when i ran combofix it said something about the program being expired and do i wish to run in reduced functionality mode. i said yes, and posted the log
mbab log
Malwarebytes Anti-Malware (Trial) 1.60.0.1800
www.malwarebytes.org
Database version: v2012.01.23.06
Windows 7 Service Pack 1 x64 NTFS
Internet Explorer 9.0.8112.16421
Eric :: ERIC-LAPTOP [administrator]
Protection: Enabled
1/23/2012 9:29:10 PM
mbam-log-2012-01-23 (23-59-25).txt
Scan type: Full scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 510398
Time elapsed: 2 hour(s), 9 minute(s), 46 second(s)
Memory Processes Detected: 0
(No malicious items detected)
Memory Modules Detected: 0
(No malicious items detected)
Registry Keys Detected: 0
(No malicious items detected)
Registry Values Detected: 0
(No malicious items detected)
Registry Data Items Detected: 0
(No malicious items detected)
Folders Detected: 0
(No malicious items detected)
Files Detected: 2
C:\Program Files\VS Revo Group\Revo Uninstaller Pro\Revo.Uninstaller.Pro.2.x.x.Generic.Patch-JW.exe (RiskWare.Tool.CK) -> No action taken.
C:\Users\Eric\Downloads\asus\SoftonicDownloader_for_picasa.exe (PUP.BundleOffer.Downloader.S) -> No action taken.
(end)
ComboFix 12-01-16.02 - Eric 01/24/2012 0:04.3.2 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.8190.5887 [GMT -5:00]
Running from: c:\users\Eric\Desktop\geeks to go\ComboFix.exe
AV: Norton Internet Security *Enabled/Updated* {63DF5164-9100-186D-2187-8DC619EFD8BF}
FW: Norton Internet Security *Enabled* {5BE4D041-DB6F-1935-0AD8-24F3E73C9FC4}
SP: Norton Internet Security *Enabled/Updated* {D8BEB080-B73A-17E3-1B37-B6B462689202}
SP: Windows Defender *Disabled/Outdated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
- REDUCED FUNCTIONALITY MODE -
.
.
((((((((((((((((((((((((( Files Created from 2011-12-24 to 2012-01-24 )))))))))))))))))))))))))))))))
.
.
2012-01-24 05:05 . 2012-01-24 05:05 -------- d-----w- c:\users\QBDataServiceUser20\AppData\Local\temp
2012-01-24 05:05 . 2012-01-24 05:05 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-01-24 00:08 . 2012-01-24 00:08 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-01-24 00:08 . 2011-12-10 20:24 23152 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-01-17 17:39 . 2012-01-17 17:39 -------- d-----w- C:\_OTL
2012-01-17 01:10 . 2012-01-17 01:10 -------- d-----w- c:\users\Eric\AppData\Roaming\Malwarebytes
2012-01-17 01:10 . 2012-01-17 01:10 -------- d-----w- c:\programdata\Malwarebytes
2012-01-14 06:06 . 2011-12-21 07:24 43992 ----a-w- c:\program files (x86)\Mozilla Firefox\mozutils.dll
2012-01-14 06:06 . 2011-12-21 04:30 626688 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcr80.dll
2012-01-14 06:06 . 2011-12-21 04:30 548864 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcp80.dll
2012-01-14 06:06 . 2011-12-21 04:30 479232 ----a-w- c:\program files (x86)\Mozilla Firefox\msvcm80.dll
2012-01-14 04:24 . 2012-01-14 15:32 -------- d-----w- C:\NBRT
2012-01-14 01:04 . 2012-01-14 01:04 -------- d-----w- C:\NPE
2012-01-13 22:20 . 2012-01-24 05:08 -------- d-----w- c:\users\Eric\AppData\Local\Temp
2012-01-13 21:21 . 2009-05-18 07:47 34152 ----a-w- c:\windows\system32\drivers\GEARAspiWDM.sys
2012-01-13 21:20 . 2012-01-13 21:20 -------- d-----w- c:\windows\system32\drivers\NBRTWizardx64
2012-01-13 21:20 . 2012-01-13 21:20 -------- d-----w- c:\program files (x86)\Norton Bootable Recovery Tool Wizard
2012-01-13 19:38 . 2012-01-13 19:38 96376 ----a-w- c:\windows\system32\drivers\SMR210.SYS
2012-01-11 21:06 . 2012-01-11 21:06 -------- d-----w- c:\program files (x86)\WebGear
2012-01-11 20:29 . 2012-01-11 20:29 326268174 ----a-w- C:\Regbackup.reg
2012-01-11 20:04 . 2012-01-14 05:56 -------- d-----w- c:\users\Eric\AppData\Local\NPE
2012-01-11 08:27 . 2012-01-19 00:09 -------- d-----w- c:\program files (x86)\679C1
2012-01-11 07:56 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-01-11 07:56 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-01-11 07:56 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-01-11 07:56 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-01-11 07:56 . 2011-11-17 05:38 1292080 ----a-w- c:\windows\SysWow64\ntdll.dll
2012-01-11 07:56 . 2011-11-17 06:41 1731920 ----a-w- c:\windows\system32\ntdll.dll
2012-01-11 07:56 . 2011-11-19 14:58 77312 ----a-w- c:\windows\system32\packager.dll
2012-01-11 07:56 . 2011-11-19 14:01 67072 ----a-w- c:\windows\SysWow64\packager.dll
2012-01-09 21:01 . 2012-01-09 21:01 -------- d-----w- c:\users\Eric\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2011-12-26 03:59 . 2011-12-26 04:00 -------- d-----w- c:\program files\iTunes
2011-12-26 03:59 . 2011-12-26 04:00 -------- d-----w- c:\program files (x86)\iTunes
2011-12-26 03:59 . 2011-12-26 03:59 -------- d-----w- c:\program files\iPod
.
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-01-11 22:38 . 2011-06-02 03:37 414368 ----a-w- c:\windows\SysWow64\FlashPlayerCPLApp.cpl
2011-11-25 03:23 . 2011-11-25 03:23 203320 ----a-w- c:\windows\system32\drivers\ssudmdm.sys
2011-11-25 03:23 . 2011-11-25 03:23 98616 ----a-w- c:\windows\system32\drivers\ssudbus.sys
2011-11-24 04:52 . 2011-12-14 06:20 3145216 ----a-w- c:\windows\system32\win32k.sys
2011-11-05 05:32 . 2011-12-14 06:20 2048 ----a-w- c:\windows\system32\tzres.dll
2011-11-05 04:26 . 2011-12-14 06:20 2048 ----a-w- c:\windows\SysWow64\tzres.dll
2011-11-04 01:53 . 2011-12-14 08:03 2309120 ----a-w- c:\windows\system32\jscript9.dll
2011-11-04 01:44 . 2011-12-14 08:03 1390080 ----a-w- c:\windows\system32\wininet.dll
2011-11-04 01:44 . 2011-12-14 08:03 1493504 ----a-w- c:\windows\system32\inetcpl.cpl
2011-11-04 01:34 . 2011-12-14 08:03 2382848 ----a-w- c:\windows\system32\mshtml.tlb
2011-11-03 22:47 . 2011-12-14 08:03 1798144 ----a-w- c:\windows\SysWow64\jscript9.dll
2011-11-03 22:40 . 2011-12-14 08:03 1427456 ----a-w- c:\windows\SysWow64\inetcpl.cpl
2011-11-03 22:39 . 2011-12-14 08:03 1127424 ----a-w- c:\windows\SysWow64\wininet.dll
2011-11-03 22:31 . 2011-12-14 08:03 2382848 ----a-w- c:\windows\SysWow64\mshtml.tlb
2011-10-26 05:21 . 2011-12-14 06:20 43520 ----a-w- c:\windows\system32\csrsrv.dll
2011-04-09 00:57 . 2011-04-09 00:57 12535496 ----a-w- c:\program files (x86)\Common Files\lpuninstall.exe
.
.
((((((((((((((((((((((((((((( SnapShot@2012-01-16_23.55.17 )))))))))))))))))))))))))))))))))))))))))
.
- 2011-07-07 18:55 . 2010-11-20 12:08 96768 c:\windows\SysWOW64\sspicli.dll
+ 2012-01-22 01:03 . 2011-11-17 05:28 96768 c:\windows\SysWOW64\sspicli.dll
+ 2012-01-22 01:03 . 2011-11-17 05:34 22016 c:\windows\SysWOW64\secur32.dll
- 2011-07-07 18:54 . 2010-11-20 12:21 22016 c:\windows\SysWOW64\secur32.dll
+ 2011-01-25 20:00 . 2012-01-24 05:09 71312 c:\windows\system32\wdi\ShutdownPerformanceDiagnostics_SystemData.bin
+ 2009-07-14 05:10 . 2012-01-24 05:09 52210 c:\windows\system32\wdi\BootPerformanceDiagnostics_SystemData.bin
+ 2011-01-25 19:04 . 2012-01-24 05:09 15978 c:\windows\system32\wdi\{86432a0b-3c7d-4ddf-a89c-172faa90485d}\S-1-5-21-1948204673-1780984394-1029538037-1000_UserData.bin
- 2011-07-07 18:55 . 2010-11-20 13:27 29184 c:\windows\system32\sspisrv.dll
+ 2012-01-22 01:03 . 2011-11-17 06:35 29184 c:\windows\system32\sspisrv.dll
- 2011-07-07 18:55 . 2010-11-20 13:27 28160 c:\windows\system32\secur32.dll
+ 2012-01-22 01:03 . 2011-11-17 06:35 28160 c:\windows\system32\secur32.dll
- 2009-07-13 23:20 . 2009-07-14 01:39 31232 c:\windows\system32\lsass.exe
+ 2012-01-22 01:03 . 2011-11-17 06:33 31232 c:\windows\system32\lsass.exe
+ 2012-01-22 01:03 . 2011-11-17 06:49 95600 c:\windows\system32\drivers\ksecdd.sys
- 2011-01-26 01:04 . 2012-01-16 22:17 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-01-26 01:04 . 2012-01-23 20:15 16384 c:\windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2011-01-26 01:04 . 2012-01-23 20:15 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2011-01-26 01:04 . 2012-01-16 22:17 32768 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-01-16 22:17 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-01-23 20:15 16384 c:\windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:46 . 2012-01-23 20:05 91616 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\Cache\cache.dat
- 2011-06-02 03:32 . 2012-01-09 21:24 4280 c:\windows\system32\wdi\ERCQueuedResolutions.dat
+ 2011-06-02 03:32 . 2012-01-23 17:39 4280 c:\windows\system32\wdi\ERCQueuedResolutions.dat
- 2012-01-16 23:53 . 2012-01-16 23:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-24 05:06 . 2012-01-24 05:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive1.dat
+ 2012-01-24 05:06 . 2012-01-24 05:06 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
- 2012-01-16 23:53 . 2012-01-16 23:53 2048 c:\windows\ServiceProfiles\LocalService\AppData\Local\lastalive0.dat
+ 2012-01-22 01:03 . 2011-11-17 05:35 314880 c:\windows\SysWOW64\webio.dll
- 2011-07-07 18:56 . 2010-11-20 12:21 314880 c:\windows\SysWOW64\webio.dll
+ 2012-01-22 01:03 . 2011-11-17 05:34 224768 c:\windows\SysWOW64\schannel.dll
- 2009-07-14 04:54 . 2012-01-16 23:54 458752 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2009-07-14 04:54 . 2012-01-24 05:07 458752 c:\windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
+ 2012-01-22 01:03 . 2011-11-17 06:35 395776 c:\windows\system32\webio.dll
- 2011-07-07 18:56 . 2010-11-20 13:27 395776 c:\windows\system32\webio.dll
+ 2011-01-26 05:02 . 2012-01-24 02:22 264822 c:\windows\system32\wdi\SuspendPerformanceDiagnostics_SystemData_S3.bin
- 2011-07-07 18:55 . 2010-11-20 13:27 136192 c:\windows\system32\sspicli.dll
+ 2012-01-22 01:03 . 2011-11-17 06:35 136192 c:\windows\system32\sspicli.dll
- 2011-07-07 18:56 . 2010-11-20 13:27 340992 c:\windows\system32\schannel.dll
+ 2012-01-22 01:03 . 2011-11-17 06:35 340992 c:\windows\system32\schannel.dll
+ 2012-01-22 01:03 . 2011-11-17 06:49 152432 c:\windows\system32\drivers\ksecpkg.sys
+ 2012-01-22 01:03 . 2011-11-17 06:44 459232 c:\windows\system32\drivers\cng.sys
- 2009-07-14 05:01 . 2012-01-14 23:16 425148 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
+ 2009-07-14 05:01 . 2012-01-24 05:05 425148 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-System.dat
- 2009-07-14 04:54 . 2012-01-16 23:54 3768320 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
+ 2009-07-14 04:54 . 2012-01-24 05:07 3768320 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
- 2009-07-14 04:54 . 2012-01-16 23:54 9453568 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
+ 2009-07-14 04:54 . 2012-01-24 05:07 9453568 c:\windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
- 2011-07-07 18:56 . 2010-11-20 13:26 1447936 c:\windows\system32\lsasrv.dll
+ 2012-01-22 01:03 . 2011-11-17 06:35 1447936 c:\windows\system32\lsasrv.dll
- 2009-07-14 04:45 . 2012-01-11 08:32 7149876 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2009-07-14 04:45 . 2012-01-23 17:44 7149876 c:\windows\ServiceProfiles\NetworkService\AppData\Roaming\Microsoft\SoftwareProtectionPlatform\tokens.dat
+ 2012-01-06 06:04 . 2012-01-06 06:04 3878912 c:\windows\Installer\2e005ff.msi
+ 2009-07-14 02:34 . 2012-01-23 17:39 10747904 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
- 2009-07-14 02:34 . 2012-01-16 04:05 10747904 c:\windows\system32\SMI\Store\Machine\SCHEMA.DAT
+ 2011-01-25 06:18 . 2012-01-21 17:14 16074336 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2011-01-25 06:18 . 2012-01-13 18:38 16074336 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache3.0.0.0.dat
- 2011-03-17 01:15 . 2012-01-14 23:16 19902500 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1948204673-1780984394-1029538037-1000-12288.dat
+ 2011-03-17 01:15 . 2012-01-23 19:53 19902500 c:\windows\ServiceProfiles\LocalService\AppData\Local\FontCache-S-1-5-21-1948204673-1780984394-1029538037-1000-12288.dat
.
