Jump to content

Welcome to Geeks to Go - Register now for FREE

Need help with your computer or device? Want to learn new tech skills? You're in the right place!
Geeks to Go is a friendly community of tech experts who can solve any problem you have. Just create a free account and post your question. Our volunteers will reply quickly and guide you through the steps. Don't let tech troubles stop you. Join Geeks to Go now and get the support you need!

How it Works Create Account
Photo

malware - http://isearch.claro-search.com/ [Solved]


  • This topic is locked This topic is locked

#1
dreamfalcon21

dreamfalcon21

    Member

  • Member
  • PipPip
  • 21 posts
Hi,

My system has been infected with the isearch-claro-search.com and I have so far been unsuccessful in removing this.

I read the post in "http://www.geekstogo...s-cant-remove/" and run the ADWcleaner, but the problem still persists.

OTL logs are pasted below, extras below that, and finally the ADWCleaner logs. I have also downloaded Malwarebytes Antimalware tool but it is not identifying anything wrong. Any help in resolving this will be much appreciated.

OTL logfile created on: 8/24/2012 5:02:40 PM - Run 1
OTL by OldTimer - Version 3.2.58.1 Folder = C:\Users\i5\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.92 Gb Total Physical Memory | 1.46 Gb Available Physical Memory | 49.94% Memory free
5.83 Gb Paging File | 3.63 Gb Available in Paging File | 62.27% Paging File free
Paging file location(s): d:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 195.31 Gb Total Space | 172.10 Gb Free Space | 88.12% Space Free | Partition Type: NTFS
Drive D: | 386.11 Gb Total Space | 367.06 Gb Free Space | 95.07% Space Free | Partition Type: NTFS

Computer Name: I5-PC | User Name: i5 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/08/24 16:34:30 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\i5\Desktop\OTL.exe
PRC - [2012/08/18 03:58:57 | 001,229,848 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2012/07/26 10:29:46 | 000,244,656 | ---- | M] (Facebook) -- C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe
PRC - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/07/03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/07/03 13:46:42 | 000,973,488 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2012/04/21 15:11:09 | 000,077,064 | ---- | M] () -- C:\Program Files (x86)\WordWeb\wweb32.exe
PRC - [2012/04/04 11:23:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/06/09 04:22:52 | 000,100,256 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
PRC - [2011/06/09 04:19:55 | 000,329,056 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
PRC - [2011/02/15 17:56:42 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe
PRC - [2010/12/20 16:00:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/12/20 16:00:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/12/05 07:09:24 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe


========== Modules (No Company Name) ==========

MOD - [2012/08/18 03:58:55 | 000,442,392 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\ppgooglenaclpluginchrome.dll
MOD - [2012/08/18 03:58:54 | 012,236,824 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll
MOD - [2012/08/18 03:58:52 | 003,997,720 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\pdf.dll
MOD - [2012/08/18 03:57:36 | 000,526,872 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\libglesv2.dll
MOD - [2012/08/18 03:57:35 | 000,104,984 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\libegl.dll
MOD - [2012/08/18 03:57:23 | 000,144,424 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\avutil-51.dll
MOD - [2012/08/18 03:57:22 | 000,266,792 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\avformat-54.dll
MOD - [2012/08/18 03:57:21 | 002,480,680 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\avcodec-54.dll
MOD - [2012/08/14 15:33:25 | 006,611,456 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll
MOD - [2012/08/14 15:33:19 | 011,833,344 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll
MOD - [2012/08/14 15:32:43 | 012,436,480 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012/08/14 15:32:37 | 001,591,808 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012/08/14 15:32:26 | 005,452,800 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012/08/14 15:32:20 | 000,971,264 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012/08/14 15:32:16 | 007,967,232 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012/08/14 15:32:06 | 011,492,864 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2012/07/26 10:30:04 | 021,014,960 | ---- | M] () -- C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\libcef.dll
MOD - [2012/07/26 10:29:40 | 000,283,568 | ---- | M] () -- C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\CefSharp.WinForms.dll
MOD - [2012/07/26 10:29:36 | 000,455,600 | ---- | M] () -- C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\CefSharp.dll
MOD - [2012/07/15 12:27:53 | 002,216,480 | ---- | M] () -- C:\Windows\SysWOW64\wweb32.dll
MOD - [2012/07/15 12:25:02 | 000,022,800 | ---- | M] () -- C:\Program Files (x86)\WordWeb\WUCNT.dll
MOD - [2012/04/21 15:11:09 | 000,077,064 | ---- | M] () -- C:\Program Files (x86)\WordWeb\wweb32.exe
MOD - [2011/06/09 04:22:52 | 000,100,256 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
MOD - [2011/06/09 04:19:55 | 000,013,664 | ---- | M] () -- C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll
MOD - [2010/11/21 08:54:08 | 002,927,616 | ---- | M] () -- C:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2010/11/11 16:09:46 | 000,133,024 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\WindowsApiHookDll32.dll
MOD - [2010/11/11 16:08:44 | 000,161,696 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\ActiveDetect32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2012/05/25 17:13:54 | 000,162,224 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
SRV:64bit: - [2012/05/25 16:59:02 | 000,210,616 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV:64bit: - [2012/05/25 16:58:32 | 000,199,304 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV:64bit: - [2012/04/19 08:22:48 | 000,502,032 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\mcafee\virusscan\mcods.exe -- (McODS)
SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2011/02/15 17:56:42 | 000,956,192 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McProxy)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McOobeSv)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV:64bit: - [2010/09/30 20:35:42 | 000,311,296 | ---- | M] (Realtek Semiconductor Corp.) [Auto | Running] -- C:\Program Files\Realtek\RtLED\RtLEDService.exe -- (RtLedService)
SRV:64bit: - [2010/09/22 23:40:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/08/09 20:11:46 | 000,220,528 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- c:\Program Files\mcafee\msc\McAWFwk.exe -- (McAWFwk)
SRV:64bit: - [2009/07/14 07:11:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/04/04 11:23:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/12/20 16:00:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010/12/20 16:00:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/11 02:53:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/03/01 12:16:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/02/22 13:29:46 | 000,647,208 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,487,296 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)
DRV:64bit: - [2012/02/22 13:29:46 | 000,289,664 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,229,528 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,160,792 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,075,936 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfenlfk.sys -- (mfenlfk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,065,264 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)
DRV:64bit: - [2011/06/09 04:34:04 | 000,039,008 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LhdX64.sys -- (LHDmgr)
DRV:64bit: - [2011/06/09 04:34:02 | 000,029,792 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV:64bit: - [2011/06/09 04:21:35 | 000,057,952 | ---- | M] (Lenovo) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fbfmon.sys -- (fbfmon)
DRV:64bit: - [2011/06/09 04:21:35 | 000,013,408 | ---- | M] (Lenovo) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BPntDrv.sys -- (BPntDrv)
DRV:64bit: - [2011/03/25 15:47:48 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011/03/11 12:11:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 12:11:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/18 13:41:54 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/02/15 12:15:16 | 000,349,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (BTWAMPFL)
DRV:64bit: - [2011/02/15 12:15:12 | 000,138,280 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2011/02/15 12:15:12 | 000,107,560 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2011/02/15 12:15:12 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2011/02/15 12:15:12 | 000,021,416 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010/12/22 17:49:58 | 001,407,024 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/12/05 07:09:44 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2010/11/30 12:10:04 | 000,307,304 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtsuvstor.sys -- (RSUSBVSTOR)
DRV:64bit: - [2010/11/21 08:54:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 08:53:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 08:53:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/10/28 15:46:24 | 004,716,608 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2010/10/19 14:04:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010/10/14 22:58:16 | 000,317,440 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010/05/31 09:16:50 | 000,333,928 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/07/21 19:50:06 | 000,121,840 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd)
DRV:64bit: - [2009/07/14 07:22:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 07:18:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 07:15:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/11 02:04:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/11 02:04:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/11 02:04:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/11 02:01:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/14 06:49:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co...=LENN&bmod=LENN
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com [binary data]
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.claro...000c0f8daa6d7b3
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.co...1I7LENN_enIN496
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7LENN_enIN496
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\npFbDesktopPlugin.dll (Facebook, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/08/10 08:27:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/08/23 19:25:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\WordWeb\WCaptureMoz [2012/08/16 12:53:51 | 000,000,000 | ---D | M]

[2012/08/24 14:34:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\i5\AppData\Roaming\Mozilla\Extensions
[2012/08/24 14:31:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - homepage: http://isearch.claro...000c0f8daa6d7b3
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://isearch.claro...000c0f8daa6d7b3
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.75\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.50524.0\npctrl.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

O1 HOSTS File: ([2012/08/13 13:27:43 | 000,000,849 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 50.194.176.39 SAP-BOBJ4
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20120810081925.dll (McAfee, Inc.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg64.dll (Google Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20120810081925.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4:64bit: - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Lenovo EE Boot Optimizer] C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe (Lenovo)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [OnekeyStudio] C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
O4 - HKLM..\Run: [WordWeb] C:\Program Files (x86)\WordWeb\wweb32.exe ()
O4 - HKLM..\Run: [YouCam Mirage] C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (CyberLink)
O4 - HKLM..\Run: [YouCam Tray] C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe (CyberLink Corp.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-676971024-488182067-3021444819-1000..\Run: [Facebook Update] C:\Users\i5\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-676971024-488182067-3021444819-1000..\Run: [RDReminder] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk = C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe (Facebook)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.200
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7F498266-AF17-45EB-969A-D0122626E259}: DhcpNameServer = 192.168.1.200
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B2F4FA5D-5F6B-452A-B8C7-9231DAE833EC}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/08/24 17:02:02 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\i5\Desktop\OTL.exe
[2012/08/24 16:21:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/08/24 15:51:46 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Malwarebytes
[2012/08/24 15:51:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/08/24 15:51:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/08/24 15:51:18 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2012/08/24 15:51:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/08/24 14:34:16 | 000,000,000 | ---D | C] -- C:\Users\i5\Desktop\Download
[2012/08/24 14:34:12 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Mozilla
[2012/08/24 14:31:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/08/24 13:50:44 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\dll-files.com
[2012/08/24 13:50:36 | 000,017,128 | ---- | C] (Dll-Files.com) -- C:\windows\SysNative\roboot64.exe
[2012/08/24 13:50:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dll-Files.com Fixer
[2012/08/24 13:50:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dll-Files.com Fixer
[2012/08/24 06:41:03 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\PhotoScape
[2012/08/24 06:23:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
[2012/08/24 06:22:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PhotoScape
[2012/08/23 19:59:30 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook
[2012/08/23 19:51:39 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Facebook
[2012/08/22 12:51:35 | 000,000,000 | ---D | C] -- C:\Users\i5\.businessobjects
[2012/08/17 14:06:59 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\MigWiz
[2012/08/16 12:53:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WordWeb
[2012/08/13 13:21:13 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\SAP BusinessObjects
[2012/08/13 13:21:13 | 000,000,000 | ---D | C] -- C:\Users\i5\Documents\My SAP BusinessObjects Documents
[2012/08/13 13:14:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SAP BusinessObjects BI platform 4.0
[2012/08/13 12:17:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012/08/13 12:17:09 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2012/08/13 12:06:46 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\XcelsiuscustomThemesAutoInfo
[2012/08/13 12:06:46 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\XcelsiuscustomThemes
[2012/08/13 12:06:40 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Xcelsius
[2012/08/13 12:03:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dashboard Design
[2012/08/13 12:01:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2012/08/13 12:01:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\MSSoap
[2012/08/13 11:57:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SAP BusinessObjects
[2012/08/13 11:02:20 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Transcend Elite
[2012/08/11 17:10:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent
[2012/08/11 17:05:59 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\uTorrent
[2012/08/11 08:01:04 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\eScription
[2012/08/11 08:00:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eScription
[2012/08/11 07:58:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\eScription
[2012/08/11 07:54:58 | 000,000,000 | ---D | C] -- C:\windows\Downloaded Installations
[2012/08/11 07:52:08 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Adobe
[2012/08/11 07:40:47 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\Wat
[2012/08/11 07:40:47 | 000,000,000 | ---D | C] -- C:\windows\SysNative\Wat
[2012/08/10 19:37:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/08/10 19:37:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/08/10 07:43:41 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012/08/10 07:43:41 | 000,000,000 | -HSD | C] -- C:\Boot
[2012/08/09 23:23:25 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012/08/09 23:12:53 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Google
[2012/08/09 22:38:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2012/08/09 22:30:27 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Macromedia
[2012/08/09 22:10:24 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Adobe
[2012/08/09 21:19:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SAP AG
[2012/08/09 21:14:14 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Diagnostics
[2012/08/09 19:06:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2012/08/09 19:06:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2012/08/09 18:48:57 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Microsoft Games
[2012/08/09 18:40:28 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\vlc
[2012/08/09 18:38:36 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Google
[2012/08/09 18:32:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012/08/09 18:32:20 | 093,721,296 | ---- | C] (Samsung Electronics Co., Ltd. ) -- C:\Users\i5\Desktop\Kies_2.3.2.12064_10_1.exe
[2012/08/09 18:31:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/08/09 18:31:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2012/08/09 18:31:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works
[2012/08/09 18:31:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2012/08/09 18:31:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2012/08/09 18:30:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2012/08/09 18:29:14 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012/08/09 18:29:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2012/08/09 18:28:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Microsoft Help
[2012/08/09 18:28:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2012/08/09 18:28:25 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2012/08/09 18:27:09 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\WinRAR
[2012/08/09 18:25:34 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/08/09 18:25:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/08/09 18:25:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR
[2012/08/09 18:20:28 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Broadcom
[2012/08/09 18:20:28 | 000,000,000 | ---D | C] -- C:\Users\i5\Documents\Bluetooth Exchange Folder
[2012/08/09 18:19:53 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\SRS Labs
[2012/08/09 18:19:11 | 000,000,000 | R--D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/08/09 18:19:11 | 000,000,000 | R--D | C] -- C:\Users\i5\Searches
[2012/08/09 18:19:11 | 000,000,000 | R--D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/08/09 18:19:10 | 000,000,000 | -H-D | C] -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/08/09 18:18:54 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Identities
[2012/08/09 18:18:51 | 000,000,000 | R--D | C] -- C:\Users\i5\Contacts
[2012/08/09 18:18:50 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/08/09 18:18:48 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\VirtualStore
[2012/08/09 18:18:38 | 000,000,000 | --SD | C] -- C:\Users\i5\AppData\Roaming\Microsoft
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Videos
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Saved Games
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Pictures
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Music
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Links
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Favorites
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Downloads
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Documents
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Desktop
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\AppData\Local\Temporary Internet Files
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Templates
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Start Menu
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\SendTo
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Recent
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\PrintHood
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\NetHood
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Documents\My Videos
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Documents\My Pictures
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Documents\My Music
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\My Documents
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Local Settings
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\AppData\Local\History
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Cookies
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Application Data
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\AppData\Local\Application Data
[2012/08/09 18:18:38 | 000,000,000 | -H-D | C] -- C:\Users\i5\AppData
[2012/08/09 18:18:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Temp
[2012/08/09 18:18:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Microsoft
[2012/08/09 18:18:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Media Center Programs
[2012/08/09 18:18:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
[2012/08/09 18:18:24 | 000,000,000 | -HSD | C] -- C:\Recovery

========== Files - Modified Within 30 Days ==========

[2012/08/24 16:57:55 | 000,000,916 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000UA.job
[2012/08/24 16:34:30 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\i5\Desktop\OTL.exe
[2012/08/24 16:28:38 | 000,000,912 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/24 16:25:10 | 000,021,072 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/24 16:25:10 | 000,021,072 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/24 16:21:17 | 000,001,828 | ---- | M] () -- C:\Users\Public\Desktop\McAfee AntiVirus Plus.lnk
[2012/08/24 16:20:54 | 000,729,688 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012/08/24 16:20:54 | 000,626,278 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012/08/24 16:20:54 | 000,107,522 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012/08/24 16:16:29 | 000,125,011 | ---- | M] () -- C:\windows\SysNative\fastboot.set
[2012/08/24 16:15:54 | 000,000,908 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/24 16:15:46 | 000,000,286 | ---- | M] () -- C:\windows\tasks\DLL-files.com Fixer_UPDATES.job
[2012/08/24 16:15:46 | 000,000,266 | ---- | M] () -- C:\windows\tasks\DLL-files.com Fixer_MONTHLY.job
[2012/08/24 16:15:34 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/08/24 15:51:34 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/24 13:50:35 | 000,002,028 | ---- | M] () -- C:\Users\i5\Desktop\Check PC For Errors.lnk
[2012/08/24 13:50:35 | 000,002,012 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2012/08/24 06:23:09 | 000,001,055 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk
[2012/08/24 06:23:09 | 000,001,031 | ---- | M] () -- C:\Users\i5\Desktop\PhotoScape.lnk
[2012/08/23 19:59:30 | 000,001,326 | ---- | M] () -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk
[2012/08/23 19:57:00 | 000,000,894 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000Core.job
[2012/08/21 15:26:23 | 000,007,639 | ---- | M] () -- C:\Users\i5\AppData\Local\Resmon.ResmonCfg
[2012/08/16 15:11:17 | 000,000,280 | ---- | M] () -- C:\windows\ODBC.INI
[2012/08/16 11:31:24 | 000,437,248 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012/08/15 12:27:59 | 000,001,133 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012/08/13 12:03:17 | 000,001,050 | ---- | M] () -- C:\Users\Public\Desktop\Dashboard Design.lnk
[2012/08/11 18:17:33 | 000,003,544 | ---- | M] () -- C:\bootsqm.dat
[2012/08/11 17:10:52 | 000,000,967 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/08/11 17:10:52 | 000,000,943 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/08/11 08:00:21 | 000,002,771 | ---- | M] () -- C:\Users\Public\Desktop\EditScript MT 9.lnk
[2012/08/10 19:38:04 | 000,001,945 | ---- | M] () -- C:\windows\epplauncher.mif
[2012/08/10 19:37:57 | 000,731,106 | ---- | M] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/08/09 23:47:53 | 000,108,227 | ---- | M] () -- C:\windows\SysWow64\license.rtf
[2012/08/09 23:47:53 | 000,108,227 | ---- | M] () -- C:\windows\SysNative\license.rtf
[2012/08/09 23:12:12 | 000,001,437 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/08/09 22:38:54 | 000,002,019 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/08/09 21:19:23 | 000,001,704 | ---- | M] () -- C:\Users\Public\Desktop\SAP Management Console.lnk
[2012/08/09 19:07:14 | 000,001,361 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2012/08/09 18:31:53 | 000,001,066 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/08/09 18:19:48 | 000,001,118 | ---- | M] () -- C:\Users\i5\Desktop\Cyberlink Power2Go.lnk
[2012/08/09 18:19:43 | 000,002,086 | ---- | M] () -- C:\Users\i5\Desktop\OneKey Recovery.lnk
[2012/07/30 08:23:24 | 093,721,296 | ---- | M] (Samsung Electronics Co., Ltd. ) -- C:\Users\i5\Desktop\Kies_2.3.2.12064_10_1.exe

========== Files Created - No Company Name ==========

[2012/08/24 15:51:34 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/24 13:50:47 | 000,000,286 | ---- | C] () -- C:\windows\tasks\DLL-files.com Fixer_UPDATES.job
[2012/08/24 13:50:46 | 000,000,266 | ---- | C] () -- C:\windows\tasks\DLL-files.com Fixer_MONTHLY.job
[2012/08/24 13:50:35 | 000,002,028 | ---- | C] () -- C:\Users\i5\Desktop\Check PC For Errors.lnk
[2012/08/24 13:50:35 | 000,002,012 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2012/08/24 06:23:09 | 000,001,055 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk
[2012/08/24 06:23:09 | 000,001,031 | ---- | C] () -- C:\Users\i5\Desktop\PhotoScape.lnk
[2012/08/23 19:59:30 | 000,001,326 | ---- | C] () -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk
[2012/08/23 19:52:34 | 000,000,916 | ---- | C] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000UA.job
[2012/08/23 19:52:34 | 000,000,894 | ---- | C] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000Core.job
[2012/08/16 12:53:53 | 000,001,966 | ---- | C] () -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WordWeb.lnk
[2012/08/16 12:53:52 | 002,216,480 | ---- | C] () -- C:\windows\SysWow64\wweb32.dll
[2012/08/13 14:36:49 | 000,000,280 | ---- | C] () -- C:\windows\ODBC.INI
[2012/08/13 12:03:17 | 000,001,050 | ---- | C] () -- C:\Users\Public\Desktop\Dashboard Design.lnk
[2012/08/13 11:41:00 | 000,001,133 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012/08/11 18:17:33 | 000,003,544 | ---- | C] () -- C:\bootsqm.dat
[2012/08/11 17:10:52 | 000,000,967 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/08/11 17:10:52 | 000,000,943 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/08/11 09:33:30 | 000,007,639 | ---- | C] () -- C:\Users\i5\AppData\Local\Resmon.ResmonCfg
[2012/08/11 08:00:21 | 000,002,771 | ---- | C] () -- C:\Users\Public\Desktop\EditScript MT 9.lnk
[2012/08/10 19:38:04 | 000,001,945 | ---- | C] () -- C:\windows\epplauncher.mif
[2012/08/10 19:37:59 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/08/10 19:37:57 | 000,731,106 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/08/10 07:43:48 | 000,383,786 | RHS- | C] () -- C:\bootmgr
[2012/08/09 23:12:12 | 000,001,437 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/08/09 22:38:54 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/08/09 22:38:54 | 000,002,019 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/08/09 21:19:23 | 000,001,704 | ---- | C] () -- C:\Users\Public\Desktop\SAP Management Console.lnk
[2012/08/09 21:19:23 | 000,001,686 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SAP Management Console.lnk
[2012/08/09 19:07:14 | 000,001,361 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2012/08/09 19:07:13 | 000,001,172 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ImageReady 7.0.lnk
[2012/08/09 19:07:13 | 000,001,167 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 7.0.lnk
[2012/08/09 18:31:53 | 000,001,066 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/08/09 18:31:17 | 021,073,406 | ---- | C] () -- C:\Users\i5\Desktop\vlc-1.1.11-win32.rar
[2012/08/09 18:19:28 | 000,001,409 | ---- | C] () -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012/08/09 18:19:16 | 000,001,443 | ---- | C] () -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/08/09 18:18:38 | 000,002,235 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/09 18:18:38 | 000,002,086 | ---- | C] () -- C:\Users\i5\Desktop\OneKey Recovery.lnk
[2012/08/09 18:18:38 | 000,001,118 | ---- | C] () -- C:\Users\i5\Desktop\Cyberlink Power2Go.lnk
[2012/08/09 18:18:38 | 000,000,290 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/08/09 18:18:38 | 000,000,272 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/08/09 18:18:38 | 000,000,189 | ---- | C] () -- C:\Users\i5\Desktop\Lenovo Telephony Start Now.url
[2011/06/09 04:20:00 | 002,086,240 | ---- | C] () -- C:\windows\SysWow64\LenovoVeriface.Interface.dll
[2011/06/09 04:20:00 | 001,500,512 | ---- | C] () -- C:\windows\SysWow64\Apblend.dll
[2011/06/09 04:20:00 | 001,171,456 | ---- | C] () -- C:\windows\SysWow64\PicNotify.dll
[2011/06/09 04:20:00 | 000,466,944 | ---- | C] () -- C:\windows\SysWow64\Lenovo.VerifaceStub.dll
[2011/06/09 04:19:53 | 001,044,480 | ---- | C] () -- C:\windows\SysWow64\3DImageRenderer.dll
[2011/06/09 04:07:54 | 000,089,328 | ---- | C] () -- C:\windows\un_dext.exe
[2011/06/09 04:07:54 | 000,087,928 | ---- | C] () -- C:\windows\SPRemove_x64.exe
[2011/06/09 04:07:54 | 000,003,566 | ---- | C] () -- C:\windows\Dext_09.ini
[2011/06/09 04:07:54 | 000,002,998 | ---- | C] () -- C:\windows\Dext_04.ini
[2011/06/09 04:07:54 | 000,002,790 | ---- | C] () -- C:\windows\Dext_2052.ini
[2011/06/09 04:07:54 | 000,002,573 | ---- | C] () -- C:\windows\Remove.ini
[2011/04/14 08:31:25 | 000,963,116 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin
[2011/04/14 08:31:22 | 000,216,876 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin
[2011/04/14 08:31:19 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin
[2011/04/14 08:21:06 | 000,066,856 | ---- | C] () -- C:\windows\SysWow64\SynTPEnhPS.dll

========== LOP Check ==========

[2012/08/24 13:50:44 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\dll-files.com
[2012/08/11 08:01:04 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\eScription
[2012/08/24 06:41:31 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\PhotoScape
[2012/08/13 13:21:13 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\SAP BusinessObjects
[2012/08/13 11:02:20 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\Transcend Elite
[2012/08/11 17:11:16 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\uTorrent
[2012/08/24 13:12:42 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\Xcelsius
[2012/08/13 12:06:46 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\XcelsiuscustomThemes
[2012/08/13 12:06:46 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\XcelsiuscustomThemesAutoInfo
[2012/08/24 16:15:46 | 000,000,266 | ---- | M] () -- C:\windows\Tasks\DLL-files.com Fixer_MONTHLY.job
[2012/08/24 16:15:46 | 000,000,286 | ---- | M] () -- C:\windows\Tasks\DLL-files.com Fixer_UPDATES.job
[2012/08/23 19:57:00 | 000,000,894 | ---- | M] () -- C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000Core.job
[2012/08/24 16:57:55 | 000,000,916 | ---- | M] () -- C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000UA.job
[2009/07/14 10:38:49 | 000,014,408 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >



OTL Extras logfile created on: 8/24/2012 5:02:40 PM - Run 1
OTL by OldTimer - Version 3.2.58.1 Folder = C:\Users\i5\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.92 Gb Total Physical Memory | 1.46 Gb Available Physical Memory | 49.94% Memory free
5.83 Gb Paging File | 3.63 Gb Available in Paging File | 62.27% Paging File free
Paging file location(s): d:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 195.31 Gb Total Space | 172.10 Gb Free Space | 88.12% Space Free | Partition Type: NTFS
Drive D: | 386.11 Gb Total Space | 367.06 Gb Free Space | 95.07% Space Free | Partition Type: NTFS

