Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

Help with a trojan "chost.exe" [Solved]


  • This topic is locked This topic is locked

#1
hamadm

hamadm

    Member

  • Member
  • PipPip
  • 21 posts
Hello,

I have downloaded a crack for "Holdem Indicator" software, and i think it's a trojan to read other poker players cards, my antivirus software "COMODO" shows the name and it's "chost.exe"
my system is vista 32 amd cpu 3.2 2gb ram, below the log from HijackThis, please help, what to do.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21:13:58, on 23/09/2012
Platform: Windows Vista SP2 (WinNT 6.00.1906)
MSIE: Internet Explorer v9.00 (9.00.8112.16450)
Boot mode: Normal

Running processes:
C:\Program Files\TeamViewer\Version7\TeamViewer.exe
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\ProgramData\DatacardService\DCSHelper.exe
C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
C:\Windows\WindowsMobile\wmdc.exe
C:\Program Files\COMODO\COMODO Internet Security\cfp.exe
C:\Program Files\Microsoft Xbox 360 Accessories\XBoxStat.exe
C:\Program Files\Microsoft Security Client\msseces.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Users\Hamad\Desktop\Tools\RestReminder.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Mz Ultimate Tools\Mz RAM Booster\MzRAMBooster.exe
C:\Program Files\Google\Drive\googledrivesync.exe
C:\Windows\System32\spool\drivers\w32x86\3\E_TATIHTE.EXE
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
C:\Program Files\Evernote\Evernote\EvernoteTray.exe
C:\Users\Hamad\.thinkbuzan\imindmap\preload\iMindMap_Preloader.exe
C:\Program Files\Evernote\Evernote\Evernote.exe
C:\Program Files\OpenOffice.org 3\program\soffice.exe
C:\Users\Hamad\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler.exe
C:\Program Files\Hotspot Shield\bin\openvpntray.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe
C:\Program Files\OpenOffice.org 3\program\soffice.bin
C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files\Google\Drive\googledrivesync.exe
C:\Program Files\ThinkBuzan\iMindMap 5\iMindMap 5.exe
C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CCC.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\Hamad\AppData\Roaming\eType\eType.exe
C:\Users\Hamad\AppData\Roaming\eType\eTypeUpdate.exe
C:\Users\Hamad\Downloads\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://badoo.com/startpage/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft....k/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft....k/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft....k/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft....k/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: (no name) - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - (no file)
O1 - Hosts: ::1 localhost
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Java™ Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Java™ Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll
O2 - BHO: Hotspot Shield Class - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll
O3 - Toolbar: Snagit - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll
O3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dll
O4 - HKLM\..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe -r
O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [Windows Mobile Device Center] C:\Windows\WindowsMobile\wmdc.exe
O4 - HKLM\..\Run: [BCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServices
O4 - HKLM\..\Run: [COMODO Internet Security] "C:\Program Files\COMODO\COMODO Internet Security\cfp.exe" -h
O4 - HKLM\..\Run: [XboxStat] "C:\Program Files\Microsoft Xbox 360 Accessories\XboxStat.exe" silentrun
O4 - HKLM\..\Run: [APSDaemon] "C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [MSC] "c:\Program Files\Microsoft Security Client\msseces.exe" -hide -runkey
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [StartCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [EEventManager] "C:\Program Files\Epson Software\Event Manager\EEventManager.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [Rest Reminder] C:\Users\Hamad\Desktop\Tools\RestReminder.exe hide
O4 - HKCU\..\Run: [Google Update] "C:\Users\Hamad\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe
O4 - HKCU\..\Run: [MzRAMBooster] C:\Program Files\Mz Ultimate Tools\Mz RAM Booster\MzRAMBooster.exe
O4 - HKCU\..\Run: [GoogleDriveSync] "C:\Program Files\Google\Drive\googledrivesync.exe" /autostart
O4 - HKCU\..\Run: [eType] C:\Users\Hamad\AppData\Roaming\eType\eType.exe
O4 - HKCU\..\Run: [EPLTarget\P0000000000000000] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_TATIHTE.EXE /EPT "EPLTarget\P0000000000000000" /M "Epson Stylus SX535WD"
O4 - HKCU\..\Run: [3E5B51B1070B4BCA0B1B83988C3ED26C78D7DD3E._service_run] "C:\Users\Hamad\AppData\Local\Google\Chrome\Application\chrome.exe" --type=service
O4 - HKCU\..\Run: [Policies] C:\System32\chost.exe
O4 - HKCU\..\Run: [HydraVisionDesktopManager] "C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe"
O4 - Startup: EvernoteClipper.lnk = C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
O4 - Startup: EvernoteTray.lnk = C:\Program Files\Evernote\Evernote\EvernoteTray.exe
O4 - Startup: GoalSync 3.0.lnk = C:\Program Files\Success Studios\GoalSync 3.0\GoalSync3.exe
O4 - Startup: iMindMap Preloader.lnk = C:\Users\Hamad\.thinkbuzan\imindmap\preload\iMindMap_Preloader.exe
O4 - Startup: OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe
O4 - Global Startup: Start 3DxWare.lnk = C:\Program Files\3Dconnexion\3Dconnexion 3DxSoftware\3DxWare\3dxsrv.exe
O8 - Extra context menu item: Add to Evernote 4.0 - res://C:\Program Files\Evernote\Evernote\EvernoteIE.dll/204
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Bluetooth\Bluetooth Software\btsendto_ie_ctx.htm
O9 - Extra button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra 'Tools' menuitem: @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll
O9 - Extra button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra 'Tools' menuitem: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - res://C:\Program Files\Evernote\Evernote\EvernoteIE.dll/204 (file missing)
O9 - Extra button: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Users\Hamad\Desktop\PartyCasino.lnk (HKCU)
O9 - Extra 'Tools' menuitem: PartyCasino - {B4B52284-A248-4c51-9F7C-F0A0C67FCC9D} - C:\Users\Hamad\Desktop\PartyCasino.lnk (HKCU)
O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Hamad\Desktop\PartyPoker.lnk (HKCU)
O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Users\Hamad\Desktop\PartyPoker.lnk (HKCU)
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O17 - HKLM\System\CCS\Services\Tcpip\..\{2F9F615D-0349-47F8-BFC3-B16499BF9FB0}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{4FEE97B2-80F1-4C1E-B131-9DCF5475DE71}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CCS\Services\Tcpip\..\{DF758A09-D2E2-4787-8764-22389FC697B6}: NameServer = 10.93.120.1
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O20 - AppInit_DLLs: C:\Windows\system32\guard32.dll
O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll
O23 - Service: ABBYY FineReader 9.0 Sprint Licensing Service (ABBYY.Licensing.FineReader.Sprint.9.0) - ABBYY - C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\system32\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exe
O23 - Service: AMD FUEL Service - Advanced Micro Devices, Inc. - C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: COMODO Internet Security Helper Service (cmdAgent) - COMODO - C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
O23 - Service: DCService.exe - Unknown owner - C:\ProgramData\DatacardService\DCService.exe
O23 - Service: FibUacService - Unknown owner - C:\ProgramData\Clickfree\FullImagingBackup\FibUac.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Flexera Software, Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: FullImagingService - Unknown owner - C:\programdata\Clickfree\FullImagingBackup\FullImagingService.exe (file missing)
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: Hotspot Shield Service (hshld) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\bin\openvpnas.exe
O23 - Service: Hotspot Shield Routing Service (HssSrv) - AnchorFree Inc. - C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
O23 - Service: Hotspot Shield Tray Service (HssTrayService) - Unknown owner - C:\Program Files\Hotspot Shield\bin\HssTrayService.EXE
O23 - Service: Hotspot Shield Monitoring Service (HssWd) - Unknown owner - C:\Program Files\Hotspot Shield\bin\hsswd.exe
O23 - Service: Updater Service (IBUpdaterService) - Unknown owner - C:\ProgramData\IBUpdaterService\ibsvc.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: Autodesk Moldflow Inventor Tool Suite Integration 2012 Job Manager (mitsijm2012) - Autodesk, Inc. - C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe
O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: OpenVPN Service (OpenVPNService) - Unknown owner - C:\Program Files\HMA! Pro VPN\bin\openvpnserv.exe
O23 - Service: PACSPTISVR-Sound_Organizer - Sony Corporation - C:\Program Files\Sony\Sound Organizer\Sony.Earth\PACSPTISVR.exe
O23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
O23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe
O23 - Service: TeamViewer 7 (TeamViewer7) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe

--
End of file - 14799 bytes

Thank you

Edited by hamadm, 23 September 2012 - 12:35 PM.

  • 0

Advertisements


#2
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Hi there unfortunately Hijackthis is no longer man enough for the job, it misses a lot of malware points

Download OTL to your Desktop
  • Double click on the icon to run it. Make sure all other windows are closed and to let it run uninterrupted.
    Posted Image
  • Select All Users
  • Under the Custom Scan box paste this in
    netsvcs
    BASESERVICES
    %SYSTEMDRIVE%\*.exe
    /md5start
    services.*
    explorer.exe
    winlogon.exe
    Userinit.exe
    svchost.exe
    qmgr.dll
    /md5stop
    CREATERESTOREPOINT
  • Click the Quick Scan button. Do not change any settings unless otherwise told to do so. The scan wont take long.
  • When the scan completes, it will open two notepad windows. OTL.Txt and Extras.Txt. These are saved in the same location as OTL.
  • Post both logs

THEN

Download aswMBR.exe ( 4.8mb ) to your desktop.
Double click the aswMBR.exe to run it Click the "Scan" button to start scan

Posted Image

On completion of the scan click save log, save it to your desktop and post in your next reply

Posted Image
  • 0

#3
hamadm

hamadm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
here is the OTL


OTL logfile created on: 23/09/2012 23:45:20 - Run 1
OTL by OldTimer - Version 3.2.66.0 Folder = C:\Users\Hamad\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.32 Gb Available Physical Memory | 65.92% Memory free
4.23 Gb Paging File | 2.87 Gb Available in Paging File | 67.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 177.14 Gb Free Space | 38.03% Space Free | Partition Type: NTFS

Computer Name: HAMAD-PC | User Name: Hamad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/09/23 23:35:02 | 000,601,600 | ---- | M] (OldTimer Tools) -- C:\Users\Hamad\Desktop\OTL.exe
PRC - [2012/09/21 02:51:47 | 000,212,432 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe
PRC - [2012/09/15 05:17:27 | 000,212,432 | ---- | M] (Google Inc.) -- C:\Users\Hamad\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler.exe
PRC - [2012/09/14 04:33:34 | 000,412,016 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
PRC - [2012/09/14 04:33:34 | 000,388,976 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\hsswd.exe
PRC - [2012/09/14 03:03:54 | 000,511,344 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
PRC - [2012/08/14 10:52:28 | 001,014,624 | ---- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) -- C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
PRC - [2012/07/27 23:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/26 05:31:33 | 000,219,008 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\spool\drivers\w32x86\3\E_TATIHTE.EXE
PRC - [2012/07/24 15:38:42 | 002,327,208 | ---- | M] (DSNR Media Innovations) -- C:\Users\Hamad\AppData\Roaming\eType\eTypeUpdate.exe
PRC - [2012/07/16 17:31:32 | 002,673,064 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2012/06/16 23:49:54 | 000,397,848 | ---- | M] () -- C:\ProgramData\IBUpdaterService\ibsvc.exe
PRC - [2012/06/11 20:19:36 | 000,468,992 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2012/06/11 20:19:02 | 000,217,600 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2012/06/11 13:10:58 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
PRC - [2012/03/26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/03/12 00:13:21 | 001,983,232 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2010/12/07 17:28:06 | 000,579,384 | ---- | M] (Autodesk, Inc.) -- C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe
PRC - [2010/10/12 13:56:40 | 000,979,328 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
PRC - [2010/08/19 11:52:14 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
PRC - [2010/08/19 11:52:04 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe
PRC - [2009/05/14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
PRC - [2009/04/11 09:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/04/11 09:27:20 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
PRC - [2008/12/31 13:12:40 | 000,693,512 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
PRC - [2008/12/30 12:01:52 | 017,059,840 | R--- | M] (VIA) -- C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
PRC - [2008/12/10 16:16:18 | 000,380,928 | ---- | M] (AMD) -- C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe
PRC - [2006/12/23 18:05:20 | 000,143,360 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2006/12/23 18:04:42 | 000,905,216 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/14 03:35:25 | 000,240,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\9104e78d8897df008eed3a2af3bda6a2\WindowsFormsIntegration.ni.dll
MOD - [2012/06/14 03:35:22 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012/06/14 03:33:30 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012/06/14 03:33:23 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012/06/14 03:33:12 | 014,329,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7343fbab1ba137db2f8b284047ef3f3c\PresentationFramework.ni.dll
MOD - [2012/06/14 03:32:45 | 012,219,392 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b6293b0c23321c255c2530aea8e32bb\PresentationCore.ni.dll
MOD - [2012/06/11 19:24:32 | 000,037,376 | ---- | M] () -- C:\Windows\System32\atitmpxx.dll
MOD - [2012/06/11 13:11:04 | 000,095,232 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
MOD - [2012/06/11 12:45:06 | 000,369,152 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2012/05/26 14:37:04 | 002,295,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\0f2b877ed16daa577f95be735a63d19c\System.Core.ni.dll
MOD - [2012/05/26 14:36:49 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012/05/26 14:36:40 | 000,060,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\5fd0071c259b92078ced7cd752a14730\UIAutomationProvider.ni.dll
MOD - [2012/05/26 14:36:37 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012/05/26 14:22:58 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012/05/26 14:22:03 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c8c3ab08933fef9fb6657da871395c46\PresentationFramework.Aero.ni.dll
MOD - [2012/05/26 14:21:34 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\54426ee1881b42af5b090e223f43823c\WindowsBase.ni.dll
MOD - [2012/05/26 14:21:31 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/26 14:21:24 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2012/03/16 15:42:58 | 000,315,392 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libtidy.dll
MOD - [2012/03/16 15:42:56 | 000,433,664 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libxml2.dll
MOD - [2012/02/13 14:02:19 | 001,736,984 | ---- | M] () -- C:\Windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/04/13 18:45:44 | 000,109,464 | ---- | M] () -- C:\Users\Hamad\AppData\Roaming\eType\MyZip.dll
MOD - [2008/05/30 05:38:22 | 000,069,632 | R--- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
MOD - [2008/03/17 12:50:00 | 000,069,632 | R--- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll
MOD - [2008/02/14 08:57:00 | 000,094,208 | R--- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\VMicApi.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\programdata\Clickfree\FullImagingBackup\FullImagingService.exe -- (FullImagingService)
SRV - File not found [Auto | Stopped] -- C:\ProgramData\Clickfree\FullImagingBackup\FibUac.exe -- (FibUacService)
SRV - [2012/09/14 04:33:34 | 000,412,016 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
SRV - [2012/09/14 04:33:34 | 000,388,976 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2012/09/14 03:03:54 | 000,511,344 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (hshld)
SRV - [2012/09/14 00:08:34 | 000,078,072 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hotspot Shield\bin\HSSTrayService.exe -- (HssTrayService)
SRV - [2012/09/08 05:13:43 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/27 23:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/16 17:31:32 | 002,673,064 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012/06/16 23:49:54 | 000,397,848 | ---- | M] () [Auto | Running] -- C:\ProgramData\IBUpdaterService\ibsvc.exe -- (IBUpdaterService)
SRV - [2012/06/11 20:19:02 | 000,217,600 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2012/06/11 13:10:58 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV - [2012/03/26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/03/12 00:13:21 | 001,983,232 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011/08/27 08:44:38 | 001,044,816 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/07/13 17:00:16 | 000,036,352 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\HMA! Pro VPN\bin\openvpnserv.exe -- (OpenVPNService)
SRV - [2011/06/23 14:25:20 | 000,157,544 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Sound Organizer\Sony.Earth\PACSPTISVR.exe -- (PACSPTISVR-Sound_Organizer)
SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2010/12/07 17:28:06 | 000,579,384 | ---- | M] (Autodesk, Inc.) [Auto | Running] -- C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe -- (mitsijm2012)
SRV - [2010/08/19 11:52:04 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe)
SRV - [2009/05/14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) [Auto | Running] -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0)
SRV - [2008/12/31 13:12:44 | 000,910,600 | ---- | M] (Raxco Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe -- (PD91Engine)
SRV - [2008/12/31 13:12:40 | 000,693,512 | ---- | M] (Raxco Software, Inc.) [Auto | Running] -- C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe -- (PD91Agent)
SRV - [2008/01/18 23:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/05/31 09:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 09:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- D:\NTGLM7X.sys -- (SetupNTGLM7X)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\NTACCESS.sys -- (NTACCESS)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\install4\MSICPL.sys -- (MSICPL)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\btwusb.sys -- (BTWUSB)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2012/09/22 11:40:47 | 000,152,576 | ---- | M] (SysProgs.org) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BazisPortableCDBus.sys -- (BazisPortableCDBus)
DRV - [2012/07/10 05:48:18 | 000,035,560 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\hssdrv6.sys -- (HssDRV6)
DRV - [2012/06/11 21:58:44 | 008,733,696 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2012/06/11 19:25:48 | 000,295,936 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2012/03/20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012/03/12 00:13:29 | 000,082,400 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\inspect.sys -- (inspect)
DRV - [2012/03/12 00:13:28 | 000,038,616 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2012/03/12 00:13:26 | 000,491,816 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\System32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2012/02/23 15:31:36 | 000,083,984 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdLH3.sys -- (AtiHDAudioService)
DRV - [2012/02/16 00:24:36 | 000,181,432 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2012/02/16 00:24:36 | 000,080,824 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2012/01/05 02:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2011/12/01 05:46:38 | 000,021,992 | ---- | M] (Silicon Laboratories) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SiUSBXp.sys -- (SIUSBXP)
DRV - [2011/07/13 17:00:14 | 000,026,112 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tap0901.sys -- (tap0901)
DRV - [2010/06/01 14:07:14 | 000,116,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2010/05/22 14:48:20 | 000,070,656 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2010/03/25 10:08:38 | 000,105,984 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010/03/20 11:56:04 | 000,101,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010/02/18 09:18:22 | 000,037,944 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\amdiox86.sys -- (amdiox86)
DRV - [2009/08/05 06:18:22 | 000,048,640 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1E60x86.sys -- (L1E)
DRV - [2009/04/11 07:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB)
DRV - [2009/01/05 14:16:36 | 000,071,184 | R--- | M] (Raxco Software, Inc.) [File_System | Auto | Running] -- C:\Windows\System32\drivers\DefragFS.sys -- (DefragFS)
DRV - [2008/12/19 06:40:06 | 000,923,136 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2008/04/28 16:26:42 | 000,014,352 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie)
DRV - [2008/03/19 18:28:52 | 000,022,072 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\usbfilter.sys -- (usbfilter)
DRV - [2006/10/18 15:44:48 | 000,007,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2786678


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://badoo.com/startpage/
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 00 6F 08 3F 02 CD 01 [binary data]
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\SearchScopes\{8A244612-A1F7-11E0-95C0-E71F4824019B}: "URL" = http://badoo.com/sta...q={searchTerms}
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2786678
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Hamad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Hamad\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Hamad\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Hamad\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)



========== Chrome ==========

CHR - homepage: http://www.google.co...=en&source=iglk
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage: http://www.google.co...=en&source=iglk
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Hamad\AppData\Local\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Hamad\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Hamad\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Hamad\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Hamad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Hamad\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U5 (Enabled) = C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

O1 HOSTS File: ([2006/09/19 00:41:30 | 000,000,761 | ---- | M]) - C:\Windows\System32\drivers\etc\hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
O3 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O3 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [EPLTarget\P0000000000000000] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_TATIHTE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [eType] C:\Users\Hamad\AppData\Roaming\eType\eType.exe (DSNR Media Innovations)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe (AMD)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [MzRAMBooster] C:\Program Files\Mz Ultimate Tools\Mz RAM Booster\MzRAMBooster.exe (Mz Ultimate Tools)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [POEngine5] File not found
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [Policies] C:\System32\chost.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [Rest Reminder] C:\Users\Hamad\Desktop\Tools\RestReminder.exe (NGCoders)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe ()
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteTray.lnk = C:\Program Files\Evernote\Evernote\EvernoteTray.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GoalSync 3.0.lnk = C:\Program Files\Success Studios\GoalSync 3.0\GoalSync3.exe (Success Studios)
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iMindMap Preloader.lnk = C:\Users\Hamad\.thinkbuzan\imindmap\preload\iMindMap_Preloader.exe ()
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Bluetooth\Bluetooth Software\btsendto_ie_ctx.htm File not found
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.7.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{04692C57-3E14-4E03-B576-8DA1A24E6C0C}: DhcpNameServer = 84.235.107.122 84.235.107.123
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{13C7E60A-EF6A-432C-9B82-4D89CB7AA6D2}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F9F615D-0349-47F8-BFC3-B16499BF9FB0}: DhcpNameServer = 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F9F615D-0349-47F8-BFC3-B16499BF9FB0}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4FEE97B2-80F1-4C1E-B131-9DCF5475DE71}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ACA39361-FD78-46FC-9FC5-63B2976D2B1D}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B5DDAC35-B3E7-4933-A271-708A75D296A3}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF758A09-D2E2-4787-8764-22389FC697B6}: NameServer = 10.93.120.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EFF4DFDD-2EF5-41DD-9FEE-70475D11B0B7}: DhcpNameServer = 84.235.107.250 84.235.107.251
O20 - AppInit_DLLs: (C:\Windows\system32\guard32.dll) - C:\Windows\System32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 00:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0906f0d7-0aea-11e1-aee9-e53dc77dbff0}\Shell - "" = AutoRun
O33 - MountPoints2\{0906f0d7-0aea-11e1-aee9-e53dc77dbff0}\Shell\AutoRun\command - "" = E:\FIBPGuard.exe
O33 - MountPoints2\{0af632fe-f214-11e1-9214-e8d63c07d8bd}\Shell - "" = AutoRun
O33 - MountPoints2\{0af632fe-f214-11e1-9214-e8d63c07d8bd}\Shell\AutoRun\command - "" = E:\Autorun.exe
O33 - MountPoints2\{4c3be28b-e6d8-11e0-bee2-001e101f2500}\Shell - "" = AutoRun
O33 - MountPoints2\{4c3be28b-e6d8-11e0-bee2-001e101f2500}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{4c3be2de-e6d8-11e0-bee2-001e101f79c9}\Shell - "" = AutoRun
O33 - MountPoints2\{4c3be2de-e6d8-11e0-bee2-001e101f79c9}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{7152b1de-da97-11e0-a371-001e101f3315}\Shell - "" = AutoRun
O33 - MountPoints2\{7152b1de-da97-11e0-a371-001e101f3315}\Shell\AutoRun\command - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{7152b1de-da97-11e0-a371-001e101f3315}\Shell\start\COMMAND - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{834dd50f-dc90-11e0-bda7-001e101f8924}\Shell - "" = AutoRun
O33 - MountPoints2\{834dd50f-dc90-11e0-bda7-001e101f8924}\Shell\AutoRun\command - "" = G:\FIBPGuard.exe
O33 - MountPoints2\{99142b42-da3b-11e0-822b-001e101fb681}\Shell - "" = AutoRun
O33 - MountPoints2\{99142b42-da3b-11e0-822b-001e101fb681}\Shell\AutoRun\command - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{99142b42-da3b-11e0-822b-001e101fb681}\Shell\start\COMMAND - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{99142b44-da3b-11e0-822b-001e101fb681}\Shell - "" = AutoRun
O33 - MountPoints2\{99142b44-da3b-11e0-822b-001e101fb681}\Shell\AutoRun\command - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{99142b44-da3b-11e0-822b-001e101fb681}\Shell\start\COMMAND - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{b3351883-cf35-11e0-95a6-e57d28a13cad}\Shell - "" = AutoRun
O33 - MountPoints2\{b3351883-cf35-11e0-95a6-e57d28a13cad}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{bbc7ab38-042d-11e2-8b30-d85d19b1fac9}\Shell - "" = AutoRun
O33 - MountPoints2\{bbc7ab38-042d-11e2-8b30-d85d19b1fac9}\Shell\AutoRun\command - "" = E:\LiveTutDVD.exe
O33 - MountPoints2\{c46d67fb-cca5-11e1-9820-892c994a8b31}\Shell - "" = AutoRun
O33 - MountPoints2\{c46d67fb-cca5-11e1-9820-892c994a8b31}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{cbb33115-eb72-11e0-b1ef-00248ca430af}\Shell - "" = AutoRun
O33 - MountPoints2\{cbb33115-eb72-11e0-b1ef-00248ca430af}\Shell\AutoRun\command - "" = E:\setup.exe
O33 - MountPoints2\{cbb33148-eb72-11e0-b1ef-00248ca430af}\Shell - "" = AutoRun
O33 - MountPoints2\{cbb33148-eb72-11e0-b1ef-00248ca430af}\Shell\AutoRun\command - "" = E:\setup.exe
O34 - HKLM BootExecute: (PDBoot.exe)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

NetSvcs: FastUserSwitchingCompatibility - File not found
NetSvcs: Ias - C:\Windows\System32\ias.dll (Microsoft Corporation)
NetSvcs: Nla - File not found
NetSvcs: Ntmssvc - File not found
NetSvcs: NWCWorkstation - File not found
NetSvcs: Nwsapagent - File not found
NetSvcs: SRService - File not found
NetSvcs: WmdmPmSp - File not found
NetSvcs: LogonHours - File not found
NetSvcs: PCAudit - File not found
NetSvcs: helpsvc - File not found
NetSvcs: uploadmgr - File not found