-- Snapshot reset to current date --
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 94208 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt.14.dll
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Dekisoft Monitor Off Utility"="c:\program files (x86)\Monitor Off Utility\monoff.exe" [2011-03-20 303104]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"StartCCC"="c:\program files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" [2009-04-22 61440]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
CrashPlan Tray.lnk - c:\program files\CrashPlan\CrashPlanTray.exe [2011-3-16 217088]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 0 (0x0)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableLUA"= 0 (0x0)
"EnableUIADesktopToggle"= 0 (0x0)
"PromptOnSecureDesktop"= 0 (0x0)
"EnableLinkedConnections"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\explorer]
"HideSCAHealth"= 1 (0x1)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"aux2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
R2 clr_optimization_v4.0.30319_32;Microsoft .NET Framework NGEN v4.0.30319_X86;c:\windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe [2010-03-18 130384]
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-03 136176]
R2 LMIRescue_0fe6e286-2520-4db5-80eb-6fd4c551264d;LogMeIn Rescue (0fe6e286-2520-4db5-80eb-6fd4c551264d);c:\users\Eric\AppData\Local\Temp\LMIR0002.tmp\LMI_Rescue_srv.exe [x]
R2 LMIRescue_261da54f-1e37-4813-8d88-0419630b1c3d;LogMeIn Rescue (261da54f-1e37-4813-8d88-0419630b1c3d);c:\users\Eric\AppData\Local\Temp\LMIR0003.tmp\LMI_Rescue_srv.exe [x]
R2 LMIRescue_28ec28fe-b6a0-41cf-875f-97e948bf15af;LogMeIn Rescue (28ec28fe-b6a0-41cf-875f-97e948bf15af);c:\users\Eric\AppData\Local\Temp\LMIR0001.tmp\LMI_Rescue_srv.exe [x]
R3 dg_ssudbus;SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudbus.sys [x]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-03 136176]
R3 netw5v64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows Vista 64 Bit;c:\windows\system32\DRIVERS\netw5v64.sys [x]
R3 Revoflt;Revoflt;c:\windows\system32\DRIVERS\revoflt.sys [x]
R3 ssudmdm;SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.);c:\windows\system32\DRIVERS\ssudmdm.sys [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [x]
R3 USBAAPL64;Apple Mobile USB Driver;c:\windows\system32\Drivers\usbaapl64.sys [x]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [x]
R4 MSSQLServerADHelper100;SQL Active Directory Helper Service;c:\program files\Microsoft SQL Server\100\Shared\SQLADHLP.EXE [2010-04-03 59744]
R4 SQLAgent$MAXIMIZER;SQL Server Agent (MAXIMIZER);c:\program files\Microsoft SQL Server\MSSQL10_50.MAXIMIZER\MSSQL\Binn\SQLAGENT.EXE [2011-04-24 428384]
S0 SMR210;Symantec SMR Utility Service 2.1.0;c:\windows\System32\drivers\SMR210.SYS [x]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NISx64\1206000.01D\SYMDS64.SYS [x]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NISx64\1206000.01D\SYMEFA64.SYS [x]
S0 Thpevm;TOSHIBA HDD Protection - Shock Sensor Driver;c:\windows\system32\DRIVERS\Thpevm.SYS [x]
S1 BHDrvx64;BHDrvx64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20120121.002\BHDrvx64.sys [2011-12-01 1157240]
S1 IDSVia64;IDSVia64;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20120120.002\IDSvia64.sys [2011-08-23 488568]
S1 RsFx0150;RsFx0150 Driver;c:\windows\system32\DRIVERS\RsFx0150.sys [x]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NISx64\1206000.01D\Ironx64.SYS [x]
S1 SymNetS;Symantec Network Security WFP Driver;c:\windows\System32\Drivers\NISx64\1206000.01D\SYMNETS.SYS [x]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [x]
S2 AMD External Events Utility;AMD External Events Utility;c:\windows\system32\atiesrxx.exe [x]
S2 CrashPlanService;CrashPlan Backup Service;c:\program files\CrashPlan\CrashPlanService.exe [2011-03-16 222720]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2011-12-24 652872]
S2 MSSQL$MAXIMIZER;SQL Server (MAXIMIZER);c:\program files\Microsoft SQL Server\MSSQL10_50.MAXIMIZER\MSSQL\Binn\sqlservr.exe [2011-04-24 61916000]
S2 NIS;Norton Internet Security;c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe [2011-04-17 130008]
S2 RichVideo64;Cyberlink RichVideo64 Service(CRVS);c:\program files\CyberLink\Shared files\RichVideo64.exe [2010-08-19 386344]
S2 rimspci;rimspci;c:\windows\system32\DRIVERS\rimspe64.sys [x]
S2 rixdpcie;rixdpcie;c:\windows\system32\DRIVERS\rixdpe64.sys [x]
S2 ScrybeUpdater;Scrybe Updater;c:\program files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe [2011-05-27 1300264]
S2 TeamViewer6;TeamViewer 6;c:\program files (x86)\TeamViewer\Version6\TeamViewer_Service.exe [2011-08-30 2358656]
S2 TeamViewer7;TeamViewer 7;c:\program files (x86)\TeamViewer\Version7\TeamViewer_Service.exe [2011-12-14 2984832]
S2 XobniService;XobniService;c:\program files (x86)\Xobni\XobniService.exe [2011-02-11 62184]
S3 AirDisplay;Air Display Support;c:\windows\system32\DRIVERS\AVVideoCard.sys [x]
S3 AirDisplayMirror;Air Display Mirror Support;c:\windows\system32\DRIVERS\AVVideoCardMirror.sys [x]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2011-11-09 138360]
S3 FwLnk;FwLnk Driver;c:\windows\system32\DRIVERS\FwLnk.sys [x]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [x]
S3 NETw5s64;Intel® Wireless WiFi Link 5000 Series Adapter Driver for Windows 7 - 64 Bit;c:\windows\system32\DRIVERS\NETw5s64.sys [x]
S3 Point64;Microsoft IntelliPoint Filter Driver;c:\windows\system32\DRIVERS\point64.sys [x]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [x]
.
.
Contents of the 'Scheduled Tasks' folder
.
2012-01-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948204673-1780984394-1029538037-1000Core.job
- c:\users\Eric\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-20 18:39]
.
2012-01-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-1948204673-1780984394-1029538037-1000UA.job
- c:\users\Eric\AppData\Local\Facebook\Update\FacebookUpdate.exe [2011-11-20 18:39]
.
2012-01-24 c:\windows\Tasks\GlaryInitialize.job
- c:\program files (x86)\Glary Utilities\initialize.exe [2011-05-30 13:26]
.
2012-01-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-03 10:19]
.
2012-01-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-07-03 10:19]
.
2012-01-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1948204673-1780984394-1029538037-1000Core.job
- c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-25 20:09]
.
2012-01-24 c:\windows\Tasks\GoogleUpdateTaskUserS-1-5-21-1948204673-1780984394-1029538037-1000UA.job
- c:\users\Eric\AppData\Local\Google\Update\GoogleUpdate.exe [2011-01-25 20:09]
.
.
--------- x86-64 -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt1]
@="{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314ED9-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 97792 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt2]
@="{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDA-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 97792 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt3]
@="{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDB-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 97792 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\DropboxExt4]
@="{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}"
[HKEY_CLASSES_ROOT\CLSID\{FB314EDC-A251-47B7-93E1-CDD82E34AF8B}]
2010-10-06 23:36 97792 ----a-w- c:\users\Eric\AppData\Roaming\Dropbox\bin\DropboxExt64.14.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncBackedUp]
@="{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}"
[HKEY_CLASSES_ROOT\CLSID\{0C4A258A-3F3B-4FFF-80A7-9B3BEC139472}]
2011-12-22 12:47 405504 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncPending]
@="{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}"
[HKEY_CLASSES_ROOT\CLSID\{62CCD8E3-9C21-41E1-B55E-1E26DFC68511}]
2011-12-22 12:47 405504 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncRoot]
@="{A759AFF6-5851-457D-A540-F4ECED148351}"
[HKEY_CLASSES_ROOT\CLSID\{A759AFF6-5851-457D-A540-F4ECED148351}]
2011-12-22 12:47 405504 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\SugarSyncShared]
@="{1574C9EF-7D58-488F-B358-8B78C1538F51}"
[HKEY_CLASSES_ROOT\CLSID\{1574C9EF-7D58-488F-B358-8B78C1538F51}]
2011-12-22 12:47 405504 ----a-w- c:\program files (x86)\SugarSync\SugarSyncShellExt_x64.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IntelliPoint"="c:\program files\Microsoft IntelliPoint\ipoint.exe" [2011-04-13 2399632]
"SynTPEnh"="c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe" [BU]
.
------- Supplementary Scan -------
.
uLocal Page = c:\windows\system32\blank.htm
uStart Page =
https://movedowntown...n/MyOffice.aspxuDefault_Search_URL = hxxp://www.google.com/ie
mLocal Page = c:\windows\SysWOW64\blank.htm
uSearchAssistant = hxxp://www.google.com/ie
uSearchURL,(Default) = hxxp://www.google.com/search?q=%s
IE: Add to Google Photos Screensa&ver - c:\windows\system32\GPhotos.scr/200
IE: Append to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert link target to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert link target to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert selected links to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
IE: Convert selected links to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
IE: Convert selection to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: Convert selection to existing PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
IE: Convert to Adobe PDF - c:\program files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
TCP: Interfaces\{51398D5A-0EC7-4C59-898D-AC16AE86436F}: NameServer = 209.18.47.61,209.18.47.62
DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E} - hxxp://cbrmls.columbusrealtors.com/5.1.01.11828/Control/IRCSharc.cab
FF - ProfilePath - c:\users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\agrx8nd2.default\
FF - prefs.js: browser.startup.homepage - hxxp://www.bing.com/?pc=ZUGO&form=ZGAPHP
FF - prefs.js: network.proxy.http - 127.0.0.1
FF - prefs.js: network.proxy.http_port - 50707
FF - prefs.js: network.proxy.type - 0
FF - user.js: general.useragent.extra.brc -
.
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\NIS]
"ImagePath"="\"c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files (x86)\Norton Internet Security\Engine\18.6.0.29\diMaster.dll\" /prefetch:1"
"ImagePath"="\"c:\program files\CyberLink\Shared files\RichVideo64.exe\"\00Z
[\]^_˜\00\00˜\00\00\00\00HIJKLMNO\00\00\00\00\00\00\00\00\03\00\00\00|}~˜\00\00˜\00\00\00\00˜\00\00\00\00\00\00\00\00‘’“"
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_USERS\.Default\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (LocalSystem)
"6256FFB019F8FDFBD36745B06F4540E9AEAF222A25"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,39,09,ce,2e,95,53,88,48,b2,44,54,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A*D* ]
@SACL=(02 0001)
"Order"=hex:08,00,00,00,02,00,00,00,4c,14,00,00,01,00,00,00,1f,00,00,00,5a,00,
00,00,00,00,00,00,4c,00,31,00,00,00,00,00,00,2a,8b,b2,10,00,57,6f,72,64,73,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A*D* \Words]
"Order"=hex:08,00,00,00,02,00,00,00,60,04,00,00,01,00,00,00,07,00,00,00,b0,00,
00,00,06,00,00,00,a2,00,32,00,84,00,00,00,00,e5,6a,cc,20,00,31,35,43,4c,45,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\A*D* ]
@SACL=(02 0001)
"Order"=hex:08,00,00,00,02,00,00,00,a4,08,00,00,01,00,00,00,0e,00,00,00,78,00,
00,00,0d,00,00,00,6a,00,32,00,84,00,00,00,00,81,71,03,20,00,41,44,55,4c,54,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\B*u*s*i*n*e*s*s* \Images]
"Order"=hex:08,00,00,00,02,00,00,00,b2,01,00,00,01,00,00,00,03,00,00,00,6a,00,
00,00,00,00,00,00,5c,00,32,00,84,00,00,00,00,8f,8d,9b,20,00,46,6c,69,63,6b,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\B*u*s*i*n*e*s*s* \Personal Devolopment]
"Order"=hex:08,00,00,00,02,00,00,00,48,01,00,00,01,00,00,00,02,00,00,00,aa,00,
00,00,00,00,00,00,9c,00,32,00,84,00,00,00,00,41,4c,db,20,00,41,4e,54,48,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\B*u*s*i*n*e*s*s* \Success and Motivation]
"Order"=hex:08,00,00,00,02,00,00,00,a0,01,00,00,01,00,00,00,03,00,00,00,80,00,
00,00,00,00,00,00,72,00,32,00,84,00,00,00,00,92,11,f4,20,00,42,55,53,49,4e,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\C*o*m*p*u*t*e*r*s* *a*n*d* *T*e*c*h*n*o*l*o*g*y* \Forums]
"Order"=hex:08,00,00,00,02,00,00,00,28,0b,00,00,01,00,00,00,11,00,00,00,88,00,
00,00,00,00,00,00,7a,00,32,00,84,00,00,00,00,68,5c,85,20,00,41,46,54,45,52,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\C*o*m*p*u*t*e*r*s* *a*n*d* *T*e*c*h*n*o*l*o*g*y* \Media Guides]
"Order"=hex:08,00,00,00,02,00,00,00,50,08,00,00,01,00,00,00,0c,00,00,00,8e,00,
00,00,00,00,00,00,80,00,32,00,84,00,00,00,00,fc,94,4c,20,00,41,47,55,49,44,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\C*o*m*p*u*t*e*r*s* *a*n*d* *T*e*c*h*n*o*l*o*g*y* \Proxy]
"Order"=hex:08,00,00,00,02,00,00,00,f0,09,00,00,01,00,00,00,0e,00,00,00,a2,00,
00,00,0d,00,00,00,94,00,32,00,84,00,00,00,00,25,22,c1,20,00,53,48,41,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\C*o*m*p*u*t*e*r*s* *a*n*d* *T*e*c*h*n*o*l*o*g*y* \Technical Support]
"Order"=hex:08,00,00,00,02,00,00,00,88,06,00,00,01,00,00,00,0a,00,00,00,80,00,
00,00,00,00,00,00,72,00,32,00,84,00,00,00,00,48,47,8b,20,00,45,58,50,45,52,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*i*n*a*n*c*i*a*l* *I*n*f*o* \Computers and Technology]
"Order"=hex:08,00,00,00,02,00,00,00,7a,14,00,00,01,00,00,00,1d,00,00,00,6c,00,
00,00,00,00,00,00,5e,00,31,00,00,00,00,00,00,b8,33,b2,10,00,4d,45,44,49,41,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*i*n*a*n*c*i*a*l* *I*n*f*o* \Computers and Technology\Media Guides]
"Order"=hex:08,00,00,00,02,00,00,00,c2,07,00,00,01,00,00,00,0b,00,00,00,b8,00,
00,00,00,00,00,00,aa,00,32,00,84,00,00,00,00,3f,67,9f,20,00,41,46,54,45,52,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*i*n*a*n*c*i*a*l* *I*n*f*o* \Computers and Technology\Proxy]
"Order"=hex:08,00,00,00,02,00,00,00,6c,09,00,00,01,00,00,00,0d,00,00,00,a6,00,
00,00,0c,00,00,00,98,00,32,00,84,00,00,00,00,f5,03,1a,20,00,53,48,41,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*i*n*a*n*c*i*a*l* *I*n*f*o* \Computers and Technology\Technical Support]
"Order"=hex:08,00,00,00,02,00,00,00,08,06,00,00,01,00,00,00,09,00,00,00,bc,00,
00,00,00,00,00,00,ae,00,32,00,84,00,00,00,00,22,83,aa,20,00,46,49,52,45,46,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*o*o*d* \Food Carryout]
"Order"=hex:08,00,00,00,02,00,00,00,56,14,00,00,01,00,00,00,21,00,00,00,7e,00,
00,00,00,00,00,00,70,00,32,00,84,00,00,00,00,16,81,b7,20,00,41,50,50,4c,45,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \AMWF (1542011)--4tabs]
"Order"=hex:08,00,00,00,02,00,00,00,64,02,00,00,01,00,00,00,04,00,00,00,ae,00,
00,00,01,00,00,00,a0,00,32,00,84,00,00,00,00,6b,b1,7e,20,00,41,53,49,41,4e,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \AMWF 2 (1842011)--6tabs]
"Order"=hex:08,00,00,00,02,00,00,00,c0,03,00,00,01,00,00,00,06,00,00,00,96,00,
00,00,03,00,00,00,88,00,32,00,84,00,00,00,00,59,a0,78,20,00,41,42,4f,55,54,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \camping checklist (792011)--5tabs]
"Order"=hex:08,00,00,00,02,00,00,00,76,00,00,00,01,00,00,00,01,00,00,00,6a,00,
00,00,00,00,00,00,5c,00,31,00,00,00,00,00,00,45,f8,0e,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \camping checklist (792011)--5tabs\window 2555]
"Order"=hex:08,00,00,00,02,00,00,00,14,03,00,00,01,00,00,00,05,00,00,00,82,00,
00,00,02,00,00,00,74,00,32,00,84,00,00,00,00,f3,bc,d0,20,00,43,41,4d,50,49,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \didlos (1112012)--7tabs]
"Order"=hex:08,00,00,00,02,00,00,00,72,00,00,00,01,00,00,00,01,00,00,00,66,00,
00,00,00,00,00,00,58,00,31,00,00,00,00,00,00,83,f7,5f,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \didlos (1112012)--7tabs\window 69]
"Order"=hex:08,00,00,00,02,00,00,00,ea,04,00,00,01,00,00,00,07,00,00,00,c8,00,
00,00,04,00,00,00,ba,00,32,00,84,00,00,00,00,88,15,e2,20,00,41,44,41,4d,26,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \ebay thongs (1112012)--10tabs]
"Order"=hex:08,00,00,00,02,00,00,00,74,00,00,00,01,00,00,00,01,00,00,00,68,00,
00,00,00,00,00,00,5a,00,31,00,00,00,00,00,00,68,59,f1,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \ebay thongs (1112012)--10tabs\window 101]
"Order"=hex:08,00,00,00,02,00,00,00,40,07,00,00,01,00,00,00,0a,00,00,00,7c,00,
00,00,07,00,00,00,6e,00,32,00,84,00,00,00,00,41,b9,b4,20,00,43,53,54,52,49,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \ebay thongs shoppingfromeast (1112012)--2tabs]
"Order"=hex:08,00,00,00,02,00,00,00,74,00,00,00,01,00,00,00,01,00,00,00,68,00,
00,00,00,00,00,00,5a,00,31,00,00,00,00,00,00,fb,f9,ef,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \ebay thongs shoppingfromeast (1112012)--2tabs\window 122]
"Order"=hex:08,00,00,00,02,00,00,00,90,01,00,00,01,00,00,00,02,00,00,00,f8,00,
00,00,01,00,00,00,ea,00,32,00,84,00,00,00,00,e5,02,92,20,00,53,45,58,59,4d,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \Eye Stuff (2652011)--6tabs]
"Order"=hex:08,00,00,00,02,00,00,00,76,04,00,00,01,00,00,00,06,00,00,00,da,00,
00,00,04,00,00,00,cc,00,32,00,84,00,00,00,00,bd,f0,de,20,00,42,4c,55,45,43,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \harness (1182011)--14tabs]
"Order"=hex:08,00,00,00,02,00,00,00,72,00,00,00,01,00,00,00,01,00,00,00,66,00,
00,00,00,00,00,00,58,00,31,00,00,00,00,00,00,2c,61,2a,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \harness (1182011)--14tabs\window 77]
"Order"=hex:08,00,00,00,02,00,00,00,12,0b,00,00,01,00,00,00,0e,00,00,00,de,00,
00,00,07,00,00,00,d0,00,32,00,84,00,00,00,00,89,5e,f7,20,00,41,4d,41,5a,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \harness (1282011)--12tabs]
"Order"=hex:08,00,00,00,02,00,00,00,72,00,00,00,01,00,00,00,01,00,00,00,66,00,
00,00,00,00,00,00,58,00,31,00,00,00,00,00,00,8d,64,d0,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \harness (1282011)--12tabs\window 77]
"Order"=hex:08,00,00,00,02,00,00,00,6a,09,00,00,01,00,00,00,0c,00,00,00,90,00,
00,00,07,00,00,00,82,00,32,00,84,00,00,00,00,5d,24,91,20,00,42,45,53,54,48,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \harness (1382011)--12tabs]
"Order"=hex:08,00,00,00,02,00,00,00,74,00,00,00,01,00,00,00,01,00,00,00,68,00,
00,00,00,00,00,00,5a,00,31,00,00,00,00,00,00,78,d8,27,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \harness (1382011)--12tabs\window 107]
"Order"=hex:08,00,00,00,02,00,00,00,f6,08,00,00,01,00,00,00,0b,00,00,00,d4,00,
00,00,08,00,00,00,c6,00,32,00,84,00,00,00,00,99,5b,0e,20,00,41,4d,41,5a,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \h*a*r*n*e*s*s* *(*1*3*8*2*0*1*1*)*-*-*1*2*t*a*b*s* \window 107]
"Order"=hex:08,00,00,00,02,00,00,00,a8,01,00,00,01,00,00,00,02,00,00,00,da,00,
00,00,01,00,00,00,cc,00,32,00,84,00,00,00,00,e2,91,71,20,00,44,4f,55,42,4c,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \harness (1582011)--10tabs]
"Order"=hex:08,00,00,00,02,00,00,00,74,00,00,00,01,00,00,00,01,00,00,00,68,00,
00,00,00,00,00,00,5a,00,31,00,00,00,00,00,00,d3,f3,4d,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \harness (1582011)--10tabs\window 442]
"Order"=hex:08,00,00,00,02,00,00,00,a2,07,00,00,01,00,00,00,0a,00,00,00,e0,00,
00,00,00,00,00,00,d2,00,32,00,84,00,00,00,00,2e,16,49,20,00,41,4d,41,5a,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \harness (1582011)--13tabs]
"Order"=hex:08,00,00,00,02,00,00,00,72,00,00,00,01,00,00,00,01,00,00,00,66,00,
00,00,00,00,00,00,58,00,31,00,00,00,00,00,00,88,5a,ed,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \harness (1582011)--13tabs\window 44]
"Order"=hex:08,00,00,00,02,00,00,00,cc,0a,00,00,01,00,00,00,0d,00,00,00,e0,00,
00,00,02,00,00,00,d2,00,32,00,84,00,00,00,00,36,22,53,20,00,41,4d,41,5a,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \ice maker (1942011)--11tabs]
"Order"=hex:08,00,00,00,02,00,00,00,4a,07,00,00,01,00,00,00,0b,00,00,00,78,00,
00,00,06,00,00,00,6a,00,32,00,84,00,00,00,00,17,03,78,20,00,41,44,53,45,4e,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \latest (1312012)--9tabs]
"Order"=hex:08,00,00,00,02,00,00,00,72,00,00,00,01,00,00,00,01,00,00,00,66,00,
00,00,00,00,00,00,58,00,31,00,00,00,00,00,00,b8,eb,3c,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \latest (1312012)--9tabs\window 16]
"Order"=hex:08,00,00,00,02,00,00,00,02,06,00,00,01,00,00,00,09,00,00,00,de,00,
00,00,04,00,00,00,d0,00,32,00,84,00,00,00,00,b8,f2,a9,20,00,42,45,54,54,45,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \latest (2972011)--5tabs]
"Order"=hex:08,00,00,00,02,00,00,00,74,00,00,00,01,00,00,00,01,00,00,00,68,00,
00,00,00,00,00,00,5a,00,31,00,00,00,00,00,00,94,fa,64,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \latest (2972011)--5tabs\window 107]
"Order"=hex:08,00,00,00,02,00,00,00,5c,04,00,00,01,00,00,00,05,00,00,00,e6,00,
00,00,00,00,00,00,d8,00,32,00,84,00,00,00,00,83,68,ab,20,00,4d,41,53,53,41,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \latest (572011)--15tabs]
"Order"=hex:08,00,00,00,02,00,00,00,72,00,00,00,01,00,00,00,01,00,00,00,66,00,
00,00,00,00,00,00,58,00,31,00,00,00,00,00,00,97,59,09,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \latest (572011)--15tabs\window 52]
"Order"=hex:08,00,00,00,02,00,00,00,62,0b,00,00,01,00,00,00,0f,00,00,00,e6,00,
00,00,06,00,00,00,d8,00,32,00,84,00,00,00,00,0f,55,32,20,00,36,32,37,32,30,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \latest (982011)--11tabs]
"Order"=hex:08,00,00,00,02,00,00,00,72,00,00,00,01,00,00,00,01,00,00,00,66,00,
00,00,00,00,00,00,58,00,31,00,00,00,00,00,00,14,69,4a,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \latest (982011)--11tabs\window 26]
"Order"=hex:08,00,00,00,02,00,00,00,ea,08,00,00,01,00,00,00,0b,00,00,00,d4,00,
00,00,04,00,00,00,c6,00,32,00,84,00,00,00,00,54,8d,73,20,00,42,49,4f,52,55,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \pbay porn (3152011)--7tabs]
"Order"=hex:08,00,00,00,02,00,00,00,34,06,00,00,01,00,00,00,07,00,00,00,f8,00,
00,00,00,00,00,00,ea,00,32,00,84,00,00,00,00,12,04,bd,20,00,5f,37,32,30,50,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \pinned for ipad (572011)--5tabs]
"Order"=hex:08,00,00,00,02,00,00,00,72,00,00,00,01,00,00,00,01,00,00,00,66,00,
00,00,00,00,00,00,58,00,31,00,00,00,00,00,00,8f,b5,83,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \pinned for ipad (572011)--5tabs\window 53]
"Order"=hex:08,00,00,00,02,00,00,00,4c,03,00,00,01,00,00,00,05,00,00,00,c8,00,
00,00,02,00,00,00,ba,00,32,00,84,00,00,00,00,ee,fb,ab,20,00,42,49,4f,52,55,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \Pinned Tabs (1542011)--7tabs]
"Order"=hex:08,00,00,00,02,00,00,00,ea,04,00,00,01,00,00,00,07,00,00,00,d2,00,
00,00,06,00,00,00,c4,00,32,00,84,00,00,00,00,2b,bc,36,20,00,42,55,53,49,4e,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \pinned tabs (2842011)--13tabs]
"Order"=hex:08,00,00,00,02,00,00,00,da,09,00,00,01,00,00,00,0d,00,00,00,9e,00,
00,00,05,00,00,00,90,00,32,00,84,00,00,00,00,33,38,96,20,00,43,4f,4f,4c,45,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \pirate bay xxx (1552011)--4tabs]
"Order"=hex:08,00,00,00,02,00,00,00,ba,03,00,00,01,00,00,00,04,00,00,00,f8,00,
00,00,01,00,00,00,ea,00,32,00,84,00,00,00,00,3c,a1,9c,20,00,5f,37,32,30,50,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \Plump (2962011)--25tabs]
"Order"=hex:08,00,00,00,02,00,00,00,74,00,00,00,01,00,00,00,01,00,00,00,68,00,
00,00,00,00,00,00,5a,00,31,00,00,00,00,00,00,b2,0d,90,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \Plump (2962011)--25tabs\window 105]
"Order"=hex:08,00,00,00,02,00,00,00,54,0f,00,00,01,00,00,00,19,00,00,00,7e,00,
00,00,05,00,00,00,70,00,32,00,84,00,00,00,00,e1,ee,19,20,00,42,42,57,49,4e,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \porn (1192011)--13tabs]
"Order"=hex:08,00,00,00,02,00,00,00,72,00,00,00,01,00,00,00,01,00,00,00,66,00,
00,00,00,00,00,00,58,00,31,00,00,00,00,00,00,ef,e3,42,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \porn (1192011)--13tabs\window 85]
"Order"=hex:08,00,00,00,02,00,00,00,f8,0a,00,00,01,00,00,00,0d,00,00,00,de,00,
00,00,00,00,00,00,d0,00,32,00,84,00,00,00,00,c1,02,ee,20,00,5f,37,32,30,50,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \porn (2392011)--15tabs]
"Order"=hex:08,00,00,00,02,00,00,00,76,00,00,00,01,00,00,00,01,00,00,00,6a,00,
00,00,00,00,00,00,5c,00,31,00,00,00,00,00,00,4b,d5,09,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \porn (2392011)--15tabs\window 1094]
"Order"=hex:08,00,00,00,02,00,00,00,74,0d,00,00,01,00,00,00,0f,00,00,00,f8,00,
00,00,06,00,00,00,ea,00,32,00,84,00,00,00,00,18,fa,ed,20,00,5f,37,32,30,50,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \porn (2492011)--26tabs]
"Order"=hex:08,00,00,00,02,00,00,00,76,00,00,00,01,00,00,00,01,00,00,00,6a,00,
00,00,00,00,00,00,5c,00,31,00,00,00,00,00,00,86,9f,1f,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \porn (2492011)--26tabs\window 1626]
"Order"=hex:08,00,00,00,02,00,00,00,94,15,00,00,01,00,00,00,1a,00,00,00,d4,00,
00,00,11,00,00,00,c6,00,32,00,84,00,00,00,00,ae,63,90,20,00,5f,37,32,30,50,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \Restore session on 1092011 (1092011)--17tabs]
"Order"=hex:08,00,00,00,02,00,00,00,72,00,00,00,01,00,00,00,01,00,00,00,66,00,
00,00,00,00,00,00,58,00,31,00,00,00,00,00,00,d6,1c,29,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \Restore session on 1092011 (1092011)--17tabs\window 59]
"Order"=hex:08,00,00,00,02,00,00,00,f4,0c,00,00,01,00,00,00,11,00,00,00,e6,00,
00,00,0b,00,00,00,d8,00,32,00,84,00,00,00,00,40,56,a3,20,00,36,54,4f,31,30,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \Rooting Phone (7102011)--4tabs]
"Order"=hex:08,00,00,00,02,00,00,00,74,00,00,00,01,00,00,00,01,00,00,00,68,00,
00,00,00,00,00,00,5a,00,31,00,00,00,00,00,00,c8,68,18,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \Rooting Phone (7102011)--4tabs\window 137]
"Order"=hex:08,00,00,00,02,00,00,00,84,03,00,00,01,00,00,00,04,00,00,00,f8,00,
00,00,00,00,00,00,ea,00,32,00,84,00,00,00,00,5f,75,22,20,00,5f,47,55,49,44,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \STVI (2062011)--7tabs]
"Order"=hex:08,00,00,00,02,00,00,00,74,00,00,00,01,00,00,00,01,00,00,00,68,00,
00,00,00,00,00,00,5a,00,31,00,00,00,00,00,00,f5,56,57,10,00,57,49,4e,44,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\F*r*e*s*h*S*t*a*r*t* *S*e*s*s*i*o*n*s* \STVI (2062011)--7tabs\window 276]
"Order"=hex:08,00,00,00,02,00,00,00,62,05,00,00,01,00,00,00,07,00,00,00,c2,00,
00,00,02,00,00,00,b4,00,32,00,84,00,00,00,00,d0,94,4a,20,00,42,4f,41,52,44,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\G*a*m*i*n*g* \Singularity]
"Order"=hex:08,00,00,00,02,00,00,00,ba,01,00,00,01,00,00,00,02,00,00,00,ce,00,
00,00,00,00,00,00,c0,00,32,00,84,00,00,00,00,cd,25,75,20,00,50,52,4f,54,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\I*n*t*e*r*n*e*t* *M*a*r*k*e*t*i*n*g* \Forums]
"Order"=hex:08,00,00,00,02,00,00,00,3a,02,00,00,01,00,00,00,03,00,00,00,be,00,
00,00,00,00,00,00,b0,00,32,00,84,00,00,00,00,f8,be,3f,20,00,42,4c,41,43,4b,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\I*n*t*e*r*n*e*t* *M*a*r*k*e*t*i*n*g* \Generators]
"Order"=hex:08,00,00,00,02,00,00,00,5e,07,00,00,01,00,00,00,0c,00,00,00,aa,00,
00,00,00,00,00,00,9c,00,32,00,84,00,00,00,00,cb,75,33,20,00,42,45,48,49,4e,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\I*n*t*e*r*n*e*t* *M*a*r*k*e*t*i*n*g* \My Web Sites]
"Order"=hex:08,00,00,00,02,00,00,00,a8,01,00,00,01,00,00,00,03,00,00,00,96,00,
00,00,00,00,00,00,88,00,32,00,84,00,00,00,00,d0,10,51,20,00,46,41,53,54,48,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\I*n*t*e*r*n*e*t* *M*a*r*k*e*t*i*n*g* \Spam]
"Order"=hex:08,00,00,00,02,00,00,00,66,01,00,00,01,00,00,00,02,00,00,00,9a,00,
00,00,00,00,00,00,8c,00,32,00,84,00,00,00,00,a4,2d,e4,20,00,47,45,54,54,49,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*o*v*e* *D*o*w*n*t*o*w*n* \Apartment Rentals]
"Order"=hex:08,00,00,00,02,00,00,00,9e,03,00,00,01,00,00,00,05,00,00,00,92,00,
00,00,00,00,00,00,84,00,32,00,84,00,00,00,00,25,01,37,20,00,43,4f,4c,55,4d,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*o*v*e* *D*o*w*n*t*o*w*n* \Business App Pages]
"Order"=hex:08,00,00,00,02,00,00,00,22,01,00,00,01,00,00,00,02,00,00,00,8e,00,
00,00,01,00,00,00,80,00,32,00,84,00,00,00,00,8b,96,82,20,00,53,4b,59,44,52,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*o*v*e* *D*o*w*n*t*o*w*n* \Continuing Education]
"Order"=hex:08,00,00,00,02,00,00,00,e8,01,00,00,01,00,00,00,02,00,00,00,f8,00,
00,00,00,00,00,00,ea,00,32,00,84,00,00,00,00,05,c2,1d,20,00,4f,48,49,4f,52,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*o*v*e* *D*o*w*n*t*o*w*n* \Marketing]
"Order"=hex:08,00,00,00,02,00,00,00,e2,10,00,00,01,00,00,00,1b,00,00,00,82,00,
00,00,00,00,00,00,74,00,32,00,84,00,00,00,00,db,07,50,20,00,31,26,31,43,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*o*v*e* *D*o*w*n*t*o*w*n* \Real Estate]
"Order"=hex:08,00,00,00,02,00,00,00,22,0f,00,00,01,00,00,00,1a,00,00,00,6a,00,
00,00,08,00,00,00,5c,00,31,00,00,00,00,00,00,fe,95,7f,10,00,45,58,49,54,52,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*o*v*e* *D*o*w*n*t*o*w*n* \Real Estate\Exit Realty]
"Order"=hex:08,00,00,00,02,00,00,00,2a,0d,00,00,01,00,00,00,15,00,00,00,68,00,
00,00,10,00,00,00,5a,00,31,00,00,00,00,00,00,3d,a7,29,10,00,55,54,49,4c,54,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*o*v*e* *D*o*w*n*t*o*w*n* \Real Estate\Exit Realty\Utiltities]
"Order"=hex:08,00,00,00,02,00,00,00,96,00,00,00,01,00,00,00,01,00,00,00,8a,00,
00,00,00,00,00,00,7c,00,32,00,84,00,00,00,00,dc,b7,4a,20,00,41,45,50,4f,48,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*o*v*e* *D*o*w*n*t*o*w*n* \Real Estate\Hard Money Loans]
"Order"=hex:08,00,00,00,02,00,00,00,a6,03,00,00,01,00,00,00,05,00,00,00,c2,00,
00,00,00,00,00,00,b4,00,32,00,84,00,00,00,00,c3,85,dc,20,00,42,52,4f,4f,4b,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*o*v*e* *D*o*w*n*t*o*w*n* \Real Estate\Investing]
"Order"=hex:08,00,00,00,02,00,00,00,d6,04,00,00,01,00,00,00,07,00,00,00,a8,00,
00,00,00,00,00,00,9a,00,32,00,84,00,00,00,00,d9,c6,64,20,00,48,41,52,44,4d,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*o*v*e* *D*o*w*n*t*o*w*n* \Real Estate\Marketing Sites]
"Order"=hex:08,00,00,00,02,00,00,00,e8,08,00,00,01,00,00,00,0b,00,00,00,9a,00,
00,00,00,00,00,00,8c,00,32,00,84,00,00,00,00,da,63,f8,20,00,41,4c,45,58,41,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*o*v*e* *D*o*w*n*t*o*w*n* \Real Estate\Printers and Sign]
"Order"=hex:08,00,00,00,02,00,00,00,66,0a,00,00,01,00,00,00,11,00,00,00,b6,00,
00,00,00,00,00,00,a8,00,32,00,84,00,00,00,00,2e,92,ca,20,00,34,42,55,4d,50,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*o*v*e* *D*o*w*n*t*o*w*n* \Sites to link to]
"Order"=hex:08,00,00,00,02,00,00,00,04,01,00,00,01,00,00,00,01,00,00,00,f8,00,
00,00,00,00,00,00,ea,00,32,00,84,00,00,00,00,04,0a,75,20,00,43,4f,4c,55,4d,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*y* *S*t*u*f*f* \Fishing]
"Order"=hex:08,00,00,00,02,00,00,00,32,07,00,00,01,00,00,00,0b,00,00,00,be,00,
00,00,00,00,00,00,b0,00,32,00,84,00,00,00,00,f4,b6,73,20,00,41,52,45,57,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*y* *S*t*u*f*f* \Galaxy S2]
"Order"=hex:08,00,00,00,02,00,00,00,ea,0a,00,00,01,00,00,00,0e,00,00,00,f8,00,
00,00,0c,00,00,00,ea,00,32,00,84,00,00,00,00,be,da,85,20,00,5f,41,43,53,5f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*y* *S*t*u*f*f* \Guitar Tabs]
"Order"=hex:08,00,00,00,02,00,00,00,4c,04,00,00,01,00,00,00,06,00,00,00,b6,00,
00,00,00,00,00,00,a8,00,32,00,84,00,00,00,00,93,e1,22,20,00,39,31,31,54,41,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*y* *S*t*u*f*f* \Local]
"Order"=hex:08,00,00,00,02,00,00,00,78,01,00,00,01,00,00,00,03,00,00,00,7c,00,
00,00,00,00,00,00,6e,00,32,00,84,00,00,00,00,1a,3f,ad,20,00,43,4f,4c,55,4d,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*y* *S*t*u*f*f* \Rhymes]
"Order"=hex:08,00,00,00,02,00,00,00,d8,01,00,00,01,00,00,00,03,00,00,00,9c,00,
00,00,00,00,00,00,8e,00,32,00,84,00,00,00,00,b2,c8,fc,20,00,46,52,45,45,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\M*y* *S*t*u*f*f* \Travel]
"Order"=hex:08,00,00,00,02,00,00,00,a2,03,00,00,01,00,00,00,05,00,00,00,82,00,
00,00,00,00,00,00,74,00,32,00,84,00,00,00,00,bb,29,45,20,00,41,4d,45,52,49,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\P*e*e*r*t*o*P*e*e*r* \AD]
"Order"=hex:08,00,00,00,02,00,00,00,e0,09,00,00,01,00,00,00,10,00,00,00,78,00,
00,00,0e,00,00,00,6a,00,32,00,84,00,00,00,00,65,e6,c3,20,00,41,44,55,4c,54,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\P*e*e*r*t*o*P*e*e*r* \Apple Stuff]
"Order"=hex:08,00,00,00,02,00,00,00,f6,01,00,00,01,00,00,00,03,00,00,00,80,00,
00,00,00,00,00,00,72,00,32,00,84,00,00,00,00,dd,04,3c,20,00,41,50,50,54,52,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\P*e*e*r*t*o*P*e*e*r* \Exclusive]
"Order"=hex:08,00,00,00,02,00,00,00,12,0f,00,00,01,00,00,00,1c,00,00,00,78,00,
00,00,00,00,00,00,6a,00,32,00,84,00,00,00,00,dd,8b,41,20,00,41,43,45,54,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\P*e*e*r*t*o*P*e*e*r* \Exclusive Not Signed Up]
"Order"=hex:08,00,00,00,02,00,00,00,8a,05,00,00,01,00,00,00,0b,00,00,00,70,00,
00,00,00,00,00,00,62,00,32,00,84,00,00,00,00,ef,0f,a0,20,00,62,69,74,47,41,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\P*e*e*r*t*o*P*e*e*r* \Forums]
"Order"=hex:08,00,00,00,02,00,00,00,20,04,00,00,01,00,00,00,06,00,00,00,a4,00,
00,00,00,00,00,00,96,00,32,00,84,00,00,00,00,d0,24,0f,20,00,46,49,4c,45,4e,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\P*e*e*r*t*o*P*e*e*r* \Meta Search Engines]
"Order"=hex:08,00,00,00,02,00,00,00,f2,02,00,00,01,00,00,00,05,00,00,00,bc,00,
00,00,00,00,00,00,ae,00,32,00,84,00,00,00,00,a9,1b,c5,20,00,4c,4f,4f,4b,54,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\P*e*e*r*t*o*P*e*e*r* \Security and Apps]
"Order"=hex:08,00,00,00,02,00,00,00,4a,02,00,00,01,00,00,00,04,00,00,00,7e,00,
00,00,00,00,00,00,70,00,32,00,84,00,00,00,00,5b,7f,18,20,00,42,49,53,53,46,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \Christmas Gifts]
"Order"=hex:08,00,00,00,02,00,00,00,88,01,00,00,01,00,00,00,02,00,00,00,be,00,
00,00,00,00,00,00,b0,00,32,00,84,00,00,00,00,bc,0b,8a,20,00,50,4f,47,4f,50,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \Comparison Shopping and Deals]
"Order"=hex:08,00,00,00,02,00,00,00,2a,09,00,00,01,00,00,00,0d,00,00,00,6c,00,
00,00,00,00,00,00,5e,00,32,00,84,00,00,00,00,8a,cb,ce,20,00,42,69,7a,72,61,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \Department Stores]
"Order"=hex:08,00,00,00,02,00,00,00,a6,01,00,00,01,00,00,00,03,00,00,00,72,00,
00,00,00,00,00,00,64,00,32,00,84,00,00,00,00,38,99,70,20,00,4b,4d,41,52,54,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \Electronics, Computers & Accessories]
"Order"=hex:08,00,00,00,02,00,00,00,2a,0c,00,00,01,00,00,00,12,00,00,00,be,00,
00,00,00,00,00,00,b0,00,32,00,84,00,00,00,00,f9,31,18,20,00,41,42,54,2d,43,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \Grocery & Pharmacy & Gas]
"Order"=hex:08,00,00,00,02,00,00,00,24,04,00,00,01,00,00,00,07,00,00,00,7e,00,
00,00,06,00,00,00,70,00,31,00,00,00,00,00,00,53,20,17,10,00,57,45,45,4b,4c,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \Grocery & Pharmacy & Gas\Weekly Shopping Lists]
"Order"=hex:08,00,00,00,02,00,00,00,f8,01,00,00,01,00,00,00,03,00,00,00,6a,00,
00,00,01,00,00,00,5c,00,32,00,84,00,00,00,00,57,e6,59,20,00,4b,72,6f,67,65,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \Office Supplies]
"Order"=hex:08,00,00,00,02,00,00,00,98,04,00,00,01,00,00,00,06,00,00,00,f8,00,
00,00,00,00,00,00,ea,00,32,00,84,00,00,00,00,be,af,88,20,00,42,41,4c,53,41,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \sex supplements]
"Order"=hex:08,00,00,00,02,00,00,00,38,03,00,00,01,00,00,00,05,00,00,00,68,00,
00,00,03,00,00,00,5a,00,31,00,00,00,00,00,00,21,54,04,10,00,4e,45,57,46,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \sex supplements\New folder]
"Order"=hex:08,00,00,00,02,00,00,00,b6,0c,00,00,01,00,00,00,11,00,00,00,cc,00,
00,00,00,00,00,00,be,00,32,00,84,00,00,00,00,cb,e6,7f,20,00,41,4d,41,5a,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \sit stand desks, and laptop mounts]
"Order"=hex:08,00,00,00,02,00,00,00,82,09,00,00,01,00,00,00,0c,00,00,00,f8,00,
00,00,00,00,00,00,ea,00,32,00,84,00,00,00,00,4d,25,ee,20,00,41,4d,41,5a,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \Supplements]
"Order"=hex:08,00,00,00,02,00,00,00,86,0a,00,00,01,00,00,00,10,00,00,00,76,00,
00,00,06,00,00,00,68,00,31,00,00,00,00,00,00,49,0b,6d,10,00,42,53,4e,53,48,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \Supplements\BSN Shopping tabs]
"Order"=hex:08,00,00,00,02,00,00,00,7a,00,00,00,01,00,00,00,01,00,00,00,6e,00,
00,00,00,00,00,00,60,00,31,00,00,00,00,00,00,d6,8f,02,10,00,5f,46,4f,4c,44,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \Supplements\BSN Shopping tabs\[Folder Name]]
"Order"=hex:08,00,00,00,02,00,00,00,a0,08,00,00,01,00,00,00,0b,00,00,00,60,00,
00,00,0a,00,00,00,52,00,32,00,84,00,00,00,00,48,da,05,20,00,35,34,32,30,7e,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \Travel]
"Order"=hex:08,00,00,00,02,00,00,00,c2,01,00,00,01,00,00,00,02,00,00,00,be,00,
00,00,00,00,00,00,b0,00,32,00,84,00,00,00,00,4a,ef,d1,20,00,41,49,52,46,41,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*h*o*p*p*i*n*g* \Under Armour]
"Order"=hex:08,00,00,00,02,00,00,00,5c,08,00,00,01,00,00,00,0b,00,00,00,f8,00,
00,00,00,00,00,00,ea,00,32,00,84,00,00,00,00,df,dc,79,20,00,42,55,59,4d,45,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*o*c*i*a*l*i*z*i*n*g* \Dating Sites]
"Order"=hex:08,00,00,00,02,00,00,00,98,08,00,00,01,00,00,00,0d,00,00,00,be,00,
00,00,00,00,00,00,b0,00,32,00,84,00,00,00,00,a8,2c,ba,20,00,41,52,45,59,4f,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*o*c*i*a*l*i*z*i*n*g* \Misc Socializing]
"Order"=hex:08,00,00,00,02,00,00,00,44,02,00,00,01,00,00,00,04,00,00,00,be,00,
00,00,00,00,00,00,b0,00,32,00,84,00,00,00,00,7d,b2,7a,20,00,4d,59,53,50,41,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*o*c*i*a*l*i*z*i*n*g* \Sed]
"Order"=hex:08,00,00,00,02,00,00,00,16,05,00,00,01,00,00,00,06,00,00,00,cc,00,
00,00,00,00,00,00,be,00,32,00,84,00,00,00,00,f5,cb,ad,20,00,41,43,4d,45,4c,\
.
[HKEY_USERS\S-1-5-21-1948204673-1780984394-1029538037-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\MenuOrder\Favorites\S*p*o*r*t*s* \Volleyball]
"Order"=hex:08,00,00,00,02,00,00,00,0e,07,00,00,01,00,00,00,09,00,00,00,ce,00,
00,00,00,00,00,00,c0,00,32,00,84,00,00,00,00,c4,14,6a,20,00,41,4c,4c,41,42,\
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe,-101"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\FlashUtil11e_ActiveX.exe"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\Windows\\SysWOW64\\Macromed\\Flash\\Flash11e.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Office\Common\Smart Tag\Actions\{B9A09F18-45AB-4F09-A117-A4ADDA8FA8C8}]
@Denied: (A) (Everyone)
"Solution"="{36eb6792-3a29-43b3-8cd0-f67d266fb426}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane]
@Denied: (A) (Everyone)
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Schema Library\ActionsPane\0]
"Key"="ActionsPane"
"Location"="c:\\Program Files (x86)\\Common Files\\Microsoft Shared\\VSTO\\8.0\\ActionsPane.xsd"
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
"MSCurrentCountry"=dword:000000b5
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0001\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0002\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0003\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0004\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0005\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0006\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0007\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
------------------------ Other Running Processes ------------------------
.
c:\program files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
c:\program files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
c:\program files (x86)\Microsoft SQL Server\90\Shared\sqlbrowser.exe
c:\program files (x86)\TeamViewer\Version7\TeamViewer.exe
c:\program files (x86)\TeamViewer\Version7\tv_w32.exe
.
**************************************************************************
.
Completion time: 2012-01-24 00:13:43 - machine was rebooted
ComboFix-quarantined-files.txt 2012-01-24 05:13
ComboFix2.txt 2012-01-19 22:13
ComboFix3.txt 2012-01-17 00:04
.
Pre-Run: 82,123,976,704 bytes free
Post-Run: 82,115,186,688 bytes free
.
- - End Of File - - 4E8221E34CC9CC91015F783775E60156
OTL logfile created on: 1/24/2012 12:20:38 AM - Run 9
OTL by OldTimer - Version 3.2.31.0 Folder = C:\Users\Eric\Desktop\geeks to go
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy
8.00 Gb Total Physical Memory | 5.37 Gb Available Physical Memory | 67.14% Memory free
15.99 Gb Paging File | 13.02 Gb Available in Paging File | 81.41% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]
%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 454.05 Gb Total Space | 76.55 Gb Free Space | 16.86% Space Free | Partition Type: NTFS
Computer Name: ERIC-LAPTOP | User Name: Eric | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days
========== Processes (SafeList) ========== PRC - [2012/01/16 21:03:01 | 000,584,192 | ---- | M] (OldTimer Tools) -- C:\Users\Eric\Desktop\geeks to go\OTL.exe
PRC - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2011/12/14 06:59:20 | 002,984,832 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2011/12/14 06:59:18 | 010,981,248 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer.exe
PRC - [2011/12/14 06:41:54 | 000,116,608 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version7\tv_w32.exe
PRC - [2011/11/22 15:45:32 | 000,161,336 | ---- | M] (Google) -- C:\Users\Eric\AppData\Local\Google\Google Talk Plugin\googletalkplugin.exe
PRC - [2011/09/06 19:12:06 | 000,045,056 | ---- | M] (Intuit) -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe
PRC - [2011/08/30 11:18:30 | 002,358,656 | ---- | M] (TeamViewer GmbH) -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe
PRC - [2011/05/27 15:23:00 | 001,300,264 | ---- | M] (Synaptics, Inc.) -- C:\Program Files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe
PRC - [2011/04/16 19:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccsvchst.exe
PRC - [2011/02/10 19:47:12 | 000,062,184 | ---- | M] (Xobni Corporation) -- C:\Program Files (x86)\Xobni\XobniService.exe
PRC - [2010/11/20 07:17:55 | 000,257,536 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\wbem\WmiPrvSE.exe
========== Modules (No Company Name) ========== MOD - [2012/01/08 08:41:12 | 000,093,696 | ---- | M] () -- C:\Program Files (x86)\FileZilla FTP Client\fzshellext.dll
MOD - [2012/01/05 04:48:44 | 000,411,120 | ---- | M] () -- C:\Users\Eric\AppData\Local\Google\Chrome\Application\16.0.912.75\ppgooglenaclpluginchrome.dll
MOD - [2012/01/05 04:48:43 | 003,767,792 | ---- | M] () -- C:\Users\Eric\AppData\Local\Google\Chrome\Application\16.0.912.75\pdf.dll
MOD - [2012/01/05 04:47:19 | 000,122,880 | ---- | M] () -- C:\Users\Eric\AppData\Local\Google\Chrome\Application\16.0.912.75\avutil-51.dll
MOD - [2012/01/05 04:47:18 | 000,222,208 | ---- | M] () -- C:\Users\Eric\AppData\Local\Google\Chrome\Application\16.0.912.75\avformat-53.dll
MOD - [2012/01/05 04:47:17 | 001,746,432 | ---- | M] () -- C:\Users\Eric\AppData\Local\Google\Chrome\Application\16.0.912.75\avcodec-53.dll
MOD - [2012/01/05 02:06:01 | 008,593,056 | ---- | M] () -- C:\Users\Eric\AppData\Local\Google\Chrome\Application\16.0.912.75\gcswf32.dll
========== Win32 Services (SafeList) ========== SRV:
64bit: - [2011/03/16 10:19:38 | 000,222,720 | ---- | M] (CrashPlan) [Auto | Running] -- C:\Program Files\CrashPlan\CrashPlanService.exe -- (CrashPlanService)
SRV:
64bit: - [2010/08/19 16:43:24 | 000,386,344 | ---- | M] () [Auto | Running] -- C:\Program Files\CyberLink\Shared files\RichVideo64.exe -- (RichVideo64)
SRV:
64bit: - [2009/08/18 02:36:20 | 000,203,264 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\SysNative\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2011/12/24 17:50:18 | 000,652,872 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2011/12/14 06:59:20 | 002,984,832 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2011/09/06 19:12:06 | 000,045,056 | ---- | M] (Intuit) [Auto | Running] -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\QBCFMonitorService.exe -- (QBCFMonitorService)
SRV - [2011/08/30 11:18:30 | 002,358,656 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files (x86)\TeamViewer\Version6\TeamViewer_Service.exe -- (TeamViewer6)
SRV - [2011/05/27 15:23:00 | 001,300,264 | ---- | M] (Synaptics, Inc.) [Auto | Running] -- C:\Program Files (x86)\Synaptics\Scrybe\Service\ScrybeUpdater.exe -- (ScrybeUpdater)
SRV - [2011/04/16 19:45:11 | 000,130,008 | R--- | M] (Symantec Corporation) [Unknown | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ccSvcHst.exe -- (NIS)
SRV - [2011/02/10 19:47:12 | 000,062,184 | ---- | M] (Xobni Corporation) [Auto | Running] -- C:\Program Files (x86)\Xobni\XobniService.exe -- (XobniService)
SRV - [2011/01/26 14:53:27 | 000,654,848 | ---- | M] (Macrovision Europe Ltd.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/07/23 21:10:38 | 000,061,440 | ---- | M] (Intuit Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Intuit\QuickBooks\FCS\Intuit.QuickBooks.FCS.exe -- (QBFCService)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
========== Driver Services (SafeList) ========== DRV:
64bit: - [2012/01/13 14:38:39 | 000,096,376 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\SMR210.SYS -- (SMR210)
DRV:
64bit: - [2011/12/10 15:24:08 | 000,023,152 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:
64bit: - [2011/11/24 22:23:32 | 000,203,320 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudmdm.sys -- (ssudmdm) SAMSUNG Mobile USB Modem Drivers (DEVGURU Ver.)
DRV:
64bit: - [2011/11/24 22:23:28 | 000,098,616 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ssudbus.sys -- (dg_ssudbus) SAMSUNG Mobile USB Composite Device Driver (DEVGURU Ver.)
DRV:
64bit: - [2011/08/02 16:38:56 | 000,051,712 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:
64bit: - [2011/07/08 16:45:12 | 000,386,168 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1206000.01D\symnets.sys -- (SymNetS)
DRV:
64bit: - [2011/05/11 07:58:02 | 000,174,200 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:
64bit: - [2011/04/14 13:28:10 | 000,015,728 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVVideoCardMirror.sys -- (AirDisplayMirror)
DRV:
64bit: - [2011/04/14 13:28:08 | 000,015,728 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AVVideoCard.sys -- (AirDisplay)
DRV:
64bit: - [2011/04/13 14:04:38 | 000,045,432 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\point64.sys -- (Point64)
DRV:
64bit: - [2011/03/31 18:32:00 | 001,424,944 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:
64bit: - [2011/03/30 22:04:12 | 000,043,640 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SymIMV.sys -- (SymIM)
DRV:
64bit: - [2011/03/30 22:00:09 | 000,744,568 | ---- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtsp64.sys -- (SRTSP)
DRV:
64bit: - [2011/03/30 22:00:09 | 000,040,568 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1206000.01D\srtspx64.sys -- (SRTSPX) Symantec Real Time Storage Protection (PEL)
DRV:
64bit: - [2011/03/14 21:31:23 | 000,912,504 | ---- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1206000.01D\symefa64.sys -- (SymEFA)
DRV:
64bit: - [2011/03/11 01:41:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:
64bit: - [2011/03/11 01:41:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:
64bit: - [2011/01/27 01:47:10 | 000,450,680 | ---- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1206000.01D\symds64.sys -- (SymDS)
DRV:
64bit: - [2011/01/27 00:07:06 | 000,171,128 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1206000.01D\ironx64.sys -- (SymIRON)
DRV:
64bit: - [2010/11/20 08:33:35 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:
64bit: - [2010/11/20 06:07:05 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:
64bit: - [2010/11/20 04:37:42 | 000,109,056 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\sdbus.sys -- (sdbus)
DRV:
64bit: - [2010/06/23 09:10:56 | 000,344,680 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:
64bit: - [2010/04/03 10:30:40 | 000,313,696 | ---- | M] (Microsoft Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\RsFx0150.sys -- (RsFx0150)
DRV:
64bit: - [2010/01/13 16:37:18 | 007,675,392 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\NETw5s64.sys -- (NETw5s64) Intel®
DRV:
64bit: - [2009/12/30 11:21:24 | 000,031,800 | ---- | M] (VS Revo Group) [File_System | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\revoflt.sys -- (Revoflt)
DRV:
64bit: - [2009/08/18 03:48:48 | 006,037,504 | ---- | M] (ATI Technologies Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\atikmdag.sys -- (atikmdag)
DRV:
64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:
64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:
64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:
64bit: - [2009/06/10 16:01:06 | 001,146,880 | ---- | M] (LSI Corp) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\agrsm64.sys -- (AgereSoftModem)
DRV:
64bit: - [2009/06/10 15:35:28 | 005,434,368 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\netw5v64.sys -- (netw5v64) Intel®
DRV:
64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:
64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:
64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:
64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:
64bit: - [2009/05/18 02:47:08 | 000,034,152 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:
64bit: - [2009/04/24 17:29:40 | 000,206,336 | ---- | M] (Realtek ) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\Rtlh64.sys -- (RTL8169)
DRV:
64bit: - [2009/02/12 18:28:00 | 000,057,344 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rimspe64.sys -- (rimspci)
DRV:
64bit: - [2009/01/14 16:50:50 | 000,055,296 | ---- | M] (REDC) [Kernel | Auto | Running] -- C:\Windows\SysNative\drivers\rixdpe64.sys -- (rixdpcie)
DRV:
64bit: - [2007/11/09 17:00:30 | 000,026,968 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\TVALZ_O.SYS -- (TVALZ)
DRV:
64bit: - [2007/09/04 13:29:04 | 000,014,872 | ---- | M] (TOSHIBA Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\Thpevm.sys -- (Thpevm)
DRV:
64bit: - [2006/11/20 00:11:06 | 000,008,704 | ---- | M] (TOSHIBA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\FwLnk.sys -- (FwLnk)
DRV - [2011/11/30 21:25:03 | 001,157,240 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\BASHDefs\20120121.002\BHDrvx64.sys -- (BHDrvx64)
DRV - [2011/11/09 10:44:45 | 000,482,936 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2011/11/09 10:44:45 | 000,138,360 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2011/10/31 20:37:57 | 002,048,632 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120123.002\EX64.SYS -- (NAVEX15)
DRV - [2011/10/31 20:37:57 | 000,117,880 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\VirusDefs\20120123.002\ENG64.SYS -- (NAVENG)
DRV - [2011/08/22 23:17:32 | 000,488,568 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\Definitions\IPSDefs\20120120.002\IDSviA64.sys -- (IDSVia64)
DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)
========== Standard Registry (SafeList) ========== ========== Internet Explorer ========== IE:
64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = %SystemRoot%\system32\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page =
https://movedowntown...n/MyOffice.aspxIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-us
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 24 7E A0 6E 5F 45 CC 01 [binary data]
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,Default_Search_URL =
http://www.google.com/ieIE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Search,SearchAssistant =
http://www.google.com/ieIE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
========== FireFox ========== FF:
64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_11_1_102.dll File not found
FF:
64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@google.com/npPicasa3,version=3.0.0: C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll (Google, Inc.)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin: C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll (Sun Microsystems, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\4.0.60831.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3538.0513: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@videolan.org/vlc,version=1.1.11: C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll (the VideoLAN Team)
FF - HKCU\Software\MozillaPlugins\@Skype Limited.com/Facebook Video Calling Plugin: C:\Users\Eric\AppData\Local\Facebook\Video\Skype\npFacebookVideoCalling.dll (Skype Limited)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Eric\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Eric\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Eric\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Eric\AppData\Local\Google\Update\1.3.21.79\npGoogleUpdate3.dll (Google Inc.)
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\IPSFFPlgn\ [2011/10/05 22:30:42 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_18.1.0.37\coFFPlgn_2011_7_4_3 [2012/01/24 00:07:24 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Components: C:\Program Files (x86)\Mozilla Firefox\components [2012/01/15 02:01:46 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Mozilla Firefox 9.0.1\extensions\\Plugins: C:\Program Files (x86)\Mozilla Firefox\plugins [2011/11/02 10:10:16 | 000,000,000 | ---D | M]
[2011/06/03 16:44:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eric\AppData\Roaming\Mozilla\Extensions
[2011/06/03 16:44:31 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eric\AppData\Roaming\Mozilla\Extensions\{ea278cf8-93cd-484f-b951-57360482d33a}
[2012/01/06 16:22:11 | 000,000,000 | ---D | M] (No name found) -- C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\agrx8nd2.default\extensions
[2011/06/29 09:55:20 | 000,000,000 | ---D | M] (All-in-One Gestures) -- C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\agrx8nd2.default\extensions\{8b86149f-01fb-4842-9dd8-4d7eb02fd055}
[2011/11/12 12:30:20 | 000,000,000 | ---D | M] (Greasemonkey) -- C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\agrx8nd2.default\extensions\{e4a8a97b-f2ed-450b-b12d-ee082ba24781}
[2011/12/31 19:06:08 | 000,000,000 | ---D | M] ("Xmarks") -- C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\agrx8nd2.default\extensions\
[email protected][2011/11/05 13:15:14 | 000,000,000 | ---D | M] (LastPass) -- C:\Users\Eric\AppData\Roaming\Mozilla\Firefox\Profiles\agrx8nd2.default\extensions\
[email protected][2012/01/14 01:06:10 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions
[2011/12/21 02:24:52 | 000,121,816 | ---- | M] (Mozilla Foundation) -- C:\Program Files (x86)\mozilla firefox\components\browsercomps.dll
[2011/10/03 04:06:04 | 000,476,904 | ---- | M] (Sun Microsystems, Inc.) -- C:\Program Files (x86)\mozilla firefox\plugins\npdeployJava1.dll
[2011/12/20 23:30:41 | 000,002,252 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\bing.xml
[2011/12/20 23:30:41 | 000,002,040 | ---- | M] () -- C:\Program Files (x86)\mozilla firefox\searchplugins\twitter.xml
========== Chrome ========== CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}sourceid=chrome&ie={inputEncoding}&q={searchTerms}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}{google:instantFieldTrialGroupParameter}client=chrome&hl={language}&q={searchTerms}
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Eric\AppData\Local\Google\Chrome\Application\16.0.912.75\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.6.9 (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\npqtplugin7.dll
CHR - plugin: Java Deployment Toolkit 6.0.270.7 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npdeployJava1.dll
CHR - plugin: Java Platform SE 6 U27 (Enabled) = C:\Program Files (x86)\Java\jre6\bin\new_plugin\npjp2.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\4.0.60531.0\npctrl.dll
CHR - plugin: Microsoft\u00AE Windows Media Player Firefox Plugin (Enabled) = C:\Program Files (x86)\Mozilla Firefox\plugins\np-mswmp.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Eric\AppData\Local\Google\Chrome\Application\16.0.912.75\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Eric\AppData\Local\Google\Chrome\Application\16.0.912.75\pdf.dll
CHR - plugin: NPLastPass (Enabled) = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\1.75.9_0\nplastpass.dll
CHR - plugin: Adobe Acrobat (Disabled) = C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\Browser\nppdf32.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Eric\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Eric\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Picasa (Enabled) = C:\Program Files (x86)\Google\Picasa3\npPicasa3.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.69\npGoogleUpdate3.dll
CHR - plugin: VLC Multimedia Plug-in (Enabled) = C:\Program Files (x86)\VideoLAN\VLC\npvlc.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Default Plug-in (Enabled) = default_plugin
CHR - Extension: Entanglement = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\aciahcmjmecflokailenpkdchphgkefd\2.7.9_0\
CHR - Extension: USA TODAY = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\aggljnipbdiebhbmadknfbjlhehbohbn\2.1_0\
CHR - Extension: Xmarks Bookmark Sync = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\ajpgkpeckebdhofmmjfgcjjiiejpodla\1.0.17_0\
CHR - Extension: Open _new & _blank in new background tab = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\bblhflcbilbefagmeoanbdiofmmnehda\1.0_0\
CHR - Extension: Adblock Plus (Beta) = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfhdojbkjhnklbpkdaibdccddilifddb\1.2_0\
CHR - Extension: Offline Google Mail = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\ejidjjhkpiempkbhmpbfngldlkglhimk\1.13_0\
CHR - Extension: LastPass = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\hdokiejnpimakedhajhdlcegeplioahd\1.80.5_0\
CHR - Extension: Google Voice (by Google) = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\kcnhkahnjcbndmmehfkdnkjomaanaooo\2.3.6.1_0\
CHR - Extension: Smooth Gestures = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfkgmnnajiljnolcgolmmgnecgldgeld\0.15.4.12_0\
CHR - Extension: Linkclump = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\lfpjkncokllnfokkgpkobnkbkmelfefj\2.0.16_0\
CHR - Extension: Copy Link Text = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\lhdokmjpoambonhlpgcodobebebjdeil\0.5.1_0\
CHR - Extension: Poppit = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\mcbkbpnkkkipelfledbfocopglifcfmi\2.2_0\
CHR - Extension: FreshStart - Cross Browser Session Manager = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmidkjogcjnnlfimjcedenagjfacpobb\1.5.4_0\
CHR - Extension: Better Pop Up Blocker = C:\Users\Eric\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmpeeekfhbmikbdhlpjbfmnpgcbeggic\2.1.6_0\
O1 HOSTS File: ([2012/01/24 00:07:35 | 000,000,027 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O2:
64bit: - BHO: (LastPass Browser Helper Object) - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar64.dll (LastPass)
O2 - BHO: (Symantec NCO BHO) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O2 - BHO: (Symantec Intrusion Prevention) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\ips\ipsbho.dll (Symantec Corporation)
O2 - BHO: (LastPass Browser Helper Object) - {95D9ECF5-2A4D-4550-BE49-70D42F71296E} - C:\Program Files (x86)\LastPass\LPBar.dll (LastPass)
O2 - BHO: (Adobe PDF Conversion Toolbar Helper) - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3:
64bit: - HKLM\..\Toolbar: (LastPass Toolbar) - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar64.dll (LastPass)
O3 - HKLM\..\Toolbar: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (LastPass Toolbar) - {9f6b5cc3-5c7b-4b5c-97af-19dec1e380e5} - C:\Program Files (x86)\LastPass\LPBar.dll (LastPass)
O3 - HKCU\..\Toolbar\WebBrowser: (Adobe PDF) - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O3 - HKCU\..\Toolbar\WebBrowser: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\18.6.0.29\coieplg.dll (Symantec Corporation)
O4:
64bit: - HKLM..\Run: [IntelliPoint] c:\Program Files\Microsoft IntelliPoint\ipoint.exe (Microsoft Corporation)
O4 - HKLM..\Run: [StartCCC] C:\Program Files (x86)\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKCU..\Run: [Dekisoft Monitor Off Utility] C:\Program Files (x86)\Monitor Off Utility\monoff.exe (Dekisoft)
O6 - HKLM\Software\Policies\Microsoft\Internet Explorer\Restrictions present
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: HideSCAHealth = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLinkedConnections = 1
O7 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDrives = 0
O8:
64bit: - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200 File not found
O8:
64bit: - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8:
64bit: - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Add to Google Photos Screensa&ver - C:\Windows\SysWow64\GPhotos.scr (Google Inc.)
O8 - Extra context menu item: Append to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert link target to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selected links to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert selection to existing PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O8 - Extra context menu item: Convert to Adobe PDF - C:\Program Files (x86)\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll (Adobe Systems Incorporated)
O9:
64bit: - Extra Button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPBar64.dll (LastPass)
O9 - Extra Button: LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPBar.dll (LastPass)
O9 - Extra 'Tools' menuitem : LastPass - {43699cd0-e34f-11de-8a39-0800200c9a66} - C:\Program Files (x86)\LastPass\LPBar.dll (LastPass)
O10 - Broken Internet access at catalog 000000000005
O16 - DPF: {02BCC737-B171-4746-94C9-0D8A0B2C0089}
http://office.micros...n/ieawsdc32.cab (Microsoft Office Template and Media Control)
O16 - DPF: {83AB6E4D-CDD7-11D3-B5E7-00104B9AFF6E}
http://cbrmls.columb...ol/IRCSharc.cab (GeacRevw Control)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 209.18.47.61 209.18.47.62
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{3315377E-1827-411A-8A89-D1292871D5AE}: DhcpNameServer = 209.18.47.61 209.18.47.62
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{51398D5A-0EC7-4C59-898D-AC16AE86436F}: NameServer = 209.18.47.61,209.18.47.62
O18:
64bit: - Protocol\Handler\intu-help-qb3 - No CLSID value found
O18:
64bit: - Protocol\Handler\livecall - No CLSID value found
O18:
64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:
64bit: - Protocol\Handler\msnim - No CLSID value found
O18:
64bit: - Protocol\Handler\qbwc - No CLSID value found
O18:
64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:
64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\intu-help-qb3 {c5e479ea-0a65-4b05-8c6c-2fc8cc682eb4} - C:\Program Files (x86)\Intuit\QuickBooks 2010\HelpAsyncPluggableProtocol.dll (Intuit, Inc.)
O20:
64bit: - HKLM Winlogon: Shell - (Explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (SystemPropertiesPerformance.exe) - C:\Windows\SysNative\SystemPropertiesPerformance.exe (Microsoft Corporation)
O20:
64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (Explorer.exe) -C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) -C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\TOSHIBA-1.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\TOSHIBA-1.jpg
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:
64bit: - HKLM\..comfile [open] -- "%1" %*
O35:
64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:
64bit: - HKLM\...com [@ = ComFile] -- "%1" %*
O37:
64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = ComFile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
========== Files/Folders - Created Within 30 Days ========== [2012/01/24 00:07:54 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/01/24 00:05:00 | 000,000,000 | ---D | C] -- C:\Windows\temp
[2012/01/23 19:08:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/01/23 19:08:08 | 000,023,152 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2012/01/23 19:08:08 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/01/21 20:03:27 | 001,447,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\lsasrv.dll
[2012/01/21 20:03:26 | 000,395,776 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\webio.dll
[2012/01/21 20:03:26 | 000,314,880 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\webio.dll
[2012/01/21 20:03:26 | 000,136,192 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspicli.dll
[2012/01/21 20:03:26 | 000,029,184 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\sspisrv.dll
[2012/01/21 20:03:26 | 000,028,160 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secur32.dll
[2012/01/17 12:39:44 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/01/16 20:10:40 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\Malwarebytes
[2012/01/16 20:10:31 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/01/16 18:39:41 | 000,518,144 | ---- | C] (SteelWerX) -- C:\Windows\SWREG.exe
[2012/01/16 18:39:41 | 000,060,416 | ---- | C] (NirSoft) -- C:\Windows\NIRCMD.exe
[2012/01/16 18:39:40 | 000,406,528 | ---- | C] (SteelWerX) -- C:\Windows\SWSC.exe
[2012/01/16 16:57:16 | 000,000,000 | ---D | C] -- C:\Windows\ERDNT
[2012/01/16 14:43:08 | 000,000,000 | ---D | C] -- C:\Qoobox
[2012/01/16 14:35:01 | 000,000,000 | ---D | C] -- C:\Users\Eric\Desktop\geeks to go
[2012/01/13 23:24:55 | 000,000,000 | ---D | C] -- C:\NBRT
[2012/01/13 20:04:49 | 000,000,000 | ---D | C] -- C:\NPE
[2012/01/13 17:20:43 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\Temp
[2012/01/13 16:21:42 | 000,034,152 | ---- | C] (GEAR Software Inc.) -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys
[2012/01/13 16:20:59 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NBRTWizardx64
[2012/01/13 16:20:59 | 000,000,000 | ---D | C] -- C:\Windows\SysNative\drivers\NBRTWizardx64\0401000.00F
[2012/01/13 16:20:57 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Norton Bootable Recovery Tool Wizard
[2012/01/13 16:20:57 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Norton Bootable Recovery Tool Wizard
[2012/01/13 16:14:15 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton
[2012/01/13 14:38:39 | 000,096,376 | ---- | C] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SMR210.SYS
[2012/01/11 16:06:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\GO Contact Sync Mod
[2012/01/11 16:06:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WebGear
[2012/01/11 15:04:53 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\NPE
[2012/01/11 03:27:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\679C1
[2012/01/11 02:56:37 | 001,572,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\quartz.dll
[2012/01/11 02:56:37 | 001,328,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\quartz.dll
[2012/01/11 02:56:37 | 000,514,560 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\qdvd.dll
[2012/01/11 02:56:37 | 000,366,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\qdvd.dll
[2012/01/11 02:56:35 | 001,731,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ntdll.dll
[2012/01/11 02:56:34 | 000,077,312 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\packager.dll
[2012/01/11 02:56:34 | 000,067,072 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\packager.dll
[2012/01/09 17:33:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PDF-XChange PDF Viewer
[2012/01/09 17:01:52 | 000,000,000 | ---D | C] -- C:\Users\Eric\Desktop\PDF-XChange.Viewer.Pro.v2.042.7.Multilingual.Cracked-EAT
[2012/01/09 16:01:24 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Roaming\com.adobe.mauby.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2012/01/09 14:25:55 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\{F5C9B070-3124-44D4-A2B0-51E843B0421E}
[2012/01/09 14:25:52 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\{26F4E894-BE27-4D56-80C2-DECD41B57B7F}
[2012/01/09 01:40:40 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\{5F690E7E-FE96-4F1C-ACFC-8A2FBDDD42AD}
[2012/01/09 01:40:38 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\{2FC95A88-D39F-459B-B7F0-C58608BE1660}
[2012/01/08 13:40:20 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\{3AACCF45-EC22-46EC-A236-C7D06B5C275F}
[2012/01/08 13:40:18 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\{D650295A-2195-425A-8A82-0CC902A6F37A}
[2012/01/08 01:40:11 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\{A3EF6F9B-EC64-4F35-B611-FA24D122696E}
[2012/01/08 01:40:09 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\{AECBE636-CA8D-47A8-9D8C-6A302B8981DE}
[2011/12/30 20:07:07 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\{CA8063F6-590E-4E7C-823F-2ADF139AC157}
[2011/12/30 20:07:05 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\{43FBE04C-7767-48A2-8A58-49B05224213C}
[2011/12/29 19:37:43 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\{3D35D1A2-7DDC-43A6-B5E6-A175EAB048CF}
[2011/12/29 19:37:40 | 000,000,000 | ---D | C] -- C:\Users\Eric\AppData\Local\{CDF54AE7-0EA6-4018-BA9E-89E8C01066CA}
[2011/12/25 23:00:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\iTunes
[2011/12/25 22:59:34 | 000,000,000 | ---D | C] -- C:\Program Files\iTunes
[2011/12/25 22:59:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\iTunes
[2011/12/25 22:59:34 | 000,000,000 | ---D | C] -- C:\Program Files\iPod
[2011/04/08 19:57:26 | 012,535,496 | ---- | C] (LastPass) -- C:\Program Files (x86)\Common Files\lpuninstall.exe
[2010/02/03 23:00:00 | 000,139,264 | ---- | C] ( ) -- C:\Windows\sipr3260.dll
========== Files - Modified Within 30 Days ========== [2012/01/24 00:24:39 | 000,011,120 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/01/24 00:24:39 | 000,011,120 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/01/24 00:08:27 | 000,001,888 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CrashPlan Tray.lnk
[2012/01/24 00:07:35 | 000,000,027 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\hosts
[2012/01/24 00:07:05 | 000,000,890 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/01/24 00:07:05 | 000,000,322 | ---- | M] () -- C:\Windows\tasks\GlaryInitialize.job
[2012/01/24 00:06:40 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2012/01/24 00:06:19 | 2145,898,495 | -HS- | M] () -- C:\hiberfil.sys
[2012/01/23 23:57:11 | 000,000,894 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/01/23 23:39:11 | 000,000,904 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1948204673-1780984394-1029538037-1000UA.job
[2012/01/23 22:44:05 | 000,000,924 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1948204673-1780984394-1029538037-1000UA.job
[2012/01/23 22:39:00 | 000,000,852 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-1948204673-1780984394-1029538037-1000Core.job
[2012/01/23 21:21:13 | 000,000,149 | ---- | M] () -- C:\Windows\ODBC.INI
[2012/01/23 19:08:10 | 000,001,120 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/23 15:15:50 | 000,000,869 | ---- | M] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/01/23 13:44:00 | 000,000,902 | ---- | M] () -- C:\Windows\tasks\FacebookUpdateTaskUserS-1-5-21-1948204673-1780984394-1029538037-1000Core.job
[2012/01/21 14:58:39 | 000,002,512 | ---- | M] () -- C:\{7FCD103C-5EDB-4F13-A9D0-4B70CDF0087E}
[2012/01/21 12:53:52 | 000,000,426 | ---- | M] () -- C:\Windows\BRWMARK.INI
[2012/01/18 17:42:43 | 000,093,508 | ---- | M] () -- C:\Users\Eric\Desktop\winsock2a.reg
[2012/01/17 12:39:51 | 000,255,874 | ---- | M] () -- C:\Users\Eric\Desktop\winsock2.reg
[2012/01/15 20:50:31 | 000,005,357 | ---- | M] () -- C:\Users\Eric\Desktop\Attach.zip
[2012/01/15 15:38:23 | 000,000,512 | ---- | M] () -- C:\Users\Eric\Desktop\MBR.dat
[2012/01/15 13:50:24 | 000,178,645 | ---- | M] () -- C:\Users\Eric\Desktop\20120114_001915.jpg
[2012/01/14 01:06:16 | 000,001,149 | ---- | M] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/01/13 18:05:50 | 000,122,616 | ---- | M] () -- C:\Users\Eric\Desktop\BFE.reg
[2012/01/13 16:21:35 | 000,001,544 | ---- | M] () -- C:\Users\Public\Desktop\Norton Bootable Recovery Tool Wizard.LNK
[2012/01/13 16:16:39 | 000,822,200 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2012/01/13 16:16:39 | 000,692,628 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2012/01/13 16:16:39 | 000,131,922 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2012/01/13 16:14:17 | 000,001,380 | ---- | M] () -- C:\Users\Eric\Desktop\Norton Installation Files.lnk
[2012/01/13 14:41:22 | 000,000,777 | ---- | M] () -- C:\Users\Eric\AppData\Roaming\SMRBackup210.dat
[2012/01/13 14:38:39 | 000,096,376 | ---- | M] (Symantec Corporation) -- C:\Windows\SysNative\drivers\SMR210.SYS
[2012/01/11 17:38:37 | 000,414,368 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2012/01/11 15:29:33 | 326,268,174 | ---- | M] () -- C:\Regbackup.reg
[2012/01/11 03:30:35 | 000,002,664 | ---- | M] () -- C:\{BA1E3C8B-3DD8-46EB-A96F-84A5AC9FAA45}
[2012/01/11 03:30:31 | 000,031,256 | ---- | M] () -- C:\{27665EE5-2AC5-443B-9FFE-7F6BCDEA2273}
[2012/01/05 16:00:16 | 001,329,952 | ---- | M] () -- C:\Users\Eric\Desktop\Average_Joes_To_Go_FA12.pdf
[2011/12/29 20:49:24 | 000,002,600 | ---- | M] () -- C:\{66706779-3150-4686-8960-64808F6A89F3}
[2011/12/25 23:00:18 | 000,001,790 | ---- | M] () -- C:\Users\Public\Desktop\iTunes.lnk
========== Files Created - No Company Name ========== [2012/01/24 00:08:27 | 000,001,888 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\CrashPlan Tray.lnk
[2012/01/23 19:08:10 | 000,001,120 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/01/23 15:15:50 | 000,000,869 | ---- | C] () -- C:\Users\Public\Desktop\CCleaner.lnk
[2012/01/21 14:58:39 | 000,002,512 | ---- | C] () -- C:\{7FCD103C-5EDB-4F13-A9D0-4B70CDF0087E}
[2012/01/18 17:42:43 | 000,093,508 | ---- | C] () -- C:\Users\Eric\Desktop\winsock2a.reg
[2012/01/17 12:39:51 | 000,255,874 | ---- | C] () -- C:\Users\Eric\Desktop\winsock2.reg
[2012/01/16 18:39:41 | 000,256,000 | ---- | C] () -- C:\Windows\PEV.exe
[2012/01/16 18:39:41 | 000,208,896 | ---- | C] () -- C:\Windows\MBR.exe
[2012/01/16 18:39:41 | 000,080,412 | ---- | C] () -- C:\Windows\grep.exe
[2012/01/16 18:39:41 | 000,068,096 | ---- | C] () -- C:\Windows\zip.exe
[2012/01/16 18:39:40 | 000,098,816 | ---- | C] () -- C:\Windows\sed.exe
[2012/01/15 20:50:31 | 000,005,357 | ---- | C] () -- C:\Users\Eric\Desktop\Attach.zip
[2012/01/15 15:38:23 | 000,000,512 | ---- | C] () -- C:\Users\Eric\Desktop\MBR.dat
[2012/01/15 13:47:24 | 000,178,645 | ---- | C] () -- C:\Users\Eric\Desktop\20120114_001915.jpg
[2012/01/14 01:06:15 | 000,001,149 | ---- | C] () -- C:\Users\Public\Desktop\Mozilla Firefox.lnk
[2012/01/13 18:05:49 | 000,122,616 | ---- | C] () -- C:\Users\Eric\Desktop\BFE.reg
[2012/01/13 16:21:35 | 000,001,544 | ---- | C] () -- C:\Users\Public\Desktop\Norton Bootable Recovery Tool Wizard.LNK
[2012/01/13 16:20:59 | 000,000,172 | ---- | C] () -- C:\Windows\SysNative\drivers\NBRTWizardx64\0401000.00F\isolate.ini
[2012/01/13 16:14:15 | 000,001,380 | ---- | C] () -- C:\Users\Eric\Desktop\Norton Installation Files.lnk
[2012/01/13 14:41:22 | 000,000,777 | ---- | C] () -- C:\Users\Eric\AppData\Roaming\SMRBackup210.dat
[2012/01/12 22:45:11 | 000,001,109 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TeamViewer 7.lnk
[2012/01/11 15:29:10 | 326,268,174 | ---- | C] () -- C:\Regbackup.reg
[2012/01/11 03:30:31 | 000,031,256 | ---- | C] () -- C:\{27665EE5-2AC5-443B-9FFE-7F6BCDEA2273}
[2012/01/11 03:30:31 | 000,002,664 | ---- | C] () -- C:\{BA1E3C8B-3DD8-46EB-A96F-84A5AC9FAA45}
[2012/01/05 15:55:56 | 001,329,952 | ---- | C] () -- C:\Users\Eric\Desktop\Average_Joes_To_Go_FA12.pdf
[2011/12/29 20:49:21 | 000,002,600 | ---- | C] () -- C:\{66706779-3150-4686-8960-64808F6A89F3}
[2011/12/25 23:00:17 | 000,001,790 | ---- | C] () -- C:\Users\Public\Desktop\iTunes.lnk
[2011/12/20 00:03:22 | 000,066,856 | ---- | C] () -- C:\Windows\SysWow64\SynTPEnhPS.dll
[2011/11/13 22:00:15 | 000,231,048 | -H-- | C] () -- C:\Windows\SysWow64\mlfcache.dat
[2011/09/16 11:54:48 | 000,030,568 | ---- | C] () -- C:\Windows\MusiccityDownload.exe
[2011/09/16 11:54:44 | 000,974,848 | ---- | C] () -- C:\Windows\SysWow64\cis-2.4.dll
[2011/09/16 11:54:44 | 000,081,920 | ---- | C] () -- C:\Windows\SysWow64\issacapi_bs-2.3.dll
[2011/09/16 11:54:44 | 000,065,536 | ---- | C] () -- C:\Windows\SysWow64\issacapi_pe-2.3.dll
[2011/09/16 11:54:44 | 000,057,344 | ---- | C] () -- C:\Windows\SysWow64\issacapi_se-2.3.dll
[2011/08/11 18:59:22 | 000,202,240 | ---- | C] () -- C:\Windows\patchw32.dll
[2011/05/12 15:25:44 | 000,797,020 | ---- | C] () -- C:\Users\Eric\AppData\Roaming\ericc2728.zip
[2011/05/03 10:48:36 | 000,000,320 | ---- | C] () -- C:\Users\Eric\AppData\Roaming\SEC540722.trad
[2011/05/03 10:48:24 | 000,000,043 | ---- | C] () -- C:\Windows\WALLSTRT.INI
[2011/03/24 12:38:31 | 000,000,341 | ---- | C] () -- C:\Windows\BCLWDDE.INI
[2011/03/12 15:22:21 | 000,010,240 | ---- | C] () -- C:\Users\Eric\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2011/02/07 13:22:51 | 000,001,465 | ---- | C] () -- C:\Windows\pcforms.ini
[2011/02/02 14:53:41 | 000,000,126 | ---- | C] () -- C:\Windows\QUICKEN.INI
[2011/02/01 18:03:46 | 000,000,090 | ---- | C] () -- C:\Windows\QBChanUtil_Trigger.ini
[2011/02/01 17:32:18 | 000,000,000 | ---- | C] () -- C:\Windows\nsreg.dat
[2011/01/28 14:34:08 | 000,000,426 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2011/01/27 16:49:45 | 000,037,843 | ---- | C] () -- C:\Users\Eric\AppData\Roaming\Comma Separated Values (Windows).ADR
[2011/01/27 15:08:04 | 000,000,149 | ---- | C] () -- C:\Windows\ODBC.INI
[2011/01/26 15:04:13 | 000,000,410 | ---- | C] () -- C:\Windows\ODBCINST.INI
[2011/01/25 22:37:48 | 000,743,534 | ---- | C] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2011/01/25 20:03:48 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2011/01/25 16:50:16 | 000,000,000 | ---- | C] () -- C:\Windows\ToDisc.INI
[2011/01/25 13:36:46 | 000,000,017 | RHS- | C] () -- C:\Windows\SysWow64\drivers\fbd.sys
[2011/01/25 03:12:44 | 000,000,000 | ---- | C] () -- C:\Windows\NDSTray.INI
[2010/12/29 01:23:14 | 000,079,360 | ---- | C] () -- C:\Windows\SysWow64\ff_vfw.dll
[2010/06/30 20:26:00 | 000,365,568 | ---- | C] () -- C:\Windows\SysWow64\WINCTL32.DLL
[2010/06/30 20:26:00 | 000,055,808 | ---- | C] () -- C:\Windows\ICE_JNIRegistry.dll
[2010/06/30 20:26:00 | 000,049,152 | ---- | C] () -- C:\Windows\SysWow64\Simspy32.dll
[2010/06/30 20:26:00 | 000,032,768 | ---- | C] () -- C:\Windows\Java2INI.dll
[2010/06/23 11:35:52 | 000,790,528 | ---- | C] () -- C:\Windows\SysWow64\xvidcore.dll
[2010/06/23 11:35:52 | 000,134,144 | ---- | C] () -- C:\Windows\SysWow64\xvidvfw.dll
[2010/03/15 04:31:48 | 000,165,376 | ---- | C] () -- C:\Windows\SysWow64\unrar.dll
[2009/12/13 15:58:21 | 000,000,008 | RHS- | C] () -- C:\Windows\neoqaz2.dll
[2009/07/14 00:38:36 | 000,067,584 | --S- | C] () -- C:\Windows\bootstat.dat
[2009/07/13 21:35:51 | 000,000,741 | ---- | C] () -- C:\Windows\SysWow64\NOISE.DAT
[2009/07/13 21:34:42 | 000,215,943 | ---- | C] () -- C:\Windows\SysWow64\dssec.dat
[2009/07/13 19:10:29 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2009/07/13 18:42:10 | 000,064,000 | ---- | C] () -- C:\Windows\SysWow64\BWContextHandler.dll
[2009/07/13 16:03:59 | 000,364,544 | ---- | C] () -- C:\Windows\SysWow64\msjetoledb40.dll
[2009/06/10 16:26:10 | 000,673,088 | ---- | C] () -- C:\Windows\SysWow64\mlang.dat
[2007/02/05 19:05:26 | 000,000,038 | ---- | C] () -- C:\Windows\AviSplitter.INI
[2006/11/02 09:12:52 | 000,217,088 | ---- | C] () -- C:\Windows\SysWow64\missouri.dll
[2005/01/17 07:10:16 | 000,045,056 | ---- | C] () -- C:\Windows\SysWow64\BRTCPCON.DLL
[2004/08/09 07:00:42 | 000,000,114 | ---- | C] () -- C:\Windows\SysWow64\BRLMW03A.INI
[2003/02/28 15:51:00 | 000,163,840 | ---- | C] () -- C:\Windows\SysWow64\easysoap.dll
[2003/01/28 02:09:00 | 000,143,360 | ---- | C] () -- C:\Windows\SysWow64\libexpat.dll
[2002/02/27 10:41:28 | 000,024,576 | ---- | C] () -- C:\Windows\SysWow64\nsldappr32v50.dll
[2002/02/27 10:41:26 | 000,139,264 | ---- | C] () -- C:\Windows\SysWow64\nsldap32v50.dll
[2002/02/27 10:41:26 | 000,040,960 | ---- | C] () -- C:\Windows\SysWow64\nsldapssl32v50.dll
========== Alternate Data Streams ========== @Alternate Data Stream - 8 bytes -> C:\Windows:
< End of report >