Computer Name: I5-PC | User Name: i5 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01E0EFFF-1230-4DBB-B394-40FB68941BB5}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{0DD69765-AB41-4302-A7CE-44BABF863BA0}" = lport=139 | protocol=6 | dir=in | app=system |
"{15EE831B-438F-4623-9A52-52073726DCE9}" = rport=137 | protocol=17 | dir=out | app=system |
"{17586DDD-09B9-4A67-AE79-DE9490EAF443}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1A2FC6A7-9B03-42C3-A97B-2FF497BE450C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1AA74A9D-B11E-482E-820B-019EA56746CF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2136CDCA-9F4C-4778-954D-CD34EC1DC78A}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{292051F4-C61F-4071-9B78-C32A456C41C4}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2BB0BA8F-A593-416C-973C-AE43E6EDFFF0}" = rport=139 | protocol=6 | dir=out | app=system |
"{3537CBAA-054E-402F-AD2A-FE6F7DC969B2}" = lport=138 | protocol=17 | dir=in | app=system |
"{3F2643FE-ABA3-4BE0-A992-2F96A662902C}" = lport=137 | protocol=17 | dir=in | app=system |
"{433AD7E7-E59D-4480-80BC-48E87F49213E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{43C55908-45BD-4C8A-8D66-0D24DE5281FE}" = lport=2869 | protocol=6 | dir=in | app=system |
"{607305D5-928A-4306-BB16-92C42FE6C167}" = lport=10243 | protocol=6 | dir=in | app=system |
"{7742C6A0-A6D9-482F-B934-94DECDECAEDA}" = rport=10243 | protocol=6 | dir=out | app=system |
"{9F67076B-FEBF-4877-B545-5FE056F620A8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A1F6C22B-B6B2-4AE1-8AA1-2DF68F83E6EF}" = lport=445 | protocol=6 | dir=in | app=system |
"{A3BF33A9-E955-4D57-8183-D485BD638F9C}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{C6219A4B-49AC-48B6-B82C-7A19027C514A}" = rport=445 | protocol=6 | dir=out | app=system |
"{CAFA0D10-AF12-4FC7-9B00-F6BA174796BC}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{CF03D8C3-D5ED-4269-8920-C22F95C97C56}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{D8052B9F-8405-4371-9CDA-60AA96CB77DF}" = rport=138 | protocol=17 | dir=out | app=system |
"{FDB374D3-1468-4D56-BCFC-802217D45B66}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FE3B1625-FA13-4854-AF61-CBDB1BA95025}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{031177BC-47D8-45EE-948F-EDE42DA49CDE}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{08554157-F4DC-4B72-9BF5-E4C2CC130EF7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{08611196-B0A9-4A40-8D6D-81F28F896361}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{08C30054-0A2F-4F82-85D0-4A9122318243}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{08DB19BE-B84C-43E1-8F4D-650F4467BB37}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{0F60D51A-343F-4F1B-A77E-3BF6281036E0}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{16E5C711-8750-47AA-A8F2-FFE4188C15CD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{34A5D0C0-7A5B-467B-802D-BAC8B7337EB5}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{44B7D80D-6E71-4D46-A01A-86E7BBD64FAB}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{47846671-6C6D-4D60-BD28-7085F21A21A6}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{578A0DD9-9BCB-46EE-B97D-514C0015F3A8}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{5E789850-4294-4E98-A843-829445FE3594}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{62628874-857D-44DB-B2C1-D976263F915B}" = protocol=6 | dir=out | app=system |
"{6616A798-5FC9-4503-8997-AAD595A05005}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{6D57DEF3-50B5-40E1-AA5F-97526D84BEDE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{73978E81-F256-4C4A-A4C9-450E27828F75}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{84C4C64F-3598-4EA2-BAA7-DAE08E19BC0B}" = protocol=58 | dir=out | [email protected],-28546 |
"{8B56405F-813F-4F66-AAD6-CE1606039161}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{8D593F24-3768-447B-B302-9D40D66AFB06}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8F9103CA-11C8-4D66-9E4A-9982B3D0D683}" = protocol=1 | dir=out | [email protected],-28544 |
"{C05BC242-4943-41DE-B428-E2EB4921E6AC}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{C3B4558D-69B5-4F99-BCCD-BB240A692053}" = protocol=58 | dir=in | [email protected],-28545 |
"{C6C6DD4A-B456-485A-8C15-3814B37985C1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C8E6C2E5-66A2-436E-A6D4-572AB434533B}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{C9848FDB-6FC0-4D92-AD42-AC8538CC0426}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{C9CFA290-0010-46A4-86A9-533EC9914698}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CCC66ECD-3CDF-43A0-913E-BADDE445245A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DFD2EAF4-A937-42F4-892F-994C8DA3724F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DFE6346D-C502-4204-8010-42DA363B0B04}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{E3EECCDD-6E97-465B-9766-A64F8001B482}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{E567318E-EC24-4177-B5A7-848CF04F36D3}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F2918D40-666A-467F-BE05-331D4CEAE73F}" = protocol=1 | dir=in | [email protected],-28543 |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java™ 7 Update 5 (64-bit)
"{2998191E-A35E-47E2-BE38-7702C731D722}" = SRS Premium Sound Control Panel
"{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}" = Lenovo Bluetooth with Enhanced Data Rate Software
"{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
"{ACB6F4ED-835B-44EC-9EFD-AC8C83D28597}" = RtLED
"{B2DFBCF2-D656-46E6-8BD2-ED599FB0C26C}" = SAP MMC SnapIn
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"EA12B1FB53CE4E387C31A85236C41EF559B5E392" = Windows Driver Package - Lenovo (ACPIVPC) System (12/02/2010 6.1.0.1)
"Lenovo EE Boot Optimizer" = Lenovo EE Boot Optimizer
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00183566-044A-465F-A316-97665F7DB343}" = platform.sdk.boe.com.slplugins.binfiles-4.0-core-32
"{003C2709-D01A-4F26-9D9B-A56A6751972D}" = connectivity.connectionserver.drivers.sybase.ctlib.config-4.0-core-nu
"{00734D48-2B0E-4AA2-973C-5E893B007763}" = olap.oda.ssas2005.java-4.0-core-nu
"{00C257BD-C218-4958-A09D-CEBD455443B8}" = connectivity.connectionserver.drivers.mysql.odbc-4.0-core-32
"{01C2619E-D79F-4983-BA39-5C7F2CBF057A}" = connectivity.connectionserver.drivers.informix.jdbc-4.0-core-nu
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam
"{028DBE4D-705F-4707-9983-EB05518E27D7}" = informationengine.qt.drivers.datafederator.odbc.config-4.0-core-32
"{02D3D6E6-9549-4540-8DB7-131DFBDAD47D}" = foundation.bcm.java.classes-4.0-core-nu
"{03193771-8DC4-40C8-99FA-DBC3BAEA6D3E}" = crystalreports.dataaccess.driver.psenterprise-4.0-core-32
"{038BB2E3-62C2-4EAD-9FE9-5EBEBF8357F3}" = datafederator.boe.client.java-4.0-core-nu
"{03ADEE2C-9BDF-4843-82D0-45BFF149074C}" = connectivity.connectionserver.drivers.mssqlsrv.odbc.config-4.0-en-nu
"{03C8BC71-C012-453E-B20A-BCA9F28D8651}" = crystalreports.dataaccess.driver.db2-4.0-en-32
"{0418C87C-9327-47E7-A3D0-0916CB947A3C}" = migration.reporter-4.0-en-32
"{04396999-6ADD-4927-914C-45C3ED13365D}" = informationengine.qt.drivers.progress.jdbc-4.0-core-nu
"{0449635A-700B-4D35-9B36-D4B4BE170684}" = tp.sap.jco-3.0.5-core-32
"{045617C0-E56C-45D5-9DB6-4BE975AED05A}" = platform.sdk.boe.java.classes-4.0-core-nu
"{0471DE53-F859-4591-AFD0-DD22A6CB9CC2}" = tp.ooc.java-4.0.5-core-nu
"{05031260-71CD-4E74-B53C-A0C795B5EB6F}" = crystalreports.dataaccess.driver.p2dbase-4.0-en-32
"{0584221A-97A7-4123-84E6-5A5892C0A1F1}" = webi.webiversion-4.0-core-32
"{06830350-AA9D-4BB4-AEE6-C5AEE6FCAA08}" = tools.i18n-4.0-core-32
"{075A7F25-1895-4841-9251-4349814ECF63}" = connectivity.connectionserver.drivers.oracle.jdbc-4.0-core-nu
"{07DD51EB-D521-43EC-9AA0-21652E1295E8}" = tp.netegrity.siteminder.cpp.smagent-6.0-core-32
"{0842CE13-B2FF-49FA-BE59-96ECE08857BA}" = crystalreports.boe.sdkplugins.java.crlov-4.0-core-nu
"{08B53286-F776-4BAF-8544-1FE7520E4048}" = tp.datadirect.cpp-6.0-core-32
"{091F4468-FCAB-4F34-9BD3-4DFD58E2C032}" = platform.webservices.cons.dsws.legacydotnet2-4.0-core-32
"{092D9D9F-78DE-4E22-933A-2B0E8CC29B9B}" = tp.eclipse.aspectj.classes-1.6.5-core-nu
"{09C0F5C8-2AEB-4A42-B850-FF9882693CB6}" = crystalreports.boe.sdkplugins.java.managedreports-4.0-core-nu
"{0A0C9850-5754-4812-8615-1F78A059E3B6}" = crystalreports.cpp.runtimeshare-4.0-core-32
"{0A262EA4-D727-40BC-84AC-154D6F5D1B70}" = crystalreports.cpp.businessview.sdk-4.0-en-32
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0B18FC59-1FFB-4E89-A757-F2D89BC077F7}" = connectivity.connectionserver.drivers.informix.odbc-4.0-core-32
"{0B61B26C-1F0F-48AF-ACD1-ADD680CD008A}" = informationengine.qt.drivers.generic.jdbc-4.0-core-nu
"{0B799160-49B9-43D5-929D-B048C82D22C6}" = EditScript MT
"{0BBA949B-FF59-4E22-BD76-9197533FACB3}" = tp.apache.commons.java.classes-3.1-core-nu
"{0BCC554D-5820-4963-9223-339329E307C5}" = tp.ooc.cpp-3.3.2-core-32
"{0BF246BD-68E3-439A-8B04-7B11A3D9DC03}" = informationengine.qt.drivers.greenplum.odbc.config-4.0-core-nu
"{0C29318C-86B7-40DA-8AFD-2D10A3AB0015}" = tp.antlr.java-3.1.1-core-nu
"{0C6EAF85-B69F-4875-AE6E-F7BF39B92452}" = olap.oda.api_services.java-4.0-core-nu
"{0CA4293C-8902-4DC3-B844-ABF26558E0FC}" = crystalreports.cpp.filedialog-4.0-en-32
"{0D3B494E-C042-42D5-9905-BAAE2143EB16}" = informationengine.qt.drivers.sybase.odbc.config-4.0-core-nu
"{0D5679E0-7575-4E2D-BFCF-1CC052CD8316}" = crystalreports.dataaccess.driver.sap-4.0-en-32
"{0DAF19E3-1F7C-4A9A-8DF3-E9C977C6D6A1}" = connectivity.connectionserver.drivers.teradata.odbc.config-4.0-en-nu
"{0DCBAD0B-27C4-416C-BED4-723D64B01FF1}" = xcelsius.assets-4.0-core-32
"{0DFBA76C-C5E2-4B96-A741-633C0F465F41}" = repoaccess.bo_storage-4.0-core-32
"{0EB2ABA3-0867-4684-88C6-AF38F93B6C8B}" = platform.sdk.boe.java.sap.plugins_bundle-4.0-core-nu
"{0F1F7DCE-D7E9-48FB-9FE8-24CB45636596}" = tp.castor-1.3-core-nu
"{0FC43627-7DBB-4485-878B-B92473B98EBD}" = connectivity.connectionserver.drivers.msaccess.odbc-4.0-core-32
"{1039F9EB-0237-4A5D-8042-E9D3C0E73500}" = re.shared.webservices.cons.dsws.javasdk-4.0-core-nu
"{103D21F5-95E2-43B9-82C2-C79A2EDE6B50}" = informationengine.qt.drivers.neoview.jdbc-4.0-core-nu
"{111D6660-D51A-4D11-A4B7-D2A87A13110A}" = crystalreports.dataaccess.driver.filesystem-4.0-core-32
"{119BE0EF-59D9-4612-B3F4-675152BD1168}" = tp.apache.log4j.bundle-1.2.6_sap.1-core-nu
"{11D49E6E-EFC9-45C3-975B-9FDB2125ACF7}" = informationengine.qt.drivers.datafederator.jdbc-4.0-core-nu
"{120B73E9-E544-43AB-A147-394E23B5865D}" = cvom.java.ui_helpers-4.0-core-nu
"{1281C902-7FEF-4403-A7CE-91A2C0174873}" = webi.resdk-4.0-core-nu
"{12A3827E-CD52-4F56-9C59-40738E0F2A4B}" = connectivity.connectionserver.drivers.personalfiles.odbc.config-4.0-core-32
"{12B96A76-43D0-4546-9351-E44F72507827}" = olap.oda.core.java-4.0-core-nu
"{137E9F19-AE30-4DC1-B7AA-F1E83308BBC1}" = crystalreports.dataaccess.driver.java-4.0-core-nu
"{1383CCDF-7C62-442A-9B45-92B4B8B23B98}" = SAP BusinessObjects BI platform 4.0 Client Tools
"{13976822-8340-4422-B586-FF9A2BC837EF}" = repoaccess.async_scheduling-4.0-core-32
"{13EC197B-95A6-4295-99DA-D1A0D26C0F96}" = tp.apache.derby.classes-10.2.2.0-core-nu
"{1425445E-F894-4C79-B092-5873AD856C82}" = shared.library.keycode.defn-4.0-core-32
"{149056B0-4C7F-4126-8EEF-66260105F4CA}" = product.shared.installiverse.reg-4.0-core-nu
"{15201CB5-8209-4F26-B6B9-7B0844DD07C7}" = tp.ibm.icu.java-3.8.1-core-nu
"{158E8D09-A827-44D2-A166-95E25C875238}" = repoaccess.extensions.ds_excel.java-4.0-core-nu
"{15F87172-A567-426A-9353-5F8A9D925F22}" = cvom.java.classes-4.0-en-nu
"{170334EF-3E95-4B9E-88FD-E00294F46DDA}" = tp.sap.pluginwrapper.dotnet-720-core-32
"{17221B10-14A6-4E0E-8E9B-E5628B70866D}" = crystalreports.dataaccess.driver.adoplus-4.0-en-32
"{172D8E90-C81A-4704-9D5B-E10D62723303}" = olap.analysis.implementation.cpp.sofa-4.0-core-32
"{17730789-B659-449E-B090-16F4BB0DED4C}" = platform.client.cpp.plugins-4.0-core-32
"{181D3741-8C38-4FD0-8A42-D5FEA4267DE7}" = repoaccess.repo_proxy_jni.java-4.0-core-nu
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18F461BC-E460-11DE-9C59-3ECC56D89593}" = Dashboard Design
"{193707DA-8B72-48D8-888C-FBBA32189919}" = migration.busobj.dpxml-4.0-core-32
"{1988BCCD-A635-4C7D-9931-B370F4BC6CB4}" = universedesigner.rptdisp-4.0-core-32
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{19EF00A1-B676-46F1-949B-70D939B24163}" = connectivity.connectionserver.drivers.db2.odbc-4.0-core-32
"{1A4E8488-33A6-4483-9E36-D8E6D94DA21C}" = informationengine.ieserver.inproc-4.0-core-32
"{1A6F325E-6CD2-4A2B-B5AD-21395F3BF380}" = repoaccess.container.java.shared_classes-4.0-core-nu
"{1AC03186-5F8F-45F7-B0EE-AF5540474C01}" = platform.sdk.boe.com.slplugins.pinfiles-4.0-core-nu
"{1B1E4BFC-81A1-4BAD-AB58-15F136361F1D}" = shared.library.cxlib.cxlib-4.0-core-32
"{1B2D7B3A-7D62-44CC-B894-12B9836F1DB4}" = crystalreports.boe.serviceplugins.pss.java-4.0-core-nu
"{1B62A129-B2D0-49BA-90A8-45275CA2C685}" = crystalreports.cpp.businessview.sdk-4.0-core-32
"{1B83AFB1-957B-40D2-91C4-F545A5BEB5D9}" = connectivity.connectionserver.drivers.open-4.0-core-nu
"{1BFE8C8F-71A9-4FDF-9271-B96886C6B2F5}" = connectivity.connectionserver.plugin.corba.cpp-4.0-core-32
"{1C3CEB55-5B02-40D4-AB3B-A53A2FAA00E4}" = crystalreports.dataaccess.driver.p2sexchange-4.0-core-32
"{1C8CB977-3EDD-49E8-B8C1-47143E1A5AA1}" = migration.conversion.ct-4.0-en-32
"{1CEA7276-10B2-4825-B971-D42611A730E4}" = connectivity.connectionserver.drivers.sybase.ctlib.config-4.0-en-nu
"{1E17A1F9-66D2-437E-BF43-8E74B61D4103}" = tp.shared.pvlocale.pvlocale-4.0-core-32
"{1E6ADBED-AF09-429E-9593-2E4D87B34824}" = crystalreports.boe.sdkplugins.java-4.0-core-nu
"{1E99BD91-F50E-43D0-8B6F-8765BFEAC301}" = webi.cdp.plugin.cds_plugins.biservice_dp-4.0-en-nu
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FC19888-84F9-4F1F-AC8D-5F78BAF6873A}" = platform.client.java.helper.supportability-4.0-core-nu
"{1FD36706-6AC0-4D42-A708-053D5593AAE1}" = connectivity.connectionserver.drivers.ingres.odbc.config-4.0-en-nu
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{203768F0-9191-4637-8DB9-213AC6788D2D}" = platform.sdk.boe.java.oracle-4.0-core-nu
"{2071F9E0-3E9E-41F5-BB9F-4F5A74614562}" = universedesigner.designer-4.0-core-32
"{2082FD28-F7AC-4521-896B-40C01EFCF1E1}" = connectivity.connectionserver.drivers.mssqlsrv.oledbolap-4.0-core-32
"{20FA4764-770C-4DBD-86A2-EBBC80414DC1}" = webi.cdzsrv.lib.binfiles-4.0-core-32
"{2102B99E-4919-45E6-A8AD-2791D6287A9F}" = tp.apache.log4j.nteventlogappender-1.2.6_sap.1-core-32
"{211559AF-C2FB-474E-B65B-780BECD70039}" = repoaccess.cdztools.java-4.0-core-nu
"{214BC6BB-69DE-4EFC-94E8-3470BB848A01}" = platform.library.common.authentication.peoplesoft-4.0-core-32
"{2177C026-F3BE-403C-8B94-2F69C414FE93}" = webi.cdzsrv.lib.java-4.0-core-nu
"{21AED98E-7216-4BCB-9C38-706A8AE34A00}" = informationengine.ieplugin.binfiles-4.0-core-32
"{22FC0426-3100-44B7-9F32-A39117AA9D9D}" = informationengine.qt.drivers.derby.jdbc-4.0-core-nu
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{231EA591-7684-4DB2-8D58-860C7D679DAE}" = repoaccess.cdztools-4.0-core-32
"{2333675F-CE40-44F2-9D19-68CAA0B85A01}" = tp.sap.fxu8-720-core-32
"{234EE58E-8B16-4122-A97F-3A88B5709486}" = connectivity.connectionserver.client.corba.java-4.0-core-nu
"{2379C3A0-C598-473C-9D40-1B162E99FDF2}" = connectivity.connectionserver.drivers.mysql.jdbc-4.0-core-nu
"{23A97B11-8B5F-4018-9F64-216C05802BD6}" = bi.2.00.bi.bics-4.0-core-nu
"{241C8DE5-7658-47AE-9B2C-211D8FECF4EB}" = connectivity.connectionserver.drivers.neoview.odbc.config-4.0-core-nu
"{24C5F6EA-1490-4278-BD41-2CFC97D6756B}" = sdkbase.framework.java-4.0-core-nu
"{25021BF2-3DF7-4C74-B838-EC955407C0C4}" = repoaccess.container-4.0-core-32
"{25BEFC75-25B6-4489-B617-C98EF170891E}" = crystalreports.cpp.ras.bv-4.0-en-32
"{261784B1-38AB-4B59-B000-2280398EFFA7}" = repoaccess.cdztools.jtools-4.0-core-nu
"{261ADA1F-9D61-4250-87C9-CDED6C336946}" = tp.sun.jdk-1.6-core-32
"{26E7D39D-2CA8-4990-A1EE-1DE6201AE60F}" = crystalreports.dataaccess.driver.p2slog-4.0-en-32
"{26F26CE9-EEC6-45E4-8206-26A53E5F3E90}" = mda.clients.platform.boe.plugin_bundle-4.0-core-nu
"{2725A3D9-3FCB-4A35-A435-FFED1C270E6F}" = connectivity.connectionserver.drivers.javabean-4.0-core-nu
"{273E87B2-8883-4BA4-BF91-8343A3D6B57E}" = informationengine.qt.drivers.db2.odbc.config-4.0-core-nu
"{27772B1E-90D8-4681-99F2-E6A968905D51}" = repoaccess.cdz_ext-4.0-core-32
"{27826709-CF56-47B8-A786-D43531F85BCE}" = connectivity.connectionserver.drivers.mysql.jdbc-4.0-en-nu
"{27BB8D4E-0792-4BD0-8943-4214A1B5768C}" = universedesigner.fcwin.resources-4.0-en-32
"{287E4D97-F1EF-4B9E-8A56-C8F2184E4018}" = qaaws.qawsclient-4.0-core-32
"{28ABE740-47F3-441B-9437-852F6A64EFF8}" = Lenovo_Wireless_Driver
"{28FD7B4A-44A9-46CC-B909-F11B011B5D37}" = connectivity.connectionserver.drivers.db2.odbc.config-4.0-en-nu
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{29334C1C-9C8F-44A2-A637-8DD738769051}" = repoaccess.repoaccess_plugins.binfiles-4.0-core-32
"{297D1DCE-4E6D-4F67-B0F8-39922FCF9421}" = universedesigner.tools-4.0-core-32
"{2A83F525-8811-44B6-A72B-B7A672930AB7}" = connectivity.connectionserver.drivers.greenplum.odbc-4.0-core-32
"{2AB38016-C36D-409C-8FCA-272AED5C8891}" = informationengine.qt-4.0-en-32
"{2B233583-2EE2-4E18-9C4D-7E26E63E6796}" = dsl.bimodeler-4.0-core-nu
"{2B3CA7B5-3366-45E4-9898-DA4F4414DBE1}" = migration.busobj.registry-4.0-core-32
"{2BB3DD3B-B74E-481A-820E-EB7EE32984F6}" = connectivity.connectionserver.drivers.generic.oledb-4.0-core-32
"{2C362D7C-DAD3-4316-8884-FD85912117E1}" = informationengine.ieplugin.java-4.0-core-nu
"{2C9A7DCC-D420-4524-A374-8D64020AF415}" = repoaccess.repo_proxy.cpp-4.0-core-32
"{2CD5694D-55F2-422B-8E2F-8E93476FB8BF}" = connectivity.connectionserver.drivers.teradata.odbc.config-4.0-core-nu
"{2DB30F3C-DA77-405C-B776-9349384B9E13}" = tp.apache.log4net-1.2.10-core-32
"{2DCFDA59-C838-4129-A4C2-E7A5B1739A7C}" = dsl.clientsdk.pbd-4.0-core-nu
"{2E2FBBCB-EFFD-4D25-B07C-B8BF3801CF00}" = crystalreports.dataaccess.driver.p2bbde-4.0-en-32
"{2EDBE939-B1F0-46DF-8ED2-A923595E5496}" = universedesigner.global.registry-4.0-core-32
"{2F5FE210-14D8-4825-AD95-039A4D2302C6}" = webi.repeng-4.0-core-32
"{2F8D4CEC-B2C5-452C-9050-D0A8D64D96EF}" = tp.synthetica-2.11-core-nu
"{3005F490-322A-4963-83A7-F59CB6E76FB0}" = connectivity.connectionserver.core.config-4.0-en-nu
"{305E281F-9508-4CC2-A769-E90F8BD095E7}" = repoaccess.javasdk_repoaccess-4.0-core-nu
"{30A569B8-0B5F-4868-B806-1DC25C22EEF3}" = connectivity.connectionserver.drivers.oracle.jdbc-4.0-en-nu
"{31106887-7C6F-43FD-A5A5-3A7430324E6D}" = Required Runtimes
"{317198E2-8A3B-458A-AB08-DDCBE99337EF}" = informationengine.qt.drivers.generic.oledb.config-4.0-core-nu
"{3260B305-240C-4EF2-85DD-D2E0838FCEEC}" = universedesigner.tfc-4.0-en-32
"{32CF9719-8CF9-4FD2-8F81-10894AF3FB93}" = informationengine.qt.drivers.ingres.jdbc-4.0-core-nu
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{335130A3-A667-4BC6-AE2E-46578D171172}" = crystalreports.cpp.businessview.clients-4.0-core-32
"{3355ACAE-8BC0-4FBA-993E-3D9E45FAC159}" = connectivity.connectionserver.drivers.teradata.odbc-4.0-core-32
"{33F42F0A-FC34-4266-988D-229F90A04C70}" = tp.azalea.fonts-5.5-core-nu
"{3454AC60-7ACA-4A9E-80A3-20F78FB64F18}" = tp.json.java-1.0_sap.1-core-nu
"{347E5CD0-9D45-42C7-AD2C-8C1C926F087E}" = connectivity.connectionserver.tools.cscheck-4.0-core-32
"{34932327-5980-44D3-9832-D26109C02D41}" = informationengine.qt-4.0-core-32
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{351A2FC7-7404-4D54-AA66-F57FA8EDEE85}" = psepmsecuritybridge-4.0-en-32
"{3551D350-BFCF-4CD1-9D2A-2F21A5D418EB}" = tools.astools.cpp-4.0-core-32
"{360DA719-813B-4B52-8508-BA368BA5AA38}" = informationengine.qt.drivers.openaccess.odbc.config-4.0-core-32
"{363A7D16-636C-4292-ACF8-D6BE18E9C812}" = informationengine.qt.drivers.informix.odbc.config-4.0-core-nu
"{3762F589-C1EB-4310-BC82-6EEEBD4C6BD6}" = informationengine.qt.drivers.sap.config-4.0-core-nu
"{37758CCF-01E6-4019-845B-6578D62A9FD3}" = connectivity.connectionserver.client.extended.cpp-4.0-core-32
"{37873A77-9D7E-43F6-AEB6-F55B105F5719}" = connectivity.connectionserver.client.http.cpp-4.0-core-32
"{3837A019-925A-4B60-84B0-F59B01AFE252}" = tools.wstk.webcontent-4.0-core-nu
"{3846C0BD-85CB-4D9D-B996-D807196A979C}" = connectivity.connectionserver.drivers.mssqlsrv.oledb.config-4.0-core-nu
"{38577C88-F3C6-4CE9-9469-B3ECEEACDF47}" = universedesigner.registry-4.0-core-32
"{385EBA5A-7DE4-4C51-8256-534CF40047D5}" = crystalreports.cpp.businessview.clients-4.0-en-32
"{3882DB27-8862-42B1-8289-BA552B63CC04}" = crystalreports.dataaccess.driver.ado-4.0-en-32
"{3953A794-6532-4DC7-8BA8-206FDCD84961}" = repoaccess.cdztools.oldregistry-4.0-en-32
"{3ACBE84D-8294-4E8F-A25B-17D16EA89F59}" = crystalreports.dataaccess.driver.btrieve-4.0-en-32
"{3B2367AE-04DB-4587-9003-829A1A5AC075}" = connectivity.connectionserver.drivers.neoview.jdbc-4.0-core-nu
"{3BBFEE93-ECF6-45D1-B0F8-A42CDA18272A}" = crystalreports.partner.shared.cpp.pvlmapping-4.0-core-32
"{3CE22C95-69A5-4BE5-BC6F-551F2D4F9F88}" = informationengine.qt.drivers.informix.jdbc-4.0-core-nu
"{3DB9988B-4D8A-421B-BC00-ED5BB1C2D0E0}" = connectivity.connectionserver.core.config-4.0-core-nu
"{3DBC395E-496B-40CF-A0B9-5D20658D4D51}" = connectivity.connectionserver.drivers.mssqlsrv.oledbolap.config-4.0-en-32
"{3E03E16A-E510-499F-A336-2DB38FE31826}" = connectivity.connectionserver.helpers.cpp-4.0-core-32
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3E456D75-3FC3-45B9-B554-7512263C957E}" = connectivity.connectionserver.drivers.sybase.odbc-4.0-core-32
"{3E7DCB57-E7D2-48A1-B1C5-E2594CFFD5B0}" = webi.cdzsrv.lib.data-4.0-core-nu
"{3EA5C03A-432E-4DE4-B0F5-CC6B246E8A37}" = connectivity.connectionserver.drivers.mssqlsrv.oledb-4.0-core-32
"{3EF1EA92-61A1-47B0-87F0-BBC6458A1F3D}" = foundation.bipjcomanager-4.0-core-nu
"{3F90A3AB-E6FF-4432-ACAE-567D66486A76}" = qaaws.qawsclient-4.0-en-32
"{3FB119D8-86D6-4D82-BFDE-5EC95914566D}" = webi.composable.ui.desktop.dotnet-4.0-core-32
"{3FFB1C2A-50F7-4A56-86FC-7C073D3EB78E}" = olap.oda.bicsprovider.java-4.0-en-nu
"{3FFBE1CA-FBDF-40B6-ADD9-A24CC414BFB5}" = connectivity.connectionserver.drivers.jdbc.core-4.0-core-nu
"{408C09C5-F432-4A96-9204-81FBC6285EF2}" = tp.apache.derby-10.2.2.0-core-nu
"{40A0A513-B4B7-47EC-8DA1-6D749712DF81}" = re.shared.webservices.cons.dsws.dotnet2-4.0-core-32
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40CADF29-8AE1-47F3-B28B-8029D675CC92}" = informationengine.qt.drivers.maxdb.odbc.config-4.0-core-nu
"{4146E5B9-2477-49D0-BF41-526DF4A3CE6C}" = connectivity.connectionserver.drivers.mysql.odbc.config-4.0-core-nu
"{41A3CF96-298C-4A49-9A0F-E929AB542C0F}" = connectivity.connectionserver.drivers.sybase.jdbc-4.0-core-nu
"{421A23F1-4A22-4C9C-9BD0-0F4EDBD98D41}" = informationengine.qt.drivers.neoview.odbc.config-4.0-core-nu
"{426E4DF4-263E-4FAB-BDDA-0207DEFA1FAB}" = migration.rss_files-4.0-core-32
"{42FD6111-7BDC-41A4-8A39-BD3D5833C351}" = repoaccess.container.admintool.java-4.0-core-nu
"{43C00144-7432-4AA4-9BE0-AB2995235DC3}" = webi.cdp.plugin.cds_plugins.biservice_ui-4.0-core-nu
"{44646E59-3486-4D66-B405-4A6229318912}" = crystalreports.dataaccess.driver.db2-4.0-core-32
"{44B7393E-1A1D-4A04-88A6-14C9379B0162}" = connectivity.connectionserver.drivers.maxdb.odbc.config-4.0-en-nu
"{452948DC-743B-44D6-AE1B-BC18633B0B7F}" = connectivity.connectionserver.drivers.sap.bapi.config-4.0-en-32
"{45E06122-0C1A-4FD7-9BE7-604A1216FF3B}" = connectivity.connectionserver.drivers.mssqlsrv.odbc-4.0-core-32
"{46117992-0D6E-42AF-AD60-B00D53DFF82E}" = crystalreports.dataaccess.driver.sforce-4.0-core-32
"{463501E0-2EA1-4790-A1C0-0517E285F5CF}" = datafederator.boe.client.java-4.0-en-nu
"{463FF5C4-556F-4411-83D1-B1BE463910BF}" = connectivity.connectionserver.drivers.msaccess.odbc.config-4.0-en-32
"{467B5F7D-19FC-4187-B4F3-6423EA8111D3}" = webi.cdp.plugin.cds_plugins.biservice_dp-4.0-core-nu
"{46F1AB86-42D8-49CE-B3C3-993EBC0F3A55}" = tp.apache.xerces.java-2.9.1-core-nu
"{479AA04A-CE47-4AD6-AB38-CC1F1B0C63D6}" = connectivity.connectionserver.drivers.ingres.odbc-4.0-core-32
"{4842F5C8-C54B-49EF-A966-5E3024BE1D7D}" = tp.libxml2-2.0-core-32
"{485DE520-E443-4BAD-BBC1-AA0D044200F0}" = informationengine.qt.drivers.db2.cli.config-4.0-core-nu
"{49544EC3-2563-4063-952D-FE455D882CEE}" = webi.composable.ui.desktop.dotnet-4.0-en-32
"{4990290C-DD59-4650-AD0C-2C22C2B645EE}" = informationengine.qt.drivers.netezza.jdbc-4.0-core-nu
"{4A171F4F-5E16-43D7-8127-260070F986C0}" = tp.apache.commons.java-3.1-core-nu
"{4A62A2D2-F59C-41EA-959F-3F6D0E080E42}" = crystalreports.dataaccess.driver.ado-4.0-core-32
"{4AC12302-2F8A-46ED-81CE-7882CFCE096B}" = connectivity.connectionserver.drivers.db2.cli.config-4.0-en-nu
"{4AF3F733-1D93-4EB3-8178-12BD8C48D515}" = mda.services.client.platform.boe.plugin_shared_bundle-4.0-core-nu
"{4B54CE76-4FFF-44DA-95DF-BE8D4AFF8CC6}" = repoaccess.jhelpers-4.0-core-32
"{4BA74AA2-41EE-46C5-8A5D-A0FBEC58136B}" = connectivity.connectionserver.drivers.progress.jdbc-4.0-en-nu
"{4BB359AE-0A12-407C-BD6B-F2E9B64529EF}" = universedesigner.designer-4.0-en-32
"{4BE10A6A-9622-4203-89DF-2A2030C2744D}" = informationengine.qt.drivers.netezza.odbc.config-4.0-core-nu
"{4C7EA020-D9CB-4B2D-A963-9ED50D91310F}" = biwidgets.client.dotnet-4.0-core-32
"{4CDD6439-8884-443B-8E7A-3190D61E3DF6}" = universedesigner.fccube.export-4.0-core-32
"{4DF314A8-AFC6-4C61-BB93-0DE91CAF7F2B}" = repoaccess.cdztools.jshell.shared_classes-4.0-core-nu
"{4DFE54A8-0DDE-4159-8530-99A15173B07D}" = connectivity.connectionserver.drivers.oracle.oci-4.0-core-32
"{4E31BB5B-4755-49F9-A9AA-9DBB6419D947}" = connectivity.connectionserver.drivers.generic.odbc.config-4.0-core-nu
"{4E8B3E78-6117-4D12-9694-7B60DAE8FDD0}" = connectivity.connectionserver.drivers.datafederator.jdbc-4.0-core-nu
"{4EC32E69-21CA-46F1-9A1E-54352124187F}" = connectivity.connectionserver.drivers.informix.odbc.config-4.0-core-nu
"{4F98D546-754E-40BD-8D56-5CE2009DB0E5}" = connectivity.connectionserver.drivers.essbase.olap.config-4.0-en-32
"{4FA3239F-DD57-453B-91B5-475344872E25}" = informationengine.qt.drivers.mssqlsrv.oledb.config-4.0-core-nu
"{4FD65ED5-B49B-4968-AE83-E7581DEB75BC}" = platform.sdk.boe.dotnet_providers-4.0-core-32
"{504DA2AF-D764-4FB3-A6C8-588F0458CB21}" = migration.reporter-4.0-core-32
"{5097DDB3-BB59-4987-BE4A-6160B4497C55}" = connectivity.connectionserver.drivers.ingres.jdbc-4.0-core-nu
"{520C9ACB-6AD9-4FCA-BE6C-0E42751CA1BC}" = crystalreports.dataaccess.driver.sforce-4.0-en-32
"{5250D920-0C32-4410-AD73-DF3C4E75229A}" = repoaccess.cvomextendedblock.pbds-4.0-core-nu
"{5486FA5F-7C83-48C1-9835-B5616826BB15}" = tp.dom4j-1.6.1-core-nu
"{54A1909A-B141-45F2-A699-08C13A2493BB}" = informationengine.qt.drivers.progress.odbc.config-4.0-core-32
"{557FA925-94A9-4E3F-80F6-481227265A30}" = crystalreports.dataaccess.driver.dataset-4.0-core-32
"{55A0D8FF-4052-4021-95D2-64335EF8F9B2}" = olap.mda.data.cpp-4.0-en-32
"{55B3B01D-6D50-49DE-B981-857F2357E716}" = informationengine.qt.drivers.oracle.oci.config-4.0-core-nu
"{5603F784-FBEC-4BA5-8EC2-818E657B97CA}" = tp.apache.axis2-1.3-core-nu
"{563912FA-A205-4BF1-A194-77618D51B643}" = tp.apache.axis-1.3-core-nu
"{56AE00F1-90F2-472A-9E66-D545694415D9}" = product.businessobjectsclient.shortcut.univdesign-4.0-core-32
"{57092540-27F5-4DB3-91D4-32CDA5733DBB}" = connectivity.connectionserver.client.java.cpp-4.0-core-32
"{5744176C-5DF5-49AD-B836-9B0CA5B6A04B}" = foundation.bcm.cpp-4.0-core-32
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5806653B-211D-4E37-A2A9-008909E77721}" = tp.sap.ncs-720-core-32
"{5814D37E-6ECA-4599-890A-95369AEB36AA}" = webi.cdp.dsl_plugin-4.0-core-nu
"{58A965EF-897F-462B-A214-85EE2677FA38}" = connectivity.connectionserver.drivers.msaccess.odbc.config-4.0-core-32
"{58CCC4E6-6884-412B-A892-3D0991091B95}" = crystalreports.cpp.exporting.u2dpost-4.0-en-32
"{59311C7E-A4EA-4A32-83EF-A64495721B14}" = universedesigner.sqlboserver.dx-4.0-core-32
"{598D7B74-24CF-4234-A54B-C21F918D863F}" = connectivity.connectionserver.drivers.mysql.odbc.config-4.0-en-nu
"{599CBEC8-3BFD-4620-B0A4-3055A1B73389}" = informationengine.cube.binfiles-4.0-en-32
"{5A9A2C89-B56A-467F-B94D-8A327FB75474}" = product.businessobjectsclient.arp-4.0-core-32
"{5B5C5E2E-A759-4830-8356-21760F83AC86}" = tp.sourceforge.libpng.cpp-1.0.30-core-32
"{5BB10062-2FFD-4EC6-B898-329F8F4CB4E0}" = crystalreports.cpp.share-4.0-en-32
"{5BB52399-6E57-45EA-83AF-8712CC8A2BBE}" = foundation.bcm.java-4.0-core-nu
"{5BBD8A38-D31E-4A3D-943B-67C00C0108D5}" = informationengine.qt.drivers.personalfiles.odbc.config-4.0-core-32
"{5BE4A0F1-D09A-4C41-9C52-E951B123EC40}" = connectivity.connectionserver.drivers.db2.jdbc-4.0-en-nu
"{5BEE1DC6-AB46-4542-B54B-836E3A83E491}" = informationengine.qt.drivers.open-4.0-core-nu
"{5C20D21A-0461-41DC-B09C-373C62465D12}" = translation.manager.cms-4.0-core-32
"{5D40DC2B-4E33-462B-9035-29FE5FD8AA31}" = tp.xpp3.eclipse-1.1.3.8-core-nu
"{5DED0186-0733-4D74-AFE0-FF69219FE3B3}" = crystalreports.dataaccess.driver.p2bbde-4.0-core-32
"{5E8E6FF4-7F62-4595-8393-3295185E50AB}" = connectivity.connectionserver.core.cpp-4.0-core-32
"{5ED72CCC-F880-4E0D-A50B-F02131833F73}" = tp.apache.xerces.java.classes-2.6.2-core-nu
"{5EFE7C91-EB85-410B-A43D-128B2B9EAFC0}" = crystalreports.partner.shared.cpp-4.0-core-32
"{5F2BD233-B38E-4DF0-941E-D9BE9EF9FFB2}" = informationengine.qt.drivers.mssqlsrv.odbc.config-4.0-core-nu
"{60009F8D-15E3-48C8-B280-6C6696F532E8}" = crystalreports.sdk.java.sdkcommon-4.0-core-nu
"{601EC7C9-C1BF-4DDB-8FE1-0CBA68669403}" = xcelsius.designer.present-4.0-core-32
"{60D7A67C-AAAC-4292-B9B9-FDAFFEF06ABC}" = tp.threedgraphics.pgsdk.cpp-2.50.16.busobj.1-core-32
"{60F22BDF-2CEB-438E-8C15-460155CC7D7F}" = datafederator.boe.nativeconnection-4.0-core-nu
"{61A3D124-67DD-49A7-8163-50FB6001EA91}" = informationengine.qt.drivers.mssqlsrv.jdbc-4.0-core-nu
"{61D719F5-515A-48B3-9071-B0CCBA67E94E}" = crystalreports.dataaccess.driver.oracle-4.0-en-32
"{62AA269A-B581-4987-8019-5FB185B643CE}" = xcelsius.assets.present-4.0-en-32
"{62BBB2F0-E220-4821-A564-730807D2C34D}" = Realtek USB 2.0 Reader Driver
"{6358E6D0-5371-4370-8B2E-35D2FCC818F4}" = connectivity.connectionserver.client.inproc.cpp-4.0-core-32
"{637FF9A8-079D-4F7C-B0D8-224DE99BEB02}" = connectivity.connectionserver.drivers.progress.odbc.config-4.0-core-32
"{63F527FD-FFF8-4717-845A-A3A952E6EDE3}" = connectivity.connectionserver.drivers.greenplum.odbc.config-4.0-core-nu
"{63FE996E-C41E-4F62-BE5E-8A1A17220702}" = connectivity.connectionserver.drivers.derby.jdbc-4.0-core-nu
"{642C4DB5-3F34-4155-B3F1-FF7A97C9DB8D}" = tp.apache.axis2-1.4-core-nu
"{64E256E0-EC03-42F7-80F0-B9987FCB6476}" = connectivity.connectionserver.drivers.sybase.ctlib-4.0-core-32
"{650E661D-05EF-445D-9EA7-482397E80261}" = olap.oda.ssas2005.java-4.0-en-nu
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65FD3118-A840-4314-BD01-29865F6DFB7A}" = connectivity.connectionserver.drivers.open-4.0-en-nu
"{66439427-C6D7-4960-86C5-FDDCCB356BB2}" = repoaccess.repositoryproxyinterface.java-4.0-core-nu
"{668338D8-7E62-4732-99E4-88ED1B998927}" = platform.sdk.boe.java.pbds-4.0-core-nu
"{66EED8A6-AE66-4D7C-955B-E2E27EEECEB0}" = tp.protobuf-2.2.0-core-32
"{67042E97-BA1C-43EB-B27F-3874664151AD}" = webi.so.webi.adapter-4.0-core-nu
"{674E3B9B-3DB0-49B3-A3A3-F827E632F75E}" = product.businessobjectsclient.langpackproperty-4.0-en-nu
"{6760C9A2-2338-4151-9AA7-3BD88BA9E2C3}" = connectivity.connectionserver.drivers.sap.bapi.config-4.0-core-32
"{67AA1E23-C193-46B5-A2A7-8AB2637BF6E6}" = foundation.tracelog.java-4.0-core-nu
"{67C6B5AA-5DFE-4B0C-A215-122AB141EDCB}" = webi.cdzsrv.lib.binfiles-4.0-en-32
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68ADB2E3-6359-4C1B-B69B-4CDA8B607923}" = connectivity.connectionserver.drivers.javabean-4.0-en-nu
"{68E42F72-A66C-47E5-83F1-A64A31506F56}" = universedesigner.tfc-4.0-core-32
"{6920BA3F-9664-4AA6-B9F2-D2A6DE726C5E}" = connectivity.connectionserver.drivers.sybase.odbc.config-4.0-core-nu
"{6931F446-F5FD-43E0-A866-44695269DB5F}" = connectivity.connectionserver.drivers.maxdb.jdbc-4.0-en-nu
"{69487097-E2FA-4A29-8BA9-06F8616281CA}" = crystalreports.dataaccess.driver.com-4.0-en-32
"{699D34D0-6F87-4C46-98E8-E6AFBC799C27}" = connectivity.connectionserver.drivers.odbc.core.config-4.0-en-nu
"{699F0A70-0FA0-4F3D-8E68-40570581DF41}" = universedesigner.queryunv-4.0-core-32
"{69F0FD99-8C99-4615-B237-6434B2F100AB}" = tp.jide-2.8-core-nu
"{6AAD19AE-9E91-4DF5-9A13-7FBCD477F1A8}" = connectivity.connectionserver.drivers.ingres.odbc.config-4.0-core-nu
"{6B41EA6F-4FD6-40F2-94C1-625E992BACAE}" = crystalreports.dataaccess.driver.access-4.0-en-32
"{6BC110A8-0181-485E-94E9-B82C4F95E742}" = connectivity.connectionserver.drivers.greenplum.odbc.config-4.0-en-nu
"{6C38FA8C-8AED-4CC2-B6BE-D8D6E86D3193}" = crystalreports.dataaccess.driver.fielddef-4.0-core-32
"{6D1A011B-BA4D-4818-B7C0-965B1C8CB631}" = connectivity.cis.java-4.0-core-nu
"{6D34F44E-276B-4DCF-B0B5-1E73E8344131}" = xcelsius.designer.present-4.0-en-32
"{6D924AF5-3D07-47C5-A367-CC7652FB0AF2}" = tp.ooc.dotnet-1.0-core-nu
"{6DCC3B94-DFD6-4C97-8549-FB17199FF279}" = connectivity.connectionserver.server.bridge.cpp-4.0-core-32
"{6DE52612-F4D5-4237-9C4D-3634A9313FE8}" = connectivity.connectionserver.drivers.maxdb.odbc-4.0-core-32
"{6E1DB188-419B-4BBB-B56A-29AFD07A705B}" = tp.sap.ljs.passport-0.7.0-core-nu
"{6E230A9A-A56D-48AC-B4DE-78110C9E0DF7}" = crystalreports.cpp.xcsaptoolbar-4.0-en-32
"{6E487C56-D3A1-4541-8477-32860C3B23CE}" = platform.sdk.boe.java-4.0-core-nu
"{6EE365B8-4756-47FD-9EC8-9F3A015711A2}" = crystalreports.cpp.cractivexviewer-4.0-en-32
"{6F1D95E5-481A-4402-A405-37BE1B4E7685}" = crystalreports.dataaccess.driver.jdbc-4.0-en-32
"{6F44D5EA-FF93-47E8-AA06-0D301BEF1FA1}" = universedesigner.fccube-4.0-core-32
"{70730005-086B-453B-B5C0-2467D07CE6A8}" = tp.openssl-0.9.8l-core-32
"{70E237DC-9E1C-4119-B500-CB4184356BFD}" = shared.library.content-4.0-en-32
"{70E59A71-06AB-4A50-9CB3-C85059959BD0}" = tp.eclipse.aspectj-1.6.5-core-nu
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71386AAC-7FAE-49BD-9693-B53AF9A5AACF}" = crystalreports.dataaccess.driver.com-4.0-core-32
"{7163A430-35BA-4572-A5FB-62F4E8926B00}" = crystalreports.dataaccess.querybuilder-4.0-core-32
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{72462C9F-A03C-4A53-819F-9C5F11EB0F2D}" = crystalreports.partner.shared.cpp-4.0-en-32
"{727E93DC-5770-4601-ABD5-118DDB3733BF}" = platform.sdk.boe.dotnet.enterprise-4.0-core-32
"{7282723F-0262-4AB7-8615-CC9857BB1C29}" = connectivity.connectionserver.drivers.oledb.core.config-4.0-en-nu
"{72A1EEC9-9345-4661-8E6A-EF0559E77D75}" = connectivity.connectionserver.drivers.mssqlsrv.jdbc-4.0-en-nu
"{73547438-AA85-4460-933E-F8EEC2F4DB0E}" = tools.astools.java-4.0-core-nu
"{73684FF5-E845-4E2A-8B26-4F28E526F6A7}" = connectivity.connectionserver.drivers.neoview.odbc.config-4.0-en-nu
"{737F093D-9C55-487F-84A5-1A89123D3A5C}" = olap.oda.xmla_core.java-4.0-en-nu
"{738E1426-59C3-43A4-9F01-298C682174A3}" = translation.manager.cms-4.0-en-32
"{73D1C995-F10E-44C7-BAFD-BD2A0C95605B}" = connectivity.connectionserver.drivers.ingres.jdbc-4.0-en-nu
"{73DAC1A9-C1C9-4832-8622-D524D28A75D7}" = connectivity.connectionserver.drivers.oledb.core-4.0-core-32
"{73EF6C5E-4DC9-4EAC-8533-5F2A61C78807}" = product.xcelsius.langpackproperty-4.0-en-nu
"{74604F93-9FB0-4F24-BB32-138D0A8D70E7}" = crystalreports.cpp.xcsaptoolbar-4.0-core-32
"{75E9530D-D98C-45A5-A99B-F2C14B264623}" = platform.library.common.authentication.oracle-4.0-core-32
"{763DBF6A-7B92-42DF-BDB2-3450DCBD4BD9}" = foundation.locale_fallback.cpp-4.0-core-32
"{763E9062-5752-440B-AE8A-9C3B11D143D3}" = tp.tom.eclipse-26-core-nu
"{76423E31-835B-4241-8A20-45446E853834}" = platform.webservices.cons.dsws.dotnetsdk-4.0-core-32
"{7701BDAF-FDD0-4A21-AE8A-8F73854AA4DE}" = connectivity.connectionserver.drivers.db2.odbc.config-4.0-core-nu
"{779C6BA2-B88F-40BB-B795-76278983522C}" = foundation.javalibs.classes-4.0-core-nu
"{77B876EA-8974-4A38-86B2-EEF8BA1B4750}" = tp.apache.xalan.java-2.5.2-core-nu
"{77EECA52-543B-4A39-8C25-9A140402E6E9}" = dsl.slproxy.slproxybridge.binfiles-4.0-core-32
"{7904BAD3-ED0E-4AA9-AA2A-201DE2AEFDFF}" = crystalreports.dataaccess.driver.p2soutlk-4.0-en-32
"{794DCEEB-C7E9-46BF-A916-2D444AE54866}" = platform.webservices.cons.dsws.javasdk-4.0-core-nu
"{795BC502-5E33-47F7-B8F2-527120EF5AFA}" = platform.services.ras21.clientsdk_bundle-4.0-core-nu
"{7A3A5421-B92D-49A9-9468-30030BF86E18}" = webi.webservices.cons.dsws.javasdk-4.0-core-nu
"{7A589FB0-452A-4C2B-9E34-DB1DF555069F}" = connectivity.connectionserver.drivers.progress.odbc-4.0-core-32
"{7A67FCBC-FF0D-4559-BFA6-1858F21C7F69}" = crystalreports.dataaccess.driver.olap-4.0-core-32
"{7AEE649B-E768-4BDD-9D7A-549375C53293}" = connectivity.cis.cpp-4.0-core-32
"{7BA3338D-DD04-4EFD-99D0-2EEE4B797FD3}" = tools.srvtools-4.0-core-32
"{7BB5E925-A3DD-48C2-9A82-017AF5982FFE}" = Facebook Messenger 2.1.4590.0
"{7BCCC2EA-0495-4870-8E13-FDD50764251A}" = connectivity.connectionserver.ddk.java-4.0-core-nu
"{7BF1E119-212E-4C26-A091-11F6C06077B7}" = product.xcelsius.arp-4.0-core-32
"{7C4ACEBE-AB19-41EA-9409-57B605AA6B00}" = tp.rsa.crypto.cpp-3.2.1.2-core-32
"{7CA63938-51FE-4E7C-8E53-1939BE7ED980}" = informationengine.qt.drivers.msaccess.odbc.config-4.0-core-32
"{7D3E886C-B9A9-478C-9AA6-E69956EA7F2D}" = platform.library.common.instrumentation-4.0-core-nu
"{7DF858CF-2FB8-4CC5-A62B-2A52F4C8A280}" = tp.apache.axis2.bundle-1.3-core-nu
"{7E776ADB-FBB7-426D-86B4-40DA64EA6E7E}" = crystalreports.dataaccess.driver.ebs-4.0-core-32
"{7E7FC727-E84A-48F0-BAEC-6A8B7809A9E3}" = olap.oda.xmla_core.java-4.0-core-nu
"{7EB0BAEE-3B4F-44F1-896F-740A67A49E3D}" = repoaccess.async_helpers-4.0-core-32
"{7EBB358F-321F-4127-8390-C2C6975FED40}" = shared.library.content-4.0-core-32
"{7EC14FED-33B3-427C-96D0-8A5D67BAB2CE}" = tp.cup-0.11-core-nu
"{7ED1A0B8-1B70-4E3D-B449-3F2C1DB10EB0}" = connectivity.connectionserver.drivers.derby.jdbc-4.0-en-nu
"{7FAEE42B-A586-426C-9906-971EBA5F0C0C}" = xcelsius.assets.present-4.0-core-32
"{802E0C61-DB26-44A5-B9D9-83D98A906D7A}" = platform.services.ras21.clientsdk.java.pbd-4.0-core-nu
"{80941F2A-E7F7-4B86-BF5C-344C0E3F592B}" = platform.services.search.sdk.shared.java-4.0-core-nu
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{81B862FE-AE60-4239-A3CE-2A65FE2C38BF}" = crystalreports.dataaccess.driver.sybase-4.0-core-32
"{821428CC-0213-43D2-8753-B7DAC82B7595}" = crystalreports.sdk.java.repository-4.0-core-nu
"{824739C6-1DF6-4BC5-8A79-8F4BC2029889}" = tp.apache.xbean-2.1.0-core-nu
"{829565E9-B77B-4A53-A10A-E86B72135835}" = connectivity.connectionserver.tools.cscheck-4.0-en-32
"{835A77B3-8F53-493C-B05F-608EC68347C5}" = tp.synthetica.addons-1.3-core-nu
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{848885AE-86AC-4CC4-87ED-3EAE5F58BA8B}" = connectivity.connectionserver.drivers.greenplum.jdbc-4.0-core-nu
"{848DB4CE-7EDD-490E-9FA2-3FAC50640757}" = crystalreports.dataaccess.driver.btrieve-4.0-core-32
"{849E8871-C5E8-499D-A0AE-2923CBFC0454}" = tp.xpp3-1.1.3.8-core-nu
"{856902BD-848B-4605-AC50-F82771A55541}" = tp.rsa.crypto.java-4.1-core-nu
"{85DB8088-9158-4B5D-BD18-27530F7F3081}" = migration.conversion.documentation-4.0-en-32
"{8616B2F6-43FF-4042-9A58-8FD5DF7A1E1E}" = tp.apache.log4j.classes-1.2.6_sap.1-core-nu
"{864C043A-D21E-4B0E-BA81-984B8A51B59E}" = repoaccess.container_plugins.java-4.0-core-nu
"{87233779-674B-468C-817E-8314B148CB30}" = tp.pdflib-8.0.1p5-core-32
"{87D5D113-58E7-453F-B4E1-5FC4A441FB06}" = dsl.slproxy.consumption_light.binfiles-4.0-core-32
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{887C90B6-805C-43A8-81BF-A6780D278959}" = tp.apache.rampart.classes-1.3-core-nu
"{88C02807-008A-4BE2-8C5F-CAF55DAE36D0}" = repoaccess.container_plugins-4.0-en-32
"{89905A26-DD09-4F4C-954C-176A9E9C7665}" = olap.mda.data.cpp-4.0-core-32
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A6539E9-D4B8-4B30-8C50-7CF4E0C0C85F}" = informationengine.qt.drivers.greenplum.jdbc-4.0-core-nu
"{8AC2FA85-D98D-4058-9FE4-1F60C244DD8E}" = crystalreports.dataaccess.querybuilder-4.0-en-32
"{8B39F472-1CD4-4880-9E6D-FE3A6AA77EEA}" = crystalreports.dataaccess.driver.odbc-4.0-en-32
"{8B7C7644-4027-42F5-95FD-49DE8FF21E86}" = platform.sdk.boe.java.peoplesoft-4.0-core-nu
"{8B8125A4-1475-4BDD-9F4A-1FE342BC46E4}" = tp.apache.log4j-1.2.6_sap.1-core-nu
"{8B980C51-02B6-4C61-9667-C3CA32F904D3}" = informationengine.qt.drivers.maxdb.jdbc-4.0-core-nu
"{8B9AD19F-81F3-42D4-AD31-D86048199601}" = connectivity.connectionserver.drivers.generic.odbc.config-4.0-en-nu
"{8BD6F287-D8F1-45D6-92D6-F822325A76D6}" = connectivity.connectionserver.drivers.essbase.olap-4.0-core-32
"{8C097C21-1F5C-4F7F-9E90-65C0A269CC66}" = platform.client.dotnet.ure.uri-4.0-core-32
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8C7C5FEE-A493-459F-832D-F8D2AB111690}" = tp.threedgraphics.pgsdk.cpp-2.50.16.busobj.1-en-32
"{8CECB201-C763-4E5B-8952-768A5E5F7C32}" = connectivity.connectionserver.client.extended.java-4.0-core-nu
"{8CFC54CF-C832-4A30-A28F-14F51B837FC2}" = crystalreports.boe.sdkplugins.dotnet-4.0-core-32
"{8D17B405-D091-49A3-B26F-2CD1602444EB}" = connectivity.connectionserver.drivers.mssqlsrv.odbc.config-4.0-core-nu
"{8D232883-F199-4423-B774-5717A93355CC}" = platform.sdk.boe.java.sap-4.0-core-nu
"{8DB2CC7D-FE37-4F25-82B4-A48364B3C1DE}" = universedesigner.bridges-4.0-core-32
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F4FBAEE-C886-476C-A71C-E1EC938B104D}" = universedesigner.xmlpinfiles-4.0-core-nu
"{8FE10FDC-6425-4837-BCA9-575F89C6B15D}" = migration.busobj.dpxml-4.0-en-32
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{911DCE4C-EBE2-4964-BE5D-2A2750779DA5}" = connectivity.connectionserver.drivers.netezza.odbc-4.0-core-32
"{91525DAD-50C3-4887-AC27-C4ED8B8B2D1B}" = tp.xpp3.classes-1.1.3.8-core-nu
"{922D390F-40F0-4F0C-95BD-07F5F1BB299E}" = dsl.slproxy.pbd-4.0-core-nu
"{9243D2B9-5FE1-4C4A-8814-15B3EB81187E}" = dsl.bimodeler-4.0-en-nu
"{926EA874-9DAD-41B3-9EB7-58F2F368AC65}" = connectivity.connectionserver.drivers.mssqlsrv.oledb.config-4.0-en-nu
"{927739E2-984A-4FCD-BDCF-3DCB67E38EE2}" = informationengine.qt.drivers.teradata.jdbc-4.0-core-nu
"{92B69E10-E4B6-4E6B-BACF-0F2BA083837A}" = platform.sdk.boe.com-4.0-en-32
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{930C79C8-7F89-452A-BF43-D69DFAC991FA}" = connectivity.connectionserver.drivers.datafederator.odbc-4.0-core-32
"{93476EBF-00C6-4189-9FEC-7517B03CE93C}" = crystalreports.cpp.printcontrol-4.0-core-32
"{93BCE3A3-2EDF-433F-A92E-CB117A0621A3}" = datafederator.sourcedefiner.java-4.0-core-nu
"{943AF0B0-5563-48F7-9791-10D4A7ED0711}" = tp.apache.xalan.java.classes-2.5.2-core-nu
"{9462F34E-18ED-4F4A-B056-814BC7427E03}" = tp.ibm.icu.java.classes-3.8.1-core-nu
"{94A6D67D-AE5C-4CB9-8CFE-60774CB698FA}" = crystalreports.cpp.parameterprompt-4.0-core-32
"{9507D552-4047-4989-BBBE-8502B083A359}" = repoaccess.extensions_cvom-4.0-core-32
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{95CE391F-518B-4094-B7F0-B30CF8FEBB62}" = tp.pkware.cpp-1.0-core-32
"{96C49432-A707-44AB-B0BE-E4FD990F253B}" = crystalreports.dataaccess.driver.informix-4.0-core-32
"{96F86AAD-04CD-43C9-9CC4-A80067E251CA}" = migration.busobj.procfc-4.0-core-32
"{97451F4D-DC9F-43DC-BF3E-E3F3F9CA54D7}" = olap.oda.bpc.java-4.0-core-nu
"{9883A6B7-F3C6-4AC7-A3AE-72FF47CA37D1}" = crystalreports.dataaccess.driver.xml-4.0-core-32
"{98E47143-9B45-4620-ABCD-7D93C4B0E83B}" = platform.sdk.boe.java.oracle.plugins_bundle-4.0-core-nu
"{99E65BFC-886F-4052-84D0-F85E5823187A}" = connectivity.connectionserver.drivers.datafederator.odbc.config-4.0-core-32
"{99F1D522-1C38-492B-A73A-E10EBFF3B600}" = xcelsius.designer-4.0-core-32
"{9A080B6C-32AB-4566-BAB5-B4FC60D63D14}" = crystalreports.cpp.printcontrol-4.0-en-32
"{9A7B7EAF-AEBC-4306-AA47-D78C5760662C}" = informationengine.qt.drivers.mysql.odbc.config-4.0-core-nu
"{9A880441-398F-428E-8694-F15456DF6F0C}" = crystalreports.dataaccess.driver.olap-4.0-en-32
"{9A945CFA-60F3-4E9A-A1EA-34171E9B4104}" = connectivity.foundation.cpp-4.0-core-32
"{9A999F52-ACCA-486E-AF1D-F76AA1A9A43A}" = connectivity.connectionserver.drivers.datafederator.jdbc-4.0-en-nu
"{9B12274D-F720-4BC2-929D-822669CAA654}" = connectivity.connectionserver.drivers.teradata.jdbc-4.0-core-nu
"{9C15DF4C-C50D-45DD-B85E-A4420F2E2D7F}" = tp.rsa.crypto.java.classes-4.1-core-nu
"{9C1CEC03-0204-44CC-9C17-54D2F5F6ADF5}" = repoaccess.cdz_ext.framework-4.0-core-nu
"{9C60C74D-D4B2-4BD0-93A4-7E5E098BE121}" = crystalreports.cpp.share-4.0-core-32
"{9C799EF8-33B2-49F5-A042-7CBF254FDFC1}" = universedesigner.vartools-4.0-core-32
"{9D0832C5-2A2E-4B5D-A07E-67F76A9D6867}" = connectivity.connectionserver.drivers.hsqldb.jdbc-4.0-en-nu
"{9D1AD433-7A8D-46D8-B01D-86628D0AE9BE}" = webi.cdp.cdsframework_common-4.0-core-nu
"{9D1BEE6B-A5D4-4D56-9EE9-C76539DA19AD}" = informationengine.qt.drivers.sybase.jdbc-4.0-core-nu
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9D793912-2459-4769-86B7-EF158BAF7AF6}" = tp.apache.xerces.cpp-2.7.0-core-32
"{9DCCE485-EB15-49C3-82A7-45A501EC0F1D}" = tools.wstk-4.0-core-32
"{9DD463C1-FC7F-4E5B-9523-37FF7039410E}" = tp.protobuf.jar-2.2.0-core-nu
"{9DE9CA2F-D016-40D9-A3D2-22AB1B6EA70F}" = universedesigner.tools-4.0-en-32
"{9E556178-5F68-4D5D-BAF3-C15A342B5CA6}" = crystalreports.dataaccess.driver.filesystem-4.0-en-32
"{9EB290A5-C055-4118-95B7-659F4EA1C4D7}" = crystalreports.dataaccess.driver.oracle-4.0-core-32
"{9F03508E-E0F1-44F8-AF4B-51624279C606}" = crystalreports.dataaccess.driver.p2soutlk-4.0-core-32
"{9F3E7642-65A7-4278-BDDD-92D7891FEDC2}" = webi.richclient.common-4.0-core-32
"{9F460B0C-C953-4B03-8028-B3F1B7D0E844}" = universedesigner.designer.documentation-4.0-en-32
"{9FC5DA38-6195-4F54-8B4F-9E6840608600}" = connectivity.connectionserver.drivers.db2.cli.config-4.0-core-nu
"{A06F3506-2129-4605-B8FB-475434C22F4D}" = tp.apache.xerces.cpp-2.1.0-core-32
"{A0933CF7-AAC4-4819-B275-9FCCBDAE1986}" = tp.apache.xerces.java-2.6.2-core-nu
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A0DC1C16-0FDA-4D6E-92DB-552F93A0F538}" = repoaccess.ctplugin.java-4.0-core-nu
"{A0DC4E36-9FD4-45EE-B0F3-E2E4AAB0041A}" = crystalreports.dataaccess.driver.xml-4.0-en-32
"{A11C5365-0625-45B2-87B7-ED625EE66BE9}" = informationengine.ieplugin.binfiles-4.0-en-32
"{A1609E8A-E1DA-4435-A626-375752ADFDD2}" = tp.ooc.java.bundle-4.0.5-core-nu
"{A17931F7-276D-4D6B-A37D-48C5C4E0CBFE}" = foundation.tracelog.java.classes-4.0-core-nu
"{A2C7ED60-2C86-41CE-86C5-EA79995CB6E5}" = crystalreports.dataaccess.driver.p2slog-4.0-core-32
"{A2D36CB4-25E5-46DA-B0B8-015AB7AA3AAF}" = crystalreports.dataaccess.driver.javabeans-4.0-core-32
"{A3031FC4-E9ED-4BE5-8A86-1C60F48C5D52}" = dsl.transmgr_unx-4.0-core-nu
"{A3520959-EC76-40C8-A818-AF728EDE6F3D}" = crystalreports.dataaccess.driver.javabeans-4.0-en-32
"{A4998564-1316-4170-983B-E3D93E275D3A}" = connectivity.connectionserver.drivers.netezza.jdbc-4.0-en-nu
"{A588A72E-F0DC-4005-B94B-3A6986D1AF6F}" = connectivity.connectionserver.helpers.java-4.0-core-nu
"{A59C9634-0B12-4625-A381-12F61E7BE3E8}" = platform.sdk.boe.com.core-4.0-core-32
"{A5F00EDE-C61C-47E3-B4E5-166877ECAD78}" = informationengine.qt.drivers.javabean-4.0-core-nu
"{A6319946-E044-4F34-AFD5-FA3ADD62A5D5}" = olap.oda.bicsprovider.java-4.0-core-nu
"{A6C768F1-CA52-496E-9BC7-E3312A4F9B9A}" = platform.sdk.boe.java.bundles-4.0-core-nu
"{A705F4AD-5B19-4EA9-BE4D-DAEE63FA09C7}" = dsl.slproxy.slproxybridge.java-4.0-core-nu
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A72825BF-3887-4F13-91BC-66681C21BE43}" = tp.rosette-4.2.1-core-32
"{A8DA3FFB-9219-4FD8-BBD0-EF2202002123}" = tp.bcgsoft.controlbar.cpp-6.4-core-32
"{A8E920CC-FEA4-48C5-AB08-99DCD08D8F0C}" = crystalreports.cpp.businessview.clients.crw-4.0-en-32
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9559A9F-C3BA-494E-B2BC-20129C786EB7}" = crystalreports.dataaccess.driver.dataset-4.0-en-32
"{A9662DDE-28DA-4E9A-BE1A-60BBB622CF84}" = connectivity.connectionserver.drivers.generic.odbc-4.0-core-32
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA1AEF00-3439-4272-9AF4-008B3B373DFE}" = crystalreports.cpp.cractivexviewer-4.0-core-32
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAC31E60-2BDB-4217-BC24-00EA51FD5B10}" = webi.cdp.plugin.cds_plugins.biservice_ui-4.0-en-nu
"{AAD7037A-7B49-44AB-B710-683C6F3EA2CF}" = repoaccess.global.registry-4.0-core-32
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AAF63F76-B7F3-45A3-9623-09C192925B97}" = webi.composable.ui.shared.dotnet-4.0-core-32
"{AC5607B1-B649-42CA-A9D5-1A75165B4E2B}" = crystalreports.cpp.ras.bv-4.0-core-32
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{ACA9CF47-991C-4B76-AFE4-93E9D6C0BB06}" = tp.microsoft.mssdk-10.0-core-32
"{AD5F12A5-7753-46AC-9137-66CDEDE44AA7}" = crystalreports.cpp.businessview.clients.crw-4.0-core-32
"{AD61A91F-625B-409F-AF92-94E4551785D5}" = olap.oda.api.java-4.0-core-nu
"{AD6A931E-17AC-4DAB-93D8-B1AD2D1DFF72}" = crystalreports.cpp.filedialog-4.0-core-32
"{ADBA7722-3CAE-43E7-976B-7DF949D62DB7}" = platform.sdk.boe.java.dfo.util-4.0-core-nu
"{ADD59CE4-FF67-4292-8ACD-D1EFB0BB8205}" = repoaccess.repoaccess_plugins.data-4.0-core-nu
"{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}" = Lenovo EasyCamera
"{ADEA818B-38F2-4479-932D-A791EA83F780}" = connectivity.connectionserver.drivers.sap.bapi-4.0-core-32
"{ADFC6298-F364-4AB9-BE1D-D70760B101CE}" = connectivity.connectionserver.client.inproc.java-4.0-core-nu
"{AE111FB3-75AB-45D0-9CC3-21F92C0408C8}" = crystalreports.dataaccess.driver.p2sevt-4.0-core-32
"{AF286C85-3B32-43D1-B4F0-05E431827C97}" = tp.poco-1.3.6-core-32
"{AFAD3A19-6C6B-49E5-AC02-E31C177A5CDC}" = tp.tom-26-core-nu
"{AFAEC5B4-46D8-41B3-8092-142B561556BD}" = platform.services.ras21.clientsdk.java-4.0-core-nu
"{AFE0E94D-2549-4829-98FB-E92177D9CCF7}" = platform.services.ras21.clientsdk_shared_bundle-4.0-core-nu
"{B04A22F1-B53E-4BA9-82B4-0E5BE1355464}" = crystalreports.cpp.businessview.samples-4.0-core-nu
"{B0BE2D52-3226-4B50-BB5D-BA8E63A38652}" = tp.sap.introscope-822-core-nu
"{B104C6FB-074C-47D7-A717-3394C50C6B7B}" = crystalreports.dataaccess.driver.sap-4.0-core-32
"{B1280DF3-00BB-4C4B-B6B4-10C5BDCDA91D}" = tp.sun-1.1-core-nu
"{B1A3FD1E-4C0C-4615-9008-CB1D5995DE69}" = informationengine.qt.drivers.oracle.jdbc-4.0-core-nu
"{B1C14366-B371-459E-B90A-F2D575B79EA1}" = crystalreports.dataaccess.driver.act-4.0-core-32
"{B1E6E875-A3B2-4E1A-B500-E3A25581A55E}" = biwidgets.client.dotnet-4.0-en-32
"{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare
"{B2EF9594-89DB-43A0-A9F9-B3DA914FBB8C}" = connectivity.connectionserver.drivers.jdbc.core.config-4.0-core-nu
"{B31BA9F0-524C-42CA-A5FE-45CF3C446517}" = repoaccess.plugins_shared_bundle-4.0-core-nu
"{B38911D0-1799-46B5-A653-950BC34526B4}" = connectivity.connectionserver.drivers.jdbc.core.config-4.0-en-nu
"{B3C3FF2B-240D-4AF9-9925-DCA62FBFDAC2}" = universedesigner.rptdlg-4.0-core-32
"{B442500C-75A4-44A0-A7CC-A465C2950D0D}" = connectivity.connectionserver.drivers.openaccess.odbc.config-4.0-core-32
"{B4754D6B-D84E-4BD8-9AC1-B539748A7616}" = cvom.java-4.0-en-nu
"{B57CFF9F-CF49-4E18-8184-BA62550ED71D}" = bi.2.00.bi.base-4.0-core-nu
"{B5A82341-3C1F-4A56-BCC5-9620F750D4EC}" = connectivity.connectionserver.drivers.informix.jdbc-4.0-en-nu
"{B63F5593-A100-4166-89B4-D1E725FD88DA}" = crystalreports.dataaccess.driver.p2sexchange-4.0-en-32
"{B68DED34-CD05-49AE-92F0-96DA7DD8EB64}" = informationengine.unvtools-4.0-core-32
"{B6CA0F76-0F17-4D53-8CD0-ACC71B8DC575}" = universedesigner.bridges-4.0-en-32
"{B6E499CF-867D-4DC0-AAE1-75F2A039F441}" = tp.ooc.java.classes-4.0.5-core-nu
"{B76ED284-B8FE-4FF7-A209-1607F9538021}" = platform.sdk.boe.dotnet-4.0-core-32
"{B7895722-516C-49BB-93D4-7EAD9AC4B02B}" = informationengine.qt.drivers.mysql.jdbc-4.0-core-nu
"{B829F975-3301-453B-8FE4-B26218DE125E}" = translation.manager-4.0-core-32
"{B89220C0-7C89-4304-879B-363AAD67CBB3}" = connectivity.connectionserver.drivers.teradata.jdbc-4.0-en-nu
"{B89BF5A9-E932-41EF-A95E-CA7C6AF79327}" = crystalreports.dataaccess.driver.p2dbase-4.0-core-32
"{B9847524-3B87-4A80-86EE-7CFAB37D7CD8}" = connectivity.connectionserver.drivers.progress.odbc.config-4.0-en-32
"{BA467D77-871A-4CE1-B580-BC9C2A2E5A71}" = tp.microsoft.wse-3.0-core-32
"{BAD0DF81-7389-450D-B9E7-EF42938A6316}" = datafederator.boe.dfadmin-4.0-core-32
"{BAEC2486-2048-4D03-9140-DF504040F266}" = platform.library.common-4.0-core-32
"{BB25DCF7-8C02-4B54-8755-843EEC67DF86}" = tp.apache.axis2.classes-1.3-core-nu
"{BBDC0D46-850A-4819-B257-6DC31296496E}" = crystalreports.dataaccess.driver.universe-4.0-en-32
"{BC533138-A8AA-4922-82B5-4934CB53D5F8}" = informationengine.qt.drivers.db2.jdbc-4.0-core-nu
"{BC9BDA6F-E918-451C-8B60-EB45A89B630C}" = tools.i18n4j-4.0-core-nu
"{BD7F9FCD-D20B-4A5D-ACDD-2C254E2EF4FF}" = webi.cdp.cdsframework_dp.java-4.0-core-nu
"{BD995805-3584-44FA-96A3-84FFBFF32EAD}" = repoaccess.extensions_cvom.java-4.0-core-nu
"{BDF1DBF5-F45F-4D01-B764-A1F61A66D1D0}" = connectivity.connectionserver.drivers.generic.jdbc-4.0-core-nu
"{BEA94B00-7AB7-4048-A224-F1D0B69FA861}" = webi.sharedobjects-4.0-core-nu
"{BFCE575E-49B8-40C5-9B4A-D2D9D3535E2E}" = connectivity.connectionserver.drivers.odbc.core.config-4.0-core-nu
"{C0B3B64C-3056-495D-8C9C-09E023AAB4FB}" = connectivity.connectionserver.drivers.netezza.jdbc-4.0-core-nu
"{C10D0C09-C55F-4FBF-83F4-AEEC2E9EA1A1}" = connectivity.connectionserver.drivers.maxdb.odbc.config-4.0-core-nu
"{C13870D8-716A-4608-9A9A-BF581B613EC3}" = crystalreports.dataaccess.driver.adoplus-4.0-core-32
"{C16F8BE5-1DF0-42C7-89BD-7223655B06C0}" = crystalreports.cpp.erom-4.0-core-32
"{C17B3247-0B69-4B48-B382-467CA1A89F76}" = tp.netscape.ldap.cpp-6.0.5-core-32
"{C1827786-F58B-41D0-B607-CCC222929070}" = tp.sap.ljs.passport.classes-0.7.0-core-nu
"{C1BCEEAA-3ED9-49AE-A0CE-419C6C2C124D}" = connectivity.connectionserver.tools.codcheck-4.0-core-nu
"{C2AAA588-4193-46E4-A537-83CCC1530A66}" = crystalreports.cpp.exporting.u2dpost-4.0-core-32
"{C2CF75D8-6EED-4BF1-B6A8-AAF8D1117B8F}" = informationengine.cube.binfiles-4.0-core-32
"{C31D3FFB-DAC5-4AF4-8E16-6B58E8770250}" = tools.i18n4j.classes-4.0-core-nu
"{C3785226-4912-4845-9194-29D85CDD2E06}" = tp.netscape.ldap.cpp.mozjavascript-6.0.5-core-32
"{C42DEBBC-9069-4336-BAE9-5ACD11E2BB16}" = migration.busobj.dpvba-4.0-en-32
"{C4D16820-B476-4290-9EE0-3095C8280CDF}" = informationengine.qt.drivers.ingres.odbc.config-4.0-core-nu
"{C51E54E4-F5D3-4374-BEA5-AEAAC8C1FEFA}" = connectivity.connectionserver.drivers.sybase.odbc.config-4.0-en-nu
"{C59299BA-D7FC-4D59-9DB6-51ED2E79759A}" = crystalreports.crystalcommon.cpp.crlang-4.0-core-32
"{C5C53B9F-8F88-411B-9642-C9364D607ABC}" = crystalreports.dataaccess.share.registry-4.0-core-32
"{C6127442-C07C-47E0-B163-6888D78C9E5C}" = connectivity.connectionserver.drivers.datafederator.odbc.config-4.0-en-32
"{C62D6FB9-05D8-4FF6-ABA0-EE58601F1D2D}" = crystalreports.cpp.registrywrapper-4.0-core-32
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C6F00397-A2A9-44C7-8C37-0282D1556A1F}" = olap.oda.core.java-4.0-en-nu
"{C72F4F45-1CBC-4ACE-8485-AB06F89FAD76}" = connectivity.connectionserver.drivers.netezza.odbc.config-4.0-core-nu
"{C8016259-1B5B-47A8-81D4-13E9829993DA}" = webi.richclient.registry-4.0-core-32
"{C8EF4DED-86BA-4F56-AC34-37EC95B0C01A}" = tp.gzip-1.2.3-core-32
"{C99FC6E7-5057-4CC0-9E3C-B70788B34A53}" = repoaccess.cdztools.oldregistry-4.0-core-32
"{C9B39207-86EB-4D68-80EC-2F0861F89EDC}" = crystalreports.dataaccess.driver.p2sevt-4.0-en-32
"{C9B9D6AA-177B-44F5-BF9C-88B2FC873902}" = repoaccess.extensions.ds_excel-4.0-core-32
"{C9E75769-DF19-4585-B5DD-180DEF0C2345}" = olap.oda.api.java-4.0-en-nu
"{CA339C77-8F57-46D6-864F-08A632F7F12D}" = connectivity.connectionserver.drivers.informix.odbc.config-4.0-en-nu
"{CA36F34E-4DE2-4AC0-B822-60F9A1110AB4}" = repoaccess.jnitools.java.shared_classes-4.0-core-nu
"{CA57B2DE-838F-4E77-A644-A0CF83210493}" = connectivity.connectionserver.drivers.odbc.core-4.0-core-32
"{CB6911FD-1265-429D-870C-B2BC17A5A2E9}" = cvom.java.classes-4.0-core-nu
"{CBB484BD-A6A3-4CE1-BAB4-BC112AB7390A}" = connectivity.foundation.connectionsdk.java-4.0-core-nu
"{CC3BAA08-0E2F-4E99-877E-E2468A365F4E}" = webi.cdp.dsl_plugin-4.0-en-nu
"{CDCC3D2F-9E7F-4703-BC55-D5107A9ABB78}" = connectivity.connectionserver.drivers.generic.jdbc-4.0-en-nu
"{CDE360CD-6DD0-4C44-9553-19B170690E83}" = connectivity.connectionserver.drivers.openaccess.odbc.config-4.0-en-32
"{CDEFBB6A-BE09-4768-9806-6543C1E42EF4}" = connectivity.connectionserver.client.httpxir3.cpp-4.0-core-32
"{CE6A1FA8-5506-4258-A90B-390C77B45AA3}" = universedesigner.uitools-4.0-core-32
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CE9B4D74-4A89-4105-AF8D-EEF7C8343313}" = webi.webservices.cons.dsws.dotnet2-4.0-core-32
"{CEEFBD91-DC3D-41DD-B0E4-58B82287DB9D}" = tp.timing_framework-1.0-core-nu
"{CEF69C8F-FCFF-4D6C-8CCF-BE7CD49D3D92}" = crystalreports.dataaccess.driver.odbc-4.0-core-32
"{CF332BF5-564B-4BA5-9322-3202850D467D}" = repoaccess.container.java-4.0-core-nu
"{CFA6024E-B358-4F50-9075-62F5738FA5DA}" = crystalreports.cpp.cslib-4.0-core-32
"{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management
"{D0995FD0-9A1E-4763-9CF3-81FB869EC8EA}" = tp.utexasaustin.hoard-3.7.1-core-32
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D0D65D56-1BF2-4409-9867-4C41223CE51C}" = crystalreports.cpp.erom-4.0-en-32
"{D19EE8D6-6BD6-41FD-B2B6-2BF358BDA683}" = repoaccess.async_scheduling-4.0-en-32
"{D1A8A8CF-A854-4861-9EC6-0C502A80FC1D}" = platform.sdk.boe.com.instrumentation-4.0-core-nu
"{D201FA7D-58AD-437F-AB49-56EE3F309A82}" = connectivity.connectionserver.drivers.personalfiles.odbc.config-4.0-en-32
"{D207E625-6B4C-414C-B44E-CE772FD4CF9D}" = crystalreports.dataaccess.driver.cdo-4.0-en-32
"{D21A1FF1-2376-4DCE-A168-B17FA632959C}" = informationengine.qt.drivers.generic.odbc.config-4.0-core-nu
"{D227BEC2-87E5-4C52-AED1-570BF3691AAD}" = translation.manager-4.0-en-32
"{D22EBF86-64BF-45F4-B94D-C0ECC77B6A85}" = tp.curl.cpp-7.13.2-core-32
"{D2342A19-A8C0-41F7-AB09-681640251C46}" = connectivity.connectionserver.drivers.mssqlsrv.jdbc-4.0-core-nu
"{D267B562-A05B-4853-9C79-1C416F97A48E}" = dsl.transmgr_unv-4.0-core-nu
"{D2E2923F-F097-41D3-85B4-175183866581}" = connectivity.connectionserver.drivers.netezza.odbc.config-4.0-en-nu
"{D392EA8A-707A-40A8-9298-5ABE34FF64DE}" = tp.apache.guice-1.0-core-nu
"{D39A54F7-1A4F-417D-9D56-83F4E2497EED}" = cvom.java-4.0-core-nu
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4756A5A-E5C2-4081-8128-72665DA59C02}" = connectivity.connectionserver.drivers.db2.cli-4.0-core-32
"{D4B060B9-AD4A-4152-9D99-28B93C615AFE}" = Onekey Theater
"{D5698882-7AA3-4513-BCFF-EEC7277C2900}" = platform.webservices.cons.dsws.dotnet2-4.0-core-32
"{D56E5404-E469-46DE-A475-D276AC6A44D9}" = repoaccess.repo_proxy_jni-4.0-core-32
"{D7B02A9A-1746-4212-A704-FC4ACDEB34EA}" = repoaccess.ctplugin.java.shared_classes-4.0-core-nu
"{D7DFD61E-35A9-4C36-B5BE-BD66475375A2}" = informationengine.olapclient-4.0-core-32
"{D81BE593-DF3F-450E-924D-A49E66A8CA8E}" = tp.threedgraphics.pgsdk.cpp.runtime-2.50.16.busobj.1-core-32
"{D852E6B6-B24F-4A6D-81FF-E3DD9F49FEE2}" = tp.azalea-5.5-core-32
"{D85ED785-A121-4AEB-98AF-4DB096C35AAB}" = crystalreports.cpp.share.registry-4.0-core-32
"{D8A7195E-F41F-47E4-9D1E-ECA00D9D1B15}" = connectivity.connectionserver.client.jni.cpp-4.0-core-32
"{D8B58AC4-B4D1-4431-ACDB-BDFBEAB61EE4}" = dsl.transmgr_core-4.0-core-nu
"{D8DAA275-6532-4D57-AD01-66990171796A}" = crystalreports.dataaccess.driver.sybase-4.0-en-32
"{DA126147-DE91-408B-9B6A-9BAA9DD6BA59}" = repoaccess.container_plugins-4.0-core-32
"{DB1A4610-11D4-42E3-8454-CD80A8EF08E8}" = universedesigner.framework-4.0-core-32
"{DB5F1634-1FA4-4B76-BB71-800A020AD21A}" = connectivity.connectionserver.drivers.generic.oledb.config-4.0-core-nu
"{DB9F2A16-E00B-4167-BFEA-7B3CF8F7E663}" = datafederator.boe.dfadmin-4.0-en-32
"{DBD797EF-90EC-40AF-A091-0D9AFC6C6AB1}" = tp.eclipse.equinox-3.4-core-nu
"{DC64DAFA-22BC-44A8-BCBE-7D8FEE6EE24F}" = connectivity.connectionserver.drivers.db2.jdbc-4.0-core-nu
"{DC6EFE44-EE34-4DA5-8A6F-FCBFA69EA471}" = connectivity.connectionserver.drivers.oracle.oci.config-4.0-en-nu
"{DC75EFAC-8605-43CE-8F28-F5CD6F38594F}" = webi.cdzsrv.cdz_inproc-4.0-core-32
"{DCA3678E-257B-4419-B26C-E52D5B6C9CC5}" = repoaccess.repo_proxy.java-4.0-core-nu
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE228C0F-CC41-4FE5-B5EE-517465DACE67}" = connectivity.connectionserver.platform.helpers.cpp-4.0-core-32
"{DE3D03BE-81C7-4968-A93B-A1B51CC8288E}" = webi.richclient.common-4.0-en-32
"{DEA721A0-FF03-4522-B49C-6248740EEE42}" = crystalreports.dataaccess.share-4.0-en-32
"{DEB2111C-B35F-4519-ADD7-CF2734040909}" = tp.ibm.icu.cpp-3.0.1-core-32
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF52F366-8E12-4A4D-ACD6-FB37C44B3C91}" = universedesigner.sessmgr-4.0-core-32
"{DF537A4A-FC56-466D-B89D-B27DBCDB8909}" = platform.sdk.boe.dotnet.core-4.0-core-32
"{DFD95182-A3C2-4A1B-9253-B44BCF40079D}" = migration.conversion.ct-4.0-core-32
"{DFE96861-1C02-4EB4-994E-85AC888A21CA}" = connectivity.foundation.java-4.0-core-nu
"{E037DEBA-4DA6-4401-B0C6-95BA2E9528CB}" = tp.threedgraphics.pgsdk.cpp.chartsupport-2.50.16.busobj.1-core-nu
"{E070BD4E-CE16-4BE2-BED1-78CBFFED9A29}" = webi.cdp.cdsframework_ui-4.0-core-nu
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1907352-E402-4A77-97E1-29AF957358CF}" = tp.threedgraphics.pgsdk.cpp.runtime-2.50.16.busobj.1-en-32
"{E202A749-B50C-4465-8D6D-7F2B41347E90}" = dsl.informationdesigntool.exe-4.0-core-32
"{E207BD23-8B4D-46A2-BBBF-849D3C815041}" = crystalreports.webreporting.common-4.0-en-nu
"{E25C4D03-2048-42F4-A5DC-5AD7DD2622D0}" = foundation.javalibs-4.0-core-nu
"{E2AB4259-123E-43F5-9DE7-98F8FD22872E}" = crystalreports.dataaccess.driver.informix-4.0-en-32
"{E2C039AC-797A-49ED-90DD-3620E670A6EC}" = repoaccess.cdztools.jshell-4.0-core-nu
"{E2F50BC6-0BDA-4E8E-B1B8-8368655BBBF2}" = tp.pervasive.db.btrieve-3.0-core-32
"{E372A7BE-6DFB-4FF3-8935-AADE594A6D03}" = crystalreports.dataaccess.driver.fielddef-4.0-en-32
"{E3CD7222-9E9A-41EC-8CE0-894D79B49004}" = informationengine.qt.drivers.sybase.ctlib.config-4.0-core-nu
"{E3EBA934-4E2B-4014-999B-5C9307C7E67F}" = foundation.dotnetlibs-4.0-core-32
"{E48047FB-939F-442E-A964-D8452759F684}" = connectivity.connectionserver.plugin.http.cpp-4.0-core-32
"{E488FEE0-CD99-4C67-8DCC-64A75D06DC7B}" = crystalreports.cpp.parameterprompt-4.0-en-32
"{E4EF483C-1089-4F4C-A2D2-B71120A0E870}" = tp.ibm.icu.cpp-4.2.1-core-32
"{E5058C44-2EB2-4144-B1CE-1084D6426AF4}" = universedesigner.sqlboserver-4.0-core-32
"{E5465D4F-3FB9-4D36-9DEB-3CAA5D96A821}" = platform.sdk.boe.java.peoplesoft.plugins_bundle-4.0-core-nu
"{E5ECDC59-967C-4EE3-9B2E-7F7FF6E72C3B}" = webi.richclient-4.0-en-32
"{E61FBA96-F432-4F0E-8533-0BDE3260DAA3}" = connectivity.connectionserver.drivers.neoview.jdbc-4.0-en-nu
"{E686A699-B638-4212-A24D-0A5441EFFE40}" = shared.library.keycode.decoder.cpp-4.0-core-32
"{E71EAC97-C547-4BFD-9733-6B9338B01904}" = informationengine.cube.resource-4.0-core-nu
"{E76B93A3-1163-4691-A2AC-804505E30595}" = xcelsius.boe.sdkplugins.cpp-4.0-core-32
"{E7C9E006-CDB8-445F-ADD0-462AD4D4DB26}" = tp.apache.ant-1.7.0-core-nu
"{E7F3D1C3-10FF-4173-AD49-9A7A053123ED}" = crystalreports.boe.sdkplugins.java-4.0-en-nu
"{E88F0CED-FD45-415D-86EA-CEBE787E278E}" = informationengine.qt.drivers.teradata.odbc.config-4.0-core-nu
"{E8D90FE7-55A9-4C7A-8E25-F52C833CB90A}" = dsl.dsl_clientsdk_light-4.0-core-nu
"{E9D8ACCB-0018-48E7-BF05-90BA27C4282B}" = tp.rsa.crypto-6.3-core-32
"{E9FB1C40-4995-40B9-8862-5CB725B5E7C1}" = olap.oda.tom.java-4.0-core-nu
"{EA7DF75B-57B9-495C-8B64-9F9AA3794E64}" = connectivity.connectionserver.drivers.mssqlsrv.oledbolap.config-4.0-core-32
"{EA8A25D2-EF96-4557-9B4F-81F7E4357E6D}" = tp.sun.classes-1.1-core-nu
"{EAE857DE-DFEA-41C3-9B33-6449D5A9BDBD}" = tools.wstk.java-4.0-core-nu
"{EB1FC21E-5A78-45EB-BE87-9A318F346161}" = setup.engine.sharedregistry-4.0-core-32
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EC10D725-AC4D-4F2B-BB29-31B4BCB02642}" = platform.library.common.authentication.sap-4.0-core-32
"{EC44405E-0F23-4E8F-A19D-2A67C04027DE}" = connectivity.connectionserver.drivers.sybase.jdbc-4.0-en-nu
"{EC48E92B-0FCE-488F-BD46-E1544F97B253}" = webi.cdp.cdsframework_driver-4.0-en-32
"{EC6903FF-7296-4749-8E38-03757717C02F}" = product.shared.langpackreg-4.0-core-nu
"{EC78F10C-131A-4510-AA14-F47483095D6A}" = crystalreports.crystalcommon.cpp.crjavaconfig-4.0-core-nu
"{ED578083-0F43-4A93-8E59-B125779E114E}" = tp.sap.nwrfc-711-core-32
"{ED767D7C-9A82-472C-BE0A-2B5FAB99ACA8}" = webi.cdp.cdsframework_dp-4.0-core-32
"{ED8A3E6A-386E-47F8-AF32-8BC6C3F486D0}" = crystalreports.dataaccess.driver.cdo-4.0-core-32
"{EE359EE2-732E-431F-A839-BBD87127536D}" = dsl.dsl_engine.binfiles-4.0-core-nu
"{EEB201EA-10F1-4B50-8EEA-0A9353A4F4AD}" = tp.sap.jco.java-3.0.5-core-nu
"{EEE8F470-6AB1-4A44-8BD4-2DDB620BC005}" = crystalreports.dataaccess.driver.act-4.0-en-32
"{EF090511-AA26-4295-A8D2-8F314F82092F}" = connectivity.connectionserver.drivers.neoview.odbc-4.0-core-32
"{F00087F3-5608-458A-BFFD-5B80605CECBE}" = webi.cdp.cdsframework_driver-4.0-core-32
"{F01EBEA7-3E4D-4A3C-BC34-92446D448360}" = crystalreports.dataaccess.driver.access-4.0-core-32
"{F0603F24-7765-4143-892A-C5E1B91CE2D4}" = migration.busobj.dpvba-4.0-core-32
"{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = UserGuide
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E314AB-1939-4797-BD1C-CD17E2C74111}" = connectivity.connectionserver.drivers.progress.jdbc-4.0-core-nu
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1A093A6-8418-49BD-B2A5-BDD5F0E2ED1A}" = foundation.javalibs.bundle-4.0-core-nu
"{F1B264DB-1AB1-4BCD-9BB9-10CC68C821A9}" = connectivity.connectionserver.drivers.hsqldb.jdbc-4.0-core-nu
"{F2974CA4-CC2C-499F-ABBA-92887D5074D7}" = olap.oda.pcm.java-4.0-core-nu
"{F3530201-CCC3-4B5D-A39C-C52CEA16A2A4}" = connectivity.connectionserver.drivers.oracle.oci.config-4.0-core-nu
"{F387839F-9E17-4DB5-8898-847EAFD373F9}" = isapi3_files
"{F3FCECCE-34F5-4CC9-8CA6-F58B9350BE33}" = connectivity.connectionserver.client.corba.cpp-4.0-core-32
"{F40AB5C1-F50D-463E-BC0B-E37DDC8A716C}" = tp.jdom-1.1.1-core-nu
"{F43A4928-382D-441C-8D61-C429544071B3}" = connectivity.connectionserver.drivers.openaccess.odbc-4.0-core-32
"{F445F4AC-67AF-4DFD-AA7B-B972C31F8758}" = crystalreports.dataaccess.share-4.0-core-32
"{F4F0DF43-8EFC-4176-A882-478CB52AEF93}" = connectivity.connectionserver.tools.cscheck.config-4.0-core-nu
"{F53719B0-5778-4BA1-9C4B-76D6D9D68D8E}" = connectivity.connectionserver.drivers.maxdb.jdbc-4.0-core-nu
"{F55FCB83-37BC-44AF-BF43-CB864A96184B}" = psepmsecuritybridge-4.0-core-32
"{F65A3DCE-9519-4E9F-86C5-7742F99150DE}" = platform.sdk.boe.com-4.0-core-32
"{F6B24CE9-B2EA-47CD-8F53-525B92C2D829}" = connectivity.connectionserver.drivers.greenplum.jdbc-4.0-en-nu
"{F7512A38-E302-40FF-8C72-20B16F770732}" = olap.oda.ea.java-4.0-core-nu
"{F7ADA33D-4E87-46C1-AD90-7EE8CA5F6D67}" = crystalreports.dataaccess.driver.universe-4.0-core-32
"{F7ED6DFF-3093-4D47-8E4F-AA12A3DB9199}" = crystalreports.dataaccess.driver.jdbc-4.0-core-32
"{F86ECFE6-6CBB-4E04-A413-27CF5EE8E34C}" = platform.sdk.boe.java.pbds_full-4.0-core-nu
"{F8A87587-76B6-426D-95CC-0506681F85CB}" = tp.salesforce-9.0-core-nu
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{F949AA24-1819-4331-970D-EB7C0DC5A0A1}" = informationengine.qt.drivers.hsqldb.jdbc-4.0-core-nu
"{F953FB3F-6DA0-470D-9CFD-7C1095CC205A}" = tp.sun.jdk.jre-1.6-core-32
"{F95DB2A3-DFB8-4E32-A1D5-57D6CA3EC965}" = universedesigner.sqlboserver.reposit-4.0-core-32
"{F9736D08-CB51-4320-83D8-212B88B85978}" = connectivity.connectionserver.drivers.personalfiles.odbc-4.0-core-32
"{F991A978-C93D-4603-88B2-FE41B5C57020}" = connectivity.connectionserver.core.helpers.cpp-4.0-core-32
"{F993656B-DB66-4C64-B216-679F95CF432E}" = crystalreports.webreporting.common-4.0-core-nu
"{FA1157A7-1977-4EBA-BBB3-182C00DBF846}" = crystalreports.cpp.runtimeshare-4.0-en-32
"{FA35A0C4-9094-4CA4-86AF-7082EBB21DF8}" = repoaccess.cdztools-4.0-en-32
"{FA768A4D-79D1-4E0C-9098-F4397F345580}" = connectivity.connectionserver.drivers.essbase.olap.config-4.0-core-32
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{FAC5E86A-B593-4141-A9F3-0FB572E647D2}" = dsl.dsl_platformactions-4.0-core-nu
"{FB4898C7-F957-44B3-805B-6FB44F34850E}" = tp.apache.xalan.cpp-1.10.0-core-32
"{FBB0B1A4-40B2-422A-B775-9DA613E8F40F}" = foundation.tracelog.cpp-4.0-core-32
"{FBF2D8EA-B019-4A8A-AD56-5BCCD2C2DB11}" = crystalreports.crystalcommon.cpp.crlogger-4.0-core-32
"{FC1A589B-C9FA-41F2-A627-650DF994EE50}" = connectivity.connectionserver.client.cpp.java-4.0-core-nu
"{FC9ECCBF-A263-4205-8F95-222C2DBFAA12}" = tp.sap.rfcsdku-70-core-32
"{FD6F6C56-E172-4685-8868-DA72DF47090F}" = foundation.bcm.java.bundle-4.0-core-nu
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF2A8008-A17C-40E1-BB63-9E206808D509}" = tp.xpp3.bundle-1.1.3.8-core-nu
"{FF9D17F1-B66E-41BE-A5DB-2CF7908ADC52}" = tp.apache.rampart-1.3-core-nu
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Dll-Files.com Fixer_is1" = Dll-Files.com Fixer
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Google Chrome" = Google Chrome
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam
"InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"InstallShield_{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare
"InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management
"InstallShield_{D4B060B9-AD4A-4152-9D99-28B93C615AFE}" = Onekey Theater
"InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = UserGuide
"Lenovo Games Console" = Lenovo Games Console
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"MSC" = McAfee AntiVirus Plus
"PhotoScape" = PhotoScape
"uTorrent" = µTorrent
"VeriFace" = VeriFace
"VLC media player" = VLC media player 1.1.11
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WordWeb" = WordWeb

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 8/13/2012 2:30:17 AM | Computer Name = i5-PC | Source = MsiInstaller | ID = 11904
Description =

Error - 8/13/2012 2:46:52 AM | Computer Name = i5-PC | Source = System Restore | ID = 8193
Description =

Error - 8/13/2012 2:47:05 AM | Computer Name = i5-PC | Source = System Restore | ID = 8193
Description =

Error - 8/13/2012 2:54:02 AM | Computer Name = i5-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Xcelsius.exe, version: 14.0.0.760, time
stamp: 0x4d68a492 Faulting module name: Xcelsius.exe, version: 14.0.0.760, time
stamp: 0x4d68a492 Exception code: 0xc0000005 Fault offset: 0x0002a31c Faulting process
id: 0x1a18 Faulting application start time: 0x01cd791dff0bfd7c Faulting application
path: C:\Program Files (x86)\SAP BusinessObjects\Xcelsius 4.0\Xcelsius.exe Faulting
module path: C:\Program Files (x86)\SAP BusinessObjects\Xcelsius 4.0\Xcelsius.exe
Report
Id: a9f677e6-e513-11e1-a50b-c0f8dab687ec

Error - 8/13/2012 7:09:42 AM | Computer Name = i5-PC | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 2324 (0x914) Thread address : 0x0000000073040738 Thread message : Build VSCORE.14.4.0.387
/ 5400.1158 Object being scanned = \Device\HarddiskVolume1\windows\System32\svchost.exe

by C:\windows\system32\services.exe 7011(118748)(0) 93(118748)(0) 5(118748)(0)
4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0)

Error - 8/13/2012 8:27:59 AM | Computer Name = i5-PC | Source = System Restore | ID = 8193
Description =

Error - 8/13/2012 8:38:09 AM | Computer Name = i5-PC | Source = Windows Search Service | ID = 3007
Description =

Error - 8/14/2012 3:32:55 AM | Computer Name = i5-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/14/2012 3:42:59 AM | Computer Name = i5-PC | Source = System Restore | ID = 8193
Description =

Error - 8/14/2012 12:42:16 PM | Computer Name = i5-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 8/13/2012 7:12:21 AM | Computer Name = i5-PC | Source = Service Control Manager | ID = 7034
Description = The McAfee Scanner service terminated unexpectedly. It has done this
1 time(s).

Error - 8/13/2012 8:27:35 AM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =

Error - 8/14/2012 2:28:47 PM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =

Error - 8/14/2012 10:27:48 PM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =

Error - 8/15/2012 2:47:12 AM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =

Error - 8/15/2012 2:37:06 PM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =

Error - 8/15/2012 2:37:11 PM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =

Error - 8/22/2012 3:27:16 AM | Computer Name = i5-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 8/22/2012 3:27:18 AM | Computer Name = i5-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 8/22/2012 8:17:38 AM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =


< End of report >


The ADWCleaner log is given below

# AdwCleaner v1.801 - Logfile created 08/24/2012 at 16:06:47
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : i5 - I5-PC
# Boot Mode : Normal
# Running from : C:\Users\i5\Downloads\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\i5\AppData\Roaming\Babylon
Folder Deleted : C:\Users\i5\AppData\Roaming\Media Finder
Folder Deleted : C:\Users\i5\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[email protected]
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder
Folder Deleted : C:\ProgramData\Partner
File Deleted : C:\user.js

***** [Registry] *****

Key Deleted : HKCU\Software\MediaFinder
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Download with &Media Finder
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKLM\SOFTWARE\BabylonToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\kt_bho_dll.dll
Key Deleted : HKLM\SOFTWARE\Classes\kt_bho.KettleBho
Key Deleted : HKLM\SOFTWARE\Classes\kt_bho.KettleBho.1
Key Deleted : HKLM\SOFTWARE\Classes\MF
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Media Finder]

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{28A88B70-D874-4f73-BBBA-9B2B222FB7D6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{86676E13-D6D8-4652-9FCF-F2047F1FB000}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
[x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7601.17514

[OK] Registry is clean.

-\\ Google Chrome v21.0.1180.83

File : C:\Users\i5\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted : "description": "The plug-in from the General-Crawler.com website which lets the users[...]
Deleted : "homepage_url": "hxxp://www.general-crawler.com",
Deleted : "name": "General Crawler",
Deleted : "update_url": "hxxp://1.update.general-crawler.com/updates/update_chrome.xml",

*************************

AdwCleaner[S1].txt - [3067 octets] - [24/08/2012 16:06:47]

########## EOF - C:\AdwCleaner[S1].txt - [3195 octets] ##########
  • 0

Advertisements


#2
dreamfalcon21

dreamfalcon21

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Hi,

My system has been infected with the isearch-claro-search.com and I have so far been unsuccessful in removing this.

I read the post in "http://www.geekstogo...s-cant-remove/" and run the ADWcleaner, but the problem still persists.

OTL logs are pasted below, extras below that, and finally the ADWCleaner logs. I have also downloaded Malwarebytes Antimalware tool but it is not identifying anything wrong. Any help in resolving this will be much appreciated.

OTL logfile created on: 8/24/2012 5:02:40 PM - Run 1
OTL by OldTimer - Version 3.2.58.1 Folder = C:\Users\i5\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.92 Gb Total Physical Memory | 1.46 Gb Available Physical Memory | 49.94% Memory free
5.83 Gb Paging File | 3.63 Gb Available in Paging File | 62.27% Paging File free
Paging file location(s): d:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 195.31 Gb Total Space | 172.10 Gb Free Space | 88.12% Space Free | Partition Type: NTFS
Drive D: | 386.11 Gb Total Space | 367.06 Gb Free Space | 95.07% Space Free | Partition Type: NTFS

Computer Name: I5-PC | User Name: i5 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/08/24 16:34:30 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\i5\Desktop\OTL.exe
PRC - [2012/08/18 03:58:57 | 001,229,848 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2012/07/26 10:29:46 | 000,244,656 | ---- | M] (Facebook) -- C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe
PRC - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/07/03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/07/03 13:46:42 | 000,973,488 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbam.exe
PRC - [2012/04/21 15:11:09 | 000,077,064 | ---- | M] () -- C:\Program Files (x86)\WordWeb\wweb32.exe
PRC - [2012/04/04 11:23:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/06/09 04:22:52 | 000,100,256 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
PRC - [2011/06/09 04:19:55 | 000,329,056 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
PRC - [2011/02/15 17:56:42 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe
PRC - [2010/12/20 16:00:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/12/20 16:00:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/12/05 07:09:24 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe


========== Modules (No Company Name) ==========

MOD - [2012/08/18 03:58:55 | 000,442,392 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\ppgooglenaclpluginchrome.dll
MOD - [2012/08/18 03:58:54 | 012,236,824 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll
MOD - [2012/08/18 03:58:52 | 003,997,720 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\pdf.dll
MOD - [2012/08/18 03:57:36 | 000,526,872 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\libglesv2.dll
MOD - [2012/08/18 03:57:35 | 000,104,984 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\libegl.dll
MOD - [2012/08/18 03:57:23 | 000,144,424 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\avutil-51.dll
MOD - [2012/08/18 03:57:22 | 000,266,792 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\avformat-54.dll
MOD - [2012/08/18 03:57:21 | 002,480,680 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\avcodec-54.dll
MOD - [2012/08/14 15:33:25 | 006,611,456 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Data\f3814b488d9e083cbbc623e01b389f09\System.Data.ni.dll
MOD - [2012/08/14 15:33:19 | 011,833,344 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Web\a501b7960f6c6e2e39162b83f3303aaa\System.Web.ni.dll
MOD - [2012/08/14 15:32:43 | 012,436,480 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\7b7fbe651c6e72f12099a298654c9594\System.Windows.Forms.ni.dll
MOD - [2012/08/14 15:32:37 | 001,591,808 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\6bb439b3f87736d3248ae27d43e2c0d6\System.Drawing.ni.dll
MOD - [2012/08/14 15:32:26 | 005,452,800 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Xml\ba3d70b651454c7d49b407b93663bfed\System.Xml.ni.dll
MOD - [2012/08/14 15:32:20 | 000,971,264 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\cfa9c506bfb9254c89dace7b83bc9f9d\System.Configuration.ni.dll
MOD - [2012/08/14 15:32:16 | 007,967,232 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\System\ce9ff6baf9053ed2ed673d948179195c\System.ni.dll
MOD - [2012/08/14 15:32:06 | 011,492,864 | ---- | M] () -- C:\windows\assembly\NativeImages_v2.0.50727_32\mscorlib\acfc1391e45fedd2a359778ea57d914c\mscorlib.ni.dll
MOD - [2012/07/26 10:30:04 | 021,014,960 | ---- | M] () -- C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\libcef.dll
MOD - [2012/07/26 10:29:40 | 000,283,568 | ---- | M] () -- C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\CefSharp.WinForms.dll
MOD - [2012/07/26 10:29:36 | 000,455,600 | ---- | M] () -- C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\CefSharp.dll
MOD - [2012/07/15 12:27:53 | 002,216,480 | ---- | M] () -- C:\Windows\SysWOW64\wweb32.dll
MOD - [2012/07/15 12:25:02 | 000,022,800 | ---- | M] () -- C:\Program Files (x86)\WordWeb\WUCNT.dll
MOD - [2012/04/21 15:11:09 | 000,077,064 | ---- | M] () -- C:\Program Files (x86)\WordWeb\wweb32.exe
MOD - [2011/06/09 04:22:52 | 000,100,256 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
MOD - [2011/06/09 04:19:55 | 000,013,664 | ---- | M] () -- C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll
MOD - [2010/11/21 08:54:08 | 002,927,616 | ---- | M] () -- C:\windows\assembly\GAC_32\System.Data\2.0.0.0__b77a5c561934e089\System.Data.dll
MOD - [2010/11/11 16:09:46 | 000,133,024 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\WindowsApiHookDll32.dll
MOD - [2010/11/11 16:08:44 | 000,161,696 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\ActiveDetect32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2012/05/25 17:13:54 | 000,162,224 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
SRV:64bit: - [2012/05/25 16:59:02 | 000,210,616 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV:64bit: - [2012/05/25 16:58:32 | 000,199,304 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV:64bit: - [2012/04/19 08:22:48 | 000,502,032 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\mcafee\virusscan\mcods.exe -- (McODS)
SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2011/02/15 17:56:42 | 000,956,192 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McProxy)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McOobeSv)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV:64bit: - [2010/09/30 20:35:42 | 000,311,296 | ---- | M] (Realtek Semiconductor Corp.) [Auto | Running] -- C:\Program Files\Realtek\RtLED\RtLEDService.exe -- (RtLedService)
SRV:64bit: - [2010/09/22 23:40:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/08/09 20:11:46 | 000,220,528 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- c:\Program Files\mcafee\msc\McAWFwk.exe -- (McAWFwk)
SRV:64bit: - [2009/07/14 07:11:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/04/04 11:23:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/12/20 16:00:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010/12/20 16:00:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/11 02:53:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/03/01 12:16:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/02/22 13:29:46 | 000,647,208 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,487,296 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)
DRV:64bit: - [2012/02/22 13:29:46 | 000,289,664 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,229,528 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,160,792 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,075,936 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfenlfk.sys -- (mfenlfk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,065,264 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)
DRV:64bit: - [2011/06/09 04:34:04 | 000,039,008 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LhdX64.sys -- (LHDmgr)
DRV:64bit: - [2011/06/09 04:34:02 | 000,029,792 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV:64bit: - [2011/06/09 04:21:35 | 000,057,952 | ---- | M] (Lenovo) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fbfmon.sys -- (fbfmon)
DRV:64bit: - [2011/06/09 04:21:35 | 000,013,408 | ---- | M] (Lenovo) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BPntDrv.sys -- (BPntDrv)
DRV:64bit: - [2011/03/25 15:47:48 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011/03/11 12:11:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 12:11:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/18 13:41:54 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/02/15 12:15:16 | 000,349,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (BTWAMPFL)
DRV:64bit: - [2011/02/15 12:15:12 | 000,138,280 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2011/02/15 12:15:12 | 000,107,560 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2011/02/15 12:15:12 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2011/02/15 12:15:12 | 000,021,416 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010/12/22 17:49:58 | 001,407,024 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/12/05 07:09:44 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2010/11/30 12:10:04 | 000,307,304 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtsuvstor.sys -- (RSUSBVSTOR)
DRV:64bit: - [2010/11/21 08:54:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 08:53:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 08:53:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/10/28 15:46:24 | 004,716,608 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2010/10/19 14:04:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010/10/14 22:58:16 | 000,317,440 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010/05/31 09:16:50 | 000,333,928 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/07/21 19:50:06 | 000,121,840 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd)
DRV:64bit: - [2009/07/14 07:22:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 07:18:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 07:15:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/11 02:04:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/11 02:04:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/11 02:04:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/11 02:01:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/14 06:49:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co...=LENN&bmod=LENN
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com [binary data]
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.claro...000c0f8daa6d7b3
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.co...1I7LENN_enIN496
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7LENN_enIN496
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\npFbDesktopPlugin.dll (Facebook, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/08/10 08:27:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/08/23 19:25:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\WordWeb\WCaptureMoz [2012/08/16 12:53:51 | 000,000,000 | ---D | M]

[2012/08/24 14:34:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\i5\AppData\Roaming\Mozilla\Extensions
[2012/08/24 14:31:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - homepage: http://isearch.claro...000c0f8daa6d7b3
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://isearch.claro...000c0f8daa6d7b3
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.75\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.50524.0\npctrl.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

O1 HOSTS File: ([2012/08/13 13:27:43 | 000,000,849 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 50.194.176.39 SAP-BOBJ4
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20120810081925.dll (McAfee, Inc.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg64.dll (Google Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20120810081925.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4:64bit: - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Lenovo EE Boot Optimizer] C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe (Lenovo)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [OnekeyStudio] C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
O4 - HKLM..\Run: [WordWeb] C:\Program Files (x86)\WordWeb\wweb32.exe ()
O4 - HKLM..\Run: [YouCam Mirage] C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (CyberLink)
O4 - HKLM..\Run: [YouCam Tray] C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe (CyberLink Corp.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-676971024-488182067-3021444819-1000..\Run: [Facebook Update] C:\Users\i5\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-676971024-488182067-3021444819-1000..\Run: [RDReminder] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk = C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe (Facebook)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.200
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7F498266-AF17-45EB-969A-D0122626E259}: DhcpNameServer = 192.168.1.200
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B2F4FA5D-5F6B-452A-B8C7-9231DAE833EC}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2012/08/24 17:02:02 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\i5\Desktop\OTL.exe
[2012/08/24 16:21:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/08/24 15:51:46 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Malwarebytes
[2012/08/24 15:51:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/08/24 15:51:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/08/24 15:51:18 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2012/08/24 15:51:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/08/24 14:34:16 | 000,000,000 | ---D | C] -- C:\Users\i5\Desktop\Download
[2012/08/24 14:34:12 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Mozilla
[2012/08/24 14:31:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/08/24 13:50:44 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\dll-files.com
[2012/08/24 13:50:36 | 000,017,128 | ---- | C] (Dll-Files.com) -- C:\windows\SysNative\roboot64.exe
[2012/08/24 13:50:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dll-Files.com Fixer
[2012/08/24 13:50:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dll-Files.com Fixer
[2012/08/24 06:41:03 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\PhotoScape
[2012/08/24 06:23:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
[2012/08/24 06:22:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PhotoScape
[2012/08/23 19:59:30 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook
[2012/08/23 19:51:39 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Facebook
[2012/08/22 12:51:35 | 000,000,000 | ---D | C] -- C:\Users\i5\.businessobjects
[2012/08/17 14:06:59 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\MigWiz
[2012/08/16 12:53:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WordWeb
[2012/08/13 13:21:13 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\SAP BusinessObjects
[2012/08/13 13:21:13 | 000,000,000 | ---D | C] -- C:\Users\i5\Documents\My SAP BusinessObjects Documents
[2012/08/13 13:14:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SAP BusinessObjects BI platform 4.0
[2012/08/13 12:17:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012/08/13 12:17:09 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2012/08/13 12:06:46 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\XcelsiuscustomThemesAutoInfo
[2012/08/13 12:06:46 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\XcelsiuscustomThemes
[2012/08/13 12:06:40 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Xcelsius
[2012/08/13 12:03:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dashboard Design
[2012/08/13 12:01:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2012/08/13 12:01:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\MSSoap
[2012/08/13 11:57:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SAP BusinessObjects
[2012/08/13 11:02:20 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Transcend Elite
[2012/08/11 17:10:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent
[2012/08/11 17:05:59 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\uTorrent
[2012/08/11 08:01:04 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\eScription
[2012/08/11 08:00:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eScription
[2012/08/11 07:58:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\eScription
[2012/08/11 07:54:58 | 000,000,000 | ---D | C] -- C:\windows\Downloaded Installations
[2012/08/11 07:52:08 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Adobe
[2012/08/11 07:40:47 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\Wat
[2012/08/11 07:40:47 | 000,000,000 | ---D | C] -- C:\windows\SysNative\Wat
[2012/08/10 19:37:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/08/10 19:37:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/08/10 07:43:41 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012/08/10 07:43:41 | 000,000,000 | -HSD | C] -- C:\Boot
[2012/08/09 23:23:25 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012/08/09 23:12:53 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Google
[2012/08/09 22:38:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2012/08/09 22:30:27 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Macromedia
[2012/08/09 22:10:24 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Adobe
[2012/08/09 21:19:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SAP AG
[2012/08/09 21:14:14 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Diagnostics
[2012/08/09 19:06:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2012/08/09 19:06:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2012/08/09 18:48:57 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Microsoft Games
[2012/08/09 18:40:28 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\vlc
[2012/08/09 18:38:36 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Google
[2012/08/09 18:32:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012/08/09 18:32:20 | 093,721,296 | ---- | C] (Samsung Electronics Co., Ltd. ) -- C:\Users\i5\Desktop\Kies_2.3.2.12064_10_1.exe
[2012/08/09 18:31:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/08/09 18:31:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2012/08/09 18:31:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works
[2012/08/09 18:31:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2012/08/09 18:31:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2012/08/09 18:30:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2012/08/09 18:29:14 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012/08/09 18:29:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2012/08/09 18:28:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Microsoft Help
[2012/08/09 18:28:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2012/08/09 18:28:25 | 000,000,000 | RH-D | C] -- C:\MSOCache
[2012/08/09 18:27:09 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\WinRAR
[2012/08/09 18:25:34 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/08/09 18:25:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/08/09 18:25:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR
[2012/08/09 18:20:28 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Broadcom
[2012/08/09 18:20:28 | 000,000,000 | ---D | C] -- C:\Users\i5\Documents\Bluetooth Exchange Folder
[2012/08/09 18:19:53 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\SRS Labs
[2012/08/09 18:19:11 | 000,000,000 | R--D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/08/09 18:19:11 | 000,000,000 | R--D | C] -- C:\Users\i5\Searches
[2012/08/09 18:19:11 | 000,000,000 | R--D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/08/09 18:19:10 | 000,000,000 | -H-D | C] -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/08/09 18:18:54 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Identities
[2012/08/09 18:18:51 | 000,000,000 | R--D | C] -- C:\Users\i5\Contacts
[2012/08/09 18:18:50 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/08/09 18:18:48 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\VirtualStore
[2012/08/09 18:18:38 | 000,000,000 | --SD | C] -- C:\Users\i5\AppData\Roaming\Microsoft
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Videos
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Saved Games
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Pictures
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Music
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Links
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Favorites
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Downloads
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Documents
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Desktop
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\AppData\Local\Temporary Internet Files
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Templates
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Start Menu
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\SendTo
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Recent
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\PrintHood
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\NetHood
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Documents\My Videos
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Documents\My Pictures
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Documents\My Music
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\My Documents
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Local Settings
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\AppData\Local\History
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Cookies
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Application Data
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\AppData\Local\Application Data
[2012/08/09 18:18:38 | 000,000,000 | -H-D | C] -- C:\Users\i5\AppData
[2012/08/09 18:18:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Temp
[2012/08/09 18:18:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Microsoft
[2012/08/09 18:18:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Media Center Programs
[2012/08/09 18:18:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
[2012/08/09 18:18:24 | 000,000,000 | -HSD | C] -- C:\Recovery

========== Files - Modified Within 30 Days ==========

[2012/08/24 16:57:55 | 000,000,916 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000UA.job
[2012/08/24 16:34:30 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\i5\Desktop\OTL.exe
[2012/08/24 16:28:38 | 000,000,912 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/24 16:25:10 | 000,021,072 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/24 16:25:10 | 000,021,072 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/24 16:21:17 | 000,001,828 | ---- | M] () -- C:\Users\Public\Desktop\McAfee AntiVirus Plus.lnk
[2012/08/24 16:20:54 | 000,729,688 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012/08/24 16:20:54 | 000,626,278 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012/08/24 16:20:54 | 000,107,522 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012/08/24 16:16:29 | 000,125,011 | ---- | M] () -- C:\windows\SysNative\fastboot.set
[2012/08/24 16:15:54 | 000,000,908 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/24 16:15:46 | 000,000,286 | ---- | M] () -- C:\windows\tasks\DLL-files.com Fixer_UPDATES.job
[2012/08/24 16:15:46 | 000,000,266 | ---- | M] () -- C:\windows\tasks\DLL-files.com Fixer_MONTHLY.job
[2012/08/24 16:15:34 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/08/24 15:51:34 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/24 13:50:35 | 000,002,028 | ---- | M] () -- C:\Users\i5\Desktop\Check PC For Errors.lnk
[2012/08/24 13:50:35 | 000,002,012 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2012/08/24 06:23:09 | 000,001,055 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk
[2012/08/24 06:23:09 | 000,001,031 | ---- | M] () -- C:\Users\i5\Desktop\PhotoScape.lnk
[2012/08/23 19:59:30 | 000,001,326 | ---- | M] () -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk
[2012/08/23 19:57:00 | 000,000,894 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000Core.job
[2012/08/21 15:26:23 | 000,007,639 | ---- | M] () -- C:\Users\i5\AppData\Local\Resmon.ResmonCfg
[2012/08/16 15:11:17 | 000,000,280 | ---- | M] () -- C:\windows\ODBC.INI
[2012/08/16 11:31:24 | 000,437,248 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012/08/15 12:27:59 | 000,001,133 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012/08/13 12:03:17 | 000,001,050 | ---- | M] () -- C:\Users\Public\Desktop\Dashboard Design.lnk
[2012/08/11 18:17:33 | 000,003,544 | ---- | M] () -- C:\bootsqm.dat
[2012/08/11 17:10:52 | 000,000,967 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/08/11 17:10:52 | 000,000,943 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/08/11 08:00:21 | 000,002,771 | ---- | M] () -- C:\Users\Public\Desktop\EditScript MT 9.lnk
[2012/08/10 19:38:04 | 000,001,945 | ---- | M] () -- C:\windows\epplauncher.mif
[2012/08/10 19:37:57 | 000,731,106 | ---- | M] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/08/09 23:47:53 | 000,108,227 | ---- | M] () -- C:\windows\SysWow64\license.rtf
[2012/08/09 23:47:53 | 000,108,227 | ---- | M] () -- C:\windows\SysNative\license.rtf
[2012/08/09 23:12:12 | 000,001,437 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/08/09 22:38:54 | 000,002,019 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/08/09 21:19:23 | 000,001,704 | ---- | M] () -- C:\Users\Public\Desktop\SAP Management Console.lnk
[2012/08/09 19:07:14 | 000,001,361 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2012/08/09 18:31:53 | 000,001,066 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/08/09 18:19:48 | 000,001,118 | ---- | M] () -- C:\Users\i5\Desktop\Cyberlink Power2Go.lnk
[2012/08/09 18:19:43 | 000,002,086 | ---- | M] () -- C:\Users\i5\Desktop\OneKey Recovery.lnk
[2012/07/30 08:23:24 | 093,721,296 | ---- | M] (Samsung Electronics Co., Ltd. ) -- C:\Users\i5\Desktop\Kies_2.3.2.12064_10_1.exe

========== Files Created - No Company Name ==========

[2012/08/24 15:51:34 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/24 13:50:47 | 000,000,286 | ---- | C] () -- C:\windows\tasks\DLL-files.com Fixer_UPDATES.job
[2012/08/24 13:50:46 | 000,000,266 | ---- | C] () -- C:\windows\tasks\DLL-files.com Fixer_MONTHLY.job
[2012/08/24 13:50:35 | 000,002,028 | ---- | C] () -- C:\Users\i5\Desktop\Check PC For Errors.lnk
[2012/08/24 13:50:35 | 000,002,012 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2012/08/24 06:23:09 | 000,001,055 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk
[2012/08/24 06:23:09 | 000,001,031 | ---- | C] () -- C:\Users\i5\Desktop\PhotoScape.lnk
[2012/08/23 19:59:30 | 000,001,326 | ---- | C] () -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Facebook Messenger.lnk
[2012/08/23 19:52:34 | 000,000,916 | ---- | C] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000UA.job
[2012/08/23 19:52:34 | 000,000,894 | ---- | C] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000Core.job
[2012/08/16 12:53:53 | 000,001,966 | ---- | C] () -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WordWeb.lnk
[2012/08/16 12:53:52 | 002,216,480 | ---- | C] () -- C:\windows\SysWow64\wweb32.dll
[2012/08/13 14:36:49 | 000,000,280 | ---- | C] () -- C:\windows\ODBC.INI
[2012/08/13 12:03:17 | 000,001,050 | ---- | C] () -- C:\Users\Public\Desktop\Dashboard Design.lnk
[2012/08/13 11:41:00 | 000,001,133 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012/08/11 18:17:33 | 000,003,544 | ---- | C] () -- C:\bootsqm.dat
[2012/08/11 17:10:52 | 000,000,967 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/08/11 17:10:52 | 000,000,943 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/08/11 09:33:30 | 000,007,639 | ---- | C] () -- C:\Users\i5\AppData\Local\Resmon.ResmonCfg
[2012/08/11 08:00:21 | 000,002,771 | ---- | C] () -- C:\Users\Public\Desktop\EditScript MT 9.lnk
[2012/08/10 19:38:04 | 000,001,945 | ---- | C] () -- C:\windows\epplauncher.mif
[2012/08/10 19:37:59 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/08/10 19:37:57 | 000,731,106 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/08/10 07:43:48 | 000,383,786 | RHS- | C] () -- C:\bootmgr
[2012/08/09 23:12:12 | 000,001,437 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/08/09 22:38:54 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/08/09 22:38:54 | 000,002,019 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/08/09 21:19:23 | 000,001,704 | ---- | C] () -- C:\Users\Public\Desktop\SAP Management Console.lnk
[2012/08/09 21:19:23 | 000,001,686 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SAP Management Console.lnk
[2012/08/09 19:07:14 | 000,001,361 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2012/08/09 19:07:13 | 000,001,172 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ImageReady 7.0.lnk
[2012/08/09 19:07:13 | 000,001,167 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 7.0.lnk
[2012/08/09 18:31:53 | 000,001,066 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/08/09 18:31:17 | 021,073,406 | ---- | C] () -- C:\Users\i5\Desktop\vlc-1.1.11-win32.rar
[2012/08/09 18:19:28 | 000,001,409 | ---- | C] () -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012/08/09 18:19:16 | 000,001,443 | ---- | C] () -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/08/09 18:18:38 | 000,002,235 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/09 18:18:38 | 000,002,086 | ---- | C] () -- C:\Users\i5\Desktop\OneKey Recovery.lnk
[2012/08/09 18:18:38 | 000,001,118 | ---- | C] () -- C:\Users\i5\Desktop\Cyberlink Power2Go.lnk
[2012/08/09 18:18:38 | 000,000,290 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/08/09 18:18:38 | 000,000,272 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/08/09 18:18:38 | 000,000,189 | ---- | C] () -- C:\Users\i5\Desktop\Lenovo Telephony Start Now.url
[2011/06/09 04:20:00 | 002,086,240 | ---- | C] () -- C:\windows\SysWow64\LenovoVeriface.Interface.dll
[2011/06/09 04:20:00 | 001,500,512 | ---- | C] () -- C:\windows\SysWow64\Apblend.dll
[2011/06/09 04:20:00 | 001,171,456 | ---- | C] () -- C:\windows\SysWow64\PicNotify.dll
[2011/06/09 04:20:00 | 000,466,944 | ---- | C] () -- C:\windows\SysWow64\Lenovo.VerifaceStub.dll
[2011/06/09 04:19:53 | 001,044,480 | ---- | C] () -- C:\windows\SysWow64\3DImageRenderer.dll
[2011/06/09 04:07:54 | 000,089,328 | ---- | C] () -- C:\windows\un_dext.exe
[2011/06/09 04:07:54 | 000,087,928 | ---- | C] () -- C:\windows\SPRemove_x64.exe
[2011/06/09 04:07:54 | 000,003,566 | ---- | C] () -- C:\windows\Dext_09.ini
[2011/06/09 04:07:54 | 000,002,998 | ---- | C] () -- C:\windows\Dext_04.ini
[2011/06/09 04:07:54 | 000,002,790 | ---- | C] () -- C:\windows\Dext_2052.ini
[2011/06/09 04:07:54 | 000,002,573 | ---- | C] () -- C:\windows\Remove.ini
[2011/04/14 08:31:25 | 000,963,116 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin
[2011/04/14 08:31:22 | 000,216,876 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin
[2011/04/14 08:31:19 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin
[2011/04/14 08:21:06 | 000,066,856 | ---- | C] () -- C:\windows\SysWow64\SynTPEnhPS.dll

========== LOP Check ==========

[2012/08/24 13:50:44 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\dll-files.com
[2012/08/11 08:01:04 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\eScription
[2012/08/24 06:41:31 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\PhotoScape
[2012/08/13 13:21:13 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\SAP BusinessObjects
[2012/08/13 11:02:20 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\Transcend Elite
[2012/08/11 17:11:16 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\uTorrent
[2012/08/24 13:12:42 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\Xcelsius
[2012/08/13 12:06:46 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\XcelsiuscustomThemes
[2012/08/13 12:06:46 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\XcelsiuscustomThemesAutoInfo
[2012/08/24 16:15:46 | 000,000,266 | ---- | M] () -- C:\windows\Tasks\DLL-files.com Fixer_MONTHLY.job
[2012/08/24 16:15:46 | 000,000,286 | ---- | M] () -- C:\windows\Tasks\DLL-files.com Fixer_UPDATES.job
[2012/08/23 19:57:00 | 000,000,894 | ---- | M] () -- C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000Core.job
[2012/08/24 16:57:55 | 000,000,916 | ---- | M] () -- C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000UA.job
[2009/07/14 10:38:49 | 000,014,408 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



< End of report >



OTL Extras logfile created on: 8/24/2012 5:02:40 PM - Run 1
OTL by OldTimer - Version 3.2.58.1 Folder = C:\Users\i5\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.92 Gb Total Physical Memory | 1.46 Gb Available Physical Memory | 49.94% Memory free
5.83 Gb Paging File | 3.63 Gb Available in Paging File | 62.27% Paging File free
Paging file location(s): d:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 195.31 Gb Total Space | 172.10 Gb Free Space | 88.12% Space Free | Partition Type: NTFS
Drive D: | 386.11 Gb Total Space | 367.06 Gb Free Space | 95.07% Space Free | Partition Type: NTFS

Computer Name: I5-PC | User Name: i5 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)
.url[@ = InternetShortcut] -- C:\windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = ChromeHTML] -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe (Google Inc.)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [edit] -- Reg Error: Key error.
htmlfile [print] -- rundll32.exe %windir%\system32\mshtml.dll,PrintHTML "%1"
http [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
https [open] -- "C:\Program Files (x86)\Google\Chrome\Application\chrome.exe" -- "%1" (Google Inc.)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files (x86)\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01E0EFFF-1230-4DBB-B394-40FB68941BB5}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{0DD69765-AB41-4302-A7CE-44BABF863BA0}" = lport=139 | protocol=6 | dir=in | app=system |
"{15EE831B-438F-4623-9A52-52073726DCE9}" = rport=137 | protocol=17 | dir=out | app=system |
"{17586DDD-09B9-4A67-AE79-DE9490EAF443}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{1A2FC6A7-9B03-42C3-A97B-2FF497BE450C}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{1AA74A9D-B11E-482E-820B-019EA56746CF}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{2136CDCA-9F4C-4778-954D-CD34EC1DC78A}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{292051F4-C61F-4071-9B78-C32A456C41C4}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{2BB0BA8F-A593-416C-973C-AE43E6EDFFF0}" = rport=139 | protocol=6 | dir=out | app=system |
"{3537CBAA-054E-402F-AD2A-FE6F7DC969B2}" = lport=138 | protocol=17 | dir=in | app=system |
"{3F2643FE-ABA3-4BE0-A992-2F96A662902C}" = lport=137 | protocol=17 | dir=in | app=system |
"{433AD7E7-E59D-4480-80BC-48E87F49213E}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{43C55908-45BD-4C8A-8D66-0D24DE5281FE}" = lport=2869 | protocol=6 | dir=in | app=system |
"{607305D5-928A-4306-BB16-92C42FE6C167}" = lport=10243 | protocol=6 | dir=in | app=system |
"{7742C6A0-A6D9-482F-B934-94DECDECAEDA}" = rport=10243 | protocol=6 | dir=out | app=system |
"{9F67076B-FEBF-4877-B545-5FE056F620A8}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{A1F6C22B-B6B2-4AE1-8AA1-2DF68F83E6EF}" = lport=445 | protocol=6 | dir=in | app=system |
"{A3BF33A9-E955-4D57-8183-D485BD638F9C}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{C6219A4B-49AC-48B6-B82C-7A19027C514A}" = rport=445 | protocol=6 | dir=out | app=system |
"{CAFA0D10-AF12-4FC7-9B00-F6BA174796BC}" = lport=6004 | protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\outlook.exe |
"{CF03D8C3-D5ED-4269-8920-C22F95C97C56}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{D8052B9F-8405-4371-9CDA-60AA96CB77DF}" = rport=138 | protocol=17 | dir=out | app=system |
"{FDB374D3-1468-4D56-BCFC-802217D45B66}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{FE3B1625-FA13-4854-AF61-CBDB1BA95025}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{031177BC-47D8-45EE-948F-EDE42DA49CDE}" = protocol=6 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{08554157-F4DC-4B72-9BF5-E4C2CC130EF7}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{08611196-B0A9-4A40-8D6D-81F28F896361}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{08C30054-0A2F-4F82-85D0-4A9122318243}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{08DB19BE-B84C-43E1-8F4D-650F4467BB37}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{0F60D51A-343F-4F1B-A77E-3BF6281036E0}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{16E5C711-8750-47AA-A8F2-FFE4188C15CD}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{34A5D0C0-7A5B-467B-802D-BAC8B7337EB5}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{44B7D80D-6E71-4D46-A01A-86E7BBD64FAB}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{47846671-6C6D-4D60-BD28-7085F21A21A6}" = protocol=6 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{578A0DD9-9BCB-46EE-B97D-514C0015F3A8}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{5E789850-4294-4E98-A843-829445FE3594}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{62628874-857D-44DB-B2C1-D976263F915B}" = protocol=6 | dir=out | app=system |
"{6616A798-5FC9-4503-8997-AAD595A05005}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{6D57DEF3-50B5-40E1-AA5F-97526D84BEDE}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{73978E81-F256-4C4A-A4C9-450E27828F75}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{84C4C64F-3598-4EA2-BAA7-DAE08E19BC0B}" = protocol=58 | dir=out | [email protected],-28546 |
"{8B56405F-813F-4F66-AAD6-CE1606039161}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{8D593F24-3768-447B-B302-9D40D66AFB06}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{8F9103CA-11C8-4D66-9E4A-9982B3D0D683}" = protocol=1 | dir=out | [email protected],-28544 |
"{C05BC242-4943-41DE-B428-E2EB4921E6AC}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{C3B4558D-69B5-4F99-BCCD-BB240A692053}" = protocol=58 | dir=in | [email protected],-28545 |
"{C6C6DD4A-B456-485A-8C15-3814B37985C1}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C8E6C2E5-66A2-436E-A6D4-572AB434533B}" = protocol=17 | dir=in | app=c:\program files (x86)\utorrent\utorrent.exe |
"{C9848FDB-6FC0-4D92-AD42-AC8538CC0426}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\groove.exe |
"{C9CFA290-0010-46A4-86A9-533EC9914698}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{CCC66ECD-3CDF-43A0-913E-BADDE445245A}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DFD2EAF4-A937-42F4-892F-994C8DA3724F}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{DFE6346D-C502-4204-8010-42DA363B0B04}" = protocol=17 | dir=in | app=c:\program files\common files\mcafee\mcsvchost\mcsvhost.exe |
"{E3EECCDD-6E97-465B-9766-A64F8001B482}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{E567318E-EC24-4177-B5A7-848CF04F36D3}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{F2918D40-666A-467F-BE05-331D4CEAE73F}" = protocol=1 | dir=in | [email protected],-28543 |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{23170F69-40C1-2702-0920-000001000000}" = 7-Zip 9.20 (x64 edition)
"{26A24AE4-039D-4CA4-87B4-2F86417005FF}" = Java™ 7 Update 5 (64-bit)
"{2998191E-A35E-47E2-BE38-7702C731D722}" = SRS Premium Sound Control Panel
"{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}" = Lenovo Bluetooth with Enhanced Data Rate Software
"{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{9D046B26-7978-47CD-91E6-AC3C1DFBC3D0}" = Microsoft Security Client
"{ACB6F4ED-835B-44EC-9EFD-AC8C83D28597}" = RtLED
"{B2DFBCF2-D656-46E6-8BD2-ED599FB0C26C}" = SAP MMC SnapIn
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"{F5B09CFD-F0B2-36AF-8DF4-1DF6B63FC7B4}" = Microsoft .NET Framework 4 Client Profile
"EA12B1FB53CE4E387C31A85236C41EF559B5E392" = Windows Driver Package - Lenovo (ACPIVPC) System (12/02/2010 6.1.0.1)
"Lenovo EE Boot Optimizer" = Lenovo EE Boot Optimizer
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft Security Client" = Microsoft Security Essentials
"SynTPDeinstKey" = Synaptics Pointing Device Driver

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00183566-044A-465F-A316-97665F7DB343}" = platform.sdk.boe.com.slplugins.binfiles-4.0-core-32
"{003C2709-D01A-4F26-9D9B-A56A6751972D}" = connectivity.connectionserver.drivers.sybase.ctlib.config-4.0-core-nu
"{00734D48-2B0E-4AA2-973C-5E893B007763}" = olap.oda.ssas2005.java-4.0-core-nu
"{00C257BD-C218-4958-A09D-CEBD455443B8}" = connectivity.connectionserver.drivers.mysql.odbc-4.0-core-32
"{01C2619E-D79F-4983-BA39-5C7F2CBF057A}" = connectivity.connectionserver.drivers.informix.jdbc-4.0-core-nu
"{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam
"{028DBE4D-705F-4707-9983-EB05518E27D7}" = informationengine.qt.drivers.datafederator.odbc.config-4.0-core-32
"{02D3D6E6-9549-4540-8DB7-131DFBDAD47D}" = foundation.bcm.java.classes-4.0-core-nu
"{03193771-8DC4-40C8-99FA-DBC3BAEA6D3E}" = crystalreports.dataaccess.driver.psenterprise-4.0-core-32
"{038BB2E3-62C2-4EAD-9FE9-5EBEBF8357F3}" = datafederator.boe.client.java-4.0-core-nu
"{03ADEE2C-9BDF-4843-82D0-45BFF149074C}" = connectivity.connectionserver.drivers.mssqlsrv.odbc.config-4.0-en-nu
"{03C8BC71-C012-453E-B20A-BCA9F28D8651}" = crystalreports.dataaccess.driver.db2-4.0-en-32
"{0418C87C-9327-47E7-A3D0-0916CB947A3C}" = migration.reporter-4.0-en-32
"{04396999-6ADD-4927-914C-45C3ED13365D}" = informationengine.qt.drivers.progress.jdbc-4.0-core-nu
"{0449635A-700B-4D35-9B36-D4B4BE170684}" = tp.sap.jco-3.0.5-core-32
"{045617C0-E56C-45D5-9DB6-4BE975AED05A}" = platform.sdk.boe.java.classes-4.0-core-nu
"{0471DE53-F859-4591-AFD0-DD22A6CB9CC2}" = tp.ooc.java-4.0.5-core-nu
"{05031260-71CD-4E74-B53C-A0C795B5EB6F}" = crystalreports.dataaccess.driver.p2dbase-4.0-en-32
"{0584221A-97A7-4123-84E6-5A5892C0A1F1}" = webi.webiversion-4.0-core-32
"{06830350-AA9D-4BB4-AEE6-C5AEE6FCAA08}" = tools.i18n-4.0-core-32
"{075A7F25-1895-4841-9251-4349814ECF63}" = connectivity.connectionserver.drivers.oracle.jdbc-4.0-core-nu
"{07DD51EB-D521-43EC-9AA0-21652E1295E8}" = tp.netegrity.siteminder.cpp.smagent-6.0-core-32
"{0842CE13-B2FF-49FA-BE59-96ECE08857BA}" = crystalreports.boe.sdkplugins.java.crlov-4.0-core-nu
"{08B53286-F776-4BAF-8544-1FE7520E4048}" = tp.datadirect.cpp-6.0-core-32
"{091F4468-FCAB-4F34-9BD3-4DFD58E2C032}" = platform.webservices.cons.dsws.legacydotnet2-4.0-core-32
"{092D9D9F-78DE-4E22-933A-2B0E8CC29B9B}" = tp.eclipse.aspectj.classes-1.6.5-core-nu
"{09C0F5C8-2AEB-4A42-B850-FF9882693CB6}" = crystalreports.boe.sdkplugins.java.managedreports-4.0-core-nu
"{0A0C9850-5754-4812-8615-1F78A059E3B6}" = crystalreports.cpp.runtimeshare-4.0-core-32
"{0A262EA4-D727-40BC-84AC-154D6F5D1B70}" = crystalreports.cpp.businessview.sdk-4.0-en-32
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0B18FC59-1FFB-4E89-A757-F2D89BC077F7}" = connectivity.connectionserver.drivers.informix.odbc-4.0-core-32
"{0B61B26C-1F0F-48AF-ACD1-ADD680CD008A}" = informationengine.qt.drivers.generic.jdbc-4.0-core-nu
"{0B799160-49B9-43D5-929D-B048C82D22C6}" = EditScript MT
"{0BBA949B-FF59-4E22-BD76-9197533FACB3}" = tp.apache.commons.java.classes-3.1-core-nu
"{0BCC554D-5820-4963-9223-339329E307C5}" = tp.ooc.cpp-3.3.2-core-32
"{0BF246BD-68E3-439A-8B04-7B11A3D9DC03}" = informationengine.qt.drivers.greenplum.odbc.config-4.0-core-nu
"{0C29318C-86B7-40DA-8AFD-2D10A3AB0015}" = tp.antlr.java-3.1.1-core-nu
"{0C6EAF85-B69F-4875-AE6E-F7BF39B92452}" = olap.oda.api_services.java-4.0-core-nu
"{0CA4293C-8902-4DC3-B844-ABF26558E0FC}" = crystalreports.cpp.filedialog-4.0-en-32
"{0D3B494E-C042-42D5-9905-BAAE2143EB16}" = informationengine.qt.drivers.sybase.odbc.config-4.0-core-nu
"{0D5679E0-7575-4E2D-BFCF-1CC052CD8316}" = crystalreports.dataaccess.driver.sap-4.0-en-32
"{0DAF19E3-1F7C-4A9A-8DF3-E9C977C6D6A1}" = connectivity.connectionserver.drivers.teradata.odbc.config-4.0-en-nu
"{0DCBAD0B-27C4-416C-BED4-723D64B01FF1}" = xcelsius.assets-4.0-core-32
"{0DFBA76C-C5E2-4B96-A741-633C0F465F41}" = repoaccess.bo_storage-4.0-core-32
"{0EB2ABA3-0867-4684-88C6-AF38F93B6C8B}" = platform.sdk.boe.java.sap.plugins_bundle-4.0-core-nu
"{0F1F7DCE-D7E9-48FB-9FE8-24CB45636596}" = tp.castor-1.3-core-nu
"{0FC43627-7DBB-4485-878B-B92473B98EBD}" = connectivity.connectionserver.drivers.msaccess.odbc-4.0-core-32
"{1039F9EB-0237-4A5D-8042-E9D3C0E73500}" = re.shared.webservices.cons.dsws.javasdk-4.0-core-nu
"{103D21F5-95E2-43B9-82C2-C79A2EDE6B50}" = informationengine.qt.drivers.neoview.jdbc-4.0-core-nu
"{111D6660-D51A-4D11-A4B7-D2A87A13110A}" = crystalreports.dataaccess.driver.filesystem-4.0-core-32
"{119BE0EF-59D9-4612-B3F4-675152BD1168}" = tp.apache.log4j.bundle-1.2.6_sap.1-core-nu
"{11D49E6E-EFC9-45C3-975B-9FDB2125ACF7}" = informationengine.qt.drivers.datafederator.jdbc-4.0-core-nu
"{120B73E9-E544-43AB-A147-394E23B5865D}" = cvom.java.ui_helpers-4.0-core-nu
"{1281C902-7FEF-4403-A7CE-91A2C0174873}" = webi.resdk-4.0-core-nu
"{12A3827E-CD52-4F56-9C59-40738E0F2A4B}" = connectivity.connectionserver.drivers.personalfiles.odbc.config-4.0-core-32
"{12B96A76-43D0-4546-9351-E44F72507827}" = olap.oda.core.java-4.0-core-nu
"{137E9F19-AE30-4DC1-B7AA-F1E83308BBC1}" = crystalreports.dataaccess.driver.java-4.0-core-nu
"{1383CCDF-7C62-442A-9B45-92B4B8B23B98}" = SAP BusinessObjects BI platform 4.0 Client Tools
"{13976822-8340-4422-B586-FF9A2BC837EF}" = repoaccess.async_scheduling-4.0-core-32
"{13EC197B-95A6-4295-99DA-D1A0D26C0F96}" = tp.apache.derby.classes-10.2.2.0-core-nu
"{1425445E-F894-4C79-B092-5873AD856C82}" = shared.library.keycode.defn-4.0-core-32
"{149056B0-4C7F-4126-8EEF-66260105F4CA}" = product.shared.installiverse.reg-4.0-core-nu
"{15201CB5-8209-4F26-B6B9-7B0844DD07C7}" = tp.ibm.icu.java-3.8.1-core-nu
"{158E8D09-A827-44D2-A166-95E25C875238}" = repoaccess.extensions.ds_excel.java-4.0-core-nu
"{15F87172-A567-426A-9353-5F8A9D925F22}" = cvom.java.classes-4.0-en-nu
"{170334EF-3E95-4B9E-88FD-E00294F46DDA}" = tp.sap.pluginwrapper.dotnet-720-core-32
"{17221B10-14A6-4E0E-8E9B-E5628B70866D}" = crystalreports.dataaccess.driver.adoplus-4.0-en-32
"{172D8E90-C81A-4704-9D5B-E10D62723303}" = olap.analysis.implementation.cpp.sofa-4.0-core-32
"{17730789-B659-449E-B090-16F4BB0DED4C}" = platform.client.cpp.plugins-4.0-core-32
"{181D3741-8C38-4FD0-8A42-D5FEA4267DE7}" = repoaccess.repo_proxy_jni.java-4.0-core-nu
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18F461BC-E460-11DE-9C59-3ECC56D89593}" = Dashboard Design
"{193707DA-8B72-48D8-888C-FBBA32189919}" = migration.busobj.dpxml-4.0-core-32
"{1988BCCD-A635-4C7D-9931-B370F4BC6CB4}" = universedesigner.rptdisp-4.0-core-32
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{19EF00A1-B676-46F1-949B-70D939B24163}" = connectivity.connectionserver.drivers.db2.odbc-4.0-core-32
"{1A4E8488-33A6-4483-9E36-D8E6D94DA21C}" = informationengine.ieserver.inproc-4.0-core-32
"{1A6F325E-6CD2-4A2B-B5AD-21395F3BF380}" = repoaccess.container.java.shared_classes-4.0-core-nu
"{1AC03186-5F8F-45F7-B0EE-AF5540474C01}" = platform.sdk.boe.com.slplugins.pinfiles-4.0-core-nu
"{1B1E4BFC-81A1-4BAD-AB58-15F136361F1D}" = shared.library.cxlib.cxlib-4.0-core-32
"{1B2D7B3A-7D62-44CC-B894-12B9836F1DB4}" = crystalreports.boe.serviceplugins.pss.java-4.0-core-nu
"{1B62A129-B2D0-49BA-90A8-45275CA2C685}" = crystalreports.cpp.businessview.sdk-4.0-core-32
"{1B83AFB1-957B-40D2-91C4-F545A5BEB5D9}" = connectivity.connectionserver.drivers.open-4.0-core-nu
"{1BFE8C8F-71A9-4FDF-9271-B96886C6B2F5}" = connectivity.connectionserver.plugin.corba.cpp-4.0-core-32
"{1C3CEB55-5B02-40D4-AB3B-A53A2FAA00E4}" = crystalreports.dataaccess.driver.p2sexchange-4.0-core-32
"{1C8CB977-3EDD-49E8-B8C1-47143E1A5AA1}" = migration.conversion.ct-4.0-en-32
"{1CEA7276-10B2-4825-B971-D42611A730E4}" = connectivity.connectionserver.drivers.sybase.ctlib.config-4.0-en-nu
"{1E17A1F9-66D2-437E-BF43-8E74B61D4103}" = tp.shared.pvlocale.pvlocale-4.0-core-32
"{1E6ADBED-AF09-429E-9593-2E4D87B34824}" = crystalreports.boe.sdkplugins.java-4.0-core-nu
"{1E99BD91-F50E-43D0-8B6F-8765BFEAC301}" = webi.cdp.plugin.cds_plugins.biservice_dp-4.0-en-nu
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FC19888-84F9-4F1F-AC8D-5F78BAF6873A}" = platform.client.java.helper.supportability-4.0-core-nu
"{1FD36706-6AC0-4D42-A708-053D5593AAE1}" = connectivity.connectionserver.drivers.ingres.odbc.config-4.0-en-nu
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{203768F0-9191-4637-8DB9-213AC6788D2D}" = platform.sdk.boe.java.oracle-4.0-core-nu
"{2071F9E0-3E9E-41F5-BB9F-4F5A74614562}" = universedesigner.designer-4.0-core-32
"{2082FD28-F7AC-4521-896B-40C01EFCF1E1}" = connectivity.connectionserver.drivers.mssqlsrv.oledbolap-4.0-core-32
"{20FA4764-770C-4DBD-86A2-EBBC80414DC1}" = webi.cdzsrv.lib.binfiles-4.0-core-32
"{2102B99E-4919-45E6-A8AD-2791D6287A9F}" = tp.apache.log4j.nteventlogappender-1.2.6_sap.1-core-32
"{211559AF-C2FB-474E-B65B-780BECD70039}" = repoaccess.cdztools.java-4.0-core-nu
"{214BC6BB-69DE-4EFC-94E8-3470BB848A01}" = platform.library.common.authentication.peoplesoft-4.0-core-32
"{2177C026-F3BE-403C-8B94-2F69C414FE93}" = webi.cdzsrv.lib.java-4.0-core-nu
"{21AED98E-7216-4BCB-9C38-706A8AE34A00}" = informationengine.ieplugin.binfiles-4.0-core-32
"{22FC0426-3100-44B7-9F32-A39117AA9D9D}" = informationengine.qt.drivers.derby.jdbc-4.0-core-nu
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{231EA591-7684-4DB2-8D58-860C7D679DAE}" = repoaccess.cdztools-4.0-core-32
"{2333675F-CE40-44F2-9D19-68CAA0B85A01}" = tp.sap.fxu8-720-core-32
"{234EE58E-8B16-4122-A97F-3A88B5709486}" = connectivity.connectionserver.client.corba.java-4.0-core-nu
"{2379C3A0-C598-473C-9D40-1B162E99FDF2}" = connectivity.connectionserver.drivers.mysql.jdbc-4.0-core-nu
"{23A97B11-8B5F-4018-9F64-216C05802BD6}" = bi.2.00.bi.bics-4.0-core-nu
"{241C8DE5-7658-47AE-9B2C-211D8FECF4EB}" = connectivity.connectionserver.drivers.neoview.odbc.config-4.0-core-nu
"{24C5F6EA-1490-4278-BD41-2CFC97D6756B}" = sdkbase.framework.java-4.0-core-nu
"{25021BF2-3DF7-4C74-B838-EC955407C0C4}" = repoaccess.container-4.0-core-32
"{25BEFC75-25B6-4489-B617-C98EF170891E}" = crystalreports.cpp.ras.bv-4.0-en-32
"{261784B1-38AB-4B59-B000-2280398EFFA7}" = repoaccess.cdztools.jtools-4.0-core-nu
"{261ADA1F-9D61-4250-87C9-CDED6C336946}" = tp.sun.jdk-1.6-core-32
"{26E7D39D-2CA8-4990-A1EE-1DE6201AE60F}" = crystalreports.dataaccess.driver.p2slog-4.0-en-32
"{26F26CE9-EEC6-45E4-8206-26A53E5F3E90}" = mda.clients.platform.boe.plugin_bundle-4.0-core-nu
"{2725A3D9-3FCB-4A35-A435-FFED1C270E6F}" = connectivity.connectionserver.drivers.javabean-4.0-core-nu
"{273E87B2-8883-4BA4-BF91-8343A3D6B57E}" = informationengine.qt.drivers.db2.odbc.config-4.0-core-nu
"{27772B1E-90D8-4681-99F2-E6A968905D51}" = repoaccess.cdz_ext-4.0-core-32
"{27826709-CF56-47B8-A786-D43531F85BCE}" = connectivity.connectionserver.drivers.mysql.jdbc-4.0-en-nu
"{27BB8D4E-0792-4BD0-8943-4214A1B5768C}" = universedesigner.fcwin.resources-4.0-en-32
"{287E4D97-F1EF-4B9E-8A56-C8F2184E4018}" = qaaws.qawsclient-4.0-core-32
"{28ABE740-47F3-441B-9437-852F6A64EFF8}" = Lenovo_Wireless_Driver
"{28FD7B4A-44A9-46CC-B909-F11B011B5D37}" = connectivity.connectionserver.drivers.db2.odbc.config-4.0-en-nu
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{29334C1C-9C8F-44A2-A637-8DD738769051}" = repoaccess.repoaccess_plugins.binfiles-4.0-core-32
"{297D1DCE-4E6D-4F67-B0F8-39922FCF9421}" = universedesigner.tools-4.0-core-32
"{2A83F525-8811-44B6-A72B-B7A672930AB7}" = connectivity.connectionserver.drivers.greenplum.odbc-4.0-core-32
"{2AB38016-C36D-409C-8FCA-272AED5C8891}" = informationengine.qt-4.0-en-32
"{2B233583-2EE2-4E18-9C4D-7E26E63E6796}" = dsl.bimodeler-4.0-core-nu
"{2B3CA7B5-3366-45E4-9898-DA4F4414DBE1}" = migration.busobj.registry-4.0-core-32
"{2BB3DD3B-B74E-481A-820E-EB7EE32984F6}" = connectivity.connectionserver.drivers.generic.oledb-4.0-core-32
"{2C362D7C-DAD3-4316-8884-FD85912117E1}" = informationengine.ieplugin.java-4.0-core-nu
"{2C9A7DCC-D420-4524-A374-8D64020AF415}" = repoaccess.repo_proxy.cpp-4.0-core-32
"{2CD5694D-55F2-422B-8E2F-8E93476FB8BF}" = connectivity.connectionserver.drivers.teradata.odbc.config-4.0-core-nu
"{2DB30F3C-DA77-405C-B776-9349384B9E13}" = tp.apache.log4net-1.2.10-core-32
"{2DCFDA59-C838-4129-A4C2-E7A5B1739A7C}" = dsl.clientsdk.pbd-4.0-core-nu
"{2E2FBBCB-EFFD-4D25-B07C-B8BF3801CF00}" = crystalreports.dataaccess.driver.p2bbde-4.0-en-32
"{2EDBE939-B1F0-46DF-8ED2-A923595E5496}" = universedesigner.global.registry-4.0-core-32
"{2F5FE210-14D8-4825-AD95-039A4D2302C6}" = webi.repeng-4.0-core-32
"{2F8D4CEC-B2C5-452C-9050-D0A8D64D96EF}" = tp.synthetica-2.11-core-nu
"{3005F490-322A-4963-83A7-F59CB6E76FB0}" = connectivity.connectionserver.core.config-4.0-en-nu
"{305E281F-9508-4CC2-A769-E90F8BD095E7}" = repoaccess.javasdk_repoaccess-4.0-core-nu
"{30A569B8-0B5F-4868-B806-1DC25C22EEF3}" = connectivity.connectionserver.drivers.oracle.jdbc-4.0-en-nu
"{31106887-7C6F-43FD-A5A5-3A7430324E6D}" = Required Runtimes
"{317198E2-8A3B-458A-AB08-DDCBE99337EF}" = informationengine.qt.drivers.generic.oledb.config-4.0-core-nu
"{3260B305-240C-4EF2-85DD-D2E0838FCEEC}" = universedesigner.tfc-4.0-en-32
"{32CF9719-8CF9-4FD2-8F81-10894AF3FB93}" = informationengine.qt.drivers.ingres.jdbc-4.0-core-nu
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{335130A3-A667-4BC6-AE2E-46578D171172}" = crystalreports.cpp.businessview.clients-4.0-core-32
"{3355ACAE-8BC0-4FBA-993E-3D9E45FAC159}" = connectivity.connectionserver.drivers.teradata.odbc-4.0-core-32
"{33F42F0A-FC34-4266-988D-229F90A04C70}" = tp.azalea.fonts-5.5-core-nu
"{3454AC60-7ACA-4A9E-80A3-20F78FB64F18}" = tp.json.java-1.0_sap.1-core-nu
"{347E5CD0-9D45-42C7-AD2C-8C1C926F087E}" = connectivity.connectionserver.tools.cscheck-4.0-core-32
"{34932327-5980-44D3-9832-D26109C02D41}" = informationengine.qt-4.0-core-32
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{351A2FC7-7404-4D54-AA66-F57FA8EDEE85}" = psepmsecuritybridge-4.0-en-32
"{3551D350-BFCF-4CD1-9D2A-2F21A5D418EB}" = tools.astools.cpp-4.0-core-32
"{360DA719-813B-4B52-8508-BA368BA5AA38}" = informationengine.qt.drivers.openaccess.odbc.config-4.0-core-32
"{363A7D16-636C-4292-ACF8-D6BE18E9C812}" = informationengine.qt.drivers.informix.odbc.config-4.0-core-nu
"{3762F589-C1EB-4310-BC82-6EEEBD4C6BD6}" = informationengine.qt.drivers.sap.config-4.0-core-nu
"{37758CCF-01E6-4019-845B-6578D62A9FD3}" = connectivity.connectionserver.client.extended.cpp-4.0-core-32
"{37873A77-9D7E-43F6-AEB6-F55B105F5719}" = connectivity.connectionserver.client.http.cpp-4.0-core-32
"{3837A019-925A-4B60-84B0-F59B01AFE252}" = tools.wstk.webcontent-4.0-core-nu
"{3846C0BD-85CB-4D9D-B996-D807196A979C}" = connectivity.connectionserver.drivers.mssqlsrv.oledb.config-4.0-core-nu
"{38577C88-F3C6-4CE9-9469-B3ECEEACDF47}" = universedesigner.registry-4.0-core-32
"{385EBA5A-7DE4-4C51-8256-534CF40047D5}" = crystalreports.cpp.businessview.clients-4.0-en-32
"{3882DB27-8862-42B1-8289-BA552B63CC04}" = crystalreports.dataaccess.driver.ado-4.0-en-32
"{3953A794-6532-4DC7-8BA8-206FDCD84961}" = repoaccess.cdztools.oldregistry-4.0-en-32
"{3ACBE84D-8294-4E8F-A25B-17D16EA89F59}" = crystalreports.dataaccess.driver.btrieve-4.0-en-32
"{3B2367AE-04DB-4587-9003-829A1A5AC075}" = connectivity.connectionserver.drivers.neoview.jdbc-4.0-core-nu
"{3BBFEE93-ECF6-45D1-B0F8-A42CDA18272A}" = crystalreports.partner.shared.cpp.pvlmapping-4.0-core-32
"{3CE22C95-69A5-4BE5-BC6F-551F2D4F9F88}" = informationengine.qt.drivers.informix.jdbc-4.0-core-nu
"{3DB9988B-4D8A-421B-BC00-ED5BB1C2D0E0}" = connectivity.connectionserver.core.config-4.0-core-nu
"{3DBC395E-496B-40CF-A0B9-5D20658D4D51}" = connectivity.connectionserver.drivers.mssqlsrv.oledbolap.config-4.0-en-32
"{3E03E16A-E510-499F-A336-2DB38FE31826}" = connectivity.connectionserver.helpers.cpp-4.0-core-32
"{3E29EE6C-963A-4aae-86C1-DC237C4A49FC}" = Intel® Rapid Storage Technology
"{3E456D75-3FC3-45B9-B554-7512263C957E}" = connectivity.connectionserver.drivers.sybase.odbc-4.0-core-32
"{3E7DCB57-E7D2-48A1-B1C5-E2594CFFD5B0}" = webi.cdzsrv.lib.data-4.0-core-nu
"{3EA5C03A-432E-4DE4-B0F5-CC6B246E8A37}" = connectivity.connectionserver.drivers.mssqlsrv.oledb-4.0-core-32
"{3EF1EA92-61A1-47B0-87F0-BBC6458A1F3D}" = foundation.bipjcomanager-4.0-core-nu
"{3F90A3AB-E6FF-4432-ACAE-567D66486A76}" = qaaws.qawsclient-4.0-en-32
"{3FB119D8-86D6-4D82-BFDE-5EC95914566D}" = webi.composable.ui.desktop.dotnet-4.0-core-32
"{3FFB1C2A-50F7-4A56-86FC-7C073D3EB78E}" = olap.oda.bicsprovider.java-4.0-en-nu
"{3FFBE1CA-FBDF-40B6-ADD9-A24CC414BFB5}" = connectivity.connectionserver.drivers.jdbc.core-4.0-core-nu
"{408C09C5-F432-4A96-9204-81FBC6285EF2}" = tp.apache.derby-10.2.2.0-core-nu
"{40A0A513-B4B7-47EC-8DA1-6D749712DF81}" = re.shared.webservices.cons.dsws.dotnet2-4.0-core-32
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{40CADF29-8AE1-47F3-B28B-8029D675CC92}" = informationengine.qt.drivers.maxdb.odbc.config-4.0-core-nu
"{4146E5B9-2477-49D0-BF41-526DF4A3CE6C}" = connectivity.connectionserver.drivers.mysql.odbc.config-4.0-core-nu
"{41A3CF96-298C-4A49-9A0F-E929AB542C0F}" = connectivity.connectionserver.drivers.sybase.jdbc-4.0-core-nu
"{421A23F1-4A22-4C9C-9BD0-0F4EDBD98D41}" = informationengine.qt.drivers.neoview.odbc.config-4.0-core-nu
"{426E4DF4-263E-4FAB-BDDA-0207DEFA1FAB}" = migration.rss_files-4.0-core-32
"{42FD6111-7BDC-41A4-8A39-BD3D5833C351}" = repoaccess.container.admintool.java-4.0-core-nu
"{43C00144-7432-4AA4-9BE0-AB2995235DC3}" = webi.cdp.plugin.cds_plugins.biservice_ui-4.0-core-nu
"{44646E59-3486-4D66-B405-4A6229318912}" = crystalreports.dataaccess.driver.db2-4.0-core-32
"{44B7393E-1A1D-4A04-88A6-14C9379B0162}" = connectivity.connectionserver.drivers.maxdb.odbc.config-4.0-en-nu
"{452948DC-743B-44D6-AE1B-BC18633B0B7F}" = connectivity.connectionserver.drivers.sap.bapi.config-4.0-en-32
"{45E06122-0C1A-4FD7-9BE7-604A1216FF3B}" = connectivity.connectionserver.drivers.mssqlsrv.odbc-4.0-core-32
"{46117992-0D6E-42AF-AD60-B00D53DFF82E}" = crystalreports.dataaccess.driver.sforce-4.0-core-32
"{463501E0-2EA1-4790-A1C0-0517E285F5CF}" = datafederator.boe.client.java-4.0-en-nu
"{463FF5C4-556F-4411-83D1-B1BE463910BF}" = connectivity.connectionserver.drivers.msaccess.odbc.config-4.0-en-32
"{467B5F7D-19FC-4187-B4F3-6423EA8111D3}" = webi.cdp.plugin.cds_plugins.biservice_dp-4.0-core-nu
"{46F1AB86-42D8-49CE-B3C3-993EBC0F3A55}" = tp.apache.xerces.java-2.9.1-core-nu
"{479AA04A-CE47-4AD6-AB38-CC1F1B0C63D6}" = connectivity.connectionserver.drivers.ingres.odbc-4.0-core-32
"{4842F5C8-C54B-49EF-A966-5E3024BE1D7D}" = tp.libxml2-2.0-core-32
"{485DE520-E443-4BAD-BBC1-AA0D044200F0}" = informationengine.qt.drivers.db2.cli.config-4.0-core-nu
"{49544EC3-2563-4063-952D-FE455D882CEE}" = webi.composable.ui.desktop.dotnet-4.0-en-32
"{4990290C-DD59-4650-AD0C-2C22C2B645EE}" = informationengine.qt.drivers.netezza.jdbc-4.0-core-nu
"{4A171F4F-5E16-43D7-8127-260070F986C0}" = tp.apache.commons.java-3.1-core-nu
"{4A62A2D2-F59C-41EA-959F-3F6D0E080E42}" = crystalreports.dataaccess.driver.ado-4.0-core-32
"{4AC12302-2F8A-46ED-81CE-7882CFCE096B}" = connectivity.connectionserver.drivers.db2.cli.config-4.0-en-nu
"{4AF3F733-1D93-4EB3-8178-12BD8C48D515}" = mda.services.client.platform.boe.plugin_shared_bundle-4.0-core-nu
"{4B54CE76-4FFF-44DA-95DF-BE8D4AFF8CC6}" = repoaccess.jhelpers-4.0-core-32
"{4BA74AA2-41EE-46C5-8A5D-A0FBEC58136B}" = connectivity.connectionserver.drivers.progress.jdbc-4.0-en-nu
"{4BB359AE-0A12-407C-BD6B-F2E9B64529EF}" = universedesigner.designer-4.0-en-32
"{4BE10A6A-9622-4203-89DF-2A2030C2744D}" = informationengine.qt.drivers.netezza.odbc.config-4.0-core-nu
"{4C7EA020-D9CB-4B2D-A963-9ED50D91310F}" = biwidgets.client.dotnet-4.0-core-32
"{4CDD6439-8884-443B-8E7A-3190D61E3DF6}" = universedesigner.fccube.export-4.0-core-32
"{4DF314A8-AFC6-4C61-BB93-0DE91CAF7F2B}" = repoaccess.cdztools.jshell.shared_classes-4.0-core-nu
"{4DFE54A8-0DDE-4159-8530-99A15173B07D}" = connectivity.connectionserver.drivers.oracle.oci-4.0-core-32
"{4E31BB5B-4755-49F9-A9AA-9DBB6419D947}" = connectivity.connectionserver.drivers.generic.odbc.config-4.0-core-nu
"{4E8B3E78-6117-4D12-9694-7B60DAE8FDD0}" = connectivity.connectionserver.drivers.datafederator.jdbc-4.0-core-nu
"{4EC32E69-21CA-46F1-9A1E-54352124187F}" = connectivity.connectionserver.drivers.informix.odbc.config-4.0-core-nu
"{4F98D546-754E-40BD-8D56-5CE2009DB0E5}" = connectivity.connectionserver.drivers.essbase.olap.config-4.0-en-32
"{4FA3239F-DD57-453B-91B5-475344872E25}" = informationengine.qt.drivers.mssqlsrv.oledb.config-4.0-core-nu
"{4FD65ED5-B49B-4968-AE83-E7581DEB75BC}" = platform.sdk.boe.dotnet_providers-4.0-core-32
"{504DA2AF-D764-4FB3-A6C8-588F0458CB21}" = migration.reporter-4.0-core-32
"{5097DDB3-BB59-4987-BE4A-6160B4497C55}" = connectivity.connectionserver.drivers.ingres.jdbc-4.0-core-nu
"{520C9ACB-6AD9-4FCA-BE6C-0E42751CA1BC}" = crystalreports.dataaccess.driver.sforce-4.0-en-32
"{5250D920-0C32-4410-AD73-DF3C4E75229A}" = repoaccess.cvomextendedblock.pbds-4.0-core-nu
"{5486FA5F-7C83-48C1-9835-B5616826BB15}" = tp.dom4j-1.6.1-core-nu
"{54A1909A-B141-45F2-A699-08C13A2493BB}" = informationengine.qt.drivers.progress.odbc.config-4.0-core-32
"{557FA925-94A9-4E3F-80F6-481227265A30}" = crystalreports.dataaccess.driver.dataset-4.0-core-32
"{55A0D8FF-4052-4021-95D2-64335EF8F9B2}" = olap.mda.data.cpp-4.0-en-32
"{55B3B01D-6D50-49DE-B981-857F2357E716}" = informationengine.qt.drivers.oracle.oci.config-4.0-core-nu
"{5603F784-FBEC-4BA5-8EC2-818E657B97CA}" = tp.apache.axis2-1.3-core-nu
"{563912FA-A205-4BF1-A194-77618D51B643}" = tp.apache.axis-1.3-core-nu
"{56AE00F1-90F2-472A-9E66-D545694415D9}" = product.businessobjectsclient.shortcut.univdesign-4.0-core-32
"{57092540-27F5-4DB3-91D4-32CDA5733DBB}" = connectivity.connectionserver.client.java.cpp-4.0-core-32
"{5744176C-5DF5-49AD-B836-9B0CA5B6A04B}" = foundation.bcm.cpp-4.0-core-32
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5806653B-211D-4E37-A2A9-008909E77721}" = tp.sap.ncs-720-core-32
"{5814D37E-6ECA-4599-890A-95369AEB36AA}" = webi.cdp.dsl_plugin-4.0-core-nu
"{58A965EF-897F-462B-A214-85EE2677FA38}" = connectivity.connectionserver.drivers.msaccess.odbc.config-4.0-core-32
"{58CCC4E6-6884-412B-A892-3D0991091B95}" = crystalreports.cpp.exporting.u2dpost-4.0-en-32
"{59311C7E-A4EA-4A32-83EF-A64495721B14}" = universedesigner.sqlboserver.dx-4.0-core-32
"{598D7B74-24CF-4234-A54B-C21F918D863F}" = connectivity.connectionserver.drivers.mysql.odbc.config-4.0-en-nu
"{599CBEC8-3BFD-4620-B0A4-3055A1B73389}" = informationengine.cube.binfiles-4.0-en-32
"{5A9A2C89-B56A-467F-B94D-8A327FB75474}" = product.businessobjectsclient.arp-4.0-core-32
"{5B5C5E2E-A759-4830-8356-21760F83AC86}" = tp.sourceforge.libpng.cpp-1.0.30-core-32
"{5BB10062-2FFD-4EC6-B898-329F8F4CB4E0}" = crystalreports.cpp.share-4.0-en-32
"{5BB52399-6E57-45EA-83AF-8712CC8A2BBE}" = foundation.bcm.java-4.0-core-nu
"{5BBD8A38-D31E-4A3D-943B-67C00C0108D5}" = informationengine.qt.drivers.personalfiles.odbc.config-4.0-core-32
"{5BE4A0F1-D09A-4C41-9C52-E951B123EC40}" = connectivity.connectionserver.drivers.db2.jdbc-4.0-en-nu
"{5BEE1DC6-AB46-4542-B54B-836E3A83E491}" = informationengine.qt.drivers.open-4.0-core-nu
"{5C20D21A-0461-41DC-B09C-373C62465D12}" = translation.manager.cms-4.0-core-32
"{5D40DC2B-4E33-462B-9035-29FE5FD8AA31}" = tp.xpp3.eclipse-1.1.3.8-core-nu
"{5DED0186-0733-4D74-AFE0-FF69219FE3B3}" = crystalreports.dataaccess.driver.p2bbde-4.0-core-32
"{5E8E6FF4-7F62-4595-8393-3295185E50AB}" = connectivity.connectionserver.core.cpp-4.0-core-32
"{5ED72CCC-F880-4E0D-A50B-F02131833F73}" = tp.apache.xerces.java.classes-2.6.2-core-nu
"{5EFE7C91-EB85-410B-A43D-128B2B9EAFC0}" = crystalreports.partner.shared.cpp-4.0-core-32
"{5F2BD233-B38E-4DF0-941E-D9BE9EF9FFB2}" = informationengine.qt.drivers.mssqlsrv.odbc.config-4.0-core-nu
"{60009F8D-15E3-48C8-B280-6C6696F532E8}" = crystalreports.sdk.java.sdkcommon-4.0-core-nu
"{601EC7C9-C1BF-4DDB-8FE1-0CBA68669403}" = xcelsius.designer.present-4.0-core-32
"{60D7A67C-AAAC-4292-B9B9-FDAFFEF06ABC}" = tp.threedgraphics.pgsdk.cpp-2.50.16.busobj.1-core-32
"{60F22BDF-2CEB-438E-8C15-460155CC7D7F}" = datafederator.boe.nativeconnection-4.0-core-nu
"{61A3D124-67DD-49A7-8163-50FB6001EA91}" = informationengine.qt.drivers.mssqlsrv.jdbc-4.0-core-nu
"{61D719F5-515A-48B3-9071-B0CCBA67E94E}" = crystalreports.dataaccess.driver.oracle-4.0-en-32
"{62AA269A-B581-4987-8019-5FB185B643CE}" = xcelsius.assets.present-4.0-en-32
"{62BBB2F0-E220-4821-A564-730807D2C34D}" = Realtek USB 2.0 Reader Driver
"{6358E6D0-5371-4370-8B2E-35D2FCC818F4}" = connectivity.connectionserver.client.inproc.cpp-4.0-core-32
"{637FF9A8-079D-4F7C-B0D8-224DE99BEB02}" = connectivity.connectionserver.drivers.progress.odbc.config-4.0-core-32
"{63F527FD-FFF8-4717-845A-A3A952E6EDE3}" = connectivity.connectionserver.drivers.greenplum.odbc.config-4.0-core-nu
"{63FE996E-C41E-4F62-BE5E-8A1A17220702}" = connectivity.connectionserver.drivers.derby.jdbc-4.0-core-nu
"{642C4DB5-3F34-4155-B3F1-FF7A97C9DB8D}" = tp.apache.axis2-1.4-core-nu
"{64E256E0-EC03-42F7-80F0-B9987FCB6476}" = connectivity.connectionserver.drivers.sybase.ctlib-4.0-core-32
"{650E661D-05EF-445D-9EA7-482397E80261}" = olap.oda.ssas2005.java-4.0-en-nu
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65FD3118-A840-4314-BD01-29865F6DFB7A}" = connectivity.connectionserver.drivers.open-4.0-en-nu
"{66439427-C6D7-4960-86C5-FDDCCB356BB2}" = repoaccess.repositoryproxyinterface.java-4.0-core-nu
"{668338D8-7E62-4732-99E4-88ED1B998927}" = platform.sdk.boe.java.pbds-4.0-core-nu
"{66EED8A6-AE66-4D7C-955B-E2E27EEECEB0}" = tp.protobuf-2.2.0-core-32
"{67042E97-BA1C-43EB-B27F-3874664151AD}" = webi.so.webi.adapter-4.0-core-nu
"{674E3B9B-3DB0-49B3-A3A3-F827E632F75E}" = product.businessobjectsclient.langpackproperty-4.0-en-nu
"{6760C9A2-2338-4151-9AA7-3BD88BA9E2C3}" = connectivity.connectionserver.drivers.sap.bapi.config-4.0-core-32
"{67AA1E23-C193-46B5-A2A7-8AB2637BF6E6}" = foundation.tracelog.java-4.0-core-nu
"{67C6B5AA-5DFE-4B0C-A215-122AB141EDCB}" = webi.cdzsrv.lib.binfiles-4.0-en-32
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{68ADB2E3-6359-4C1B-B69B-4CDA8B607923}" = connectivity.connectionserver.drivers.javabean-4.0-en-nu
"{68E42F72-A66C-47E5-83F1-A64A31506F56}" = universedesigner.tfc-4.0-core-32
"{6920BA3F-9664-4AA6-B9F2-D2A6DE726C5E}" = connectivity.connectionserver.drivers.sybase.odbc.config-4.0-core-nu
"{6931F446-F5FD-43E0-A866-44695269DB5F}" = connectivity.connectionserver.drivers.maxdb.jdbc-4.0-en-nu
"{69487097-E2FA-4A29-8BA9-06F8616281CA}" = crystalreports.dataaccess.driver.com-4.0-en-32
"{699D34D0-6F87-4C46-98E8-E6AFBC799C27}" = connectivity.connectionserver.drivers.odbc.core.config-4.0-en-nu
"{699F0A70-0FA0-4F3D-8E68-40570581DF41}" = universedesigner.queryunv-4.0-core-32
"{69F0FD99-8C99-4615-B237-6434B2F100AB}" = tp.jide-2.8-core-nu
"{6AAD19AE-9E91-4DF5-9A13-7FBCD477F1A8}" = connectivity.connectionserver.drivers.ingres.odbc.config-4.0-core-nu
"{6B41EA6F-4FD6-40F2-94C1-625E992BACAE}" = crystalreports.dataaccess.driver.access-4.0-en-32
"{6BC110A8-0181-485E-94E9-B82C4F95E742}" = connectivity.connectionserver.drivers.greenplum.odbc.config-4.0-en-nu
"{6C38FA8C-8AED-4CC2-B6BE-D8D6E86D3193}" = crystalreports.dataaccess.driver.fielddef-4.0-core-32
"{6D1A011B-BA4D-4818-B7C0-965B1C8CB631}" = connectivity.cis.java-4.0-core-nu
"{6D34F44E-276B-4DCF-B0B5-1E73E8344131}" = xcelsius.designer.present-4.0-en-32
"{6D924AF5-3D07-47C5-A367-CC7652FB0AF2}" = tp.ooc.dotnet-1.0-core-nu
"{6DCC3B94-DFD6-4C97-8549-FB17199FF279}" = connectivity.connectionserver.server.bridge.cpp-4.0-core-32
"{6DE52612-F4D5-4237-9C4D-3634A9313FE8}" = connectivity.connectionserver.drivers.maxdb.odbc-4.0-core-32
"{6E1DB188-419B-4BBB-B56A-29AFD07A705B}" = tp.sap.ljs.passport-0.7.0-core-nu
"{6E230A9A-A56D-48AC-B4DE-78110C9E0DF7}" = crystalreports.cpp.xcsaptoolbar-4.0-en-32
"{6E487C56-D3A1-4541-8477-32860C3B23CE}" = platform.sdk.boe.java-4.0-core-nu
"{6EE365B8-4756-47FD-9EC8-9F3A015711A2}" = crystalreports.cpp.cractivexviewer-4.0-en-32
"{6F1D95E5-481A-4402-A405-37BE1B4E7685}" = crystalreports.dataaccess.driver.jdbc-4.0-en-32
"{6F44D5EA-FF93-47E8-AA06-0D301BEF1FA1}" = universedesigner.fccube-4.0-core-32
"{70730005-086B-453B-B5C0-2467D07CE6A8}" = tp.openssl-0.9.8l-core-32
"{70E237DC-9E1C-4119-B500-CB4184356BFD}" = shared.library.content-4.0-en-32
"{70E59A71-06AB-4A50-9CB3-C85059959BD0}" = tp.eclipse.aspectj-1.6.5-core-nu
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71386AAC-7FAE-49BD-9693-B53AF9A5AACF}" = crystalreports.dataaccess.driver.com-4.0-core-32
"{7163A430-35BA-4572-A5FB-62F4E8926B00}" = crystalreports.dataaccess.querybuilder-4.0-core-32
"{716E0306-8318-4364-8B8F-0CC4E9376BAC}" = MSXML 4.0 SP2 Parser and SDK
"{72462C9F-A03C-4A53-819F-9C5F11EB0F2D}" = crystalreports.partner.shared.cpp-4.0-en-32
"{727E93DC-5770-4601-ABD5-118DDB3733BF}" = platform.sdk.boe.dotnet.enterprise-4.0-core-32
"{7282723F-0262-4AB7-8615-CC9857BB1C29}" = connectivity.connectionserver.drivers.oledb.core.config-4.0-en-nu
"{72A1EEC9-9345-4661-8E6A-EF0559E77D75}" = connectivity.connectionserver.drivers.mssqlsrv.jdbc-4.0-en-nu
"{73547438-AA85-4460-933E-F8EEC2F4DB0E}" = tools.astools.java-4.0-core-nu
"{73684FF5-E845-4E2A-8B26-4F28E526F6A7}" = connectivity.connectionserver.drivers.neoview.odbc.config-4.0-en-nu
"{737F093D-9C55-487F-84A5-1A89123D3A5C}" = olap.oda.xmla_core.java-4.0-en-nu
"{738E1426-59C3-43A4-9F01-298C682174A3}" = translation.manager.cms-4.0-en-32
"{73D1C995-F10E-44C7-BAFD-BD2A0C95605B}" = connectivity.connectionserver.drivers.ingres.jdbc-4.0-en-nu
"{73DAC1A9-C1C9-4832-8622-D524D28A75D7}" = connectivity.connectionserver.drivers.oledb.core-4.0-core-32
"{73EF6C5E-4DC9-4EAC-8533-5F2A61C78807}" = product.xcelsius.langpackproperty-4.0-en-nu
"{74604F93-9FB0-4F24-BB32-138D0A8D70E7}" = crystalreports.cpp.xcsaptoolbar-4.0-core-32
"{75E9530D-D98C-45A5-A99B-F2C14B264623}" = platform.library.common.authentication.oracle-4.0-core-32
"{763DBF6A-7B92-42DF-BDB2-3450DCBD4BD9}" = foundation.locale_fallback.cpp-4.0-core-32
"{763E9062-5752-440B-AE8A-9C3B11D143D3}" = tp.tom.eclipse-26-core-nu
"{76423E31-835B-4241-8A20-45446E853834}" = platform.webservices.cons.dsws.dotnetsdk-4.0-core-32
"{7701BDAF-FDD0-4A21-AE8A-8F73854AA4DE}" = connectivity.connectionserver.drivers.db2.odbc.config-4.0-core-nu
"{779C6BA2-B88F-40BB-B795-76278983522C}" = foundation.javalibs.classes-4.0-core-nu
"{77B876EA-8974-4A38-86B2-EEF8BA1B4750}" = tp.apache.xalan.java-2.5.2-core-nu
"{77EECA52-543B-4A39-8C25-9A140402E6E9}" = dsl.slproxy.slproxybridge.binfiles-4.0-core-32
"{7904BAD3-ED0E-4AA9-AA2A-201DE2AEFDFF}" = crystalreports.dataaccess.driver.p2soutlk-4.0-en-32
"{794DCEEB-C7E9-46BF-A916-2D444AE54866}" = platform.webservices.cons.dsws.javasdk-4.0-core-nu
"{795BC502-5E33-47F7-B8F2-527120EF5AFA}" = platform.services.ras21.clientsdk_bundle-4.0-core-nu
"{7A3A5421-B92D-49A9-9468-30030BF86E18}" = webi.webservices.cons.dsws.javasdk-4.0-core-nu
"{7A589FB0-452A-4C2B-9E34-DB1DF555069F}" = connectivity.connectionserver.drivers.progress.odbc-4.0-core-32
"{7A67FCBC-FF0D-4559-BFA6-1858F21C7F69}" = crystalreports.dataaccess.driver.olap-4.0-core-32
"{7AEE649B-E768-4BDD-9D7A-549375C53293}" = connectivity.cis.cpp-4.0-core-32
"{7BA3338D-DD04-4EFD-99D0-2EEE4B797FD3}" = tools.srvtools-4.0-core-32
"{7BB5E925-A3DD-48C2-9A82-017AF5982FFE}" = Facebook Messenger 2.1.4590.0
"{7BCCC2EA-0495-4870-8E13-FDD50764251A}" = connectivity.connectionserver.ddk.java-4.0-core-nu
"{7BF1E119-212E-4C26-A091-11F6C06077B7}" = product.xcelsius.arp-4.0-core-32
"{7C4ACEBE-AB19-41EA-9409-57B605AA6B00}" = tp.rsa.crypto.cpp-3.2.1.2-core-32
"{7CA63938-51FE-4E7C-8E53-1939BE7ED980}" = informationengine.qt.drivers.msaccess.odbc.config-4.0-core-32
"{7D3E886C-B9A9-478C-9AA6-E69956EA7F2D}" = platform.library.common.instrumentation-4.0-core-nu
"{7DF858CF-2FB8-4CC5-A62B-2A52F4C8A280}" = tp.apache.axis2.bundle-1.3-core-nu
"{7E776ADB-FBB7-426D-86B4-40DA64EA6E7E}" = crystalreports.dataaccess.driver.ebs-4.0-core-32
"{7E7FC727-E84A-48F0-BAEC-6A8B7809A9E3}" = olap.oda.xmla_core.java-4.0-core-nu
"{7EB0BAEE-3B4F-44F1-896F-740A67A49E3D}" = repoaccess.async_helpers-4.0-core-32
"{7EBB358F-321F-4127-8390-C2C6975FED40}" = shared.library.content-4.0-core-32
"{7EC14FED-33B3-427C-96D0-8A5D67BAB2CE}" = tp.cup-0.11-core-nu
"{7ED1A0B8-1B70-4E3D-B449-3F2C1DB10EB0}" = connectivity.connectionserver.drivers.derby.jdbc-4.0-en-nu
"{7FAEE42B-A586-426C-9906-971EBA5F0C0C}" = xcelsius.assets.present-4.0-core-32
"{802E0C61-DB26-44A5-B9D9-83D98A906D7A}" = platform.services.ras21.clientsdk.java.pbd-4.0-core-nu
"{80941F2A-E7F7-4B86-BF5C-344C0E3F592B}" = platform.services.search.sdk.shared.java-4.0-core-nu
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{81B862FE-AE60-4239-A3CE-2A65FE2C38BF}" = crystalreports.dataaccess.driver.sybase-4.0-core-32
"{821428CC-0213-43D2-8753-B7DAC82B7595}" = crystalreports.sdk.java.repository-4.0-core-nu
"{824739C6-1DF6-4BC5-8A79-8F4BC2029889}" = tp.apache.xbean-2.1.0-core-nu
"{829565E9-B77B-4A53-A10A-E86B72135835}" = connectivity.connectionserver.tools.cscheck-4.0-en-32
"{835A77B3-8F53-493C-B05F-608EC68347C5}" = tp.synthetica.addons-1.3-core-nu
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{848885AE-86AC-4CC4-87ED-3EAE5F58BA8B}" = connectivity.connectionserver.drivers.greenplum.jdbc-4.0-core-nu
"{848DB4CE-7EDD-490E-9FA2-3FAC50640757}" = crystalreports.dataaccess.driver.btrieve-4.0-core-32
"{849E8871-C5E8-499D-A0AE-2923CBFC0454}" = tp.xpp3-1.1.3.8-core-nu
"{856902BD-848B-4605-AC50-F82771A55541}" = tp.rsa.crypto.java-4.1-core-nu
"{85DB8088-9158-4B5D-BD18-27530F7F3081}" = migration.conversion.documentation-4.0-en-32
"{8616B2F6-43FF-4042-9A58-8FD5DF7A1E1E}" = tp.apache.log4j.classes-1.2.6_sap.1-core-nu
"{864C043A-D21E-4B0E-BA81-984B8A51B59E}" = repoaccess.container_plugins.java-4.0-core-nu
"{87233779-674B-468C-817E-8314B148CB30}" = tp.pdflib-8.0.1p5-core-32
"{87D5D113-58E7-453F-B4E1-5FC4A441FB06}" = dsl.slproxy.consumption_light.binfiles-4.0-core-32
"{8833FFB6-5B0C-4764-81AA-06DFEED9A476}" = Realtek Ethernet Controller Driver For Windows 7
"{887C90B6-805C-43A8-81BF-A6780D278959}" = tp.apache.rampart.classes-1.3-core-nu
"{88C02807-008A-4BE2-8C5F-CAF55DAE36D0}" = repoaccess.container_plugins-4.0-en-32
"{89905A26-DD09-4F4C-954C-176A9E9C7665}" = olap.mda.data.cpp-4.0-core-32
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8A6539E9-D4B8-4B30-8C50-7CF4E0C0C85F}" = informationengine.qt.drivers.greenplum.jdbc-4.0-core-nu
"{8AC2FA85-D98D-4058-9FE4-1F60C244DD8E}" = crystalreports.dataaccess.querybuilder-4.0-en-32
"{8B39F472-1CD4-4880-9E6D-FE3A6AA77EEA}" = crystalreports.dataaccess.driver.odbc-4.0-en-32
"{8B7C7644-4027-42F5-95FD-49DE8FF21E86}" = platform.sdk.boe.java.peoplesoft-4.0-core-nu
"{8B8125A4-1475-4BDD-9F4A-1FE342BC46E4}" = tp.apache.log4j-1.2.6_sap.1-core-nu
"{8B980C51-02B6-4C61-9667-C3CA32F904D3}" = informationengine.qt.drivers.maxdb.jdbc-4.0-core-nu
"{8B9AD19F-81F3-42D4-AD31-D86048199601}" = connectivity.connectionserver.drivers.generic.odbc.config-4.0-en-nu
"{8BD6F287-D8F1-45D6-92D6-F822325A76D6}" = connectivity.connectionserver.drivers.essbase.olap-4.0-core-32
"{8C097C21-1F5C-4F7F-9E90-65C0A269CC66}" = platform.client.dotnet.ure.uri-4.0-core-32
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8C7C5FEE-A493-459F-832D-F8D2AB111690}" = tp.threedgraphics.pgsdk.cpp-2.50.16.busobj.1-en-32
"{8CECB201-C763-4E5B-8952-768A5E5F7C32}" = connectivity.connectionserver.client.extended.java-4.0-core-nu
"{8CFC54CF-C832-4A30-A28F-14F51B837FC2}" = crystalreports.boe.sdkplugins.dotnet-4.0-core-32
"{8D17B405-D091-49A3-B26F-2CD1602444EB}" = connectivity.connectionserver.drivers.mssqlsrv.odbc.config-4.0-core-nu
"{8D232883-F199-4423-B774-5717A93355CC}" = platform.sdk.boe.java.sap-4.0-core-nu
"{8DB2CC7D-FE37-4F25-82B4-A48364B3C1DE}" = universedesigner.bridges-4.0-core-32
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8F4FBAEE-C886-476C-A71C-E1EC938B104D}" = universedesigner.xmlpinfiles-4.0-core-nu
"{8FE10FDC-6425-4837-BCA9-575F89C6B15D}" = migration.busobj.dpxml-4.0-en-32
"{90120000-0015-0409-0000-0000000FF1CE}" = Microsoft Office Access MUI (English) 2007
"{90120000-0015-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0019-0409-0000-0000000FF1CE}" = Microsoft Office Publisher MUI (English) 2007
"{90120000-0019-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2007
"{90120000-001A-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_ENTERPRISE_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_ENTERPRISE_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_ENTERPRISE_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_ENTERPRISE_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-0030-0000-0000-0000000FF1CE}" = Microsoft Office Enterprise 2007
"{90120000-0030-0000-0000-0000000FF1CE}_ENTERPRISE_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0044-0409-0000-0000000FF1CE}" = Microsoft Office InfoPath MUI (English) 2007
"{90120000-0044-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00BA-0409-0000-0000000FF1CE}" = Microsoft Office Groove MUI (English) 2007
"{90120000-00BA-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0114-0409-0000-0000000FF1CE}" = Microsoft Office Groove Setup Metadata MUI (English) 2007
"{90120000-0114-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_ENTERPRISE_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0117-0409-0000-0000000FF1CE}" = Microsoft Office Access Setup Metadata MUI (English) 2007
"{90120000-0117-0409-0000-0000000FF1CE}_ENTERPRISE_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{911DCE4C-EBE2-4964-BE5D-2A2750779DA5}" = connectivity.connectionserver.drivers.netezza.odbc-4.0-core-32
"{91525DAD-50C3-4887-AC27-C4ED8B8B2D1B}" = tp.xpp3.classes-1.1.3.8-core-nu
"{922D390F-40F0-4F0C-95BD-07F5F1BB299E}" = dsl.slproxy.pbd-4.0-core-nu
"{9243D2B9-5FE1-4C4A-8814-15B3EB81187E}" = dsl.bimodeler-4.0-en-nu
"{926EA874-9DAD-41B3-9EB7-58F2F368AC65}" = connectivity.connectionserver.drivers.mssqlsrv.oledb.config-4.0-en-nu
"{927739E2-984A-4FCD-BDCF-3DCB67E38EE2}" = informationengine.qt.drivers.teradata.jdbc-4.0-core-nu
"{92B69E10-E4B6-4E6B-BACF-0F2BA083837A}" = platform.sdk.boe.com-4.0-en-32
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{930C79C8-7F89-452A-BF43-D69DFAC991FA}" = connectivity.connectionserver.drivers.datafederator.odbc-4.0-core-32
"{93476EBF-00C6-4189-9FEC-7517B03CE93C}" = crystalreports.cpp.printcontrol-4.0-core-32
"{93BCE3A3-2EDF-433F-A92E-CB117A0621A3}" = datafederator.sourcedefiner.java-4.0-core-nu
"{943AF0B0-5563-48F7-9791-10D4A7ED0711}" = tp.apache.xalan.java.classes-2.5.2-core-nu
"{9462F34E-18ED-4F4A-B056-814BC7427E03}" = tp.ibm.icu.java.classes-3.8.1-core-nu
"{94A6D67D-AE5C-4CB9-8CFE-60774CB698FA}" = crystalreports.cpp.parameterprompt-4.0-core-32
"{9507D552-4047-4989-BBBE-8502B083A359}" = repoaccess.extensions_cvom-4.0-core-32
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{95CE391F-518B-4094-B7F0-B30CF8FEBB62}" = tp.pkware.cpp-1.0-core-32
"{96C49432-A707-44AB-B0BE-E4FD990F253B}" = crystalreports.dataaccess.driver.informix-4.0-core-32
"{96F86AAD-04CD-43C9-9CC4-A80067E251CA}" = migration.busobj.procfc-4.0-core-32
"{97451F4D-DC9F-43DC-BF3E-E3F3F9CA54D7}" = olap.oda.bpc.java-4.0-core-nu
"{9883A6B7-F3C6-4AC7-A3AE-72FF47CA37D1}" = crystalreports.dataaccess.driver.xml-4.0-core-32
"{98E47143-9B45-4620-ABCD-7D93C4B0E83B}" = platform.sdk.boe.java.oracle.plugins_bundle-4.0-core-nu
"{99E65BFC-886F-4052-84D0-F85E5823187A}" = connectivity.connectionserver.drivers.datafederator.odbc.config-4.0-core-32
"{99F1D522-1C38-492B-A73A-E10EBFF3B600}" = xcelsius.designer-4.0-core-32
"{9A080B6C-32AB-4566-BAB5-B4FC60D63D14}" = crystalreports.cpp.printcontrol-4.0-en-32
"{9A7B7EAF-AEBC-4306-AA47-D78C5760662C}" = informationengine.qt.drivers.mysql.odbc.config-4.0-core-nu
"{9A880441-398F-428E-8694-F15456DF6F0C}" = crystalreports.dataaccess.driver.olap-4.0-en-32
"{9A945CFA-60F3-4E9A-A1EA-34171E9B4104}" = connectivity.foundation.cpp-4.0-core-32
"{9A999F52-ACCA-486E-AF1D-F76AA1A9A43A}" = connectivity.connectionserver.drivers.datafederator.jdbc-4.0-en-nu
"{9B12274D-F720-4BC2-929D-822669CAA654}" = connectivity.connectionserver.drivers.teradata.jdbc-4.0-core-nu
"{9C15DF4C-C50D-45DD-B85E-A4420F2E2D7F}" = tp.rsa.crypto.java.classes-4.1-core-nu
"{9C1CEC03-0204-44CC-9C17-54D2F5F6ADF5}" = repoaccess.cdz_ext.framework-4.0-core-nu
"{9C60C74D-D4B2-4BD0-93A4-7E5E098BE121}" = crystalreports.cpp.share-4.0-core-32
"{9C799EF8-33B2-49F5-A042-7CBF254FDFC1}" = universedesigner.vartools-4.0-core-32
"{9D0832C5-2A2E-4B5D-A07E-67F76A9D6867}" = connectivity.connectionserver.drivers.hsqldb.jdbc-4.0-en-nu
"{9D1AD433-7A8D-46D8-B01D-86628D0AE9BE}" = webi.cdp.cdsframework_common-4.0-core-nu
"{9D1BEE6B-A5D4-4D56-9EE9-C76539DA19AD}" = informationengine.qt.drivers.sybase.jdbc-4.0-core-nu
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9D793912-2459-4769-86B7-EF158BAF7AF6}" = tp.apache.xerces.cpp-2.7.0-core-32
"{9DCCE485-EB15-49C3-82A7-45A501EC0F1D}" = tools.wstk-4.0-core-32
"{9DD463C1-FC7F-4E5B-9523-37FF7039410E}" = tp.protobuf.jar-2.2.0-core-nu
"{9DE9CA2F-D016-40D9-A3D2-22AB1B6EA70F}" = universedesigner.tools-4.0-en-32
"{9E556178-5F68-4D5D-BAF3-C15A342B5CA6}" = crystalreports.dataaccess.driver.filesystem-4.0-en-32
"{9EB290A5-C055-4118-95B7-659F4EA1C4D7}" = crystalreports.dataaccess.driver.oracle-4.0-core-32
"{9F03508E-E0F1-44F8-AF4B-51624279C606}" = crystalreports.dataaccess.driver.p2soutlk-4.0-core-32
"{9F3E7642-65A7-4278-BDDD-92D7891FEDC2}" = webi.richclient.common-4.0-core-32
"{9F460B0C-C953-4B03-8028-B3F1B7D0E844}" = universedesigner.designer.documentation-4.0-en-32
"{9FC5DA38-6195-4F54-8B4F-9E6840608600}" = connectivity.connectionserver.drivers.db2.cli.config-4.0-core-nu
"{A06F3506-2129-4605-B8FB-475434C22F4D}" = tp.apache.xerces.cpp-2.1.0-core-32
"{A0933CF7-AAC4-4819-B275-9FCCBDAE1986}" = tp.apache.xerces.java-2.6.2-core-nu
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A0DC1C16-0FDA-4D6E-92DB-552F93A0F538}" = repoaccess.ctplugin.java-4.0-core-nu
"{A0DC4E36-9FD4-45EE-B0F3-E2E4AAB0041A}" = crystalreports.dataaccess.driver.xml-4.0-en-32
"{A11C5365-0625-45B2-87B7-ED625EE66BE9}" = informationengine.ieplugin.binfiles-4.0-en-32
"{A1609E8A-E1DA-4435-A626-375752ADFDD2}" = tp.ooc.java.bundle-4.0.5-core-nu
"{A17931F7-276D-4D6B-A37D-48C5C4E0CBFE}" = foundation.tracelog.java.classes-4.0-core-nu
"{A2C7ED60-2C86-41CE-86C5-EA79995CB6E5}" = crystalreports.dataaccess.driver.p2slog-4.0-core-32
"{A2D36CB4-25E5-46DA-B0B8-015AB7AA3AAF}" = crystalreports.dataaccess.driver.javabeans-4.0-core-32
"{A3031FC4-E9ED-4BE5-8A86-1C60F48C5D52}" = dsl.transmgr_unx-4.0-core-nu
"{A3520959-EC76-40C8-A818-AF728EDE6F3D}" = crystalreports.dataaccess.driver.javabeans-4.0-en-32
"{A4998564-1316-4170-983B-E3D93E275D3A}" = connectivity.connectionserver.drivers.netezza.jdbc-4.0-en-nu
"{A588A72E-F0DC-4005-B94B-3A6986D1AF6F}" = connectivity.connectionserver.helpers.java-4.0-core-nu
"{A59C9634-0B12-4625-A381-12F61E7BE3E8}" = platform.sdk.boe.com.core-4.0-core-32
"{A5F00EDE-C61C-47E3-B4E5-166877ECAD78}" = informationengine.qt.drivers.javabean-4.0-core-nu
"{A6319946-E044-4F34-AFD5-FA3ADD62A5D5}" = olap.oda.bicsprovider.java-4.0-core-nu
"{A6C768F1-CA52-496E-9BC7-E3312A4F9B9A}" = platform.sdk.boe.java.bundles-4.0-core-nu
"{A705F4AD-5B19-4EA9-BE4D-DAEE63FA09C7}" = dsl.slproxy.slproxybridge.java-4.0-core-nu
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A72825BF-3887-4F13-91BC-66681C21BE43}" = tp.rosette-4.2.1-core-32
"{A8DA3FFB-9219-4FD8-BBD0-EF2202002123}" = tp.bcgsoft.controlbar.cpp-6.4-core-32
"{A8E920CC-FEA4-48C5-AB08-99DCD08D8F0C}" = crystalreports.cpp.businessview.clients.crw-4.0-en-32
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9559A9F-C3BA-494E-B2BC-20129C786EB7}" = crystalreports.dataaccess.driver.dataset-4.0-en-32
"{A9662DDE-28DA-4E9A-BE1A-60BBB622CF84}" = connectivity.connectionserver.drivers.generic.odbc-4.0-core-32
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AA1AEF00-3439-4272-9AF4-008B3B373DFE}" = crystalreports.cpp.cractivexviewer-4.0-core-32
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAC31E60-2BDB-4217-BC24-00EA51FD5B10}" = webi.cdp.plugin.cds_plugins.biservice_ui-4.0-en-nu
"{AAD7037A-7B49-44AB-B710-683C6F3EA2CF}" = repoaccess.global.registry-4.0-core-32
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AAF63F76-B7F3-45A3-9623-09C192925B97}" = webi.composable.ui.shared.dotnet-4.0-core-32
"{AC5607B1-B649-42CA-A9D5-1A75165B4E2B}" = crystalreports.cpp.ras.bv-4.0-core-32
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.3)
"{ACA9CF47-991C-4B76-AFE4-93E9D6C0BB06}" = tp.microsoft.mssdk-10.0-core-32
"{AD5F12A5-7753-46AC-9137-66CDEDE44AA7}" = crystalreports.cpp.businessview.clients.crw-4.0-core-32
"{AD61A91F-625B-409F-AF92-94E4551785D5}" = olap.oda.api.java-4.0-core-nu
"{AD6A931E-17AC-4DAB-93D8-B1AD2D1DFF72}" = crystalreports.cpp.filedialog-4.0-core-32
"{ADBA7722-3CAE-43E7-976B-7DF949D62DB7}" = platform.sdk.boe.java.dfo.util-4.0-core-nu
"{ADD59CE4-FF67-4292-8ACD-D1EFB0BB8205}" = repoaccess.repoaccess_plugins.data-4.0-core-nu
"{ADE16A9D-FBDC-4ECC-B6BD-9C31E51D0333}" = Lenovo EasyCamera
"{ADEA818B-38F2-4479-932D-A791EA83F780}" = connectivity.connectionserver.drivers.sap.bapi-4.0-core-32
"{ADFC6298-F364-4AB9-BE1D-D70760B101CE}" = connectivity.connectionserver.client.inproc.java-4.0-core-nu
"{AE111FB3-75AB-45D0-9CC3-21F92C0408C8}" = crystalreports.dataaccess.driver.p2sevt-4.0-core-32
"{AF286C85-3B32-43D1-B4F0-05E431827C97}" = tp.poco-1.3.6-core-32
"{AFAD3A19-6C6B-49E5-AC02-E31C177A5CDC}" = tp.tom-26-core-nu
"{AFAEC5B4-46D8-41B3-8092-142B561556BD}" = platform.services.ras21.clientsdk.java-4.0-core-nu
"{AFE0E94D-2549-4829-98FB-E92177D9CCF7}" = platform.services.ras21.clientsdk_shared_bundle-4.0-core-nu
"{B04A22F1-B53E-4BA9-82B4-0E5BE1355464}" = crystalreports.cpp.businessview.samples-4.0-core-nu
"{B0BE2D52-3226-4B50-BB5D-BA8E63A38652}" = tp.sap.introscope-822-core-nu
"{B104C6FB-074C-47D7-A717-3394C50C6B7B}" = crystalreports.dataaccess.driver.sap-4.0-core-32
"{B1280DF3-00BB-4C4B-B6B4-10C5BDCDA91D}" = tp.sun-1.1-core-nu
"{B1A3FD1E-4C0C-4615-9008-CB1D5995DE69}" = informationengine.qt.drivers.oracle.jdbc-4.0-core-nu
"{B1C14366-B371-459E-B90A-F2D575B79EA1}" = crystalreports.dataaccess.driver.act-4.0-core-32
"{B1E6E875-A3B2-4E1A-B500-E3A25581A55E}" = biwidgets.client.dotnet-4.0-en-32
"{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare
"{B2EF9594-89DB-43A0-A9F9-B3DA914FBB8C}" = connectivity.connectionserver.drivers.jdbc.core.config-4.0-core-nu
"{B31BA9F0-524C-42CA-A5FE-45CF3C446517}" = repoaccess.plugins_shared_bundle-4.0-core-nu
"{B38911D0-1799-46B5-A653-950BC34526B4}" = connectivity.connectionserver.drivers.jdbc.core.config-4.0-en-nu
"{B3C3FF2B-240D-4AF9-9925-DCA62FBFDAC2}" = universedesigner.rptdlg-4.0-core-32
"{B442500C-75A4-44A0-A7CC-A465C2950D0D}" = connectivity.connectionserver.drivers.openaccess.odbc.config-4.0-core-32
"{B4754D6B-D84E-4BD8-9AC1-B539748A7616}" = cvom.java-4.0-en-nu
"{B57CFF9F-CF49-4E18-8184-BA62550ED71D}" = bi.2.00.bi.base-4.0-core-nu
"{B5A82341-3C1F-4A56-BCC5-9620F750D4EC}" = connectivity.connectionserver.drivers.informix.jdbc-4.0-en-nu
"{B63F5593-A100-4166-89B4-D1E725FD88DA}" = crystalreports.dataaccess.driver.p2sexchange-4.0-en-32
"{B68DED34-CD05-49AE-92F0-96DA7DD8EB64}" = informationengine.unvtools-4.0-core-32
"{B6CA0F76-0F17-4D53-8CD0-ACC71B8DC575}" = universedesigner.bridges-4.0-en-32
"{B6E499CF-867D-4DC0-AAE1-75F2A039F441}" = tp.ooc.java.classes-4.0.5-core-nu
"{B76ED284-B8FE-4FF7-A209-1607F9538021}" = platform.sdk.boe.dotnet-4.0-core-32
"{B7895722-516C-49BB-93D4-7EAD9AC4B02B}" = informationengine.qt.drivers.mysql.jdbc-4.0-core-nu
"{B829F975-3301-453B-8FE4-B26218DE125E}" = translation.manager-4.0-core-32
"{B89220C0-7C89-4304-879B-363AAD67CBB3}" = connectivity.connectionserver.drivers.teradata.jdbc-4.0-en-nu
"{B89BF5A9-E932-41EF-A95E-CA7C6AF79327}" = crystalreports.dataaccess.driver.p2dbase-4.0-core-32
"{B9847524-3B87-4A80-86EE-7CFAB37D7CD8}" = connectivity.connectionserver.drivers.progress.odbc.config-4.0-en-32
"{BA467D77-871A-4CE1-B580-BC9C2A2E5A71}" = tp.microsoft.wse-3.0-core-32
"{BAD0DF81-7389-450D-B9E7-EF42938A6316}" = datafederator.boe.dfadmin-4.0-core-32
"{BAEC2486-2048-4D03-9140-DF504040F266}" = platform.library.common-4.0-core-32
"{BB25DCF7-8C02-4B54-8755-843EEC67DF86}" = tp.apache.axis2.classes-1.3-core-nu
"{BBDC0D46-850A-4819-B257-6DC31296496E}" = crystalreports.dataaccess.driver.universe-4.0-en-32
"{BC533138-A8AA-4922-82B5-4934CB53D5F8}" = informationengine.qt.drivers.db2.jdbc-4.0-core-nu
"{BC9BDA6F-E918-451C-8B60-EB45A89B630C}" = tools.i18n4j-4.0-core-nu
"{BD7F9FCD-D20B-4A5D-ACDD-2C254E2EF4FF}" = webi.cdp.cdsframework_dp.java-4.0-core-nu
"{BD995805-3584-44FA-96A3-84FFBFF32EAD}" = repoaccess.extensions_cvom.java-4.0-core-nu
"{BDF1DBF5-F45F-4D01-B764-A1F61A66D1D0}" = connectivity.connectionserver.drivers.generic.jdbc-4.0-core-nu
"{BEA94B00-7AB7-4048-A224-F1D0B69FA861}" = webi.sharedobjects-4.0-core-nu
"{BFCE575E-49B8-40C5-9B4A-D2D9D3535E2E}" = connectivity.connectionserver.drivers.odbc.core.config-4.0-core-nu
"{C0B3B64C-3056-495D-8C9C-09E023AAB4FB}" = connectivity.connectionserver.drivers.netezza.jdbc-4.0-core-nu
"{C10D0C09-C55F-4FBF-83F4-AEEC2E9EA1A1}" = connectivity.connectionserver.drivers.maxdb.odbc.config-4.0-core-nu
"{C13870D8-716A-4608-9A9A-BF581B613EC3}" = crystalreports.dataaccess.driver.adoplus-4.0-core-32
"{C16F8BE5-1DF0-42C7-89BD-7223655B06C0}" = crystalreports.cpp.erom-4.0-core-32
"{C17B3247-0B69-4B48-B382-467CA1A89F76}" = tp.netscape.ldap.cpp-6.0.5-core-32
"{C1827786-F58B-41D0-B607-CCC222929070}" = tp.sap.ljs.passport.classes-0.7.0-core-nu
"{C1BCEEAA-3ED9-49AE-A0CE-419C6C2C124D}" = connectivity.connectionserver.tools.codcheck-4.0-core-nu
"{C2AAA588-4193-46E4-A537-83CCC1530A66}" = crystalreports.cpp.exporting.u2dpost-4.0-core-32
"{C2CF75D8-6EED-4BF1-B6A8-AAF8D1117B8F}" = informationengine.cube.binfiles-4.0-core-32
"{C31D3FFB-DAC5-4AF4-8E16-6B58E8770250}" = tools.i18n4j.classes-4.0-core-nu
"{C3785226-4912-4845-9194-29D85CDD2E06}" = tp.netscape.ldap.cpp.mozjavascript-6.0.5-core-32
"{C42DEBBC-9069-4336-BAE9-5ACD11E2BB16}" = migration.busobj.dpvba-4.0-en-32
"{C4D16820-B476-4290-9EE0-3095C8280CDF}" = informationengine.qt.drivers.ingres.odbc.config-4.0-core-nu
"{C51E54E4-F5D3-4374-BEA5-AEAAC8C1FEFA}" = connectivity.connectionserver.drivers.sybase.odbc.config-4.0-en-nu
"{C59299BA-D7FC-4D59-9DB6-51ED2E79759A}" = crystalreports.crystalcommon.cpp.crlang-4.0-core-32
"{C5C53B9F-8F88-411B-9642-C9364D607ABC}" = crystalreports.dataaccess.share.registry-4.0-core-32
"{C6127442-C07C-47E0-B163-6888D78C9E5C}" = connectivity.connectionserver.drivers.datafederator.odbc.config-4.0-en-32
"{C62D6FB9-05D8-4FF6-ABA0-EE58601F1D2D}" = crystalreports.cpp.registrywrapper-4.0-core-32
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C6F00397-A2A9-44C7-8C37-0282D1556A1F}" = olap.oda.core.java-4.0-en-nu
"{C72F4F45-1CBC-4ACE-8485-AB06F89FAD76}" = connectivity.connectionserver.drivers.netezza.odbc.config-4.0-core-nu
"{C8016259-1B5B-47A8-81D4-13E9829993DA}" = webi.richclient.registry-4.0-core-32
"{C8EF4DED-86BA-4F56-AC34-37EC95B0C01A}" = tp.gzip-1.2.3-core-32
"{C99FC6E7-5057-4CC0-9E3C-B70788B34A53}" = repoaccess.cdztools.oldregistry-4.0-core-32
"{C9B39207-86EB-4D68-80EC-2F0861F89EDC}" = crystalreports.dataaccess.driver.p2sevt-4.0-en-32
"{C9B9D6AA-177B-44F5-BF9C-88B2FC873902}" = repoaccess.extensions.ds_excel-4.0-core-32
"{C9E75769-DF19-4585-B5DD-180DEF0C2345}" = olap.oda.api.java-4.0-en-nu
"{CA339C77-8F57-46D6-864F-08A632F7F12D}" = connectivity.connectionserver.drivers.informix.odbc.config-4.0-en-nu
"{CA36F34E-4DE2-4AC0-B822-60F9A1110AB4}" = repoaccess.jnitools.java.shared_classes-4.0-core-nu
"{CA57B2DE-838F-4E77-A644-A0CF83210493}" = connectivity.connectionserver.drivers.odbc.core-4.0-core-32
"{CB6911FD-1265-429D-870C-B2BC17A5A2E9}" = cvom.java.classes-4.0-core-nu
"{CBB484BD-A6A3-4CE1-BAB4-BC112AB7390A}" = connectivity.foundation.connectionsdk.java-4.0-core-nu
"{CC3BAA08-0E2F-4E99-877E-E2468A365F4E}" = webi.cdp.dsl_plugin-4.0-en-nu
"{CDCC3D2F-9E7F-4703-BC55-D5107A9ABB78}" = connectivity.connectionserver.drivers.generic.jdbc-4.0-en-nu
"{CDE360CD-6DD0-4C44-9553-19B170690E83}" = connectivity.connectionserver.drivers.openaccess.odbc.config-4.0-en-32
"{CDEFBB6A-BE09-4768-9806-6543C1E42EF4}" = connectivity.connectionserver.client.httpxir3.cpp-4.0-core-32
"{CE6A1FA8-5506-4258-A90B-390C77B45AA3}" = universedesigner.uitools-4.0-core-32
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{CE9B4D74-4A89-4105-AF8D-EEF7C8343313}" = webi.webservices.cons.dsws.dotnet2-4.0-core-32
"{CEEFBD91-DC3D-41DD-B0E4-58B82287DB9D}" = tp.timing_framework-1.0-core-nu
"{CEF69C8F-FCFF-4D6C-8CCF-BE7CD49D3D92}" = crystalreports.dataaccess.driver.odbc-4.0-core-32
"{CF332BF5-564B-4BA5-9322-3202850D467D}" = repoaccess.container.java-4.0-core-nu
"{CFA6024E-B358-4F50-9075-62F5738FA5DA}" = crystalreports.cpp.cslib-4.0-core-32
"{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management
"{D0995FD0-9A1E-4763-9CF3-81FB869EC8EA}" = tp.utexasaustin.hoard-3.7.1-core-32
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D0D65D56-1BF2-4409-9867-4C41223CE51C}" = crystalreports.cpp.erom-4.0-en-32
"{D19EE8D6-6BD6-41FD-B2B6-2BF358BDA683}" = repoaccess.async_scheduling-4.0-en-32
"{D1A8A8CF-A854-4861-9EC6-0C502A80FC1D}" = platform.sdk.boe.com.instrumentation-4.0-core-nu
"{D201FA7D-58AD-437F-AB49-56EE3F309A82}" = connectivity.connectionserver.drivers.personalfiles.odbc.config-4.0-en-32
"{D207E625-6B4C-414C-B44E-CE772FD4CF9D}" = crystalreports.dataaccess.driver.cdo-4.0-en-32
"{D21A1FF1-2376-4DCE-A168-B17FA632959C}" = informationengine.qt.drivers.generic.odbc.config-4.0-core-nu
"{D227BEC2-87E5-4C52-AED1-570BF3691AAD}" = translation.manager-4.0-en-32
"{D22EBF86-64BF-45F4-B94D-C0ECC77B6A85}" = tp.curl.cpp-7.13.2-core-32
"{D2342A19-A8C0-41F7-AB09-681640251C46}" = connectivity.connectionserver.drivers.mssqlsrv.jdbc-4.0-core-nu
"{D267B562-A05B-4853-9C79-1C416F97A48E}" = dsl.transmgr_unv-4.0-core-nu
"{D2E2923F-F097-41D3-85B4-175183866581}" = connectivity.connectionserver.drivers.netezza.odbc.config-4.0-en-nu
"{D392EA8A-707A-40A8-9298-5ABE34FF64DE}" = tp.apache.guice-1.0-core-nu
"{D39A54F7-1A4F-417D-9D56-83F4E2497EED}" = cvom.java-4.0-core-nu
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D4756A5A-E5C2-4081-8128-72665DA59C02}" = connectivity.connectionserver.drivers.db2.cli-4.0-core-32
"{D4B060B9-AD4A-4152-9D99-28B93C615AFE}" = Onekey Theater
"{D5698882-7AA3-4513-BCFF-EEC7277C2900}" = platform.webservices.cons.dsws.dotnet2-4.0-core-32
"{D56E5404-E469-46DE-A475-D276AC6A44D9}" = repoaccess.repo_proxy_jni-4.0-core-32
"{D7B02A9A-1746-4212-A704-FC4ACDEB34EA}" = repoaccess.ctplugin.java.shared_classes-4.0-core-nu
"{D7DFD61E-35A9-4C36-B5BE-BD66475375A2}" = informationengine.olapclient-4.0-core-32
"{D81BE593-DF3F-450E-924D-A49E66A8CA8E}" = tp.threedgraphics.pgsdk.cpp.runtime-2.50.16.busobj.1-core-32
"{D852E6B6-B24F-4A6D-81FF-E3DD9F49FEE2}" = tp.azalea-5.5-core-32
"{D85ED785-A121-4AEB-98AF-4DB096C35AAB}" = crystalreports.cpp.share.registry-4.0-core-32
"{D8A7195E-F41F-47E4-9D1E-ECA00D9D1B15}" = connectivity.connectionserver.client.jni.cpp-4.0-core-32
"{D8B58AC4-B4D1-4431-ACDB-BDFBEAB61EE4}" = dsl.transmgr_core-4.0-core-nu
"{D8DAA275-6532-4D57-AD01-66990171796A}" = crystalreports.dataaccess.driver.sybase-4.0-en-32
"{DA126147-DE91-408B-9B6A-9BAA9DD6BA59}" = repoaccess.container_plugins-4.0-core-32
"{DB1A4610-11D4-42E3-8454-CD80A8EF08E8}" = universedesigner.framework-4.0-core-32
"{DB5F1634-1FA4-4B76-BB71-800A020AD21A}" = connectivity.connectionserver.drivers.generic.oledb.config-4.0-core-nu
"{DB9F2A16-E00B-4167-BFEA-7B3CF8F7E663}" = datafederator.boe.dfadmin-4.0-en-32
"{DBD797EF-90EC-40AF-A091-0D9AFC6C6AB1}" = tp.eclipse.equinox-3.4-core-nu
"{DC64DAFA-22BC-44A8-BCBE-7D8FEE6EE24F}" = connectivity.connectionserver.drivers.db2.jdbc-4.0-core-nu
"{DC6EFE44-EE34-4DA5-8A6F-FCBFA69EA471}" = connectivity.connectionserver.drivers.oracle.oci.config-4.0-en-nu
"{DC75EFAC-8605-43CE-8F28-F5CD6F38594F}" = webi.cdzsrv.cdz_inproc-4.0-core-32
"{DCA3678E-257B-4419-B26C-E52D5B6C9CC5}" = repoaccess.repo_proxy.java-4.0-core-nu
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE228C0F-CC41-4FE5-B5EE-517465DACE67}" = connectivity.connectionserver.platform.helpers.cpp-4.0-core-32
"{DE3D03BE-81C7-4968-A93B-A1B51CC8288E}" = webi.richclient.common-4.0-en-32
"{DEA721A0-FF03-4522-B49C-6248740EEE42}" = crystalreports.dataaccess.share-4.0-en-32
"{DEB2111C-B35F-4519-ADD7-CF2734040909}" = tp.ibm.icu.cpp-3.0.1-core-32
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{DF52F366-8E12-4A4D-ACD6-FB37C44B3C91}" = universedesigner.sessmgr-4.0-core-32
"{DF537A4A-FC56-466D-B89D-B27DBCDB8909}" = platform.sdk.boe.dotnet.core-4.0-core-32
"{DFD95182-A3C2-4A1B-9253-B44BCF40079D}" = migration.conversion.ct-4.0-core-32
"{DFE96861-1C02-4EB4-994E-85AC888A21CA}" = connectivity.foundation.java-4.0-core-nu
"{E037DEBA-4DA6-4401-B0C6-95BA2E9528CB}" = tp.threedgraphics.pgsdk.cpp.chartsupport-2.50.16.busobj.1-core-nu
"{E070BD4E-CE16-4BE2-BED1-78CBFFED9A29}" = webi.cdp.cdsframework_ui-4.0-core-nu
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1907352-E402-4A77-97E1-29AF957358CF}" = tp.threedgraphics.pgsdk.cpp.runtime-2.50.16.busobj.1-en-32
"{E202A749-B50C-4465-8D6D-7F2B41347E90}" = dsl.informationdesigntool.exe-4.0-core-32
"{E207BD23-8B4D-46A2-BBBF-849D3C815041}" = crystalreports.webreporting.common-4.0-en-nu
"{E25C4D03-2048-42F4-A5DC-5AD7DD2622D0}" = foundation.javalibs-4.0-core-nu
"{E2AB4259-123E-43F5-9DE7-98F8FD22872E}" = crystalreports.dataaccess.driver.informix-4.0-en-32
"{E2C039AC-797A-49ED-90DD-3620E670A6EC}" = repoaccess.cdztools.jshell-4.0-core-nu
"{E2F50BC6-0BDA-4E8E-B1B8-8368655BBBF2}" = tp.pervasive.db.btrieve-3.0-core-32
"{E372A7BE-6DFB-4FF3-8935-AADE594A6D03}" = crystalreports.dataaccess.driver.fielddef-4.0-en-32
"{E3CD7222-9E9A-41EC-8CE0-894D79B49004}" = informationengine.qt.drivers.sybase.ctlib.config-4.0-core-nu
"{E3EBA934-4E2B-4014-999B-5C9307C7E67F}" = foundation.dotnetlibs-4.0-core-32
"{E48047FB-939F-442E-A964-D8452759F684}" = connectivity.connectionserver.plugin.http.cpp-4.0-core-32
"{E488FEE0-CD99-4C67-8DCC-64A75D06DC7B}" = crystalreports.cpp.parameterprompt-4.0-en-32
"{E4EF483C-1089-4F4C-A2D2-B71120A0E870}" = tp.ibm.icu.cpp-4.2.1-core-32
"{E5058C44-2EB2-4144-B1CE-1084D6426AF4}" = universedesigner.sqlboserver-4.0-core-32
"{E5465D4F-3FB9-4D36-9DEB-3CAA5D96A821}" = platform.sdk.boe.java.peoplesoft.plugins_bundle-4.0-core-nu
"{E5ECDC59-967C-4EE3-9B2E-7F7FF6E72C3B}" = webi.richclient-4.0-en-32
"{E61FBA96-F432-4F0E-8533-0BDE3260DAA3}" = connectivity.connectionserver.drivers.neoview.jdbc-4.0-en-nu
"{E686A699-B638-4212-A24D-0A5441EFFE40}" = shared.library.keycode.decoder.cpp-4.0-core-32
"{E71EAC97-C547-4BFD-9733-6B9338B01904}" = informationengine.cube.resource-4.0-core-nu
"{E76B93A3-1163-4691-A2AC-804505E30595}" = xcelsius.boe.sdkplugins.cpp-4.0-core-32
"{E7C9E006-CDB8-445F-ADD0-462AD4D4DB26}" = tp.apache.ant-1.7.0-core-nu
"{E7F3D1C3-10FF-4173-AD49-9A7A053123ED}" = crystalreports.boe.sdkplugins.java-4.0-en-nu
"{E88F0CED-FD45-415D-86EA-CEBE787E278E}" = informationengine.qt.drivers.teradata.odbc.config-4.0-core-nu
"{E8D90FE7-55A9-4C7A-8E25-F52C833CB90A}" = dsl.dsl_clientsdk_light-4.0-core-nu
"{E9D8ACCB-0018-48E7-BF05-90BA27C4282B}" = tp.rsa.crypto-6.3-core-32
"{E9FB1C40-4995-40B9-8862-5CB725B5E7C1}" = olap.oda.tom.java-4.0-core-nu
"{EA7DF75B-57B9-495C-8B64-9F9AA3794E64}" = connectivity.connectionserver.drivers.mssqlsrv.oledbolap.config-4.0-core-32
"{EA8A25D2-EF96-4557-9B4F-81F7E4357E6D}" = tp.sun.classes-1.1-core-nu
"{EAE857DE-DFEA-41C3-9B33-6449D5A9BDBD}" = tools.wstk.java-4.0-core-nu
"{EB1FC21E-5A78-45EB-BE87-9A318F346161}" = setup.engine.sharedregistry-4.0-core-32
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{EC10D725-AC4D-4F2B-BB29-31B4BCB02642}" = platform.library.common.authentication.sap-4.0-core-32
"{EC44405E-0F23-4E8F-A19D-2A67C04027DE}" = connectivity.connectionserver.drivers.sybase.jdbc-4.0-en-nu
"{EC48E92B-0FCE-488F-BD46-E1544F97B253}" = webi.cdp.cdsframework_driver-4.0-en-32
"{EC6903FF-7296-4749-8E38-03757717C02F}" = product.shared.langpackreg-4.0-core-nu
"{EC78F10C-131A-4510-AA14-F47483095D6A}" = crystalreports.crystalcommon.cpp.crjavaconfig-4.0-core-nu
"{ED578083-0F43-4A93-8E59-B125779E114E}" = tp.sap.nwrfc-711-core-32
"{ED767D7C-9A82-472C-BE0A-2B5FAB99ACA8}" = webi.cdp.cdsframework_dp-4.0-core-32
"{ED8A3E6A-386E-47F8-AF32-8BC6C3F486D0}" = crystalreports.dataaccess.driver.cdo-4.0-core-32
"{EE359EE2-732E-431F-A839-BBD87127536D}" = dsl.dsl_engine.binfiles-4.0-core-nu
"{EEB201EA-10F1-4B50-8EEA-0A9353A4F4AD}" = tp.sap.jco.java-3.0.5-core-nu
"{EEE8F470-6AB1-4A44-8BD4-2DDB620BC005}" = crystalreports.dataaccess.driver.act-4.0-en-32
"{EF090511-AA26-4295-A8D2-8F314F82092F}" = connectivity.connectionserver.drivers.neoview.odbc-4.0-core-32
"{F00087F3-5608-458A-BFFD-5B80605CECBE}" = webi.cdp.cdsframework_driver-4.0-core-32
"{F01EBEA7-3E4D-4A3C-BC34-92446D448360}" = crystalreports.dataaccess.driver.access-4.0-core-32
"{F0603F24-7765-4143-892A-C5E1B91CE2D4}" = migration.busobj.dpvba-4.0-core-32
"{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = UserGuide
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0E314AB-1939-4797-BD1C-CD17E2C74111}" = connectivity.connectionserver.drivers.progress.jdbc-4.0-core-nu
"{F0E3AD40-2BBD-4360-9C76-B9AC9A5886EA}" = Intel® Processor Graphics
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1A093A6-8418-49BD-B2A5-BDD5F0E2ED1A}" = foundation.javalibs.bundle-4.0-core-nu
"{F1B264DB-1AB1-4BCD-9BB9-10CC68C821A9}" = connectivity.connectionserver.drivers.hsqldb.jdbc-4.0-core-nu
"{F2974CA4-CC2C-499F-ABBA-92887D5074D7}" = olap.oda.pcm.java-4.0-core-nu
"{F3530201-CCC3-4B5D-A39C-C52CEA16A2A4}" = connectivity.connectionserver.drivers.oracle.oci.config-4.0-core-nu
"{F387839F-9E17-4DB5-8898-847EAFD373F9}" = isapi3_files
"{F3FCECCE-34F5-4CC9-8CA6-F58B9350BE33}" = connectivity.connectionserver.client.corba.cpp-4.0-core-32
"{F40AB5C1-F50D-463E-BC0B-E37DDC8A716C}" = tp.jdom-1.1.1-core-nu
"{F43A4928-382D-441C-8D61-C429544071B3}" = connectivity.connectionserver.drivers.openaccess.odbc-4.0-core-32
"{F445F4AC-67AF-4DFD-AA7B-B972C31F8758}" = crystalreports.dataaccess.share-4.0-core-32
"{F4F0DF43-8EFC-4176-A882-478CB52AEF93}" = connectivity.connectionserver.tools.cscheck.config-4.0-core-nu
"{F53719B0-5778-4BA1-9C4B-76D6D9D68D8E}" = connectivity.connectionserver.drivers.maxdb.jdbc-4.0-core-nu
"{F55FCB83-37BC-44AF-BF43-CB864A96184B}" = psepmsecuritybridge-4.0-core-32
"{F65A3DCE-9519-4E9F-86C5-7742F99150DE}" = platform.sdk.boe.com-4.0-core-32
"{F6B24CE9-B2EA-47CD-8F53-525B92C2D829}" = connectivity.connectionserver.drivers.greenplum.jdbc-4.0-en-nu
"{F7512A38-E302-40FF-8C72-20B16F770732}" = olap.oda.ea.java-4.0-core-nu
"{F7ADA33D-4E87-46C1-AD90-7EE8CA5F6D67}" = crystalreports.dataaccess.driver.universe-4.0-core-32
"{F7ED6DFF-3093-4D47-8E4F-AA12A3DB9199}" = crystalreports.dataaccess.driver.jdbc-4.0-core-32
"{F86ECFE6-6CBB-4E04-A413-27CF5EE8E34C}" = platform.sdk.boe.java.pbds_full-4.0-core-nu
"{F8A87587-76B6-426D-95CC-0506681F85CB}" = tp.salesforce-9.0-core-nu
"{F8A9085D-4C7A-41a9-8A77-C8998A96C421}" = Intel® Control Center
"{F949AA24-1819-4331-970D-EB7C0DC5A0A1}" = informationengine.qt.drivers.hsqldb.jdbc-4.0-core-nu
"{F953FB3F-6DA0-470D-9CFD-7C1095CC205A}" = tp.sun.jdk.jre-1.6-core-32
"{F95DB2A3-DFB8-4E32-A1D5-57D6CA3EC965}" = universedesigner.sqlboserver.reposit-4.0-core-32
"{F9736D08-CB51-4320-83D8-212B88B85978}" = connectivity.connectionserver.drivers.personalfiles.odbc-4.0-core-32
"{F991A978-C93D-4603-88B2-FE41B5C57020}" = connectivity.connectionserver.core.helpers.cpp-4.0-core-32
"{F993656B-DB66-4C64-B216-679F95CF432E}" = crystalreports.webreporting.common-4.0-core-nu
"{FA1157A7-1977-4EBA-BBB3-182C00DBF846}" = crystalreports.cpp.runtimeshare-4.0-en-32
"{FA35A0C4-9094-4CA4-86AF-7082EBB21DF8}" = repoaccess.cdztools-4.0-en-32
"{FA768A4D-79D1-4E0C-9098-F4397F345580}" = connectivity.connectionserver.drivers.essbase.olap.config-4.0-core-32
"{FAA7F8FF-3C05-4A61-8F14-D8A6E9ED6623}" = ooVoo
"{FAC5E86A-B593-4141-A9F3-0FB572E647D2}" = dsl.dsl_platformactions-4.0-core-nu
"{FB4898C7-F957-44B3-805B-6FB44F34850E}" = tp.apache.xalan.cpp-1.10.0-core-32
"{FBB0B1A4-40B2-422A-B775-9DA613E8F40F}" = foundation.tracelog.cpp-4.0-core-32
"{FBF2D8EA-B019-4A8A-AD56-5BCCD2C2DB11}" = crystalreports.crystalcommon.cpp.crlogger-4.0-core-32
"{FC1A589B-C9FA-41F2-A627-650DF994EE50}" = connectivity.connectionserver.client.cpp.java-4.0-core-nu
"{FC9ECCBF-A263-4205-8F95-222C2DBFAA12}" = tp.sap.rfcsdku-70-core-32
"{FD6F6C56-E172-4685-8868-DA72DF47090F}" = foundation.bcm.java.bundle-4.0-core-nu
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"{FF2A8008-A17C-40E1-BB63-9E206808D509}" = tp.xpp3.bundle-1.1.3.8-core-nu
"{FF9D17F1-B66E-41BE-A5DB-2CF7908ADC52}" = tp.apache.rampart-1.3-core-nu
"Adobe Flash Player Plugin" = Adobe Flash Player 10 Plugin
"Adobe Photoshop 7.0" = Adobe Photoshop 7.0
"Dll-Files.com Fixer_is1" = Dll-Files.com Fixer
"ENTERPRISE" = Microsoft Office Enterprise 2007
"Google Chrome" = Google Chrome
"InstallShield_{01FB4998-33C4-4431-85ED-079E3EEFE75D}" = Lenovo YouCam
"InstallShield_{46F4D124-20E5-4D12-BE52-EC177A7A4B42}" = Lenovo OneKey Recovery
"InstallShield_{B2164CCB-C002-4B80-8550-7535D80DF237}" = Lenovo DirectShare
"InstallShield_{D0956C11-0F60-43FE-99AD-524E833471BB}" = Energy Management
"InstallShield_{D4B060B9-AD4A-4152-9D99-28B93C615AFE}" = Onekey Theater
"InstallShield_{F07C2CF8-4C53-4EC3-8162-A6221E36EB88}" = UserGuide
"Lenovo Games Console" = Lenovo Games Console
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.62.0.1300
"MSC" = McAfee AntiVirus Plus
"PhotoScape" = PhotoScape
"uTorrent" = µTorrent
"VeriFace" = VeriFace
"VLC media player" = VLC media player 1.1.11
"WinLiveSuite" = Windows Live Essentials
"WinRAR archiver" = WinRAR archiver
"WordWeb" = WordWeb

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 8/13/2012 2:30:17 AM | Computer Name = i5-PC | Source = MsiInstaller | ID = 11904
Description =

Error - 8/13/2012 2:46:52 AM | Computer Name = i5-PC | Source = System Restore | ID = 8193
Description =

Error - 8/13/2012 2:47:05 AM | Computer Name = i5-PC | Source = System Restore | ID = 8193
Description =

Error - 8/13/2012 2:54:02 AM | Computer Name = i5-PC | Source = Application Error | ID = 1000
Description = Faulting application name: Xcelsius.exe, version: 14.0.0.760, time
stamp: 0x4d68a492 Faulting module name: Xcelsius.exe, version: 14.0.0.760, time
stamp: 0x4d68a492 Exception code: 0xc0000005 Fault offset: 0x0002a31c Faulting process
id: 0x1a18 Faulting application start time: 0x01cd791dff0bfd7c Faulting application
path: C:\Program Files (x86)\SAP BusinessObjects\Xcelsius 4.0\Xcelsius.exe Faulting
module path: C:\Program Files (x86)\SAP BusinessObjects\Xcelsius 4.0\Xcelsius.exe
Report
Id: a9f677e6-e513-11e1-a50b-c0f8dab687ec

Error - 8/13/2012 7:09:42 AM | Computer Name = i5-PC | Source = McLogEvent | ID = 5051
Description = A thread in process C:\Program Files\Common Files\McAfee\SystemCore\mcshield.exe
took longer than 90000 ms to complete a request. The process will be terminated.
Thread
id : 2324 (0x914) Thread address : 0x0000000073040738 Thread message : Build VSCORE.14.4.0.387
/ 5400.1158 Object being scanned = \Device\HarddiskVolume1\windows\System32\svchost.exe

by C:\windows\system32\services.exe 7011(118748)(0) 93(118748)(0) 5(118748)(0)
4(0)(0) 4(0)(0) 7200(0)(0) 7595(0)(0) 7005(0)(0)

Error - 8/13/2012 8:27:59 AM | Computer Name = i5-PC | Source = System Restore | ID = 8193
Description =

Error - 8/13/2012 8:38:09 AM | Computer Name = i5-PC | Source = Windows Search Service | ID = 3007
Description =

Error - 8/14/2012 3:32:55 AM | Computer Name = i5-PC | Source = WinMgmt | ID = 10
Description =

Error - 8/14/2012 3:42:59 AM | Computer Name = i5-PC | Source = System Restore | ID = 8193
Description =

Error - 8/14/2012 12:42:16 PM | Computer Name = i5-PC | Source = WinMgmt | ID = 10
Description =

[ System Events ]
Error - 8/13/2012 7:12:21 AM | Computer Name = i5-PC | Source = Service Control Manager | ID = 7034
Description = The McAfee Scanner service terminated unexpectedly. It has done this
1 time(s).

Error - 8/13/2012 8:27:35 AM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =

Error - 8/14/2012 2:28:47 PM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =

Error - 8/14/2012 10:27:48 PM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =

Error - 8/15/2012 2:47:12 AM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =

Error - 8/15/2012 2:37:06 PM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =

Error - 8/15/2012 2:37:11 PM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =

Error - 8/22/2012 3:27:16 AM | Computer Name = i5-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 8/22/2012 3:27:18 AM | Computer Name = i5-PC | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk1\DR1.

Error - 8/22/2012 8:17:38 AM | Computer Name = i5-PC | Source = DCOM | ID = 10010
Description =


< End of report >


The ADWCleaner log is given below

# AdwCleaner v1.801 - Logfile created 08/24/2012 at 16:06:47
# Updated 14/08/2012 by Xplode
# Operating system : Windows 7 Home Premium Service Pack 1 (64 bits)
# User : i5 - I5-PC
# Boot Mode : Normal
# Running from : C:\Users\i5\Downloads\adwcleaner.exe
# Option [Delete]


***** [Services] *****


***** [Files / Folders] *****

Folder Deleted : C:\Users\i5\AppData\Roaming\Babylon
Folder Deleted : C:\Users\i5\AppData\Roaming\Media Finder
Folder Deleted : C:\Users\i5\AppData\Roaming\Mozilla\Extensions\{ec8030f7-c20a-464f-9b0e-13a3a9e97384}\[email protected]
Folder Deleted : C:\ProgramData\Babylon
Folder Deleted : C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Finder
Folder Deleted : C:\ProgramData\Partner
File Deleted : C:\user.js

***** [Registry] *****

Key Deleted : HKCU\Software\MediaFinder
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\MenuExt\Download with &Media Finder
Key Deleted : HKLM\SOFTWARE\Babylon
Key Deleted : HKLM\SOFTWARE\BabylonToolbar
Key Deleted : HKLM\SOFTWARE\Classes\AppID\kt_bho_dll.dll
Key Deleted : HKLM\SOFTWARE\Classes\kt_bho.KettleBho
Key Deleted : HKLM\SOFTWARE\Classes\kt_bho.KettleBho.1
Key Deleted : HKLM\SOFTWARE\Classes\MF
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\dednnpigldgdbpgcdpfppmlcnnbjciel
Key Deleted : HKLM\SOFTWARE\Google\Chrome\Extensions\lpmkgpnbiojfaoklbkpfneikocaobfai
Value Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Run [Media Finder]

***** [Registre - GUID] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\{28A88B70-D874-4f73-BBBA-9B2B222FB7D6}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{86676E13-D6D8-4652-9FCF-F2047F1FB000}
Key Deleted : HKCU\Software\Microsoft\Internet Explorer\SearchScopes\{0ECDF796-C2DC-4D79-A620-CCE0C0A66CC9}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
[x64] Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}
[x64] Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{83FF80F4-8C74-4b80-B5BA-C8DDD434E5C4}

***** [Internet Browsers] *****

-\\ Internet Explorer v8.0.7601.17514

[OK] Registry is clean.

-\\ Google Chrome v21.0.1180.83

File : C:\Users\i5\AppData\Local\Google\Chrome\User Data\Default\Preferences

Deleted : "description": "The plug-in from the General-Crawler.com website which lets the users[...]
Deleted : "homepage_url": "hxxp://www.general-crawler.com",
Deleted : "name": "General Crawler",
Deleted : "update_url": "hxxp://1.update.general-crawler.com/updates/update_chrome.xml",

*************************

AdwCleaner[S1].txt - [3067 octets] - [24/08/2012 16:06:47]

########## EOF - C:\AdwCleaner[S1].txt - [3195 octets] ##########
  • 0

#3
ali.B

ali.B

    Trusted Helper

  • Malware Removal
  • 3,086 posts
I have merged your topics, please do not start more than one topic at once. I will be post shorty instructions, do not run any tool unless instructed to do so.
  • 1

#4
ali.B

ali.B

    Trusted Helper

  • Malware Removal
  • 3,086 posts
hi :welcome:

  • Download RogueKiller and save it on your desktop.
  • Quit all programs
  • Start RogueKiller.exe.
  • Wait until Prescan has finished ...
  • Click on Scan
Posted Image
  • Wait for the end of the scan.
  • The report has been created on the desktop.
  • Click on the Delete button.
Posted Image
  • The report has been created on the desktop.

  • Next click on the ShortcutsFix
    Posted Image
  • The report has been created on the desktop.

Please post: All RKreport.txt text files located on your desktop.

THEN[/B[

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    Posted Image
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    %SYSTEMDRIVE%\*.exe
    /md5start
    services.*
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    qmgr.dll
    /md5stop
    HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS /s
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and [b]Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

  • 0

#5
dreamfalcon21

dreamfalcon21

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Please find below, the 3 RK logs. Will be posting the OTL logs soon as they are ready (I understood you to mean I post RK logs first and then run the OTL logs while you peruse them).


RogueKiller V7.6.6 [08/10/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo...13-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: i5 [Admin rights]
Mode: Scan -- Date: 08/24/2012 18:09:49

¤¤¤ Bad processes: 1 ¤¤¤
[SUSP PATH] FacebookMessenger.exe -- C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe -> KILLED [TermProc]

¤¤¤ Registry Entries: 3 ¤¤¤
[SUSP PATH] Facebook Messenger.lnk @i5 : C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> FOUND
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> FOUND

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 install.iminent.com # Hosts Anti-Adware / PUPs
127.0.0.1 install.blamcity.com # Hosts Anti-Adware / PUPs
127.0.0.1 b.juiceknowledge.com # Hosts Anti-Adware / PUPs
127.0.0.1 a.juiceknowledge.com # Hosts Anti-Adware / PUPs
127.0.0.1 1f1.fr # Hosts Anti-Adware / PUPs
127.0.0.1 2010-fr.com # Hosts Anti-Adware / PUPs
127.0.0.1 24h00business.com # Hosts Anti-Adware / PUPs
127.0.0.1 4990usd.com # Hosts Anti-Adware / PUPs
127.0.0.1 4xp.com # Hosts Anti-Adware / PUPs
127.0.0.1 adomiciletravail.googlepages.com # Hosts Anti-Adware / PUPs
127.0.0.1 adwarealert.com # Hosts Anti-Adware / PUPs
127.0.0.1 affilibot.eu # Hosts Anti-Adware / PUPs
127.0.0.1 aformula.biz # Hosts Anti-Adware / PUPs
127.0.0.1 antivirusgratuit.vg # Hosts Anti-Adware / PUPs
127.0.0.1 argent-domicile.eu # Hosts Anti-Adware / PUPs
127.0.0.1 argent-travail-domicile.fr # Hosts Anti-Adware / PUPs
127.0.0.1 argent-vital.com # Hosts Anti-Adware / PUPs
127.0.0.1 argentastuce.com # Hosts Anti-Adware / PUPs
127.0.0.1 ascentive.com # Hosts Anti-Adware / PUPs
127.0.0.1 augmentersesrevenus.pyclie.com # Hosts Anti-Adware / PUPs
[...]


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: TOSHIBA MK6465GSX +++++
--- User ---
[MBR] 866fe985fe8b1f53e8ae2209ebae403b
[BSP] 66511a3e47de54ef09c1abcc514822d0 : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 199996 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409593240 | Size: 395373 Mo
2 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 1219319808 | Size: 15109 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[1].txt >>
RKreport[1].txt



RogueKiller V7.6.6 [08/10/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo...13-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: i5 [Admin rights]
Mode: Remove -- Date: 08/24/2012 18:11:47

¤¤¤ Bad processes: 1 ¤¤¤
[SUSP PATH] FacebookMessenger.exe -- C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe -> KILLED [TermProc]

¤¤¤ Registry Entries: 3 ¤¤¤
[SUSP PATH] Facebook Messenger.lnk @i5 : C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe -> DELETED
[HJ] HKLM\[...]\NewStartPanel : {59031a47-3f72-44a7-89c5-5595fe6b30ee} (1) -> REPLACED (0)
[HJ] HKLM\[...]\NewStartPanel : {20D04FE0-3AEA-1069-A2D8-08002B30309D} (1) -> REPLACED (0)

¤¤¤ Particular Files / Folders: ¤¤¤

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ Infection : ¤¤¤

¤¤¤ HOSTS File: ¤¤¤
127.0.0.1 install.iminent.com # Hosts Anti-Adware / PUPs
127.0.0.1 install.blamcity.com # Hosts Anti-Adware / PUPs
127.0.0.1 b.juiceknowledge.com # Hosts Anti-Adware / PUPs
127.0.0.1 a.juiceknowledge.com # Hosts Anti-Adware / PUPs
127.0.0.1 1f1.fr # Hosts Anti-Adware / PUPs
127.0.0.1 2010-fr.com # Hosts Anti-Adware / PUPs
127.0.0.1 24h00business.com # Hosts Anti-Adware / PUPs
127.0.0.1 4990usd.com # Hosts Anti-Adware / PUPs
127.0.0.1 4xp.com # Hosts Anti-Adware / PUPs
127.0.0.1 adomiciletravail.googlepages.com # Hosts Anti-Adware / PUPs
127.0.0.1 adwarealert.com # Hosts Anti-Adware / PUPs
127.0.0.1 affilibot.eu # Hosts Anti-Adware / PUPs
127.0.0.1 aformula.biz # Hosts Anti-Adware / PUPs
127.0.0.1 antivirusgratuit.vg # Hosts Anti-Adware / PUPs
127.0.0.1 argent-domicile.eu # Hosts Anti-Adware / PUPs
127.0.0.1 argent-travail-domicile.fr # Hosts Anti-Adware / PUPs
127.0.0.1 argent-vital.com # Hosts Anti-Adware / PUPs
127.0.0.1 argentastuce.com # Hosts Anti-Adware / PUPs
127.0.0.1 ascentive.com # Hosts Anti-Adware / PUPs
127.0.0.1 augmentersesrevenus.pyclie.com # Hosts Anti-Adware / PUPs
[...]


¤¤¤ MBR Check: ¤¤¤

+++++ PhysicalDrive0: TOSHIBA MK6465GSX +++++
--- User ---
[MBR] 866fe985fe8b1f53e8ae2209ebae403b
[BSP] 66511a3e47de54ef09c1abcc514822d0 : Windows 7 MBR Code
Partition table:
0 - [ACTIVE] NTFS (0x07) [VISIBLE] Offset (sectors): 63 | Size: 199996 Mo
1 - [XXXXXX] NTFS (0x07) [VISIBLE] Offset (sectors): 409593240 | Size: 395373 Mo
2 - [XXXXXX] COMPAQ (0x12) [VISIBLE] Offset (sectors): 1219319808 | Size: 15109 Mo
User = LL1 ... OK!
User = LL2 ... OK!

Finished : << RKreport[2].txt >>
RKreport[1].txt ; RKreport[2].txt



RogueKiller V7.6.6 [08/10/2012] by Tigzy
mail: tigzyRK<at>gmail<dot>com
Feedback: http://www.geekstogo...13-roguekiller/
Blog: http://tigzyrk.blogspot.com

Operating System: Windows 7 (6.1.7601 Service Pack 1) 64 bits version
Started in : Normal mode
User: i5 [Admin rights]
Mode: Shortcuts HJfix -- Date: 08/24/2012 18:15:57

¤¤¤ Bad processes: 1 ¤¤¤
[SUSP PATH] FacebookMessenger.exe -- C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\FacebookMessenger.exe -> KILLED [TermProc]

¤¤¤ Driver: [NOT LOADED] ¤¤¤

¤¤¤ File attributes restored: ¤¤¤
Desktop: Success 1 / Fail 0
Quick launch: Success 1 / Fail 0
Programs: Success 7 / Fail 0
Start menu: Success 1 / Fail 0
User folder: Success 75 / Fail 0
My documents: Success 0 / Fail 0
My favorites: Success 0 / Fail 0
My pictures: Success 0 / Fail 0
My music: Success 0 / Fail 0
My videos: Success 0 / Fail 0
Local drives: Success 69 / Fail 0
Backup: [NOT FOUND]

Drives:
[C:] \Device\HarddiskVolume1 -- 0x3 --> Restored
[D:] \Device\HarddiskVolume2 -- 0x3 --> Restored
[F:] \Device\CdRom0 -- 0x5 --> Skipped

¤¤¤ Infection : ¤¤¤

Finished : << RKreport[3].txt >>
RKreport[1].txt ; RKreport[2].txt ; RKreport[3].txt
  • 0

#6
dreamfalcon21

dreamfalcon21

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Here is the OTL log... Extras log did not open

OTL logfile created on: 8/24/2012 6:21:34 PM - Run 2
OTL by OldTimer - Version 3.2.58.1 Folder = C:\Users\i5\Desktop
64bit- Home Premium Edition Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 8.0.7601.17514)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

2.92 Gb Total Physical Memory | 1.75 Gb Available Physical Memory | 60.04% Memory free
5.83 Gb Paging File | 3.90 Gb Available in Paging File | 66.82% Paging File free
Paging file location(s): d:\pagefile.sys 0 0 [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 195.31 Gb Total Space | 172.08 Gb Free Space | 88.11% Space Free | Partition Type: NTFS
Drive D: | 386.11 Gb Total Space | 367.06 Gb Free Space | 95.07% Space Free | Partition Type: NTFS

Computer Name: I5-PC | User Name: i5 | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/08/24 17:51:19 | 000,302,961 | ---- | M] () -- C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
PRC - [2012/08/24 16:34:30 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\i5\Desktop\OTL.exe
PRC - [2012/08/18 03:58:57 | 001,229,848 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe
PRC - [2012/07/03 13:46:44 | 000,462,920 | ---- | M] (Malwarebytes Corporation) -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe
PRC - [2012/04/21 15:11:09 | 000,077,064 | ---- | M] () -- C:\Program Files (x86)\WordWeb\wweb32.exe
PRC - [2012/04/04 11:23:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2011/06/09 04:22:52 | 000,100,256 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
PRC - [2011/06/09 04:19:55 | 000,329,056 | ---- | M] (Lenovo) -- C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe
PRC - [2011/02/15 17:56:42 | 000,013,600 | ---- | M] (Broadcom Corporation.) -- C:\Program Files\Lenovo\Bluetooth Software\BluetoothHeadsetProxy.exe
PRC - [2010/12/20 16:00:38 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2010/12/20 16:00:36 | 000,325,656 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/12/05 07:09:24 | 000,136,488 | ---- | M] (CyberLink) -- C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe


========== Modules (No Company Name) ==========

MOD - [2012/08/24 17:51:19 | 000,302,961 | ---- | M] () -- C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe
MOD - [2012/08/18 03:58:55 | 000,442,392 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\ppgooglenaclpluginchrome.dll
MOD - [2012/08/18 03:58:54 | 012,236,824 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\PepperFlash\pepflashplayer.dll
MOD - [2012/08/18 03:58:52 | 003,997,720 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\pdf.dll
MOD - [2012/08/18 03:57:23 | 000,144,424 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\avutil-51.dll
MOD - [2012/08/18 03:57:22 | 000,266,792 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\avformat-54.dll
MOD - [2012/08/18 03:57:21 | 002,480,680 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\avcodec-54.dll
MOD - [2012/07/15 12:27:53 | 002,216,480 | ---- | M] () -- C:\Windows\SysWOW64\wweb32.dll
MOD - [2012/07/15 12:25:02 | 000,022,800 | ---- | M] () -- C:\Program Files (x86)\WordWeb\WUCNT.dll
MOD - [2012/04/21 15:11:09 | 000,077,064 | ---- | M] () -- C:\Program Files (x86)\WordWeb\wweb32.exe
MOD - [2011/06/09 04:22:52 | 000,100,256 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeySupport.exe
MOD - [2011/06/09 04:19:55 | 000,013,664 | ---- | M] () -- C:\Program Files (x86)\Lenovo\VeriFace\ChooseLang.dll
MOD - [2010/11/11 16:09:46 | 000,133,024 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\WindowsApiHookDll32.dll
MOD - [2010/11/11 16:08:44 | 000,161,696 | ---- | M] () -- C:\Program Files (x86)\Lenovo\Onekey Theater\ActiveDetect32.dll


========== Win32 Services (SafeList) ==========

SRV:64bit: - [2012/05/25 17:13:54 | 000,162,224 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Windows\SysNative\mfevtps.exe -- (mfevtp)
SRV:64bit: - [2012/05/25 16:59:02 | 000,210,616 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mfefire.exe -- (mfefire)
SRV:64bit: - [2012/05/25 16:58:32 | 000,199,304 | ---- | M] () [Auto | Running] -- C:\Program Files\Common Files\McAfee\SystemCore\\mcshield.exe -- (McShield)
SRV:64bit: - [2012/04/19 08:22:48 | 000,502,032 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- C:\Program Files\mcafee\virusscan\mcods.exe -- (McODS)
SRV:64bit: - [2012/03/26 18:49:56 | 000,291,696 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV:64bit: - [2012/03/26 18:49:56 | 000,012,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV:64bit: - [2011/02/15 17:56:42 | 000,956,192 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- C:\Program Files\Lenovo\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McProxy)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Disabled | Stopped] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McOobeSv)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNASvc)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (McNaiAnn)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\mcafee\McSvcHost\McSvHost.exe -- (mcmscsvc)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McMPFSvc)
SRV:64bit: - [2011/01/27 18:28:20 | 000,249,936 | ---- | M] (McAfee, Inc.) [Auto | Running] -- C:\Program Files\Common Files\McAfee\McSvcHost\McSvHost.exe -- (McAfee SiteAdvisor Service)
SRV:64bit: - [2010/09/30 20:35:42 | 000,311,296 | ---- | M] (Realtek Semiconductor Corp.) [Auto | Running] -- C:\Program Files\Realtek\RtLED\RtLEDService.exe -- (RtLedService)
SRV:64bit: - [2010/09/22 23:40:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2010/08/09 20:11:46 | 000,220,528 | ---- | M] (McAfee, Inc.) [On_Demand | Stopped] -- c:\Program Files\mcafee\msc\McAWFwk.exe -- (McAWFwk)
SRV:64bit: - [2009/07/14 07:11:27 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2012/07/03 13:46:44 | 000,655,944 | ---- | M] (Malwarebytes Corporation) [Auto | Running] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe -- (MBAMService)
SRV - [2012/04/04 11:23:50 | 000,063,928 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2010/12/20 16:00:38 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2010/12/20 16:00:36 | 000,325,656 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/03/18 13:16:28 | 000,130,384 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2009/06/11 02:53:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2012/07/03 13:46:44 | 000,024,904 | ---- | M] (Malwarebytes Corporation) [File_System | On_Demand | Running] -- C:\Windows\SysNative\drivers\mbam.sys -- (MBAMProtector)
DRV:64bit: - [2012/03/20 20:44:12 | 000,098,688 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\NisDrvWFP.sys -- (NisDrv)
DRV:64bit: - [2012/03/01 12:16:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2012/02/22 13:29:46 | 000,647,208 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfehidk.sys -- (mfehidk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,487,296 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfefirek.sys -- (mfefirek)
DRV:64bit: - [2012/02/22 13:29:46 | 000,289,664 | ---- | M] (McAfee, Inc.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\mfewfpk.sys -- (mfewfpk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,229,528 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeavfk.sys -- (mfeavfk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,160,792 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\mfeapfk.sys -- (mfeapfk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,075,936 | ---- | M] (McAfee, Inc.) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\mfenlfk.sys -- (mfenlfk)
DRV:64bit: - [2012/02/22 13:29:46 | 000,065,264 | ---- | M] (McAfee, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\cfwids.sys -- (cfwids)
DRV:64bit: - [2011/06/09 04:34:04 | 000,039,008 | ---- | M] (Lenovo.) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\LhdX64.sys -- (LHDmgr)
DRV:64bit: - [2011/06/09 04:34:02 | 000,029,792 | ---- | M] (Lenovo Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\AcpiVpc.sys -- (ACPIVPC)
DRV:64bit: - [2011/06/09 04:21:35 | 000,057,952 | ---- | M] (Lenovo) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\fbfmon.sys -- (fbfmon)
DRV:64bit: - [2011/06/09 04:21:35 | 000,013,408 | ---- | M] (Lenovo) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\BPntDrv.sys -- (BPntDrv)
DRV:64bit: - [2011/03/25 15:47:48 | 012,262,336 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2011/03/11 12:11:12 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/03/11 12:11:12 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/02/18 13:41:54 | 000,439,320 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/02/15 12:15:16 | 000,349,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (BTWAMPFL)
DRV:64bit: - [2011/02/15 12:15:12 | 000,138,280 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2011/02/15 12:15:12 | 000,107,560 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2011/02/15 12:15:12 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2011/02/15 12:15:12 | 000,021,416 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010/12/22 17:49:58 | 001,407,024 | ---- | M] (Synaptics Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SynTP.sys -- (SynTP)
DRV:64bit: - [2010/12/05 07:09:44 | 000,031,088 | ---- | M] (CyberLink Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\clwvd.sys -- (clwvd)
DRV:64bit: - [2010/11/30 12:10:04 | 000,307,304 | ---- | M] (Realtek Semiconductor Corp.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\rtsuvstor.sys -- (RSUSBVSTOR)
DRV:64bit: - [2010/11/21 08:54:33 | 000,059,392 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2010/11/21 08:53:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/11/21 08:53:47 | 000,031,232 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2010/10/28 15:46:24 | 004,716,608 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2010/10/19 14:04:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010/10/14 22:58:16 | 000,317,440 | ---- | M] (Intel® Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\IntcDAud.sys -- (IntcDAud)
DRV:64bit: - [2010/05/31 09:16:50 | 000,333,928 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2009/07/21 19:50:06 | 000,121,840 | ---- | M] (CyberLink) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\wsvd.sys -- (wsvd)
DRV:64bit: - [2009/07/14 07:22:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/14 07:18:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/14 07:15:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/11 02:04:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/11 02:04:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/11 02:04:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/11 02:01:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV - [2009/07/14 06:49:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE:64bit: - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com/ [binary data]
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://lenovo.msn.com
IE - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.google.co...=LENN&bmod=LENN
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Secondary Start Pages = http://www.lenovo.com [binary data]
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://isearch.claro...000c0f8daa6d7b3
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\URLSearchHook: {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\SearchScopes\{67A2568C-7A0A-4EED-AECC-B5405DE63B64}: "URL" = http://www.google.co...1I7LENN_enIN496
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7LENN_enIN496
IE - HKU\S-1-5-21-676971024-488182067-3021444819-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.5.0: C:\windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.5.0: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\PROGRA~1\mcafee\msc\NPMCSN~1.DLL ()
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/MSC,version=10: c:\progra~2\mcafee\msc\npmcsn~1.dll ()
FF - HKLM\Software\MozillaPlugins\@mcafee.com/SAFFPlugin: C:\Program Files (x86)\McAfee\SiteAdvisor\npmcffplg32.dll (McAfee, Inc.)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: C:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\facebook.com/fbDesktopPlugin: C:\Users\i5\AppData\Local\Facebook\Messenger\2.1.4590.0\npFbDesktopPlugin.dll (Facebook, Inc.)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{D19CA586-DD6C-4a0a-96F8-14644F340D60}: C:\Program Files (x86)\Common Files\McAfee\SystemCore [2012/08/10 08:27:26 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{4ED1F68A-5463-4931-9384-8FFF5ED91D92}: C:\Program Files (x86)\McAfee\SiteAdvisor [2012/08/23 19:25:35 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\WordWeb\WCaptureMoz [2012/08/16 12:53:51 | 000,000,000 | ---D | M]

[2012/08/24 14:34:12 | 000,000,000 | ---D | M] (No name found) -- C:\Users\i5\AppData\Roaming\Mozilla\Extensions
[2012/08/24 14:31:14 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - homepage: http://isearch.claro...000c0f8daa6d7b3
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms}
CHR - homepage: http://isearch.claro...000c0f8daa6d7b3
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.75\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\gcswf32.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\windows\SysWOW64\Macromed\Flash\NPSWF32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\21.0.1180.83\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Silverlight Plug-In (Enabled) = C:\Program Files (x86)\Microsoft Silverlight\4.0.50524.0\npctrl.dll
CHR - plugin: Windows Live\u0099 Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll

O1 HOSTS File: ([2012/08/24 17:51:42 | 000,022,326 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 install.iminent.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 install.blamcity.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 b.juiceknowledge.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 a.juiceknowledge.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 1f1.fr # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 2010-fr.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 24h00business.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 4990usd.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 4xp.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 adomiciletravail.googlepages.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 adwarealert.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 affilibot.eu # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 aformula.biz # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 antivirusgratuit.vg # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 argent-domicile.eu # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 argent-travail-domicile.fr # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 argent-vital.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 argentastuce.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 ascentive.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 augmentersesrevenus.pyclie.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 auto-webcash.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 avigora.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 avs4you.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 bababiz.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 127.0.0.1 badusoft.com # Hosts Anti-Adware / PUPs
O1 - Hosts: 371 more lines...
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\Common Files\mcafee\systemcore\ScriptSn.20120810081925.dll (McAfee, Inc.)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\5.7.7529.1424\swg64.dll (Google Inc.)
O2:64bit: - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (scriptproxy) - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files (x86)\Common Files\mcafee\SystemCore\ScriptSn.20120810081925.dll (McAfee, Inc.)
O2 - BHO: (Google Toolbar Notifier BHO) - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.7.7529.1424\swg.dll (Google Inc.)
O2 - BHO: (McAfee SiteAdvisor BHO) - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (McAfee SiteAdvisor Toolbar) - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-676971024-488182067-3021444819-1000\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [Energy Management] C:\Program Files (x86)\Lenovo\Energy Management\Energy Management.exe (Lenovo (Beijing) Limited)
O4:64bit: - HKLM..\Run: [EnergyUtility] C:\Program Files (x86)\Lenovo\Energy Management\utility.exe (Lenovo(beijing) Limited)
O4:64bit: - HKLM..\Run: [HotKeysCmds] C:\Windows\SysNative\hkcmd.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [IgfxTray] C:\Windows\SysNative\igfxtray.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [Lenovo EE Boot Optimizer] C:\Program Files (x86)\Lenovo\Boot Optimizer\PopWnd.exe (Lenovo)
O4:64bit: - HKLM..\Run: [MSC] C:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4:64bit: - HKLM..\Run: [OnekeyStudio] C:\Program Files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe (Lenovo)
O4:64bit: - HKLM..\Run: [Persistence] C:\Windows\SysNative\igfxpers.exe (Intel Corporation)
O4:64bit: - HKLM..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RAVCpl64.exe (Realtek Semiconductor)
O4:64bit: - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [HOSTS Anti-Adware_PUPs] C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe ()
O4 - HKLM..\Run: [Malwarebytes' Anti-Malware] C:\Program Files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe (Malwarebytes Corporation)
O4 - HKLM..\Run: [mcui_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe (McAfee, Inc.)
O4 - HKLM..\Run: [UpdateP2GShortCut] C:\Program Files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [UpdatePRCShortCut] C:\Program Files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe (CyberLink Corp.)
O4 - HKLM..\Run: [VeriFaceManager] C:\Program Files (x86)\Lenovo\VeriFace\PManage.exe (Lenovo)
O4 - HKLM..\Run: [WordWeb] C:\Program Files (x86)\WordWeb\wweb32.exe ()
O4 - HKLM..\Run: [YouCam Mirage] C:\Program Files (x86)\Lenovo\YouCam\YCMMirage.exe (CyberLink)
O4 - HKLM..\Run: [YouCam Tray] C:\Program Files (x86)\Lenovo\YouCam\YouCam.exe (CyberLink Corp.)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-676971024-488182067-3021444819-1000..\Run: [Facebook Update] C:\Users\i5\AppData\Local\Facebook\Update\FacebookUpdate.exe (Facebook Inc.)
O4 - HKU\S-1-5-21-676971024-488182067-3021444819-1000..\Run: [RDReminder] File not found
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoControlPanel = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O8:64bit: - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8:64bit: - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm ()
O8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra Button: @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files\Lenovo\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\Lenovo\Bluetooth Software\btsendto_ie.htm ()
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.1.200
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{7F498266-AF17-45EB-969A-D0122626E259}: DhcpNameServer = 192.168.1.200
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B2F4FA5D-5F6B-452A-B8C7-9231DAE833EC}: DhcpNameServer = 192.168.2.1
O18:64bit: - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\grooveLocalGWS - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\x64\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\dssrequest {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18 - Protocol\Handler\sacore {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\Program Files (x86)\McAfee\SiteAdvisor\McIEPlg.dll (McAfee, Inc.)
O18:64bit: - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files\mcafee\msc\McSnIePl64.dll (McAfee, Inc.)
O18 - Protocol\Filter\application/x-mfe-ipt {3EF5086B-5478-4598-A054-786C45D75692} - c:\Program Files (x86)\McAfee\msc\McSnIePl.dll (McAfee, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (userinit.exe) - C:\windows\SysWow64\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: VMApplet - (/pagefile) - File not found
O20:64bit: - Winlogon\Notify\igfxcui: DllName - (igfxdev.dll) - C:\windows\SysNative\igfxdev.dll (Intel Corporation)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)


CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/08/24 18:08:44 | 000,000,000 | ---D | C] -- C:\Users\i5\Desktop\RK_Quarantine
[2012/08/24 18:04:56 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\McAfee
[2012/08/24 17:50:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Hosts_Anti_Adwares_PUPs
[2012/08/24 17:02:02 | 000,596,480 | ---- | C] (OldTimer Tools) -- C:\Users\i5\Desktop\OTL.exe
[2012/08/24 15:51:46 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Malwarebytes
[2012/08/24 15:51:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/08/24 15:51:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/08/24 15:51:18 | 000,024,904 | ---- | C] (Malwarebytes Corporation) -- C:\windows\SysNative\drivers\mbam.sys
[2012/08/24 15:51:17 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2012/08/24 14:34:16 | 000,000,000 | ---D | C] -- C:\Users\i5\Desktop\Download
[2012/08/24 14:34:12 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Mozilla
[2012/08/24 14:31:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Mozilla Firefox
[2012/08/24 13:50:44 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\dll-files.com
[2012/08/24 13:50:36 | 000,017,128 | ---- | C] (Dll-Files.com) -- C:\windows\SysNative\roboot64.exe
[2012/08/24 13:50:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dll-Files.com Fixer
[2012/08/24 13:50:27 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Dll-Files.com Fixer
[2012/08/24 06:41:03 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\PhotoScape
[2012/08/24 06:23:09 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PhotoScape
[2012/08/24 06:22:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\PhotoScape
[2012/08/23 19:59:30 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Facebook
[2012/08/23 19:51:39 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Facebook
[2012/08/22 12:51:35 | 000,000,000 | ---D | C] -- C:\Users\i5\.businessobjects
[2012/08/17 14:06:59 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\MigWiz
[2012/08/16 12:53:50 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WordWeb
[2012/08/13 13:21:13 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\SAP BusinessObjects
[2012/08/13 13:21:13 | 000,000,000 | ---D | C] -- C:\Users\i5\Documents\My SAP BusinessObjects Documents
[2012/08/13 13:14:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SAP BusinessObjects BI platform 4.0
[2012/08/13 12:17:16 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\7-Zip
[2012/08/13 12:17:09 | 000,000,000 | ---D | C] -- C:\Program Files\7-Zip
[2012/08/13 12:06:46 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\XcelsiuscustomThemesAutoInfo
[2012/08/13 12:06:46 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\XcelsiuscustomThemes
[2012/08/13 12:06:40 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Xcelsius
[2012/08/13 12:03:12 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Dashboard Design
[2012/08/13 12:01:28 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\MSXML 4.0
[2012/08/13 12:01:23 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\MSSoap
[2012/08/13 11:57:07 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SAP BusinessObjects
[2012/08/13 11:02:20 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Transcend Elite
[2012/08/11 17:10:44 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\uTorrent
[2012/08/11 17:05:59 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\uTorrent
[2012/08/11 08:01:04 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\eScription
[2012/08/11 08:00:17 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\eScription
[2012/08/11 07:58:37 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\eScription
[2012/08/11 07:54:58 | 000,000,000 | ---D | C] -- C:\windows\Downloaded Installations
[2012/08/11 07:52:08 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Adobe
[2012/08/11 07:40:47 | 000,000,000 | ---D | C] -- C:\windows\SysWow64\Wat
[2012/08/11 07:40:47 | 000,000,000 | ---D | C] -- C:\windows\SysNative\Wat
[2012/08/10 19:37:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Security Client
[2012/08/10 19:37:53 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Security Client
[2012/08/10 07:43:41 | 000,000,000 | --SD | C] -- C:\Boot
[2012/08/10 07:43:41 | 000,000,000 | -HSD | C] -- C:\System Volume Information
[2012/08/09 23:23:25 | 000,000,000 | ---D | C] -- C:\Program Files\Java
[2012/08/09 23:12:53 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Google
[2012/08/09 22:38:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Adobe
[2012/08/09 22:30:27 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Macromedia
[2012/08/09 22:10:24 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Adobe
[2012/08/09 21:19:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\SAP AG
[2012/08/09 21:14:14 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Diagnostics
[2012/08/09 19:06:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\Adobe
[2012/08/09 19:06:18 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Adobe
[2012/08/09 18:48:57 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Microsoft Games
[2012/08/09 18:40:28 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\vlc
[2012/08/09 18:38:36 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Google
[2012/08/09 18:32:33 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Office
[2012/08/09 18:32:20 | 093,721,296 | ---- | C] (Samsung Electronics Co., Ltd. ) -- C:\Users\i5\Desktop\Kies_2.3.2.12064_10_1.exe
[2012/08/09 18:31:53 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VideoLAN
[2012/08/09 18:31:41 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\VideoLAN
[2012/08/09 18:31:33 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Works
[2012/08/09 18:31:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio
[2012/08/09 18:31:15 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Common Files\DESIGNER
[2012/08/09 18:30:56 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft.NET
[2012/08/09 18:29:14 | 000,000,000 | ---D | C] -- C:\Program Files\Microsoft Office
[2012/08/09 18:29:10 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Microsoft Visual Studio 8
[2012/08/09 18:28:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Microsoft Help
[2012/08/09 18:28:37 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft Help
[2012/08/09 18:28:25 | 000,000,000 | R--D | C] -- C:\MSOCache
[2012/08/09 18:27:09 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\WinRAR
[2012/08/09 18:25:34 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/08/09 18:25:34 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\WinRAR
[2012/08/09 18:25:32 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\WinRAR
[2012/08/09 18:20:28 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Broadcom
[2012/08/09 18:20:28 | 000,000,000 | ---D | C] -- C:\Users\i5\Documents\Bluetooth Exchange Folder
[2012/08/09 18:19:53 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\SRS Labs
[2012/08/09 18:19:11 | 000,000,000 | R--D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup
[2012/08/09 18:19:11 | 000,000,000 | R--D | C] -- C:\Users\i5\Searches
[2012/08/09 18:19:11 | 000,000,000 | R--D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Administrative Tools
[2012/08/09 18:19:10 | 000,000,000 | ---D | C] -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\User Pinned
[2012/08/09 18:18:54 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Identities
[2012/08/09 18:18:51 | 000,000,000 | R--D | C] -- C:\Users\i5\Contacts
[2012/08/09 18:18:50 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/08/09 18:18:48 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\VirtualStore
[2012/08/09 18:18:38 | 000,000,000 | --SD | C] -- C:\Users\i5\AppData\Roaming\Microsoft
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Videos
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Saved Games
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Pictures
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Music
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Maintenance
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Links
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Favorites
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Downloads
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Documents
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\Desktop
[2012/08/09 18:18:38 | 000,000,000 | R--D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\AppData\Local\Temporary Internet Files
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Templates
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Start Menu
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\SendTo
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Recent
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\PrintHood
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\NetHood
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Documents\My Videos
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Documents\My Pictures
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Documents\My Music
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\My Documents
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Local Settings
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\AppData\Local\History
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Cookies
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\Application Data
[2012/08/09 18:18:38 | 000,000,000 | -HSD | C] -- C:\Users\i5\AppData\Local\Application Data
[2012/08/09 18:18:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Temp
[2012/08/09 18:18:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Local\Microsoft
[2012/08/09 18:18:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Media Center Programs
[2012/08/09 18:18:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Lenovo
[2012/08/09 18:18:38 | 000,000,000 | ---D | C] -- C:\Users\i5\AppData
[2012/08/09 18:18:24 | 000,000,000 | -HSD | C] -- C:\Recovery

========== Files - Modified Within 30 Days ==========

[2012/08/24 18:28:05 | 000,000,912 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/24 18:07:29 | 001,558,528 | ---- | M] () -- C:\Users\i5\Desktop\RogueKiller.exe
[2012/08/24 18:06:50 | 000,021,072 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/24 18:06:50 | 000,021,072 | -H-- | M] () -- C:\windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/24 18:05:07 | 000,729,688 | ---- | M] () -- C:\windows\SysNative\PerfStringBackup.INI
[2012/08/24 18:05:07 | 000,626,278 | ---- | M] () -- C:\windows\SysNative\perfh009.dat
[2012/08/24 18:05:07 | 000,107,522 | ---- | M] () -- C:\windows\SysNative\perfc009.dat
[2012/08/24 18:04:56 | 000,001,828 | ---- | M] () -- C:\Users\Public\Desktop\McAfee AntiVirus Plus.lnk
[2012/08/24 17:59:46 | 000,123,921 | ---- | M] () -- C:\windows\SysNative\fastboot.set
[2012/08/24 17:59:23 | 000,000,908 | ---- | M] () -- C:\windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/24 17:58:19 | 000,067,584 | --S- | M] () -- C:\windows\bootstat.dat
[2012/08/24 17:51:42 | 000,022,326 | ---- | M] () -- C:\windows\SysNative\drivers\etc\hosts
[2012/08/24 16:57:55 | 000,000,916 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000UA.job
[2012/08/24 16:34:30 | 000,596,480 | ---- | M] (OldTimer Tools) -- C:\Users\i5\Desktop\OTL.exe
[2012/08/24 16:15:46 | 000,000,286 | ---- | M] () -- C:\windows\tasks\DLL-files.com Fixer_UPDATES.job
[2012/08/24 16:15:46 | 000,000,266 | ---- | M] () -- C:\windows\tasks\DLL-files.com Fixer_MONTHLY.job
[2012/08/24 15:51:34 | 000,001,109 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/24 15:46:40 | 000,618,227 | ---- | M] () -- C:\Users\i5\Desktop\adwcleaner.exe
[2012/08/24 13:50:35 | 000,002,028 | ---- | M] () -- C:\Users\i5\Desktop\Check PC For Errors.lnk
[2012/08/24 13:50:35 | 000,002,012 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2012/08/24 06:23:09 | 000,001,055 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk
[2012/08/24 06:23:09 | 000,001,031 | ---- | M] () -- C:\Users\i5\Desktop\PhotoScape.lnk
[2012/08/23 19:57:00 | 000,000,894 | ---- | M] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000Core.job
[2012/08/21 15:26:23 | 000,007,639 | ---- | M] () -- C:\Users\i5\AppData\Local\Resmon.ResmonCfg
[2012/08/16 15:11:17 | 000,000,280 | ---- | M] () -- C:\windows\ODBC.INI
[2012/08/16 11:31:24 | 000,437,248 | ---- | M] () -- C:\windows\SysNative\FNTCACHE.DAT
[2012/08/15 12:27:59 | 000,001,133 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012/08/13 12:03:17 | 000,001,050 | ---- | M] () -- C:\Users\Public\Desktop\Dashboard Design.lnk
[2012/08/11 18:17:33 | 000,003,544 | ---- | M] () -- C:\bootsqm.dat
[2012/08/11 17:10:52 | 000,000,967 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/08/11 17:10:52 | 000,000,943 | ---- | M] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/08/11 08:00:21 | 000,002,771 | ---- | M] () -- C:\Users\Public\Desktop\EditScript MT 9.lnk
[2012/08/10 19:38:04 | 000,001,945 | ---- | M] () -- C:\windows\epplauncher.mif
[2012/08/10 19:37:57 | 000,731,106 | ---- | M] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/08/09 23:47:53 | 000,108,227 | ---- | M] () -- C:\windows\SysWow64\license.rtf
[2012/08/09 23:47:53 | 000,108,227 | ---- | M] () -- C:\windows\SysNative\license.rtf
[2012/08/09 23:12:12 | 000,001,437 | ---- | M] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/08/09 22:38:54 | 000,002,019 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/08/09 21:19:23 | 000,001,704 | ---- | M] () -- C:\Users\Public\Desktop\SAP Management Console.lnk
[2012/08/09 19:07:14 | 000,001,361 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2012/08/09 18:31:53 | 000,001,066 | ---- | M] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/08/09 18:19:48 | 000,001,118 | ---- | M] () -- C:\Users\i5\Desktop\Cyberlink Power2Go.lnk
[2012/08/09 18:19:43 | 000,002,086 | ---- | M] () -- C:\Users\i5\Desktop\OneKey Recovery.lnk
[2012/07/30 08:23:24 | 093,721,296 | ---- | M] (Samsung Electronics Co., Ltd. ) -- C:\Users\i5\Desktop\Kies_2.3.2.12064_10_1.exe

========== Files Created - No Company Name ==========

[2012/08/24 18:07:25 | 001,558,528 | ---- | C] () -- C:\Users\i5\Desktop\RogueKiller.exe
[2012/08/24 15:51:34 | 000,001,109 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/08/24 15:46:34 | 000,618,227 | ---- | C] () -- C:\Users\i5\Desktop\adwcleaner.exe
[2012/08/24 13:50:47 | 000,000,286 | ---- | C] () -- C:\windows\tasks\DLL-files.com Fixer_UPDATES.job
[2012/08/24 13:50:46 | 000,000,266 | ---- | C] () -- C:\windows\tasks\DLL-files.com Fixer_MONTHLY.job
[2012/08/24 13:50:35 | 000,002,028 | ---- | C] () -- C:\Users\i5\Desktop\Check PC For Errors.lnk
[2012/08/24 13:50:35 | 000,002,012 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Check PC For Errors.lnk
[2012/08/24 06:23:09 | 000,001,055 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\PhotoScape.lnk
[2012/08/24 06:23:09 | 000,001,031 | ---- | C] () -- C:\Users\i5\Desktop\PhotoScape.lnk
[2012/08/23 19:52:34 | 000,000,916 | ---- | C] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000UA.job
[2012/08/23 19:52:34 | 000,000,894 | ---- | C] () -- C:\windows\tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000Core.job
[2012/08/16 12:53:53 | 000,001,966 | ---- | C] () -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\WordWeb.lnk
[2012/08/16 12:53:52 | 002,216,480 | ---- | C] () -- C:\windows\SysWow64\wweb32.dll
[2012/08/13 14:36:49 | 000,000,280 | ---- | C] () -- C:\windows\ODBC.INI
[2012/08/13 12:03:17 | 000,001,050 | ---- | C] () -- C:\Users\Public\Desktop\Dashboard Design.lnk
[2012/08/13 11:41:00 | 000,001,133 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Microsoft Office Outlook.lnk
[2012/08/11 18:17:33 | 000,003,544 | ---- | C] () -- C:\bootsqm.dat
[2012/08/11 17:10:52 | 000,000,967 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\µTorrent.lnk
[2012/08/11 17:10:52 | 000,000,943 | ---- | C] () -- C:\Users\Public\Desktop\µTorrent.lnk
[2012/08/11 09:33:30 | 000,007,639 | ---- | C] () -- C:\Users\i5\AppData\Local\Resmon.ResmonCfg
[2012/08/11 08:00:21 | 000,002,771 | ---- | C] () -- C:\Users\Public\Desktop\EditScript MT 9.lnk
[2012/08/10 19:38:04 | 000,001,945 | ---- | C] () -- C:\windows\epplauncher.mif
[2012/08/10 19:37:59 | 000,001,915 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Microsoft Security Essentials.lnk
[2012/08/10 19:37:57 | 000,731,106 | ---- | C] () -- C:\windows\SysWow64\PerfStringBackup.INI
[2012/08/10 07:43:48 | 000,383,786 | R-S- | C] () -- C:\bootmgr
[2012/08/09 23:12:12 | 000,001,437 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Launch Internet Explorer Browser.lnk
[2012/08/09 22:38:54 | 000,002,441 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Reader X.lnk
[2012/08/09 22:38:54 | 000,002,019 | ---- | C] () -- C:\Users\Public\Desktop\Adobe Reader X.lnk
[2012/08/09 21:19:23 | 000,001,704 | ---- | C] () -- C:\Users\Public\Desktop\SAP Management Console.lnk
[2012/08/09 21:19:23 | 000,001,686 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\SAP Management Console.lnk
[2012/08/09 19:07:14 | 000,001,361 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Adobe Gamma Loader.lnk
[2012/08/09 19:07:13 | 000,001,172 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe ImageReady 7.0.lnk
[2012/08/09 19:07:13 | 000,001,167 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Adobe Photoshop 7.0.lnk
[2012/08/09 18:31:53 | 000,001,066 | ---- | C] () -- C:\Users\Public\Desktop\VLC media player.lnk
[2012/08/09 18:31:17 | 021,073,406 | ---- | C] () -- C:\Users\i5\Desktop\vlc-1.1.11-win32.rar
[2012/08/09 18:19:28 | 000,001,409 | ---- | C] () -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer (64-bit).lnk
[2012/08/09 18:19:16 | 000,001,443 | ---- | C] () -- C:\Users\i5\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Internet Explorer.lnk
[2012/08/09 18:18:38 | 000,002,235 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/09 18:18:38 | 000,002,086 | ---- | C] () -- C:\Users\i5\Desktop\OneKey Recovery.lnk
[2012/08/09 18:18:38 | 000,001,118 | ---- | C] () -- C:\Users\i5\Desktop\Cyberlink Power2Go.lnk
[2012/08/09 18:18:38 | 000,000,290 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Shows Desktop.lnk
[2012/08/09 18:18:38 | 000,000,272 | ---- | C] () -- C:\Users\i5\Application Data\Microsoft\Internet Explorer\Quick Launch\Window Switcher.lnk
[2012/08/09 18:18:38 | 000,000,189 | ---- | C] () -- C:\Users\i5\Desktop\Lenovo Telephony Start Now.url
[2011/06/09 04:20:00 | 002,086,240 | ---- | C] () -- C:\windows\SysWow64\LenovoVeriface.Interface.dll
[2011/06/09 04:20:00 | 001,500,512 | ---- | C] () -- C:\windows\SysWow64\Apblend.dll
[2011/06/09 04:20:00 | 001,171,456 | ---- | C] () -- C:\windows\SysWow64\PicNotify.dll
[2011/06/09 04:20:00 | 000,466,944 | ---- | C] () -- C:\windows\SysWow64\Lenovo.VerifaceStub.dll
[2011/06/09 04:19:53 | 001,044,480 | ---- | C] () -- C:\windows\SysWow64\3DImageRenderer.dll
[2011/06/09 04:07:54 | 000,089,328 | ---- | C] () -- C:\windows\un_dext.exe
[2011/06/09 04:07:54 | 000,087,928 | ---- | C] () -- C:\windows\SPRemove_x64.exe
[2011/06/09 04:07:54 | 000,003,566 | ---- | C] () -- C:\windows\Dext_09.ini
[2011/06/09 04:07:54 | 000,002,998 | ---- | C] () -- C:\windows\Dext_04.ini
[2011/06/09 04:07:54 | 000,002,790 | ---- | C] () -- C:\windows\Dext_2052.ini
[2011/06/09 04:07:54 | 000,002,573 | ---- | C] () -- C:\windows\Remove.ini
[2011/04/14 08:31:25 | 000,963,116 | ---- | C] () -- C:\windows\SysWow64\igkrng600.bin
[2011/04/14 08:31:22 | 000,216,876 | ---- | C] () -- C:\windows\SysWow64\igfcg600m.bin
[2011/04/14 08:31:19 | 000,145,804 | ---- | C] () -- C:\windows\SysWow64\igcompkrng600.bin
[2011/04/14 08:21:06 | 000,066,856 | ---- | C] () -- C:\windows\SysWow64\SynTPEnhPS.dll

========== LOP Check ==========

[2012/08/24 13:50:44 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\dll-files.com
[2012/08/11 08:01:04 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\eScription
[2012/08/24 06:41:31 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\PhotoScape
[2012/08/13 13:21:13 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\SAP BusinessObjects
[2012/08/13 11:02:20 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\Transcend Elite
[2012/08/11 17:11:16 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\uTorrent
[2012/08/24 13:12:42 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\Xcelsius
[2012/08/13 12:06:46 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\XcelsiuscustomThemes
[2012/08/13 12:06:46 | 000,000,000 | ---D | M] -- C:\Users\i5\AppData\Roaming\XcelsiuscustomThemesAutoInfo
[2012/08/24 16:15:46 | 000,000,266 | ---- | M] () -- C:\windows\Tasks\DLL-files.com Fixer_MONTHLY.job
[2012/08/24 16:15:46 | 000,000,286 | ---- | M] () -- C:\windows\Tasks\DLL-files.com Fixer_UPDATES.job
[2012/08/23 19:57:00 | 000,000,894 | ---- | M] () -- C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000Core.job
[2012/08/24 16:57:55 | 000,000,916 | ---- | M] () -- C:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000UA.job
[2009/07/14 10:38:49 | 000,014,908 | ---- | M] () -- C:\windows\Tasks\SCHEDLGU.TXT

========== Purity Check ==========



========== Custom Scans ==========

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/02/26 10:49:21 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/02/25 11:49:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/02/25 11:49:30 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/02/26 11:44:34 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/21 08:54:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/02/25 11:00:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/02/25 11:00:54 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/21 08:54:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: QMGR.DLL >
[2010/11/21 08:53:51 | 000,849,920 | ---- | M] (Microsoft Corporation) MD5=1EA7969E3271CBC59E1730697DC74682 -- C:\windows\SysNative\qmgr.dll
[2010/11/21 08:53:51 | 000,849,920 | ---- | M] (Microsoft Corporation) MD5=1EA7969E3271CBC59E1730697DC74682 -- C:\Windows\winsxs\amd64_microsoft-windows-bits-client_31bf3856ad364e35_6.1.7601.17514_none_81b6ca5c101195cd\qmgr.dll

< MD5 for: SERVICES >
[2009/06/11 02:30:26 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2012/04/04 11:23:54 | 000,585,987 | ---- | M] () MD5=7BAB089A4F862C6BC86E0201D5BF1779 -- C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R--- | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.EXE >
[2009/07/14 07:09:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\windows\SysNative\services.exe
[2009/07/14 07:09:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 12:36:16 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 -- C:\windows\SysNative\en-US\services.exe.mui
[2010/11/21 12:36:16 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 -- C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.LNK >
[2009/07/14 10:24:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/14 10:24:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/11 02:14:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\windows\SysNative\wbem\services.mof
[2009/06/11 02:14:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2010/11/21 12:36:14 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\windows\SysNative\en-US\services.msc
[2009/06/11 02:08:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\windows\SysNative\services.msc
[2010/11/21 12:36:17 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysWOW64\en-US\services.msc
[2009/06/11 02:51:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysWOW64\services.msc
[2010/11/21 12:36:14 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/11 02:08:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 12:36:17 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/11 02:51:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/14 01:46:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/14 01:46:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SVCHOST.EXE >
[2009/07/14 06:44:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009/07/14 06:44:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2012/07/03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/14 07:09:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\windows\SysNative\svchost.exe
[2009/07/14 07:09:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/21 08:53:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/21 08:53:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/21 08:54:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\windows\SysNative\userinit.exe
[2010/11/21 08:54:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< MD5 for: WINLOGON.EXE >
[2010/11/21 08:54:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\windows\SysNative\winlogon.exe
[2010/11/21 08:54:29 | 000,390,656 | ---- | M] (Microsoft Corporation) MD5=1151B1BAA6F350B1DB6598E0FEA7C457 -- C:\Windows\winsxs\amd64_microsoft-windows-winlogon_31bf3856ad364e35_6.1.7601.17514_none_cde90685eb910636\winlogon.exe
[2012/07/03 13:46:42 | 000,217,672 | ---- | M] () MD5=8A7F34F0BBD076EC3815680A7309114F -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\winlogon.exe

< HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS /s >
"DisplayName" = @%SystemRoot%\system32\qmgr.dll,-1000
"ImagePath" = %SystemRoot%\System32\svchost.exe -k netsvcs -- [2009/07/14 06:44:41 | 000,020,992 | ---- | M] (Microsoft Corporation)
"Description" = @%SystemRoot%\system32\qmgr.dll,-1001
"ObjectName" = LocalSystem
"ErrorControl" = 1
"Start" = 3
"DelayedAutoStart" = 1
"Type" = 32
"DependOnService" = RpcSsEventSystem [binary data]
"ServiceSidType" = 1
"RequiredPrivileges" = [Binary data over 100 bytes]
"FailureActions" = 80 51 01 00 00 00 00 00 00 00 00 00 03 00 00 00 14 00 00 00 01 00 00 00 60 EA 00 00 01 00 00 00 C0 D4 01 00 00 00 00 00 00 00 00 00 [binary data]
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Parameters]
"ServiceDll" = %SystemRoot%\System32\qmgr.dll
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Performance]
"Library" = bitsperf.dll -- [2010/11/21 08:54:01 | 000,019,456 | ---- | M] (Microsoft Corporation)
"Open" = PerfMon_Open
"Collect" = PerfMon_Collect
"Close" = PerfMon_Close
"InstallType" = 1
"PerfIniFile" = bitsctrs.ini
"First Counter" = 2156
"Last Counter" = 2172
"First Help" = 2157
"Last Help" = 2173
"Object List" = 2156
"PerfMMFileName" = Global\MMF_BITS_s
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\BITS\Security]
"Security" = [Binary data over 100 bytes]

< End of report >
  • 0

#7
dreamfalcon21

dreamfalcon21

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
And I am such a dork - Thanks a lot ali.B for trying to help me!!!
  • 0

#8
ali.B

ali.B

    Trusted Helper

  • Malware Removal
  • 3,086 posts

127.0.0.1 install.iminent.com # Hosts Anti-Adware / PUPs
127.0.0.1 install.blamcity.com # Hosts Anti-Adware / PUPs
127.0.0.1 b.juiceknowledge.com # Hosts Anti-Adware / PUPs
127.0.0.1 a.juiceknowledge.com # Hosts Anti-Adware / PUPs
127.0.0.1 1f1.fr # Hosts Anti-Adware / PUPs
127.0.0.1 2010-fr.com # Hosts Anti-Adware / PUPs
127.0.0.1 24h00business.com # Hosts Anti-Adware / PUPs
127.0.0.1 4990usd.com # Hosts Anti-Adware / PUPs
127.0.0.1 4xp.com # Hosts Anti-Adware / PUPs
127.0.0.1 adomiciletravail.googlepages.com # Hosts Anti-Adware / PUPs
127.0.0.1 adwarealert.com # Hosts Anti-Adware / PUPs
127.0.0.1 affilibot.eu # Hosts Anti-Adware / PUPs
127.0.0.1 aformula.biz # Hosts Anti-Adware / PUPs
127.0.0.1 antivirusgratuit.vg # Hosts Anti-Adware / PUPs
127.0.0.1 argent-domicile.eu # Hosts Anti-Adware / PUPs
127.0.0.1 argent-travail-domicile.fr # Hosts Anti-Adware / PUPs
127.0.0.1 argent-vital.com # Hosts Anti-Adware / PUPs
127.0.0.1 argentastuce.com # Hosts Anti-Adware / PUPs
127.0.0.1 ascentive.com # Hosts Anti-Adware / PUPs
127.0.0.1 augmentersesrevenus.pyclie.com # Hosts Anti-Adware / PUPs


did you add these to your hosts file ?
  • 0

#9
dreamfalcon21

dreamfalcon21

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Nope...

Could be from the ADWCleaner's "Hosts Anti-PUP/Adware"
  • 0

#10
dreamfalcon21

dreamfalcon21

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Shall I delete all of them from host files?
  • 0

Advertisements


#11
ali.B

ali.B

    Trusted Helper

  • Malware Removal
  • 3,086 posts
hi

Download and Install Combofix

Download ComboFix from one of the following locations:
Link 1
Link 2

VERY IMPORTANT !!! Save ComboFix.exe to your Desktop

* IMPORTANT - Disable your AntiVirus and AntiSpyware applications, usually via a right click on the System Tray icon. They may otherwise interfere with our tools. If you have difficulty properly disabling your protective programs, refer to this link here
  • Double click on ComboFix.exe & follow the prompts.
  • Accept the disclaimer and allow to update if it asks

    Posted Image

    Posted Image
  • When finished, it shall produce a log for you.
  • Please include the C:\ComboFix.txt in your next reply.

Notes:
1. Do not mouse-click Combofix's window while it is running. That may cause it to stall.
2. Do not "re-run" Combofix. If you have a problem, reply back for further instructions.
3. If after the reboot you get errors about programmes being marked for deletion then reboot, that will cure it.

  • 0

#12
dreamfalcon21

dreamfalcon21

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Hi ali.B, herez the ComboFix log

ComboFix 12-08-22.03 - i5 08/24/2012 19:37:56.1.4 - x64
Microsoft Windows 7 Home Premium 6.1.7601.1.1252.1.1033.18.2986.1228 [GMT 5.5:30]
Running from: c:\users\i5\Desktop\ComboFix.exe
AV: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {86355677-4064-3EA7-ABB3-1B136EB04637}
AV: Microsoft Security Essentials *Disabled/Updated* {9765EA51-0D3C-7DFB-6091-10E4E1F341F6}
FW: McAfee Firewall *Disabled* {BE0ED752-0A0B-3FFF-80EC-B2269063014C}
SP: McAfee Anti-Virus and Anti-Spyware *Disabled/Updated* {3D54B793-665E-3129-9103-206115370C8A}
SP: Microsoft Security Essentials *Disabled/Updated* {2C040BB5-2B06-7275-5A21-2B969A740B4B}
SP: Windows Defender *Disabled/Updated* {D68DDC3A-831F-4fae-9E44-DA132C1ACF46}
.
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
.
c:\windows\s.bat
c:\windows\SysWow64\DEBUG.log
.
.
((((((((((((((((((((((((( Files Created from 2012-07-24 to 2012-08-24 )))))))))))))))))))))))))))))))
.
.
2012-08-24 14:13 . 2012-08-24 14:13 -------- d-----w- c:\users\Default\AppData\Local\temp
2012-08-24 12:20 . 2012-08-24 12:24 -------- d-----w- c:\program files (x86)\Hosts_Anti_Adwares_PUPs
2012-08-24 10:21 . 2012-08-24 10:21 -------- d-----w- c:\programdata\Malwarebytes
2012-08-24 10:21 . 2012-07-03 08:16 24904 ----a-w- c:\windows\system32\drivers\mbam.sys
2012-08-24 10:21 . 2012-08-24 10:21 -------- d-----w- c:\program files (x86)\Malwarebytes' Anti-Malware
2012-08-24 09:46 . 2012-08-01 22:58 9309624 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{BBCB761E-8DCC-487F-B719-365A02FC3BD4}\mpengine.dll
2012-08-24 08:48 . 2012-08-01 22:58 9309624 ----a-w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\Backup\mpengine.dll
2012-08-24 08:20 . 2011-03-25 12:33 17128 ----a-w- c:\windows\system32\roboot64.exe
2012-08-24 08:20 . 2011-03-25 00:06 2297552 ----a-w- c:\windows\SysWow64\d3dx9_26.dll
2012-08-24 08:20 . 2012-08-24 08:20 -------- d-----w- c:\program files (x86)\Dll-Files.com Fixer
2012-08-24 00:52 . 2012-08-24 00:53 -------- d-----w- c:\program files (x86)\PhotoScape
2012-08-16 07:23 . 2012-07-15 06:57 2216480 ------w- c:\windows\SysWow64\wweb32.dll
2012-08-16 07:23 . 2012-08-16 07:23 -------- d-----w- c:\program files (x86)\WordWeb
2012-08-15 18:39 . 2012-07-06 20:07 552960 ----a-w- c:\windows\system32\drivers\bthport.sys
2012-08-15 15:49 . 2012-06-27 07:02 64512 ----a-w- c:\windows\system32\jsproxy.dll
2012-08-15 15:49 . 2012-06-27 05:50 163328 ----a-w- c:\program files (x86)\Internet Explorer\ieproxy.dll
2012-08-15 15:49 . 2012-06-27 07:06 134144 ----a-w- c:\windows\system32\url.dll
2012-08-15 15:49 . 2012-06-27 04:53 1638912 ----a-w- c:\windows\system32\mshtml.tlb
2012-08-15 15:49 . 2012-06-27 04:10 1638912 ----a-w- c:\windows\SysWow64\mshtml.tlb
2012-08-15 15:39 . 2012-05-05 08:36 503808 ----a-w- c:\windows\system32\srcore.dll
2012-08-15 15:39 . 2012-05-05 07:46 43008 ----a-w- c:\windows\SysWow64\srclient.dll
2012-08-15 15:22 . 2012-07-18 18:15 3148800 ----a-w- c:\windows\system32\win32k.sys
2012-08-15 15:22 . 2012-05-14 05:26 956928 ----a-w- c:\windows\system32\localspl.dll
2012-08-13 06:47 . 2012-08-13 06:47 -------- d-----w- c:\program files\7-Zip
2012-08-13 06:31 . 2012-08-13 06:31 -------- d-----w- c:\program files (x86)\MSXML 4.0
2012-08-13 06:27 . 2012-08-13 07:16 -------- d-----w- c:\program files (x86)\SAP BusinessObjects
2012-08-11 11:40 . 2012-08-11 11:40 -------- d-----w- c:\program files (x86)\uTorrent
2012-08-11 02:28 . 2012-08-11 02:28 -------- d-----w- c:\program files (x86)\eScription
2012-08-11 02:24 . 2012-08-11 02:24 -------- d-----w- c:\windows\Downloaded Installations
2012-08-11 02:10 . 2012-08-11 02:10 -------- d-----w- c:\windows\SysWow64\Wat
2012-08-11 02:10 . 2012-08-11 02:10 -------- d-----w- c:\windows\system32\Wat
2012-08-10 18:54 . 2012-08-10 18:54 -------- d-----w- c:\users\Default\AppData\Local\Microsoft Help
2012-08-10 14:35 . 2012-08-10 14:35 927800 ------w- c:\programdata\Microsoft\Microsoft Antimalware\Definition Updates\{126BB441-93FB-4F2B-97EA-BE6D63FADF1F}\gapaengine.dll
2012-08-10 14:07 . 2012-08-10 14:07 -------- d-----w- c:\program files (x86)\Microsoft Security Client
2012-08-10 14:07 . 2012-08-10 14:08 -------- d-----w- c:\program files\Microsoft Security Client
2012-08-10 14:04 . 2012-07-02 21:49 59701280 ----a-w- c:\windows\system32\MRT.exe
2012-08-10 10:13 . 2011-04-29 05:55 244736 ----a-w- c:\program files\Internet Explorer\sqmapi.dll
2012-08-10 10:13 . 2011-04-29 04:57 189952 ----a-w- c:\program files (x86)\Internet Explorer\sqmapi.dll
2012-08-10 09:48 . 2012-05-04 11:06 5559664 ----a-w- c:\windows\system32\ntoskrnl.exe
2012-08-10 09:48 . 2012-05-04 10:03 3913072 ----a-w- c:\windows\SysWow64\ntoskrnl.exe
2012-08-10 09:48 . 2012-05-04 10:03 3968368 ----a-w- c:\windows\SysWow64\ntkrnlpa.exe
2012-08-10 09:28 . 2011-10-01 05:45 886784 ----a-w- c:\program files\Common Files\System\wab32.dll
2012-08-10 09:28 . 2011-10-01 04:37 708608 ----a-w- c:\program files (x86)\Common Files\System\wab32.dll
2012-08-10 09:28 . 2011-04-09 06:58 142336 ----a-w- c:\windows\system32\poqexec.exe
2012-08-10 09:28 . 2011-04-09 05:56 123904 ----a-w- c:\windows\SysWow64\poqexec.exe
2012-08-10 09:24 . 2011-02-25 06:19 2871808 ----a-w- c:\windows\explorer.exe
2012-08-10 09:24 . 2011-02-25 05:30 2616320 ----a-w- c:\windows\SysWow64\explorer.exe
2012-08-10 09:23 . 2010-12-23 10:42 961024 ----a-w- c:\windows\system32\CPFilters.dll
2012-08-10 09:22 . 2010-12-23 05:54 642048 ----a-w- c:\windows\SysWow64\CPFilters.dll
2012-08-10 09:22 . 2010-12-23 10:42 1118720 ----a-w- c:\windows\system32\sbe.dll
2012-08-10 09:22 . 2010-12-23 10:36 259072 ----a-w- c:\windows\system32\mpg2splt.ax
2012-08-10 09:22 . 2010-12-23 05:54 850944 ----a-w- c:\windows\SysWow64\sbe.dll
2012-08-10 09:22 . 2010-12-23 05:50 199680 ----a-w- c:\windows\SysWow64\mpg2splt.ax
2012-08-10 09:21 . 2011-10-26 05:25 1572864 ----a-w- c:\windows\system32\quartz.dll
2012-08-10 09:21 . 2011-10-26 04:32 1328128 ----a-w- c:\windows\SysWow64\quartz.dll
2012-08-10 09:21 . 2011-10-26 05:25 366592 ----a-w- c:\windows\system32\qdvd.dll
2012-08-10 09:21 . 2011-10-26 04:32 514560 ----a-w- c:\windows\SysWow64\qdvd.dll
2012-08-10 09:20 . 2012-01-04 10:44 509952 ----a-w- c:\windows\system32\ntshrui.dll
2012-08-10 09:20 . 2012-01-04 08:58 442880 ----a-w- c:\windows\SysWow64\ntshrui.dll
2012-08-10 09:17 . 2011-05-04 04:28 86528 ----a-w- c:\windows\SysWow64\SearchFilterHost.exe
2012-08-10 09:17 . 2011-05-04 05:22 75264 ----a-w- c:\windows\system32\msscntrs.dll
2012-08-10 09:17 . 2011-05-04 04:32 197120 ----a-w- c:\windows\SysWow64\mssphtb.dll
2012-08-10 09:17 . 2011-05-04 04:32 59392 ----a-w- c:\windows\SysWow64\msscntrs.dll
2012-08-10 09:17 . 2011-11-17 06:35 395776 ----a-w- c:\windows\system32\webio.dll
2012-08-10 09:17 . 2011-11-17 05:35 314880 ----a-w- c:\windows\SysWow64\webio.dll
2012-08-10 09:14 . 2011-03-12 12:08 1465344 ----a-w- c:\windows\system32\XpsPrint.dll
2012-08-10 09:14 . 2011-03-12 11:23 870912 ----a-w- c:\windows\SysWow64\XpsPrint.dll
2012-08-10 09:13 . 2011-03-11 06:34 1359872 ----a-w- c:\windows\system32\mfc42u.dll
2012-08-10 09:13 . 2011-03-11 06:34 1395712 ----a-w- c:\windows\system32\mfc42.dll
2012-08-10 09:13 . 2011-03-11 05:33 1164288 ----a-w- c:\windows\SysWow64\mfc42u.dll
2012-08-10 09:13 . 2011-03-11 05:33 1137664 ----a-w- c:\windows\SysWow64\mfc42.dll
2012-08-10 09:13 . 2012-06-09 05:43 14172672 ----a-w- c:\windows\system32\shell32.dll
2012-08-10 09:07 . 2012-04-26 05:41 77312 ----a-w- c:\windows\system32\rdpwsx.dll
2012-08-10 09:07 . 2012-04-26 05:41 149504 ----a-w- c:\windows\system32\rdpcorekmts.dll
2012-08-10 09:07 . 2012-04-26 05:34 9216 ----a-w- c:\windows\system32\rdrmemptylst.exe
2012-08-10 08:57 . 2011-02-19 09:00 367616 ----a-w- c:\windows\system32\atmfd.dll
2012-08-10 08:57 . 2011-02-19 04:34 294912 ----a-w- c:\windows\SysWow64\atmfd.dll
2012-08-10 08:57 . 2011-02-19 12:03 46080 ----a-w- c:\windows\system32\atmlib.dll
2012-08-10 08:57 . 2011-02-19 06:30 34304 ----a-w- c:\windows\SysWow64\atmlib.dll
2012-08-10 08:57 . 2010-09-30 10:41 100864 ----a-w- c:\windows\system32\fontsub.dll
2012-08-10 08:57 . 2010-09-30 06:47 70656 ----a-w- c:\windows\SysWow64\fontsub.dll
2012-08-10 08:56 . 2011-04-22 22:15 27520 ----a-w- c:\windows\system32\drivers\Diskdump.sys
2012-08-10 08:55 . 2012-05-01 05:40 209920 ----a-w- c:\windows\system32\profsvc.dll
2012-08-10 08:55 . 2011-03-03 06:24 357888 ----a-w- c:\windows\system32\dnsapi.dll
2012-08-10 08:55 . 2011-03-03 06:24 183296 ----a-w- c:\windows\system32\dnsrslvr.dll
2012-08-10 08:55 . 2011-03-03 06:21 30208 ----a-w- c:\windows\system32\dnscacheugc.exe
2012-08-10 08:55 . 2011-03-03 05:36 28672 ----a-w- c:\windows\SysWow64\dnscacheugc.exe
2012-08-10 08:42 . 2012-04-28 03:55 210944 ----a-w- c:\windows\system32\drivers\rdpwd.sys
2012-08-10 08:42 . 2012-04-24 05:37 1462272 ----a-w- c:\windows\system32\crypt32.dll
2012-08-10 08:42 . 2012-04-24 05:37 184320 ----a-w- c:\windows\system32\cryptsvc.dll
2012-08-10 08:42 . 2012-04-24 05:37 140288 ----a-w- c:\windows\system32\cryptnet.dll
2012-08-10 08:42 . 2012-04-24 04:36 1158656 ----a-w- c:\windows\SysWow64\crypt32.dll
2012-08-10 08:42 . 2012-04-24 04:36 140288 ----a-w- c:\windows\SysWow64\cryptsvc.dll
2012-08-10 08:42 . 2012-04-24 04:36 103936 ----a-w- c:\windows\SysWow64\cryptnet.dll
2012-08-10 08:40 . 2011-07-16 05:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-util-l1-1-0.dll
2012-08-10 08:40 . 2011-07-16 02:17 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-util-l1-1-0.dll
2012-08-10 08:40 . 2011-07-16 05:21 4096 ---ha-w- c:\windows\system32\api-ms-win-core-localization-l1-1-0.dll
2012-08-10 08:40 . 2011-07-16 05:21 3072 ---ha-w- c:\windows\system32\api-ms-win-core-console-l1-1-0.dll
2012-08-10 08:40 . 2011-07-16 04:15 4096 ---ha-w- c:\windows\SysWow64\api-ms-win-core-localization-l1-1-0.dll
2012-08-10 08:40 . 2011-07-16 04:15 3072 ---ha-w- c:\windows\SysWow64\api-ms-win-core-console-l1-1-0.dll
2012-08-10 08:40 . 2011-07-16 02:21 2048 ----a-w- c:\windows\SysWow64\user.exe
2012-08-10 07:53 . 2011-01-17 11:09 197120 ----a-w- c:\windows\system32\d3d10_1.dll
2012-08-10 07:53 . 2011-01-17 05:47 161792 ----a-w- c:\windows\SysWow64\d3d10_1.dll
2012-08-10 07:53 . 2011-04-29 03:06 467456 ----a-w- c:\windows\system32\drivers\srv.sys
2012-08-10 07:53 . 2011-04-29 03:05 410112 ----a-w- c:\windows\system32\drivers\srv2.sys
2012-08-10 07:53 . 2011-04-29 03:05 168448 ----a-w- c:\windows\system32\drivers\srvnet.sys
2012-08-10 07:48 . 2011-08-17 05:26 613888 ----a-w- c:\windows\system32\psisdecd.dll
2012-08-10 07:48 . 2011-08-17 04:19 75776 ----a-w- c:\windows\SysWow64\psisrndr.ax
2012-08-10 07:45 . 2011-05-24 11:42 404480 ----a-w- c:\windows\system32\umpnpmgr.dll
2012-08-10 07:45 . 2011-05-24 10:37 252928 ----a-w- c:\windows\SysWow64\drvinst.exe
2012-08-10 07:45 . 2011-05-24 10:39 145920 ----a-w- c:\windows\SysWow64\cfgmgr32.dll
2012-08-10 07:45 . 2011-05-24 10:40 64512 ----a-w- c:\windows\SysWow64\devobj.dll
2012-08-10 07:45 . 2011-05-24 10:40 44544 ----a-w- c:\windows\SysWow64\devrtl.dll
2012-08-10 07:45 . 2011-02-18 10:51 31232 ----a-w- c:\windows\system32\prevhost.exe
2012-08-10 07:45 . 2011-02-18 05:39 31232 ----a-w- c:\windows\SysWow64\prevhost.exe
2012-08-10 07:39 . 2011-02-12 11:34 267776 ----a-w- c:\windows\system32\FXSCOVER.exe
2012-08-10 07:39 . 2011-05-03 05:29 976896 ----a-w- c:\windows\system32\inetcomm.dll
2012-08-10 07:39 . 2011-05-03 04:30 741376 ----a-w- c:\windows\SysWow64\inetcomm.dll
2012-08-10 07:39 . 2011-12-16 08:46 634880 ----a-w- c:\windows\system32\msvcrt.dll
2012-08-10 07:39 . 2011-12-16 07:52 690688 ----a-w- c:\windows\SysWow64\msvcrt.dll
2012-08-10 07:32 . 2012-06-06 06:05 1499136 ----a-w- c:\program files\Common Files\System\ado\msado15.dll
2012-08-10 07:32 . 2012-06-06 05:05 1019904 ----a-w- c:\program files (x86)\Common Files\System\ado\msado15.dll
2012-08-10 07:32 . 2012-06-06 06:05 466944 ----a-w- c:\program files\Common Files\System\ado\msadomd.dll
2012-08-10 07:32 . 2012-06-06 06:05 258048 ----a-w- c:\program files\Common Files\System\msadc\msadco.dll
2012-08-10 07:32 . 2012-06-06 06:05 495616 ----a-w- c:\program files\Common Files\System\ado\msadox.dll
.
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2012-08-10 03:00 . 2010-06-24 11:33 19720 ----a-w- c:\programdata\Microsoft\IdentityCRL\production\ppcrlconfig600.dll
2012-06-06 15:29 . 2012-06-06 15:29 1070152 ----a-w- c:\windows\SysWow64\MSCOMCTL.OCX
.
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
.
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Facebook Update"="c:\users\i5\AppData\Local\Facebook\Update\FacebookUpdate.exe" [2012-08-23 138096]
"swg"="c:\program files (x86)\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe" [2011-06-08 39408]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\Run]
"mcui_exe"="c:\program files\McAfee.com\Agent\mcagent.exe" [2012-03-21 1675160]
"YouCam Mirage"="c:\program files (x86)\Lenovo\YouCam\YCMMirage.exe" [2010-12-05 136488]
"YouCam Tray"="c:\program files (x86)\Lenovo\YouCam\YouCam.exe" [2010-12-05 224352]
"VeriFaceManager"="c:\program files (x86)\Lenovo\VeriFace\PManage.exe" [2011-06-08 329056]
"UpdateP2GShortCut"="c:\program files (x86)\Lenovo\Power2Go\MUITransfer\MUIStartMenu.exe" [2010-07-26 222504]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"GrooveMonitor"="c:\program files (x86)\Microsoft Office\Office12\GrooveMonitor.exe" [2009-02-26 30040]
"Adobe ARM"="c:\program files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe" [2012-04-04 843712]
"WordWeb"="c:\program files (x86)\WordWeb\wweb32.exe" [2012-04-21 77064]
"Malwarebytes' Anti-Malware"="c:\program files (x86)\Malwarebytes' Anti-Malware\mbamgui.exe" [2012-07-03 462920]
"HOSTS Anti-Adware_PUPs"="c:\program files (x86)\Hosts_Anti_Adwares_PUPs\HOSTS_Anti-Adware_main.exe" [2012-08-24 302961]
.
c:\programdata\Microsoft\Windows\Start Menu\Programs\Startup\
Adobe Gamma Loader.lnk - c:\program files (x86)\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2012-8-9 113664]
Bluetooth.lnk - c:\program files\Lenovo\Bluetooth Software\BTTray.exe [2011-2-15 1136928]
SRS Premium Sound.lnk - c:\program files\SRS Labs\SRS Premium Sound Control Panel\SRSPremiumPanel_64.exe [2010-12-17 1927528]
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"ConsentPromptBehaviorAdmin"= 5 (0x5)
"ConsentPromptBehaviorUser"= 3 (0x3)
"EnableUIADesktopToggle"= 0 (0x0)
.
[HKEY_LOCAL_MACHINE\software\wow6432node\microsoft\windows nt\currentversion\drivers32]
"mixer2"=wdmaud.drv
.
[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\lsa]
Security Packages REG_MULTI_SZ kerberos msv1_0 schannel wdigest tspkg pku2u livessp
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\mcmscsvc]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MCODS]
@=""
.
[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\MsMpSvc]
@="Service"
.
R2 clr_optimization_v4.0.30319_64;Microsoft .NET Framework NGEN v4.0.30319_X64;c:\windows\Microsoft.NET\Framework64\v4.0.30319\mscorsvw.exe [2010-03-18 138576]
R2 gupdate;Google Update Service (gupdate);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-08 136176]
R3 gupdatem;Google Update Service (gupdatem);c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-08 136176]
R3 McAWFwk;McAfee Activation Service;c:\progra~1\mcafee\msc\mcawfwk.exe [2010-08-09 220528]
R3 NisDrv;Microsoft Network Inspection System;c:\windows\system32\DRIVERS\NisDrvWFP.sys [2012-03-20 98688]
R3 NisSrv;Microsoft Network Inspection;c:\program files\Microsoft Security Client\NisSrv.exe [2012-03-26 291696]
R3 Partner Service;Partner Service;c:\programdata\Partner\Partner.exe [x]
R3 TsUsbFlt;TsUsbFlt;c:\windows\system32\drivers\tsusbflt.sys [2010-11-21 59392]
R3 TsUsbGD;Remote Desktop Generic USB Device;c:\windows\system32\drivers\TsUsbGD.sys [2010-11-21 31232]
R3 WatAdminSvc;Windows Activation Technologies Service;c:\windows\system32\Wat\WatAdminSvc.exe [2012-08-10 1255736]
R3 wsvd;wsvd;c:\windows\system32\DRIVERS\wsvd.sys [2009-07-21 121840]
R4 McOobeSv;McAfee OOBE Service;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
R4 wlcrasvc;Windows Live Mesh remote connections service;c:\program files\Windows Live\Mesh\wlcrasvc.exe [2010-09-22 57184]
S0 fbfmon;fbfmon;c:\windows\system32\drivers\fbfmon.sys [2011-06-08 57952]
S0 LHDmgr;LHDmgr;c:\windows\System32\DRIVERS\LhdX64.sys [2011-06-08 39008]
S0 mfewfpk;McAfee Inc. mfewfpk;c:\windows\system32\drivers\mfewfpk.sys [2012-02-22 289664]
S1 BPntDrv;BPntDrv;c:\windows\system32\drivers\BPntDrv.sys [2011-06-08 13408]
S1 mfenlfk;McAfee NDIS Light Filter;c:\windows\system32\DRIVERS\mfenlfk.sys [2012-02-22 75936]
S1 vwififlt;Virtual WiFi Filter Driver;c:\windows\system32\DRIVERS\vwififlt.sys [2009-07-14 59904]
S2 AdobeARMservice;Adobe Acrobat Update Service;c:\program files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe [2012-04-04 63928]
S2 MBAMService;MBAMService;c:\program files (x86)\Malwarebytes' Anti-Malware\mbamservice.exe [2012-07-03 655944]
S2 McAfee SiteAdvisor Service;McAfee SiteAdvisor Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 McMPFSvc;McAfee Personal Firewall Service;c:\program files\Common Files\McAfee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 McNaiAnn;McAfee VirusScan Announcer;c:\program files\Common Files\mcafee\McSvcHost\McSvHost.exe [2011-01-27 249936]
S2 mfefire;McAfee Firewall Core Service;c:\program files\Common Files\McAfee\SystemCore\\mfefire.exe [2012-05-25 210616]
S2 mfevtp;McAfee Validation Trust Protection Service;c:\windows\system32\mfevtps.exe [2012-05-25 162224]
S2 RtLedService;RtLedService Installer;c:\program files\Realtek\RtLED\RtLEDService.exe [2010-09-30 311296]
S2 UNS;Intel® Management and Security Application User Notification Service;c:\program files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe [2010-12-20 2656280]
S3 ACPIVPC;Lenovo Virtual Power Controller Driver;c:\windows\system32\DRIVERS\AcpiVpc.sys [2011-06-08 29792]
S3 BTWAMPFL;BTWAMPFL;c:\windows\system32\DRIVERS\btwampfl.sys [2011-02-15 349736]
S3 btwl2cap;Bluetooth L2CAP Service;c:\windows\system32\DRIVERS\btwl2cap.sys [2011-02-15 39464]
S3 cfwids;McAfee Inc. cfwids;c:\windows\system32\drivers\cfwids.sys [2012-02-22 65264]
S3 clwvd;CyberLink WebCam Virtual Driver;c:\windows\system32\DRIVERS\clwvd.sys [2010-12-05 31088]
S3 IntcDAud;Intel® Display Audio;c:\windows\system32\DRIVERS\IntcDAud.sys [2010-10-14 317440]
S3 MBAMProtector;MBAMProtector;c:\windows\system32\drivers\mbam.sys [2012-07-03 24904]
S3 MEIx64;Intel® Management Engine Interface;c:\windows\system32\DRIVERS\HECIx64.sys [2010-10-19 56344]
S3 mfefirek;McAfee Inc. mfefirek;c:\windows\system32\drivers\mfefirek.sys [2012-02-22 487296]
S3 RSUSBVSTOR;RtsUVStor.Sys Realtek USB Card Reader;c:\windows\system32\Drivers\RtsUVStor.sys [2010-11-30 307304]
S3 RTL8167;Realtek 8167 NT Driver;c:\windows\system32\DRIVERS\Rt64win7.sys [2010-05-31 333928]
S3 SPUVCbv;SPUVCb Driver Service;c:\windows\system32\Drivers\usbvideo.sys [2010-11-21 184960]
.
.
--- Other Services/Drivers In Memory ---
.
*Deregistered* - mfeavfk01
.
Contents of the 'Scheduled Tasks' folder
.
2012-08-24 c:\windows\Tasks\DLL-files.com Fixer_MONTHLY.job
- c:\program files (x86)\Dll-Files.com Fixer\DLLFixer.exe [2012-08-24 12:33]
.
2012-08-24 c:\windows\Tasks\DLL-files.com Fixer_UPDATES.job
- c:\program files (x86)\Dll-Files.com Fixer\DLLFixer.exe [2012-08-24 12:33]
.
2012-08-23 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000Core.job
- c:\users\i5\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-23 14:21]
.
2012-08-24 c:\windows\Tasks\FacebookUpdateTaskUserS-1-5-21-676971024-488182067-3021444819-1000UA.job
- c:\users\i5\AppData\Local\Facebook\Update\FacebookUpdate.exe [2012-08-23 14:21]
.
2012-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-08 22:58]
.
2012-08-24 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files (x86)\Google\Update\GoogleUpdate.exe [2011-06-08 22:58]
.
.
--------- X64 Entries -----------
.
.
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\explorer\shelliconoverlayidentifiers\VeriFace Enc]
@="{771C7324-DA80-49D3-8017-753B0AF60951}"
[HKEY_CLASSES_ROOT\CLSID\{771C7324-DA80-49D3-8017-753B0AF60951}]
2011-06-08 22:49 1502720 ----a-w- c:\windows\System32\IcnOvrly.dll
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2011-03-29 167960]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2011-03-29 391704]
"Persistence"="c:\windows\system32\igfxpers.exe" [2011-03-29 418840]
"RtHDVCpl"="c:\program files\Realtek\Audio\HDA\RAVCpl64.exe" [2010-12-14 11697768]
"Lenovo EE Boot Optimizer"="c:\program files (x86)\Lenovo\Boot Optimizer\PopWnd.exe" [2011-06-08 114688]
"OnekeyStudio"="c:\program files (x86)\Lenovo\Onekey Theater\OnekeyStudio.exe" [2011-06-08 789920]
"UpdatePRCShortCut"="c:\program files\Lenovo\OneKey App\OneKey Recovery\MUITransfer\MUIStartMenu.exe" [2009-05-13 222504]
"Energy Management"="c:\program files (x86)\Lenovo\Energy Management\Energy Management.exe" [2011-06-08 9769888]
"EnergyUtility"="c:\program files (x86)\Lenovo\Energy Management\Utility.exe" [2011-06-08 5908928]
"MSC"="c:\program files\Microsoft Security Client\msseces.exe" [2012-03-26 1271168]
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows]
"LoadAppInit_DLLs"=0x0
.
------- Supplementary Scan -------
.
uStart Page = hxxp://isearch.claro-search.com/?affID=115131&tt=3412_8&babsrc=HP_iclro&mntrId=269a99fd000000000000c0f8daa6d7b3
uLocal Page = c:\windows\system32\blank.htm
mStart Page = hxxp://lenovo.msn.com
mLocal Page = c:\windows\SysWOW64\blank.htm
IE: E&xport to Microsoft Excel - c:\progra~2\MICROS~1\Office12\EXCEL.EXE/3000
IE: Send image to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie_ctx.htm
IE: Send page to &Bluetooth Device... - c:\program files\Lenovo\Bluetooth Software\btsendto_ie.htm
TCP: DhcpNameServer = 192.168.1.200
.
- - - - ORPHANS REMOVED - - - -
.
Toolbar-Locked - (no file)
Wow6432Node-HKCU-Run-RDReminder - (no file)
Toolbar-Locked - (no file)
HKLM-Run-SynTPEnh - c:\program files (x86)\Synaptics\SynTP\SynTPEnh.exe
.
.
.
--------------------- LOCKED REGISTRY KEYS ---------------------
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Shockwave Flash Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\MiscStatus]
@="0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ProgID]
@="ShockwaveFlash.ShockwaveFlash.10"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB6E-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="ShockwaveFlash.ShockwaveFlash"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}]
@Denied: (A 2) (Everyone)
@="Macromedia Flash Factory Object"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\InprocServer32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx"
"ThreadingModel"="Apartment"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ProgID]
@="FlashFactory.FlashFactory.1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\ToolboxBitmap32]
@="c:\\windows\\SysWow64\\Macromed\\Flash\\Flash10h.ocx, 1"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\TypeLib]
@="{D27CDB6B-AE6D-11cf-96B8-444553540000}"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\Version]
@="1.0"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{D27CDB70-AE6D-11cf-96B8-444553540000}\VersionIndependentProgID]
@="FlashFactory.FlashFactory"
.
[HKEY_LOCAL_MACHINE\SOFTWARE\McAfee]
"SymbolicLinkValue"=hex(6):5c,00,72,00,65,00,67,00,69,00,73,00,74,00,72,00,79,
00,5c,00,6d,00,61,00,63,00,68,00,69,00,6e,00,65,00,5c,00,53,00,6f,00,66,00,\
.
[HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\PCW\Security]
@Denied: (Full) (Everyone)
.
Completion time: 2012-08-24 19:49:28
ComboFix-quarantined-files.txt 2012-08-24 14:19
.
Pre-Run: 184,124,096,512 bytes free
Post-Run: 184,170,618,880 bytes free
.
- - End Of File - - E3199F025B86CE5C8609C47CF95A76DB
  • 0

#13
dreamfalcon21

dreamfalcon21

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Hi Ali.B! Extremely glad to see you back online! I have posted ComboFix logs.

Edited by dreamfalcon21, 24 August 2012 - 09:09 AM.

  • 0

#14
ali.B

ali.B

    Trusted Helper

  • Malware Removal
  • 3,086 posts
are you still getting redirected ?
  • 0

#15
dreamfalcon21

dreamfalcon21

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
:blush:

Didn't realize that it is fixed. The malware had changed my homepage in chrome and explorer to isearch-claro-search.com and I kept thinking my system is still infected :bashhead:

:notworthy: thanks a lot ali.B for your help.

:unsure: I think it is fixed since it is not going back to isearch-claro-search.com when I reopen either browser.



May not be a related topic, but would sure appreciate your comments. My system got sluggish and slow and would freeze up when I work on transcription. The audio would stop every 5-10 seconds for a couple of seconds and when that happens my screen, keyboard, foot pedal, and mouse will freeze up too. I took the system to Lenovo for troubleshooting and they removed all the partitions and reinstalled the OS (Win7 HP) from the one-key recovery. It took around 3 hours for the OS to load from one-key and the service person told me that my hard disk will need to be replaced as it seems to be having "logic" errors. I was not convinced as he did not run any sort of diagnostics on it before coming to that conclusion, either via software or physically. Please guide me on how to check if my hard-drive is okay.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP