2012-06-11 16:43 . 2012-06-11 16:43 4729344 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiumdva.dll

+ 2012-06-11 16:45 . 2012-06-11 16:45 5480448 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiumdag.dll

+ 2012-06-11 16:51 . 2012-06-11 16:51 4246528 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiumd6a.dll

+ 2012-06-11 16:36 . 2012-06-11 16:36 6605824 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atiumd64.dll

+ 2012-06-11 17:01 . 2012-06-11 17:01 6914560 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atidxx64.dll

+ 2012-06-11 17:16 . 2012-06-11 17:16 6301696 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atidxx32.dll

+ 2012-06-11 17:23 . 2012-06-11 17:23 1090560 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticfx64.dll

+ 2010-01-23 09:16 . 2012-07-12 01:02 1350152 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat

+ 2012-07-04 19:10 . 2012-07-04 19:10 1787904 c:\windows\Installer\190bdf.msi

+ 2012-07-04 19:04 . 2012-07-04 19:04 1884672 c:\windows\Installer\190b38.msi

+ 2012-07-04 19:10 . 2012-07-04 19:10 8307200 c:\windows\Installer\190929.msi

+ 2012-07-09 22:28 . 2012-07-09 22:28 5561856 c:\windows\assembly\NativeImages_v4.0.30319_32\KeePass\70c2c3ca25f2127e9bc48ac55e25a75e\KeePass.ni.exe

- 2012-06-24 23:13 . 2012-06-24 23:13 5561856 c:\windows\assembly\NativeImages_v4.0.30319_32\KeePass\70c2c3ca25f2127e9bc48ac55e25a75e\KeePass.ni.exe

- 2009-07-14 02:34 . 2012-07-06 08:54 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

+ 2009-07-14 02:34 . 2012-07-11 10:16 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

+ 2012-06-11 18:00 . 2012-06-11 18:00 20467712 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atioglxx.dll

+ 2012-06-11 18:29 . 2012-06-11 18:29 24826368 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atio6axx.dll

+ 2012-06-11 18:59 . 2012-06-11 18:59 10248192 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\atikmdag.sys

+ 2012-06-11 16:45 . 2012-06-11 16:45 15703040 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticaldd64.dll

+ 2012-06-11 16:40 . 2012-06-11 16:40 13277696 c:\windows\system32\DriverStore\FileRepository\c7142035.inf_amd64_neutral_5a58625592d83a31\B140419\aticaldd.dll

+ 2010-02-26 09:22 . 2012-07-12 01:03 24081248 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-645954481-4171391755-2920796181-1000-12288.dat

+ 2012-07-04 19:11 . 2012-07-04 19:11 16912384 c:\windows\Installer\190bf2.msi

+ 2012-07-04 18:57 . 2012-07-04 18:57 14294528 c:\windows\Installer\190bcf.msi

.

Link to post
Share on other sites

-- Snapshot reset to current date --

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]

@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-02 1242448]

"AlcoholAutomount"="c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]

"Xvid"="c:\program files (x86)\XviD\CheckUpdate.exe" [2011-01-17 8192]

"Snarl"="c:\program files (x86)\full phat\Snarl\snarl.exe" [2011-05-25 925696]

"Tonido"="c:\users\Hayden\AppData\Roaming\Tonido\launcher.exe" [2011-11-14 100864]

"MusicManager"="c:\users\Hayden\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [2012-06-01 13806592]

"GoToMeeting"="c:\program files (x86)\Citrix\GoToMeeting\952\g2mstart.exe" [2012-05-25 39816]

"Spotify Web Helper"="c:\users\Hayden\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-30 932528]

"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]

"GoogleChromeAutoLaunch_7BA29E3153B77E65C37077A2469120EB"="c:\users\Hayden\AppData\Local\Google\Chrome\Application\chrome.exe" [2012-07-10 1250328]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]

"AVG9_TRAY"="c:\progra~2\AVG\AVG9\avgtray.exe" [2012-01-26 2077536]

"VolPanel"="c:\program files (x86)\Creative\Volume Panel\VolPanlu.exe" [2008-08-06 233576]

"CTxfiHlp"="CTXFIHLP.EXE" [2009-07-14 24576]

"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]

"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]

"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]

"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]

"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2012-05-03 217256]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-04-04 462408]

"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-05-01 1895424]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]

.

c:\users\Hayden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

CurseClientStartup.ccip [2010-12-7 0]

Dropbox.lnk - c:\users\Hayden\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]

EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2012-6-13 1014112]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]

Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2011-8-21 102912]

Subsonic.lnk - c:\program files (x86)\Subsonic\subsonic-agent.exe [2011-12-6 206336]

UltraMon.lnk - c:\windows\Installer\{B49673F8-7AB6-4A14-8213-C8A7BE370010}\IcoUltraMon.ico [2010-8-23 29310]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

"HideShutdownScripts"= 0 (0x0)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"MaxRecentDocs"= 99 (0x63)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2011-09-10 18432]

R2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-04-02 90112]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [x]

R2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-02 67400]

R2 MSSQL$MSSQL;SQL Server (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\sqlservr.exe [2010-04-03 61913952]

R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]

R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2009-10-31 79360]

R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-31 79360]

R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-08 230488]

R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]

R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-08 95320]

R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [x]

R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-07 113120]

R3 MSSQLFDLauncher$MSSQL;SQL Full-text Filter Daemon Launcher (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\fdlauncher.exe [2010-04-03 32096]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]

R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2012-05-29 19952]

R3 SQLAgent$MSSQL;SQL Server Agent (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\SQLAGENT.EXE [2010-04-03 428384]

R3 SSMO3v2Filter;MMO3v2 Mouse;c:\windows\system32\drivers\MO3v2Driver.sys [2010-11-22 23040]

R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]

R3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM10864.sys [2010-08-13 1310720]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-10 1255736]

R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]

R3 WMSVC;Web Management Service;c:\windows\system32\inetsrv\wmsvc.exe [2009-07-14 10752]

R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]

R4 RsFx0150;RsFx0150 Driver;c:\windows\system32\DRIVERS\RsFx0150.sys [2010-04-03 313696]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

S0 AvgRkx64;avgrkx64.sys;c:\windows\System32\Drivers\avgrkx64.sys [2010-03-29 56008]

S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-12 503352]

S1 AvgLdx64;AVG AVI Loader Driver x64;c:\windows\System32\Drivers\avgldx64.sys [2010-06-22 269904]

S1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;c:\windows\System32\Drivers\avgmfx64.sys [2011-09-13 35664]

S1 AvgTdiA;AVG Network Redirector x64;c:\windows\System32\Drivers\avgtdia.sys [2011-05-06 317520]

S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]

S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]

S2 avg9emc;AVG E-mail Scanner;c:\program files (x86)\AVG\AVG9\avgemc.exe [2010-07-21 921952]

S2 avg9wd;AVG WatchDog;c:\program files (x86)\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]

S2 DeviceMonitorService;DeviceMonitorService;c:\program files (x86)\Motorola Media Link\Lite\NServiceEntry.exe [2012-06-05 87400]

S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2011-11-08 14216]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-04-04 654408]

S2 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-06-05 116632]

S2 MSOLAP$MSSQL;SQL Server Analysis Services (MSSQL);c:\program files\Microsoft SQL Server\MSAS10_50.MSSQL\OLAP\bin\msmdsrv.exe [2010-04-03 54568288]

S2 NitroDriverReadSpool2;NitroPDFDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Professional\7.0\NitroPDFDriverService2x64.exe [2012-06-25 216072]

S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\NLSSRV32.EXE [2012-06-25 69640]

S2 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2011-09-02 65657]

S2 ReportServer$MSSQL;SQL Server Reporting Services (MSSQL);c:\program files\Microsoft SQL Server\MSRS10_50.MSSQL\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2010-04-03 2175328]

S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2008-11-14 20512]

S2 WDDMService.exe;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-08-17 116224]

S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]

S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]

S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-08 230488]

S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]

S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-08 95320]

S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys [2010-05-22 66728]

S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-08 1612888]

S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2010-12-12 22408]

S3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys [2009-07-01 30728]

S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2010-12-12 16008]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-04-04 24904]

S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]

S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]

S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-09-28 395264]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

iissvcs REG_MULTI_SZ w3svc was

apphost REG_MULTI_SZ apphostsvc

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Contents of the 'Scheduled Tasks' folder

.

2012-07-11 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000Core.job

- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]

.

2012-07-12 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000UA.job

- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]

.

.

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 97792 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 97792 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 97792 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]

@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 97792 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-06-15 110360]

"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]

"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]

"Cm108Sound"="c:\windows\Syswow64\cm108.dll" [2010-10-13 8757248]

.

------- Supplementary Scan -------

.

uStart Page =

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local;192.168.*.*

IE: &Verzenden naar OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105

IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000

Trusted Zone: clonewarsadventures.com

Trusted Zone: freerealms.com

Trusted Zone: soe.com

Trusted Zone: sony.com

TCP: DhcpNameServer = 192.168.1.254

DPF: {EF0D1A14-1033-41A2-A589-240C01EDC078} - hxxp://dl.pplive.com/PluginSetup.cab

FF - ProfilePath - c:\users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\

.

- - - - ORPHANS REMOVED - - - -

.

WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)

.

.

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MsDepSvc]

"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]

@Denied: (2) (S-1-5-21-645954481-4171391755-2920796181-1000)

@Denied: (2) (LocalSystem)

"Progid"="ThunderbirdEML"

.

[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.VCard.1"

.

[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\SecuROM\License information*]

"datasecu"=hex:97,d2,c9,85,02,71,88,e1,fc,ae,42,fe,02,8d,8e,24,19,8e,34,38,98,

bf,29,19,59,bb,61,f1,77,18,e7,bc,4a,35,98,08,f1,6c,21,76,ba,c6,fb,cc,72,f4,\

"rkeysecu"=hex:79,fe,52,e1,00,f1,26,9b,6e,10,c9,f7,ce,d0,27,3d

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.10"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}]

@Denied: (A) (Everyone)

"Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane\0]

"Key"="ActionsPane"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files (x86)\Bonjour\mDNSResponder.exe

c:\xampp\filezillaftp\filezillaserver.exe

c:\program files (x86)\Windows Media Player\wmplayer.exe

c:\windows\SysWOW64\rundll32.exe

c:\users\Hayden\AppData\Roaming\Tonido\tonido.exe

c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

c:\program files (x86)\Motorola Mobility\MotoCast\MotoCast.exe

c:\program files (x86)\AVG\AVG9\avgtray.exe

c:\windows\SysWOW64\Ctxfihlp.exe

c:\windows\SysWOW64\CTXFISPI.EXE

c:\xampp\mysql\bin\mysqld.exe

c:\program files (x86)\full phat\Snarl\extensions\AudioMon\snarl-audiomon.exe

c:\program files (x86)\Citrix\GoToMeeting\952\g2mcomm.exe

c:\program files (x86)\Citrix\GoToMeeting\952\g2mlauncher.exe

c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe

c:\program files (x86)\AVG\AVG9\avgcsrvx.exe

c:\program files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe

c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDMovieViewer.exe

c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDWebCam.exe

c:\program files\Logitech Gaming Software\plugins\LCDAppletsMono-8.00.048\Applets\x86\LCDMedia.exe

c:\users\Hayden\Desktop\downloads\SirReal\LCDSirReal.exe

c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDYT.exe

c:\program files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe

c:\program files (x86)\HP\Digital Imaging\bin\hpqbam08.exe

c:\program files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe

c:\program files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe

.

**************************************************************************

.

Completion time: 2012-07-11 20:29:55 - machine was rebooted

ComboFix-quarantined-files.txt 2012-07-12 01:29

ComboFix2.txt 2012-07-08 00:33

.

Pre-Run: 88,333,967,360 bytes free

Post-Run: 88,599,154,688 bytes free

.

- - End Of File - - 01354FEA945C4CCE7AEAB1B72CAF7589

Link to post
Share on other sites

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

Folder::
c:\users\Hayden\AppData\Local\blekkotb_031

JavaClearCache::

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Link to post
Share on other sites

I'm not positive the script ran. I dragged it onto ComboFix, but then ran a ComboFix update. I assume ComboFix then ran with the script, but it may not have. Let me know.

ComboFix 12-07-13.03 - Hayden 07/13/2012 18:11:50.3.8 - x64

Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.12279.7511 [GMT -5:00]

Running from: c:\users\Hayden\Desktop\ComboFix.exe

Command switches used :: c:\users\Hayden\Desktop\CFScript.txt

AV: AVG Anti-Virus *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

SP: AVG Anti-Virus *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\Hayden\AppData\Local\blekkotb_031

c:\users\Hayden\AppData\Local\blekkotb_031\catalog.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711124102-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711124102-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711130019-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711130019-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711131001-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711131001-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711132048-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711132048-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711134018-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711134018-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711140044-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711140044-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711165450-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711165450-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711170034-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711170034-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711185041-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711185041-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190017-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190017-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190959-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190959-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711192046-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711192046-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711194008-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711194008-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711195104-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711195104-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711200047-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711200047-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711201027-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711201027-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202010-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202010-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202115-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202115-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711204041-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711204041-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711210013-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711210013-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711211057-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711211057-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711212040-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711212040-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711214104-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711214104-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711215200-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711215200-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711220038-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711220038-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711221122-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711221122-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711222104-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711222104-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224029-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224029-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224136-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224136-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711230007-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711230007-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711231158-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711231158-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711232038-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711232038-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234102-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234102-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234209-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234209-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712000034-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712000034-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712001223-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712001223-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712002102-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712002102-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004022-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004022-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004234-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004234-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712010106-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712010106-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712011255-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712011255-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712012031-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712012031-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014056-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014056-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014308-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014308-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712020035-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712020035-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712021328-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712021328-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712022103-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712022103-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024022-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024022-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024337-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024337-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712030102-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712030102-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712031357-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712031357-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712032029-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712032029-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712034050-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712034050-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712040020-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712040020-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712041417-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712041417-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712042048-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712042048-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044112-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044112-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044428-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044428-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712050050-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712050050-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712051448-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712051448-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712052016-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712052016-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054036-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054036-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054455-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054455-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712060012-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712060012-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712061518-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712061518-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064110-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064110-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064530-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064530-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712070045-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712070045-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712071547-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712071547-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072011-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072011-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072638-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072638-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074040-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074040-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074604-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074604-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712080053-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712080053-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712081701-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712081701-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712082019-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712082019-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712084108-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712084108-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712090033-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712090033-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712091748-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712091748-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712092106-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712092106-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094023-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094023-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094755-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094755-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712100102-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712100102-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712101811-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712101811-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712102025-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712102025-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104047-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104047-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104820-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104820-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712105917-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712105917-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712110028-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712110028-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712111846-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712111846-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712112059-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712112059-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712114015-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712114015-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712120049-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712120049-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712121902-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712121902-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712122011-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712122011-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712124034-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712124034-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712130110-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712130110-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712131928-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712131928-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712132038-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712132038-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712134108-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712134108-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712140050-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712140050-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712142013-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712142013-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712144040-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712144040-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712150122-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712150122-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712152041-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712152041-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712154107-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712154107-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712155049-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712155049-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712160040-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712160040-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712162113-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712162113-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712164037-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712164037-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712165131-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712165131-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712170118-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712170118-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712172149-f.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712174016-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712174016-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712175211-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712175211-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180051-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180051-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180310-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180310-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182024-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182024-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182235-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182235-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712183324-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712183324-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712184100-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712184100-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712185255-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712185255-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712190030-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712190030-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192114-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192114-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192325-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192325-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712194042-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712194042-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712195336-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712195336-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712200014-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712200014-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202053-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202053-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202409-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202409-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712204024-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712204024-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712210050-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712210050-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212015-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212015-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212438-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212438-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712214038-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712214038-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712215529-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712215529-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712220052-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712220052-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222104-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222104-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222625-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222625-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712224013-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712224013-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712225707-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712225707-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712230026-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712230026-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232040-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232040-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232806-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232806-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712234054-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712234054-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712235857-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712235857-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713000114-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713000114-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002032-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002032-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002135-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002135-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002239-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002239-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002343-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002343-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002447-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002447-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002552-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002552-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002700-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002700-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002804-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002804-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713153753-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713153753-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713160908-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713160908-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161042-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161042-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161324-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161324-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161515-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161515-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161643-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161643-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161907-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161907-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162036-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162036-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162217-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162217-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162826-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162826-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163034-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163034-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163413-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163413-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163606-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163606-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\temp.zip

c:\windows\isRS-000.tmp

.

.

((((((((((((((((((((((((( Files Created from 2012-06-13 to 2012-07-13 )))))))))))))))))))))))))))))))

.

.

2012-07-13 23:32 . 2012-07-13 23:33 -------- d-----w- c:\users\Hayden\AppData\Local\blekkotb_031

2012-07-13 23:27 . 2012-07-13 23:27 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp

2012-07-13 23:27 . 2012-07-13 23:27 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-07-13 23:27 . 2012-07-13 23:27 -------- d-----w- c:\users\Classic .NET AppPool\AppData\Local\temp

2012-07-12 18:10 . 2012-04-12 03:55 17936 ----a-w- c:\windows\system32\nitrolocalui2.dll

2012-07-12 18:10 . 2012-04-12 03:55 29712 ----a-w- c:\windows\system32\nitrolocalmon2.dll

2012-07-12 18:10 . 2012-07-12 18:10 -------- d-----w- c:\program files\Common Files\Nitro PDF

2012-07-12 18:10 . 2012-07-12 18:10 -------- d-----w- c:\program files (x86)\Common Files\Nitro PDF

2012-07-12 18:09 . 2012-07-12 18:10 -------- d-----w- c:\program files (x86)\Nitro PDF

2012-07-10 23:48 . 2012-07-10 23:48 -------- d-----w- c:\programdata\ATI

2012-07-10 23:47 . 2012-07-10 23:47 -------- d-----w- c:\program files (x86)\AMD APP

2012-07-10 23:00 . 2012-07-10 23:00 -------- d-----w- C:\_OTL

2012-07-09 22:27 . 2012-07-09 22:27 -------- d-----w- c:\program files (x86)\KeePass Password Safe 2

2012-07-07 22:36 . 2012-07-07 22:36 -------- d-----w- C:\TDSSKiller_Quarantine

2012-07-07 18:57 . 2012-07-07 18:57 -------- d-----w- c:\users\Hayden\AppData\Roaming\Malwarebytes

2012-07-07 18:56 . 2012-07-12 06:32 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-07-07 18:56 . 2012-07-07 18:56 -------- d-----w- c:\programdata\Malwarebytes

2012-07-07 18:56 . 2012-07-03 18:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-07-07 06:02 . 2012-07-07 06:02 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll

2012-07-07 06:02 . 2012-07-07 06:02 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll

2012-07-06 19:18 . 2012-07-11 00:43 -------- d-----w- C:\subsonic

2012-07-06 19:18 . 2012-07-06 19:18 -------- d-----w- c:\program files (x86)\Subsonic

2012-07-02 18:01 . 2012-07-02 18:01 -------- d-----w- c:\users\Hayden\.pdfsam

2012-07-02 16:17 . 2012-07-02 16:17 -------- d-----w- c:\program files (x86)\pdfsam

2012-07-02 16:07 . 2012-07-04 20:37 -------- d-----w- c:\users\Hayden\AppData\Roaming\ParmisPDF

2012-07-02 15:49 . 2012-07-12 18:13 -------- d-----w- c:\users\Hayden\AppData\Roaming\PrimoPDF

2012-07-02 15:48 . 2012-07-12 18:09 -------- d-----w- c:\users\Hayden\AppData\Roaming\OpenCandy

2012-07-02 15:48 . 2011-02-28 22:37 95008 ----a-w- c:\windows\system32\Primomonnt.dll

2012-07-02 05:32 . 2012-07-02 05:32 -------- d-----w- c:\program files (x86)\Maxis

2012-07-01 07:33 . 2012-07-01 07:33 -------- d-----w- c:\users\Hayden\AppData\Roaming\EAC

2012-07-01 07:33 . 2012-07-01 07:33 -------- d-----w- c:\program files (x86)\Exact Audio Copy

2012-07-01 07:32 . 2012-07-01 07:32 -------- d-----w- c:\programdata\Anti-phishing Domain Advisor

2012-06-27 22:19 . 2012-07-11 01:44 -------- d-----w- c:\users\Hayden\AppData\Roaming\Nitro PDF

2012-06-27 22:18 . 2012-07-02 15:51 -------- d-----w- c:\programdata\Nitro PDF

2012-06-27 19:50 . 2012-06-27 20:00 -------- d-----w- c:\users\Hayden\.cpan

2012-06-25 00:35 . 2012-06-25 00:35 -------- d-----w- c:\programdata\phpDesigner

2012-06-20 01:45 . 2012-06-20 01:45 -------- d-----w- c:\program files (x86)\Motorola Media Link

2012-06-14 01:07 . 2012-06-14 01:46 -------- d-----w- c:\program files (x86)\Ken Ward's Makeup

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-06-25 02:47 . 2012-06-25 02:47 69640 ----a-w- c:\windows\SysWow64\NLSSRV32.EXE

2012-06-18 08:12 . 2012-07-12 08:11 9013136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{75A75839-1E75-4ED3-A1C2-EDCBE53DD30D}\mpengine.dll

2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys

2012-06-11 18:50 . 2012-06-11 18:50 187392 ----a-w- c:\windows\system32\clinfo.exe

2012-06-11 18:50 . 2012-06-11 18:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll

2012-06-11 18:50 . 2012-06-11 18:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll

2012-06-11 18:50 . 2012-06-11 18:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll

2012-06-11 18:50 . 2012-06-11 18:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll

2012-06-11 18:50 . 2012-06-11 18:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll

2012-06-11 18:49 . 2012-06-11 18:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll

2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll

2012-06-11 18:29 . 2011-10-26 02:16 24826368 ----a-w- c:\windows\system32\atio6axx.dll

2012-06-11 18:00 . 2012-06-11 18:00 20467712 ----a-w- c:\windows\SysWow64\atioglxx.dll

2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe

2012-06-11 17:24 . 2011-12-06 03:17 924160 ----a-w- c:\windows\SysWow64\aticfx32.dll

2012-06-11 17:23 . 2011-10-26 02:04 1090560 ----a-w- c:\windows\system32\aticfx64.dll

2012-06-11 17:20 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll

2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe

2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe

2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll

2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll

2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll

2012-06-11 17:17 . 2012-06-11 17:17 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll

2012-06-11 17:16 . 2012-06-11 17:16 6301696 ----a-w- c:\windows\SysWow64\atidxx32.dll

2012-06-11 17:01 . 2012-06-11 17:01 6914560 ----a-w- c:\windows\system32\atidxx64.dll

2012-06-11 16:51 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll

2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll

2012-06-11 16:45 . 2012-06-11 16:45 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll

2012-06-11 16:45 . 2011-12-06 02:33 5480448 ----a-w- c:\windows\SysWow64\atiumdag.dll

2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll

2012-06-11 16:45 . 2012-06-11 16:45 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll

2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll

2012-06-11 16:43 . 2011-12-06 02:28 4729344 ----a-w- c:\windows\SysWow64\atiumdva.dll

2012-06-11 16:40 . 2012-06-11 16:40 13277696 ----a-w- c:\windows\SysWow64\aticaldd.dll

2012-06-11 16:36 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll

2012-06-11 16:27 . 2011-10-26 01:22 539136 ----a-w- c:\windows\system32\atiadlxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll

2012-06-11 16:26 . 2011-10-26 01:22 17920 ----a-w- c:\windows\system32\atig6pxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll

2012-06-11 16:26 . 2011-10-26 01:22 41984 ----a-w- c:\windows\system32\atig6txx.dll

2012-06-11 16:26 . 2012-06-11 16:26 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys

2012-06-11 16:25 . 2010-11-26 02:16 54784 ----a-w- c:\windows\system32\atiuxp64.dll

2012-06-11 16:25 . 2012-06-11 16:25 42496 ----a-w- c:\windows\SysWow64\atiuxpag.dll

2012-06-11 16:25 . 2012-06-11 16:25 45056 ----a-w- c:\windows\system32\atiu9p64.dll

2012-06-11 16:24 . 2010-11-26 02:15 32768 ----a-w- c:\windows\SysWow64\atiu9pag.dll

2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll

2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll

2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll

2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll

2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll

2012-05-31 17:25 . 2009-10-30 23:04 279656 ------w- c:\windows\system32\MpSigStub.exe

.