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2012/09/23 23:36:30 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Hamad\Desktop\aswMBR.exe
[2012/09/23 23:34:47 | 000,601,600 | ---- | C] (OldTimer Tools) -- C:\Users\Hamad\Desktop\OTL.exe
[2012/09/22 19:54:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Propellerhead Software
[2012/09/19 21:01:53 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\NP3
[2012/09/19 20:54:39 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\MWS
[2012/09/19 20:54:39 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\MindWorkStation
[2012/09/19 20:54:39 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Mind WorkStation Sessions
[2012/09/19 20:44:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mind WorkStation
[2012/09/19 20:43:52 | 000,000,000 | ---D | C] -- C:\Program Files\Mind WorkStation
[2012/09/19 19:00:06 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\NeuroProgrammer3
[2012/09/19 19:00:06 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Neuro-Programmer 3 Documents
[2012/09/19 18:59:54 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\Xenocode
[2012/09/19 18:59:54 | 000,000,000 | ---D | C] -- C:\Program Files\Xenocode
[2012/09/19 18:46:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Neuro-Programmer 3
[2012/09/19 18:46:24 | 000,000,000 | ---D | C] -- C:\Program Files\Neuro-Programmer 3
[2012/09/18 23:33:02 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Ableton
[2012/09/18 23:33:02 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Ableton
[2012/09/18 23:20:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Ableton
[2012/09/11 21:42:14 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Mozilla
[2012/09/11 08:52:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/09/08 17:46:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Holdem Indicator
[2012/09/08 17:45:43 | 000,000,000 | ---D | C] -- C:\Program Files\Holdem Indicator
[2012/09/08 17:24:13 | 000,000,000 | ---D | C] -- C:\Users\Hamad\PokerOffice
[2012/09/08 17:23:58 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerOffice5
[2012/09/08 17:22:18 | 000,000,000 | ---D | C] -- C:\Program Files\PokerOffice5
[2012/09/06 08:12:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PartyCasino
[2012/09/06 07:36:13 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\betonline
[2012/09/06 07:35:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetOnline Poker 8.2
[2012/09/06 07:35:16 | 000,000,000 | ---D | C] -- C:\Program Files\BetOnline Poker 8.2
[2012/09/06 07:07:18 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Mozilla-Cache
[2012/09/06 07:06:07 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Party
[2012/09/06 07:05:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PartyPoker
[2012/09/06 07:01:57 | 000,000,000 | ---D | C] -- C:\Programs
[2012/09/02 00:21:53 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\dvd
[2012/09/02 00:14:43 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\DVD Flick
[2012/09/02 00:14:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Flick
[2012/09/02 00:14:23 | 000,040,960 | ---- | C] (vbAccelerator) -- C:\Windows\System32\ssubtmr6.dll
[2012/09/02 00:14:23 | 000,036,864 | ---- | C] (Robdogg Inc.) -- C:\Windows\System32\trayicon_handler.ocx
[2012/09/02 00:14:22 | 000,028,672 | ---- | C] (-) -- C:\Windows\System32\mousewheel.ocx
[2012/09/02 00:14:22 | 000,000,000 | ---D | C] -- C:\Program Files\DVD Flick
[2012/09/01 18:39:07 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\NeroVision
[2012/08/31 11:04:25 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\Ubisoft Game Launcher
[2012/08/31 10:20:17 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Ubisoft
[2012/08/31 10:04:55 | 000,000,000 | ---D | C] -- C:\Program Files\Ubisoft
[2012/08/31 10:03:55 | 000,000,000 | -H-D | C] -- C:\Users\Hamad\InstallAnywhere
[2012/08/30 12:40:49 | 000,000,000 | -H-D | C] -- C:\Windows\PIF
[2012/08/28 00:29:32 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TriDef 3D
[2012/08/28 00:29:02 | 000,000,000 | ---D | C] -- C:\ProgramData\DDD
[2012/08/28 00:28:47 | 000,000,000 | ---D | C] -- C:\Program Files\TriDef 3D
[2012/08/28 00:20:48 | 000,000,000 | ---D | C] -- C:\Program Files\MonitorDriver
[2012/08/27 02:36:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
[2012/08/27 01:52:56 | 000,000,000 | ---D | C] -- C:\Windows\CheckSur
[2012/08/27 01:10:27 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\dvdcss
[2012/08/27 00:53:26 | 002,808,832 | R--- | C] (RealTek Semicoductor Corp.) -- C:\Windows\alcwzrd.exe
[2012/08/27 00:53:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\RTCOM
[2012/08/27 00:52:10 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek
[2012/08/26 01:56:50 | 000,000,000 | -HSD | C] -- C:\$RECYCLE.BIN
[2012/08/26 01:55:53 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\Temp
[2012/08/25 19:24:31 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Desktop\New Folder
[2012/08/25 19:24:21 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Books
[2012/08/25 19:24:18 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\dynamic trading workshop
[2012/08/25 19:24:17 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Desktop icons
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2012/09/23 23:57:15 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/23 23:39:32 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Hamad\Desktop\aswMBR.exe
[2012/09/23 23:35:02 | 000,601,600 | ---- | M] (OldTimer Tools) -- C:\Users\Hamad\Desktop\OTL.exe
[2012/09/23 23:22:06 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3562748159-1388759733-2883167963-1000UA.job
[2012/09/23 23:18:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/23 22:25:48 | 000,004,176 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/23 22:25:48 | 000,004,176 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/23 20:35:22 | 000,046,080 | ---- | M] () -- C:\Users\Hamad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/23 18:26:12 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/23 18:25:12 | 2146,623,488 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/22 20:03:15 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012/09/22 11:44:31 | 000,660,296 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/09/22 11:44:31 | 000,126,518 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/09/22 11:40:47 | 000,152,576 | ---- | M] (SysProgs.org) -- C:\Windows\System32\drivers\BazisPortableCDBus.sys
[2012/09/22 05:22:00 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3562748159-1388759733-2883167963-1000Core.job
[2012/09/19 21:02:01 | 000,000,924 | ---- | M] () -- C:\Users\Public\Desktop\Neuro-Programmer 3.lnk
[2012/09/19 20:44:02 | 000,000,895 | ---- | M] () -- C:\Users\Public\Desktop\Mind WorkStation.lnk
[2012/09/19 16:38:26 | 000,000,749 | ---- | M] () -- C:\Users\Hamad\Desktop\Ableton Live 8.lnk
[2012/09/10 17:00:42 | 000,010,063 | -H-- | M] () -- C:\Users\Hamad\AppData\Roaming\Hamadlog.dat
[2012/09/08 17:46:05 | 000,000,919 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Holdem Indicator.lnk
[2012/09/08 17:46:05 | 000,000,895 | ---- | M] () -- C:\Users\Hamad\Desktop\Holdem Indicator.lnk
[2012/09/08 17:23:59 | 000,001,740 | ---- | M] () -- C:\Users\Hamad\Desktop\PokerOffice 5.lnk
[2012/09/06 08:12:37 | 000,001,667 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyCasino.lnk
[2012/09/06 08:12:36 | 000,001,643 | ---- | M] () -- C:\Users\Hamad\Desktop\PartyCasino.lnk
[2012/09/06 07:35:36 | 000,001,810 | ---- | M] () -- C:\Users\Public\Desktop\BetOnline Poker 8.2.lnk
[2012/09/06 07:05:54 | 000,001,667 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
[2012/09/06 07:05:54 | 000,001,643 | ---- | M] () -- C:\Users\Hamad\Desktop\PartyPoker.lnk
[2012/09/03 03:18:08 | 000,002,004 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/09/02 00:14:32 | 000,001,699 | ---- | M] () -- C:\Users\Hamad\Desktop\DVD Flick.lnk
[2012/08/30 03:17:41 | 000,177,640 | ---- | M] () -- C:\Users\Hamad\Documents\SetupData.trx
[2012/08/30 03:17:40 | 000,007,599 | ---- | M] () -- C:\Users\Hamad\Documents\ReviewActions.xml
[2012/08/30 02:52:09 | 000,000,725 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Evernote.lnk
[2012/08/30 02:51:55 | 000,000,825 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\YNAB 3.lnk
[2012/08/30 02:51:51 | 000,001,011 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\iMindMap 5.lnk
[2012/08/28 18:16:40 | 000,002,133 | ---- | M] () -- C:\Users\Public\Desktop\SyncMaster 3D Game Launcher (TriDef 3D).lnk
[2012/08/27 16:07:24 | 000,177,640 | ---- | M] () -- C:\Users\Hamad\Documents\SetupData.bak.trx
[2012/08/27 02:44:47 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini
[2012/08/26 14:08:57 | 000,371,128 | ---- | M] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/08/26 04:16:26 | 000,000,000 | ---- | M] () -- C:\Windows\EEventManager.INI
[1 C:\Windows\*.tmp files -> C:\Windows\*.tmp -> ]

========== Files Created - No Company Name ==========

[2012/09/19 20:44:02 | 000,000,895 | ---- | C] () -- C:\Users\Public\Desktop\Mind WorkStation.lnk
[2012/09/19 18:46:46 | 000,000,924 | ---- | C] () -- C:\Users\Public\Desktop\Neuro-Programmer 3.lnk
[2012/09/19 16:38:26 | 000,000,749 | ---- | C] () -- C:\Users\Hamad\Desktop\Ableton Live 8.lnk
[2012/09/18 23:20:26 | 000,000,749 | ---- | C] () -- C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ableton Live 8.lnk
[2012/09/08 17:46:05 | 000,000,919 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Holdem Indicator.lnk
[2012/09/08 17:46:05 | 000,000,895 | ---- | C] () -- C:\Users\Hamad\Desktop\Holdem Indicator.lnk
[2012/09/08 17:23:58 | 000,001,740 | ---- | C] () -- C:\Users\Hamad\Desktop\PokerOffice 5.lnk
[2012/09/06 08:12:37 | 000,001,667 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyCasino.lnk
[2012/09/06 08:12:36 | 000,001,643 | ---- | C] () -- C:\Users\Hamad\Desktop\PartyCasino.lnk
[2012/09/06 07:35:36 | 000,001,810 | ---- | C] () -- C:\Users\Public\Desktop\BetOnline Poker 8.2.lnk
[2012/09/06 07:05:54 | 000,001,667 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
[2012/09/06 07:05:54 | 000,001,643 | ---- | C] () -- C:\Users\Hamad\Desktop\PartyPoker.lnk
[2012/09/02 00:14:32 | 000,001,699 | ---- | C] () -- C:\Users\Hamad\Desktop\DVD Flick.lnk
[2012/08/30 02:52:09 | 000,000,725 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Evernote.lnk
[2012/08/30 02:51:55 | 000,000,825 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\YNAB 3.lnk
[2012/08/30 02:51:51 | 000,001,011 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\iMindMap 5.lnk
[2012/08/28 00:29:39 | 000,002,133 | ---- | C] () -- C:\Users\Public\Desktop\SyncMaster 3D Game Launcher (TriDef 3D).lnk
[2012/08/27 02:44:47 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2012/08/27 00:53:23 | 000,143,360 | R--- | C] () -- C:\Windows\System32\RtlCPAPI.dll
[2012/08/27 00:53:23 | 000,049,152 | R--- | C] () -- C:\Windows\System32\ChCfg.exe
[2012/08/26 04:16:53 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2012/08/26 04:16:26 | 000,000,000 | ---- | C] () -- C:\Windows\EEventManager.INI
[2012/08/25 19:28:31 | 000,000,908 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3562748159-1388759733-2883167963-1000UA.job
[2012/08/25 19:28:31 | 000,000,884 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/08/25 19:28:31 | 000,000,830 | ---- | C] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/08/25 19:28:30 | 000,660,296 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2012/08/25 19:28:30 | 000,126,518 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2012/08/25 19:28:30 | 000,004,176 | -H-- | C] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/08/25 19:28:30 | 000,004,176 | -H-- | C] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/08/25 19:28:30 | 000,000,880 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/08/25 19:28:30 | 000,000,856 | ---- | C] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3562748159-1388759733-2883167963-1000Core.job
[2012/08/25 19:27:04 | 000,002,004 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/08/25 19:26:28 | 000,046,080 | ---- | C] () -- C:\Users\Hamad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/25 19:24:20 | 022,657,136 | ---- | C] () -- C:\Users\Hamad\Documents\vlc-2.0.2-win32.exe
[2012/08/25 19:24:20 | 000,563,952 | ---- | C] () -- C:\Users\Hamad\Documents\bookmarks_12_12_11.html
[2012/08/25 19:24:19 | 000,023,613 | ---- | C] () -- C:\Users\Hamad\Documents\Untitled 1.ods
[2012/08/23 02:02:40 | 000,000,022 | ---- | C] () -- C:\Windows\cmm.dat
[2012/08/23 02:02:39 | 000,001,746 | ---- | C] () -- C:\Windows\Language_trs.ini
[2012/08/23 02:02:39 | 000,000,426 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012/08/23 02:02:25 | 000,038,090 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2012/08/23 02:02:25 | 000,000,264 | ---- | C] () -- C:\Windows\Brownie.ini
[2012/08/23 02:02:24 | 000,030,320 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2012/08/23 02:02:24 | 000,000,011 | ---- | C] () -- C:\Windows\BRVIDEO.INI
[2012/08/23 02:02:24 | 000,000,000 | ---- | C] () -- C:\Windows\brmx2001.ini
[2012/08/23 02:02:24 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/08/23 02:00:10 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2012/08/23 01:38:53 | 000,159,232 | ---- | C] () -- C:\Windows\System32\clinfo.exe
[2012/08/23 01:38:51 | 000,179,271 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2012/08/23 01:38:47 | 000,000,186 | ---- | C] () -- C:\Windows\System32\CleanMem.ini
[2012/08/23 01:38:45 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2012/08/23 01:38:45 | 000,003,917 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2012/08/23 01:38:44 | 000,645,632 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2012/08/23 01:38:44 | 000,637,743 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2012/08/23 01:38:41 | 000,000,034 | ---- | C] () -- C:\Windows\System32\BXD2140.DAT
[2012/08/23 01:38:27 | 000,037,376 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2012/08/23 01:38:21 | 000,043,008 | ---- | C] () -- C:\Windows\System32\spwini.dll
[2012/08/23 01:38:15 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2012/08/23 01:38:15 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2012/08/23 01:38:09 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2012/08/23 01:38:06 | 000,062,976 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2012/08/23 01:37:32 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2012/08/23 01:37:29 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2012/08/23 01:37:26 | 000,371,128 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/08/23 01:37:25 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2012/08/23 01:37:21 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2012/08/23 01:37:21 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2012/08/23 01:37:21 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2012/08/23 01:32:58 | 000,007,680 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys
[2012/08/23 01:32:56 | 000,010,296 | ---- | C] () -- C:\Windows\System32\drivers\ASUSHWIO.SYS
[2012/08/23 01:26:54 | 000,031,274 | ---- | C] () -- C:\Users\Hamad\.TransferManager.db
[2012/08/23 01:26:02 | 000,037,845 | ---- | C] () -- C:\Users\Hamad\AppData\Roaming\Comma Separated Values (Windows).ADR
[2012/08/23 01:26:02 | 000,000,630 | ---- | C] () -- C:\Users\Hamad\AppData\Roaming\lazy_remote_server_settings.dat
[2012/08/23 01:24:34 | 000,001,356 | ---- | C] () -- C:\Users\Hamad\AppData\Local\d3d9caps.dat
[2006/07/27 02:34:15 | 000,010,063 | -H-- | C] () -- C:\Users\Hamad\AppData\Roaming\Hamadlog.dat

========== ZeroAccess Check ==========

[2006/11/02 15:54:18 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 20:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 09:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/08/23 01:25:44 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\.thinkingrock
[2012/08/23 01:25:50 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\3Dconnexion
[2012/09/22 19:54:32 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Ableton
[2012/08/23 01:25:30 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Arduino
[2012/08/23 01:25:30 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Autodesk
[2012/09/06 07:36:13 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\betonline
[2012/08/23 01:25:51 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Business Logic
[2012/08/23 01:25:57 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\com.conqu
[2012/08/23 01:25:49 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\com.youneedabudget.YNAB3.Live.9C763150EFAB05FD2A2B78705C7A54E2FCDDE07D.1
[2012/08/23 01:25:50 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Epson
[2012/09/23 23:35:24 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\eType
[2012/08/23 01:25:49 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Fritzing
[2012/08/23 01:25:49 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\HabitShaper
[2012/08/23 01:25:51 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Klok2.DD7F2188B985C2439837C76B42A187050457E61B.1
[2012/09/19 21:01:28 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\MindWorkStation
[2012/09/19 19:24:26 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\NeuroProgrammer3
[2012/08/23 01:25:46 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\OpenOffice.org
[2012/09/06 07:11:26 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Party
[2012/08/23 01:25:28 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Softland
[2012/08/23 01:26:02 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\TeamViewer
[2012/09/23 23:35:20 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\uTorrent
[2012/08/23 01:25:51 | 000,000,000 | -HSD | M] -- C:\Users\Hamad\AppData\Roaming\wyUpdate AU

========== Purity Check ==========



========== Custom Scans ==========

========== Base Services ==========
SRV - [2006/11/02 12:46:02 | 000,024,576 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\aelupsvc.dll -- (AeLookupSvc)
SRV - [2008/01/18 23:33:44 | 000,033,280 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\appinfo.dll -- (Appinfo)
SRV - [2008/01/18 23:33:02 | 000,059,392 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\alg.exe -- (ALG)
SRV - [2009/04/11 09:28:23 | 000,758,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\qmgr.dll -- (BITS)
SRV - [2009/04/11 09:28:18 | 000,334,848 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\BFE.DLL -- (BFE)
SRV - [2011/11/16 17:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\lsass.exe -- (KeyIso)
SRV - [2009/04/11 09:28:19 | 000,268,800 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\es.dll -- (EventSystem)
SRV - [2008/01/18 23:33:50 | 000,081,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\browser.dll -- (Browser)
SRV - [2012/04/23 19:00:53 | 000,133,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\cryptsvc.dll -- (CryptSvc)
SRV - [2009/04/11 09:28:24 | 000,550,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (DcomLaunch)
SRV - [2009/04/11 09:28:18 | 000,204,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dhcpcsvc.dll -- (Dhcp)
SRV - [2011/03/02 18:44:27 | 000,086,528 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\dnsrslvr.dll -- (Dnscache)
SRV - [2008/01/18 23:34:10 | 000,057,344 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\eapsvc.dll -- (EapHost)
SRV - [2009/04/11 09:28:19 | 000,026,112 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\hidserv.dll -- (hidserv)
SRV - [2008/01/18 23:34:36 | 000,288,256 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\ipnathlp.dll -- (SharedAccess)
SRV - [2009/04/11 09:28:20 | 000,364,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\IPSECSVC.DLL -- (PolicyAgent)
SRV - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/03/26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2009/04/11 09:28:24 | 000,311,808 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\swprv.dll -- (swprv)
SRV - [2008/01/18 23:34:50 | 000,045,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\mmcss.dll -- (MMCSS)
SRV - [2008/01/18 23:35:38 | 000,274,432 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\netman.dll -- (Netman)
SRV - [2008/01/18 23:35:38 | 000,237,056 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\netprofm.dll -- (netprofm)
SRV - [2008/01/18 23:35:40 | 000,168,448 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nlasvc.dll -- (NlaSvc)
SRV - [2008/01/18 23:35:58 | 000,018,432 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\nsisvc.dll -- (nsi)
SRV - [2009/04/11 09:28:25 | 000,222,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\umpnpmgr.dll -- (PlugPlay)
SRV - [2010/08/17 17:11:37 | 000,128,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\spoolsv.exe -- (Spooler)
SRV - [2011/11/16 17:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\lsass.exe -- (ProtectedStorage)
SRV - [2009/04/11 09:28:19 | 000,564,224 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\emdmgmt.dll -- (EMDMgmt)
SRV - [2008/01/18 23:36:16 | 000,090,624 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\rasauto.dll -- (RasAuto)
SRV - [2009/04/11 09:28:24 | 000,262,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\rasmans.dll -- (RasMan)
SRV - [2009/04/11 09:28:24 | 000,550,400 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\rpcss.dll -- (RpcSs)
SRV - [2008/01/18 23:36:22 | 000,019,968 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\seclogon.dll -- (seclogon)
SRV - [2011/11/16 17:12:25 | 000,009,728 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\lsass.exe -- (SamSs)
SRV - [2009/04/11 09:28:26 | 000,061,440 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wscsvc.dll -- (wscsvc)
SRV - [2010/09/06 19:20:29 | 000,125,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\srvsvc.dll -- (LanmanServer)
SRV - [2009/07/10 14:47:42 | 000,247,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (ShellHWDetection)
SRV - [2009/04/11 09:27:49 | 003,408,896 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\SLsvc.exe -- (slsvc)
SRV - [2010/11/04 21:55:12 | 000,601,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\schedsvc.dll -- (Schedule)
SRV - [2009/04/11 09:28:24 | 000,242,688 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\System32\tapisrv.dll -- (TapiSrv)
SRV - [2009/07/10 14:47:42 | 000,247,808 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\shsvcs.dll -- (Themes)
SRV - [2009/04/11 09:28:23 | 000,153,088 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\profsvc.dll -- (ProfSvc)
SRV - [2009/04/11 09:28:10 | 001,055,232 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\VSSVC.exe -- (VSS)
SRV - [2009/04/11 09:28:18 | 000,315,392 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (Audiosrv)
SRV - [2009/04/11 09:28:18 | 000,315,392 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\audiosrv.dll -- (AudioEndpointBuilder)
SRV - [2008/01/18 23:36:22 | 000,104,960 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\sdrsvc.dll -- (SDRSVC)
SRV - [2008/01/18 23:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2009/04/11 09:28:25 | 001,017,856 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wevtsvc.dll -- (Eventlog)
SRV - [2009/04/11 09:28:20 | 000,407,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\MPSSVC.dll -- (MpsSvc)
SRV - [2009/04/11 09:28:25 | 000,453,120 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wiaservc.dll -- (stisvc)
SRV - [2009/04/11 09:27:45 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\msiexec.exe -- (msiserver)
SRV - [2009/04/11 09:28:25 | 000,162,304 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wbem\WMIsvc.dll -- (Winmgmt)
SRV - [2012/06/03 01:19:17 | 001,933,848 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wuaueng.dll -- (wuauserv)
SRV - [2009/04/11 09:28:18 | 000,175,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\dot3svc.dll -- (dot3svc)
SRV - [2011/08/26 08:54:24 | 000,513,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\System32\wlansvc.dll -- (Wlansvc)
SRV - [2011/08/26 08:41:30 | 000,160,256 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\System32\wkssvc.dll -- (LanmanWorkstation)

< %SYSTEMDRIVE%\*.exe >

< MD5 for: EXPLORER.EXE >
[2011/08/26 08:29:20 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=37440D09DEAE0B672A04DCCF7ABF06BE -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16771_none_4f83bb287ccdb7e3\explorer.exe
[2011/08/26 08:29:19 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=4F554999D7D5F05DAAEBBA7B5BA1089D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18164_none_5177ca9879e978e8\explorer.exe
[2011/08/26 08:29:19 | 002,927,616 | ---- | M] (Microsoft Corporation) MD5=50BA5850147410CDE89C523AD3BC606E -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.22298_none_51e4f8c7931bd1e1\explorer.exe
[2011/08/26 08:55:54 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=6D06CD98D954FE87FB2DB8108793B399 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16549_none_4fac29707cae347a\explorer.exe
[2011/08/26 08:55:54 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=BD06F0BF753BC704B653C3A50F89D362 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20668_none_501f261995dcf2cf\explorer.exe
[2009/04/11 09:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\explorer.exe
[2009/04/11 09:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) MD5=D07D4C3038F3578FFCE1C0237F2A1253 -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6002.18005_none_53a0201e76de3a0b\explorer.exe
[2011/08/26 08:29:20 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=E7156B0B74762D9DE0E66BDCDE06E5FB -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.20947_none_5033cb5995cd990b\explorer.exe
[2006/11/02 12:45:07 | 002,923,520 | ---- | M] (Microsoft Corporation) MD5=FD8C53FB002217F6F888BCF6F5D7084D -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6000.16386_none_4f7de5167cd15deb\explorer.exe
[2008/01/18 23:33:12 | 002,927,104 | ---- | M] (Microsoft Corporation) MD5=FFA764631CB70A30065C12EF8E174F9F -- C:\Windows\winsxs\x86_microsoft-windows-explorer_31bf3856ad364e35_6.0.6001.18000_none_51b4a71279bc6ebf\explorer.exe

< MD5 for: QMGR.DLL >
[2008/01/18 23:36:14 | 000,758,272 | ---- | M] (Microsoft Corporation) MD5=02ED7B4DBC2A3232A389106DA7515C3D -- C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6001.18000_none_2390c4ecf9720b8c\qmgr.dll
[2006/11/02 12:46:12 | 000,749,568 | ---- | M] (Microsoft Corporation) MD5=733FB484A06B9D6A44DD9CA1D3BE937B -- C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6000.16386_none_215a02f0fc86fab8\qmgr.dll
[2009/04/11 09:28:23 | 000,758,784 | ---- | M] (Microsoft Corporation) MD5=93952506C6D67330367F7E7934B6A02F -- C:\Windows\System32\qmgr.dll
[2009/04/11 09:28:23 | 000,758,784 | ---- | M] (Microsoft Corporation) MD5=93952506C6D67330367F7E7934B6A02F -- C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6002.18005_none_257c3df8f693d6d8\qmgr.dll
[2011/08/26 07:29:52 | 000,750,080 | ---- | M] (Microsoft Corporation) MD5=DA551697E34D2B9943C8B1C8EAFFE89A -- C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6000.16531_none_218b14e6fc62ea9e\qmgr.dll
[2011/08/26 07:29:52 | 000,750,080 | ---- | M] (Microsoft Corporation) MD5=F1148566FA5173A4FD48AF8E8BC09401 -- C:\Windows\winsxs\x86_microsoft-windows-bits-client_31bf3856ad364e35_6.0.6000.20647_none_220fe38215833e63\qmgr.dll

< MD5 for: SERVICES >
[2006/09/19 00:41:30 | 000,017,244 | ---- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 -- C:\Windows\System32\drivers\etc\services
[2006/09/19 00:41:30 | 000,017,244 | ---- | M] () MD5=9F534244B7F8F55D5C0BB498D8D481E7 -- C:\Windows\winsxs\x86_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.0.6000.16386_none_024e4071fa6fea95\services

< MD5 for: SERVICES.CFG >
[2012/07/27 23:51:34 | 000,586,083 | ---- | M] () MD5=6DE4EA437EC1FE6DB27CADB0A7EA8DC2 -- C:\Program Files\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 12:55:30 | 000,584,045 | R--- | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.EXE >
[2008/01/18 23:33:30 | 000,279,040 | ---- | M] (Microsoft Corporation) MD5=2B336AB6286D6C81FA02CBAB914E3C6C -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.exe
[2006/11/02 12:45:40 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=329CF3C97CE4C19375C8ABCABAE258B0 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.exe
[2009/04/11 09:27:59 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B -- C:\Windows\System32\services.exe
[2009/04/11 09:27:59 | 000,279,552 | ---- | M] (Microsoft Corporation) MD5=D4E6D91C1349B7BFB3599A6ADA56851B -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2006/11/02 15:40:57 | 000,017,920 | ---- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C -- C:\Windows\System32\en-US\services.exe.mui
[2006/11/02 15:40:57 | 000,017,920 | ---- | M] (Microsoft Corporation) MD5=1626EACF0E7E59F85C59DDDD27C4169C -- C:\Windows\winsxs\x86_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.0.6000.16386_en-us_67c6851b290a1ced\services.exe.mui

< MD5 for: SERVICES.HTML >
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\AppData\Local\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\Local Settings\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\AppData\Local\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\AppData\Local\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\Local Settings\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\Local Settings\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:23:24 | 000,099,505 | ---- | M] () MD5=9E7613BE4A45E68BF8DFD1751A256177 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\components\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\AppData\Local\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\Local Settings\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\AppData\Local\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\AppData\Local\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\Local Settings\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\Local Settings\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html
[2012/07/10 09:24:18 | 000,062,034 | ---- | M] () MD5=DB8D325CB00CDF3F8D0EB0F229070BA0 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\docs\guide\topics\ui\accessibility\services.html

< MD5 for: SERVICES.JAVA >
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\AppData\Local\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\Local Settings\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Documents and Settings\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\AppData\Local\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\AppData\Local\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\AppData\Local\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\Local Settings\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\Local Settings\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java
[2012/07/10 18:35:48 | 000,006,748 | R--- | M] () MD5=411111AD775B441DDCC5D4EFF612F591 -- C:\Users\Hamad\Local Settings\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Android\android-sdk\sources\android-16\org\apache\harmony\security\fortress\Services.java

< MD5 for: SERVICES.LNK >
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Documents and Settings\All Users\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\ProgramData\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Application Data\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2011/08/26 21:35:08 | 000,001,688 | ---- | M] () MD5=326F2F5D0CC46383B21B1E9B739417D2 -- C:\Users\All Users\Start Menu\Programs\Administrative Tools\services.lnk
File not found Unable to obtain MD5 -- C:\Documents and Settings\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
File not found Unable to obtain MD5 -- C:\Users\All Users\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Application Data\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk

< MD5 for: SERVICES.MOF >
[2006/09/19 00:46:11 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\System32\wbem\services.mof
[2006/09/19 00:46:11 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6000.16386_none_cd28fe6bd05df036\services.mof
[2006/09/19 00:46:11 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6001.18000_none_cf5fc067cd49010a\services.mof
[2006/09/19 00:46:11 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\x86_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.0.6002.18005_none_d14b3973ca6acc56\services.mof

< MD5 for: SERVICES.MSC >
[2006/11/02 15:41:32 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\en-US\services.msc
[2006/09/19 00:29:40 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\System32\services.msc
[2006/11/02 15:41:32 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.0.6000.16386_en-us_a2085506ff73b6e0\services.msc
[2006/09/19 00:29:40 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6000.16386_none_cd2d20a848cfd40f\services.msc
[2006/09/19 00:29:40 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.0.6001.18000_none_cf63e2a445bae4e3\services.msc

< MD5 for: SERVICES.RDB >
[2011/01/17 18:52:22 | 000,237,568 | ---- | M] () MD5=507957679AE4579C15D57FA741EA6FFA -- C:\Program Files\OpenOffice.org 3\URE\misc\services.rdb
[2011/01/17 18:51:48 | 005,539,328 | ---- | M] () MD5=F2B666905F7FDAA80C86A101A7DE62F9 -- C:\Program Files\OpenOffice.org 3\Basis\program\services.rdb

< MD5 for: SVCHOST.EXE >
[2006/11/02 12:45:47 | 000,022,016 | ---- | M] (Microsoft Corporation) MD5=10DA15933D582D2FEDCF705EFE394B09 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6000.16386_none_b38497a50862ad11\svchost.exe
[2008/01/18 23:33:34 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\System32\svchost.exe
[2008/01/18 23:33:34 | 000,021,504 | ---- | M] (Microsoft Corporation) MD5=3794B461C45882E06856F282EEF025AF -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.0.6001.18000_none_b5bb59a1054dbde5\svchost.exe

< MD5 for: USERINIT.EXE >
[2008/01/18 23:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\System32\userinit.exe
[2008/01/18 23:33:34 | 000,025,088 | ---- | M] (Microsoft Corporation) MD5=0E135526E9785D085BCD9AEDE6FBCBF9 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6001.18000_none_dc28ba15d1aff80b\userinit.exe
[2006/11/02 12:45:50 | 000,024,576 | ---- | M] (Microsoft Corporation) MD5=22027835939F86C3E47AD8E3FBDE3D11 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.0.6000.16386_none_d9f1f819d4c4e737\userinit.exe

< MD5 for: WINLOGON.EXE >
[2009/04/11 09:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\System32\winlogon.exe
[2009/04/11 09:28:13 | 000,314,368 | ---- | M] (Microsoft Corporation) MD5=898E7C06A350D4A1A64A9EA264D55452 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6002.18005_none_71ae7a22d2134741\winlogon.exe
[2006/11/02 12:45:57 | 000,308,224 | ---- | M] (Microsoft Corporation) MD5=9F75392B9128A91ABAFB044EA350BAAD -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6000.16386_none_6d8c3f1ad8066b21\winlogon.exe
[2008/01/18 23:33:38 | 000,314,880 | ---- | M] (Microsoft Corporation) MD5=C2610B6BDBEFC053BBDAB4F1B965CB24 -- C:\Windows\winsxs\x86_microsoft-windows-winlogon_31bf3856ad364e35_6.0.6001.18000_none_6fc30116d4f17bf5\winlogon.exe

========== Alternate Data Streams ==========

@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:157E1AD3
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:5FC93B4C

< End of report >


And the Extras



OTL Extras logfile created on: 23/09/2012 23:45:21 - Run 1
OTL by OldTimer - Version 3.2.66.0 Folder = C:\Users\Hamad\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.32 Gb Available Physical Memory | 65.92% Memory free
4.23 Gb Paging File | 2.87 Gb Available in Paging File | 67.74% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 177.14 Gb Free Space | 38.03% Space Free | Partition Type: NTFS

Computer Name: HAMAD-PC | User Name: Hamad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\System32\control.exe (Microsoft Corporation)
.hlp [@ = hlpfile] -- C:\Windows\winhlp32.exe (Microsoft Corporation)

========== Shell Spawning ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
hlpfile [open] -- %SystemRoot%\winhlp32.exe %1 (Microsoft Corporation)
htmlfile [edit] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" %1 (Microsoft Corporation)
htmlfile [print] -- "C:\Program Files\Microsoft Office\Office14\msohtmed.exe" /p %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [AddToPlaylistVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --playlist-enqueue "%1" ()
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Directory [PlayWithVLC] -- "C:\Program Files\VideoLAN\VLC\vlc.exe" --started-from-file --no-playlist-enqueue "%1" ()
Folder [open] -- %SystemRoot%\Explorer.exe /separate,/idlist,%I,%L (Microsoft Corporation)
Folder [explore] -- %SystemRoot%\Explorer.exe /separate,/e,/idlist,%I,%L (Microsoft Corporation)
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)

========== Security Center Settings ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0
"VistaSp1" = Reg Error: Unknown registry data type -- File not found
"VistaSp2" = Reg Error: Unknown registry data type -- File not found