.

((((((((((((((((((((((((((((( SnapShot_2012-07-12_01.06.01 )))))))))))))))))))))))))))))))))))))))))

.

+ 2012-07-13 23:33 . 2012-07-13 23:33 27585 c:\windows\temp\e4jE4B3.tmp_dir\i4jdel.exe

+ 2009-10-30 23:27 . 2012-07-13 23:36 93700 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-07-13 23:36 31782 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2009-10-30 22:49 . 2012-07-13 23:36 15994 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-645954481-4171391755-2920796181-1000_UserData.bin

+ 2012-07-12 18:10 . 2012-04-12 03:55 83472 c:\windows\system32\spool\drivers\x64\NitroReaderUI2.dll

+ 2012-07-12 18:10 . 2012-04-12 03:55 45584 c:\windows\system32\spool\drivers\x64\NitroReaderGraphics2.dll

+ 2009-10-31 00:26 . 2012-07-13 09:10 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-31 00:26 . 2012-07-11 00:47 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2012-07-10 23:27 . 2012-07-13 09:10 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2012-07-10 23:27 . 2012-07-11 00:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-07-14 04:54 . 2012-07-13 09:10 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-07-14 04:54 . 2012-07-11 00:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-10-30 22:48 . 2012-07-13 23:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-13 23:35 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-13 23:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-13 23:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-13 23:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2012-07-12 01:04 . 2012-07-12 01:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-07-13 23:30 . 2012-07-13 23:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-07-13 23:30 . 2012-07-13 23:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2012-07-12 01:04 . 2012-07-12 01:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2012-07-02 15:48 . 2011-02-28 22:37 738080 c:\windows\system32\spool\drivers\x64\3\pscript5.dll

+ 2012-07-02 15:48 . 2011-02-28 22:37 241952 c:\windows\system32\spool\drivers\x64\3\ps5ui.dll

+ 2009-07-14 05:01 . 2012-07-13 23:28 515388 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2009-07-14 05:01 . 2012-07-12 01:02 515388 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2010-01-23 09:16 . 2012-07-12 01:02 1350152 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat

+ 2010-01-23 09:16 . 2012-07-13 23:28 1350152 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat

+ 2009-07-14 02:34 . 2012-07-12 04:38 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

- 2009-07-14 02:34 . 2012-07-11 10:16 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

+ 2010-02-26 09:22 . 2012-07-13 23:28 24521432 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-645954481-4171391755-2920796181-1000-12288.dat

+ 2012-04-30 21:43 . 2012-04-30 21:43 45831680 c:\windows\Installer\27a2bc1.msi

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]

@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-02 1242448]

"AlcoholAutomount"="c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]

"Xvid"="c:\program files (x86)\XviD\CheckUpdate.exe" [2011-01-17 8192]

"Snarl"="c:\program files (x86)\full phat\Snarl\snarl.exe" [2011-05-25 925696]

"Tonido"="c:\users\Hayden\AppData\Roaming\Tonido\launcher.exe" [2011-11-14 100864]

"MusicManager"="c:\users\Hayden\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [2012-06-01 13806592]

"GoToMeeting"="c:\program files (x86)\Citrix\GoToMeeting\952\g2mstart.exe" [2012-05-25 39816]

"Spotify Web Helper"="c:\users\Hayden\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-30 932528]

"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]

"GoogleChromeAutoLaunch_7BA29E3153B77E65C37077A2469120EB"="c:\users\Hayden\AppData\Local\Google\Chrome\Application\chrome.exe" [2012-07-10 1250328]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]

"AVG9_TRAY"="c:\progra~2\AVG\AVG9\avgtray.exe" [2012-01-26 2077536]

"VolPanel"="c:\program files (x86)\Creative\Volume Panel\VolPanlu.exe" [2008-08-06 233576]

"CTxfiHlp"="CTXFIHLP.EXE" [2009-07-14 24576]

"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]

"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]

"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]

"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]

"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2012-05-03 217256]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]

"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-05-01 1895424]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]

.

c:\users\Hayden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

CurseClientStartup.ccip [2010-12-7 0]

Dropbox.lnk - c:\users\Hayden\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]

EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2012-6-13 1014112]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]

Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2011-8-21 102912]

Subsonic.lnk - c:\program files (x86)\Subsonic\subsonic-agent.exe [2011-12-6 206336]

UltraMon.lnk - c:\windows\Installer\{B49673F8-7AB6-4A14-8213-C8A7BE370010}\IcoUltraMon.ico [2010-8-23 29310]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

"HideShutdownScripts"= 0 (0x0)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"MaxRecentDocs"= 99 (0x63)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2011-09-10 18432]

R2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-04-02 90112]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [x]

R2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-02 67400]

R2 MSSQL$MSSQL;SQL Server (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\sqlservr.exe [2010-04-03 61913952]

R2 ReportServer$MSSQL;SQL Server Reporting Services (MSSQL);c:\program files\Microsoft SQL Server\MSRS10_50.MSSQL\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2010-04-03 2175328]

R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]

R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2009-10-31 79360]

R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-31 79360]

R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-08 230488]

R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]

R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-08 95320]

R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [x]

R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-07 113120]

R3 MSSQLFDLauncher$MSSQL;SQL Full-text Filter Daemon Launcher (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\fdlauncher.exe [2010-04-03 32096]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]

R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2012-05-29 19952]

R3 SQLAgent$MSSQL;SQL Server Agent (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\SQLAGENT.EXE [2010-04-03 428384]

R3 SSMO3v2Filter;MMO3v2 Mouse;c:\windows\system32\drivers\MO3v2Driver.sys [2010-11-22 23040]

R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]

R3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM10864.sys [2010-08-13 1310720]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-10 1255736]

R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]

R3 WMSVC;Web Management Service;c:\windows\system32\inetsrv\wmsvc.exe [2009-07-14 10752]

R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]

R4 RsFx0150;RsFx0150 Driver;c:\windows\system32\DRIVERS\RsFx0150.sys [2010-04-03 313696]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

S0 AvgRkx64;avgrkx64.sys;c:\windows\System32\Drivers\avgrkx64.sys [2010-03-29 56008]

S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-12 503352]

S1 AvgLdx64;AVG AVI Loader Driver x64;c:\windows\System32\Drivers\avgldx64.sys [2010-06-22 269904]

S1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;c:\windows\System32\Drivers\avgmfx64.sys [2011-09-13 35664]

S1 AvgTdiA;AVG Network Redirector x64;c:\windows\System32\Drivers\avgtdia.sys [2011-05-06 317520]

S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]

S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]

S2 avg9emc;AVG E-mail Scanner;c:\program files (x86)\AVG\AVG9\avgemc.exe [2010-07-21 921952]

S2 avg9wd;AVG WatchDog;c:\program files (x86)\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]

S2 DeviceMonitorService;DeviceMonitorService;c:\program files (x86)\Motorola Media Link\Lite\NServiceEntry.exe [2012-06-05 87400]

S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2011-11-08 14216]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]

S2 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-06-05 116632]

S2 MSOLAP$MSSQL;SQL Server Analysis Services (MSSQL);c:\program files\Microsoft SQL Server\MSAS10_50.MSSQL\OLAP\bin\msmdsrv.exe [2010-04-03 54568288]

S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2012-04-12 204304]

S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\NLSSRV32.EXE [2012-06-25 69640]

S2 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2011-09-02 65657]

S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2008-11-14 20512]

S2 WDDMService.exe;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-08-17 116224]

S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]

S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]

S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-08 230488]

S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]

S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-08 95320]

S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys [2010-05-22 66728]

S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-08 1612888]

S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2010-12-12 22408]

S3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys [2009-07-01 30728]

S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2010-12-12 16008]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]

S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]

S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]

S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-09-28 395264]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

iissvcs REG_MULTI_SZ w3svc was

apphost REG_MULTI_SZ apphostsvc

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Contents of the 'Scheduled Tasks' folder

.

2012-07-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000Core.job

- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]

.

2012-07-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000UA.job

- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]

.

.

Link to post
Share on other sites

<p> </p>

<div>--------- X64 Entries -----------</div>

<div>.</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]</div>

<div>@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space:pre"> </span>97792<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]</div>

<div>@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space:pre"> </span>97792<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]</div>

<div>@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space:pre"> </span>97792<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]</div>

<div>@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space:pre"> </span>97792<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]</div>

<div>"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-06-15 110360]</div>

<div>"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]</div>

<div>"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]</div>

<div>"Cm108Sound"="c:\windows\Syswow64\cm108.dll" [2010-10-13 8757248]</div>

<div>.</div>

<div>------- Supplementary Scan -------</div>

<div>.</div>

<div>uStart Page = </div>

<div>mLocal Page = c:\windows\SysWOW64\blank.htm</div>

<div>uInternet Settings,ProxyOverride = *.local;192.168.*.*</div>

<div>IE: &Verzenden naar OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105</div>

<div>IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204</div>

<div>IE: E&xporteren naar Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000</div>

<div>Trusted Zone: clonewarsadventures.com</div>

<div>Trusted Zone: freerealms.com</div>

<div>Trusted Zone: soe.com</div>

<div>Trusted Zone: sony.com</div>

<div>TCP: DhcpNameServer = 192.168.1.254</div>

<div>DPF: {EF0D1A14-1033-41A2-A589-240C01EDC078} - hxxp://dl.pplive.com/PluginSetup.cab</div>

<div>FF - ProfilePath - c:\users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\</div>

<div>.</div>

<div>- - - - ORPHANS REMOVED - - - -</div>

<div>.</div>

<div>WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)</div>

<div>.</div>

<div>.</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MsDepSvc]</div>

<div>"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"</div>

<div>.</div>

<div>--------------------- LOCKED REGISTRY KEYS ---------------------</div>

<div>.</div>

<div>[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]</div>

<div>@Denied: (2) (S-1-5-21-645954481-4171391755-2920796181-1000)</div>

<div>@Denied: (2) (LocalSystem)</div>

<div>"Progid"="ThunderbirdEML"</div>

<div>.</div>

<div>[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]</div>

<div>@Denied: (2) (LocalSystem)</div>

<div>"Progid"="WindowsLiveMail.VCard.1"</div>

<div>.</div>

<div>[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\SecuROM\License information*]</div>

<div>"datasecu"=hex:97,d2,c9,85,02,71,88,e1,fc,ae,42,fe,02,8d,8e,24,19,8e,34,38,98,</div>

<div>   bf,29,19,59,bb,61,f1,77,18,e7,bc,4a,35,98,08,f1,6c,21,76,ba,c6,fb,cc,72,f4,\</div>

<div>"rkeysecu"=hex:79,fe,52,e1,00,f1,26,9b,6e,10,c9,f7,ce,d0,27,3d</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]</div>

<div>@Denied: (A 2) (Everyone)</div>

<div>@="FlashBroker"</div>

<div>"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe,-101"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]</div>

<div>"Enabled"=dword:00000001</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]</div>

<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]</div>

<div>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]</div>

<div>@Denied: (A 2) (Everyone)</div>

<div>@="Shockwave Flash Object"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]</div>

<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"</div>

<div>"ThreadingModel"="Apartment"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]</div>

<div>@="0"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]</div>

<div>@="ShockwaveFlash.ShockwaveFlash.10"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]</div>

<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]</div>

<div>@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]</div>

<div>@="1.0"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]</div>

<div>@="ShockwaveFlash.ShockwaveFlash"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]</div>

<div>@Denied: (A 2) (Everyone)</div>

<div>@="Macromedia Flash Factory Object"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]</div>

<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"</div>

<div>"ThreadingModel"="Apartment"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]</div>

<div>@="FlashFactory.FlashFactory.1"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]</div>

<div>@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]</div>

<div>@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]</div>

<div>@="1.0"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]</div>

<div>@="FlashFactory.FlashFactory"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]</div>

<div>@Denied: (A 2) (Everyone)</div>

<div>@="IFlashBroker4"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]</div>

<div>@="{00020424-0000-0000-C000-000000000046}"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]</div>

<div>@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"</div>

<div>"Version"="1.0"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]</div>

<div>@Denied: (A) (Everyone)</div>

<div>"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}]</div>

<div>@Denied: (A) (Everyone)</div>

<div>"Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane]</div>

<div>@Denied: (A) (Everyone)</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane\0]</div>

<div>"Key"="ActionsPane"</div>

<div>"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]</div>

<div>@Denied: (A) (Everyone)</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]</div>

<div>"Key"="ActionsPane3"</div>

<div>"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]</div>

<div>@Denied: (Full) (Everyone)</div>

<div>.</div>

<div>------------------------ Other Running Processes ------------------------</div>

<div>.</div>

<div>c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe</div>

<div>c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe</div>

<div>c:\program files (x86)\Bonjour\mDNSResponder.exe</div>

<div>c:\xampp\filezillaftp\filezillaserver.exe</div>

<div>c:\program files (x86)\Windows Media Player\wmplayer.exe</div>

<div>c:\windows\SysWOW64\rundll32.exe</div>

<div>c:\users\Hayden\AppData\Roaming\Tonido\tonido.exe</div>

<div>c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe</div>

<div>c:\program files (x86)\Motorola Mobility\MotoCast\MotoCast.exe</div>

<div>c:\program files (x86)\AVG\AVG9\avgtray.exe</div>

<div>c:\windows\SysWOW64\Ctxfihlp.exe</div>

<div>c:\windows\SysWOW64\CTXFISPI.EXE</div>

<div>c:\xampp\mysql\bin\mysqld.exe</div>

<div>c:\program files (x86)\Citrix\GoToMeeting\952\g2mcomm.exe</div>

<div>c:\program files (x86)\full phat\Snarl\extensions\AudioMon\snarl-audiomon.exe</div>

<div>c:\program files (x86)\Citrix\GoToMeeting\952\g2mlauncher.exe</div>

<div>c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe</div>

<div>c:\program files (x86)\AVG\AVG9\avgcsrvx.exe</div>

<div>c:\program files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe</div>

<div>c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDMovieViewer.exe</div>

<div>c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDWebCam.exe</div>

<div>c:\program files\Logitech Gaming Software\plugins\LCDAppletsMono-8.00.048\Applets\x86\LCDMedia.exe</div>

<div>c:\users\Hayden\Desktop\downloads\SirReal\LCDSirReal.exe</div>

<div>c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDYT.exe</div>

<div>c:\program files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe</div>

<div>c:\program files (x86)\HP\Digital Imaging\bin\hpqbam08.exe</div>

<div>c:\program files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe</div>

<div>c:\program files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe</div>

<div>.</div>

<div>**************************************************************************</div>

<div>.</div>

<div>Completion time: 2012-07-13  18:57:19 - machine was rebooted</div>

<div>ComboFix-quarantined-files.txt  2012-07-13 23:57</div>

<div>ComboFix2.txt  2012-07-12 01:30</div>

<div>ComboFix3.txt  2012-07-08 00:33</div>

<div>.</div>

<div>Pre-Run: 96,251,113,472 bytes free</div>

<div>Post-Run: 96,319,385,600 bytes free</div>

<div>.</div>

<div>- - End Of File - - 806BEEB66FCDFB4B1CADDE76F1176FB8</div>

<div> </div>

Link to post
Share on other sites

<p>Don't know what happened there... I copied and pasted that from the text file that CF made. So trying again, nothing changed, not positive the script ran because ComboFix updated beforehand. But here's the report in two parts without HTML:</p>

<p> </p>

<p> </p>

<div>ComboFix 12-07-13.03 - Hayden 07/13/2012  18:11:50.3.8 - x64</div>

<div>Microsoft Windows 7 Professional   6.1.7600.0.1252.1.1033.18.12279.7511 [GMT -5:00]</div>

<div>Running from: c:\users\Hayden\Desktop\ComboFix.exe</div>

<div>Command switches used :: c:\users\Hayden\Desktop\CFScript.txt</div>

<div>AV: AVG Anti-Virus *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}</div>

<div>SP: AVG Anti-Virus *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}</div>

<div>SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}</div>

<div>.</div>

<div>.</div>

<div>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>.</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\catalog.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711124102-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711124102-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711130019-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711130019-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711131001-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711131001-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711132048-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711132048-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711134018-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711134018-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711140044-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711140044-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711165450-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711165450-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711170034-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711170034-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711185041-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711185041-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190017-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190017-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190959-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190959-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711192046-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711192046-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711194008-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711194008-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711195104-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711195104-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711200047-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711200047-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711201027-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711201027-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202010-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202010-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202115-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202115-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711204041-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711204041-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711210013-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711210013-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711211057-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711211057-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711212040-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711212040-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711214104-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711214104-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711215200-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711215200-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711220038-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711220038-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711221122-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711221122-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711222104-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711222104-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224029-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224029-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224136-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224136-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711230007-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711230007-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711231158-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711231158-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711232038-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711232038-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234102-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234102-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234209-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234209-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712000034-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712000034-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712001223-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712001223-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712002102-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712002102-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004022-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004022-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004234-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004234-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712010106-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712010106-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712011255-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712011255-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712012031-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712012031-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014056-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014056-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014308-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014308-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712020035-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712020035-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712021328-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712021328-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712022103-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712022103-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024022-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024022-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024337-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024337-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712030102-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712030102-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712031357-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712031357-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712032029-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712032029-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712034050-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712034050-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712040020-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712040020-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712041417-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712041417-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712042048-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712042048-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044112-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044112-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044428-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044428-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712050050-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712050050-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712051448-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712051448-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712052016-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712052016-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054036-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054036-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054455-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054455-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712060012-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712060012-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712061518-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712061518-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064110-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064110-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064530-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064530-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712070045-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712070045-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712071547-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712071547-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072011-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072011-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072638-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072638-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074040-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074040-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074604-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074604-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712080053-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712080053-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712081701-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712081701-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712082019-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712082019-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712084108-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712084108-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712090033-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712090033-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712091748-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712091748-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712092106-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712092106-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094023-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094023-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094755-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094755-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712100102-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712100102-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712101811-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712101811-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712102025-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712102025-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104047-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104047-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104820-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104820-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712105917-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712105917-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712110028-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712110028-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712111846-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712111846-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712112059-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712112059-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712114015-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712114015-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712120049-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712120049-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712121902-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712121902-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712122011-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712122011-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712124034-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712124034-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712130110-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712130110-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712131928-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712131928-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712132038-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712132038-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712134108-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712134108-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712140050-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712140050-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712142013-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712142013-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712144040-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712144040-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712150122-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712150122-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712152041-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712152041-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712154107-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712154107-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712155049-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712155049-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712160040-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712160040-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712162113-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712162113-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712164037-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712164037-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712165131-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712165131-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712170118-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712170118-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712172149-f.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712174016-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712174016-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712175211-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712175211-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180051-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180051-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180310-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180310-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182024-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182024-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182235-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182235-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712183324-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712183324-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712184100-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712184100-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712185255-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712185255-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712190030-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712190030-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192114-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192114-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192325-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192325-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712194042-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712194042-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712195336-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712195336-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712200014-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712200014-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202053-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202053-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202409-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202409-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712204024-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712204024-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712210050-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712210050-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212015-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212015-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212438-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212438-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712214038-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712214038-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712215529-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712215529-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712220052-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712220052-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222104-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222104-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222625-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222625-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712224013-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712224013-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712225707-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712225707-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712230026-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712230026-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232040-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232040-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232806-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232806-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712234054-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712234054-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712235857-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712235857-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713000114-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713000114-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002032-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002032-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002135-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002135-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002239-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002239-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002343-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002343-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002447-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002447-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002552-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002552-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002700-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002700-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002804-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002804-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713153753-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713153753-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713160908-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713160908-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161042-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161042-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161324-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161324-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161515-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161515-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161643-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161643-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161907-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161907-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162036-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162036-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162217-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162217-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162826-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162826-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163034-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163034-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163413-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163413-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163606-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163606-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\temp.zip</div>

<div>c:\windows\isRS-000.tmp</div>

<div>.</div>

<div>.</div>

<div>(((((((((((((((((((((((((   Files Created from 2012-06-13 to 2012-07-13  )))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>.</div>

<div>2012-07-13 23:32 . 2012-07-13 23:33<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Local\blekkotb_031</div>

<div>2012-07-13 23:27 . 2012-07-13 23:27<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\LogMeInRemoteUser\AppData\Local\temp</div>

<div>2012-07-13 23:27 . 2012-07-13 23:27<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Default\AppData\Local\temp</div>

<div>2012-07-13 23:27 . 2012-07-13 23:27<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Classic .NET AppPool\AppData\Local\temp</div>

<div>2012-07-12 18:10 . 2012-04-12 03:55<span class="Apple-tab-span" style="white-space:pre"> </span>17936<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\nitrolocalui2.dll</div>

<div>2012-07-12 18:10 . 2012-04-12 03:55<span class="Apple-tab-span" style="white-space:pre"> </span>29712<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\nitrolocalmon2.dll</div>

<div>2012-07-12 18:10 . 2012-07-12 18:10<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files\Common Files\Nitro PDF</div>

<div>2012-07-12 18:10 . 2012-07-12 18:10<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Common Files\Nitro PDF</div>

<div>2012-07-12 18:09 . 2012-07-12 18:10<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Nitro PDF</div>

<div>2012-07-10 23:48 . 2012-07-10 23:48<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\programdata\ATI</div>

<div>2012-07-10 23:47 . 2012-07-10 23:47<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\AMD APP</div>

<div>2012-07-10 23:00 . 2012-07-10 23:00<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>C:\_OTL</div>

<div>2012-07-09 22:27 . 2012-07-09 22:27<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\KeePass Password Safe 2</div>

<div>2012-07-07 22:36 . 2012-07-07 22:36<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>C:\TDSSKiller_Quarantine</div>

<div>2012-07-07 18:57 . 2012-07-07 18:57<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Malwarebytes</div>

<div>2012-07-07 18:56 . 2012-07-12 06:32<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Malwarebytes' Anti-Malware</div>

<div>2012-07-07 18:56 . 2012-07-07 18:56<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\programdata\Malwarebytes</div>

<div>2012-07-07 18:56 . 2012-07-03 18:46<span class="Apple-tab-span" style="white-space:pre"> </span>24904<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\drivers\mbam.sys</div>

<div>2012-07-07 06:02 . 2012-07-07 06:02<span class="Apple-tab-span" style="white-space:pre"> </span>770384<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Mozilla Firefox\msvcr100.dll</div>

<div>2012-07-07 06:02 . 2012-07-07 06:02<span class="Apple-tab-span" style="white-space:pre"> </span>421200<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Mozilla Firefox\msvcp100.dll</div>

<div>2012-07-06 19:18 . 2012-07-11 00:43<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>C:\subsonic</div>

<div>2012-07-06 19:18 . 2012-07-06 19:18<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Subsonic</div>

<div>2012-07-02 18:01 . 2012-07-02 18:01<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\.pdfsam</div>

<div>2012-07-02 16:17 . 2012-07-02 16:17<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\pdfsam</div>

<div>2012-07-02 16:07 . 2012-07-04 20:37<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\ParmisPDF</div>

<div>2012-07-02 15:49 . 2012-07-12 18:13<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\PrimoPDF</div>

<div>2012-07-02 15:48 . 2012-07-12 18:09<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\OpenCandy</div>

<div>2012-07-02 15:48 . 2011-02-28 22:37<span class="Apple-tab-span" style="white-space:pre"> </span>95008<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\Primomonnt.dll</div>

<div>2012-07-02 05:32 . 2012-07-02 05:32<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Maxis</div>

<div>2012-07-01 07:33 . 2012-07-01 07:33<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\EAC</div>

<div>2012-07-01 07:33 . 2012-07-01 07:33<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Exact Audio Copy</div>

<div>2012-07-01 07:32 . 2012-07-01 07:32<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\programdata\Anti-phishing Domain Advisor</div>

<div>2012-06-27 22:19 . 2012-07-11 01:44<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Nitro PDF</div>

<div>2012-06-27 22:18 . 2012-07-02 15:51<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\programdata\Nitro PDF</div>

<div>2012-06-27 19:50 . 2012-06-27 20:00<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\.cpan</div>

<div>2012-06-25 00:35 . 2012-06-25 00:35<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\programdata\phpDesigner</div>

<div>2012-06-20 01:45 . 2012-06-20 01:45<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Motorola Media Link</div>

<div>2012-06-14 01:07 . 2012-06-14 01:46<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Ken Ward's Makeup</div>

<div>.</div>

<div>.</div>

<div>.</div>

<div>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>2012-06-25 02:47 . 2012-06-25 02:47<span class="Apple-tab-span" style="white-space:pre"> </span>69640<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\NLSSRV32.EXE</div>

<div>2012-06-18 08:12 . 2012-07-12 08:11<span class="Apple-tab-span" style="white-space:pre"> </span>9013136<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\programdata\Microsoft\Windows Defender\Definition Updates\{75A75839-1E75-4ED3-A1C2-EDCBE53DD30D}\mpengine.dll</div>

<div>2012-06-11 18:59 . 2012-06-11 18:59<span class="Apple-tab-span" style="white-space:pre"> </span>10248192<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\drivers\atikmdag.sys</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50<span class="Apple-tab-span" style="white-space:pre"> </span>187392<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\clinfo.exe</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50<span class="Apple-tab-span" style="white-space:pre"> </span>75264<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\OpenVideo64.dll</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50<span class="Apple-tab-span" style="white-space:pre"> </span>65024<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\OpenVideo.dll</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50<span class="Apple-tab-span" style="white-space:pre"> </span>63488<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\OVDecode64.dll</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50<span class="Apple-tab-span" style="white-space:pre"> </span>56320<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\OVDecode.dll</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50<span class="Apple-tab-span" style="white-space:pre"> </span>16457728<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\amdocl64.dll</div>

<div>2012-06-11 18:49 . 2012-06-11 18:49<span class="Apple-tab-span" style="white-space:pre"> </span>13008896<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\amdocl.dll</div>

<div>2012-06-11 18:35 . 2012-06-11 18:35<span class="Apple-tab-span" style="white-space:pre"> </span>70144<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\coinst_8.98.dll</div>

<div>2012-06-11 18:29 . 2011-10-26 02:16<span class="Apple-tab-span" style="white-space:pre"> </span>24826368<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atio6axx.dll</div>

<div>2012-06-11 18:00 . 2012-06-11 18:00<span class="Apple-tab-span" style="white-space:pre"> </span>20467712<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atioglxx.dll</div>

<div>2012-06-11 17:25 . 2012-06-11 17:25<span class="Apple-tab-span" style="white-space:pre"> </span>163840<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiapfxx.exe</div>

<div>2012-06-11 17:24 . 2011-12-06 03:17<span class="Apple-tab-span" style="white-space:pre"> </span>924160<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\aticfx32.dll</div>

<div>2012-06-11 17:23 . 2011-10-26 02:04<span class="Apple-tab-span" style="white-space:pre"> </span>1090560<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\aticfx64.dll</div>

<div>2012-06-11 17:20 . 2012-06-11 17:20<span class="Apple-tab-span" style="white-space:pre"> </span>442368<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\ATIDEMGX.dll</div>

<div>2012-06-11 17:19 . 2012-06-11 17:19<span class="Apple-tab-span" style="white-space:pre"> </span>532992<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atieclxx.exe</div>

<div>2012-06-11 17:19 . 2012-06-11 17:19<span class="Apple-tab-span" style="white-space:pre"> </span>239616<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiesrxx.exe</div>

<div>2012-06-11 17:17 . 2012-06-11 17:17<span class="Apple-tab-span" style="white-space:pre"> </span>120320<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atitmm64.dll</div>

<div>2012-06-11 17:17 . 2012-06-11 17:17<span class="Apple-tab-span" style="white-space:pre"> </span>21504<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atimuixx.dll</div>

<div>2012-06-11 17:17 . 2012-06-11 17:17<span class="Apple-tab-span" style="white-space:pre"> </span>59392<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiedu64.dll</div>

<div>2012-06-11 17:17 . 2012-06-11 17:17<span class="Apple-tab-span" style="white-space:pre"> </span>43520<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\ati2edxx.dll</div>

<div>2012-06-11 17:16 . 2012-06-11 17:16<span class="Apple-tab-span" style="white-space:pre"> </span>6301696<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atidxx32.dll</div>

<div>2012-06-11 17:01 . 2012-06-11 17:01<span class="Apple-tab-span" style="white-space:pre"> </span>6914560<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atidxx64.dll</div>

<div>2012-06-11 16:51 . 2012-06-11 16:51<span class="Apple-tab-span" style="white-space:pre"> </span>4246528<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiumd6a.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45<span class="Apple-tab-span" style="white-space:pre"> </span>51200<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\aticalrt64.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45<span class="Apple-tab-span" style="white-space:pre"> </span>46080<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\aticalrt.dll</div>

<div>2012-06-11 16:45 . 2011-12-06 02:33<span class="Apple-tab-span" style="white-space:pre"> </span>5480448<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atiumdag.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45<span class="Apple-tab-span" style="white-space:pre"> </span>44544<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\aticalcl64.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45<span class="Apple-tab-span" style="white-space:pre"> </span>44032<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\aticalcl.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45<span class="Apple-tab-span" style="white-space:pre"> </span>15703040<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\aticaldd64.dll</div>

<div>2012-06-11 16:43 . 2011-12-06 02:28<span class="Apple-tab-span" style="white-space:pre"> </span>4729344<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atiumdva.dll</div>

<div>2012-06-11 16:40 . 2012-06-11 16:40<span class="Apple-tab-span" style="white-space:pre"> </span>13277696<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\aticaldd.dll</div>

<div>2012-06-11 16:36 . 2012-06-11 16:36<span class="Apple-tab-span" style="white-space:pre"> </span>6605824<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiumd64.dll</div>

<div>2012-06-11 16:27 . 2011-10-26 01:22<span class="Apple-tab-span" style="white-space:pre"> </span>539136<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiadlxx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26<span class="Apple-tab-span" style="white-space:pre"> </span>368640<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atiadlxy.dll</div>

<div>2012-06-11 16:26 . 2011-10-26 01:22<span class="Apple-tab-span" style="white-space:pre"> </span>17920<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atig6pxx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26<span class="Apple-tab-span" style="white-space:pre"> </span>14848<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atiglpxx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26<span class="Apple-tab-span" style="white-space:pre"> </span>14848<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiglpxx.dll</div>

<div>2012-06-11 16:26 . 2011-10-26 01:22<span class="Apple-tab-span" style="white-space:pre"> </span>41984<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atig6txx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26<span class="Apple-tab-span" style="white-space:pre"> </span>33280<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atigktxx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26<span class="Apple-tab-span" style="white-space:pre"> </span>367616<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\drivers\atikmpag.sys</div>

<div>2012-06-11 16:25 . 2010-11-26 02:16<span class="Apple-tab-span" style="white-space:pre"> </span>54784<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiuxp64.dll</div>

<div>2012-06-11 16:25 . 2012-06-11 16:25<span class="Apple-tab-span" style="white-space:pre"> </span>42496<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atiuxpag.dll</div>

<div>2012-06-11 16:25 . 2012-06-11 16:25<span class="Apple-tab-span" style="white-space:pre"> </span>45056<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiu9p64.dll</div>

<div>2012-06-11 16:24 . 2010-11-26 02:15<span class="Apple-tab-span" style="white-space:pre"> </span>32768<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atiu9pag.dll</div>

<div>2012-06-11 16:24 . 2012-06-11 16:24<span class="Apple-tab-span" style="white-space:pre"> </span>53248<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\drivers\ati2erec.dll</div>

<div>2012-06-11 16:23 . 2012-06-11 16:23<span class="Apple-tab-span" style="white-space:pre"> </span>56320<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atimpc64.dll</div>

<div>2012-06-11 16:23 . 2012-06-11 16:23<span class="Apple-tab-span" style="white-space:pre"> </span>56320<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\amdpcom64.dll</div>

<div>2012-06-11 16:23 . 2012-06-11 16:23<span class="Apple-tab-span" style="white-space:pre"> </span>56832<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atimpc32.dll</div>

<div>2012-06-11 16:23 . 2012-06-11 16:23<span class="Apple-tab-span" style="white-space:pre"> </span>56832<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\amdpcom32.dll</div>

<div>2012-05-31 17:25 . 2009-10-30 23:04<span class="Apple-tab-span" style="white-space:pre"> </span>279656<span class="Apple-tab-span" style="white-space:pre"> </span>------w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\MpSigStub.exe</div>

<div>.</div>

<div>.</div>

<div>(((((((((((((((((((((((((((((   SnapShot_2012-07-12_01.06.01   )))))))))))))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>+ 2012-07-13 23:33 . 2012-07-13 23:33<span class="Apple-tab-span" style="white-space:pre"> </span>27585              c:\windows\temp\e4jE4B3.tmp_dir\i4jdel.exe</div>

<div>+ 2009-10-30 23:27 . 2012-07-13 23:36<span class="Apple-tab-span" style="white-space:pre"> </span>93700              c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin</div>

<div>+ 2009-07-14 05:10 . 2012-07-13 23:36<span class="Apple-tab-span" style="white-space:pre"> </span>31782              c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin</div>

<div>+ 2009-10-30 22:49 . 2012-07-13 23:36<span class="Apple-tab-span" style="white-space:pre"> </span>15994              c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-645954481-4171391755-2920796181-1000_UserData.bin</div>

<div>+ 2012-07-12 18:10 . 2012-04-12 03:55<span class="Apple-tab-span" style="white-space:pre"> </span>83472              c:\windows\system32\spool\drivers\x64\NitroReaderUI2.dll</div>

<div>+ 2012-07-12 18:10 . 2012-04-12 03:55<span class="Apple-tab-span" style="white-space:pre"> </span>45584              c:\windows\system32\spool\drivers\x64\NitroReaderGraphics2.dll</div>

<div>+ 2009-10-31 00:26 . 2012-07-13 09:10<span class="Apple-tab-span" style="white-space:pre"> </span>49152              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>- 2009-10-31 00:26 . 2012-07-11 00:47<span class="Apple-tab-span" style="white-space:pre"> </span>49152              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>+ 2012-07-10 23:27 . 2012-07-13 09:10<span class="Apple-tab-span" style="white-space:pre"> </span>32768              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat</div>

<div>- 2012-07-10 23:27 . 2012-07-11 00:47<span class="Apple-tab-span" style="white-space:pre"> </span>32768              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat</div>

<div>+ 2009-07-14 04:54 . 2012-07-13 09:10<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>- 2009-07-14 04:54 . 2012-07-11 00:47<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-13 23:35<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10<span class="Apple-tab-span" style="white-space:pre"> </span>32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-13 23:35<span class="Apple-tab-span" style="white-space:pre"> </span>32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-13 23:35<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-13 23:36<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-13 23:36<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>- 2012-07-12 01:04 . 2012-07-12 01:04<span class="Apple-tab-span" style="white-space:pre"> </span>2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat</div>

<div>+ 2012-07-13 23:30 . 2012-07-13 23:30<span class="Apple-tab-span" style="white-space:pre"> </span>2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat</div>

<div>+ 2012-07-13 23:30 . 2012-07-13 23:30<span class="Apple-tab-span" style="white-space:pre"> </span>2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat</div>

<div>- 2012-07-12 01:04 . 2012-07-12 01:04<span class="Apple-tab-span" style="white-space:pre"> </span>2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat</div>

<div>+ 2012-07-02 15:48 . 2011-02-28 22:37<span class="Apple-tab-span" style="white-space:pre"> </span>738080              c:\windows\system32\spool\drivers\x64\3\pscript5.dll</div>

<div>+ 2012-07-02 15:48 . 2011-02-28 22:37<span class="Apple-tab-span" style="white-space:pre"> </span>241952              c:\windows\system32\spool\drivers\x64\3\ps5ui.dll</div>

<div>+ 2009-07-14 05:01 . 2012-07-13 23:28<span class="Apple-tab-span" style="white-space:pre"> </span>515388              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat</div>

<div>- 2009-07-14 05:01 . 2012-07-12 01:02<span class="Apple-tab-span" style="white-space:pre"> </span>515388              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat</div>

<div>- 2010-01-23 09:16 . 2012-07-12 01:02<span class="Apple-tab-span" style="white-space:pre"> </span>1350152              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat</div>

<div>+ 2010-01-23 09:16 . 2012-07-13 23:28<span class="Apple-tab-span" style="white-space:pre"> </span>1350152              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat</div>

<div>+ 2009-07-14 02:34 . 2012-07-12 04:38<span class="Apple-tab-span" style="white-space:pre"> </span>10485760              c:\windows\system32\SMI\Store\Machine\schema.dat</div>

<div>- 2009-07-14 02:34 . 2012-07-11 10:16<span class="Apple-tab-span" style="white-space:pre"> </span>10485760              c:\windows\system32\SMI\Store\Machine\schema.dat</div>

<div>+ 2010-02-26 09:22 . 2012-07-13 23:28<span class="Apple-tab-span" style="white-space:pre"> </span>24521432              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-645954481-4171391755-2920796181-1000-12288.dat</div>

<div>+ 2012-04-30 21:43 . 2012-04-30 21:43<span class="Apple-tab-span" style="white-space:pre"> </span>45831680              c:\windows\Installer\27a2bc1.msi</div>

<div>.</div>

<div>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>.</div>

<div>*Note* empty entries & legit default entries are not shown </div>

<div>REGEDIT4</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]</div>

<div>@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space:pre"> </span>94208<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]</div>

<div>@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space:pre"> </span>94208<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]</div>

<div>@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space:pre"> </span>94208<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]</div>

<div>@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space:pre"> </span>94208<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll</div>

<div>.</div>

<div>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]</div>

<div>"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-02 1242448]</div>

<div>"AlcoholAutomount"="c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]</div>

<div>"Xvid"="c:\program files (x86)\XviD\CheckUpdate.exe" [2011-01-17 8192]</div>

<div>"Snarl"="c:\program files (x86)\full phat\Snarl\snarl.exe" [2011-05-25 925696]</div>

<div>"Tonido"="c:\users\Hayden\AppData\Roaming\Tonido\launcher.exe" [2011-11-14 100864]</div>

<div>"MusicManager"="c:\users\Hayden\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [2012-06-01 13806592]</div>

<div>"GoToMeeting"="c:\program files (x86)\Citrix\GoToMeeting\952\g2mstart.exe" [2012-05-25 39816]</div>

<div>"Spotify Web Helper"="c:\users\Hayden\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-30 932528]</div>

<div>"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]</div>

<div>"GoogleChromeAutoLaunch_7BA29E3153B77E65C37077A2469120EB"="c:\users\Hayden\AppData\Local\Google\Chrome\Application\chrome.exe" [2012-07-10 1250328]</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]</div>

<div>"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]</div>

<div>"AVG9_TRAY"="c:\progra~2\AVG\AVG9\avgtray.exe" [2012-01-26 2077536]</div>

<div>"VolPanel"="c:\program files (x86)\Creative\Volume Panel\VolPanlu.exe" [2008-08-06 233576]</div>

<div>"CTxfiHlp"="CTXFIHLP.EXE" [2009-07-14 24576]</div>

<div>"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]</div>

<div>"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]</div>

<div>"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]</div>

<div>"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]</div>

<div>"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]</div>

<div>"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]</div>

<div>"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]</div>

<div>"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]</div>

<div>"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2012-05-03 217256]</div>

<div>"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]</div>

<div>"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-05-01 1895424]</div>

<div>"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704]</div>

<div>.</div>

<div>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]</div>

<div>"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]</div>

<div>.</div>

<div>c:\users\Hayden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\</div>

<div>CurseClientStartup.ccip [2010-12-7 0]</div>

<div>Dropbox.lnk - c:\users\Hayden\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]</div>

<div>EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2012-6-13 1014112]</div>

<div>.</div>

<div>c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\</div>

<div>HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]</div>

<div>Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2011-8-21 102912]</div>

<div>Subsonic.lnk - c:\program files (x86)\Subsonic\subsonic-agent.exe [2011-12-6 206336]</div>

<div>UltraMon.lnk - c:\windows\Installer\{B49673F8-7AB6-4A14-8213-C8A7BE370010}\IcoUltraMon.ico [2010-8-23 29310]</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]</div>

<div>"ConsentPromptBehaviorAdmin"= 0 (0x0)</div>

<div>"ConsentPromptBehaviorUser"= 3 (0x3)</div>

<div>"EnableLUA"= 0 (0x0)</div>

<div>"EnableUIADesktopToggle"= 0 (0x0)</div>

<div>"PromptOnSecureDesktop"= 0 (0x0)</div>

<div>"HideShutdownScripts"= 0 (0x0)</div>

<div>.</div>

<div>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]</div>

<div>"MaxRecentDocs"= 99 (0x63)</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]</div>

<div>Security Packages<span class="Apple-tab-span" style="white-space:pre"> </span>REG_MULTI_SZ   <span class="Apple-tab-span" style="white-space:pre"> </span>kerberos msv1_0 schannel wdigest tspkg pku2u livessp</div>

<div>.</div>

<div>R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2011-09-10 18432]</div>

<div>R2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-04-02 90112]</div>

<div>R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]</div>

<div>R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [x]</div>

<div>R2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-02 67400]</div>

<div>R2 MSSQL$MSSQL;SQL Server (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\sqlservr.exe [2010-04-03 61913952]</div>

<div>R2 ReportServer$MSSQL;SQL Server Reporting Services (MSSQL);c:\program files\Microsoft SQL Server\MSRS10_50.MSSQL\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2010-04-03 2175328]</div>

<div>R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]</div>

<div>R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2009-10-31 79360]</div>

<div>R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-31 79360]</div>

<div>R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-08 230488]</div>

<div>R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]</div>

<div>R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-08 95320]</div>

<div>R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [x]</div>

<div>R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-07 113120]</div>

<div>R3 MSSQLFDLauncher$MSSQL;SQL Full-text Filter Daemon Launcher (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\fdlauncher.exe [2010-04-03 32096]</div>

<div>R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]</div>

<div>R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2012-05-29 19952]</div>

<div>R3 SQLAgent$MSSQL;SQL Server Agent (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\SQLAGENT.EXE [2010-04-03 428384]</div>

<div>R3 SSMO3v2Filter;MMO3v2 Mouse;c:\windows\system32\drivers\MO3v2Driver.sys [2010-11-22 23040]</div>

<div>R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]</div>

<div>R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]</div>

<div>R3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM10864.sys [2010-08-13 1310720]</div>

<div>R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-10 1255736]</div>

<div>R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]</div>

<div>R3 WMSVC;Web Management Service;c:\windows\system32\inetsrv\wmsvc.exe [2009-07-14 10752]</div>

<div>R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]</div>

<div>R4 RsFx0150;RsFx0150 Driver;c:\windows\system32\DRIVERS\RsFx0150.sys [2010-04-03 313696]</div>

<div>R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]</div>

<div>S0 AvgRkx64;avgrkx64.sys;c:\windows\System32\Drivers\avgrkx64.sys [2010-03-29 56008]</div>

<div>S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-12 503352]</div>

<div>S1 AvgLdx64;AVG AVI Loader Driver x64;c:\windows\System32\Drivers\avgldx64.sys [2010-06-22 269904]</div>

<div>S1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;c:\windows\System32\Drivers\avgmfx64.sys [2011-09-13 35664]</div>

<div>S1 AvgTdiA;AVG Network Redirector x64;c:\windows\System32\Drivers\avgtdia.sys [2011-05-06 317520]</div>

<div>S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]</div>

<div>S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]</div>

<div>S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]</div>

<div>S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]</div>

<div>S2 avg9emc;AVG E-mail Scanner;c:\program files (x86)\AVG\AVG9\avgemc.exe [2010-07-21 921952]</div>

<div>S2 avg9wd;AVG WatchDog;c:\program files (x86)\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]</div>

<div>S2 DeviceMonitorService;DeviceMonitorService;c:\program files (x86)\Motorola Media Link\Lite\NServiceEntry.exe [2012-06-05 87400]</div>

<div>S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2011-11-08 14216]</div>

<div>S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]</div>

<div>S2 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-06-05 116632]</div>

<div>S2 MSOLAP$MSSQL;SQL Server Analysis Services (MSSQL);c:\program files\Microsoft SQL Server\MSAS10_50.MSSQL\OLAP\bin\msmdsrv.exe [2010-04-03 54568288]</div>

<div>S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2012-04-12 204304]</div>

<div>S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\NLSSRV32.EXE [2012-06-25 69640]</div>

<div>S2 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2011-09-02 65657]</div>

<div>S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2008-11-14 20512]</div>

<div>S2 WDDMService.exe;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-08-17 116224]</div>

<div>S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]</div>

<div>S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]</div>

<div>S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]</div>

<div>S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-08 230488]</div>

<div>S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]</div>

<div>S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-08 95320]</div>

<div>S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys [2010-05-22 66728]</div>

<div>S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-08 1612888]</div>

<div>S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2010-12-12 22408]</div>

<div>S3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys [2009-07-01 30728]</div>

<div>S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2010-12-12 16008]</div>

<div>S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]</div>

<div>S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]</div>

<div>S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]</div>

<div>S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-09-28 395264]</div>

<div>.</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]</div>

<div>iissvcs<span class="Apple-tab-span" style="white-space:pre"> </span>REG_MULTI_SZ   <span class="Apple-tab-span" style="white-space:pre"> </span>w3svc was</div>

<div>apphost<span class="Apple-tab-span" style="white-space:pre"> </span>REG_MULTI_SZ   <span class="Apple-tab-span" style="white-space:pre"> </span>apphostsvc</div>

<div>hpdevmgmt<span class="Apple-tab-span" style="white-space:pre"> </span>REG_MULTI_SZ   <span class="Apple-tab-span" style="white-space:pre"> </span>hpqcxs08 hpqddsvc</div>

<div>.</div>

<div>Contents of the 'Scheduled Tasks' folder</div>

<div>.</div>

<div>2012-07-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000Core.job</div>

<div>- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]</div>

<div>.</div>

<div>2012-07-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000UA.job</div>

<div>- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]</div>

<div>.</div>

<div>.</div>

Link to post
Share on other sites

<p> </p>

<div>No idea why its pasting the HTML... I'm copying and pasting as plain text too.</div>

<div> </div>

<div>ComboFix 12-07-13.03 - Hayden 07/13/2012  18:11:50.3.8 - x64</div>

<div>Microsoft Windows 7 Professional   6.1.7600.0.1252.1.1033.18.12279.7511 [GMT -5:00]</div>

<div>Running from: c:\users\Hayden\Desktop\ComboFix.exe</div>

<div>Command switches used :: c:\users\Hayden\Desktop\CFScript.txt</div>

<div>AV: AVG Anti-Virus *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}</div>

<div>SP: AVG Anti-Virus *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}</div>

<div>SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}</div>

<div>.</div>

<div>.</div>

<div>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>.</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\catalog.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711124102-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711124102-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711130019-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711130019-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711131001-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711131001-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711132048-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711132048-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711134018-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711134018-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711140044-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711140044-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711165450-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711165450-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711170034-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711170034-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711185041-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711185041-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190017-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190017-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190959-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190959-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711192046-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711192046-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711194008-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711194008-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711195104-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711195104-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711200047-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711200047-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711201027-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711201027-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202010-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202010-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202115-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202115-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711204041-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711204041-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711210013-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711210013-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711211057-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711211057-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711212040-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711212040-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711214104-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711214104-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711215200-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711215200-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711220038-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711220038-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711221122-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711221122-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711222104-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711222104-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224029-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224029-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224136-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224136-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711230007-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711230007-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711231158-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711231158-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711232038-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711232038-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234102-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234102-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234209-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234209-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712000034-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712000034-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712001223-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712001223-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712002102-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712002102-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004022-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004022-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004234-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004234-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712010106-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712010106-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712011255-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712011255-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712012031-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712012031-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014056-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014056-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014308-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014308-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712020035-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712020035-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712021328-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712021328-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712022103-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712022103-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024022-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024022-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024337-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024337-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712030102-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712030102-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712031357-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712031357-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712032029-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712032029-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712034050-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712034050-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712040020-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712040020-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712041417-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712041417-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712042048-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712042048-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044112-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044112-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044428-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044428-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712050050-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712050050-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712051448-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712051448-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712052016-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712052016-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054036-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054036-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054455-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054455-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712060012-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712060012-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712061518-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712061518-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064110-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064110-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064530-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064530-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712070045-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712070045-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712071547-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712071547-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072011-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072011-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072638-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072638-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074040-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074040-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074604-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074604-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712080053-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712080053-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712081701-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712081701-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712082019-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712082019-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712084108-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712084108-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712090033-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712090033-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712091748-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712091748-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712092106-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712092106-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094023-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094023-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094755-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094755-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712100102-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712100102-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712101811-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712101811-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712102025-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712102025-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104047-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104047-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104820-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104820-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712105917-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712105917-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712110028-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712110028-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712111846-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712111846-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712112059-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712112059-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712114015-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712114015-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712120049-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712120049-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712121902-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712121902-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712122011-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712122011-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712124034-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712124034-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712130110-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712130110-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712131928-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712131928-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712132038-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712132038-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712134108-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712134108-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712140050-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712140050-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712142013-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712142013-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712144040-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712144040-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712150122-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712150122-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712152041-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712152041-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712154107-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712154107-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712155049-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712155049-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712160040-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712160040-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712162113-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712162113-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712164037-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712164037-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712165131-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712165131-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712170118-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712170118-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712172149-f.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712174016-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712174016-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712175211-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712175211-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180051-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180051-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180310-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180310-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182024-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182024-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182235-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182235-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712183324-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712183324-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712184100-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712184100-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712185255-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712185255-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712190030-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712190030-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192114-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192114-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192325-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192325-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712194042-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712194042-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712195336-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712195336-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712200014-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712200014-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202053-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202053-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202409-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202409-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712204024-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712204024-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712210050-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712210050-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212015-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212015-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212438-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212438-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712214038-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712214038-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712215529-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712215529-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712220052-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712220052-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222104-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222104-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222625-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222625-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712224013-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712224013-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712225707-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712225707-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712230026-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712230026-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232040-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232040-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232806-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232806-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712234054-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712234054-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712235857-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120712235857-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713000114-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713000114-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002032-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002032-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002135-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002135-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002239-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002239-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002343-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002343-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002447-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002447-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002552-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002552-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002700-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002700-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002804-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002804-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713153753-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713153753-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713160908-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713160908-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161042-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161042-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161324-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161324-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161515-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161515-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161643-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161643-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161907-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161907-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162036-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162036-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162217-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162217-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162826-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162826-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163034-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163034-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163413-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163413-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163606-l.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163606-m.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\temp.zip</div>

<div>c:\windows\isRS-000.tmp</div>

<div>.</div>

<div>.</div>

<div>(((((((((((((((((((((((((   Files Created from 2012-06-13 to 2012-07-13  )))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>.</div>

<div>2012-07-13 23:32 . 2012-07-13 23:33 -------- d-----w- c:\users\Hayden\AppData\Local\blekkotb_031</div>

<div>2012-07-13 23:27 . 2012-07-13 23:27 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp</div>

<div>2012-07-13 23:27 . 2012-07-13 23:27 -------- d-----w- c:\users\Default\AppData\Local\temp</div>

<div>2012-07-13 23:27 . 2012-07-13 23:27 -------- d-----w- c:\users\Classic .NET AppPool\AppData\Local\temp</div>

<div>2012-07-12 18:10 . 2012-04-12 03:55 17936 ----a-w- c:\windows\system32\nitrolocalui2.dll</div>

<div>2012-07-12 18:10 . 2012-04-12 03:55 29712 ----a-w- c:\windows\system32\nitrolocalmon2.dll</div>

<div>2012-07-12 18:10 . 2012-07-12 18:10 -------- d-----w- c:\program files\Common Files\Nitro PDF</div>

<div>2012-07-12 18:10 . 2012-07-12 18:10 -------- d-----w- c:\program files (x86)\Common Files\Nitro PDF</div>

<div>2012-07-12 18:09 . 2012-07-12 18:10 -------- d-----w- c:\program files (x86)\Nitro PDF</div>

<div>2012-07-10 23:48 . 2012-07-10 23:48 -------- d-----w- c:\programdata\ATI</div>

<div>2012-07-10 23:47 . 2012-07-10 23:47 -------- d-----w- c:\program files (x86)\AMD APP</div>

<div>2012-07-10 23:00 . 2012-07-10 23:00 -------- d-----w- C:\_OTL</div>

<div>2012-07-09 22:27 . 2012-07-09 22:27 -------- d-----w- c:\program files (x86)\KeePass Password Safe 2</div>

<div>2012-07-07 22:36 . 2012-07-07 22:36 -------- d-----w- C:\TDSSKiller_Quarantine</div>

<div>2012-07-07 18:57 . 2012-07-07 18:57 -------- d-----w- c:\users\Hayden\AppData\Roaming\Malwarebytes</div>

<div>2012-07-07 18:56 . 2012-07-12 06:32 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware</div>

<div>2012-07-07 18:56 . 2012-07-07 18:56 -------- d-----w- c:\programdata\Malwarebytes</div>

<div>2012-07-07 18:56 . 2012-07-03 18:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys</div>

<div>2012-07-07 06:02 . 2012-07-07 06:02 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll</div>

<div>2012-07-07 06:02 . 2012-07-07 06:02 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll</div>

<div>2012-07-06 19:18 . 2012-07-11 00:43 -------- d-----w- C:\subsonic</div>

<div>2012-07-06 19:18 . 2012-07-06 19:18 -------- d-----w- c:\program files (x86)\Subsonic</div>

<div>2012-07-02 18:01 . 2012-07-02 18:01 -------- d-----w- c:\users\Hayden\.pdfsam</div>

<div>2012-07-02 16:17 . 2012-07-02 16:17 -------- d-----w- c:\program files (x86)\pdfsam</div>

<div>2012-07-02 16:07 . 2012-07-04 20:37 -------- d-----w- c:\users\Hayden\AppData\Roaming\ParmisPDF</div>

<div>2012-07-02 15:49 . 2012-07-12 18:13 -------- d-----w- c:\users\Hayden\AppData\Roaming\PrimoPDF</div>

<div>2012-07-02 15:48 . 2012-07-12 18:09 -------- d-----w- c:\users\Hayden\AppData\Roaming\OpenCandy</div>

<div>2012-07-02 15:48 . 2011-02-28 22:37 95008 ----a-w- c:\windows\system32\Primomonnt.dll</div>

<div>2012-07-02 05:32 . 2012-07-02 05:32 -------- d-----w- c:\program files (x86)\Maxis</div>

<div>2012-07-01 07:33 . 2012-07-01 07:33 -------- d-----w- c:\users\Hayden\AppData\Roaming\EAC</div>

<div>2012-07-01 07:33 . 2012-07-01 07:33 -------- d-----w- c:\program files (x86)\Exact Audio Copy</div>

<div>2012-07-01 07:32 . 2012-07-01 07:32 -------- d-----w- c:\programdata\Anti-phishing Domain Advisor</div>

<div>2012-06-27 22:19 . 2012-07-11 01:44 -------- d-----w- c:\users\Hayden\AppData\Roaming\Nitro PDF</div>

<div>2012-06-27 22:18 . 2012-07-02 15:51 -------- d-----w- c:\programdata\Nitro PDF</div>

<div>2012-06-27 19:50 . 2012-06-27 20:00 -------- d-----w- c:\users\Hayden\.cpan</div>

<div>2012-06-25 00:35 . 2012-06-25 00:35 -------- d-----w- c:\programdata\phpDesigner</div>

<div>2012-06-20 01:45 . 2012-06-20 01:45 -------- d-----w- c:\program files (x86)\Motorola Media Link</div>

<div>2012-06-14 01:07 . 2012-06-14 01:46 -------- d-----w- c:\program files (x86)\Ken Ward's Makeup</div>

<div>.</div>

<div>.</div>

<div>.</div>

<div>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>2012-06-25 02:47 . 2012-06-25 02:47 69640 ----a-w- c:\windows\SysWow64\NLSSRV32.EXE</div>

<div>2012-06-18 08:12 . 2012-07-12 08:11 9013136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{75A75839-1E75-4ED3-A1C2-EDCBE53DD30D}\mpengine.dll</div>

<div>2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50 187392 ----a-w- c:\windows\system32\clinfo.exe</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll</div>

<div>2012-06-11 18:49 . 2012-06-11 18:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll</div>

<div>2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll</div>

<div>2012-06-11 18:29 . 2011-10-26 02:16 24826368 ----a-w- c:\windows\system32\atio6axx.dll</div>

<div>2012-06-11 18:00 . 2012-06-11 18:00 20467712 ----a-w- c:\windows\SysWow64\atioglxx.dll</div>

<div>2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe</div>

<div>2012-06-11 17:24 . 2011-12-06 03:17 924160 ----a-w- c:\windows\SysWow64\aticfx32.dll</div>

<div>2012-06-11 17:23 . 2011-10-26 02:04 1090560 ----a-w- c:\windows\system32\aticfx64.dll</div>

<div>2012-06-11 17:20 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll</div>

<div>2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe</div>

<div>2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe</div>

<div>2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll</div>

<div>2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll</div>

<div>2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll</div>

<div>2012-06-11 17:17 . 2012-06-11 17:17 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll</div>

<div>2012-06-11 17:16 . 2012-06-11 17:16 6301696 ----a-w- c:\windows\SysWow64\atidxx32.dll</div>

<div>2012-06-11 17:01 . 2012-06-11 17:01 6914560 ----a-w- c:\windows\system32\atidxx64.dll</div>

<div>2012-06-11 16:51 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll</div>

<div>2012-06-11 16:45 . 2011-12-06 02:33 5480448 ----a-w- c:\windows\SysWow64\atiumdag.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll</div>

<div>2012-06-11 16:43 . 2011-12-06 02:28 4729344 ----a-w- c:\windows\SysWow64\atiumdva.dll</div>

<div>2012-06-11 16:40 . 2012-06-11 16:40 13277696 ----a-w- c:\windows\SysWow64\aticaldd.dll</div>

<div>2012-06-11 16:36 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll</div>

<div>2012-06-11 16:27 . 2011-10-26 01:22 539136 ----a-w- c:\windows\system32\atiadlxx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll</div>

<div>2012-06-11 16:26 . 2011-10-26 01:22 17920 ----a-w- c:\windows\system32\atig6pxx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll</div>

<div>2012-06-11 16:26 . 2011-10-26 01:22 41984 ----a-w- c:\windows\system32\atig6txx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys</div>

<div>2012-06-11 16:25 . 2010-11-26 02:16 54784 ----a-w- c:\windows\system32\atiuxp64.dll</div>

<div>2012-06-11 16:25 . 2012-06-11 16:25 42496 ----a-w- c:\windows\SysWow64\atiuxpag.dll</div>

<div>2012-06-11 16:25 . 2012-06-11 16:25 45056 ----a-w- c:\windows\system32\atiu9p64.dll</div>

<div>2012-06-11 16:24 . 2010-11-26 02:15 32768 ----a-w- c:\windows\SysWow64\atiu9pag.dll</div>

<div>2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll</div>

<div>2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll</div>

<div>2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll</div>

<div>2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll</div>

<div>2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll</div>

<div>2012-05-31 17:25 . 2009-10-30 23:04 279656 ------w- c:\windows\system32\MpSigStub.exe</div>

<div>.</div>

<div>.</div>

<div>(((((((((((((((((((((((((((((   SnapShot_2012-07-12_01.06.01   )))))))))))))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>+ 2012-07-13 23:33 . 2012-07-13 23:33 27585              c:\windows\temp\e4jE4B3.tmp_dir\i4jdel.exe</div>

<div>+ 2009-10-30 23:27 . 2012-07-13 23:36 93700              c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin</div>

<div>+ 2009-07-14 05:10 . 2012-07-13 23:36 31782              c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin</div>

<div>+ 2009-10-30 22:49 . 2012-07-13 23:36 15994              c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-645954481-4171391755-2920796181-1000_UserData.bin</div>

<div>+ 2012-07-12 18:10 . 2012-04-12 03:55 83472              c:\windows\system32\spool\drivers\x64\NitroReaderUI2.dll</div>

<div>+ 2012-07-12 18:10 . 2012-04-12 03:55 45584              c:\windows\system32\spool\drivers\x64\NitroReaderGraphics2.dll</div>

<div>+ 2009-10-31 00:26 . 2012-07-13 09:10 49152              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>- 2009-10-31 00:26 . 2012-07-11 00:47 49152              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>+ 2012-07-10 23:27 . 2012-07-13 09:10 32768              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat</div>

<div>- 2012-07-10 23:27 . 2012-07-11 00:47 32768              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat</div>

<div>+ 2009-07-14 04:54 . 2012-07-13 09:10 16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>- 2009-07-14 04:54 . 2012-07-11 00:47 16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10 16384              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-13 23:35 16384              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10 32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-13 23:35 32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-13 23:35 16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10 16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-13 23:36 16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10 16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10 16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-13 23:36 16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>- 2012-07-12 01:04 . 2012-07-12 01:04 2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat</div>

<div>+ 2012-07-13 23:30 . 2012-07-13 23:30 2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat</div>

<div>+ 2012-07-13 23:30 . 2012-07-13 23:30 2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat</div>

<div>- 2012-07-12 01:04 . 2012-07-12 01:04 2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat</div>

<div>+ 2012-07-02 15:48 . 2011-02-28 22:37 738080              c:\windows\system32\spool\drivers\x64\3\pscript5.dll</div>

<div>+ 2012-07-02 15:48 . 2011-02-28 22:37 241952              c:\windows\system32\spool\drivers\x64\3\ps5ui.dll</div>

<div>+ 2009-07-14 05:01 . 2012-07-13 23:28 515388              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat</div>

<div>- 2009-07-14 05:01 . 2012-07-12 01:02 515388              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat</div>

<div>- 2010-01-23 09:16 . 2012-07-12 01:02 1350152              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat</div>

<div>+ 2010-01-23 09:16 . 2012-07-13 23:28 1350152              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat</div>

<div>+ 2009-07-14 02:34 . 2012-07-12 04:38 10485760              c:\windows\system32\SMI\Store\Machine\schema.dat</div>

<div>- 2009-07-14 02:34 . 2012-07-11 10:16 10485760              c:\windows\system32\SMI\Store\Machine\schema.dat</div>

<div>+ 2010-02-26 09:22 . 2012-07-13 23:28 24521432              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-645954481-4171391755-2920796181-1000-12288.dat</div>

<div>+ 2012-04-30 21:43 . 2012-04-30 21:43 45831680              c:\windows\Installer\27a2bc1.msi</div>

<div>.</div>

<div>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>.</div>

<div>*Note* empty entries & legit default entries are not shown </div>

<div>REGEDIT4</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]</div>

<div>@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]</div>

<div>@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]</div>

<div>@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]</div>

<div>@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll</div>

<div>.</div>

<div>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]</div>

<div>"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-02 1242448]</div>

<div>"AlcoholAutomount"="c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]</div>

<div>"Xvid"="c:\program files (x86)\XviD\CheckUpdate.exe" [2011-01-17 8192]</div>

<div>"Snarl"="c:\program files (x86)\full phat\Snarl\snarl.exe" [2011-05-25 925696]</div>

<div>"Tonido"="c:\users\Hayden\AppData\Roaming\Tonido\launcher.exe" [2011-11-14 100864]</div>

<div>"MusicManager"="c:\users\Hayden\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [2012-06-01 13806592]</div>

<div>"GoToMeeting"="c:\program files (x86)\Citrix\GoToMeeting\952\g2mstart.exe" [2012-05-25 39816]</div>

<div>"Spotify Web Helper"="c:\users\Hayden\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-30 932528]</div>

<div>"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]</div>

<div>"GoogleChromeAutoLaunch_7BA29E3153B77E65C37077A2469120EB"="c:\users\Hayden\AppData\Local\Google\Chrome\Application\chrome.exe" [2012-07-10 1250328]</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]</div>

<div>"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]</div>

<div>"AVG9_TRAY"="c:\progra~2\AVG\AVG9\avgtray.exe" [2012-01-26 2077536]</div>

<div>"VolPanel"="c:\program files (x86)\Creative\Volume Panel\VolPanlu.exe" [2008-08-06 233576]</div>

<div>"CTxfiHlp"="CTXFIHLP.EXE" [2009-07-14 24576]</div>

<div>"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]</div>

<div>"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]</div>

<div>"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]</div>

<div>"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]</div>

<div>"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]</div>

<div>"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]</div>

<div>"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]</div>

<div>"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]</div>

<div>"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2012-05-03 217256]</div>

<div>"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]</div>

<div>"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-05-01 1895424]</div>

<div>"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704]</div>

<div>.</div>

<div>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]</div>

<div>"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]</div>

<div>.</div>

<div>c:\users\Hayden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\</div>

<div>CurseClientStartup.ccip [2010-12-7 0]</div>

<div>Dropbox.lnk - c:\users\Hayden\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]</div>

<div>EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2012-6-13 1014112]</div>

<div>.</div>

<div>c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\</div>

<div>HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]</div>

<div>Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2011-8-21 102912]</div>

<div>Subsonic.lnk - c:\program files (x86)\Subsonic\subsonic-agent.exe [2011-12-6 206336]</div>

<div>UltraMon.lnk - c:\windows\Installer\{B49673F8-7AB6-4A14-8213-C8A7BE370010}\IcoUltraMon.ico [2010-8-23 29310]</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]</div>

<div>"ConsentPromptBehaviorAdmin"= 0 (0x0)</div>

<div>"ConsentPromptBehaviorUser"= 3 (0x3)</div>

<div>"EnableLUA"= 0 (0x0)</div>

<div>"EnableUIADesktopToggle"= 0 (0x0)</div>

<div>"PromptOnSecureDesktop"= 0 (0x0)</div>

<div>"HideShutdownScripts"= 0 (0x0)</div>

<div>.</div>

<div>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]</div>

<div>"MaxRecentDocs"= 99 (0x63)</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]</div>

<div>Security Packages REG_MULTI_SZ   kerberos msv1_0 schannel wdigest tspkg pku2u livessp</div>

<div>.</div>

<div>R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2011-09-10 18432]</div>

<div>R2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-04-02 90112]</div>

<div>R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]</div>

<div>R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [x]</div>

<div>R2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-02 67400]</div>

<div>R2 MSSQL$MSSQL;SQL Server (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\sqlservr.exe [2010-04-03 61913952]</div>

<div>R2 ReportServer$MSSQL;SQL Server Reporting Services (MSSQL);c:\program files\Microsoft SQL Server\MSRS10_50.MSSQL\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2010-04-03 2175328]</div>

<div>R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]</div>

<div>R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2009-10-31 79360]</div>

<div>R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-31 79360]</div>

<div>R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-08 230488]</div>

<div>R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]</div>

<div>R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-08 95320]</div>

<div>R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [x]</div>

<div>R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-07 113120]</div>

<div>R3 MSSQLFDLauncher$MSSQL;SQL Full-text Filter Daemon Launcher (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\fdlauncher.exe [2010-04-03 32096]</div>

<div>R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]</div>

<div>R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2012-05-29 19952]</div>

<div>R3 SQLAgent$MSSQL;SQL Server Agent (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\SQLAGENT.EXE [2010-04-03 428384]</div>

<div>R3 SSMO3v2Filter;MMO3v2 Mouse;c:\windows\system32\drivers\MO3v2Driver.sys [2010-11-22 23040]</div>

<div>R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]</div>

<div>R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]</div>

<div>R3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM10864.sys [2010-08-13 1310720]</div>

<div>R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-10 1255736]</div>

<div>R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]</div>

<div>R3 WMSVC;Web Management Service;c:\windows\system32\inetsrv\wmsvc.exe [2009-07-14 10752]</div>

<div>R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]</div>

<div>R4 RsFx0150;RsFx0150 Driver;c:\windows\system32\DRIVERS\RsFx0150.sys [2010-04-03 313696]</div>

<div>R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]</div>

<div>S0 AvgRkx64;avgrkx64.sys;c:\windows\System32\Drivers\avgrkx64.sys [2010-03-29 56008]</div>

<div>S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-12 503352]</div>

<div>S1 AvgLdx64;AVG AVI Loader Driver x64;c:\windows\System32\Drivers\avgldx64.sys [2010-06-22 269904]</div>

<div>S1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;c:\windows\System32\Drivers\avgmfx64.sys [2011-09-13 35664]</div>

<div>S1 AvgTdiA;AVG Network Redirector x64;c:\windows\System32\Drivers\avgtdia.sys [2011-05-06 317520]</div>

<div>S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]</div>

<div>S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]</div>

<div>S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]</div>

<div>S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]</div>

<div>S2 avg9emc;AVG E-mail Scanner;c:\program files (x86)\AVG\AVG9\avgemc.exe [2010-07-21 921952]</div>

<div>S2 avg9wd;AVG WatchDog;c:\program files (x86)\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]</div>

<div>S2 DeviceMonitorService;DeviceMonitorService;c:\program files (x86)\Motorola Media Link\Lite\NServiceEntry.exe [2012-06-05 87400]</div>

<div>S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2011-11-08 14216]</div>

<div>S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]</div>

<div>S2 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-06-05 116632]</div>

<div>S2 MSOLAP$MSSQL;SQL Server Analysis Services (MSSQL);c:\program files\Microsoft SQL Server\MSAS10_50.MSSQL\OLAP\bin\msmdsrv.exe [2010-04-03 54568288]</div>

<div>S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2012-04-12 204304]</div>

<div>S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\NLSSRV32.EXE [2012-06-25 69640]</div>

<div>S2 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2011-09-02 65657]</div>

<div>S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2008-11-14 20512]</div>

<div>S2 WDDMService.exe;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-08-17 116224]</div>

<div>S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]</div>

<div>S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]</div>

<div>S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]</div>

<div>S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-08 230488]</div>

<div>S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]</div>

<div>S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-08 95320]</div>

<div>S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys [2010-05-22 66728]</div>

<div>S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-08 1612888]</div>

<div>S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2010-12-12 22408]</div>

<div>S3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys [2009-07-01 30728]</div>

<div>S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2010-12-12 16008]</div>

<div>S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]</div>

<div>S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]</div>

<div>S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]</div>

<div>S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-09-28 395264]</div>

<div>.</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]</div>

<div>iissvcs REG_MULTI_SZ   w3svc was</div>

<div>apphost REG_MULTI_SZ   apphostsvc</div>

<div>hpdevmgmt REG_MULTI_SZ   hpqcxs08 hpqddsvc</div>

<div>.</div>

<div>Contents of the 'Scheduled Tasks' folder</div>

<div>.</div>

<div>2012-07-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000Core.job</div>

<div>- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]</div>

<div>.</div>

<div>2012-07-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000UA.job</div>

<div>- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]</div>

<div>.</div>

<div>.</div>

Link to post
Share on other sites

Looks like copy-pasting from Notepad++ has fixed it (also gonna use the preview option), so sorry for the spam. Here we go though.

ComboFix 12-07-13.03 - Hayden 07/13/2012 18:11:50.3.8 - x64

Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.12279.7511 [GMT -5:00]

Running from: c:\users\Hayden\Desktop\ComboFix.exe

Command switches used :: c:\users\Hayden\Desktop\CFScript.txt

AV: AVG Anti-Virus *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

SP: AVG Anti-Virus *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\Hayden\AppData\Local\blekkotb_031

c:\users\Hayden\AppData\Local\blekkotb_031\catalog.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711124102-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711124102-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711130019-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711130019-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711131001-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711131001-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711132048-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711132048-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711134018-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711134018-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711140044-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711140044-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711165450-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711165450-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711170034-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711170034-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711185041-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711185041-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190017-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190017-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190959-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711190959-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711192046-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711192046-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711194008-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711194008-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711195104-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711195104-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711200047-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711200047-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711201027-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711201027-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202010-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202010-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202115-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711202115-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711204041-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711204041-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711210013-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711210013-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711211057-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711211057-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711212040-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711212040-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711214104-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711214104-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711215200-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711215200-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711220038-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711220038-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711221122-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711221122-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711222104-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711222104-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224029-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224029-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224136-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711224136-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711230007-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711230007-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711231158-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711231158-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711232038-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711232038-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234102-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234102-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234209-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120711234209-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712000034-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712000034-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712001223-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712001223-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712002102-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712002102-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004022-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004022-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004234-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712004234-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712010106-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712010106-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712011255-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712011255-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712012031-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712012031-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014056-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014056-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014308-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712014308-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712020035-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712020035-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712021328-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712021328-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712022103-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712022103-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024022-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024022-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024337-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712024337-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712030102-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712030102-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712031357-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712031357-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712032029-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712032029-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712034050-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712034050-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712040020-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712040020-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712041417-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712041417-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712042048-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712042048-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044112-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044112-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044428-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712044428-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712050050-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712050050-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712051448-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712051448-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712052016-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712052016-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054036-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054036-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054455-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712054455-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712060012-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712060012-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712061518-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712061518-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064110-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064110-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064530-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712064530-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712070045-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712070045-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712071547-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712071547-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072011-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072011-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072638-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712072638-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074040-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074040-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074604-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712074604-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712080053-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712080053-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712081701-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712081701-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712082019-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712082019-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712084108-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712084108-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712090033-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712090033-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712091748-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712091748-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712092106-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712092106-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094023-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094023-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094755-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712094755-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712100102-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712100102-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712101811-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712101811-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712102025-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712102025-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104047-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104047-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104820-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712104820-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712105917-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712105917-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712110028-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712110028-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712111846-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712111846-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712112059-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712112059-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712114015-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712114015-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712120049-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712120049-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712121902-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712121902-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712122011-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712122011-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712124034-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712124034-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712130110-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712130110-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712131928-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712131928-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712132038-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712132038-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712134108-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712134108-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712140050-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712140050-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712142013-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712142013-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712144040-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712144040-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712150122-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712150122-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712152041-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712152041-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712154107-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712154107-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712155049-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712155049-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712160040-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712160040-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712162113-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712162113-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712164037-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712164037-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712165131-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712165131-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712170118-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712170118-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712172149-f.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712174016-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712174016-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712175211-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712175211-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180051-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180051-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180310-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712180310-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182024-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182024-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182235-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712182235-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712183324-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712183324-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712184100-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712184100-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712185255-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712185255-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712190030-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712190030-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192114-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192114-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192325-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712192325-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712194042-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712194042-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712195336-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712195336-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712200014-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712200014-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202053-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202053-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202409-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712202409-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712204024-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712204024-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712210050-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712210050-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212015-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212015-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212438-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712212438-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712214038-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712214038-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712215529-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712215529-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712220052-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712220052-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222104-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222104-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222625-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712222625-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712224013-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712224013-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712225707-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712225707-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712230026-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712230026-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232040-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232040-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232806-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712232806-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712234054-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712234054-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712235857-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120712235857-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713000114-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713000114-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002032-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002032-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002135-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002135-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002239-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002239-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002343-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002343-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002447-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002447-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002552-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002552-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002700-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002700-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002804-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713002804-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713153753-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713153753-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713160908-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713160908-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161042-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161042-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161324-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161324-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161515-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161515-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161643-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161643-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161907-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713161907-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162036-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162036-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162217-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162217-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162826-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713162826-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163034-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163034-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163413-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163413-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163606-l.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163606-m.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\temp.zip

c:\windows\isRS-000.tmp

.

.

((((((((((((((((((((((((( Files Created from 2012-06-13 to 2012-07-13 )))))))))))))))))))))))))))))))

.

.

2012-07-13 23:32 . 2012-07-13 23:33 -------- d-----w- c:\users\Hayden\AppData\Local\blekkotb_031

2012-07-13 23:27 . 2012-07-13 23:27 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp

2012-07-13 23:27 . 2012-07-13 23:27 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-07-13 23:27 . 2012-07-13 23:27 -------- d-----w- c:\users\Classic .NET AppPool\AppData\Local\temp

2012-07-12 18:10 . 2012-04-12 03:55 17936 ----a-w- c:\windows\system32\nitrolocalui2.dll

2012-07-12 18:10 . 2012-04-12 03:55 29712 ----a-w- c:\windows\system32\nitrolocalmon2.dll

2012-07-12 18:10 . 2012-07-12 18:10 -------- d-----w- c:\program files\Common Files\Nitro PDF

2012-07-12 18:10 . 2012-07-12 18:10 -------- d-----w- c:\program files (x86)\Common Files\Nitro PDF

2012-07-12 18:09 . 2012-07-12 18:10 -------- d-----w- c:\program files (x86)\Nitro PDF

2012-07-10 23:48 . 2012-07-10 23:48 -------- d-----w- c:\programdata\ATI

2012-07-10 23:47 . 2012-07-10 23:47 -------- d-----w- c:\program files (x86)\AMD APP

2012-07-10 23:00 . 2012-07-10 23:00 -------- d-----w- C:\_OTL

2012-07-09 22:27 . 2012-07-09 22:27 -------- d-----w- c:\program files (x86)\KeePass Password Safe 2

2012-07-07 22:36 . 2012-07-07 22:36 -------- d-----w- C:\TDSSKiller_Quarantine

2012-07-07 18:57 . 2012-07-07 18:57 -------- d-----w- c:\users\Hayden\AppData\Roaming\Malwarebytes

2012-07-07 18:56 . 2012-07-12 06:32 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-07-07 18:56 . 2012-07-07 18:56 -------- d-----w- c:\programdata\Malwarebytes

2012-07-07 18:56 . 2012-07-03 18:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-07-07 06:02 . 2012-07-07 06:02 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll

2012-07-07 06:02 . 2012-07-07 06:02 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll

2012-07-06 19:18 . 2012-07-11 00:43 -------- d-----w- C:\subsonic

2012-07-06 19:18 . 2012-07-06 19:18 -------- d-----w- c:\program files (x86)\Subsonic

2012-07-02 18:01 . 2012-07-02 18:01 -------- d-----w- c:\users\Hayden\.pdfsam

2012-07-02 16:17 . 2012-07-02 16:17 -------- d-----w- c:\program files (x86)\pdfsam

2012-07-02 16:07 . 2012-07-04 20:37 -------- d-----w- c:\users\Hayden\AppData\Roaming\ParmisPDF

2012-07-02 15:49 . 2012-07-12 18:13 -------- d-----w- c:\users\Hayden\AppData\Roaming\PrimoPDF

2012-07-02 15:48 . 2012-07-12 18:09 -------- d-----w- c:\users\Hayden\AppData\Roaming\OpenCandy

2012-07-02 15:48 . 2011-02-28 22:37 95008 ----a-w- c:\windows\system32\Primomonnt.dll

2012-07-02 05:32 . 2012-07-02 05:32 -------- d-----w- c:\program files (x86)\Maxis

2012-07-01 07:33 . 2012-07-01 07:33 -------- d-----w- c:\users\Hayden\AppData\Roaming\EAC

2012-07-01 07:33 . 2012-07-01 07:33 -------- d-----w- c:\program files (x86)\Exact Audio Copy

2012-07-01 07:32 . 2012-07-01 07:32 -------- d-----w- c:\programdata\Anti-phishing Domain Advisor

2012-06-27 22:19 . 2012-07-11 01:44 -------- d-----w- c:\users\Hayden\AppData\Roaming\Nitro PDF

2012-06-27 22:18 . 2012-07-02 15:51 -------- d-----w- c:\programdata\Nitro PDF

2012-06-27 19:50 . 2012-06-27 20:00 -------- d-----w- c:\users\Hayden\.cpan

2012-06-25 00:35 . 2012-06-25 00:35 -------- d-----w- c:\programdata\phpDesigner

2012-06-20 01:45 . 2012-06-20 01:45 -------- d-----w- c:\program files (x86)\Motorola Media Link

2012-06-14 01:07 . 2012-06-14 01:46 -------- d-----w- c:\program files (x86)\Ken Ward's Makeup

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-06-25 02:47 . 2012-06-25 02:47 69640 ----a-w- c:\windows\SysWow64\NLSSRV32.EXE

2012-06-18 08:12 . 2012-07-12 08:11 9013136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{75A75839-1E75-4ED3-A1C2-EDCBE53DD30D}\mpengine.dll

2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys

2012-06-11 18:50 . 2012-06-11 18:50 187392 ----a-w- c:\windows\system32\clinfo.exe

2012-06-11 18:50 . 2012-06-11 18:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll

2012-06-11 18:50 . 2012-06-11 18:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll

2012-06-11 18:50 . 2012-06-11 18:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll

2012-06-11 18:50 . 2012-06-11 18:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll

2012-06-11 18:50 . 2012-06-11 18:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll

2012-06-11 18:49 . 2012-06-11 18:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll

2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll

2012-06-11 18:29 . 2011-10-26 02:16 24826368 ----a-w- c:\windows\system32\atio6axx.dll

2012-06-11 18:00 . 2012-06-11 18:00 20467712 ----a-w- c:\windows\SysWow64\atioglxx.dll

2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe

2012-06-11 17:24 . 2011-12-06 03:17 924160 ----a-w- c:\windows\SysWow64\aticfx32.dll

2012-06-11 17:23 . 2011-10-26 02:04 1090560 ----a-w- c:\windows\system32\aticfx64.dll

2012-06-11 17:20 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll

2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe

2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe

2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll

2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll

2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll

2012-06-11 17:17 . 2012-06-11 17:17 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll

2012-06-11 17:16 . 2012-06-11 17:16 6301696 ----a-w- c:\windows\SysWow64\atidxx32.dll

2012-06-11 17:01 . 2012-06-11 17:01 6914560 ----a-w- c:\windows\system32\atidxx64.dll

2012-06-11 16:51 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll

2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll

2012-06-11 16:45 . 2012-06-11 16:45 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll

2012-06-11 16:45 . 2011-12-06 02:33 5480448 ----a-w- c:\windows\SysWow64\atiumdag.dll

2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll

2012-06-11 16:45 . 2012-06-11 16:45 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll

2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll

2012-06-11 16:43 . 2011-12-06 02:28 4729344 ----a-w- c:\windows\SysWow64\atiumdva.dll

2012-06-11 16:40 . 2012-06-11 16:40 13277696 ----a-w- c:\windows\SysWow64\aticaldd.dll

2012-06-11 16:36 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll

2012-06-11 16:27 . 2011-10-26 01:22 539136 ----a-w- c:\windows\system32\atiadlxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll

2012-06-11 16:26 . 2011-10-26 01:22 17920 ----a-w- c:\windows\system32\atig6pxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll

2012-06-11 16:26 . 2011-10-26 01:22 41984 ----a-w- c:\windows\system32\atig6txx.dll

2012-06-11 16:26 . 2012-06-11 16:26 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys

2012-06-11 16:25 . 2010-11-26 02:16 54784 ----a-w- c:\windows\system32\atiuxp64.dll

2012-06-11 16:25 . 2012-06-11 16:25 42496 ----a-w- c:\windows\SysWow64\atiuxpag.dll

2012-06-11 16:25 . 2012-06-11 16:25 45056 ----a-w- c:\windows\system32\atiu9p64.dll

2012-06-11 16:24 . 2010-11-26 02:15 32768 ----a-w- c:\windows\SysWow64\atiu9pag.dll

2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll

2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll

2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll

2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll

2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll

2012-05-31 17:25 . 2009-10-30 23:04 279656 ------w- c:\windows\system32\MpSigStub.exe

.

.

((((((((((((((((((((((((((((( SnapShot_2012-07-12_01.06.01 )))))))))))))))))))))))))))))))))))))))))

.

+ 2012-07-13 23:33 . 2012-07-13 23:33 27585 c:\windows\temp\e4jE4B3.tmp_dir\i4jdel.exe

+ 2009-10-30 23:27 . 2012-07-13 23:36 93700 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-07-13 23:36 31782 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2009-10-30 22:49 . 2012-07-13 23:36 15994 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-645954481-4171391755-2920796181-1000_UserData.bin

+ 2012-07-12 18:10 . 2012-04-12 03:55 83472 c:\windows\system32\spool\drivers\x64\NitroReaderUI2.dll

+ 2012-07-12 18:10 . 2012-04-12 03:55 45584 c:\windows\system32\spool\drivers\x64\NitroReaderGraphics2.dll

+ 2009-10-31 00:26 . 2012-07-13 09:10 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-31 00:26 . 2012-07-11 00:47 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2012-07-10 23:27 . 2012-07-13 09:10 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2012-07-10 23:27 . 2012-07-11 00:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-07-14 04:54 . 2012-07-13 09:10 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-07-14 04:54 . 2012-07-11 00:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-10-30 22:48 . 2012-07-13 23:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-13 23:35 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-13 23:35 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-13 23:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-13 23:36 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2012-07-12 01:04 . 2012-07-12 01:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-07-13 23:30 . 2012-07-13 23:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-07-13 23:30 . 2012-07-13 23:30 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2012-07-12 01:04 . 2012-07-12 01:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2012-07-02 15:48 . 2011-02-28 22:37 738080 c:\windows\system32\spool\drivers\x64\3\pscript5.dll

+ 2012-07-02 15:48 . 2011-02-28 22:37 241952 c:\windows\system32\spool\drivers\x64\3\ps5ui.dll

+ 2009-07-14 05:01 . 2012-07-13 23:28 515388 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2009-07-14 05:01 . 2012-07-12 01:02 515388 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2010-01-23 09:16 . 2012-07-12 01:02 1350152 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat

+ 2010-01-23 09:16 . 2012-07-13 23:28 1350152 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat

+ 2009-07-14 02:34 . 2012-07-12 04:38 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

- 2009-07-14 02:34 . 2012-07-11 10:16 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

+ 2010-02-26 09:22 . 2012-07-13 23:28 24521432 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-645954481-4171391755-2920796181-1000-12288.dat

+ 2012-04-30 21:43 . 2012-04-30 21:43 45831680 c:\windows\Installer\27a2bc1.msi

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]

@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-02 1242448]

"AlcoholAutomount"="c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]

"Xvid"="c:\program files (x86)\XviD\CheckUpdate.exe" [2011-01-17 8192]

"Snarl"="c:\program files (x86)\full phat\Snarl\snarl.exe" [2011-05-25 925696]

"Tonido"="c:\users\Hayden\AppData\Roaming\Tonido\launcher.exe" [2011-11-14 100864]

"MusicManager"="c:\users\Hayden\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [2012-06-01 13806592]

"GoToMeeting"="c:\program files (x86)\Citrix\GoToMeeting\952\g2mstart.exe" [2012-05-25 39816]

"Spotify Web Helper"="c:\users\Hayden\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-30 932528]

"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]

"GoogleChromeAutoLaunch_7BA29E3153B77E65C37077A2469120EB"="c:\users\Hayden\AppData\Local\Google\Chrome\Application\chrome.exe" [2012-07-10 1250328]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]

"AVG9_TRAY"="c:\progra~2\AVG\AVG9\avgtray.exe" [2012-01-26 2077536]

"VolPanel"="c:\program files (x86)\Creative\Volume Panel\VolPanlu.exe" [2008-08-06 233576]

"CTxfiHlp"="CTXFIHLP.EXE" [2009-07-14 24576]

"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]

"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]

"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]

"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]

"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2012-05-03 217256]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]

"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-05-01 1895424]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]

.

c:\users\Hayden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

CurseClientStartup.ccip [2010-12-7 0]

Dropbox.lnk - c:\users\Hayden\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]

EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2012-6-13 1014112]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]

Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2011-8-21 102912]

Subsonic.lnk - c:\program files (x86)\Subsonic\subsonic-agent.exe [2011-12-6 206336]

UltraMon.lnk - c:\windows\Installer\{B49673F8-7AB6-4A14-8213-C8A7BE370010}\IcoUltraMon.ico [2010-8-23 29310]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

"HideShutdownScripts"= 0 (0x0)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"MaxRecentDocs"= 99 (0x63)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2011-09-10 18432]

R2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-04-02 90112]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [x]

R2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-02 67400]

R2 MSSQL$MSSQL;SQL Server (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\sqlservr.exe [2010-04-03 61913952]

R2 ReportServer$MSSQL;SQL Server Reporting Services (MSSQL);c:\program files\Microsoft SQL Server\MSRS10_50.MSSQL\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2010-04-03 2175328]

R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]

R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2009-10-31 79360]

R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-31 79360]

R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-08 230488]

R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]

R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-08 95320]

R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [x]

R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-07 113120]

R3 MSSQLFDLauncher$MSSQL;SQL Full-text Filter Daemon Launcher (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\fdlauncher.exe [2010-04-03 32096]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]

R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2012-05-29 19952]

R3 SQLAgent$MSSQL;SQL Server Agent (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\SQLAGENT.EXE [2010-04-03 428384]

R3 SSMO3v2Filter;MMO3v2 Mouse;c:\windows\system32\drivers\MO3v2Driver.sys [2010-11-22 23040]

R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]

R3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM10864.sys [2010-08-13 1310720]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-10 1255736]

R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]

R3 WMSVC;Web Management Service;c:\windows\system32\inetsrv\wmsvc.exe [2009-07-14 10752]

R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]

R4 RsFx0150;RsFx0150 Driver;c:\windows\system32\DRIVERS\RsFx0150.sys [2010-04-03 313696]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

S0 AvgRkx64;avgrkx64.sys;c:\windows\System32\Drivers\avgrkx64.sys [2010-03-29 56008]

S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-12 503352]

S1 AvgLdx64;AVG AVI Loader Driver x64;c:\windows\System32\Drivers\avgldx64.sys [2010-06-22 269904]

S1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;c:\windows\System32\Drivers\avgmfx64.sys [2011-09-13 35664]

S1 AvgTdiA;AVG Network Redirector x64;c:\windows\System32\Drivers\avgtdia.sys [2011-05-06 317520]

S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]

S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]

S2 avg9emc;AVG E-mail Scanner;c:\program files (x86)\AVG\AVG9\avgemc.exe [2010-07-21 921952]

S2 avg9wd;AVG WatchDog;c:\program files (x86)\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]

S2 DeviceMonitorService;DeviceMonitorService;c:\program files (x86)\Motorola Media Link\Lite\NServiceEntry.exe [2012-06-05 87400]

S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2011-11-08 14216]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]

S2 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-06-05 116632]

S2 MSOLAP$MSSQL;SQL Server Analysis Services (MSSQL);c:\program files\Microsoft SQL Server\MSAS10_50.MSSQL\OLAP\bin\msmdsrv.exe [2010-04-03 54568288]

S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2012-04-12 204304]

S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\NLSSRV32.EXE [2012-06-25 69640]

S2 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2011-09-02 65657]

S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2008-11-14 20512]

S2 WDDMService.exe;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-08-17 116224]

S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]

S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]

S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-08 230488]

S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]

S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-08 95320]

S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys [2010-05-22 66728]

S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-08 1612888]

S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2010-12-12 22408]

S3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys [2009-07-01 30728]

S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2010-12-12 16008]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]

S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]

S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]

S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-09-28 395264]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

iissvcs REG_MULTI_SZ w3svc was

apphost REG_MULTI_SZ apphostsvc

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Contents of the 'Scheduled Tasks' folder

.

2012-07-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000Core.job

- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]

.

2012-07-13 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000UA.job

- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]

.

.

Link to post
Share on other sites

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 97792 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 97792 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 97792 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]

@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 97792 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-06-15 110360]

"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]

"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]

"Cm108Sound"="c:\windows\Syswow64\cm108.dll" [2010-10-13 8757248]

.

------- Supplementary Scan -------

.

uStart Page =

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local;192.168.*.*

IE: &Verzenden naar OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105

IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000

Trusted Zone: clonewarsadventures.com

Trusted Zone: freerealms.com

Trusted Zone: soe.com

Trusted Zone: sony.com

TCP: DhcpNameServer = 192.168.1.254

DPF: {EF0D1A14-1033-41A2-A589-240C01EDC078} - hxxp://dl.pplive.com/PluginSetup.cab

FF - ProfilePath - c:\users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\

.

- - - - ORPHANS REMOVED - - - -

.

WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)

.

.

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MsDepSvc]

"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]

@Denied: (2) (S-1-5-21-645954481-4171391755-2920796181-1000)

@Denied: (2) (LocalSystem)

"Progid"="ThunderbirdEML"

.

[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.VCard.1"

.

[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\SecuROM\License information*]

"datasecu"=hex:97,d2,c9,85,02,71,88,e1,fc,ae,42,fe,02,8d,8e,24,19,8e,34,38,98,

bf,29,19,59,bb,61,f1,77,18,e7,bc,4a,35,98,08,f1,6c,21,76,ba,c6,fb,cc,72,f4,\

"rkeysecu"=hex:79,fe,52,e1,00,f1,26,9b,6e,10,c9,f7,ce,d0,27,3d

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.10"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}]

@Denied: (A) (Everyone)

"Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane\0]

"Key"="ActionsPane"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files (x86)\Bonjour\mDNSResponder.exe

c:\xampp\filezillaftp\filezillaserver.exe

c:\program files (x86)\Windows Media Player\wmplayer.exe

c:\windows\SysWOW64\rundll32.exe

c:\users\Hayden\AppData\Roaming\Tonido\tonido.exe

c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

c:\program files (x86)\Motorola Mobility\MotoCast\MotoCast.exe

c:\program files (x86)\AVG\AVG9\avgtray.exe

c:\windows\SysWOW64\Ctxfihlp.exe

c:\windows\SysWOW64\CTXFISPI.EXE

c:\xampp\mysql\bin\mysqld.exe

c:\program files (x86)\Citrix\GoToMeeting\952\g2mcomm.exe

c:\program files (x86)\full phat\Snarl\extensions\AudioMon\snarl-audiomon.exe

c:\program files (x86)\Citrix\GoToMeeting\952\g2mlauncher.exe

c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe

c:\program files (x86)\AVG\AVG9\avgcsrvx.exe

c:\program files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe

c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDMovieViewer.exe

c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDWebCam.exe

c:\program files\Logitech Gaming Software\plugins\LCDAppletsMono-8.00.048\Applets\x86\LCDMedia.exe

c:\users\Hayden\Desktop\downloads\SirReal\LCDSirReal.exe

c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDYT.exe

c:\program files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe

c:\program files (x86)\HP\Digital Imaging\bin\hpqbam08.exe

c:\program files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe

c:\program files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe

.

**************************************************************************

.

Completion time: 2012-07-13 18:57:19 - machine was rebooted

ComboFix-quarantined-files.txt 2012-07-13 23:57

ComboFix2.txt 2012-07-12 01:30

ComboFix3.txt 2012-07-08 00:33

.

Pre-Run: 96,251,113,472 bytes free

Post-Run: 96,319,385,600 bytes free

.

- - End Of File - - 806BEEB66FCDFB4B1CADDE76F1176FB8

Link to post
Share on other sites

1. Close any open browsers.

2. Close/disable all anti virus and anti malware programs so they do not interfere with the running of ComboFix.

3. Open notepad and copy/paste the text in the quotebox below into it:

Folder::
c:\users\Hayden\AppData\Local\blekkotb_031

JavaClearCache::

Save this as CFScript.txt, in the same location as ComboFix.exe

CFScriptB-4.gif

Refering to the picture above, drag CFScript into ComboFix.exe

When finished, it shall produce a log for you at C:\ComboFix.txt which I will require in your next reply.

Link to post
Share on other sites

<p> </p>

<div>ComboFix 12-07-13.03 - Hayden 07/16/2012   4:51.4.8 - x64</div>

<div>Microsoft Windows 7 Professional   6.1.7600.0.1252.1.1033.18.12279.7905 [GMT -5:00]</div>

<div>Running from: c:\users\Hayden\Desktop\ComboFix.exe</div>

<div>Command switches used :: c:\users\Hayden\Desktop\CFScript.txt</div>

<div>AV: AVG Anti-Virus *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}</div>

<div>SP: AVG Anti-Virus *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}</div>

<div>SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}</div>

<div>.</div>

<div>.</div>

<div>(((((((((((((((((((((((((((((((((((((((   Other Deletions   )))))))))))))))))))))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>.</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\catalog.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163606-f.list</div>

<div>c:\users\Hayden\AppData\Local\blekkotb_031\data\temp.zip</div>

<div>.</div>

<div>.</div>

<div>(((((((((((((((((((((((((   Files Created from 2012-06-16 to 2012-07-16  )))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>.</div>

<div>2012-07-16 10:10 . 2012-07-16 10:11<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Local\blekkotb_031</div>

<div>2012-07-16 10:06 . 2012-07-16 10:06<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\LogMeInRemoteUser\AppData\Local\temp</div>

<div>2012-07-16 10:06 . 2012-07-16 10:06<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Default\AppData\Local\temp</div>

<div>2012-07-16 10:06 . 2012-07-16 10:06<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Classic .NET AppPool\AppData\Local\temp</div>

<div>2012-07-15 21:27 . 2012-07-15 21:27<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\temp</div>

<div>2012-07-15 21:27 . 2012-07-15 22:32<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\TeamViewer</div>

<div>2012-07-12 18:10 . 2012-07-09 03:57<span class="Apple-tab-span" style="white-space:pre"> </span>17928<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\nitrolocalui2.dll</div>

<div>2012-07-12 18:10 . 2012-04-12 03:55<span class="Apple-tab-span" style="white-space:pre"> </span>29712<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\nitrolocalmon2.dll</div>

<div>2012-07-12 18:10 . 2012-07-15 23:53<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files\Common Files\Nitro PDF</div>

<div>2012-07-12 18:10 . 2012-07-12 18:10<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Common Files\Nitro PDF</div>

<div>2012-07-12 18:09 . 2012-07-15 23:53<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Nitro PDF</div>

<div>2012-07-10 23:48 . 2012-07-10 23:48<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\programdata\ATI</div>

<div>2012-07-10 23:47 . 2012-07-10 23:47<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\AMD APP</div>

<div>2012-07-10 23:00 . 2012-07-10 23:00<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>C:\_OTL</div>

<div>2012-07-09 22:27 . 2012-07-09 22:27<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\KeePass Password Safe 2</div>

<div>2012-07-07 22:36 . 2012-07-07 22:36<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>C:\TDSSKiller_Quarantine</div>

<div>2012-07-07 18:57 . 2012-07-07 18:57<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Malwarebytes</div>

<div>2012-07-07 18:56 . 2012-07-12 06:32<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Malwarebytes' Anti-Malware</div>

<div>2012-07-07 18:56 . 2012-07-07 18:56<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\programdata\Malwarebytes</div>

<div>2012-07-07 18:56 . 2012-07-03 18:46<span class="Apple-tab-span" style="white-space:pre"> </span>24904<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\drivers\mbam.sys</div>

<div>2012-07-07 06:02 . 2012-07-07 06:02<span class="Apple-tab-span" style="white-space:pre"> </span>770384<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Mozilla Firefox\msvcr100.dll</div>

<div>2012-07-07 06:02 . 2012-07-07 06:02<span class="Apple-tab-span" style="white-space:pre"> </span>421200<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Mozilla Firefox\msvcp100.dll</div>

<div>2012-07-06 19:18 . 2012-07-11 00:43<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>C:\subsonic</div>

<div>2012-07-06 19:18 . 2012-07-06 19:18<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Subsonic</div>

<div>2012-07-02 18:01 . 2012-07-02 18:01<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\.pdfsam</div>

<div>2012-07-02 16:17 . 2012-07-02 16:17<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\pdfsam</div>

<div>2012-07-02 16:07 . 2012-07-04 20:37<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\ParmisPDF</div>

<div>2012-07-02 15:49 . 2012-07-16 00:50<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\PrimoPDF</div>

<div>2012-07-02 15:48 . 2012-07-12 18:09<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\OpenCandy</div>

<div>2012-07-02 15:48 . 2011-02-28 22:37<span class="Apple-tab-span" style="white-space:pre"> </span>95008<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\Primomonnt.dll</div>

<div>2012-07-02 05:32 . 2012-07-02 05:32<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Maxis</div>

<div>2012-07-01 07:33 . 2012-07-01 07:33<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\EAC</div>

<div>2012-07-01 07:33 . 2012-07-01 07:33<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Exact Audio Copy</div>

<div>2012-07-01 07:32 . 2012-07-01 07:32<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\programdata\Anti-phishing Domain Advisor</div>

<div>2012-06-27 22:19 . 2012-07-11 01:44<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Nitro PDF</div>

<div>2012-06-27 22:18 . 2012-07-02 15:51<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\programdata\Nitro PDF</div>

<div>2012-06-27 19:50 . 2012-06-27 20:00<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\.cpan</div>

<div>2012-06-25 00:35 . 2012-06-25 00:35<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\programdata\phpDesigner</div>

<div>2012-06-20 01:45 . 2012-06-20 01:45<span class="Apple-tab-span" style="white-space:pre"> </span>--------<span class="Apple-tab-span" style="white-space:pre"> </span>d-----w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\program files (x86)\Motorola Media Link</div>

<div>.</div>

<div>.</div>

<div>.</div>

<div>((((((((((((((((((((((((((((((((((((((((   Find3M Report   ))))))))))))))))))))))))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>2012-06-25 02:47 . 2012-06-25 02:47<span class="Apple-tab-span" style="white-space:pre"> </span>69640<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\NLSSRV32.EXE</div>

<div>2012-06-18 08:12 . 2012-07-14 09:13<span class="Apple-tab-span" style="white-space:pre"> </span>9013136<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\programdata\Microsoft\Windows Defender\Definition Updates\{64F715D4-D5D8-42C8-9209-8D5798168556}\mpengine.dll</div>

<div>2012-06-11 18:59 . 2012-06-11 18:59<span class="Apple-tab-span" style="white-space:pre"> </span>10248192<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\drivers\atikmdag.sys</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50<span class="Apple-tab-span" style="white-space:pre"> </span>187392<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\clinfo.exe</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50<span class="Apple-tab-span" style="white-space:pre"> </span>75264<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\OpenVideo64.dll</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50<span class="Apple-tab-span" style="white-space:pre"> </span>65024<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\OpenVideo.dll</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50<span class="Apple-tab-span" style="white-space:pre"> </span>63488<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\OVDecode64.dll</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50<span class="Apple-tab-span" style="white-space:pre"> </span>56320<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\OVDecode.dll</div>

<div>2012-06-11 18:50 . 2012-06-11 18:50<span class="Apple-tab-span" style="white-space:pre"> </span>16457728<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\amdocl64.dll</div>

<div>2012-06-11 18:49 . 2012-06-11 18:49<span class="Apple-tab-span" style="white-space:pre"> </span>13008896<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\amdocl.dll</div>

<div>2012-06-11 18:35 . 2012-06-11 18:35<span class="Apple-tab-span" style="white-space:pre"> </span>70144<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\coinst_8.98.dll</div>

<div>2012-06-11 18:29 . 2011-10-26 02:16<span class="Apple-tab-span" style="white-space:pre"> </span>24826368<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atio6axx.dll</div>

<div>2012-06-11 18:00 . 2012-06-11 18:00<span class="Apple-tab-span" style="white-space:pre"> </span>20467712<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atioglxx.dll</div>

<div>2012-06-11 17:25 . 2012-06-11 17:25<span class="Apple-tab-span" style="white-space:pre"> </span>163840<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiapfxx.exe</div>

<div>2012-06-11 17:24 . 2011-12-06 03:17<span class="Apple-tab-span" style="white-space:pre"> </span>924160<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\aticfx32.dll</div>

<div>2012-06-11 17:23 . 2011-10-26 02:04<span class="Apple-tab-span" style="white-space:pre"> </span>1090560<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\aticfx64.dll</div>

<div>2012-06-11 17:20 . 2012-06-11 17:20<span class="Apple-tab-span" style="white-space:pre"> </span>442368<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\ATIDEMGX.dll</div>

<div>2012-06-11 17:19 . 2012-06-11 17:19<span class="Apple-tab-span" style="white-space:pre"> </span>532992<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atieclxx.exe</div>

<div>2012-06-11 17:19 . 2012-06-11 17:19<span class="Apple-tab-span" style="white-space:pre"> </span>239616<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiesrxx.exe</div>

<div>2012-06-11 17:17 . 2012-06-11 17:17<span class="Apple-tab-span" style="white-space:pre"> </span>120320<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atitmm64.dll</div>

<div>2012-06-11 17:17 . 2012-06-11 17:17<span class="Apple-tab-span" style="white-space:pre"> </span>21504<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atimuixx.dll</div>

<div>2012-06-11 17:17 . 2012-06-11 17:17<span class="Apple-tab-span" style="white-space:pre"> </span>59392<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiedu64.dll</div>

<div>2012-06-11 17:17 . 2012-06-11 17:17<span class="Apple-tab-span" style="white-space:pre"> </span>43520<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\ati2edxx.dll</div>

<div>2012-06-11 17:16 . 2012-06-11 17:16<span class="Apple-tab-span" style="white-space:pre"> </span>6301696<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atidxx32.dll</div>

<div>2012-06-11 17:01 . 2012-06-11 17:01<span class="Apple-tab-span" style="white-space:pre"> </span>6914560<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atidxx64.dll</div>

<div>2012-06-11 16:51 . 2012-06-11 16:51<span class="Apple-tab-span" style="white-space:pre"> </span>4246528<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiumd6a.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45<span class="Apple-tab-span" style="white-space:pre"> </span>51200<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\aticalrt64.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45<span class="Apple-tab-span" style="white-space:pre"> </span>46080<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\aticalrt.dll</div>

<div>2012-06-11 16:45 . 2011-12-06 02:33<span class="Apple-tab-span" style="white-space:pre"> </span>5480448<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atiumdag.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45<span class="Apple-tab-span" style="white-space:pre"> </span>44544<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\aticalcl64.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45<span class="Apple-tab-span" style="white-space:pre"> </span>44032<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\aticalcl.dll</div>

<div>2012-06-11 16:45 . 2012-06-11 16:45<span class="Apple-tab-span" style="white-space:pre"> </span>15703040<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\aticaldd64.dll</div>

<div>2012-06-11 16:43 . 2011-12-06 02:28<span class="Apple-tab-span" style="white-space:pre"> </span>4729344<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atiumdva.dll</div>

<div>2012-06-11 16:40 . 2012-06-11 16:40<span class="Apple-tab-span" style="white-space:pre"> </span>13277696<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\aticaldd.dll</div>

<div>2012-06-11 16:36 . 2012-06-11 16:36<span class="Apple-tab-span" style="white-space:pre"> </span>6605824<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiumd64.dll</div>

<div>2012-06-11 16:27 . 2011-10-26 01:22<span class="Apple-tab-span" style="white-space:pre"> </span>539136<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiadlxx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26<span class="Apple-tab-span" style="white-space:pre"> </span>368640<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atiadlxy.dll</div>

<div>2012-06-11 16:26 . 2011-10-26 01:22<span class="Apple-tab-span" style="white-space:pre"> </span>17920<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atig6pxx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26<span class="Apple-tab-span" style="white-space:pre"> </span>14848<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atiglpxx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26<span class="Apple-tab-span" style="white-space:pre"> </span>14848<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiglpxx.dll</div>

<div>2012-06-11 16:26 . 2011-10-26 01:22<span class="Apple-tab-span" style="white-space:pre"> </span>41984<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atig6txx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26<span class="Apple-tab-span" style="white-space:pre"> </span>33280<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atigktxx.dll</div>

<div>2012-06-11 16:26 . 2012-06-11 16:26<span class="Apple-tab-span" style="white-space:pre"> </span>367616<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\drivers\atikmpag.sys</div>

<div>2012-06-11 16:25 . 2010-11-26 02:16<span class="Apple-tab-span" style="white-space:pre"> </span>54784<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiuxp64.dll</div>

<div>2012-06-11 16:25 . 2012-06-11 16:25<span class="Apple-tab-span" style="white-space:pre"> </span>42496<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atiuxpag.dll</div>

<div>2012-06-11 16:25 . 2012-06-11 16:25<span class="Apple-tab-span" style="white-space:pre"> </span>45056<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atiu9p64.dll</div>

<div>2012-06-11 16:24 . 2010-11-26 02:15<span class="Apple-tab-span" style="white-space:pre"> </span>32768<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atiu9pag.dll</div>

<div>2012-06-11 16:24 . 2012-06-11 16:24<span class="Apple-tab-span" style="white-space:pre"> </span>53248<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\drivers\ati2erec.dll</div>

<div>2012-06-11 16:23 . 2012-06-11 16:23<span class="Apple-tab-span" style="white-space:pre"> </span>56320<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\atimpc64.dll</div>

<div>2012-06-11 16:23 . 2012-06-11 16:23<span class="Apple-tab-span" style="white-space:pre"> </span>56320<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\amdpcom64.dll</div>

<div>2012-06-11 16:23 . 2012-06-11 16:23<span class="Apple-tab-span" style="white-space:pre"> </span>56832<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\atimpc32.dll</div>

<div>2012-06-11 16:23 . 2012-06-11 16:23<span class="Apple-tab-span" style="white-space:pre"> </span>56832<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\SysWow64\amdpcom32.dll</div>

<div>2012-05-31 17:25 . 2009-10-30 23:04<span class="Apple-tab-span" style="white-space:pre"> </span>279656<span class="Apple-tab-span" style="white-space:pre"> </span>------w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\windows\system32\MpSigStub.exe</div>

<div>.</div>

<div>.</div>

<div>(((((((((((((((((((((((((((((   SnapShot_2012-07-12_01.06.01   )))))))))))))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>+ 2009-10-30 23:27 . 2012-07-16 10:15<span class="Apple-tab-span" style="white-space:pre"> </span>94352              c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin</div>

<div>+ 2009-07-14 05:10 . 2012-07-16 10:15<span class="Apple-tab-span" style="white-space:pre"> </span>31822              c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin</div>

<div>+ 2009-10-30 22:49 . 2012-07-16 10:15<span class="Apple-tab-span" style="white-space:pre"> </span>16026              c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-645954481-4171391755-2920796181-1000_UserData.bin</div>

<div>+ 2012-07-12 18:10 . 2012-04-12 03:55<span class="Apple-tab-span" style="white-space:pre"> </span>83472              c:\windows\system32\spool\drivers\x64\NitroReaderUI2.dll</div>

<div>+ 2012-07-12 18:10 . 2012-04-12 03:55<span class="Apple-tab-span" style="white-space:pre"> </span>45584              c:\windows\system32\spool\drivers\x64\NitroReaderGraphics2.dll</div>

<div>+ 2009-10-31 00:26 . 2012-07-13 09:10<span class="Apple-tab-span" style="white-space:pre"> </span>49152              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>- 2009-10-31 00:26 . 2012-07-11 00:47<span class="Apple-tab-span" style="white-space:pre"> </span>49152              c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>+ 2012-07-10 23:27 . 2012-07-13 09:10<span class="Apple-tab-span" style="white-space:pre"> </span>32768              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat</div>

<div>- 2012-07-10 23:27 . 2012-07-11 00:47<span class="Apple-tab-span" style="white-space:pre"> </span>32768              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat</div>

<div>+ 2009-07-14 04:54 . 2012-07-13 09:10<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>- 2009-07-14 04:54 . 2012-07-11 00:47<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-16 10:14<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10<span class="Apple-tab-span" style="white-space:pre"> </span>32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-16 10:14<span class="Apple-tab-span" style="white-space:pre"> </span>32768              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-16 10:14<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-16 10:14<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat</div>

<div>+ 2009-10-30 22:48 . 2012-07-16 10:14<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>- 2009-10-30 22:48 . 2012-07-12 01:10<span class="Apple-tab-span" style="white-space:pre"> </span>16384              c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat</div>

<div>- 2012-07-12 01:04 . 2012-07-12 01:04<span class="Apple-tab-span" style="white-space:pre"> </span>2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat</div>

<div>+ 2012-07-16 10:08 . 2012-07-16 10:08<span class="Apple-tab-span" style="white-space:pre"> </span>2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat</div>

<div>+ 2012-07-16 10:08 . 2012-07-16 10:08<span class="Apple-tab-span" style="white-space:pre"> </span>2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat</div>

<div>- 2012-07-12 01:04 . 2012-07-12 01:04<span class="Apple-tab-span" style="white-space:pre"> </span>2048              c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat</div>

<div>+ 2012-07-02 15:48 . 2011-02-28 22:37<span class="Apple-tab-span" style="white-space:pre"> </span>738080              c:\windows\system32\spool\drivers\x64\3\pscript5.dll</div>

<div>+ 2012-07-02 15:48 . 2011-02-28 22:37<span class="Apple-tab-span" style="white-space:pre"> </span>241952              c:\windows\system32\spool\drivers\x64\3\ps5ui.dll</div>

<div>+ 2009-07-14 05:01 . 2012-07-16 10:07<span class="Apple-tab-span" style="white-space:pre"> </span>515388              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat</div>

<div>- 2009-07-14 05:01 . 2012-07-12 01:02<span class="Apple-tab-span" style="white-space:pre"> </span>515388              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat</div>

<div>- 2010-01-23 09:16 . 2012-07-12 01:02<span class="Apple-tab-span" style="white-space:pre"> </span>1350152              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat</div>

<div>+ 2010-01-23 09:16 . 2012-07-16 10:07<span class="Apple-tab-span" style="white-space:pre"> </span>1350152              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat</div>

<div>+ 2009-07-14 02:34 . 2012-07-15 06:42<span class="Apple-tab-span" style="white-space:pre"> </span>10485760              c:\windows\system32\SMI\Store\Machine\schema.dat</div>

<div>- 2009-07-14 02:34 . 2012-07-11 10:16<span class="Apple-tab-span" style="white-space:pre"> </span>10485760              c:\windows\system32\SMI\Store\Machine\schema.dat</div>

<div>+ 2010-02-26 09:22 . 2012-07-16 10:07<span class="Apple-tab-span" style="white-space:pre"> </span>24521432              c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-645954481-4171391755-2920796181-1000-12288.dat</div>

<div>+ 2012-04-30 21:43 . 2012-04-30 21:43<span class="Apple-tab-span" style="white-space:pre"> </span>45831680              c:\windows\Installer\27a2bc1.msi</div>

<div>.</div>

<div>(((((((((((((((((((((((((((((((((((((   Reg Loading Points   ))))))))))))))))))))))))))))))))))))))))))))))))))</div>

<div>.</div>

<div>.</div>

<div>*Note* empty entries & legit default entries are not shown </div>

<div>REGEDIT4</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]</div>

<div>@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space:pre"> </span>94208<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]</div>

<div>@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space:pre"> </span>94208<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]</div>

<div>@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space:pre"> </span>94208<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]</div>

<div>@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"</div>

<div>[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]</div>

<div>2011-12-05 19:17<span class="Apple-tab-span" style="white-space:pre"> </span>94208<span class="Apple-tab-span" style="white-space:pre"> </span>----a-w-<span class="Apple-tab-span" style="white-space:pre"> </span>c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll</div>

<div>.</div>

<div>[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]</div>

<div>"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-02 1242448]</div>

<div>"AlcoholAutomount"="c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]</div>

<div>"Xvid"="c:\program files (x86)\XviD\CheckUpdate.exe" [2011-01-17 8192]</div>

<div>"Snarl"="c:\program files (x86)\full phat\Snarl\snarl.exe" [2011-05-25 925696]</div>

<div>"Tonido"="c:\users\Hayden\AppData\Roaming\Tonido\launcher.exe" [2011-11-14 100864]</div>

<div>"MusicManager"="c:\users\Hayden\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [2012-06-01 13806592]</div>

<div>"GoToMeeting"="c:\program files (x86)\Citrix\GoToMeeting\952\g2mstart.exe" [2012-05-25 39816]</div>

<div>"Spotify Web Helper"="c:\users\Hayden\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-30 932528]</div>

<div>"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]</div>

<div>"GoogleChromeAutoLaunch_7BA29E3153B77E65C37077A2469120EB"="c:\users\Hayden\AppData\Local\Google\Chrome\Application\chrome.exe" [2012-07-10 1250328]</div>

<div>"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2011-10-03 393216]</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]</div>

<div>"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]</div>

<div>"AVG9_TRAY"="c:\progra~2\AVG\AVG9\avgtray.exe" [2012-01-26 2077536]</div>

<div>"VolPanel"="c:\program files (x86)\Creative\Volume Panel\VolPanlu.exe" [2008-08-06 233576]</div>

<div>"CTxfiHlp"="CTXFIHLP.EXE" [2009-07-14 24576]</div>

<div>"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]</div>

<div>"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]</div>

<div>"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]</div>

<div>"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]</div>

<div>"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]</div>

<div>"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]</div>

<div>"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]</div>

<div>"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]</div>

<div>"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2012-05-03 217256]</div>

<div>"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]</div>

<div>"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-05-01 1895424]</div>

<div>"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704]</div>

<div>.</div>

<div>[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]</div>

<div>"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]</div>

<div>.</div>

<div>c:\users\Hayden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\</div>

<div>CurseClientStartup.ccip [2010-12-7 0]</div>

<div>Dropbox.lnk - c:\users\Hayden\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]</div>

<div>EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2012-6-13 1014112]</div>

<div>.</div>

<div>c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\</div>

<div>HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]</div>

<div>Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2011-8-21 102912]</div>

<div>Subsonic.lnk - c:\program files (x86)\Subsonic\subsonic-agent.exe [2011-12-6 206336]</div>

<div>UltraMon.lnk - c:\windows\Installer\{B49673F8-7AB6-4A14-8213-C8A7BE370010}\IcoUltraMon.ico [2010-8-23 29310]</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]</div>

<div>"ConsentPromptBehaviorAdmin"= 0 (0x0)</div>

<div>"ConsentPromptBehaviorUser"= 3 (0x3)</div>

<div>"EnableLUA"= 0 (0x0)</div>

<div>"EnableUIADesktopToggle"= 0 (0x0)</div>

<div>"PromptOnSecureDesktop"= 0 (0x0)</div>

<div>"HideShutdownScripts"= 0 (0x0)</div>

<div>.</div>

<div>[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]</div>

<div>"MaxRecentDocs"= 99 (0x63)</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]</div>

<div>Security Packages<span class="Apple-tab-span" style="white-space:pre"> </span>REG_MULTI_SZ   <span class="Apple-tab-span" style="white-space:pre"> </span>kerberos msv1_0 schannel wdigest tspkg pku2u livessp</div>

<div>.</div>

<div>R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2011-09-10 18432]</div>

<div>R2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-04-02 90112]</div>

<div>R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]</div>

<div>R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [x]</div>

<div>R2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-02 67400]</div>

<div>R2 MSSQL$MSSQL;SQL Server (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\sqlservr.exe [2010-04-03 61913952]</div>

<div>R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]</div>

<div>R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2009-10-31 79360]</div>

<div>R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-31 79360]</div>

<div>R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-08 230488]</div>

<div>R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]</div>

<div>R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-08 95320]</div>

<div>R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [x]</div>

<div>R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-07 113120]</div>

<div>R3 MSSQLFDLauncher$MSSQL;SQL Full-text Filter Daemon Launcher (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\fdlauncher.exe [2010-04-03 32096]</div>

<div>R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]</div>

<div>R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2012-05-29 19952]</div>

<div>R3 SQLAgent$MSSQL;SQL Server Agent (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\SQLAGENT.EXE [2010-04-03 428384]</div>

<div>R3 SSMO3v2Filter;MMO3v2 Mouse;c:\windows\system32\drivers\MO3v2Driver.sys [2010-11-22 23040]</div>

<div>R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]</div>

<div>R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]</div>

<div>R3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM10864.sys [2010-08-13 1310720]</div>

<div>R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-10 1255736]</div>

<div>R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]</div>

<div>R3 WMSVC;Web Management Service;c:\windows\system32\inetsrv\wmsvc.exe [2009-07-14 10752]</div>

<div>R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]</div>

<div>R4 RsFx0150;RsFx0150 Driver;c:\windows\system32\DRIVERS\RsFx0150.sys [2010-04-03 313696]</div>

<div>R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]</div>

<div>S0 AvgRkx64;avgrkx64.sys;c:\windows\System32\Drivers\avgrkx64.sys [2010-03-29 56008]</div>

<div>S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-12 503352]</div>

<div>S1 AvgLdx64;AVG AVI Loader Driver x64;c:\windows\System32\Drivers\avgldx64.sys [2010-06-22 269904]</div>

<div>S1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;c:\windows\System32\Drivers\avgmfx64.sys [2011-09-13 35664]</div>

<div>S1 AvgTdiA;AVG Network Redirector x64;c:\windows\System32\Drivers\avgtdia.sys [2011-05-06 317520]</div>

<div>S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]</div>

<div>S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]</div>

<div>S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]</div>

<div>S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]</div>

<div>S2 avg9emc;AVG E-mail Scanner;c:\program files (x86)\AVG\AVG9\avgemc.exe [2010-07-21 921952]</div>

<div>S2 avg9wd;AVG WatchDog;c:\program files (x86)\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]</div>

<div>S2 DeviceMonitorService;DeviceMonitorService;c:\program files (x86)\Motorola Media Link\Lite\NServiceEntry.exe [2012-06-05 87400]</div>

<div>S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2011-11-08 14216]</div>

<div>S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]</div>

<div>S2 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-06-05 116632]</div>

<div>S2 MSOLAP$MSSQL;SQL Server Analysis Services (MSSQL);c:\program files\Microsoft SQL Server\MSAS10_50.MSSQL\OLAP\bin\msmdsrv.exe [2010-04-03 54568288]</div>

<div>S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2012-04-12 204304]</div>

<div>S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\NLSSRV32.EXE [2012-06-25 69640]</div>

<div>S2 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2011-09-02 65657]</div>

<div>S2 ReportServer$MSSQL;SQL Server Reporting Services (MSSQL);c:\program files\Microsoft SQL Server\MSRS10_50.MSSQL\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2010-04-03 2175328]</div>

<div>S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2008-11-14 20512]</div>

<div>S2 WDDMService.exe;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-08-17 116224]</div>

<div>S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]</div>

<div>S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]</div>

<div>S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]</div>

<div>S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-08 230488]</div>

<div>S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]</div>

<div>S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-08 95320]</div>

<div>S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys [2010-05-22 66728]</div>

<div>S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-08 1612888]</div>

<div>S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2010-12-12 22408]</div>

<div>S3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys [2009-07-01 30728]</div>

<div>S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2010-12-12 16008]</div>

<div>S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]</div>

<div>S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]</div>

<div>S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]</div>

<div>S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-09-28 395264]</div>

<div>.</div>

<div>.</div>

<div>[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]</div>

<div>iissvcs<span class="Apple-tab-span" style="white-space:pre"> </span>REG_MULTI_SZ   <span class="Apple-tab-span" style="white-space:pre"> </span>w3svc was</div>

<div>apphost<span class="Apple-tab-span" style="white-space:pre"> </span>REG_MULTI_SZ   <span class="Apple-tab-span" style="white-space:pre"> </span>apphostsvc</div>

<div>hpdevmgmt<span class="Apple-tab-span" style="white-space:pre"> </span>REG_MULTI_SZ   <span class="Apple-tab-span" style="white-space:pre"> </span>hpqcxs08 hpqddsvc</div>

<div>.</div>

<div>Contents of the 'Scheduled Tasks' folder</div>

<div>.</div>

<div>2012-07-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000Core.job</div>

<div>- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]</div>

<div>.</div>

<div>2012-07-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000UA.job</div>

<div>- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]</div>

<div>.</div>

<div>.</div>

Link to post
Share on other sites

This forum hates me... Take 2.

ComboFix 12-07-13.03 - Hayden 07/16/2012 4:51.4.8 - x64

Microsoft Windows 7 Professional 6.1.7600.0.1252.1.1033.18.12279.7905 [GMT -5:00]

Running from: c:\users\Hayden\Desktop\ComboFix.exe

Command switches used :: c:\users\Hayden\Desktop\CFScript.txt

AV: AVG Anti-Virus *Disabled/Updated* {5A2746B1-DEE9-F85A-FBCD-ADB11639C5F0}

SP: AVG Anti-Virus *Disabled/Updated* {E146A755-F8D3-F7D4-C17D-96C36DBE8F4D}

SP: Windows Defender *Enabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}

.

.

((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))

.

.

c:\users\Hayden\AppData\Local\blekkotb_031

c:\users\Hayden\AppData\Local\blekkotb_031\catalog.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\120713163606-f.list

c:\users\Hayden\AppData\Local\blekkotb_031\data\temp.zip

.

.

((((((((((((((((((((((((( Files Created from 2012-06-16 to 2012-07-16 )))))))))))))))))))))))))))))))

.

.

2012-07-16 10:10 . 2012-07-16 10:11 -------- d-----w- c:\users\Hayden\AppData\Local\blekkotb_031

2012-07-16 10:06 . 2012-07-16 10:06 -------- d-----w- c:\users\LogMeInRemoteUser\AppData\Local\temp

2012-07-16 10:06 . 2012-07-16 10:06 -------- d-----w- c:\users\Default\AppData\Local\temp

2012-07-16 10:06 . 2012-07-16 10:06 -------- d-----w- c:\users\Classic .NET AppPool\AppData\Local\temp

2012-07-15 21:27 . 2012-07-15 21:27 -------- d-----w- c:\users\Hayden\temp

2012-07-15 21:27 . 2012-07-15 22:32 -------- d-----w- c:\users\Hayden\AppData\Roaming\TeamViewer

2012-07-12 18:10 . 2012-07-09 03:57 17928 ----a-w- c:\windows\system32\nitrolocalui2.dll

2012-07-12 18:10 . 2012-04-12 03:55 29712 ----a-w- c:\windows\system32\nitrolocalmon2.dll

2012-07-12 18:10 . 2012-07-15 23:53 -------- d-----w- c:\program files\Common Files\Nitro PDF

2012-07-12 18:10 . 2012-07-12 18:10 -------- d-----w- c:\program files (x86)\Common Files\Nitro PDF

2012-07-12 18:09 . 2012-07-15 23:53 -------- d-----w- c:\program files (x86)\Nitro PDF

2012-07-10 23:48 . 2012-07-10 23:48 -------- d-----w- c:\programdata\ATI

2012-07-10 23:47 . 2012-07-10 23:47 -------- d-----w- c:\program files (x86)\AMD APP

2012-07-10 23:00 . 2012-07-10 23:00 -------- d-----w- C:\_OTL

2012-07-09 22:27 . 2012-07-09 22:27 -------- d-----w- c:\program files (x86)\KeePass Password Safe 2

2012-07-07 22:36 . 2012-07-07 22:36 -------- d-----w- C:\TDSSKiller_Quarantine

2012-07-07 18:57 . 2012-07-07 18:57 -------- d-----w- c:\users\Hayden\AppData\Roaming\Malwarebytes

2012-07-07 18:56 . 2012-07-12 06:32 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware

2012-07-07 18:56 . 2012-07-07 18:56 -------- d-----w- c:\programdata\Malwarebytes

2012-07-07 18:56 . 2012-07-03 18:46 24904 ----a-w- c:\windows\system32\drivers\mbam.sys

2012-07-07 06:02 . 2012-07-07 06:02 770384 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr100.dll

2012-07-07 06:02 . 2012-07-07 06:02 421200 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp100.dll

2012-07-06 19:18 . 2012-07-11 00:43 -------- d-----w- C:\subsonic

2012-07-06 19:18 . 2012-07-06 19:18 -------- d-----w- c:\program files (x86)\Subsonic

2012-07-02 18:01 . 2012-07-02 18:01 -------- d-----w- c:\users\Hayden\.pdfsam

2012-07-02 16:17 . 2012-07-02 16:17 -------- d-----w- c:\program files (x86)\pdfsam

2012-07-02 16:07 . 2012-07-04 20:37 -------- d-----w- c:\users\Hayden\AppData\Roaming\ParmisPDF

2012-07-02 15:49 . 2012-07-16 00:50 -------- d-----w- c:\users\Hayden\AppData\Roaming\PrimoPDF

2012-07-02 15:48 . 2012-07-12 18:09 -------- d-----w- c:\users\Hayden\AppData\Roaming\OpenCandy

2012-07-02 15:48 . 2011-02-28 22:37 95008 ----a-w- c:\windows\system32\Primomonnt.dll

2012-07-02 05:32 . 2012-07-02 05:32 -------- d-----w- c:\program files (x86)\Maxis

2012-07-01 07:33 . 2012-07-01 07:33 -------- d-----w- c:\users\Hayden\AppData\Roaming\EAC

2012-07-01 07:33 . 2012-07-01 07:33 -------- d-----w- c:\program files (x86)\Exact Audio Copy

2012-07-01 07:32 . 2012-07-01 07:32 -------- d-----w- c:\programdata\Anti-phishing Domain Advisor

2012-06-27 22:19 . 2012-07-11 01:44 -------- d-----w- c:\users\Hayden\AppData\Roaming\Nitro PDF

2012-06-27 22:18 . 2012-07-02 15:51 -------- d-----w- c:\programdata\Nitro PDF

2012-06-27 19:50 . 2012-06-27 20:00 -------- d-----w- c:\users\Hayden\.cpan

2012-06-25 00:35 . 2012-06-25 00:35 -------- d-----w- c:\programdata\phpDesigner

2012-06-20 01:45 . 2012-06-20 01:45 -------- d-----w- c:\program files (x86)\Motorola Media Link

.

.

.

(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))

.

2012-06-25 02:47 . 2012-06-25 02:47 69640 ----a-w- c:\windows\SysWow64\NLSSRV32.EXE

2012-06-18 08:12 . 2012-07-14 09:13 9013136 ----a-w- c:\programdata\Microsoft\Windows Defender\Definition Updates\{64F715D4-D5D8-42C8-9209-8D5798168556}\mpengine.dll

2012-06-11 18:59 . 2012-06-11 18:59 10248192 ----a-w- c:\windows\system32\drivers\atikmdag.sys

2012-06-11 18:50 . 2012-06-11 18:50 187392 ----a-w- c:\windows\system32\clinfo.exe

2012-06-11 18:50 . 2012-06-11 18:50 75264 ----a-w- c:\windows\system32\OpenVideo64.dll

2012-06-11 18:50 . 2012-06-11 18:50 65024 ----a-w- c:\windows\SysWow64\OpenVideo.dll

2012-06-11 18:50 . 2012-06-11 18:50 63488 ----a-w- c:\windows\system32\OVDecode64.dll

2012-06-11 18:50 . 2012-06-11 18:50 56320 ----a-w- c:\windows\SysWow64\OVDecode.dll

2012-06-11 18:50 . 2012-06-11 18:50 16457728 ----a-w- c:\windows\system32\amdocl64.dll

2012-06-11 18:49 . 2012-06-11 18:49 13008896 ----a-w- c:\windows\SysWow64\amdocl.dll

2012-06-11 18:35 . 2012-06-11 18:35 70144 ----a-w- c:\windows\system32\coinst_8.98.dll

2012-06-11 18:29 . 2011-10-26 02:16 24826368 ----a-w- c:\windows\system32\atio6axx.dll

2012-06-11 18:00 . 2012-06-11 18:00 20467712 ----a-w- c:\windows\SysWow64\atioglxx.dll

2012-06-11 17:25 . 2012-06-11 17:25 163840 ----a-w- c:\windows\system32\atiapfxx.exe

2012-06-11 17:24 . 2011-12-06 03:17 924160 ----a-w- c:\windows\SysWow64\aticfx32.dll

2012-06-11 17:23 . 2011-10-26 02:04 1090560 ----a-w- c:\windows\system32\aticfx64.dll

2012-06-11 17:20 . 2012-06-11 17:20 442368 ----a-w- c:\windows\system32\ATIDEMGX.dll

2012-06-11 17:19 . 2012-06-11 17:19 532992 ----a-w- c:\windows\system32\atieclxx.exe

2012-06-11 17:19 . 2012-06-11 17:19 239616 ----a-w- c:\windows\system32\atiesrxx.exe

2012-06-11 17:17 . 2012-06-11 17:17 120320 ----a-w- c:\windows\system32\atitmm64.dll

2012-06-11 17:17 . 2012-06-11 17:17 21504 ----a-w- c:\windows\system32\atimuixx.dll

2012-06-11 17:17 . 2012-06-11 17:17 59392 ----a-w- c:\windows\system32\atiedu64.dll

2012-06-11 17:17 . 2012-06-11 17:17 43520 ----a-w- c:\windows\SysWow64\ati2edxx.dll

2012-06-11 17:16 . 2012-06-11 17:16 6301696 ----a-w- c:\windows\SysWow64\atidxx32.dll

2012-06-11 17:01 . 2012-06-11 17:01 6914560 ----a-w- c:\windows\system32\atidxx64.dll

2012-06-11 16:51 . 2012-06-11 16:51 4246528 ----a-w- c:\windows\system32\atiumd6a.dll

2012-06-11 16:45 . 2012-06-11 16:45 51200 ----a-w- c:\windows\system32\aticalrt64.dll

2012-06-11 16:45 . 2012-06-11 16:45 46080 ----a-w- c:\windows\SysWow64\aticalrt.dll

2012-06-11 16:45 . 2011-12-06 02:33 5480448 ----a-w- c:\windows\SysWow64\atiumdag.dll

2012-06-11 16:45 . 2012-06-11 16:45 44544 ----a-w- c:\windows\system32\aticalcl64.dll

2012-06-11 16:45 . 2012-06-11 16:45 44032 ----a-w- c:\windows\SysWow64\aticalcl.dll

2012-06-11 16:45 . 2012-06-11 16:45 15703040 ----a-w- c:\windows\system32\aticaldd64.dll

2012-06-11 16:43 . 2011-12-06 02:28 4729344 ----a-w- c:\windows\SysWow64\atiumdva.dll

2012-06-11 16:40 . 2012-06-11 16:40 13277696 ----a-w- c:\windows\SysWow64\aticaldd.dll

2012-06-11 16:36 . 2012-06-11 16:36 6605824 ----a-w- c:\windows\system32\atiumd64.dll

2012-06-11 16:27 . 2011-10-26 01:22 539136 ----a-w- c:\windows\system32\atiadlxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 368640 ----a-w- c:\windows\SysWow64\atiadlxy.dll

2012-06-11 16:26 . 2011-10-26 01:22 17920 ----a-w- c:\windows\system32\atig6pxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\SysWow64\atiglpxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 14848 ----a-w- c:\windows\system32\atiglpxx.dll

2012-06-11 16:26 . 2011-10-26 01:22 41984 ----a-w- c:\windows\system32\atig6txx.dll

2012-06-11 16:26 . 2012-06-11 16:26 33280 ----a-w- c:\windows\SysWow64\atigktxx.dll

2012-06-11 16:26 . 2012-06-11 16:26 367616 ----a-w- c:\windows\system32\drivers\atikmpag.sys

2012-06-11 16:25 . 2010-11-26 02:16 54784 ----a-w- c:\windows\system32\atiuxp64.dll

2012-06-11 16:25 . 2012-06-11 16:25 42496 ----a-w- c:\windows\SysWow64\atiuxpag.dll

2012-06-11 16:25 . 2012-06-11 16:25 45056 ----a-w- c:\windows\system32\atiu9p64.dll

2012-06-11 16:24 . 2010-11-26 02:15 32768 ----a-w- c:\windows\SysWow64\atiu9pag.dll

2012-06-11 16:24 . 2012-06-11 16:24 53248 ----a-w- c:\windows\system32\drivers\ati2erec.dll

2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\atimpc64.dll

2012-06-11 16:23 . 2012-06-11 16:23 56320 ----a-w- c:\windows\system32\amdpcom64.dll

2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\atimpc32.dll

2012-06-11 16:23 . 2012-06-11 16:23 56832 ----a-w- c:\windows\SysWow64\amdpcom32.dll

2012-05-31 17:25 . 2009-10-30 23:04 279656 ------w- c:\windows\system32\MpSigStub.exe

.

.

((((((((((((((((((((((((((((( SnapShot_2012-07-12_01.06.01 )))))))))))))))))))))))))))))))))))))))))

.

+ 2009-10-30 23:27 . 2012-07-16 10:15 94352 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin

+ 2009-07-14 05:10 . 2012-07-16 10:15 31822 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin

+ 2009-10-30 22:49 . 2012-07-16 10:15 16026 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-645954481-4171391755-2920796181-1000_UserData.bin

+ 2012-07-12 18:10 . 2012-04-12 03:55 83472 c:\windows\system32\spool\drivers\x64\NitroReaderUI2.dll

+ 2012-07-12 18:10 . 2012-04-12 03:55 45584 c:\windows\system32\spool\drivers\x64\NitroReaderGraphics2.dll

+ 2009-10-31 00:26 . 2012-07-13 09:10 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-31 00:26 . 2012-07-11 00:47 49152 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2012-07-10 23:27 . 2012-07-13 09:10 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2012-07-10 23:27 . 2012-07-11 00:47 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-07-14 04:54 . 2012-07-13 09:10 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-07-14 04:54 . 2012-07-11 00:47 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-16 10:14 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-16 10:14 32768 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-16 10:14 16384 c:\windows\ServiceProfiles\NetworkService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

+ 2009-10-30 22:48 . 2012-07-16 10:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Roaming\Microsoft\Windows\Cookies\index.dat

+ 2009-10-30 22:48 . 2012-07-16 10:14 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2009-10-30 22:48 . 2012-07-12 01:10 16384 c:\windows\ServiceProfiles\LocalService\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat

- 2012-07-12 01:04 . 2012-07-12 01:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-07-16 10:08 . 2012-07-16 10:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat

+ 2012-07-16 10:08 . 2012-07-16 10:08 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

- 2012-07-12 01:04 . 2012-07-12 01:04 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat

+ 2012-07-02 15:48 . 2011-02-28 22:37 738080 c:\windows\system32\spool\drivers\x64\3\pscript5.dll

+ 2012-07-02 15:48 . 2011-02-28 22:37 241952 c:\windows\system32\spool\drivers\x64\3\ps5ui.dll

+ 2009-07-14 05:01 . 2012-07-16 10:07 515388 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2009-07-14 05:01 . 2012-07-12 01:02 515388 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat

- 2010-01-23 09:16 . 2012-07-12 01:02 1350152 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat

+ 2010-01-23 09:16 . 2012-07-16 10:07 1350152 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat

+ 2009-07-14 02:34 . 2012-07-15 06:42 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

- 2009-07-14 02:34 . 2012-07-11 10:16 10485760 c:\windows\system32\SMI\Store\Machine\schema.dat

+ 2010-02-26 09:22 . 2012-07-16 10:07 24521432 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-645954481-4171391755-2920796181-1000-12288.dat

+ 2012-04-30 21:43 . 2012-04-30 21:43 45831680 c:\windows\Installer\27a2bc1.msi

.

((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))

.

.

*Note* empty entries & legit default entries are not shown

REGEDIT4

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]

@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 94208 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll

.

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Steam"="c:\program files (x86)\Steam\steam.exe" [2011-08-02 1242448]

"AlcoholAutomount"="c:\program files (x86)\Alcohol Soft\Alcohol 120\AxAutoMntSrv.exe" [2010-08-20 33120]

"Xvid"="c:\program files (x86)\XviD\CheckUpdate.exe" [2011-01-17 8192]

"Snarl"="c:\program files (x86)\full phat\Snarl\snarl.exe" [2011-05-25 925696]

"Tonido"="c:\users\Hayden\AppData\Roaming\Tonido\launcher.exe" [2011-11-14 100864]

"MusicManager"="c:\users\Hayden\AppData\Local\Programs\Google\MusicManager\MusicManager.exe" [2012-06-01 13806592]

"GoToMeeting"="c:\program files (x86)\Citrix\GoToMeeting\952\g2mstart.exe" [2012-05-25 39816]

"Spotify Web Helper"="c:\users\Hayden\AppData\Roaming\Spotify\Data\SpotifyWebHelper.exe" [2012-05-30 932528]

"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]

"GoogleChromeAutoLaunch_7BA29E3153B77E65C37077A2469120EB"="c:\users\Hayden\AppData\Local\Google\Chrome\Application\chrome.exe" [2012-07-10 1250328]

"HydraVisionDesktopManager"="c:\program files (x86)\ATI Technologies\HydraVision\HydraDM.exe" [2011-10-03 393216]

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]

"AMD AVT"="start AMD Accelerated Video Transcoding device initialization" [X]

"AVG9_TRAY"="c:\progra~2\AVG\AVG9\avgtray.exe" [2012-01-26 2077536]

"VolPanel"="c:\program files (x86)\Creative\Volume Panel\VolPanlu.exe" [2008-08-06 233576]

"CTxfiHlp"="CTXFIHLP.EXE" [2009-07-14 24576]

"ATICustomerCare"="c:\program files (x86)\ATI\ATICustomerCare\ATICustomerCare.exe" [2010-05-04 311296]

"QuickTime Task"="c:\program files (x86)\QuickTime\QTTask.exe" [2010-11-29 421888]

"SwitchBoard"="c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]

"AdobeCS5ServiceManager"="c:\program files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]

"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-01-03 843712]

"SunJavaUpdateSched"="c:\program files (x86)\Common Files\Java\Java Update\jusched.exe" [2012-01-17 252296]

"hpqSRMon"="c:\program files (x86)\HP\Digital Imaging\bin\hpqSRMon.exe" [2008-07-22 150528]

"HP Software Update"="c:\program files (x86)\HP\HP Software Update\HPWuSchd2.exe" [2011-05-10 49208]

"Anti-phishing Domain Advisor"="c:\programdata\Anti-phishing Domain Advisor\visicom_antiphishing.exe" [2012-05-03 217256]

"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]

"KeePass 2 PreLoad"="c:\program files (x86)\KeePass Password Safe 2\KeePass.exe" [2012-05-01 1895424]

"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2012-06-11 641704]

.

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]

"MotoCast"="c:\program files (x86)\Motorola Mobility\MotoCast\MotoLauncher.lnk" [2012-06-20 2051]

.

c:\users\Hayden\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\

CurseClientStartup.ccip [2010-12-7 0]

Dropbox.lnk - c:\users\Hayden\AppData\Roaming\Dropbox\bin\Dropbox.exe [2012-5-24 27112840]

EvernoteClipper.lnk - c:\program files (x86)\Evernote\Evernote\EvernoteClipper.exe [2012-6-13 1014112]

.

c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\

HP Digital Imaging Monitor.lnk - c:\program files (x86)\HP\Digital Imaging\bin\hpqtra08.exe [2009-9-20 270336]

Rainmeter.lnk - c:\program files\Rainmeter\Rainmeter.exe [2011-8-21 102912]

Subsonic.lnk - c:\program files (x86)\Subsonic\subsonic-agent.exe [2011-12-6 206336]

UltraMon.lnk - c:\windows\Installer\{B49673F8-7AB6-4A14-8213-C8A7BE370010}\IcoUltraMon.ico [2010-8-23 29310]

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]

"ConsentPromptBehaviorAdmin"= 0 (0x0)

"ConsentPromptBehaviorUser"= 3 (0x3)

"EnableLUA"= 0 (0x0)

"EnableUIADesktopToggle"= 0 (0x0)

"PromptOnSecureDesktop"= 0 (0x0)

"HideShutdownScripts"= 0 (0x0)

.

[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\policies\explorer]

"MaxRecentDocs"= 99 (0x63)

.

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]

Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp

.

R2 Apache2.2;Apache2.2;c:\xampp\apache\bin\httpd.exe [2011-09-10 18432]

R2 AsSysCtrlService;ASUS System Control Service;c:\program files (x86)\ASUS\AsSysCtrlService\1.00.02\AsSysCtrlService.exe [2009-04-02 90112]

R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]

R2 LMIGuardianSvc;LMIGuardianSvc;c:\program files (x86)\LogMeIn\x64\LMIGuardianSvc.exe [x]

R2 MsDepSvc;Web Deployment Agent Service;c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe [2011-04-02 67400]

R2 MSSQL$MSSQL;SQL Server (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\sqlservr.exe [2010-04-03 61913952]

R2 WDSmartWareBackgroundService;WD SmartWare Background Service;c:\program files (x86)\Western Digital\WD SmartWare\Front Parlor\WDSmartWareBackgroundService.exe [2009-06-16 20480]

R3 Creative ALchemy AL6 Licensing Service;Creative ALchemy AL6 Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\AL6Licensing.exe [2009-10-31 79360]

R3 Creative Audio Engine Licensing Service;Creative Audio Engine Licensing Service;c:\program files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe [2009-10-31 79360]

R3 CT20XUT;CT20XUT;c:\windows\system32\drivers\CT20XUT.SYS [2010-07-08 230488]

R3 CTEXFIFX;CTEXFIFX;c:\windows\system32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]

R3 CTHWIUT;CTHWIUT;c:\windows\system32\drivers\CTHWIUT.SYS [2010-07-08 95320]

R3 DAUpdaterSvc;Dragon Age: Origins - Content Updater;c:\program files (x86)\steam\steamapps\common\dragon age origins\bin_ship\DAUpdaterSvc.Service.exe [x]

R3 MozillaMaintenance;Mozilla Maintenance Service;c:\program files (x86)\Mozilla Maintenance Service\maintenanceservice.exe [2012-07-07 113120]

R3 MSSQLFDLauncher$MSSQL;SQL Full-text Filter Daemon Launcher (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\fdlauncher.exe [2010-04-03 32096]

R3 osppsvc;Office Software Protection Platform;c:\program files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE [2010-01-10 4925184]

R3 RivaTuner64;RivaTuner64;c:\program files (x86)\RivaTuner v2.24 MSI Master Overclocking Arena 2009 edition\RivaTuner64.sys [2012-05-29 19952]

R3 SQLAgent$MSSQL;SQL Server Agent (MSSQL);c:\program files\Microsoft SQL Server\MSSQL10_50.MSSQL\MSSQL\Binn\SQLAGENT.EXE [2010-04-03 428384]

R3 SSMO3v2Filter;MMO3v2 Mouse;c:\windows\system32\drivers\MO3v2Driver.sys [2010-11-22 23040]

R3 SwitchBoard;Adobe SwitchBoard;c:\program files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe [2010-02-19 517096]

R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [2011-05-10 51712]

R3 USBPNPA;USB PnP Sound Device Interface;c:\windows\system32\drivers\CM10864.sys [2010-08-13 1310720]

R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2010-03-10 1255736]

R3 WDC_SAM;WD SCSI Pass Thru driver;c:\windows\system32\DRIVERS\wdcsam64.sys [2009-02-13 14464]

R3 WMSVC;Web Management Service;c:\windows\system32\inetsrv\wmsvc.exe [2009-07-14 10752]

R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]

R4 RsFx0150;RsFx0150 Driver;c:\windows\system32\DRIVERS\RsFx0150.sys [2010-04-03 313696]

R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-23 57184]

S0 AvgRkx64;avgrkx64.sys;c:\windows\System32\Drivers\avgrkx64.sys [2010-03-29 56008]

S0 sptd;sptd;c:\windows\System32\Drivers\sptd.sys [2010-09-12 503352]

S1 AvgLdx64;AVG AVI Loader Driver x64;c:\windows\System32\Drivers\avgldx64.sys [2010-06-22 269904]

S1 AvgMfx64;AVG On-access Scanner Minifilter Driver x64;c:\windows\System32\Drivers\avgmfx64.sys [2011-09-13 35664]

S1 AvgTdiA;AVG Network Redirector x64;c:\windows\System32\Drivers\avgtdia.sys [2011-05-06 317520]

S1 VBoxDrv;VirtualBox Service;c:\windows\system32\DRIVERS\VBoxDrv.sys [2011-12-19 224048]

S1 VBoxUSBMon;VirtualBox USB Monitor Driver;c:\windows\system32\DRIVERS\VBoxUSBMon.sys [2011-12-19 130864]

S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-01-03 63928]

S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [2012-06-11 239616]

S2 avg9emc;AVG E-mail Scanner;c:\program files (x86)\AVG\AVG9\avgemc.exe [2010-07-21 921952]

S2 avg9wd;AVG WatchDog;c:\program files (x86)\AVG\AVG9\avgwdsvc.exe [2010-06-22 308136]

S2 DeviceMonitorService;DeviceMonitorService;c:\program files (x86)\Motorola Media Link\Lite\NServiceEntry.exe [2012-06-05 87400]

S2 HiPatchService;Hi-Rez Studios Authenticate and Update Service;c:\program files (x86)\Hi-Rez Studios\HiPatchService.exe [2011-11-08 14216]

S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]

S2 Motorola Device Manager;Motorola Device Manager Service;c:\program files (x86)\Motorola Mobility\Motorola Device Manager\MotoHelperService.exe [2012-06-05 116632]

S2 MSOLAP$MSSQL;SQL Server Analysis Services (MSSQL);c:\program files\Microsoft SQL Server\MSAS10_50.MSSQL\OLAP\bin\msmdsrv.exe [2010-04-03 54568288]

S2 NitroReaderDriverReadSpool2;NitroPDFReaderDriverCreatorReadSpool2;c:\program files\Common Files\Nitro PDF\Reader\2.0\NitroPDFReaderDriverService2x64.exe [2012-04-12 204304]

S2 nlsX86cc;Nalpeiron Licensing Service;c:\windows\SysWOW64\NLSSRV32.EXE [2012-06-25 69640]

S2 PST Service;PST Service;c:\program files (x86)\Motorola\MotForwardDaemon\ForwardDaemon.exe [2011-09-02 65657]

S2 ReportServer$MSSQL;SQL Server Reporting Services (MSSQL);c:\program files\Microsoft SQL Server\MSRS10_50.MSSQL\Reporting Services\ReportServer\bin\ReportingServicesService.exe [2010-04-03 2175328]

S2 UltraMonUtility;UltraMon Utility Driver;c:\program files (x86)\Common Files\Realtime Soft\UltraMonMirrorDrv\x64\UltraMonUtility.sys [2008-11-14 20512]

S2 WDDMService.exe;WD SmartWare Drive Manager Service;c:\program files\Western Digital\WD SmartWare\WD Drive Manager\WDDMService.exe [2009-08-17 116224]

S3 amdkmdag;amdkmdag;c:\windows\system32\DRIVERS\atikmdag.sys [2012-06-11 10248192]

S3 amdkmdap;amdkmdap;c:\windows\system32\DRIVERS\atikmpag.sys [2012-06-11 367616]

S3 AtiHDAudioService;AMD Function Driver for HD Audio Service;c:\windows\system32\drivers\AtihdW76.sys [2012-02-23 95760]

S3 CT20XUT.SYS;CT20XUT.SYS;c:\windows\System32\drivers\CT20XUT.SYS [2010-07-08 230488]

S3 CTEXFIFX.SYS;CTEXFIFX.SYS;c:\windows\System32\drivers\CTEXFIFX.SYS [2010-07-08 1445976]

S3 CTHWIUT.SYS;CTHWIUT.SYS;c:\windows\System32\drivers\CTHWIUT.SYS [2010-07-08 95320]

S3 EuMusDesignVirtualAudioCableWdm;Virtual Audio Cable (WDM);c:\windows\system32\DRIVERS\vrtaucbl.sys [2010-05-22 66728]

S3 ha20x22k;Creative 20X2 HAL Driver;c:\windows\system32\drivers\ha20x22k.sys [2010-07-08 1612888]

S3 LGBusEnum;Logitech GamePanel Virtual Bus Enumerator Driver;c:\windows\system32\drivers\LGBusEnum.sys [2010-12-12 22408]

S3 LGPBTDD;LGPBTDD.sys Display Driver;c:\windows\system32\Drivers\LGPBTDD.sys [2009-07-01 30728]

S3 LGVirHid;Logitech Gamepanel Virtual HID Device Driver;c:\windows\system32\drivers\LGVirHid.sys [2010-12-12 16008]

S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]

S3 VBoxNetAdp;VirtualBox Host-Only Ethernet Adapter;c:\windows\system32\DRIVERS\VBoxNetAdp.sys [2011-12-19 146736]

S3 VBoxNetFlt;VirtualBox Bridged Networking Service;c:\windows\system32\DRIVERS\VBoxNetFlt.sys [2011-12-19 165680]

S3 yukonw7;NDIS6.2 Miniport Driver for Marvell Yukon Ethernet Controller;c:\windows\system32\DRIVERS\yk62x64.sys [2009-09-28 395264]

.

.

[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\svchost]

iissvcs REG_MULTI_SZ w3svc was

apphost REG_MULTI_SZ apphostsvc

hpdevmgmt REG_MULTI_SZ hpqcxs08 hpqddsvc

.

Contents of the 'Scheduled Tasks' folder

.

2012-07-15 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000Core.job

- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]

.

2012-07-16 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-645954481-4171391755-2920796181-1000UA.job

- c:\users\Hayden\AppData\Local\Google\Update\GoogleUpdate.exe [2009-10-30 22:52]

.

.

Link to post
Share on other sites

--------- X64 Entries -----------

.

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]

@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 97792 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]

@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 97792 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]

@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 97792 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]

@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"

[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]

2011-12-05 19:17 97792 ----a-w- c:\users\Hayden\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll

.

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]

"Launch LCore"="c:\program files\Logitech Gaming Software\LCore.exe" [2011-06-15 110360]

"Start WingMan Profiler"="c:\program files\Logitech\Gaming Software\LWEMon.exe" [2010-06-14 190536]

"AdobeAAMUpdater-1.0"="c:\program files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]

"Cm108Sound"="c:\windows\Syswow64\cm108.dll" [2010-10-13 8757248]

.

------- Supplementary Scan -------

.

uStart Page =

mLocal Page = c:\windows\SysWOW64\blank.htm

uInternet Settings,ProxyOverride = *.local;192.168.*.*

IE: &Verzenden naar OneNote - c:\progra~1\MIF5BA~1\Office14\ONBttnIE.dll/105

IE: Add to Evernote 4.0 - c:\program files (x86)\Evernote\Evernote\EvernoteIE.dll/204

IE: E&xporteren naar Microsoft Excel - c:\progra~1\MIF5BA~1\Office14\EXCEL.EXE/3000

IE: Open Client to monitor &1 - c:\windows\web\AOpenClient.htm

IE: Open Client to monitor &2 - c:\windows\web\AOpenClient.htm

Trusted Zone: clonewarsadventures.com

Trusted Zone: freerealms.com

Trusted Zone: soe.com

Trusted Zone: sony.com

TCP: DhcpNameServer = 192.168.1.254

DPF: {EF0D1A14-1033-41A2-A589-240C01EDC078} - hxxp://dl.pplive.com/PluginSetup.cab

FF - ProfilePath - c:\users\Hayden\AppData\Roaming\Mozilla\Firefox\Profiles\om1tisbe.default\

.

- - - - ORPHANS REMOVED - - - -

.

WebBrowser-{BA14329E-9550-4989-B3F2-9732E92D17CC} - (no file)

.

.

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\services\MsDepSvc]

"ImagePath"="\"c:\program files\IIS\Microsoft Web Deploy\MsDepSvc.exe\" -runService:MsDepSvc"

.

--------------------- LOCKED REGISTRY KEYS ---------------------

.

[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.eml\UserChoice]

@Denied: (2) (S-1-5-21-645954481-4171391755-2920796181-1000)

@Denied: (2) (LocalSystem)

"Progid"="ThunderbirdEML"

.

[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vcf\UserChoice]

@Denied: (2) (LocalSystem)

"Progid"="WindowsLiveMail.VCard.1"

.

[HKEY_USERS\S-1-5-21-645954481-4171391755-2920796181-1000\Software\SecuROM\License information*]

"datasecu"=hex:97,d2,c9,85,02,71,88,e1,fc,ae,42,fe,02,8d,8e,24,19,8e,34,38,98,

bf,29,19,59,bb,61,f1,77,18,e7,bc,4a,35,98,08,f1,6c,21,76,ba,c6,fb,cc,72,f4,\

"rkeysecu"=hex:79,fe,52,e1,00,f1,26,9b,6e,10,c9,f7,ce,d0,27,3d

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]

@Denied: (A 2) (Everyone)

@="FlashBroker"

"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe,-101"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]

"Enabled"=dword:00000001

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil10t_ActiveX.exe"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Shockwave Flash Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]

@="0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]

@="ShockwaveFlash.ShockwaveFlash.10"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="ShockwaveFlash.ShockwaveFlash"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]

@Denied: (A 2) (Everyone)

@="Macromedia Flash Factory Object"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx"

"ThreadingModel"="Apartment"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]

@="FlashFactory.FlashFactory.1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]

@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash10t.ocx, 1"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]

@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]

@="1.0"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]

@="FlashFactory.FlashFactory"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]

@Denied: (A 2) (Everyone)

@="IFlashBroker4"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]

@="{00020424-0000-0000-C000-000000000046}"

.

[HKEY_LOCAL_MACHINE\software\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]

@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

"Version"="1.0"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\DbgagD\1*]

"value"="?\07\00\0f\17/\00?"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B7EFF951-E52F-45CC-9EF7-57124F2177CC}]

@Denied: (A) (Everyone)

"Solution"="{15727DE6-F92D-4E46-ACB4-0E2C58B31A18}"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}]

@Denied: (A) (Everyone)

"Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane\0]

"Key"="ActionsPane"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd"

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3]

@Denied: (A) (Everyone)

.

[HKEY_LOCAL_MACHINE\software\Wow6432Node\Microsoft\Schema Library\ActionsPane3\0]

"Key"="ActionsPane3"

"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\ActionsPane3.xsd"

.

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\PCW\Security]

@Denied: (Full) (Everyone)

.

------------------------ Other Running Processes ------------------------

.

c:\program files (x86)\Creative\Shared Files\CTAudSvc.exe

c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe

c:\program files (x86)\Bonjour\mDNSResponder.exe

c:\xampp\filezillaftp\filezillaserver.exe

c:\program files (x86)\Windows Media Player\wmplayer.exe

c:\windows\SysWOW64\rundll32.exe

c:\users\Hayden\AppData\Roaming\Tonido\tonido.exe

c:\program files (x86)\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe

c:\program files (x86)\Motorola Mobility\MotoCast\MotoCast.exe

c:\program files (x86)\AVG\AVG9\avgtray.exe

c:\windows\SysWOW64\Ctxfihlp.exe

c:\windows\SysWOW64\CTXFISPI.EXE

c:\xampp\mysql\bin\mysqld.exe

c:\program files (x86)\full phat\Snarl\extensions\AudioMon\snarl-audiomon.exe

c:\program files (x86)\Citrix\GoToMeeting\952\g2mcomm.exe

c:\program files (x86)\Citrix\GoToMeeting\952\g2mlauncher.exe

c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe

c:\program files (x86)\AVG\AVG9\avgcsrvx.exe

c:\program files (x86)\Common Files\Realtime Soft\RTSHookInterop\x32\RTSHookInterop.exe

c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDMovieViewer.exe

c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDWebCam.exe

c:\program files\Logitech Gaming Software\plugins\LCDAppletsMono-8.00.048\Applets\x86\LCDMedia.exe

c:\users\Hayden\Desktop\downloads\SirReal\LCDSirReal.exe

c:\program files\Logitech Gaming Software\plugins\LCDAppletsColor-8.00.048\Applets\x86\LCDYT.exe

c:\program files (x86)\HP\Digital Imaging\bin\hpqSTE08.exe

c:\program files (x86)\HP\Digital Imaging\bin\hpqbam08.exe

c:\program files (x86)\HP\Digital Imaging\bin\hpqgpc01.exe

c:\program files (x86)\Motorola Mobility\MotoCast\bin\MotoCast-thumbnailer.exe

.

**************************************************************************

.

Completion time: 2012-07-16 05:36:19 - machine was rebooted

ComboFix-quarantined-files.txt 2012-07-16 10:36

ComboFix2.txt 2012-07-13 23:57

ComboFix3.txt 2012-07-12 01:30

ComboFix4.txt 2012-07-08 00:33

.

Pre-Run: 85,684,477,952 bytes free

Post-Run: 85,416,562,688 bytes free

.

- - End Of File - - 54132E7D0C011EDA25571CC59EA91497

Link to post
Share on other sites

Guest
This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.

Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.