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"DisableNotifications" = 0
"EnableFirewall" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{001C202E-DCF1-4C8E-A1DF-4671E8C96E46}" = lport=50699 | protocol=17 | dir=in | name=canon capt port |
"{012AD73B-0750-4B0E-A5A6-10C06D232437}" = lport=65430 | protocol=17 | dir=in | name=canon capt port |
"{027E5DE8-37EC-40C9-9A01-052C7C04E13F}" = lport=62389 | protocol=17 | dir=in | name=canon capt port |
"{02E12C1D-A94D-4433-B9DC-CB7FEFD24318}" = lport=139 | protocol=6 | dir=in | app=system |
"{03DA8D3D-BAD3-4D47-AB42-BCAE032DD37C}" = lport=49443 | protocol=17 | dir=in | name=canon capt port |
"{042A6287-429F-42A8-A128-4662FD1FDEFE}" = lport=58431 | protocol=17 | dir=in | name=canon capt port |
"{044D6475-99B1-4292-9D86-82A91E36ED85}" = lport=61737 | protocol=17 | dir=in | name=canon capt port |
"{04D5CC9E-C292-4DA6-9D95-0C0040ADD85D}" = lport=55290 | protocol=17 | dir=in | name=canon capt port |
"{050F921E-0D43-424F-BE06-E5636CEF6A5C}" = lport=64252 | protocol=17 | dir=in | name=canon capt port |
"{056337F5-F2CC-464B-A3FF-2AD90311650A}" = lport=60511 | protocol=17 | dir=in | name=canon capt port |
"{0856146A-6F36-42E5-8EF0-D6251899926C}" = lport=58726 | protocol=17 | dir=in | name=canon capt port |
"{09671180-4ADC-400C-9BAE-E26C77135296}" = lport=54546 | protocol=17 | dir=in | name=canon capt port |
"{09C05562-E6E6-4137-AF70-D5B8F4F5FA20}" = lport=59140 | protocol=17 | dir=in | name=canon capt port |
"{0AFF8CD2-B668-4658-B016-F1FD2E157516}" = lport=54613 | protocol=17 | dir=in | name=canon capt port |
"{0B7E13A5-AA07-426E-AE4F-B1D4185D5A68}" = lport=62204 | protocol=17 | dir=in | name=canon capt port |
"{0C000A0D-8926-439E-82A3-269CB9ED4203}" = lport=56767 | protocol=17 | dir=in | name=canon capt port |
"{0D6E3E20-9F0C-4F51-A75C-D9A531359785}" = lport=54768 | protocol=17 | dir=in | name=canon capt port |
"{0DC689A5-F39B-4D59-A673-41970A5142A6}" = lport=64601 | protocol=17 | dir=in | name=canon capt port |
"{0E3B41B6-9150-45A2-8646-B6A66549B7BF}" = lport=52053 | protocol=17 | dir=in | name=canon capt port |
"{0FBEC32D-AF93-4871-91FB-584C2A2D9BC0}" = lport=55551 | protocol=17 | dir=in | name=canon capt port |
"{10CCD072-89F4-4B6B-9E56-7D5462D13290}" = lport=61152 | protocol=17 | dir=in | name=canon capt port |
"{10EB8845-95E9-431C-87EA-890DB892A593}" = lport=56216 | protocol=17 | dir=in | name=canon capt port |
"{11651230-A5F5-4395-AE14-76D64F91D410}" = lport=50300 | protocol=17 | dir=in | name=canon capt port |
"{117336D7-B38A-42A0-80C7-E29B01B7B189}" = lport=58629 | protocol=17 | dir=in | name=canon capt port |
"{127F7AA8-227C-4296-B8EC-52448375627D}" = lport=52980 | protocol=17 | dir=in | name=canon capt port |
"{13384D59-8EA4-430A-AAEA-D9F6D2B7B971}" = lport=61943 | protocol=17 | dir=in | name=canon capt port |
"{135550DA-72FA-48DF-8C46-7BBDDAC53756}" = lport=990 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{1432F43E-8B3D-4710-BE8F-4DF407B5EBF8}" = lport=56582 | protocol=17 | dir=in | name=canon capt port |
"{157CC23A-3688-4A30-A5A3-6549BD616BEA}" = lport=54890 | protocol=17 | dir=in | name=canon capt port |
"{161EA713-1925-4621-B409-7B1134B103AB}" = lport=54930 | protocol=17 | dir=in | name=canon capt port |
"{16D48A84-C099-4E40-9AC6-7962831C2254}" = lport=62019 | protocol=17 | dir=in | name=canon capt port |
"{17273114-6A32-4B6A-B309-7834262B00A5}" = lport=65209 | protocol=17 | dir=in | name=canon capt port |
"{1759ECBB-99C2-41B2-9B30-686D2BA2FAC9}" = lport=63251 | protocol=17 | dir=in | name=canon capt port |
"{18A19606-2623-4995-989C-CCD3E394EAEA}" = lport=49157 | protocol=17 | dir=in | name=canon capt port |
"{18AD340E-C6ED-4A0E-850E-2B15CD16512F}" = lport=58024 | protocol=17 | dir=in | name=canon capt port |
"{198BD974-135A-4825-B587-A2734D116775}" = lport=54251 | protocol=17 | dir=in | name=canon capt port |
"{199684E4-1D08-4AD8-90A3-ADF4F3C8665B}" = lport=62665 | protocol=17 | dir=in | name=canon capt port |
"{1A9F5115-7189-4EA6-86C8-FC575BA897A1}" = lport=26675 | protocol=6 | dir=in | [email protected]%systemroot%\windowsmobile\wmdcbase.exe,-4006 |
"{1AB64C3C-2620-48D7-BAC0-1AC12C649192}" = lport=59820 | protocol=17 | dir=in | name=canon capt port |
"{1B744674-B572-4249-8239-8863D3A1ED8C}" = lport=50646 | protocol=17 | dir=in | name=canon capt port |
"{1CA40ED3-729B-483F-BE64-D98E0D101507}" = lport=5678 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{1F30C4D5-188C-4FED-9484-697C85B22E43}" = lport=55762 | protocol=17 | dir=in | name=canon capt port |
"{212C0530-11B0-4D85-BCE3-9EEB66DFEB15}" = lport=51449 | protocol=17 | dir=in | name=canon capt port |
"{21EF43AE-3582-40B3-8F23-644C3F5441B8}" = lport=65445 | protocol=17 | dir=in | name=canon capt port |
"{2266F039-1F6B-4651-B84B-5C731B119EB2}" = lport=49155 | protocol=17 | dir=in | name=canon capt port |
"{22942064-083D-42B2-A923-A7F4C73D9644}" = lport=63224 | protocol=17 | dir=in | name=canon capt port |
"{234499DA-385B-450E-8AE0-CEC904CD523B}" = lport=50586 | protocol=17 | dir=in | name=canon capt port |
"{2348A9A7-6FBD-4E12-91A2-94BEA1F1F26B}" = lport=54521 | protocol=17 | dir=in | name=canon capt port |
"{2470FAC9-C10F-4034-B46C-68DBA0CBEA21}" = lport=51760 | protocol=17 | dir=in | name=canon capt port |
"{253B40FB-71DB-46A3-AB80-6C9CDBE06AF6}" = lport=64256 | protocol=17 | dir=in | name=canon capt port |
"{264DE1B2-5B8A-475B-AC0E-683F156529BB}" = lport=64803 | protocol=17 | dir=in | name=canon capt port |
"{2684F620-C7CD-4AE3-BDF2-654B973576FC}" = lport=55833 | protocol=17 | dir=in | name=canon capt port |
"{26C9C55A-7AB6-4A8E-86F5-FC8EEE91CE3B}" = lport=63015 | protocol=17 | dir=in | name=canon capt port |
"{2A642E3B-7408-42A3-8FC6-088F438BA197}" = lport=54493 | protocol=17 | dir=in | name=canon capt port |
"{2C7AA0BF-1089-467C-A46D-1E05C1DFA47F}" = lport=51256 | protocol=17 | dir=in | name=canon capt port |
"{2CE8C34F-DF6D-4E22-9A98-AB04DA78CD50}" = lport=54517 | protocol=17 | dir=in | name=canon capt port |
"{2CFD2F20-9A6B-4750-9DC5-E4D85A4BE512}" = lport=59035 | protocol=17 | dir=in | name=canon capt port |
"{2D532F72-B916-483C-99AB-7760C439DFA7}" = lport=53935 | protocol=17 | dir=in | name=canon capt port |
"{2E834062-D12F-45A2-88AF-D4D0E6E535FA}" = lport=56147 | protocol=17 | dir=in | name=canon capt port |
"{2EDB7521-9AA9-4787-9036-5AFE473DEC72}" = lport=54567 | protocol=17 | dir=in | name=canon capt port |
"{2F024EBE-CB13-4EAF-B8BD-25CFC82A9D12}" = lport=58179 | protocol=17 | dir=in | name=canon capt port |
"{31383455-EC8E-4383-BD43-44AF8F143B25}" = lport=60692 | protocol=17 | dir=in | name=canon capt port |
"{3166BB8F-5125-41E6-9832-1175F62E95E7}" = lport=55803 | protocol=17 | dir=in | name=canon capt port |
"{31DB6BC0-E72A-4F5E-AB1A-D2B0D9D4F2DC}" = lport=52309 | protocol=17 | dir=in | name=canon capt port |
"{3206D275-15C1-4BC8-A077-02A0FE16005C}" = lport=62672 | protocol=17 | dir=in | name=canon capt port |
"{3250F1D3-6229-43B5-B24E-EDA74A5318B4}" = lport=58646 | protocol=17 | dir=in | name=canon capt port |
"{325417D4-DA28-49EC-AE50-7027C4965C51}" = lport=58423 | protocol=17 | dir=in | name=canon capt port |
"{32AEFAC6-6002-4DCF-BD31-79A78ABF5B62}" = lport=50767 | protocol=17 | dir=in | name=canon capt port |
"{32EEF025-51D3-4676-B38B-1A511A8F5BA9}" = lport=55734 | protocol=17 | dir=in | name=canon capt port |
"{344447EB-2F68-411A-B844-9937D9E70019}" = lport=56611 | protocol=17 | dir=in | name=canon capt port |
"{35261734-90FD-4A8E-B830-62803012B20A}" = lport=61024 | protocol=17 | dir=in | name=canon capt port |
"{3751A1ED-9D14-4B4F-8FC9-EBDA606F7AF1}" = lport=999 | protocol=6 | dir=in | app=%systemroot%\windowsmobile\wmdhost.exe |
"{3856540D-481D-4A96-A4BF-3044A57AE28D}" = lport=138 | protocol=17 | dir=in | app=system |
"{388064E0-5C92-4E33-B4D2-B8708F8D7B8A}" = lport=51075 | protocol=17 | dir=in | name=canon capt port |
"{39BCAA70-0F3A-4785-97BC-C60A00D08E21}" = lport=63604 | protocol=17 | dir=in | name=canon capt port |
"{3A4A6AA0-B662-4CB3-B78F-76B5E37D4FF9}" = lport=51564 | protocol=17 | dir=in | name=canon capt port |
"{3B8CCED1-8AFD-4DF3-8100-9E3FEFE3797B}" = lport=56736 | protocol=17 | dir=in | name=canon capt port |
"{3BA8EBCF-61EF-400D-B255-3C70F7968D3B}" = lport=60797 | protocol=17 | dir=in | name=canon capt port |
"{3E84D2F0-C556-4868-ACFA-90377DD59FFE}" = lport=65044 | protocol=17 | dir=in | name=canon capt port |
"{3FA6FBF0-EE53-4E46-B06D-3C5437AA385B}" = lport=56139 | protocol=17 | dir=in | name=canon capt port |
"{3FE9E893-B3F6-4702-8BC6-FF95DA61BFFC}" = lport=59204 | protocol=17 | dir=in | name=canon capt port |
"{4065D165-CFB4-4A77-A149-A39EFC6459FE}" = lport=60509 | protocol=17 | dir=in | name=canon capt port |
"{4154DE94-0523-44C4-96A5-1E31559DB623}" = lport=59229 | protocol=17 | dir=in | name=canon capt port |
"{41CF031C-93C7-4F90-B42F-CA52A686DA9C}" = lport=5721 | protocol=6 | dir=in | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{432BE5A9-0AC7-47AE-8CF6-852CED9F07FB}" = lport=54233 | protocol=17 | dir=in | name=canon capt port |
"{441EBD55-675D-414D-A037-C99614023103}" = lport=63151 | protocol=17 | dir=in | name=canon capt port |
"{445B28B1-290C-45A7-BDCA-55962A30E5E8}" = lport=52242 | protocol=17 | dir=in | name=canon capt port |
"{44F5A725-9742-4E4B-839D-33AB266D6076}" = lport=50070 | protocol=17 | dir=in | name=canon capt port |
"{46896673-2055-4CB7-B777-F193A7EF0161}" = lport=51791 | protocol=17 | dir=in | name=canon capt port |
"{47870D6D-7936-4946-B84C-1AFB01C6E706}" = lport=63229 | protocol=17 | dir=in | name=canon capt port |
"{48885D9E-AE36-44A4-B9D8-B9F81AE472A4}" = lport=50443 | protocol=17 | dir=in | name=canon capt port |
"{4A8AF410-DAFD-4C85-868E-E626A352A227}" = lport=58689 | protocol=17 | dir=in | name=canon capt port |
"{4AEB5BC5-9F76-481D-BCAD-48862CAD9B25}" = lport=49548 | protocol=17 | dir=in | name=canon capt port |
"{4AECF507-1915-40B4-9438-8B17E65A9B65}" = rport=445 | protocol=6 | dir=out | app=system |
"{4B1D9885-A6CE-4E66-A983-FB7EFC330D4B}" = lport=55102 | protocol=17 | dir=in | name=canon capt port |
"{4C8C95AB-9C9A-4806-8513-C6FCECE9621C}" = lport=59441 | protocol=17 | dir=in | name=canon capt port |
"{4CF9D042-8E15-4910-BB90-D42496150EC8}" = lport=60134 | protocol=17 | dir=in | name=canon capt port |
"{4E975627-E955-495A-94A4-C8B342AE4D8E}" = lport=53824 | protocol=17 | dir=in | name=canon capt port |
"{4F115785-6854-419E-BFDF-BB4179BAC07F}" = lport=61223 | protocol=17 | dir=in | name=canon capt port |
"{50B4A63E-B5C9-4315-8D79-EC2428E1D4B4}" = lport=55452 | protocol=17 | dir=in | name=canon capt port |
"{527D86A6-0E10-43F6-81C0-65397256DE49}" = lport=49561 | protocol=17 | dir=in | name=canon capt port |
"{53254341-455E-48AE-94B0-39B97DC5D5DC}" = lport=58594 | protocol=17 | dir=in | name=canon capt port |
"{5353C73F-D1C4-4DDF-BACE-8202A31E6E74}" = lport=54828 | protocol=17 | dir=in | name=canon capt port |
"{539DFB54-9D29-4B30-84A7-2FF9097C56F1}" = lport=56860 | protocol=17 | dir=in | name=canon capt port |
"{53D60B4B-122C-4FD0-99C5-6A10C2B44B74}" = lport=60431 | protocol=17 | dir=in | name=canon capt port |
"{53EF1697-1EC3-4B69-AFE5-DDBE466005BD}" = lport=65216 | protocol=17 | dir=in | name=canon capt port |
"{5419698D-CDEF-4315-AA60-2D189C7F34AC}" = lport=55807 | protocol=17 | dir=in | name=canon capt port |
"{56A529EB-BCB0-4938-B678-ACEFD60A674C}" = lport=64619 | protocol=17 | dir=in | name=canon capt port |
"{58A3D3C6-2437-4DB7-AB06-0FBDBB8EC4EC}" = rport=139 | protocol=6 | dir=out | app=system |
"{59509BAE-D7ED-44C3-9569-A1AC42E6C709}" = lport=52136 | protocol=17 | dir=in | name=canon capt port |
"{59B0B70E-344D-410B-886E-641317890D71}" = lport=62655 | protocol=17 | dir=in | name=canon capt port |
"{5BE44654-0432-434D-A514-4F7AE4FDC66A}" = lport=62408 | protocol=17 | dir=in | name=canon capt port |
"{5C7090F1-64EC-478F-A4D9-4CB05EEE9267}" = lport=62041 | protocol=17 | dir=in | name=canon capt port |
"{5CA410D6-7774-4601-8B12-CC648CE7BAB3}" = lport=52946 | protocol=17 | dir=in | name=canon capt port |
"{5D117037-7432-41C7-9C9E-D9D5E8F8CD97}" = lport=58285 | protocol=17 | dir=in | name=canon capt port |
"{5F6AFB2B-DD0B-4473-885D-042E97C706FC}" = lport=60969 | protocol=17 | dir=in | name=canon capt port |
"{6025F8A9-7C19-4C3A-8688-A1DE5B61F2EC}" = lport=57813 | protocol=17 | dir=in | name=canon capt port |
"{605DB946-ADE4-41AE-ABE7-505DAFD2CFEB}" = lport=52342 | protocol=17 | dir=in | name=canon capt port |
"{60BA7D97-57E5-4687-AAD7-6B451A533B9F}" = lport=64151 | protocol=17 | dir=in | name=canon capt port |
"{60FCB8B1-6E51-4AE8-B77A-173FF3A560F5}" = lport=62961 | protocol=17 | dir=in | name=canon capt port |
"{612E0798-3D8E-4C78-B29C-8DC6F8FC489B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{623BA645-FDD5-4DB0-8790-2177F16CAA38}" = lport=61689 | protocol=17 | dir=in | name=canon capt port |
"{63B2FE0E-14AE-42FF-A6CE-1265F7710315}" = lport=50460 | protocol=17 | dir=in | name=canon capt port |
"{63ED584D-E214-4E92-BC95-9BAADB6868A9}" = lport=55546 | protocol=17 | dir=in | name=canon capt port |
"{64830AE4-9F6A-4B67-A18D-F1D6AFDFC8D9}" = lport=59234 | protocol=17 | dir=in | name=canon capt port |
"{64C57AA8-A3A5-44D7-B9DA-61BD64FB9AD7}" = lport=51768 | protocol=17 | dir=in | name=canon capt port |
"{6711A148-9556-49BC-9BB5-5AFF5AA1B85F}" = lport=54217 | protocol=17 | dir=in | name=canon capt port |
"{67658567-28C8-479D-B5C9-C176536161F3}" = lport=64941 | protocol=17 | dir=in | name=canon capt port |
"{6885B799-5898-409D-8ACC-B6B7BBE97197}" = lport=49968 | protocol=17 | dir=in | name=canon capt port |
"{689645A4-22E5-4A1F-86D9-EEBCB9E1BE26}" = lport=62198 | protocol=17 | dir=in | name=canon capt port |
"{68CDE852-334F-49CF-9CE3-B1BC13111B5A}" = lport=61604 | protocol=17 | dir=in | name=canon capt port |
"{703E3DB5-0135-4791-8AF8-E760A84C87FB}" = lport=61818 | protocol=17 | dir=in | name=canon capt port |
"{71AC3DEC-6332-4853-A4F8-A3CE9CB4B202}" = lport=62571 | protocol=17 | dir=in | name=canon capt port |
"{72A924FF-8EBB-4E48-8C40-DD2F17EBAC9B}" = lport=55304 | protocol=17 | dir=in | name=canon capt port |
"{73979BD9-30D3-4C66-A3BB-59CCF4255D9A}" = lport=52302 | protocol=17 | dir=in | name=canon capt port |
"{74F50389-C041-4FFC-B194-31DEE216331D}" = lport=54693 | protocol=17 | dir=in | name=canon capt port |
"{7946CECD-3A96-4A34-AB5D-0FF6F1D62360}" = lport=59364 | protocol=17 | dir=in | name=canon capt port |
"{79BD7243-5F01-46CF-BCC6-1ED4FC833A5A}" = lport=61346 | protocol=17 | dir=in | name=canon capt port |
"{79D6B69C-EED2-476F-A212-610F4C3099A1}" = lport=55322 | protocol=17 | dir=in | name=canon capt port |
"{7B332D64-BFBC-48F2-B7FA-537D04672A27}" = lport=50230 | protocol=17 | dir=in | name=canon capt port |
"{7BF62A23-2CCD-458D-8487-503C4E194EE5}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{7D105A62-1736-4ABA-90A9-593033462560}" = lport=56192 | protocol=17 | dir=in | name=canon capt port |
"{7DA36881-C942-4436-94B0-E59B6D526320}" = lport=62066 | protocol=17 | dir=in | name=canon capt port |
"{7ECA9F58-4B6E-4DDA-ABCF-4DB540F674BE}" = lport=63544 | protocol=17 | dir=in | name=canon capt port |
"{7EFE33B4-D774-4B49-9ED8-B6C0F1681EB2}" = lport=60104 | protocol=17 | dir=in | name=canon capt port |
"{7F1422D6-1E25-4398-8E0C-B9AE1664C9FB}" = lport=53394 | protocol=17 | dir=in | name=canon capt port |
"{82777478-7F34-4C70-9AE4-A56400E26847}" = lport=55645 | protocol=17 | dir=in | name=canon capt port |
"{8303310F-8B92-47B0-BF9D-ED13EF3EC1E7}" = lport=57207 | protocol=17 | dir=in | name=canon capt port |
"{839F1C88-5822-48BF-AD08-C8118E64A536}" = lport=51548 | protocol=17 | dir=in | name=canon capt port |
"{866DE3F7-A833-48BE-BD98-E19710624123}" = lport=51490 | protocol=17 | dir=in | name=canon capt port |
"{881DB1F0-92F4-41A0-85ED-CAC281946241}" = lport=63894 | protocol=17 | dir=in | name=canon capt port |
"{88CCFAEE-2D62-400A-82D4-D317877F5380}" = lport=57518 | protocol=17 | dir=in | name=canon capt port |
"{899EFE33-9623-4B6A-83B3-43518CBE644A}" = lport=50903 | protocol=17 | dir=in | name=canon capt port |
"{8CB8B2E3-186F-414F-8471-B2078FFB6B57}" = lport=58456 | protocol=17 | dir=in | name=canon capt port |
"{8CF860DE-7B1B-431C-84E1-D99D10608570}" = lport=65328 | protocol=17 | dir=in | name=canon capt port |
"{8D759A2F-411E-4FC7-B4B7-FD90CA3574EC}" = lport=53182 | protocol=17 | dir=in | name=canon capt port |
"{8E627CCB-B64C-4EA1-ABEC-9E4237C44B65}" = lport=60742 | protocol=17 | dir=in | name=canon capt port |
"{8E6E5C96-567E-4BC7-876B-BC634A5F5E74}" = lport=60592 | protocol=17 | dir=in | name=canon capt port |
"{901E760C-32A3-40AA-9391-51C5123981CE}" = lport=54442 | protocol=17 | dir=in | name=canon capt port |
"{916B34CB-F355-44E2-B2D0-400A97419D4E}" = lport=65309 | protocol=17 | dir=in | name=canon capt port |
"{91C70AC4-F2D6-4F2F-8E2F-AE27CF199C7F}" = lport=54172 | protocol=17 | dir=in | name=canon capt port |
"{9309038A-670D-4D50-A825-BB9274105CF2}" = rport=137 | protocol=17 | dir=out | app=system |
"{938BAE80-6EC2-4E03-BF8E-A4CCC9BA186D}" = lport=52260 | protocol=17 | dir=in | name=canon capt port |
"{95158788-DB30-4EB4-A198-39C852CB2E00}" = lport=64583 | protocol=17 | dir=in | name=canon capt port |
"{9516A895-F4B2-4074-8747-FBD8DC935AB2}" = lport=54836 | protocol=17 | dir=in | name=canon capt port |
"{95F16ADD-0A74-4206-90B2-6E14DD7E21BB}" = lport=49852 | protocol=17 | dir=in | name=canon capt port |
"{965AA291-7D9A-48E6-AFC2-4ACBE28E9FA3}" = lport=59128 | protocol=17 | dir=in | name=canon capt port |
"{968507BA-1170-4894-AB55-DA000BDD014B}" = lport=56805 | protocol=17 | dir=in | name=canon capt port |
"{99E6EF2A-5197-49A3-B6D5-5C38ADE63777}" = lport=58068 | protocol=17 | dir=in | name=canon capt port |
"{9A55EEB0-847A-447E-97A2-A1153A90ABBA}" = lport=51532 | protocol=17 | dir=in | name=canon capt port |
"{9A5C9487-0C2C-41D2-85EA-8B09EA5CCF72}" = lport=62765 | protocol=17 | dir=in | name=canon capt port |
"{9B7B4715-26FB-4C3E-AC1D-2BAAFABA7D87}" = lport=59821 | protocol=17 | dir=in | name=canon capt port |
"{9C1F43C9-A2D2-43E3-BC29-7C6FF228C8D4}" = lport=59816 | protocol=17 | dir=in | name=canon capt port |
"{9CCE361B-6AEB-4622-AFA7-EAC627DB08CA}" = lport=59832 | protocol=17 | dir=in | name=canon capt port |
"{9E03A8C1-6FDF-4B53-B804-3F24C53A8A21}" = lport=62298 | protocol=17 | dir=in | name=canon capt port |
"{9E94EF00-F2B7-4C94-B5A9-50D5C78C01E0}" = lport=54395 | protocol=17 | dir=in | name=canon capt port |
"{9FC5DA9F-3F5E-4FD9-B319-2CD23C7F7193}" = lport=63667 | protocol=17 | dir=in | name=canon capt port |
"{A0476A10-5AD1-407B-9BA0-3BB2F8455228}" = lport=50526 | protocol=17 | dir=in | name=canon capt port |
"{A230AC2E-D6F8-4E8F-983F-4A871FB702D6}" = lport=50672 | protocol=17 | dir=in | name=canon capt port |
"{A269C20B-C7F2-4568-A85B-1A9F59850EA4}" = lport=53130 | protocol=17 | dir=in | name=canon capt port |
"{A3EEFA0C-71B6-47E2-85FA-FB9E9BBCB60E}" = lport=59759 | protocol=17 | dir=in | name=canon capt port |
"{A561ACC3-352A-4528-80EB-4D8EFC383292}" = lport=52754 | protocol=17 | dir=in | name=canon capt port |
"{A5C39294-754A-4C67-939A-3DE8BCF394B5}" = lport=51279 | protocol=17 | dir=in | name=canon capt port |
"{A623E5CB-523A-4365-BBB8-3C35259B2E66}" = lport=50031 | protocol=17 | dir=in | name=canon capt port |
"{A6E2E68D-442C-43E9-93F2-35A7AFAE9F54}" = lport=52175 | protocol=17 | dir=in | name=canon capt port |
"{A7A65FF8-5C3C-48CB-A45C-B15B5F5DA357}" = lport=58751 | protocol=17 | dir=in | name=canon capt port |
"{A859D1F8-EB11-4218-9B94-CAB2B2555F17}" = lport=61904 | protocol=17 | dir=in | name=canon capt port |
"{A93AA17C-6D80-42CA-8BB7-941D79CAFDD4}" = lport=62131 | protocol=17 | dir=in | name=canon capt port |
"{AA953E06-9A85-481C-82A3-EC128358B370}" = lport=49153 | protocol=17 | dir=in | name=canon capt port |
"{AB072C88-00C8-4208-811E-700ECF209A72}" = lport=56737 | protocol=17 | dir=in | name=canon capt port |
"{AB0E8906-E975-4670-BBD8-891D1A1193E9}" = lport=61185 | protocol=17 | dir=in | name=canon capt port |
"{ABA48C10-5DC3-4B34-831E-176659EB6F41}" = lport=52824 | protocol=17 | dir=in | name=canon capt port |
"{AC098ECC-BD56-4528-8554-D01326669FF4}" = lport=64293 | protocol=17 | dir=in | name=canon capt port |
"{ADC33D38-2B36-4236-8F72-A1C6138C3280}" = lport=63344 | protocol=17 | dir=in | name=canon capt port |
"{AF4DEFB8-70ED-434D-A057-3BBFC75573B5}" = lport=58981 | protocol=17 | dir=in | name=canon capt port |
"{B0C6BF10-9D90-4EAE-9C62-41518AD30ADD}" = lport=61418 | protocol=17 | dir=in | name=canon capt port |
"{B0C752CF-65CA-4645-BC8B-43719316293A}" = lport=57624 | protocol=17 | dir=in | name=canon capt port |
"{B13C75E0-C95E-4B49-895A-41E6A738439A}" = lport=60306 | protocol=17 | dir=in | name=canon capt port |
"{B17D6D45-538F-4CE3-9AF4-A6096B14CAA7}" = lport=58603 | protocol=17 | dir=in | name=canon capt port |
"{B1DA3E67-BC8D-46CE-97BE-89E5800FF17B}" = lport=49159 | protocol=17 | dir=in | name=canon capt port |
"{B49F5FB2-AEF1-4A86-A299-C8BA4ACDACDF}" = lport=61729 | protocol=17 | dir=in | name=canon capt port |
"{B5EA02BA-D598-48D1-B7D9-64B27D6B225B}" = lport=49928 | protocol=17 | dir=in | name=canon capt port |
"{B692B2DE-6EBA-477F-9E07-D2C38D5F5CAE}" = lport=62858 | protocol=17 | dir=in | name=canon capt port |
"{B69411F4-F662-476E-9EC9-185067FF0EE8}" = lport=53029 | protocol=17 | dir=in | name=canon capt port |
"{B6F51D4C-A36A-4992-BF14-0418CB64821F}" = lport=51165 | protocol=17 | dir=in | name=canon capt port |
"{B7AD0E09-ACB5-48D5-9D46-44A53C9752C8}" = lport=63131 | protocol=17 | dir=in | name=canon capt port |
"{B8BB9CBF-F322-4161-8006-51ECFE77B010}" = lport=55889 | protocol=17 | dir=in | name=canon capt port |
"{B8E52BDE-FBA0-4C94-9405-E0672F90566C}" = lport=65284 | protocol=17 | dir=in | name=canon capt port |
"{B9DC0E2E-A55F-4194-926C-284F09C67AE6}" = lport=54867 | protocol=17 | dir=in | name=canon capt port |
"{BA26ED07-6726-429A-B83F-058F833CA0A9}" = lport=60826 | protocol=17 | dir=in | name=canon capt port |
"{BA47AB9F-6880-4599-9579-9814643F5DD1}" = lport=52426 | protocol=17 | dir=in | name=canon capt port |
"{BB17EC83-216C-4F21-BDBA-DD9485EE3D7E}" = lport=61109 | protocol=17 | dir=in | name=canon capt port |
"{BDFE7DDE-4FAC-4C6F-A84A-0FB26A6FF9FB}" = lport=62181 | protocol=17 | dir=in | name=canon capt port |
"{BE511C2C-FA49-4C0D-9D2B-849A54CAD572}" = lport=63870 | protocol=17 | dir=in | name=canon capt port |
"{C005FF2D-2B23-4EC3-A077-801CEE9A29E7}" = lport=53565 | protocol=17 | dir=in | name=canon capt port |
"{C0C161A7-B5F5-4510-90F0-07FDC09642BC}" = lport=445 | protocol=6 | dir=in | app=system |
"{C31669FC-E772-425A-B1F8-9CCD95B2273F}" = lport=60368 | protocol=17 | dir=in | name=canon capt port |
"{C4877B9F-8149-4D1B-94EB-17EB709BBB7C}" = lport=58421 | protocol=17 | dir=in | name=canon capt port |
"{C5281753-FBAD-4950-BF98-356B74B90853}" = lport=60014 | protocol=17 | dir=in | name=canon capt port |
"{C58106C0-D7F6-4B07-8C59-4A539A0516B5}" = lport=56699 | protocol=17 | dir=in | name=canon capt port |
"{C631E89C-63D6-49C8-9A0E-66EE6466965D}" = lport=59923 | protocol=17 | dir=in | name=canon capt port |
"{C711ADB8-CA10-4DBA-A4B9-E86E9FBAAC57}" = lport=51603 | protocol=17 | dir=in | name=canon capt port |
"{C73EC8B7-EE27-4BB9-99B5-37FE0A3A8A0A}" = lport=59522 | protocol=17 | dir=in | name=canon capt port |
"{C7AF1D5E-9707-42CC-BA9F-B12636F510A0}" = lport=65258 | protocol=17 | dir=in | name=canon capt port |
"{C94AB20D-94A5-44A2-B4BC-3EC1FED62D29}" = lport=55861 | protocol=17 | dir=in | name=canon capt port |
"{CA9D78E1-C84A-4E77-BD73-62019B9E6A2F}" = lport=58314 | protocol=17 | dir=in | name=canon capt port |
"{CD55A765-AF79-4795-AE48-29E626E2A24C}" = lport=54067 | protocol=17 | dir=in | name=canon capt port |
"{CE5FE959-DAFF-47AD-A55A-DED888E84459}" = lport=54481 | protocol=17 | dir=in | name=canon capt port |
"{CE867784-7F44-4783-95CF-098068A307CF}" = lport=53238 | protocol=17 | dir=in | name=canon capt port |
"{CF51CDB5-198E-4AD9-88A4-D7493CACBCEB}" = lport=49152 | protocol=17 | dir=in | name=canon capt port |
"{CF8618F7-24DC-455A-8ED6-45FF227635EE}" = rport=5679 | protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{D0CECA6E-F9A7-435A-A19D-739FD8A71E76}" = lport=63356 | protocol=17 | dir=in | name=canon capt port |
"{D10C8269-CBEC-482D-8D45-FF25FA7E4D8F}" = lport=50165 | protocol=17 | dir=in | name=canon capt port |
"{D126F996-ADDF-4B21-81BB-E3779D46B139}" = lport=53627 | protocol=17 | dir=in | name=canon capt port |
"{D1498E31-DEA5-4CAD-B39F-D0F8E4B2D6F0}" = lport=56218 | protocol=17 | dir=in | name=canon capt port |
"{D36B9994-A925-4CF6-9403-8BACB09F6F3B}" = lport=61823 | protocol=17 | dir=in | name=canon capt port |
"{D3BA5831-6F37-4985-9533-00C88C6CD7E6}" = lport=53813 | protocol=17 | dir=in | name=canon capt port |
"{D3C4A715-7213-4587-BD31-3ABC13CE9DEB}" = lport=53233 | protocol=17 | dir=in | name=canon capt port |
"{D492AE1A-B7B7-48EE-BA90-54603C06D84D}" = lport=60375 | protocol=17 | dir=in | name=canon capt port |
"{D5427470-8BE8-41EA-9721-02C0E7EFB0CC}" = lport=63093 | protocol=17 | dir=in | name=canon capt port |
"{D611C2D4-D238-4557-9297-F6DA0A695ECA}" = lport=50821 | protocol=17 | dir=in | name=canon capt port |
"{D63F93BD-1F6D-464F-92E6-424736A4BED9}" = lport=64507 | protocol=17 | dir=in | name=canon capt port |
"{D681A71C-2BA5-402B-B24E-FD73C5CBA913}" = lport=59744 | protocol=17 | dir=in | name=canon capt port |
"{D7C78B69-B0F7-4C58-AD65-E7A9722E303A}" = lport=137 | protocol=17 | dir=in | app=system |
"{DA6780B7-20A0-4349-92CE-94859B35B086}" = lport=57653 | protocol=17 | dir=in | name=canon capt port |
"{DA820F36-96A6-492F-8FB7-8B348EF6017F}" = lport=49479 | protocol=17 | dir=in | name=canon capt port |
"{DAC4B470-EAFC-414D-A7FD-967EA220666A}" = lport=62978 | protocol=17 | dir=in | name=canon capt port |
"{DB7DCB00-187C-41E2-8A45-C4485DB9C10F}" = lport=60583 | protocol=17 | dir=in | name=canon capt port |
"{DBD6801D-6C09-46BA-951A-E3B710D8AF40}" = lport=56383 | protocol=17 | dir=in | name=canon capt port |
"{DC17CC0A-8B14-4CA0-93B3-C03FA2A1184F}" = lport=52593 | protocol=17 | dir=in | name=canon capt port |
"{DCE4A863-04D6-490B-9E68-8F617F24E8C1}" = lport=53971 | protocol=17 | dir=in | name=canon capt port |
"{DDC3A563-9291-4654-AF87-1FF600EF2C8A}" = lport=51272 | protocol=17 | dir=in | name=canon capt port |
"{DE9DA4EA-9A44-4042-9AE7-96A8892A56C7}" = lport=63337 | protocol=17 | dir=in | name=canon capt port |
"{DEE943C2-50E2-4AFF-89E2-C412CEAEF888}" = lport=59412 | protocol=17 | dir=in | name=canon capt port |
"{E0420A52-2437-4F9D-84B7-50511C3E6DEC}" = lport=56248 | protocol=17 | dir=in | name=canon capt port |
"{E090BD43-CEEE-4456-B3E0-AB658594C834}" = lport=51216 | protocol=17 | dir=in | name=canon capt port |
"{E09F277A-8D47-4324-B0FC-C4EF498EA149}" = rport=138 | protocol=17 | dir=out | app=system |
"{E2285B7D-A6B9-434A-AA5B-95FEA35B6015}" = lport=59723 | protocol=17 | dir=in | name=canon capt port |
"{E27C38E0-1EED-462B-A6B7-F67E7DFBDA0E}" = lport=6004 | protocol=17 | dir=in | app=c:\program files\microsoft office\office14\outlook.exe |
"{E2EB0BE6-AB2E-46DE-A23D-966AA0C2C8D4}" = lport=57109 | protocol=17 | dir=in | name=canon capt port |
"{E327DBE1-12CB-4E7C-9962-41441D4D4EE4}" = lport=63204 | protocol=17 | dir=in | name=canon capt port |
"{E4D6292C-FD7E-4536-BD06-A2B9B9DF288D}" = lport=55329 | protocol=17 | dir=in | name=canon capt port |
"{E5B5EB7E-A27C-426E-ABC9-C11A674F5C0B}" = lport=50220 | protocol=17 | dir=in | name=canon capt port |
"{E5CC6534-5CB1-48B3-9730-80FF611068C8}" = lport=51819 | protocol=17 | dir=in | name=canon capt port |
"{E772B483-7BEA-4A28-B042-F40D9D821E2B}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework\v4.0.30319\smsvchost.exe |
"{E7FD5191-2C87-43C8-A601-8191B55FFBF6}" = lport=62678 | protocol=17 | dir=in | name=canon capt port |
"{E8C946C4-07F4-4AE9-BF47-25D4E01FE2A7}" = lport=60391 | protocol=17 | dir=in | name=canon capt port |
"{EB088F61-FDD6-4259-94A5-4EBEF0B1E360}" = lport=59591 | protocol=17 | dir=in | name=canon capt port |
"{EB487C96-9A38-409A-B643-D2945163A4FC}" = lport=63940 | protocol=17 | dir=in | name=canon capt port |
"{EE5F10DB-89E5-43D4-9B79-8511C363FA74}" = lport=61955 | protocol=17 | dir=in | name=canon capt port |
"{EE678BD0-3A3C-4A68-90B6-9903DAEE2AEF}" = lport=57565 | protocol=17 | dir=in | name=canon capt port |
"{EEC5702E-4A09-4549-8EF0-855864CCF24F}" = lport=62157 | protocol=17 | dir=in | name=canon capt port |
"{F2870067-670D-48EA-9CB1-417884E920A5}" = lport=56999 | protocol=17 | dir=in | name=canon capt port |
"{F29E8F0D-35B8-462B-81D1-7C89DA4438ED}" = lport=60308 | protocol=17 | dir=in | name=canon capt port |
"{F3DE68D6-7E20-420E-9D4F-24B467387EF2}" = lport=52200 | protocol=17 | dir=in | name=canon capt port |
"{F641CC4D-FC35-436A-B5DB-272A75FCE64E}" = lport=58922 | protocol=17 | dir=in | name=canon capt port |
"{F66F9B32-7952-4BAF-A286-C58286A78C62}" = lport=53015 | protocol=17 | dir=in | name=canon capt port |
"{F6801922-1ECC-4E41-AF00-55E45658D600}" = lport=56350 | protocol=17 | dir=in | name=canon capt port |
"{F6FB5018-0E2F-4243-8330-2C111173416E}" = lport=65186 | protocol=17 | dir=in | name=canon capt port |
"{F768DD09-D416-4BDB-BC2E-7B4E3F1D6BA7}" = lport=50343 | protocol=17 | dir=in | name=canon capt port |
"{F8FD15EC-1DCE-4FA0-9AA7-9A3B3B6B1A2F}" = lport=50995 | protocol=17 | dir=in | name=canon capt port |
"{F9333726-0569-4262-9CF9-761D505ABEDC}" = lport=52507 | protocol=17 | dir=in | name=canon capt port |
"{F94470C4-066E-4BF4-A371-7676C59700D0}" = lport=50135 | protocol=17 | dir=in | name=canon capt port |
"{FCA6E0B1-DA4C-445F-AFA9-20CE8F461F25}" = lport=57040 | protocol=17 | dir=in | name=canon capt port |
"{FD2D1E08-2E9C-46FC-80A1-3108BC64AEBD}" = lport=49718 | protocol=17 | dir=in | name=canon capt port |
"{FD3AE15C-BECB-419D-AD5F-9824285683E6}" = lport=52877 | protocol=17 | dir=in | name=canon capt port |
"{FEA6B732-080D-491F-AC3E-F67D15241F89}" = lport=62344 | protocol=17 | dir=in | name=canon capt port |
"{FFAE7B0D-EBDF-40CA-9F22-F2106416F932}" = lport=59457 | protocol=17 | dir=in | name=canon capt port |
"{FFB413DB-50F7-4BBA-9685-BB2C1F1DA4EE}" = lport=63944 | protocol=17 | dir=in | name=canon capt port |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{01489F19-7EF1-4237-8A14-C568216E426C}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version7\teamviewer.exe |
"{0A06129E-1AA4-44B7-92BC-F383DB786A48}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{0BDC1F9F-D3DB-4483-B5B8-3ECF05487C71}" = protocol=6 | dir=in | app=c:\program files\ubisoft\driver san francisco\driver.exe |
"{19A695F9-CD9B-4180-A510-6934C83706FE}" = protocol=6 | dir=in | app=c:\program files\teamviewer\version7\teamviewer_service.exe |
"{1C0CC55A-494B-4D4D-9E78-DCB73C08FAA3}" = protocol=58 | dir=out | [email protected],-28546 |
"{30C07DA1-AAE4-453E-AB2C-0BBC860F44F1}" = protocol=6 | dir=in | app=c:\users\hamad\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{3495767A-CA24-484B-8180-AD3FC4EB0673}" = protocol=17 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{4C6267A8-76CA-4D27-8BA6-0169BFA063A4}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{4F5F4AC0-C947-4D8D-BA13-4829ACA2890C}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{508AC0FB-88D5-4647-AB42-7224B14A8E26}" = protocol=6 | dir=in | app=c:\program files\utorrent\utorrent.exe |
"{50F92079-6729-4D40-AB32-D2E78D496520}" = dir=in | app=c:\program files\common files\apple\apple application support\webkit2webprocess.exe |
"{602D9A2F-F111-48D2-B566-A895C2564B64}" = protocol=58 | dir=in | [email protected],-28545 |
"{61799791-7617-4038-AD92-3668FCAADF9E}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{6205BA08-153F-4493-85F0-AF498D678716}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{69133BFA-A2FB-4709-884B-267CA26D1F5D}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version7\teamviewer_service.exe |
"{6E7BBF2E-A829-4C71-AD81-D97890D76468}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{773FDC49-63E9-421D-8BF1-9B80A28C12DB}" = protocol=17 | dir=in | app=c:\users\hamad\appdata\local\google\google talk plugin\googletalkplugin.exe |
"{7C0E447D-00E2-4508-ADA7-2BED40546DDD}" = protocol=6 | dir=in | app=c:\users\hamad\appdata\local\temp\7zs5ed0\hpdiagnosticcoreui.exe |
"{7CA6E19D-87C8-4978-9206-BF7743BA236C}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{845CF6B6-DA07-419E-86AA-1056B02E087C}" = protocol=17 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{893F96EF-4841-4950-B052-821D2AC9CC69}" = protocol=17 | dir=in | app=c:\program files\ubisoft\driver san francisco\driver.exe |
"{96683D70-1CDC-4A77-B45B-18C489317F2B}" = protocol=1 | dir=in | [email protected],-28543 |
"{9EF2165B-3137-4FD1-9C5F-6FBBD561BF4E}" = protocol=1 | dir=out | [email protected],-28544 |
"{AE588234-E2C3-4114-9BD7-1F89DCAAB7EF}" = protocol=17 | dir=in | app=c:\program files\teamviewer\version7\teamviewer.exe |
"{B3D3DD58-86ED-4781-9D44-5B2D84C7CAA2}" = protocol=17 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{B93077CC-D550-4243-9F5A-DA2976CCEA6D}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{C3AB8A77-2850-4EC1-A331-2267CB71FBD2}" = protocol=17 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{C5E25953-AC5B-45B8-B0F0-004DA803FDC1}" = protocol=6 | dir=out | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{CA00F390-ACBA-4ABC-94A9-4D1DF1977713}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{CC384BD1-D1C6-4C39-85B8-3FF11F8C88B5}" = protocol=6 | dir=in | app=c:\users\hamad\appdata\local\temp\7zs6003\hpdiagnosticcoreui.exe |
"{D4262A3C-8DBE-42FC-B2CC-E87CE9E44666}" = protocol=17 | dir=in | app=c:\users\hamad\appdata\local\temp\7zs6003\hpdiagnosticcoreui.exe |
"{DE0C4739-E9D2-4609-9F5B-2E07CE5934AE}" = protocol=17 | dir=in | app=c:\users\hamad\appdata\local\temp\7zs5ed0\hpdiagnosticcoreui.exe |
"{DF51CAC3-2832-4359-A4A3-67F88B34E78B}" = protocol=6 | dir=in | app=c:\program files\ubisoft\ubisoft game launcher\ubisoftgamelauncher.exe |
"{E6C7167C-A4F8-4C85-8ACC-AA3990050419}" = protocol=6 | dir=in | svc=wcescomm | app=%systemroot%\system32\svchost.exe |
"{EAAB07C4-49DF-4027-B5D6-2EF9E2D0214C}" = protocol=6 | dir=out | svc=rapimgr | app=%systemroot%\system32\svchost.exe |
"{F4E2811F-6F91-4F94-8BD9-E4B4EB57767D}" = dir=in | app=c:\program files\itunes\itunes.exe |
"TCP Query User{720D8E64-3E84-4836-879C-E0333C24F153}C:\program files\java\jre6\bin\javaw.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |
"TCP Query User{A01A03EF-C982-4A19-AD38-EAF548894F0A}C:\program files\java\jre6\bin\java.exe" = protocol=6 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{72703744-F968-4847-8B9A-98926CB49241}C:\program files\java\jre6\bin\java.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\java.exe |
"UDP Query User{9FD20E30-7260-4A18-8472-E12BB1BFC761}C:\program files\java\jre6\bin\javaw.exe" = protocol=17 | dir=in | app=c:\program files\java\jre6\bin\javaw.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{0122791A-3E7B-6255-835A-56962591DB54}" = HydraVision
"{040FF9BD-17BE-427B-85DD-67694FB8F786}" = Badoo Desktop
"{0840B4D6-7DD1-4187-8523-E6FC0007EFB7}" = Windows Live ID Sign-in Assistant
"{0A0CADCF-78DA-33C4-A350-CD51849B9702}" = Microsoft .NET Framework 4 Extended
"{0DAE32D8-EC40-42C4-BE8D-51CEB1E3A805}" = 3Dconnexion Add-On for XSI v5.0 - 2012
"{0E64B098-8018-4256-BA23-C316A43AD9B0}" = QuickTime
"{0F842B77-56EA-4AAF-8295-81A022350B5E}" = Microsoft Security Client
"{1111706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1
"{14DC0059-00F1-4F62-BD1A-AB23CD51A95E}" = Adobe AIR
"{14DDF23F-414A-46DB-4762-56569080292C}" = CCC Help Russian
"{1910EF67-D4B8-4561-9252-4F2EFF2E17AE}" = 3Dconnexion Plug-in for Acrobat 3D
"{196BB40D-1578-3D01-B289-BEFC77A11A1E}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.30319
"{1B68DE6D-A980-4E73-BF4A-C996340A4BC2}" = Sound Organizer
"{1D0F361D-A81A-49EA-B231-655437585A46}" = 3Dconnexion Plug-In for 3ds Max v9 - 2012
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F897E00-83A6-4133-54E1-58F8D35E61C2}" = AMD Catalyst Install Manager
"{2001197F-7545-41F7-9078-E8D23B3BBEAF}" = 3Dconnexion Plug-In for Photoshop CS3 - CS5
"{207780D5-A515-4E79-B7C2-E4D32F8A6CA1}" = Eco Materials Adviser
"{20D4A895-748C-4D88-871C-FDB1695B0169}" = Platform
"{21D6A73A-48E6-2195-C408-2158273A914E}" = Catalyst Control Center Localization All
"{2222706F-666A-4037-7777-211328764D10}" = JavaFX 2.1.1 SDK
"{22FC7536-BE5C-4E88-8069-C24689D34EC5}" = Snagit 10.0.1
"{23B8A91D-680B-462B-87AD-3D70F7341731}" = iTunes
"{24FF088D-CDCF-480C-8A4B-98F14A54CAA8}" = Autodesk Material Library Low Resolution Image Library 2012
"{2596DB11-997F-FC5B-F5C2-737623D9D8B6}" = AMD VISION Engine Control Center
"{266597A9-1632-0000-0100-DCBF2B69166B}" = Autodesk Vault 2012 (Client) English Language Pack
"{26A24AE4-039D-4CA4-87B4-2F83216022F0}" = Java™ 6 Update 22
"{26A24AE4-039D-4CA4-87B4-2F83216033FF}" = Java™ 6 Update 33
"{26A24AE4-039D-4CA4-87B4-2F83217007FF}" = Java 7 Update 7
"{28904D9A-13A6-ECA2-48D8-21542759D998}" = CCC Help Polish
"{2B6EC03E-6FA0-4D7C-9CCE-1B03819AB613}" = PerfectDisk 2008 Professional
"{2C8BBDA6-79A7-B2DE-3E5B-287E7F667C67}" = CCC Help Danish
"{2E119961-E99B-C147-9AC3-A93683172DC1}" = CCC Help Swedish
"{3108C217-BE83-42E4-AE9E-A56A2A92E549}" = Atheros Communications Inc.® AR8121/AR8113/AR8114 Gigabit/Fast Ethernet Driver
"{32A3A4F4-B792-11D6-A78A-00B0D0170050}" = Java SE Development Kit 7 Update 5
"{3C3901C5-3455-3E0A-A214-0B093A5070A6}" = Microsoft .NET Framework 4 Client Profile
"{3E171899-0175-47CC-84C4-562ACDD4C021}" = OpenOffice.org 3.3
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{3E8DBEA5-3303-48CD-AAD0-66180900A5EE}" = 3Dconnexion Add-In for Inventor 11 - 2012
"{434D0FA0-AB8C-497F-B30A-7A1000038201}" = DiRT 3
"{44ED90A1-453B-5C9A-D9ED-80D8AB0258B8}" = CCC Help Thai
"{45E00595-897E-64B6-28F9-5D0927EBA4A5}" = CCC Help Chinese Standard
"{46DE5F4E-BA8B-AC9E-0EED-05B7D93AD215}" = CCC Help Spanish
"{4A03706F-666A-4037-7777-5F2748764D10}" = Java Auto Updater
"{4CB0307C-565E-4441-86BE-0DF2E4FB828C}" = Microsoft Games for Windows Marketplace
"{4E1A54A9-FFB3-4BE6-B59B-3CC94C3B31D2}" = Autodesk Inventor Fusion for Inventor 2012 Add-in Language Pack
"{4E3B47F2-21EB-4F20-87C8-5A0E4D5F3858}" = Autodesk Inventor Fusion for Inventor 2012 Add-in
"{5236C5F0-9539-49DB-829A-D2C964F455D3}" = Ableton Live 8
"{5545EEE1-FA36-4F76-B6BE-5696E7F4E2D6}" = VBA (2627.01)
"{5783F2D7-A028-0409-0000-0060B0CE6BBA}" = DWG TrueView 2012
"{587178E7-B1DF-494E-9838-FA4DD36E873C}" = ASUSUpdate
"{5A7DD6D7-6456-4A86-973C-221C496731B4}" = 3Dconnexion Add-In for SolidWorks 2005 - 2011
"{5B04E832-4530-B8FF-F742-8BE25ADD43BD}" = CCC Help German
"{5D58EACA-0317-4CFF-9E13-53CCD525DE32}" = Catalyst Control Center InstallProxy
"{5ED93D68-5EAA-9343-9B74-B1E276217264}" = CCC Help Dutch
"{612C34C7-5E90-47D8-9B5C-0F717DD82726}" = swMSM
"{65420DC9-306E-4371-905F-F4DC3B418E52}" = Autodesk Material Library Base Resolution Image Library 2012
"{6AAB8068-BEB6-4CB6-958E-717EA6402467}" = 3Dconnexion Trainer
"{6B5B4231-0B1C-44FF-BE7C-DE35261F2CBF}" = 3Dconnexion Plug-In for Pro/ENGINEER Wildfire 3.0 - Creo 1.0
"{6D185295-DE89-9C39-18E6-310C148836EB}" = CCC Help Chinese Traditional
"{6D236956-B79D-4748-BEA3-A039334A66AB}" = 3Dconnexion Collage
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{71A8F958-D272-E262-7C9A-7B8F713EE0C3}" = CCC Help French
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{7391ABC8-0EA4-3798-ACE3-96B8C8D84EA8}" = Google Talk Plugin
"{7513D3F0-55BC-273C-7A53-488394EDBFCC}" = CCC Help Italian
"{757D3FC9-8E93-45BC-8AEA-39D5D9DA6790}" = 3Dconnexion Plug-In for Maya v8.5 - 2012
"{789A5B64-9DD9-4BA5-915A-F0FC0A1B7BFE}" = Apple Software Update
"{79155F2B-9895-49D7-8612-D92580E0DE5B}" = Bonjour
"{79AA9BFA-F962-A1E9-71CE-D0887A92444C}" = CCC Help Portuguese
"{7ACEF1BF-9306-5AD7-5F30-ECE72A81E924}" = CCC Help Finnish
"{7F3F35EB-3A5D-4F82-9162-D880B2D1C771}" = GoalSync 3.0 Installation
"{7F4DD591-1632-0409-0000-7107D70F3DB4}" = Autodesk Inventor Professional 2012
"{7F4DD591-1632-0409-0001-7107D70F3DB4}" = Autodesk Inventor Professional 2012 English Language Pack
"{832D9DE0-8AFC-4689-9819-4DBBDEBD3E4F}" = Microsoft Games for Windows - LIVE Redistributable
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{852252AE-F555-4BA1-B451-4E4C230D18F2}" = 3Dconnexion Extension for SketchUp
"{86892093-11EF-40D9-A92A-CC86BF0BFA1A}" = 3Dconnexion 3DxWare
"{8826576D-512B-4BD2-9655-B90530034E4C}" = TradersStudio
"{888AEF72-1AD4-47EF-8B83-8A9D606CCC8F}" = Programming Wizard
"{888F1505-C2B3-4FDE-835D-36353EBD4754}" = Ubisoft Game Launcher
"{89DE67AD-08B8-4699-A55D-CA5C0AF82BF3}" = ATI AVIVO Codecs
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{8EA79DBF-D637-448A-89D6-410A087A4493}" = Samsung_MonSetup
"{8F0837C2-EE09-4903-88F3-1976FE7FFF4E}" = Autodesk Material Library 2012
"{90140000-001A-0409-0000-0000000FF1CE}" = Microsoft Office Outlook MUI (English) 2010
"{90140000-001A-0409-0000-0000000FF1CE}_Office14.OUTLOOKR_{6BD185A0-E67F-4F77-8BCD-E34EA6AE76DF}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2010
"{90140000-001F-0409-0000-0000000FF1CE}_Office14.OUTLOOKR_{99ACCA38-6DD3-48A8-96AE-A283C9759279}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2010
"{90140000-001F-040C-0000-0000000FF1CE}_Office14.OUTLOOKR_{46298F6A-1E7E-4D4A-B5F5-106A4F0E48C6}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2010
"{90140000-001F-0C0A-0000-0000000FF1CE}_Office14.OUTLOOKR_{DEA87BE2-FFCC-4F33-9946-FCBE55A1E998}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2010
"{90140000-002C-0409-0000-0000000FF1CE}_Office14.OUTLOOKR_{7CA93DF4-8902-449E-A42E-4C5923CFBDE3}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2010
"{90140000-006E-0409-0000-0000000FF1CE}_Office14.OUTLOOKR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{90140000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2010
"{90140000-0115-0409-0000-0000000FF1CE}_Office14.OUTLOOKR_{4560037C-E356-444A-A015-D21F487D809E}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{904CCF62-818D-4675-BC76-D37EB399F917}" = Windows Mobile Device Center
"{91140000-001A-0000-0000-0000000FF1CE}" = Microsoft Office Outlook 2010
"{91140000-001A-0000-0000-0000000FF1CE}_Office14.OUTLOOKR_{047B0968-E622-4FAA-9B4B-121FA109EDDE}" = Microsoft Office 2010 Service Pack 1 (SP1)
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9C1EC871-05B9-03B7-96F6-9BD5C0D8F41D}" = Catalyst Control Center Graphics Previews Common
"{A0494B41-EBD7-4C0D-91B7-DC39741B27BB}" = Express Gate
"{A25FF1C0-80B6-4B8B-A551-DC525697A408}" = AMD APP SDK Runtime
"{A49BDCBE-590E-43A6-AB77-7C40E499B7C1}" = Autodesk Design Review 2012
"{A87B11AC-4344-4E5D-8B12-8F471A87DAD9}" = LightScribe 1.4.136.1
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.4)
"{B28B351F-1232-46EA-85EF-B8EA91641033}" = Nero 7 Essentials
"{B2D55EB8-32C5-4B43-9006-9E97DECBA178}" = Epson Easy Photo Print Plug-in for PMB(Picture Motion Browser)
"{B46DECD1-1632-4EF1-0000-22D71E81877C}" = Autodesk Inventor Content Center Libraries 2012 (Desktop Content)
"{B59D7E45-401F-9542-965A-5B76915B6E6A}" = YNAB 3
"{B7588D45-AFDC-4C93-9E2E-A100F3554B64}" = Microsoft Fix it Center
"{B8C4E707-F43D-4FF7-B876-B90D6F1BC9C3}" = TSGAOptimizer
"{BAEE5B10-1F13-4912-9C11-34C695449703}" = 3Dconnexion Add-In for Solid Edge V18 - ST4
"{BAFCA6AC-8B37-405B-B57E-C1D45DE70ACC}" = 3Dconnexion 3DxSoftware
"{BC64CEDA-74F9-4007-B9DE-09EDE0A35A67}" = Autodesk 123D Catch
"{C028F57F-603A-AB6E-F2D0-1374EA538F8A}" = ccc-utility
"{C4129D57-5C83-3BF0-A11A-3798C008C6C7}" = CCC Help Greek
"{C4CBE331-9BFC-456B-A4D8-4E43E5EA3788}" = 3Dconnexion Add-In for AutoCAD 2007 - 2010
"{C725719D-AEEA-61C8-E732-E29513201D59}" = AMD Fuel
"{CE2CDD62-0124-36CA-84D3-9F4DCF5C5BD9}" = Microsoft .NET Framework 3.5 SP1
"{CF526A26-1632-0000-0000-02E95019B628}" = Autodesk Vault 2012 (Client)
"{D0BC4101-6C30-ECFF-F693-63408134F29B}" = CCC Help Czech
"{D2402DAD-B180-A4A0-261D-4A8933BFBFEE}" = CCC Help Japanese
"{D25FF5C1-1632-469A-9794-69309387C193}" = Quick Uninstall Tool for Autodesk Inventor 2012
"{D2B4C882-B2E9-4840-BBE6-25A7D24AE839}" = Visual Trader Studio for MetaTrader
"{D2FCA41E-AC01-4DCD-B3A7-DC9E32363065}}_is1" = Rapture3D 2.4.8 Game
"{DA7E8D81-2B14-415B-8FC5-02CE4CF9F839}" = CCC Help Hungarian
"{DB3FBD3C-A061-34C9-0A2B-6CCDD8C96640}" = CCC Help Turkish
"{DCFD26A8-60A5-4C69-A52D-264D0386FDB3}" = Microsoft Xbox 360 Accessories 1.2
"{DED01768-E634-11E1-AEB0-984BE15F174E}" = Evernote v. 4.5.8
"{E086E914-2928-48F9-364B-0C715DFF6A45}" = CCC Help Korean
"{E2F0AF23-FE2F-4222-9A43-55E63CC41EF1}" = Catalyst Control Center - Branding
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E530553A-CEF4-4AE0-BEE4-D9E063F48712}" = 3Dconnexion Plug-In for NX v3.0 - v8.0
"{E6DB139F-DE64-4F3A-AFBD-5ABF7E434F12}" = AMD USB Audio Driver Filter
"{E7044E25-3038-4A76-9064-344AC038043E}" = Windows Mobile Device Center Driver Update
"{E728441A-7820-4B1C-87C9-DE7BE37B2953}" = Download Navigator
"{E8F30BD6-ABAB-C24E-E9A7-BF67EB96152C}" = CCC Help Norwegian
"{E9A5B6CD-7ABB-F295-2E11-F25BC322FF80}" = CCC Help English
"{EACCC042-848D-4166-9D97-B13D1D108722}" = Google Drive
"{EB879750-CCBD-4013-BFD5-0294D4DA5BD0}" = Apple Application Support
"{EF50A39B-5163-498A-87AE-6D2CF9310090}" = iMindMap 5
"{EFC04D3F-A152-47E7-8517-EE0F6201AFEF}" = Apple Mobile Device Support
"{F132AF7F-7BCA-4EDE-8A7C-958108FE7DBC}" = Realtek High Definition Audio Driver
"{F1E63043-54FC-429B-AB2C-31AF9FBA4BC7}" = 32 Bit HP CIO Components Installer
"{F5EC7F6B-B68B-433C-AA20-54EDFE76191D}_is1" = Forex Tester 2.8.5
"{F9000000-0018-0000-0000-074957833700}" = ABBYY FineReader 9.0 Sprint
"{FA9D303D-0FB2-49C7-9397-8E6B11EA892D}" = Epson Event Manager
"{FD3AEC41-36AE-48B7-A1B6-DC13EACF3FDC}" = Conqu
"{FD8E178D-8B4E-42DA-B434-EFF270329B1C}" = COMODO Internet Security
"{FFF5619F-6669-4EC5-A85E-9994F70A9E5D}" = Autodesk Inventor Fusion 2012
"{FFF7F80F-929E-497F-A112-B070DE816128}" = Autodesk Inventor Fusion 2012 Language Pack
"{FFF841F3-9A15-4F61-BD16-C19F132E5A27}" = Epson Easy Photo Print 2
"7-Zip" = 7-Zip 9.20
"ABBYY FineReader 9.0 Sprint" = ABBYY FineReader 9.0 Sprint
"AC3Filter" = AC3Filter (remove only)
"Adobe AIR" = Adobe AIR
"Adobe Flash Player ActiveX" = Adobe Flash Player 11 ActiveX
"Adobe Shockwave Player" = Adobe Shockwave Player 11.6
"Android SDK Tools" = Android SDK Tools
"AppInventor Setup" = AppInventor Setup
"AudibleManager" = AudibleManager
"Autodesk Design Review 2012" = Autodesk Design Review 2012
"Autodesk Inventor Fusion 2012" = Autodesk Inventor Fusion 2012
"Autodesk Inventor Fusion for Inventor 2012 Add-in" = Autodesk Inventor Fusion for Inventor 2012 Add-in
"Autodesk Inventor Professional 2012" = Autodesk Inventor Professional 2012 English
"Autodesk Vault 2012 (Client)" = Autodesk Vault 2012 (Client)
"BetOnline Poker 8.2" = BetOnline Poker 8.2
"Clickfree Easy Image" = Clickfree Easy Image
"com.youneedabudget.YNAB3.Live.9C763150EFAB05FD2A2B78705C7A54E2FCDDE07D.1" = YNAB 3
"Dirt 3_is1" = Dirt 3
"doPDF 7 printer_is1" = doPDF 7.3 printer
"Driver San Francisco" = Driver San Francisco
"DVD Flick_is1" = DVD Flick 1.3.0.7
"DWG TrueView 2012" = DWG TrueView 2012
"EPSON Scanner" = EPSON Scan
"EPSON SX535WD Series" = EPSON SX535WD Series Printer Uninstall
"EPSON SX535WD Series Netg" = Network Guide EPSON SX535WD Series
"EPSON SX535WD Series Useg" = User's Guide EPSON SX535WD Series
"experience-samsung-mon-bundle" = Samsung SyncMaster 3D Game Launcher (TriDef 3D) 1.1.6
"HabitShaper_is1" = HabitShaper
"HMA! Pro VPN" = HMA! Pro VPN 2.6.9
"Holdem Indicator_is1" = Holdem Indicator 2.3.8
"HotspotShield" = Hotspot Shield 2.70
"InstallShield_{20D4A895-748C-4D88-871C-FDB1695B0169}" = VIA Platform Device Manager
"lcc-win32 (base system)_is1" = lcc-win32 version 3.2 (base system)
"Microsoft .NET Framework 3.5 SP1" = Microsoft .NET Framework 3.5 SP1
"Microsoft .NET Framework 4 Client Profile" = Microsoft .NET Framework 4 Client Profile
"Microsoft .NET Framework 4 Extended" = Microsoft .NET Framework 4 Extended
"Microsoft Security Client" = Microsoft Security Essentials
"Mind WorkStation_is1" = Mind WorkStation 1.3.4
"MzRAMBooster_is1" = Mz RAM Booster
"Neuro-Programmer 3_is1" = Neuro-Programmer 3.1.4
"Office14.OUTLOOKR" = Microsoft Outlook 2010
"OpenAL" = OpenAL
"PartyCasino" = PartyCasino
"PartyPoker" = PartyPoker
"single-stepv3_is1" = single-step motivational software
"TeamViewer 7" = TeamViewer 7
"TR-2.2.1" = ThinkingRock-2.2.1
"Updater Service" = Updater Service
"uTorrent" = µTorrent
"VIVA Broadband" = VIVA Broadband
"VLC media player" = VLC media player 2.0.2
"Watership Planner_is1" = Watership Planner 2.21
"WinCleaner OneClick Professional Clean_is1" = WinCleaner OneClick Professional Clean Version 11
"Xvid Video Codec 1.3.2" = Xvid Video Codec

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Amazon Kindle" = Amazon Kindle
"eType" = eType
"Google Chrome" = Google Chrome
"PokerOffice5" = PokerOffice (remove only)

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 18/09/2012 17:37:46 | Computer Name = Hamad-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 18/09/2012 17:37:46 | Computer Name = Hamad-PC | Source = Windows Search Service | ID = 3013
Description =

Error - 19/09/2012 09:20:54 | Computer Name = Hamad-PC | Source = MsiInstaller | ID = 11706
Description =

Error - 19/09/2012 09:47:23 | Computer Name = Hamad-PC | Source = MsiInstaller | ID = 11706
Description =

Error - 20/09/2012 21:49:22 | Computer Name = Hamad-PC | Source = Application Error | ID = 1000
Description = Faulting application eTypeUpdate.exe, version 1.0.1.492, time stamp
0x500e974d, faulting module eTypeUpdate.exe, version 1.0.1.492, time stamp 0x500e974d,
exception code 0x40000015, fault offset 0x0016a768, process id 0x480, application
start time 0x01cd9799dec9888b.

Error - 20/09/2012 22:20:33 | Computer Name = Hamad-PC | Source = MatSvc | ID = 262152
Description = The MATS service encountered a failure when loading SAP. hr=0x80040154

SAP folder: C:\Program Files\Microsoft Fix it Center\SAPFolder\Scheduled\DDA435FA-6E05-4DBF-80FE-C4EBE882E798.32


Error - 20/09/2012 22:20:34 | Computer Name = Hamad-PC | Source = MatSvc | ID = 262159
Description = The scheduled MATS task encountered a failure when collecting configuration
data. hr=0x80040154 .

Error - 21/09/2012 17:08:56 | Computer Name = Hamad-PC | Source = Perflib | ID = 1010
Description =

Error - 21/09/2012 17:08:57 | Computer Name = Hamad-PC | Source = Perflib | ID = 1008
Description =

Error - 23/09/2012 11:34:03 | Computer Name = Hamad-PC | Source = Perflib | ID = 1010
Description =

Error - 23/09/2012 11:34:07 | Computer Name = Hamad-PC | Source = Perflib | ID = 1008
Description =

[ System Events ]
Error - 21/09/2012 14:53:26 | Computer Name = Hamad-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 21/09/2012 14:53:26 | Computer Name = Hamad-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 21/09/2012 14:53:26 | Computer Name = Hamad-PC | Source = Microsoft-Windows-Servicing | ID = 4375
Description =

Error - 21/09/2012 14:54:17 | Computer Name = Hamad-PC | Source = Microsoft-Windows-WindowsUpdateClient | ID = 20
Description =

Error - 21/09/2012 16:51:08 | Computer Name = Hamad-PC | Source = Service Control Manager | ID = 7023
Description =

Error - 21/09/2012 16:51:08 | Computer Name = Hamad-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 21/09/2012 16:51:08 | Computer Name = Hamad-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 23/09/2012 11:26:11 | Computer Name = Hamad-PC | Source = Service Control Manager | ID = 7023
Description =

Error - 23/09/2012 11:26:11 | Computer Name = Hamad-PC | Source = Service Control Manager | ID = 7000
Description =

Error - 23/09/2012 11:26:11 | Computer Name = Hamad-PC | Source = Service Control Manager | ID = 7000
Description =


< End of report >

Thank you
  • 0

#4
hamadm

hamadm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
The aswMBR log



aswMBR version 0.9.9.1665 Copyright© 2011 AVAST Software
Run date: 2012-09-24 01:18:10
-----------------------------
01:18:10.433 OS Version: Windows 6.0.6002 Service Pack 2
01:18:10.433 Number of processors: 2 586 0x4303
01:18:10.433 ComputerName: HAMAD-PC UserName: Hamad
01:18:15.175 Initialize success
01:18:44.472 Disk 0 (boot) \Device\Harddisk0\DR0 -> \Device\Ide\IdeDeviceP1T0L0-1
01:18:44.472 Disk 0 Vendor: ST3500413AS JC4B Size: 476940MB BusType: 3
01:18:44.472 Disk 0 MBR read successfully
01:18:44.488 Disk 0 MBR scan
01:18:44.488 Disk 0 Windows VISTA default MBR code
01:18:44.488 Disk 0 Partition 1 80 (A) 07 HPFS/NTFS NTFS 476938 MB offset 2048
01:18:44.503 Disk 0 scanning sectors +976771072
01:18:44.550 Disk 0 scanning C:\Windows\system32\drivers
01:18:52.958 Service scanning
01:18:59.526 Service GMSIPCI D:\INSTALL\GMSIPCI.SYS **LOCKED** 21
01:19:02.615 Service MpKsl33cdaaa7 c:\ProgramData\Microsoft\Microsoft Antimalware\Definition Updates\{62CD6CD9-56EA-4334-B372-9BFAE1B45F9A}\MpKsl33cdaaa7.sys **LOCKED** 32
01:19:02.927 Service MSICPL D:\install4\MSICPL.sys **LOCKED** 21
01:19:04.237 Service NTACCESS D:\NTACCESS.sys **LOCKED** 21
01:19:07.607 Service SetupNTGLM7X D:\NTGLM7X.sys **LOCKED** 21
01:19:12.770 Modules scanning
01:19:30.913 Disk 0 trace - called modules:
01:19:30.929 ntkrnlpa.exe CLASSPNP.SYS disk.sys acpi.sys hal.dll ataport.SYS pciide.sys PCIIDEX.SYS atapi.sys
01:19:30.929 1 nt!IofCallDriver -> \Device\Harddisk0\DR0[0x85d607d0]
01:19:30.944 3 CLASSPNP.SYS[88fa28b3] -> nt!IofCallDriver -> [0x85daf918]
01:19:30.944 5 acpi.sys[806126bc] -> nt!IofCallDriver -> \Device\Ide\IdeDeviceP1T0L0-1[0x85d3db98]
01:19:30.960 Scan finished successfully
01:19:43.409 Disk 0 MBR has been saved successfully to "C:\Users\Hamad\Desktop\MBR.dat"
01:19:43.456 The log file has been saved successfully to "C:\Users\Hamad\Desktop\aswMBR.txt"

Thank you
  • 0

#5
hamadm

hamadm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
By the way, the "include 64bit" is not exist in the software.

thank you
  • 0

#6
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
OK lets get rid of it for you

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Posted Image

    :OTL
    O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [Policies] C:\System32\chost.exe (Microsoft Corporation)
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

THEN

Please download Malwarebytes' Anti-Malware

Double Click mbam-setup.exe to install the application.
  • Make sure a checkmark is placed next to Update Malwarebytes' Anti-Malware and Launch Malwarebytes' Anti-Malware, then click Finish.
  • If an update is found, it will download and install the latest version.
  • Once the program has loaded, select "Perform Quick Scan", then click Scan.
  • The scan may take some time to finish, so please be patient.
  • When the scan is complete, click OK, then Show Results to view the results.
  • Make sure that everything is checked, and click Remove Selected.
  • When disinfection is completed, a log will open in Notepad and you may be prompted to Restart.(See Extra Note)
  • The log is automatically saved by MBAM and can be viewed by clicking the Logs tab in MBAM.
  • Copy&Paste the entire report in your next reply.
Extra Note:
If MBAM encounters a file that is difficult to remove, you will be presented with 1 of 2 prompts, click OK to either and let MBAM proceed with the disinfection process, if asked to restart the computer, please do so immediately.
  • 0

#7
hamadm

hamadm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
OTL logfile created on: 25/09/2012 16:28:26 - Run 2
OTL by OldTimer - Version 3.2.66.0 Folder = C:\Users\Hamad\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.10 Gb Available Physical Memory | 54.99% Memory free
4.23 Gb Paging File | 3.03 Gb Available in Paging File | 71.68% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 204.73 Gb Free Space | 43.96% Space Free | Partition Type: NTFS

Computer Name: HAMAD-PC | User Name: Hamad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/09/23 23:35:02 | 000,601,600 | ---- | M] (OldTimer Tools) -- C:\Users\Hamad\Desktop\OTL.exe
PRC - [2012/09/21 02:51:47 | 000,212,432 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe
PRC - [2012/09/15 05:17:27 | 000,212,432 | ---- | M] (Google Inc.) -- C:\Users\Hamad\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler.exe
PRC - [2012/09/14 04:33:34 | 000,412,016 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
PRC - [2012/09/14 04:33:34 | 000,388,976 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\hsswd.exe
PRC - [2012/09/14 03:03:54 | 000,511,344 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
PRC - [2012/08/14 10:52:28 | 001,014,624 | ---- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) -- C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
PRC - [2012/07/27 23:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/26 05:31:33 | 000,219,008 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\spool\drivers\w32x86\3\E_TATIHTE.EXE
PRC - [2012/07/24 15:38:42 | 002,327,208 | ---- | M] (DSNR Media Innovations) -- C:\Users\Hamad\AppData\Roaming\eType\eTypeUpdate.exe
PRC - [2012/07/16 17:31:32 | 002,673,064 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2012/06/16 23:49:54 | 000,397,848 | ---- | M] () -- C:\ProgramData\IBUpdaterService\ibsvc.exe
PRC - [2012/06/11 20:19:36 | 000,468,992 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2012/06/11 20:19:02 | 000,217,600 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2012/06/11 13:10:58 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
PRC - [2012/03/26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/03/12 00:13:21 | 001,983,232 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2010/12/07 17:28:06 | 000,579,384 | ---- | M] (Autodesk, Inc.) -- C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe
PRC - [2010/10/12 13:56:40 | 000,979,328 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
PRC - [2010/08/19 11:52:14 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
PRC - [2010/08/19 11:52:04 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe
PRC - [2009/05/14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
PRC - [2009/04/11 09:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/04/11 09:27:20 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
PRC - [2008/12/31 13:12:42 | 000,066,824 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk2008\PD91AgentS1.exe
PRC - [2008/12/31 13:12:40 | 000,693,512 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
PRC - [2008/12/30 12:01:52 | 017,059,840 | R--- | M] (VIA) -- C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
PRC - [2008/12/10 16:16:18 | 000,380,928 | ---- | M] (AMD) -- C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe
PRC - [2006/12/23 18:05:20 | 000,143,360 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2006/12/23 18:04:42 | 000,905,216 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/14 03:35:25 | 000,240,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\9104e78d8897df008eed3a2af3bda6a2\WindowsFormsIntegration.ni.dll
MOD - [2012/06/14 03:35:22 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012/06/14 03:33:30 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012/06/14 03:33:23 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012/06/14 03:33:12 | 014,329,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7343fbab1ba137db2f8b284047ef3f3c\PresentationFramework.ni.dll
MOD - [2012/06/14 03:32:45 | 012,219,392 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b6293b0c23321c255c2530aea8e32bb\PresentationCore.ni.dll
MOD - [2012/06/11 19:24:32 | 000,037,376 | ---- | M] () -- C:\Windows\System32\atitmpxx.dll
MOD - [2012/06/11 13:11:04 | 000,095,232 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
MOD - [2012/06/11 12:45:06 | 000,369,152 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2012/05/26 14:37:04 | 002,295,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\0f2b877ed16daa577f95be735a63d19c\System.Core.ni.dll
MOD - [2012/05/26 14:36:49 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012/05/26 14:36:40 | 000,060,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\5fd0071c259b92078ced7cd752a14730\UIAutomationProvider.ni.dll
MOD - [2012/05/26 14:36:37 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012/05/26 14:22:58 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012/05/26 14:22:03 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c8c3ab08933fef9fb6657da871395c46\PresentationFramework.Aero.ni.dll
MOD - [2012/05/26 14:21:34 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\54426ee1881b42af5b090e223f43823c\WindowsBase.ni.dll
MOD - [2012/05/26 14:21:31 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/26 14:21:24 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2012/03/16 15:42:58 | 000,315,392 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libtidy.dll
MOD - [2012/03/16 15:42:56 | 000,433,664 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libxml2.dll
MOD - [2012/02/13 14:02:19 | 001,736,984 | ---- | M] () -- C:\Windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
MOD - [2011/09/27 07:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 07:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/04/13 18:45:44 | 000,109,464 | ---- | M] () -- C:\Users\Hamad\AppData\Roaming\eType\MyZip.dll
MOD - [2008/05/30 05:38:22 | 000,069,632 | R--- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
MOD - [2008/03/17 12:50:00 | 000,069,632 | R--- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll
MOD - [2008/02/14 08:57:00 | 000,094,208 | R--- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\VMicApi.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\programdata\Clickfree\FullImagingBackup\FullImagingService.exe -- (FullImagingService)
SRV - File not found [Auto | Stopped] -- C:\ProgramData\Clickfree\FullImagingBackup\FibUac.exe -- (FibUacService)
SRV - [2012/09/14 04:33:34 | 000,412,016 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
SRV - [2012/09/14 04:33:34 | 000,388,976 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2012/09/14 03:03:54 | 000,511,344 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (hshld)
SRV - [2012/09/14 00:08:34 | 000,078,072 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hotspot Shield\bin\HSSTrayService.exe -- (HssTrayService)
SRV - [2012/09/08 05:13:43 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/27 23:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/16 17:31:32 | 002,673,064 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012/06/16 23:49:54 | 000,397,848 | ---- | M] () [Auto | Running] -- C:\ProgramData\IBUpdaterService\ibsvc.exe -- (IBUpdaterService)
SRV - [2012/06/11 20:19:02 | 000,217,600 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2012/06/11 13:10:58 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV - [2012/03/26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/03/12 00:13:21 | 001,983,232 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011/08/27 08:44:38 | 001,044,816 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/07/13 17:00:16 | 000,036,352 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\HMA! Pro VPN\bin\openvpnserv.exe -- (OpenVPNService)
SRV - [2011/06/23 14:25:20 | 000,157,544 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Sound Organizer\Sony.Earth\PACSPTISVR.exe -- (PACSPTISVR-Sound_Organizer)
SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2010/12/07 17:28:06 | 000,579,384 | ---- | M] (Autodesk, Inc.) [Auto | Running] -- C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe -- (mitsijm2012)
SRV - [2010/08/19 11:52:04 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe)
SRV - [2009/05/14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) [Auto | Running] -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0)
SRV - [2008/12/31 13:12:44 | 000,910,600 | ---- | M] (Raxco Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe -- (PD91Engine)
SRV - [2008/12/31 13:12:40 | 000,693,512 | ---- | M] (Raxco Software, Inc.) [Auto | Running] -- C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe -- (PD91Agent)
SRV - [2008/01/18 23:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/05/31 09:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 09:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- D:\NTGLM7X.sys -- (SetupNTGLM7X)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\NTACCESS.sys -- (NTACCESS)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\install4\MSICPL.sys -- (MSICPL)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\btwusb.sys -- (BTWUSB)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2012/09/22 11:40:47 | 000,152,576 | ---- | M] (SysProgs.org) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BazisPortableCDBus.sys -- (BazisPortableCDBus)
DRV - [2012/07/10 05:48:18 | 000,035,560 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\hssdrv6.sys -- (HssDRV6)
DRV - [2012/06/11 21:58:44 | 008,733,696 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2012/06/11 19:25:48 | 000,295,936 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2012/03/20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012/03/12 00:13:29 | 000,082,400 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\inspect.sys -- (inspect)
DRV - [2012/03/12 00:13:28 | 000,038,616 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2012/03/12 00:13:26 | 000,491,816 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\System32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2012/02/23 15:31:36 | 000,083,984 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdLH3.sys -- (AtiHDAudioService)
DRV - [2012/02/16 00:24:36 | 000,181,432 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2012/02/16 00:24:36 | 000,080,824 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2012/01/05 02:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2011/12/01 05:46:38 | 000,021,992 | ---- | M] (Silicon Laboratories) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SiUSBXp.sys -- (SIUSBXP)
DRV - [2011/07/13 17:00:14 | 000,026,112 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tap0901.sys -- (tap0901)
DRV - [2010/06/01 14:07:14 | 000,116,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2010/05/22 14:48:20 | 000,070,656 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2010/03/25 10:08:38 | 000,105,984 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010/03/20 11:56:04 | 000,101,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010/02/18 09:18:22 | 000,037,944 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\amdiox86.sys -- (amdiox86)
DRV - [2009/08/05 06:18:22 | 000,048,640 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1E60x86.sys -- (L1E)
DRV - [2009/04/11 07:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB)
DRV - [2009/01/05 14:16:36 | 000,071,184 | R--- | M] (Raxco Software, Inc.) [File_System | Auto | Running] -- C:\Windows\System32\drivers\DefragFS.sys -- (DefragFS)
DRV - [2008/12/19 06:40:06 | 000,923,136 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2008/04/28 16:26:42 | 000,014,352 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie)
DRV - [2008/03/19 18:28:52 | 000,022,072 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\usbfilter.sys -- (usbfilter)
DRV - [2006/10/18 15:44:48 | 000,007,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2786678


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://badoo.com/startpage/
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 00 6F 08 3F 02 CD 01 [binary data]
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\SearchScopes\{8A244612-A1F7-11E0-95C0-E71F4824019B}: "URL" = http://badoo.com/sta...q={searchTerms}
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2786678
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Hamad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Hamad\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Hamad\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Hamad\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)



========== Chrome ==========

CHR - homepage: http://www.google.co...=en&source=iglk
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage: http://www.google.co...=en&source=iglk
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Hamad\AppData\Local\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Hamad\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Hamad\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Hamad\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Hamad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Hamad\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U5 (Enabled) = C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

O1 HOSTS File: ([2012/09/25 15:56:06 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
O3 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O3 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [EPLTarget\P0000000000000000] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_TATIHTE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [eType] C:\Users\Hamad\AppData\Roaming\eType\eType.exe (DSNR Media Innovations)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe (AMD)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [MzRAMBooster] C:\Program Files\Mz Ultimate Tools\Mz RAM Booster\MzRAMBooster.exe (Mz Ultimate Tools)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [POEngine5] File not found
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [Rest Reminder] C:\Users\Hamad\Desktop\Tools\RestReminder.exe (NGCoders)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe ()
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteTray.lnk = C:\Program Files\Evernote\Evernote\EvernoteTray.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GoalSync 3.0.lnk = C:\Program Files\Success Studios\GoalSync 3.0\GoalSync3.exe (Success Studios)
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iMindMap Preloader.lnk = C:\Users\Hamad\.thinkbuzan\imindmap\preload\iMindMap_Preloader.exe ()
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Bluetooth\Bluetooth Software\btsendto_ie_ctx.htm File not found
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.7.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{04692C57-3E14-4E03-B576-8DA1A24E6C0C}: DhcpNameServer = 84.235.107.122 84.235.107.123
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{13C7E60A-EF6A-432C-9B82-4D89CB7AA6D2}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F9F615D-0349-47F8-BFC3-B16499BF9FB0}: DhcpNameServer = 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F9F615D-0349-47F8-BFC3-B16499BF9FB0}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4FEE97B2-80F1-4C1E-B131-9DCF5475DE71}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ACA39361-FD78-46FC-9FC5-63B2976D2B1D}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B5DDAC35-B3E7-4933-A271-708A75D296A3}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF758A09-D2E2-4787-8764-22389FC697B6}: NameServer = 10.93.120.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EFF4DFDD-2EF5-41DD-9FEE-70475D11B0B7}: DhcpNameServer = 84.235.107.250 84.235.107.251
O20 - AppInit_DLLs: (C:\Windows\system32\guard32.dll) - C:\Windows\System32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 00:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0906f0d7-0aea-11e1-aee9-e53dc77dbff0}\Shell - "" = AutoRun
O33 - MountPoints2\{0906f0d7-0aea-11e1-aee9-e53dc77dbff0}\Shell\AutoRun\command - "" = E:\FIBPGuard.exe
O33 - MountPoints2\{0af632fe-f214-11e1-9214-e8d63c07d8bd}\Shell - "" = AutoRun
O33 - MountPoints2\{0af632fe-f214-11e1-9214-e8d63c07d8bd}\Shell\AutoRun\command - "" = E:\Autorun.exe
O33 - MountPoints2\{4c3be28b-e6d8-11e0-bee2-001e101f2500}\Shell - "" = AutoRun
O33 - MountPoints2\{4c3be28b-e6d8-11e0-bee2-001e101f2500}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{4c3be2de-e6d8-11e0-bee2-001e101f79c9}\Shell - "" = AutoRun
O33 - MountPoints2\{4c3be2de-e6d8-11e0-bee2-001e101f79c9}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{7152b1de-da97-11e0-a371-001e101f3315}\Shell - "" = AutoRun
O33 - MountPoints2\{7152b1de-da97-11e0-a371-001e101f3315}\Shell\AutoRun\command - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{7152b1de-da97-11e0-a371-001e101f3315}\Shell\start\COMMAND - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{834dd50f-dc90-11e0-bda7-001e101f8924}\Shell - "" = AutoRun
O33 - MountPoints2\{834dd50f-dc90-11e0-bda7-001e101f8924}\Shell\AutoRun\command - "" = G:\FIBPGuard.exe
O33 - MountPoints2\{99142b42-da3b-11e0-822b-001e101fb681}\Shell - "" = AutoRun
O33 - MountPoints2\{99142b42-da3b-11e0-822b-001e101fb681}\Shell\AutoRun\command - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{99142b42-da3b-11e0-822b-001e101fb681}\Shell\start\COMMAND - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{99142b44-da3b-11e0-822b-001e101fb681}\Shell - "" = AutoRun
O33 - MountPoints2\{99142b44-da3b-11e0-822b-001e101fb681}\Shell\AutoRun\command - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{99142b44-da3b-11e0-822b-001e101fb681}\Shell\start\COMMAND - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{b3351883-cf35-11e0-95a6-e57d28a13cad}\Shell - "" = AutoRun
O33 - MountPoints2\{b3351883-cf35-11e0-95a6-e57d28a13cad}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{bbc7ab38-042d-11e2-8b30-d85d19b1fac9}\Shell - "" = AutoRun
O33 - MountPoints2\{bbc7ab38-042d-11e2-8b30-d85d19b1fac9}\Shell\AutoRun\command - "" = E:\LiveTutDVD.exe
O33 - MountPoints2\{c46d67fb-cca5-11e1-9820-892c994a8b31}\Shell - "" = AutoRun
O33 - MountPoints2\{c46d67fb-cca5-11e1-9820-892c994a8b31}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{cbb33115-eb72-11e0-b1ef-00248ca430af}\Shell - "" = AutoRun
O33 - MountPoints2\{cbb33115-eb72-11e0-b1ef-00248ca430af}\Shell\AutoRun\command - "" = E:\setup.exe
O33 - MountPoints2\{cbb33148-eb72-11e0-b1ef-00248ca430af}\Shell - "" = AutoRun
O33 - MountPoints2\{cbb33148-eb72-11e0-b1ef-00248ca430af}\Shell\AutoRun\command - "" = E:\setup.exe
O34 - HKLM BootExecute: (PDBoot.exe)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/09/25 15:56:02 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/09/24 23:57:08 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\Business Plan Pro Samples
[2012/09/24 23:45:23 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\IsolatedStorage
[2012/09/24 23:38:26 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\Palo_Alto_Software
[2012/09/24 23:38:26 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\bppenu11
[2012/09/24 23:37:50 | 000,000,000 | ---D | C] -- C:\ProgramData\IsolatedStorage
[2012/09/24 23:37:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Business Plan Pro 11.0
[2012/09/24 23:37:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Palo Alto Software
[2012/09/24 23:36:04 | 000,000,000 | ---D | C] -- C:\Program Files\Business Plan Pro
[2012/09/24 11:16:07 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Native Instruments
[2012/09/24 11:13:46 | 000,000,000 | -H-D | C] -- C:\ProgramData\{7707EA53-E29B-48FC-B28B-C8EE171EA0EB}
[2012/09/24 11:09:55 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Native Instruments
[2012/09/24 11:09:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Native Instruments
[2012/09/24 11:09:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
[2012/09/24 11:09:51 | 000,000,000 | ---D | C] -- C:\Program Files\Native Instruments
[2012/09/23 23:36:30 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Hamad\Desktop\aswMBR.exe
[2012/09/23 23:34:47 | 000,601,600 | ---- | C] (OldTimer Tools) -- C:\Users\Hamad\Desktop\OTL.exe
[2012/09/22 19:54:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Propellerhead Software
[2012/09/19 21:01:53 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\NP3
[2012/09/19 20:54:39 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\MWS
[2012/09/19 20:54:39 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\MindWorkStation
[2012/09/19 20:54:39 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Mind WorkStation Sessions
[2012/09/19 20:44:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mind WorkStation
[2012/09/19 20:43:52 | 000,000,000 | ---D | C] -- C:\Program Files\Mind WorkStation
[2012/09/19 19:00:06 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\NeuroProgrammer3
[2012/09/19 19:00:06 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Neuro-Programmer 3 Documents
[2012/09/19 18:59:54 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\Xenocode
[2012/09/19 18:59:54 | 000,000,000 | ---D | C] -- C:\Program Files\Xenocode
[2012/09/19 18:46:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Neuro-Programmer 3
[2012/09/19 18:46:24 | 000,000,000 | ---D | C] -- C:\Program Files\Neuro-Programmer 3
[2012/09/18 23:33:02 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Ableton
[2012/09/18 23:33:02 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Ableton
[2012/09/18 23:20:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Ableton
[2012/09/11 21:42:14 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Mozilla
[2012/09/11 08:52:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/09/08 17:46:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Holdem Indicator
[2012/09/08 17:45:43 | 000,000,000 | ---D | C] -- C:\Program Files\Holdem Indicator
[2012/09/08 17:24:13 | 000,000,000 | ---D | C] -- C:\Users\Hamad\PokerOffice
[2012/09/08 17:23:58 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerOffice5
[2012/09/08 17:22:18 | 000,000,000 | ---D | C] -- C:\Program Files\PokerOffice5
[2012/09/06 08:12:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PartyCasino
[2012/09/06 07:36:13 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\betonline
[2012/09/06 07:35:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetOnline Poker 8.2
[2012/09/06 07:35:16 | 000,000,000 | ---D | C] -- C:\Program Files\BetOnline Poker 8.2
[2012/09/06 07:07:18 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Mozilla-Cache
[2012/09/06 07:06:07 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Party
[2012/09/06 07:05:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PartyPoker
[2012/09/06 07:01:57 | 000,000,000 | ---D | C] -- C:\Programs
[2012/09/02 00:21:53 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\dvd
[2012/09/02 00:14:43 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\DVD Flick
[2012/09/02 00:14:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Flick
[2012/09/02 00:14:23 | 000,040,960 | ---- | C] (vbAccelerator) -- C:\Windows\System32\ssubtmr6.dll
[2012/09/02 00:14:23 | 000,036,864 | ---- | C] (Robdogg Inc.) -- C:\Windows\System32\trayicon_handler.ocx
[2012/09/02 00:14:22 | 000,028,672 | ---- | C] (-) -- C:\Windows\System32\mousewheel.ocx
[2012/09/02 00:14:22 | 000,000,000 | ---D | C] -- C:\Program Files\DVD Flick
[2012/09/01 18:39:07 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\NeroVision
[2012/08/31 11:04:25 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\Ubisoft Game Launcher
[2012/08/31 10:20:17 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Ubisoft
[2012/08/31 10:04:55 | 000,000,000 | ---D | C] -- C:\Program Files\Ubisoft
[2012/08/31 10:03:55 | 000,000,000 | -H-D | C] -- C:\Users\Hamad\InstallAnywhere
[2012/08/30 12:40:49 | 000,000,000 | -H-D | C] -- C:\Windows\PIF
[2012/08/28 00:29:32 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TriDef 3D
[2012/08/28 00:29:02 | 000,000,000 | ---D | C] -- C:\ProgramData\DDD
[2012/08/28 00:28:47 | 000,000,000 | ---D | C] -- C:\Program Files\TriDef 3D
[2012/08/28 00:20:48 | 000,000,000 | ---D | C] -- C:\Program Files\MonitorDriver
[2012/08/27 02:36:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
[2012/08/27 01:52:56 | 000,000,000 | ---D | C] -- C:\Windows\CheckSur
[2012/08/27 01:10:27 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\dvdcss
[2012/08/27 00:53:26 | 002,808,832 | R--- | C] (RealTek Semicoductor Corp.) -- C:\Windows\alcwzrd.exe
[2012/08/27 00:53:23 | 000,000,000 | ---D | C] -- C:\Windows\System32\RTCOM
[2012/08/27 00:52:10 | 000,000,000 | ---D | C] -- C:\Program Files\Realtek

========== Files - Modified Within 30 Days ==========

[2012/09/25 16:22:15 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3562748159-1388759733-2883167963-1000UA.job
[2012/09/25 16:21:54 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/25 16:21:51 | 000,004,176 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/25 16:21:51 | 000,004,176 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/25 16:21:43 | 2146,623,488 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/25 16:18:52 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012/09/25 16:18:17 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/25 15:57:09 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/25 15:56:06 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2012/09/25 15:43:20 | 000,002,613 | ---- | M] () -- C:\Users\Public\Desktop\Business Plan Pro 11.0.lnk
[2012/09/25 13:12:52 | 000,047,616 | ---- | M] () -- C:\Users\Hamad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/25 05:22:01 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3562748159-1388759733-2883167963-1000Core.job
[2012/09/24 11:13:28 | 000,000,909 | ---- | M] () -- C:\Users\Public\Desktop\Traktor 2.lnk
[2012/09/23 23:39:32 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Hamad\Desktop\aswMBR.exe
[2012/09/23 23:35:02 | 000,601,600 | ---- | M] (OldTimer Tools) -- C:\Users\Hamad\Desktop\OTL.exe
[2012/09/22 11:44:31 | 000,660,296 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/09/22 11:44:31 | 000,126,518 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/09/22 11:40:47 | 000,152,576 | ---- | M] (SysProgs.org) -- C:\Windows\System32\drivers\BazisPortableCDBus.sys
[2012/09/19 21:02:01 | 000,000,924 | ---- | M] () -- C:\Users\Public\Desktop\Neuro-Programmer 3.lnk
[2012/09/19 20:44:02 | 000,000,895 | ---- | M] () -- C:\Users\Public\Desktop\Mind WorkStation.lnk
[2012/09/19 16:38:26 | 000,000,749 | ---- | M] () -- C:\Users\Hamad\Desktop\Ableton Live 8.lnk
[2012/09/10 17:00:42 | 000,010,063 | -H-- | M] () -- C:\Users\Hamad\AppData\Roaming\Hamadlog.dat
[2012/09/08 17:46:05 | 000,000,919 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Holdem Indicator.lnk
[2012/09/08 17:46:05 | 000,000,895 | ---- | M] () -- C:\Users\Hamad\Desktop\Holdem Indicator.lnk
[2012/09/08 17:23:59 | 000,001,740 | ---- | M] () -- C:\Users\Hamad\Desktop\PokerOffice 5.lnk
[2012/09/06 08:12:37 | 000,001,667 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyCasino.lnk
[2012/09/06 08:12:36 | 000,001,643 | ---- | M] () -- C:\Users\Hamad\Desktop\PartyCasino.lnk
[2012/09/06 07:35:36 | 000,001,810 | ---- | M] () -- C:\Users\Public\Desktop\BetOnline Poker 8.2.lnk
[2012/09/06 07:05:54 | 000,001,667 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
[2012/09/06 07:05:54 | 000,001,643 | ---- | M] () -- C:\Users\Hamad\Desktop\PartyPoker.lnk
[2012/09/03 03:18:08 | 000,002,004 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/09/02 00:14:32 | 000,001,699 | ---- | M] () -- C:\Users\Hamad\Desktop\DVD Flick.lnk
[2012/08/30 03:17:41 | 000,177,640 | ---- | M] () -- C:\Users\Hamad\Documents\SetupData.trx
[2012/08/30 03:17:40 | 000,007,599 | ---- | M] () -- C:\Users\Hamad\Documents\ReviewActions.xml
[2012/08/30 02:52:09 | 000,000,725 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Evernote.lnk
[2012/08/30 02:51:55 | 000,000,825 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\YNAB 3.lnk
[2012/08/30 02:51:51 | 000,001,011 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\iMindMap 5.lnk
[2012/08/28 18:16:40 | 000,002,133 | ---- | M] () -- C:\Users\Public\Desktop\SyncMaster 3D Game Launcher (TriDef 3D).lnk
[2012/08/27 16:07:24 | 000,177,640 | ---- | M] () -- C:\Users\Hamad\Documents\SetupData.bak.trx
[2012/08/27 02:44:47 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini

========== Files Created - No Company Name ==========

[2012/09/24 23:37:39 | 000,002,613 | ---- | C] () -- C:\Users\Public\Desktop\Business Plan Pro 11.0.lnk
[2012/09/24 11:13:28 | 000,000,909 | ---- | C] () -- C:\Users\Public\Desktop\Traktor 2.lnk
[2012/09/19 20:44:02 | 000,000,895 | ---- | C] () -- C:\Users\Public\Desktop\Mind WorkStation.lnk
[2012/09/19 18:46:46 | 000,000,924 | ---- | C] () -- C:\Users\Public\Desktop\Neuro-Programmer 3.lnk
[2012/09/19 16:38:26 | 000,000,749 | ---- | C] () -- C:\Users\Hamad\Desktop\Ableton Live 8.lnk
[2012/09/18 23:20:26 | 000,000,749 | ---- | C] () -- C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ableton Live 8.lnk
[2012/09/08 17:46:05 | 000,000,919 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Holdem Indicator.lnk
[2012/09/08 17:46:05 | 000,000,895 | ---- | C] () -- C:\Users\Hamad\Desktop\Holdem Indicator.lnk
[2012/09/08 17:23:58 | 000,001,740 | ---- | C] () -- C:\Users\Hamad\Desktop\PokerOffice 5.lnk
[2012/09/06 08:12:37 | 000,001,667 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyCasino.lnk
[2012/09/06 08:12:36 | 000,001,643 | ---- | C] () -- C:\Users\Hamad\Desktop\PartyCasino.lnk
[2012/09/06 07:35:36 | 000,001,810 | ---- | C] () -- C:\Users\Public\Desktop\BetOnline Poker 8.2.lnk
[2012/09/06 07:05:54 | 000,001,667 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
[2012/09/06 07:05:54 | 000,001,643 | ---- | C] () -- C:\Users\Hamad\Desktop\PartyPoker.lnk
[2012/09/02 00:14:32 | 000,001,699 | ---- | C] () -- C:\Users\Hamad\Desktop\DVD Flick.lnk
[2012/08/30 02:52:09 | 000,000,725 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Evernote.lnk
[2012/08/30 02:51:55 | 000,000,825 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\YNAB 3.lnk
[2012/08/30 02:51:51 | 000,001,011 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\iMindMap 5.lnk
[2012/08/28 00:29:39 | 000,002,133 | ---- | C] () -- C:\Users\Public\Desktop\SyncMaster 3D Game Launcher (TriDef 3D).lnk
[2012/08/27 02:44:47 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2012/08/27 00:53:23 | 000,143,360 | R--- | C] () -- C:\Windows\System32\RtlCPAPI.dll
[2012/08/27 00:53:23 | 000,049,152 | R--- | C] () -- C:\Windows\System32\ChCfg.exe
[2012/08/26 04:16:53 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2012/08/26 04:16:26 | 000,000,000 | ---- | C] () -- C:\Windows\EEventManager.INI
[2012/08/25 19:28:30 | 000,660,296 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2012/08/25 19:28:30 | 000,126,518 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2012/08/25 19:26:28 | 000,047,616 | ---- | C] () -- C:\Users\Hamad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/23 02:02:40 | 000,000,022 | ---- | C] () -- C:\Windows\cmm.dat
[2012/08/23 02:02:39 | 000,001,746 | ---- | C] () -- C:\Windows\Language_trs.ini
[2012/08/23 02:02:39 | 000,000,426 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012/08/23 02:02:25 | 000,038,090 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2012/08/23 02:02:25 | 000,000,264 | ---- | C] () -- C:\Windows\Brownie.ini
[2012/08/23 02:02:24 | 000,030,320 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2012/08/23 02:02:24 | 000,000,011 | ---- | C] () -- C:\Windows\BRVIDEO.INI
[2012/08/23 02:02:24 | 000,000,000 | ---- | C] () -- C:\Windows\brmx2001.ini
[2012/08/23 02:02:24 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/08/23 02:00:10 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2012/08/23 01:38:53 | 000,159,232 | ---- | C] () -- C:\Windows\System32\clinfo.exe
[2012/08/23 01:38:51 | 000,179,271 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2012/08/23 01:38:47 | 000,000,186 | ---- | C] () -- C:\Windows\System32\CleanMem.ini
[2012/08/23 01:38:45 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2012/08/23 01:38:45 | 000,003,917 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2012/08/23 01:38:44 | 000,645,632 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2012/08/23 01:38:44 | 000,637,743 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2012/08/23 01:38:41 | 000,000,034 | ---- | C] () -- C:\Windows\System32\BXD2140.DAT
[2012/08/23 01:38:27 | 000,037,376 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2012/08/23 01:38:21 | 000,043,008 | ---- | C] () -- C:\Windows\System32\spwini.dll
[2012/08/23 01:38:15 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2012/08/23 01:38:15 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2012/08/23 01:38:09 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2012/08/23 01:38:06 | 000,062,976 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2012/08/23 01:37:32 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2012/08/23 01:37:29 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2012/08/23 01:37:26 | 000,371,128 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/08/23 01:37:25 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2012/08/23 01:37:21 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2012/08/23 01:37:21 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2012/08/23 01:37:21 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2012/08/23 01:32:58 | 000,007,680 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys
[2012/08/23 01:32:56 | 000,010,296 | ---- | C] () -- C:\Windows\System32\drivers\ASUSHWIO.SYS
[2012/08/23 01:26:54 | 000,031,274 | ---- | C] () -- C:\Users\Hamad\.TransferManager.db
[2012/08/23 01:26:02 | 000,037,845 | ---- | C] () -- C:\Users\Hamad\AppData\Roaming\Comma Separated Values (Windows).ADR
[2012/08/23 01:26:02 | 000,000,630 | ---- | C] () -- C:\Users\Hamad\AppData\Roaming\lazy_remote_server_settings.dat
[2012/08/23 01:24:34 | 000,001,356 | ---- | C] () -- C:\Users\Hamad\AppData\Local\d3d9caps.dat
[2006/07/27 02:34:15 | 000,010,063 | -H-- | C] () -- C:\Users\Hamad\AppData\Roaming\Hamadlog.dat

========== ZeroAccess Check ==========

[2006/11/02 15:54:18 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 20:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 09:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/08/23 01:25:44 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\.thinkingrock
[2012/08/23 01:25:50 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\3Dconnexion
[2012/09/22 19:54:32 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Ableton
[2012/08/23 01:25:30 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Arduino
[2012/08/23 01:25:30 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Autodesk
[2012/09/06 07:36:13 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\betonline
[2012/09/24 23:38:26 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\bppenu11
[2012/08/23 01:25:51 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Business Logic
[2012/08/23 01:25:57 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\com.conqu
[2012/08/23 01:25:49 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\com.youneedabudget.YNAB3.Live.9C763150EFAB05FD2A2B78705C7A54E2FCDDE07D.1
[2012/08/23 01:25:50 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Epson
[2012/09/25 16:25:33 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\eType
[2012/08/23 01:25:49 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Fritzing
[2012/08/23 01:25:49 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\HabitShaper
[2012/08/23 01:25:51 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Klok2.DD7F2188B985C2439837C76B42A187050457E61B.1
[2012/09/19 21:01:28 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\MindWorkStation
[2012/09/19 19:24:26 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\NeuroProgrammer3
[2012/08/23 01:25:46 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\OpenOffice.org
[2012/09/06 07:11:26 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Party
[2012/08/23 01:25:28 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Softland
[2012/08/23 01:26:02 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\TeamViewer
[2012/09/25 15:49:23 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\uTorrent
[2012/08/23 01:25:51 | 000,000,000 | -HSD | M] -- C:\Users\Hamad\AppData\Roaming\wyUpdate AU

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:157E1AD3
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:5FC93B4C

< End of report >
  • 0

#8
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
After MBAM has run could you let me know of any problems
  • 0

#9
hamadm

hamadm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
It detect "ibsvc.exe" then restart, everything is normal


Malwarebytes Anti-Malware 1.65.0.1400
www.malwarebytes.org

Database version: v2012.09.25.02

Windows Vista Service Pack 2 x86 NTFS
Internet Explorer 9.0.8112.16421
Hamad :: HAMAD-PC [administrator]

26/09/2012 00:00:00
mbam-log-2012-09-26 (00-00-00).txt

Scan type: Quick scan
Scan options enabled: Memory | Startup | Registry | File System | Heuristics/Extra | Heuristics/Shuriken | PUP | PUM
Scan options disabled: P2P
Objects scanned: 216708
Time elapsed: 5 minute(s), 3 second(s)

Memory Processes Detected: 1
C:\ProgramData\IBUpdaterService\ibsvc.exe (PUP.BundleInstaller.IB) -> 2584 -> Delete on reboot.

Memory Modules Detected: 0
(No malicious items detected)

Registry Keys Detected: 2
HKLM\SYSTEM\CurrentControlSet\Services\IBUpdaterService (PUP.BundleInstaller.IB) -> Quarantined and deleted successfully.
HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Updater Service (PUP.BundleInstaller.IB) -> Quarantined and deleted successfully.

Registry Values Detected: 0
(No malicious items detected)

Registry Data Items Detected: 0
(No malicious items detected)

Folders Detected: 0
(No malicious items detected)

Files Detected: 1
C:\ProgramData\IBUpdaterService\ibsvc.exe (PUP.BundleInstaller.IB) -> Delete on reboot.

(end)


Thank you
  • 0

#10
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Lets kill the entire folder for that, then let me know if any problems remain

Warning This fix is only relevant for this system and no other, using on another computer may cause problems

Be advised that when the fix commences it will shut down all running processes and you may lose the desktop and icons, they will return on reboot

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following
    Posted Image

    :OTL
    
    :Files
    C:\ProgramData\IBUpdaterService
    
    :Commands
    [purity]
    [resethosts]
    [emptytemp]
    [CREATERESTOREPOINT]
    [Reboot]
  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done
  • Open OTL again and click the Quick Scan button. Post the log it produces in your next reply.

  • 0

Advertisements


#11
hamadm

hamadm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
OTL logfile created on: 26/09/2012 01:13:01 - Run 3
OTL by OldTimer - Version 3.2.66.0 Folder = C:\Users\Hamad\Desktop
Windows Vista Business Edition Service Pack 2 (Version = 6.0.6002) - Type = NTWorkstation
Internet Explorer (Version = 9.0.8112.16421)
Locale: 00000809 | Country: United Kingdom | Language: ENG | Date Format: dd/MM/yyyy

2.00 Gb Total Physical Memory | 1.04 Gb Available Physical Memory | 52.01% Memory free
4.23 Gb Paging File | 3.01 Gb Available in Paging File | 71.01% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files
Drive C: | 465.76 Gb Total Space | 203.07 Gb Free Space | 43.60% Space Free | Partition Type: NTFS

Computer Name: HAMAD-PC | User Name: Hamad | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Quick Scan
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2012/09/23 23:35:02 | 000,601,600 | ---- | M] (OldTimer Tools) -- C:\Users\Hamad\Desktop\OTL.exe
PRC - [2012/09/21 02:51:47 | 000,212,432 | ---- | M] (Google Inc.) -- C:\Program Files\Google\Update\1.3.21.123\GoogleCrashHandler.exe
PRC - [2012/09/15 05:17:27 | 000,212,432 | ---- | M] (Google Inc.) -- C:\Users\Hamad\AppData\Local\Google\Update\1.3.21.123\GoogleCrashHandler.exe
PRC - [2012/09/14 04:33:34 | 000,412,016 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe
PRC - [2012/09/14 04:33:34 | 000,388,976 | ---- | M] () -- C:\Program Files\Hotspot Shield\bin\hsswd.exe
PRC - [2012/09/14 03:03:54 | 000,511,344 | ---- | M] (AnchorFree Inc.) -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe
PRC - [2012/08/14 10:52:28 | 001,014,624 | ---- | M] (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041) -- C:\Program Files\Evernote\Evernote\EvernoteClipper.exe
PRC - [2012/07/27 23:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2012/07/26 05:31:33 | 000,219,008 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Windows\System32\spool\drivers\w32x86\3\E_TATIHTE.EXE
PRC - [2012/07/24 15:38:42 | 002,327,208 | ---- | M] (DSNR Media Innovations) -- C:\Users\Hamad\AppData\Roaming\eType\eTypeUpdate.exe
PRC - [2012/07/16 17:31:32 | 002,673,064 | ---- | M] (TeamViewer GmbH) -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe
PRC - [2012/06/11 20:19:36 | 000,468,992 | ---- | M] (AMD) -- C:\Windows\System32\atieclxx.exe
PRC - [2012/06/11 20:19:02 | 000,217,600 | ---- | M] (AMD) -- C:\Windows\System32\atiesrxx.exe
PRC - [2012/06/11 13:10:58 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe
PRC - [2012/03/26 17:08:12 | 000,931,200 | ---- | M] (Microsoft Corporation) -- C:\Program Files\Microsoft Security Client\msseces.exe
PRC - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) -- c:\Program Files\Microsoft Security Client\MsMpEng.exe
PRC - [2012/03/12 00:13:21 | 001,983,232 | ---- | M] (COMODO) -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe
PRC - [2010/12/07 17:28:06 | 000,579,384 | ---- | M] (Autodesk, Inc.) -- C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe
PRC - [2010/10/12 13:56:40 | 000,979,328 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files\EPSON Software\Event Manager\EEventManager.exe
PRC - [2010/08/19 11:52:14 | 000,241,664 | ---- | M] (Huawei Technologies Co., Ltd.) -- C:\ProgramData\DatacardService\DCSHelper.exe
PRC - [2010/08/19 11:52:04 | 000,229,376 | ---- | M] () -- C:\ProgramData\DatacardService\DCService.exe
PRC - [2009/05/14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe
PRC - [2009/04/11 09:27:36 | 002,926,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\explorer.exe
PRC - [2009/04/11 09:27:20 | 000,088,576 | ---- | M] (Microsoft Corporation) -- C:\Windows\System32\audiodg.exe
PRC - [2009/01/17 19:09:30 | 000,264,704 | ---- | M] (NGCoders) -- C:\Users\Hamad\Desktop\Tools\RestReminder.exe
PRC - [2008/12/31 13:12:42 | 000,066,824 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk2008\PD91AgentS1.exe
PRC - [2008/12/31 13:12:40 | 000,693,512 | ---- | M] (Raxco Software, Inc.) -- C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe
PRC - [2008/12/30 12:01:52 | 017,059,840 | R--- | M] (VIA) -- C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe
PRC - [2008/12/10 16:16:18 | 000,380,928 | ---- | M] (AMD) -- C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe
PRC - [2006/12/23 18:05:20 | 000,143,360 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe
PRC - [2006/12/23 18:04:42 | 000,905,216 | ---- | M] (Nero AG) -- C:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exe


========== Modules (No Company Name) ==========

MOD - [2012/06/14 03:35:25 | 000,240,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsFormsIntegra#\9104e78d8897df008eed3a2af3bda6a2\WindowsFormsIntegration.ni.dll
MOD - [2012/06/14 03:35:22 | 011,820,032 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Web\508b444db523c5cf20ff12c7f440837b\System.Web.ni.dll
MOD - [2012/06/14 03:33:30 | 012,433,920 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Windows.Forms\f2691cfa7671cdc58179e56ba9227591\System.Windows.Forms.ni.dll
MOD - [2012/06/14 03:33:23 | 001,592,320 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Drawing\18f9789aa214c657113e676b3a9015aa\System.Drawing.ni.dll
MOD - [2012/06/14 03:33:12 | 014,329,856 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\7343fbab1ba137db2f8b284047ef3f3c\PresentationFramework.ni.dll
MOD - [2012/06/14 03:32:45 | 012,219,392 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationCore\7b6293b0c23321c255c2530aea8e32bb\PresentationCore.ni.dll
MOD - [2012/06/11 19:24:32 | 000,037,376 | ---- | M] () -- C:\Windows\System32\atitmpxx.dll
MOD - [2012/06/11 13:11:04 | 000,095,232 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Proxy.Native.dll
MOD - [2012/06/11 12:45:06 | 000,369,152 | ---- | M] () -- C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLI.Aspect.CrossDisplay.Graphics.Dashboard.dll
MOD - [2012/05/26 14:37:04 | 002,295,296 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Core\0f2b877ed16daa577f95be735a63d19c\System.Core.ni.dll
MOD - [2012/05/26 14:36:49 | 000,771,584 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Runtime.Remo#\846b9cf2756fdd15f704c9bab9c70b6f\System.Runtime.Remoting.ni.dll
MOD - [2012/05/26 14:36:40 | 000,060,928 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\UIAutomationProvider\5fd0071c259b92078ced7cd752a14730\UIAutomationProvider.ni.dll
MOD - [2012/05/26 14:36:37 | 000,971,264 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Configuration\bd76aaaa03ddc15d1840207b5a480644\System.Configuration.ni.dll
MOD - [2012/05/26 14:22:58 | 005,450,752 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System.Xml\d2630342a066a7cb9056d9eb6157687a\System.Xml.ni.dll
MOD - [2012/05/26 14:22:03 | 000,368,128 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\PresentationFramewo#\c8c3ab08933fef9fb6657da871395c46\PresentationFramework.Aero.ni.dll
MOD - [2012/05/26 14:21:34 | 003,325,952 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\WindowsBase\54426ee1881b42af5b090e223f43823c\WindowsBase.ni.dll
MOD - [2012/05/26 14:21:31 | 007,953,408 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\System\28d633338fc8d29f8af31935ef7d001b\System.ni.dll
MOD - [2012/05/26 14:21:24 | 011,492,352 | ---- | M] () -- C:\Windows\assembly\NativeImages_v2.0.50727_32\mscorlib\af9c9e9d7e0523cd444f8b551baa9cbf\mscorlib.ni.dll
MOD - [2012/03/16 15:42:58 | 000,315,392 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libtidy.dll
MOD - [2012/03/16 15:42:56 | 000,433,664 | ---- | M] () -- C:\Program Files\Evernote\Evernote\libxml2.dll
MOD - [2012/02/13 14:02:19 | 001,736,984 | ---- | M] () -- C:\Windows\assembly\GAC_32\PresentationCore\3.0.0.0__31bf3856ad364e35\wpfgfx_v0300.dll
MOD - [2011/03/17 00:11:16 | 004,297,568 | ---- | M] () -- C:\Program Files\Common Files\microsoft shared\OFFICE14\Cultures\OFFICE.ODF
MOD - [2010/04/13 18:45:44 | 000,109,464 | ---- | M] () -- C:\Users\Hamad\AppData\Roaming\eType\MyZip.dll
MOD - [2008/05/30 05:38:22 | 000,069,632 | R--- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\Dts2ApoApi.dll
MOD - [2008/03/17 12:50:00 | 000,069,632 | R--- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\QsApoApi.dll
MOD - [2008/02/14 08:57:00 | 000,094,208 | R--- | M] () -- C:\Program Files\VIA\VIAudioi\VDeck\VMicApi.dll


========== Services (SafeList) ==========

SRV - File not found [Auto | Stopped] -- C:\programdata\Clickfree\FullImagingBackup\FullImagingService.exe -- (FullImagingService)
SRV - File not found [Auto | Stopped] -- C:\ProgramData\Clickfree\FullImagingBackup\FibUac.exe -- (FibUacService)
SRV - [2012/09/14 04:33:34 | 000,412,016 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\HssWPR\hsssrv.exe -- (HssSrv)
SRV - [2012/09/14 04:33:34 | 000,388,976 | ---- | M] () [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\hsswd.exe -- (HssWd)
SRV - [2012/09/14 03:03:54 | 000,511,344 | ---- | M] (AnchorFree Inc.) [Auto | Running] -- C:\Program Files\Hotspot Shield\bin\openvpnas.exe -- (hshld)
SRV - [2012/09/14 00:08:34 | 000,078,072 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\Hotspot Shield\bin\HSSTrayService.exe -- (HssTrayService)
SRV - [2012/09/08 05:13:43 | 000,250,568 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\System32\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2012/07/27 23:51:26 | 000,063,960 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2012/07/16 17:31:32 | 002,673,064 | ---- | M] (TeamViewer GmbH) [Auto | Running] -- C:\Program Files\TeamViewer\Version7\TeamViewer_Service.exe -- (TeamViewer7)
SRV - [2012/06/11 20:19:02 | 000,217,600 | ---- | M] (AMD) [Auto | Running] -- C:\Windows\System32\atiesrxx.exe -- (AMD External Events Utility)
SRV - [2012/06/11 13:10:58 | 000,291,840 | ---- | M] (Advanced Micro Devices, Inc.) [Auto | Running] -- C:\Program Files\ATI Technologies\ATI.ACE\Fuel\Fuel.Service.exe -- (AMD FUEL Service)
SRV - [2012/03/26 17:03:40 | 000,214,952 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- c:\Program Files\Microsoft Security Client\NisSrv.exe -- (NisSrv)
SRV - [2012/03/26 17:03:40 | 000,011,552 | ---- | M] (Microsoft Corporation) [Auto | Running] -- c:\Program Files\Microsoft Security Client\MsMpEng.exe -- (MsMpSvc)
SRV - [2012/03/12 00:13:21 | 001,983,232 | ---- | M] (COMODO) [Auto | Running] -- C:\Program Files\COMODO\COMODO Internet Security\cmdagent.exe -- (cmdAgent)
SRV - [2011/08/27 08:44:38 | 001,044,816 | ---- | M] (Flexera Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe -- (FLEXnet Licensing Service)
SRV - [2011/07/13 17:00:16 | 000,036,352 | ---- | M] () [On_Demand | Stopped] -- C:\Program Files\HMA! Pro VPN\bin\openvpnserv.exe -- (OpenVPNService)
SRV - [2011/06/23 14:25:20 | 000,157,544 | ---- | M] (Sony Corporation) [On_Demand | Stopped] -- C:\Program Files\Sony\Sound Organizer\Sony.Earth\PACSPTISVR.exe -- (PACSPTISVR-Sound_Organizer)
SRV - [2011/06/13 22:09:22 | 000,267,568 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Microsoft Fix it Center\Matsvc.exe -- (MatSvc)
SRV - [2010/12/07 17:28:06 | 000,579,384 | ---- | M] (Autodesk, Inc.) [Auto | Running] -- C:\Program Files\Autodesk\Inventor 2012\Moldflow\bin\mitsijm.exe -- (mitsijm2012)
SRV - [2010/08/19 11:52:04 | 000,229,376 | ---- | M] () [Auto | Running] -- C:\ProgramData\DatacardService\DCService.exe -- (DCService.exe)
SRV - [2009/05/14 17:07:14 | 000,759,048 | ---- | M] (ABBYY) [Auto | Running] -- C:\Program Files\Common Files\ABBYY\FineReaderSprint\9.00\Licensing\NetworkLicenseServer.exe -- (ABBYY.Licensing.FineReader.Sprint.9.0)
SRV - [2008/12/31 13:12:44 | 000,910,600 | ---- | M] (Raxco Software, Inc.) [On_Demand | Stopped] -- C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exe -- (PD91Engine)
SRV - [2008/12/31 13:12:40 | 000,693,512 | ---- | M] (Raxco Software, Inc.) [Auto | Running] -- C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exe -- (PD91Agent)
SRV - [2008/01/18 23:38:26 | 000,272,952 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV - [2007/05/31 09:21:24 | 000,379,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\wcescomm.dll -- (WcesComm)
SRV - [2007/05/31 09:21:18 | 000,183,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\WindowsMobile\rapimgr.dll -- (RapiMgr)


========== Driver Services (SafeList) ==========

DRV - File not found [Kernel | On_Demand | Stopped] -- D:\NTGLM7X.sys -- (SetupNTGLM7X)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkfwd.sys -- (NwlnkFwd)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\nwlnkflt.sys -- (NwlnkFlt)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\NTACCESS.sys -- (NTACCESS)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\install4\MSICPL.sys -- (MSICPL)
DRV - File not found [Kernel | On_Demand | Stopped] -- system32\DRIVERS\ipinip.sys -- (IpInIp)
DRV - File not found [Kernel | On_Demand | Stopped] -- D:\INSTALL\GMSIPCI.SYS -- (GMSIPCI)
DRV - File not found [Kernel | On_Demand | Stopped] -- System32\Drivers\btwusb.sys -- (BTWUSB)
DRV - File not found [Kernel | Disabled | Stopped] -- C:\Windows\system32\drivers\blbdrive.sys -- (blbdrive)
DRV - [2012/09/22 11:40:47 | 000,152,576 | ---- | M] (SysProgs.org) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\BazisPortableCDBus.sys -- (BazisPortableCDBus)
DRV - [2012/07/10 05:48:18 | 000,035,560 | ---- | M] (AnchorFree Inc.) [Kernel | System | Running] -- C:\Windows\System32\drivers\hssdrv6.sys -- (HssDRV6)
DRV - [2012/06/11 21:58:44 | 008,733,696 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmdag.sys -- (amdkmdag)
DRV - [2012/06/11 19:25:48 | 000,295,936 | ---- | M] (Advanced Micro Devices, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\atikmpag.sys -- (amdkmdap)
DRV - [2012/03/20 20:44:12 | 000,074,112 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\NisDrvWFP.sys -- (NisDrv)
DRV - [2012/03/12 00:13:29 | 000,082,400 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\inspect.sys -- (inspect)
DRV - [2012/03/12 00:13:28 | 000,038,616 | ---- | M] (COMODO) [Kernel | System | Running] -- C:\Windows\System32\drivers\cmdhlp.sys -- (cmdHlp)
DRV - [2012/03/12 00:13:26 | 000,491,816 | ---- | M] (COMODO) [File_System | System | Running] -- C:\Windows\System32\drivers\cmdGuard.sys -- (cmdGuard)
DRV - [2012/02/23 15:31:36 | 000,083,984 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\AtihdLH3.sys -- (AtiHDAudioService)
DRV - [2012/02/16 00:24:36 | 000,181,432 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudmdm.sys -- (ssudmdm)
DRV - [2012/02/16 00:24:36 | 000,080,824 | ---- | M] (DEVGURU Co., LTD.(www.devguru.co.kr)) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ssudbus.sys -- (dg_ssudbus)
DRV - [2012/01/05 02:01:54 | 000,032,768 | ---- | M] (AnchorFree Inc) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\taphss.sys -- (taphss)
DRV - [2011/12/01 05:46:38 | 000,021,992 | ---- | M] (Silicon Laboratories) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\SiUSBXp.sys -- (SIUSBXP)
DRV - [2011/07/13 17:00:14 | 000,026,112 | ---- | M] (The OpenVPN Project) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\tap0901.sys -- (tap0901)
DRV - [2010/06/01 14:07:14 | 000,116,736 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbnet.sys -- (ewusbnet)
DRV - [2010/05/22 14:48:20 | 000,070,656 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ew_jubusenum.sys -- (huawei_enumerator)
DRV - [2010/03/25 10:08:38 | 000,105,984 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ewusbmdm.sys -- (hwdatacard)
DRV - [2010/03/20 11:56:04 | 000,101,504 | ---- | M] (Huawei Technologies Co., Ltd.) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\ew_hwusbdev.sys -- (ew_hwusbdev)
DRV - [2010/02/18 09:18:22 | 000,037,944 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\amdiox86.sys -- (amdiox86)
DRV - [2009/08/05 06:18:22 | 000,048,640 | ---- | M] (Atheros Communications, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\L1E60x86.sys -- (L1E)
DRV - [2009/04/11 07:42:52 | 000,031,616 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\System32\drivers\winusb.sys -- (WinUSB)
DRV - [2009/01/05 14:16:36 | 000,071,184 | R--- | M] (Raxco Software, Inc.) [File_System | Auto | Running] -- C:\Windows\System32\drivers\DefragFS.sys -- (DefragFS)
DRV - [2008/12/19 06:40:06 | 000,923,136 | ---- | M] (VIA Technologies, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\viahduaa.sys -- (VIAHdAudAddService)
DRV - [2008/04/28 16:26:42 | 000,014,352 | ---- | M] (ATI Technologies Inc.) [Kernel | Boot | Running] -- C:\Windows\System32\drivers\AtiPcie.sys -- (AtiPcie)
DRV - [2008/03/19 18:28:52 | 000,022,072 | ---- | M] (Advanced Micro Devices Inc.) [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\usbfilter.sys -- (usbfilter)
DRV - [2006/10/18 15:44:48 | 000,007,680 | ---- | M] () [Kernel | On_Demand | Running] -- C:\Windows\System32\drivers\ASACPI.sys -- (MTsensor)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE - HKLM\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
IE - HKLM\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2786678


IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0



IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://badoo.com/startpage/
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://uk.msn.com/?ocid=iehp
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-gb
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = A0 00 6F 08 3F 02 CD 01 [binary data]
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\SOFTWARE\Microsoft\Internet Explorer\Main,StartPageCache = 1
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\URLSearchHook: {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - No CLSID value found
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\SearchScopes,DefaultScope = {AFDBDDAA-5D3F-42EE-B79C-185A7020515B}
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...Box&FORM=IE8SRC
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\SearchScopes\{8A244612-A1F7-11E0-95C0-E71F4824019B}: "URL" = http://badoo.com/sta...q={searchTerms}
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\SearchScopes\{afdbddaa-5d3f-42ee-b79c-185a7020515b}: "URL" = http://search.condui...&ctid=CT2786678
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF - HKLM\Software\MozillaPlugins\@adobe.com/ShockwavePlayer: C:\Windows\system32\Adobe\Director\np32dsw_1166636.dll (Adobe Systems, Inc.)
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.7.2: C:\Windows\system32\npDeployJava1.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.7.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/OfficeAuthz,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/SharePoint,version=14.0: C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WPF,version=3.5: c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/GoogleTalkPlugin: C:\Users\Hamad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll (Google)
FF - HKCU\Software\MozillaPlugins\@talk.google.com/O3DPlugin: C:\Users\Hamad\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll ()
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Users\Hamad\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)
FF - HKCU\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Users\Hamad\AppData\Local\Google\Update\1.3.21.123\npGoogleUpdate3.dll (Google Inc.)



========== Chrome ==========

CHR - homepage: http://www.google.co...=en&source=iglk
CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:acceptedSuggestion}{google:originalQueryForSuggestion}{google:searchFieldtrialParameter}sourceid=chrome&ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client=chrome&hl={language}&q={searchTerms},
CHR - homepage: http://www.google.co...=en&source=iglk
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Hamad\AppData\Local\Google\Chrome\Application\21.0.1180.60\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Hamad\AppData\Local\Google\Chrome\Application\21.0.1180.89\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Users\Hamad\AppData\Local\Google\Chrome\Application\21.0.1180.89\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Users\Hamad\AppData\Local\Google\Chrome\Application\21.0.1180.89\pdf.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: Google Talk Plugin (Enabled) = C:\Users\Hamad\AppData\Roaming\Mozilla\plugins\npgoogletalk.dll
CHR - plugin: Google Talk Plugin Video Accelerator (Enabled) = C:\Users\Hamad\AppData\Roaming\Mozilla\plugins\npgtpo3dautoplugin.dll
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~1\Office14\NPAUTHZ.DLL
CHR - plugin: Microsoft Office 2010 (Enabled) = C:\PROGRA~1\MICROS~1\Office14\NPSPWRAP.DLL
CHR - plugin: Google Update (Enabled) = C:\Program Files\Google\Update\1.3.21.115\npGoogleUpdate3.dll
CHR - plugin: Java™ Platform SE 7 U5 (Enabled) = C:\Program Files\Oracle\JavaFX 2.1 Runtime\bin\plugin2\npjp2.dll
CHR - plugin: Java Deployment Toolkit 7.0.50.255 (Enabled) = C:\Windows\system32\npDeployJava1.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Shockwave for Director (Enabled) = C:\Windows\system32\Adobe\Director\np32dsw.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files\Microsoft Silverlight\4.1.10329.0\npctrl.dll
CHR - plugin: Windows Presentation Foundation (Enabled) = c:\Windows\Microsoft.NET\Framework\v3.5\Windows Presentation Foundation\NPWPF.dll

O1 HOSTS File: ([2012/09/26 01:01:06 | 000,000,098 | ---- | M]) - C:\Windows\System32\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2 - BHO: (SnagIt Toolbar Loader) - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\Snagit 10\SnagitBHO.dll (TechSmith Corporation)
O2 - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2 - BHO: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
O2 - BHO: (Office Document Cache Handler) - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\Program Files\Microsoft Office\Office14\URLREDIR.DLL (Microsoft Corporation)
O2 - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2 - BHO: (Hotspot Shield Class) - {F9E4A054-E9B1-4BC3-83A3-76A1AE736170} - C:\Program Files\Hotspot Shield\HssIE\HssIE.dll (AnchorFree Inc.)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (Easy Photo Print) - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\EPSON Software\Easy Photo Print\EPTBL.dll (SEIKO EPSON CORPORATION)
O3 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\Toolbar\WebBrowser: (no name) - {8FF5E180-ABDE-46EB-B09E-D2AAB95CABE3} - No CLSID value found.
O3 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000\..\Toolbar\WebBrowser: (no name) - {BF7380FA-E3B4-4DB2-AF3E-9D8783A45BFC} - No CLSID value found.
O4 - HKLM..\Run: [APSDaemon] C:\Program Files\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [BCSSync] C:\Program Files\Microsoft Office\Office14\BCSSync.exe (Microsoft Corporation)
O4 - HKLM..\Run: [COMODO Internet Security] C:\Program Files\COMODO\COMODO Internet Security\cfp.exe (COMODO)
O4 - HKLM..\Run: [EEventManager] C:\Program Files\Epson Software\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [HDAudDeck] C:\Program Files\VIA\VIAudioi\VDeck\VDeck.exe (VIA)
O4 - HKLM..\Run: [MSC] c:\Program Files\Microsoft Security Client\msseces.exe (Microsoft Corporation)
O4 - HKLM..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exe (Nero AG)
O4 - HKLM..\Run: [StartCCC] C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe (Advanced Micro Devices, Inc.)
O4 - HKLM..\Run: [Windows Defender] C:\Program Files\Windows Defender\MSASCui.exe (Microsoft Corporation)
O4 - HKU\S-1-5-19..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [WindowsWelcomeCenter] C:\Windows\System32\oobefldr.dll (Microsoft Corporation)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe (Nero AG)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [EPLTarget\P0000000000000000] C:\Windows\System32\spool\DRIVERS\W32X86\3\E_TATIHTE.EXE (SEIKO EPSON CORPORATION)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [eType] C:\Users\Hamad\AppData\Roaming\eType\eType.exe (DSNR Media Innovations)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [GoogleDriveSync] C:\Program Files\Google\Drive\googledrivesync.exe (Google)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [HydraVisionDesktopManager] C:\Program Files\ATI Technologies\HydraVision\HydraDM.exe (AMD)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [MzRAMBooster] C:\Program Files\Mz Ultimate Tools\Mz RAM Booster\MzRAMBooster.exe (Mz Ultimate Tools)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [POEngine5] File not found
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [Rest Reminder] C:\Users\Hamad\Desktop\Tools\RestReminder.exe (NGCoders)
O4 - HKU\S-1-5-21-3562748159-1388759733-2883167963-1000..\Run: [Xvid] C:\Program Files\Xvid\CheckUpdate.exe ()
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteClipper.lnk = C:\Program Files\Evernote\Evernote\EvernoteClipper.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\EvernoteTray.lnk = C:\Program Files\Evernote\Evernote\EvernoteTray.exe (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\GoalSync 3.0.lnk = C:\Program Files\Success Studios\GoalSync 3.0\GoalSync3.exe (Success Studios)
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\iMindMap Preloader.lnk = C:\Users\Hamad\.thinkbuzan\imindmap\preload\iMindMap_Preloader.exe ()
O4 - Startup: C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\OpenOffice.org 3.3.lnk = C:\Program Files\OpenOffice.org 3\program\quickstart.exe ()
O8 - Extra context menu item: Add to Evernote 4.0 - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O8 - Extra context menu item: Send To &Bluetooth - C:\Program Files\Bluetooth\Bluetooth Software\btsendto_ie_ctx.htm File not found
O9 - Extra Button: @C:\Windows\WindowsMobile\INetRepl.dll,-222 - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra 'Tools' menuitem : @C:\Windows\WindowsMobile\INetRepl.dll,-223 - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\Windows\WindowsMobile\INetRepl.dll (Microsoft Corporation)
O9 - Extra Button: @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O9 - Extra 'Tools' menuitem : @C:\Program Files\Evernote\Evernote\Resource.dll,-101 - {A95fe080-8f5d-11d2-a20b-00aa003c157a} - C:\Program Files\Evernote\Evernote\EvernoteIE.dll (Evernote Corp., 333 W Evelyn Ave. Mountain View, CA 94041)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000007 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O13 - gopher Prefix: missing
O16 - DPF: {8AD9C840-044E-11D1-B3E9-00805F499D93} http://java.sun.com/...indows-i586.cab (Reg Error: Value error.)
O16 - DPF: {CAFEEFAC-0016-0000-0022-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_22)
O16 - DPF: {CAFEEFAC-0016-0000-0033-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 1.6.0_33)
O16 - DPF: {CAFEEFAC-FFFF-FFFF-FFFF-ABCDEFFEDCBA} http://java.sun.com/...indows-i586.cab (Java Plug-in 10.7.2)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{04692C57-3E14-4E03-B576-8DA1A24E6C0C}: DhcpNameServer = 84.235.107.122 84.235.107.123
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{13C7E60A-EF6A-432C-9B82-4D89CB7AA6D2}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F9F615D-0349-47F8-BFC3-B16499BF9FB0}: DhcpNameServer = 192.168.15.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{2F9F615D-0349-47F8-BFC3-B16499BF9FB0}: NameServer = 8.26.56.26,156.154.70.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{4FEE97B2-80F1-4C1E-B131-9DCF5475DE71}: NameServer = 156.154.70.22,156.154.71.22
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{ACA39361-FD78-46FC-9FC5-63B2976D2B1D}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{B5DDAC35-B3E7-4933-A271-708A75D296A3}: DhcpNameServer = 192.168.42.129
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{DF758A09-D2E2-4787-8764-22389FC697B6}: NameServer = 10.93.120.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{EFF4DFDD-2EF5-41DD-9FEE-70475D11B0B7}: DhcpNameServer = 84.235.107.250 84.235.107.251
O20 - AppInit_DLLs: (C:\Windows\system32\guard32.dll) - C:\Windows\System32\guard32.dll (COMODO)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\System32\userinit.exe (Microsoft Corporation)
O24 - Desktop WallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O24 - Desktop BackupWallPaper: C:\Windows\Web\Wallpaper\img24.jpg
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2006/09/19 00:43:36 | 000,000,024 | ---- | M] () - C:\autoexec.bat -- [ NTFS ]
O33 - MountPoints2\{0906f0d7-0aea-11e1-aee9-e53dc77dbff0}\Shell - "" = AutoRun
O33 - MountPoints2\{0906f0d7-0aea-11e1-aee9-e53dc77dbff0}\Shell\AutoRun\command - "" = E:\FIBPGuard.exe
O33 - MountPoints2\{0af632fe-f214-11e1-9214-e8d63c07d8bd}\Shell - "" = AutoRun
O33 - MountPoints2\{0af632fe-f214-11e1-9214-e8d63c07d8bd}\Shell\AutoRun\command - "" = E:\Autorun.exe
O33 - MountPoints2\{4c3be28b-e6d8-11e0-bee2-001e101f2500}\Shell - "" = AutoRun
O33 - MountPoints2\{4c3be28b-e6d8-11e0-bee2-001e101f2500}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{4c3be2de-e6d8-11e0-bee2-001e101f79c9}\Shell - "" = AutoRun
O33 - MountPoints2\{4c3be2de-e6d8-11e0-bee2-001e101f79c9}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{7152b1de-da97-11e0-a371-001e101f3315}\Shell - "" = AutoRun
O33 - MountPoints2\{7152b1de-da97-11e0-a371-001e101f3315}\Shell\AutoRun\command - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{7152b1de-da97-11e0-a371-001e101f3315}\Shell\start\COMMAND - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{834dd50f-dc90-11e0-bda7-001e101f8924}\Shell - "" = AutoRun
O33 - MountPoints2\{834dd50f-dc90-11e0-bda7-001e101f8924}\Shell\AutoRun\command - "" = G:\FIBPGuard.exe
O33 - MountPoints2\{99142b42-da3b-11e0-822b-001e101fb681}\Shell - "" = AutoRun
O33 - MountPoints2\{99142b42-da3b-11e0-822b-001e101fb681}\Shell\AutoRun\command - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{99142b42-da3b-11e0-822b-001e101fb681}\Shell\start\COMMAND - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{99142b44-da3b-11e0-822b-001e101fb681}\Shell - "" = AutoRun
O33 - MountPoints2\{99142b44-da3b-11e0-822b-001e101fb681}\Shell\AutoRun\command - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{99142b44-da3b-11e0-822b-001e101fb681}\Shell\start\COMMAND - "" = G:\autorun.exe /autorun
O33 - MountPoints2\{b3351883-cf35-11e0-95a6-e57d28a13cad}\Shell - "" = AutoRun
O33 - MountPoints2\{b3351883-cf35-11e0-95a6-e57d28a13cad}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{bbc7ab38-042d-11e2-8b30-d85d19b1fac9}\Shell - "" = AutoRun
O33 - MountPoints2\{bbc7ab38-042d-11e2-8b30-d85d19b1fac9}\Shell\AutoRun\command - "" = E:\LiveTutDVD.exe
O33 - MountPoints2\{c46d67fb-cca5-11e1-9820-892c994a8b31}\Shell - "" = AutoRun
O33 - MountPoints2\{c46d67fb-cca5-11e1-9820-892c994a8b31}\Shell\AutoRun\command - "" = E:\AutoRun.exe
O33 - MountPoints2\{cbb33115-eb72-11e0-b1ef-00248ca430af}\Shell - "" = AutoRun
O33 - MountPoints2\{cbb33115-eb72-11e0-b1ef-00248ca430af}\Shell\AutoRun\command - "" = E:\setup.exe
O33 - MountPoints2\{cbb33148-eb72-11e0-b1ef-00248ca430af}\Shell - "" = AutoRun
O33 - MountPoints2\{cbb33148-eb72-11e0-b1ef-00248ca430af}\Shell\AutoRun\command - "" = E:\setup.exe
O34 - HKLM BootExecute: (PDBoot.exe)
O34 - HKLM BootExecute: (autocheck autochk *)
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)

========== Files/Folders - Created Within 30 Days ==========

[2012/09/25 23:57:31 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Malwarebytes
[2012/09/25 23:57:04 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Malwarebytes' Anti-Malware
[2012/09/25 23:56:58 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2012/09/25 23:56:56 | 000,022,856 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/09/25 23:56:56 | 000,000,000 | ---D | C] -- C:\Program Files\Malwarebytes' Anti-Malware
[2012/09/25 15:56:02 | 000,000,000 | ---D | C] -- C:\_OTL
[2012/09/24 23:57:08 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\Business Plan Pro Samples
[2012/09/24 23:45:23 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\IsolatedStorage
[2012/09/24 23:38:26 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\Palo_Alto_Software
[2012/09/24 23:38:26 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\bppenu11
[2012/09/24 23:37:50 | 000,000,000 | ---D | C] -- C:\ProgramData\IsolatedStorage
[2012/09/24 23:37:39 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Business Plan Pro 11.0
[2012/09/24 23:37:12 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Palo Alto Software
[2012/09/24 23:36:04 | 000,000,000 | ---D | C] -- C:\Program Files\Business Plan Pro
[2012/09/24 11:16:07 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Native Instruments
[2012/09/24 11:13:46 | 000,000,000 | -H-D | C] -- C:\ProgramData\{7707EA53-E29B-48FC-B28B-C8EE171EA0EB}
[2012/09/24 11:09:55 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Native Instruments
[2012/09/24 11:09:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Native Instruments
[2012/09/24 11:09:51 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Native Instruments
[2012/09/24 11:09:51 | 000,000,000 | ---D | C] -- C:\Program Files\Native Instruments
[2012/09/23 23:36:30 | 004,731,392 | ---- | C] (AVAST Software) -- C:\Users\Hamad\Desktop\aswMBR.exe
[2012/09/23 23:34:47 | 000,601,600 | ---- | C] (OldTimer Tools) -- C:\Users\Hamad\Desktop\OTL.exe
[2012/09/22 19:54:46 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Propellerhead Software
[2012/09/19 21:01:53 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\NP3
[2012/09/19 20:54:39 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\MWS
[2012/09/19 20:54:39 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\MindWorkStation
[2012/09/19 20:54:39 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Mind WorkStation Sessions
[2012/09/19 20:44:02 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Mind WorkStation
[2012/09/19 20:43:52 | 000,000,000 | ---D | C] -- C:\Program Files\Mind WorkStation
[2012/09/19 19:00:06 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\NeuroProgrammer3
[2012/09/19 19:00:06 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Neuro-Programmer 3 Documents
[2012/09/19 18:59:54 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\Xenocode
[2012/09/19 18:59:54 | 000,000,000 | ---D | C] -- C:\Program Files\Xenocode
[2012/09/19 18:46:44 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Neuro-Programmer 3
[2012/09/19 18:46:24 | 000,000,000 | ---D | C] -- C:\Program Files\Neuro-Programmer 3
[2012/09/18 23:33:02 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Ableton
[2012/09/18 23:33:02 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Ableton
[2012/09/18 23:20:38 | 000,000,000 | ---D | C] -- C:\ProgramData\Ableton
[2012/09/11 21:42:14 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Mozilla
[2012/09/11 08:52:45 | 000,000,000 | ---D | C] -- C:\Program Files\Common Files\Java
[2012/09/08 17:46:05 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Holdem Indicator
[2012/09/08 17:45:43 | 000,000,000 | ---D | C] -- C:\Program Files\Holdem Indicator
[2012/09/08 17:24:13 | 000,000,000 | ---D | C] -- C:\Users\Hamad\PokerOffice
[2012/09/08 17:23:58 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PokerOffice5
[2012/09/08 17:22:18 | 000,000,000 | ---D | C] -- C:\Program Files\PokerOffice5
[2012/09/06 08:12:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PartyCasino
[2012/09/06 07:36:13 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\betonline
[2012/09/06 07:35:36 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\BetOnline Poker 8.2
[2012/09/06 07:35:16 | 000,000,000 | ---D | C] -- C:\Program Files\BetOnline Poker 8.2
[2012/09/06 07:07:18 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Mozilla-Cache
[2012/09/06 07:06:07 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\Party
[2012/09/06 07:05:54 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\PartyPoker
[2012/09/06 07:01:57 | 000,000,000 | ---D | C] -- C:\Programs
[2012/09/02 00:21:53 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\dvd
[2012/09/02 00:14:43 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Roaming\DVD Flick
[2012/09/02 00:14:32 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DVD Flick
[2012/09/02 00:14:23 | 000,040,960 | ---- | C] (vbAccelerator) -- C:\Windows\System32\ssubtmr6.dll
[2012/09/02 00:14:23 | 000,036,864 | ---- | C] (Robdogg Inc.) -- C:\Windows\System32\trayicon_handler.ocx
[2012/09/02 00:14:22 | 000,028,672 | ---- | C] (-) -- C:\Windows\System32\mousewheel.ocx
[2012/09/02 00:14:22 | 000,000,000 | ---D | C] -- C:\Program Files\DVD Flick
[2012/09/01 18:39:07 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\NeroVision
[2012/08/31 11:04:25 | 000,000,000 | ---D | C] -- C:\Users\Hamad\AppData\Local\Ubisoft Game Launcher
[2012/08/31 10:20:17 | 000,000,000 | ---D | C] -- C:\Users\Hamad\Documents\Ubisoft
[2012/08/31 10:04:55 | 000,000,000 | ---D | C] -- C:\Program Files\Ubisoft
[2012/08/31 10:03:55 | 000,000,000 | -H-D | C] -- C:\Users\Hamad\InstallAnywhere
[2012/08/30 12:40:49 | 000,000,000 | -H-D | C] -- C:\Windows\PIF
[2012/08/28 00:29:32 | 000,000,000 | R--D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TriDef 3D
[2012/08/28 00:29:02 | 000,000,000 | ---D | C] -- C:\ProgramData\DDD
[2012/08/28 00:28:47 | 000,000,000 | ---D | C] -- C:\Program Files\TriDef 3D
[2012/08/28 00:20:48 | 000,000,000 | ---D | C] -- C:\Program Files\MonitorDriver
[2012/08/27 02:36:24 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Evernote
[2012/08/27 01:52:56 | 000,000,000 | ---D | C] -- C:\Windows\CheckSur

========== Files - Modified Within 30 Days ==========

[2012/09/26 01:22:00 | 000,000,908 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3562748159-1388759733-2883167963-1000UA.job
[2012/09/26 01:18:15 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2012/09/26 01:03:32 | 000,000,880 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2012/09/26 01:03:11 | 000,004,176 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-1.C7483456-A289-439d-8115-601632D005A0
[2012/09/26 01:03:10 | 000,004,176 | -H-- | M] () -- C:\Windows\System32\7B296FB0-376B-497e-B012-9C450E1B7327-2P-0.C7483456-A289-439d-8115-601632D005A0
[2012/09/26 01:03:02 | 2146,623,488 | -HS- | M] () -- C:\hiberfil.sys
[2012/09/26 01:01:48 | 000,000,012 | ---- | M] () -- C:\Windows\bthservsdp.dat
[2012/09/26 01:01:06 | 000,000,098 | ---- | M] () -- C:\Windows\System32\drivers\etc\Hosts
[2012/09/26 00:57:04 | 000,000,884 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2012/09/25 23:57:04 | 000,000,906 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/25 15:43:20 | 000,002,613 | ---- | M] () -- C:\Users\Public\Desktop\Business Plan Pro 11.0.lnk
[2012/09/25 13:12:52 | 000,047,616 | ---- | M] () -- C:\Users\Hamad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/09/25 05:22:01 | 000,000,856 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskUserS-1-5-21-3562748159-1388759733-2883167963-1000Core.job
[2012/09/24 11:13:28 | 000,000,909 | ---- | M] () -- C:\Users\Public\Desktop\Traktor 2.lnk
[2012/09/23 23:39:32 | 004,731,392 | ---- | M] (AVAST Software) -- C:\Users\Hamad\Desktop\aswMBR.exe
[2012/09/23 23:35:02 | 000,601,600 | ---- | M] (OldTimer Tools) -- C:\Users\Hamad\Desktop\OTL.exe
[2012/09/22 11:44:31 | 000,660,296 | ---- | M] () -- C:\Windows\System32\perfh009.dat
[2012/09/22 11:44:31 | 000,126,518 | ---- | M] () -- C:\Windows\System32\perfc009.dat
[2012/09/22 11:40:47 | 000,152,576 | ---- | M] (SysProgs.org) -- C:\Windows\System32\drivers\BazisPortableCDBus.sys
[2012/09/19 21:02:01 | 000,000,924 | ---- | M] () -- C:\Users\Public\Desktop\Neuro-Programmer 3.lnk
[2012/09/19 20:44:02 | 000,000,895 | ---- | M] () -- C:\Users\Public\Desktop\Mind WorkStation.lnk
[2012/09/19 16:38:26 | 000,000,749 | ---- | M] () -- C:\Users\Hamad\Desktop\Ableton Live 8.lnk
[2012/09/10 17:00:42 | 000,010,063 | -H-- | M] () -- C:\Users\Hamad\AppData\Roaming\Hamadlog.dat
[2012/09/08 17:46:05 | 000,000,919 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Holdem Indicator.lnk
[2012/09/08 17:46:05 | 000,000,895 | ---- | M] () -- C:\Users\Hamad\Desktop\Holdem Indicator.lnk
[2012/09/08 17:23:59 | 000,001,740 | ---- | M] () -- C:\Users\Hamad\Desktop\PokerOffice 5.lnk
[2012/09/07 17:04:46 | 000,022,856 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\System32\drivers\mbam.sys
[2012/09/06 08:12:37 | 000,001,667 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyCasino.lnk
[2012/09/06 08:12:36 | 000,001,643 | ---- | M] () -- C:\Users\Hamad\Desktop\PartyCasino.lnk
[2012/09/06 07:35:36 | 000,001,810 | ---- | M] () -- C:\Users\Public\Desktop\BetOnline Poker 8.2.lnk
[2012/09/06 07:05:54 | 000,001,667 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
[2012/09/06 07:05:54 | 000,001,643 | ---- | M] () -- C:\Users\Hamad\Desktop\PartyPoker.lnk
[2012/09/03 03:18:08 | 000,002,004 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Google Chrome.lnk
[2012/09/02 00:14:32 | 000,001,699 | ---- | M] () -- C:\Users\Hamad\Desktop\DVD Flick.lnk
[2012/08/30 03:17:41 | 000,177,640 | ---- | M] () -- C:\Users\Hamad\Documents\SetupData.trx
[2012/08/30 03:17:40 | 000,007,599 | ---- | M] () -- C:\Users\Hamad\Documents\ReviewActions.xml
[2012/08/30 02:52:09 | 000,000,725 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Evernote.lnk
[2012/08/30 02:51:55 | 000,000,825 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\YNAB 3.lnk
[2012/08/30 02:51:51 | 000,001,011 | ---- | M] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\iMindMap 5.lnk
[2012/08/28 18:16:40 | 000,002,133 | ---- | M] () -- C:\Users\Public\Desktop\SyncMaster 3D Game Launcher (TriDef 3D).lnk
[2012/08/27 16:07:24 | 000,177,640 | ---- | M] () -- C:\Users\Hamad\Documents\SetupData.bak.trx
[2012/08/27 02:44:47 | 000,000,069 | ---- | M] () -- C:\Windows\NeroDigital.ini

========== Files Created - No Company Name ==========

[2012/09/25 23:57:04 | 000,000,906 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2012/09/24 23:37:39 | 000,002,613 | ---- | C] () -- C:\Users\Public\Desktop\Business Plan Pro 11.0.lnk
[2012/09/24 11:13:28 | 000,000,909 | ---- | C] () -- C:\Users\Public\Desktop\Traktor 2.lnk
[2012/09/19 20:44:02 | 000,000,895 | ---- | C] () -- C:\Users\Public\Desktop\Mind WorkStation.lnk
[2012/09/19 18:46:46 | 000,000,924 | ---- | C] () -- C:\Users\Public\Desktop\Neuro-Programmer 3.lnk
[2012/09/19 16:38:26 | 000,000,749 | ---- | C] () -- C:\Users\Hamad\Desktop\Ableton Live 8.lnk
[2012/09/18 23:20:26 | 000,000,749 | ---- | C] () -- C:\Users\Hamad\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Ableton Live 8.lnk
[2012/09/08 17:46:05 | 000,000,919 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Holdem Indicator.lnk
[2012/09/08 17:46:05 | 000,000,895 | ---- | C] () -- C:\Users\Hamad\Desktop\Holdem Indicator.lnk
[2012/09/08 17:23:58 | 000,001,740 | ---- | C] () -- C:\Users\Hamad\Desktop\PokerOffice 5.lnk
[2012/09/06 08:12:37 | 000,001,667 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyCasino.lnk
[2012/09/06 08:12:36 | 000,001,643 | ---- | C] () -- C:\Users\Hamad\Desktop\PartyCasino.lnk
[2012/09/06 07:35:36 | 000,001,810 | ---- | C] () -- C:\Users\Public\Desktop\BetOnline Poker 8.2.lnk
[2012/09/06 07:05:54 | 000,001,667 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\PartyPoker.lnk
[2012/09/06 07:05:54 | 000,001,643 | ---- | C] () -- C:\Users\Hamad\Desktop\PartyPoker.lnk
[2012/09/02 00:14:32 | 000,001,699 | ---- | C] () -- C:\Users\Hamad\Desktop\DVD Flick.lnk
[2012/08/30 02:52:09 | 000,000,725 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\Evernote.lnk
[2012/08/30 02:51:55 | 000,000,825 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\YNAB 3.lnk
[2012/08/30 02:51:51 | 000,001,011 | ---- | C] () -- C:\Users\Hamad\Application Data\Microsoft\Internet Explorer\Quick Launch\iMindMap 5.lnk
[2012/08/28 00:29:39 | 000,002,133 | ---- | C] () -- C:\Users\Public\Desktop\SyncMaster 3D Game Launcher (TriDef 3D).lnk
[2012/08/27 02:44:47 | 000,000,069 | ---- | C] () -- C:\Windows\NeroDigital.ini
[2012/08/27 00:53:23 | 000,143,360 | R--- | C] () -- C:\Windows\System32\RtlCPAPI.dll
[2012/08/27 00:53:23 | 000,049,152 | R--- | C] () -- C:\Windows\System32\ChCfg.exe
[2012/08/26 04:16:53 | 000,000,012 | ---- | C] () -- C:\Windows\bthservsdp.dat
[2012/08/26 04:16:26 | 000,000,000 | ---- | C] () -- C:\Windows\EEventManager.INI
[2012/08/25 19:28:30 | 000,660,296 | ---- | C] () -- C:\Windows\System32\perfh009.dat
[2012/08/25 19:28:30 | 000,126,518 | ---- | C] () -- C:\Windows\System32\perfc009.dat
[2012/08/25 19:26:28 | 000,047,616 | ---- | C] () -- C:\Users\Hamad\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/08/23 02:02:40 | 000,000,022 | ---- | C] () -- C:\Windows\cmm.dat
[2012/08/23 02:02:39 | 000,001,746 | ---- | C] () -- C:\Windows\Language_trs.ini
[2012/08/23 02:02:39 | 000,000,426 | ---- | C] () -- C:\Windows\BRWMARK.INI
[2012/08/23 02:02:25 | 000,038,090 | ---- | C] () -- C:\Windows\Ascd_log.ini
[2012/08/23 02:02:25 | 000,000,264 | ---- | C] () -- C:\Windows\Brownie.ini
[2012/08/23 02:02:24 | 000,030,320 | ---- | C] () -- C:\Windows\Ascd_tmp.ini
[2012/08/23 02:02:24 | 000,000,011 | ---- | C] () -- C:\Windows\BRVIDEO.INI
[2012/08/23 02:02:24 | 000,000,000 | ---- | C] () -- C:\Windows\brmx2001.ini
[2012/08/23 02:02:24 | 000,000,000 | ---- | C] () -- C:\Windows\ativpsrm.bin
[2012/08/23 02:00:10 | 000,043,131 | ---- | C] () -- C:\Windows\mib.bin
[2012/08/23 01:38:53 | 000,159,232 | ---- | C] () -- C:\Windows\System32\clinfo.exe
[2012/08/23 01:38:51 | 000,179,271 | ---- | C] () -- C:\Windows\System32\xlive.dll.cat
[2012/08/23 01:38:47 | 000,000,186 | ---- | C] () -- C:\Windows\System32\CleanMem.ini
[2012/08/23 01:38:45 | 000,240,640 | ---- | C] () -- C:\Windows\System32\xvidvfw.dll
[2012/08/23 01:38:45 | 000,003,917 | ---- | C] () -- C:\Windows\System32\atipblag.dat
[2012/08/23 01:38:44 | 000,645,632 | ---- | C] () -- C:\Windows\System32\xvidcore.dll
[2012/08/23 01:38:44 | 000,637,743 | ---- | C] () -- C:\Windows\System32\atiicdxx.dat
[2012/08/23 01:38:41 | 000,000,034 | ---- | C] () -- C:\Windows\System32\BXD2140.DAT
[2012/08/23 01:38:27 | 000,037,376 | ---- | C] () -- C:\Windows\System32\atitmpxx.dll
[2012/08/23 01:38:21 | 000,043,008 | ---- | C] () -- C:\Windows\System32\spwini.dll
[2012/08/23 01:38:15 | 000,117,248 | ---- | C] () -- C:\Windows\System32\EhStorAuthn.dll
[2012/08/23 01:38:15 | 000,107,612 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchema.bin
[2012/08/23 01:38:09 | 000,018,904 | ---- | C] () -- C:\Windows\System32\StructuredQuerySchemaTrivial.bin
[2012/08/23 01:38:06 | 000,062,976 | ---- | C] () -- C:\Windows\System32\PrintBrmUi.exe
[2012/08/23 01:37:32 | 000,000,741 | ---- | C] () -- C:\Windows\System32\NOISE.DAT
[2012/08/23 01:37:29 | 000,673,088 | ---- | C] () -- C:\Windows\System32\mlang.dat
[2012/08/23 01:37:26 | 000,371,128 | ---- | C] () -- C:\Windows\System32\FNTCACHE.DAT
[2012/08/23 01:37:25 | 000,215,943 | ---- | C] () -- C:\Windows\System32\dssec.dat
[2012/08/23 01:37:21 | 000,287,440 | ---- | C] () -- C:\Windows\System32\perfi009.dat
[2012/08/23 01:37:21 | 000,030,674 | ---- | C] () -- C:\Windows\System32\perfd009.dat
[2012/08/23 01:37:21 | 000,013,750 | ---- | C] () -- C:\Windows\System32\pacerprf.ini
[2012/08/23 01:32:58 | 000,007,680 | ---- | C] () -- C:\Windows\System32\drivers\ASACPI.sys
[2012/08/23 01:32:56 | 000,010,296 | ---- | C] () -- C:\Windows\System32\drivers\ASUSHWIO.SYS
[2012/08/23 01:26:54 | 000,031,274 | ---- | C] () -- C:\Users\Hamad\.TransferManager.db
[2012/08/23 01:26:02 | 000,037,845 | ---- | C] () -- C:\Users\Hamad\AppData\Roaming\Comma Separated Values (Windows).ADR
[2012/08/23 01:26:02 | 000,000,630 | ---- | C] () -- C:\Users\Hamad\AppData\Roaming\lazy_remote_server_settings.dat
[2012/08/23 01:24:34 | 000,001,356 | ---- | C] () -- C:\Users\Hamad\AppData\Local\d3d9caps.dat
[2006/07/27 02:34:15 | 000,010,063 | -H-- | C] () -- C:\Users\Hamad\AppData\Roaming\Hamadlog.dat

========== ZeroAccess Check ==========

[2006/11/02 15:54:18 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2012/06/08 20:47:00 | 011,586,048 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]
"" = %systemroot%\system32\wbem\wbemess.dll -- [2009/04/11 09:28:25 | 000,347,648 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

========== LOP Check ==========

[2012/08/23 01:25:44 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\.thinkingrock
[2012/08/23 01:25:50 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\3Dconnexion
[2012/09/22 19:54:32 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Ableton
[2012/08/23 01:25:30 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Arduino
[2012/08/23 01:25:30 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Autodesk
[2012/09/06 07:36:13 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\betonline
[2012/09/24 23:38:26 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\bppenu11
[2012/08/23 01:25:51 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Business Logic
[2012/08/23 01:25:57 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\com.conqu
[2012/08/23 01:25:49 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\com.youneedabudget.YNAB3.Live.9C763150EFAB05FD2A2B78705C7A54E2FCDDE07D.1
[2012/08/23 01:25:50 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Epson
[2012/09/26 01:09:34 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\eType
[2012/08/23 01:25:49 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Fritzing
[2012/08/23 01:25:49 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\HabitShaper
[2012/08/23 01:25:51 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Klok2.DD7F2188B985C2439837C76B42A187050457E61B.1
[2012/09/19 21:01:28 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\MindWorkStation
[2012/09/19 19:24:26 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\NeuroProgrammer3
[2012/08/23 01:25:46 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\OpenOffice.org
[2012/09/06 07:11:26 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Party
[2012/08/23 01:25:28 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\Softland
[2012/08/23 01:26:02 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\TeamViewer
[2012/09/25 15:49:23 | 000,000,000 | ---D | M] -- C:\Users\Hamad\AppData\Roaming\uTorrent
[2012/08/23 01:25:51 | 000,000,000 | -HSD | M] -- C:\Users\Hamad\AppData\Roaming\wyUpdate AU

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 139 bytes -> C:\ProgramData\TEMP:157E1AD3
@Alternate Data Stream - 126 bytes -> C:\ProgramData\TEMP:5FC93B4C

< End of report >


Thank you
  • 0

#12
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
How is the computer behaving now .. Any problems ?
  • 0

#13
hamadm

hamadm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
No, Thank you very much man.
  • 0

#14
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Subject to no further problems :)

I will remove my tools now and give some recommendations, but, I would like you to run for 24 hours or so and come back if you have any problems

Now the best part of the day ----- Your log now appears clean :thumbsup:

A good workman always cleans up after himself so..The following will implement some cleanup procedures as well as reset System Restore points:

Run OTL
  • Under the Custom Scans/Fixes box at the bottom, paste in the following

    :Commands
    [resethosts]
    [emptytemp]
    [Reboot]

  • Then click the Run Fix button at the top
  • Let the program run unhindered, reboot the PC when it is done

Run OTL and hit the cleanup button. It will remove all the programmes we have used plus itself.

We will now confirm that your hidden files are set to that, as some of the tools I use will change that
  • Go to control panel
  • Select folder options (Appearance > Folder options in category view)
  • Select the View Tab.
  • Under the Hidden files and folders heading select Do not show hidden files and folders.
  • Click Yes to confirm.
  • Click OK.

Posted Image
Your Java is out of date. Older versions have vulnerabilities that malware can use to infect your system.
Please follow these steps to remove older version of Java components and upgrade the application.

Upgrading Java:
  • Go to this site and click Do I have Java
  • It will check your current version and then offer to update to the latest version

SPRING CLEAN

To manually create a new Restore Point
  • Go to Control Panel and select System
  • Select System
  • On the left select System Protection and accept the warning if you get one
  • Select System Protection Tab
  • Select Create at the bottom
  • Type in a name i.e. Clean
  • Select Create

Now we can purge the infected ones
  • GoStart > All programs > Accessories > system tools
  • Right click Disc cleanup and select run as administrator
  • Select Your main drive and accept the warning if you get one
  • For a few moments the system will make some calculations
  • Select the More Options tab
  • In the System Restore and Shadow Backups select Clean up
  • Select Delete on the pop up
  • Select OK
  • Select Delete

Now that you are clean, to help protect your computer in the future I recommend that you get the following free programmes:
Posted Image
Malwarebytes. Update and run weekly to keep your system clean

Download and install FileHippo update checker and run it monthly it will show you which programmes on your system need updating and give a download link

It is critical to have both a firewall and anti virus to protect your system and to keep them updated. To keep your operating system up to date visit

To learn more about how to protect yourself while on the internet read our little guide How did I get infected in the first place ?

Keep safe :wave:
  • 0

#15
hamadm

hamadm

    Member

  • Topic Starter
  • Member
  • PipPip
  • 21 posts
Thank you very much
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP