Jump to content

Welcome to Geeks to Go - Register now for FREE

Geeks To Go is a helpful hub, where thousands of volunteer geeks quickly serve friendly answers and support. Check out the forums and get free advice from the experts. Register now to gain access to all of our features, it's FREE and only takes one minute. Once registered and logged in, you will be able to create topics, post replies to existing threads, give reputation to your fellow members, get your own private messenger, post status updates, manage your profile and so much more.

Create Account How it Works
Photo

ar.voicefive.com pop up blocked by IE 11, Adobe Flash Fails [Solved]


  • This topic is locked This topic is locked

#1
vgphoto

vgphoto

    New Member

  • Member
  • Pip
  • 7 posts
Pop ups from ar.voicefive.com are being blocked by IE 11. There are no errors, but it seems that web pages may be opening slower than usual. The only other problem that I know of on the system is that Adobe Flash is not installing properly with IE 11 and other Flash using programs.
I have run the following programs:
SUPERAntiSpyware Professional it shows no errors.
Malwarebytes Anti-Malware it shows no errors.
Norton Power Erase it shows no errors, it did identify 4 old programs that I have used for a long
time.
I ran CCleaner and erased all cookies and temp files Also did a directory scan for errors.
My system is an HP: Hewlett‐Packard Company
h8‐1160t
Intel﴾R﴿ Core﴾TM﴿ i7‐2600 CPU @ 3.40GHz 3.40 GHz
16.0 GB
64‐bit Operating System

Windows edition
Windows 7 Professional
Service Pack 1
OTL logfile created on: 2/27/2014 11:10:25 AM - Run 1
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Glens\Downloads
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

15.98 Gb Total Physical Memory | 10.46 Gb Available Physical Memory | 65.47% Memory free
31.96 Gb Paging File | 26.30 Gb Available in Paging File | 82.28% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1385.03 Gb Total Space | 783.91 Gb Free Space | 56.60% Space Free | Partition Type: NTFS
Drive D: | 12.13 Gb Total Space | 1.49 Gb Free Space | 12.26% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 189.21 Gb Free Space | 40.62% Space Free | Partition Type: NTFS
Drive H: | 298.09 Gb Total Space | 66.36 Gb Free Space | 22.26% Space Free | Partition Type: NTFS
Drive O: | 931.51 Gb Total Space | 197.15 Gb Free Space | 21.16% Space Free | Partition Type: NTFS
Drive P: | 298.09 Gb Total Space | 72.04 Gb Free Space | 24.17% Space Free | Partition Type: NTFS
Drive Q: | 465.76 Gb Total Space | 93.60 Gb Free Space | 20.10% Space Free | Partition Type: NTFS
Drive R: | 596.17 Gb Total Space | 285.03 Gb Free Space | 47.81% Space Free | Partition Type: NTFS
Drive Z: | 931.51 Gb Total Space | 522.21 Gb Free Space | 56.06% Space Free | Partition Type: NTFS

Computer Name: GLENS-HP | User Name: Glens | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Quick Scan | Include 64bit Scans
Company Name Whitelist: On | Skip Microsoft Files: On | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2014/02/27 11:07:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Glens\Downloads\OTL.exe
PRC - [2014/02/26 10:53:43 | 000,346,000 | ---- | M] (Adobe Systems Incorporated) -- C:\Users\Glens\AppData\Local\Temp\Creative Cloud Helper.exe
PRC - [2014/02/22 14:07:12 | 001,134,592 | ---- | M] (Zhorn Software) -- C:\Program Files (x86)\Stickies\stickies.exe
PRC - [2014/02/20 17:55:04 | 000,118,056 | ---- | M] (Cisco WebEx LLC) -- C:\Windows\SysWOW64\atashost.exe
PRC - [2014/02/19 20:03:06 | 000,859,464 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/02/18 15:54:54 | 000,219,832 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\Dashlane.exe
PRC - [2014/02/18 15:52:34 | 000,217,600 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\DashlanePlugin.exe
PRC - [2014/02/15 14:45:38 | 000,223,112 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe
PRC - [2014/02/11 15:05:14 | 000,395,120 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
PRC - [2014/02/11 10:54:18 | 002,239,376 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
PRC - [2014/01/15 11:02:16 | 004,697,456 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncV1\CoreSync.exe
PRC - [2014/01/02 19:46:10 | 030,714,328 | ---- | M] (Dropbox, Inc.) -- C:\Users\Glens\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013/12/18 13:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/12/13 05:16:54 | 000,769,904 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
PRC - [2013/12/12 22:37:01 | 000,309,328 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
PRC - [2013/11/08 15:14:26 | 000,250,712 | ---- | M] (Garmin Ltd or its subsidiaries) -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
PRC - [2013/10/08 07:28:15 | 000,275,696 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
PRC - [2013/09/03 08:33:53 | 003,233,806 | ---- | M] () -- C:\Program Files (x86)\Tor\tor.exe
PRC - [2013/04/24 04:30:28 | 000,483,864 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
PRC - [2013/04/24 04:26:56 | 000,740,888 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
PRC - [2013/03/15 00:53:06 | 001,266,464 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2013/03/14 21:07:46 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/11/08 10:07:22 | 000,094,608 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Snagit 10\TscHelp.exe
PRC - [2011/11/08 10:07:20 | 000,094,608 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Snagit 10\SnagPriv.exe
PRC - [2011/11/08 10:07:18 | 007,397,776 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Snagit 10\SnagitEditor.exe
PRC - [2011/11/08 10:07:16 | 007,070,608 | ---- | M] (TechSmith Corporation) -- C:\Program Files (x86)\TechSmith\Snagit 10\Snagit32.exe
PRC - [2011/06/09 07:37:18 | 000,264,008 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
PRC - [2011/06/09 07:37:00 | 000,653,128 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
PRC - [2011/06/09 07:36:34 | 000,142,664 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
PRC - [2011/02/24 02:10:24 | 000,212,944 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
PRC - [2011/02/01 02:41:24 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2011/02/01 02:41:20 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/11/26 09:09:12 | 000,399,344 | ---- | M] (Roxio) -- C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
PRC - [2010/11/20 22:24:03 | 000,302,592 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWOW64\cmd.exe
PRC - [2010/08/24 16:56:14 | 000,608,528 | ---- | M] (TiVo Inc.) -- C:\Program Files (x86)\TiVo\Desktop\TiVoTransfer.exe
PRC - [2010/08/24 16:56:12 | 002,264,336 | ---- | M] (TiVo Inc.) -- C:\Program Files (x86)\TiVo\Desktop\TiVoServer.exe
PRC - [2010/08/24 16:56:10 | 000,437,520 | ---- | M] (TiVo Inc.) -- C:\Program Files (x86)\TiVo\Desktop\TiVoNotify.exe
PRC - [2010/08/24 16:56:04 | 001,104,656 | ---- | M] (TiVo Inc.) -- C:\Program Files (x86)\TiVo\Desktop\TiVoBeacon.exe
PRC - [2010/02/18 16:01:06 | 000,462,632 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2008/11/20 12:47:28 | 000,062,768 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
PRC - [2008/04/17 05:33:14 | 000,181,544 | ---- | M] (Seagate Technology LLC) -- C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe
PRC - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe
PRC - [2006/10/12 15:57:08 | 000,102,400 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\EPSON\Creativity Suite\Event Manager\EEventManager.exe
PRC - [2006/10/04 11:04:20 | 002,658,304 | R--- | M] (QUALCOMM Incorporated) -- C:\Program Files (x86)\Qualcomm\Eudora\Eudora.exe


========== Modules (No Company Name) ==========

MOD - [2014/02/22 14:07:11 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Stickies\shook70.dll
MOD - [2014/02/19 20:03:05 | 000,394,568 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ppgooglenaclpluginchrome.dll
MOD - [2014/02/19 20:03:04 | 013,632,840 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\PepperFlash\pepflashplayer.dll
MOD - [2014/02/19 20:03:03 | 004,060,488 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\pdf.dll
MOD - [2014/02/19 20:02:59 | 000,716,616 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\libglesv2.dll
MOD - [2014/02/19 20:02:58 | 000,100,168 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\libegl.dll
MOD - [2014/02/19 20:02:56 | 001,647,432 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ffmpegsumo.dll
MOD - [2014/02/19 20:02:54 | 000,051,016 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\chrome_elf.dll
MOD - [2014/02/18 15:54:54 | 000,219,832 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\Dashlane.exe
MOD - [2014/02/18 15:54:02 | 001,902,776 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLibData.2.4.0.56656.dll
MOD - [2014/02/18 15:54:02 | 000,423,096 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWUtils.2.4.0.56656.dll
MOD - [2014/02/18 15:54:02 | 000,263,352 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib_win.2.4.0.56656.dll
MOD - [2014/02/18 15:53:58 | 012,111,032 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib.2.4.0.56656.dll
MOD - [2014/02/18 15:53:56 | 000,188,600 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\Kwift_DP.2.4.0.56656.dll
MOD - [2014/02/18 15:53:54 | 028,197,904 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWExternLib.2.4.0.56656.dll
MOD - [2014/02/18 15:53:54 | 000,254,648 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebugDll_win32.2.4.0.56656.dll
MOD - [2014/02/18 15:53:52 | 004,799,160 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWData.2.4.0.56656.dll
MOD - [2014/02/18 15:53:52 | 004,306,616 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWApplication.2.4.0.56656.dll
MOD - [2014/02/18 15:53:52 | 000,360,976 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebug.2.4.0.56656.dll
MOD - [2014/02/18 15:52:34 | 000,217,600 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\DashlanePlugin.exe
MOD - [2014/02/11 15:09:42 | 032,733,080 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll
MOD - [2014/02/11 15:09:38 | 000,742,808 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libGLESv2.dll
MOD - [2014/02/11 15:09:38 | 000,136,600 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libEGL.dll
MOD - [2014/01/15 11:02:16 | 004,697,456 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncV1\CoreSync.exe
MOD - [2014/01/02 19:45:04 | 003,558,400 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2013/10/18 18:55:02 | 025,100,288 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2011/09/27 10:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 10:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/08/24 16:55:58 | 000,050,960 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\Plus\TranscodingServicePS.dll
MOD - [2010/08/24 16:34:24 | 000,259,584 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\Id3Lib.dll
MOD - [2010/05/17 21:56:22 | 000,684,032 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\LibEay32.dll
MOD - [2010/05/17 21:56:22 | 000,155,648 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\SslEay32.dll
MOD - [2010/05/17 21:54:54 | 000,716,800 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\loudmouth.dll
MOD - [2006/10/04 11:04:22 | 000,065,536 | R--- | M] () -- C:\Program Files (x86)\Qualcomm\Eudora\plstclnt.dll
MOD - [2006/10/04 11:04:18 | 000,007,680 | R--- | M] () -- C:\Program Files (x86)\Qualcomm\Eudora\EuLang.dll
MOD - [2006/09/26 12:45:40 | 000,633,856 | ---- | M] () -- C:\Program Files (x86)\Qualcomm\Eudora\x1lib.dll
MOD - [2006/09/26 12:45:34 | 000,151,552 | ---- | M] () -- C:\Program Files (x86)\Qualcomm\Eudora\libexpat.dll
MOD - [2006/08/17 14:57:24 | 000,011,264 | R--- | M] () -- C:\Users\Glens\AppData\Roaming\Qualcomm\Eudora\plugins\Unwrap32.dll
MOD - [2003/01/30 06:04:00 | 000,618,496 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\StlpMt45.dll


========== Services (SafeList) ==========

SRV:64bit: - [2014/02/06 05:48:45 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/10/10 17:54:28 | 000,144,152 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
SRV:64bit: - [2013/05/27 00:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/04/24 19:38:30 | 000,318,464 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)
SRV:64bit: - [2011/09/27 14:04:08 | 000,359,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2011/03/25 19:19:08 | 000,956,192 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2010/10/13 11:41:06 | 000,487,280 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_TouchService.exe -- (TouchServicePen)
SRV:64bit: - [2010/10/13 11:41:04 | 005,790,064 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_Tablet.exe -- (TabletServicePen)
SRV:64bit: - [2010/10/11 04:48:14 | 000,346,168 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe -- (HPClientSvc)
SRV:64bit: - [2010/09/22 20:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/09/14 00:00:00 | 000,128,512 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE -- (EPSON_PM_RPCV4_04)
SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009/03/02 17:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\IDT\WDM\AESTSr64.exe -- (AESTFilters)
SRV - [2014/02/25 15:12:14 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/02/20 17:55:04 | 000,118,056 | ---- | M] (Cisco WebEx LLC) [Auto | Running] -- C:\Windows\SysWOW64\atashost.exe -- (atashost)
SRV - [2013/12/18 13:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/11/08 15:14:26 | 000,250,712 | ---- | M] (Garmin Ltd or its subsidiaries) [Auto | Running] -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe -- (Garmin Core Update Service)
SRV - [2013/11/04 18:31:56 | 000,092,160 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)
SRV - [2013/10/08 07:28:15 | 000,275,696 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe -- (NIS)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/09/03 08:33:53 | 003,233,806 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Tor\tor.exe -- (tor)
SRV - [2013/04/24 04:30:28 | 000,483,864 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2013/03/15 00:53:06 | 001,266,464 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2013/03/14 21:07:46 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/06/09 07:37:18 | 000,264,008 | ---- | M] (HP) [Auto | Running] -- C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe -- (FPLService)
SRV - [2011/02/24 02:10:24 | 000,212,944 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe -- (jhi_service)
SRV - [2011/02/01 02:41:24 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/02/01 02:41:20 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/11/26 09:09:12 | 000,399,344 | ---- | M] (Roxio) [Auto | Running] -- C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe -- (RoxioNow Service)
SRV - [2010/10/12 12:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/08/24 16:56:04 | 001,104,656 | ---- | M] (TiVo Inc.) [Auto | Running] -- C:\Program Files (x86)\TiVo\Desktop\TiVoBeacon.exe -- (TivoBeacon2)
SRV - [2010/06/01 17:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010/02/19 15:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/02/18 16:01:06 | 000,462,632 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/04/17 05:33:14 | 000,181,544 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe -- (Maxtor Sync Service)
SRV - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/11/13 11:27:51 | 000,177,752 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2013/10/01 21:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013/09/26 22:18:30 | 001,147,480 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\SymEFA64.sys -- (SymEFA)
DRV:64bit: - [2013/09/26 21:45:56 | 000,264,280 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\Ironx64.sys -- (SymIRON)
DRV:64bit: - [2013/09/26 21:26:03 | 000,858,200 | R--- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2013/09/25 22:28:00 | 000,590,936 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\symnets.sys -- (SymNetS)
DRV:64bit: - [2013/09/25 21:50:25 | 000,162,392 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\ccSetx64.sys -- (ccSet_NIS)
DRV:64bit: - [2013/09/09 21:47:43 | 000,078,936 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SymIMV.sys -- (SymIM)
DRV:64bit: - [2013/09/09 21:47:26 | 000,493,656 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\SymDS64.sys -- (SymDS)
DRV:64bit: - [2013/09/09 20:49:49 | 000,036,952 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\srtspx64.sys -- (SRTSPX)
DRV:64bit: - [2012/12/19 00:41:52 | 000,194,488 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2012/12/13 14:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/08/23 09:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 09:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/08/13 20:36:38 | 000,013,120 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rcmirror64.sys -- (rcmirror)
DRV:64bit: - [2012/05/29 14:53:30 | 000,027,456 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cpqdfw.sys -- (CpqDfw)
DRV:64bit: - [2012/04/24 19:38:30 | 000,536,576 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/12/01 18:04:01 | 000,828,912 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2011/10/22 18:00:57 | 000,031,152 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pmxdrv.sys -- (pmxdrv)
DRV:64bit: - [2011/10/22 17:39:58 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/10/22 17:39:58 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/09/02 01:30:36 | 000,060,696 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2011/09/02 01:30:24 | 000,076,056 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LEqdUsb.sys -- (LEqdUsb)
DRV:64bit: - [2011/09/02 01:30:24 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2011/09/02 01:30:24 | 000,015,128 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidEqd.sys -- (LHidEqd)
DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:64bit: - [2011/05/16 13:55:28 | 000,533,096 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/04/26 14:07:36 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/04/20 18:07:22 | 000,399,944 | ---- | M] (Texas Instruments Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tixhci.sys -- (tixhci)
DRV:64bit: - [2011/04/20 18:07:22 | 000,131,656 | ---- | M] (Texas Instruments Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tihub3.sys -- (tihub3)
DRV:64bit: - [2011/04/05 16:29:58 | 000,066,552 | ---- | M] (PalmSource, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AceecaUSBDx64.sys -- (AceecaUSBDx64)
DRV:64bit: - [2011/03/25 21:21:10 | 000,349,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (BTWAMPFL)
DRV:64bit: - [2011/03/25 21:21:06 | 000,138,280 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2011/03/25 21:21:06 | 000,107,560 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2011/03/25 21:21:06 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2011/03/25 21:21:06 | 000,021,416 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010/11/20 22:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/20 22:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/10/19 06:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010/10/05 13:26:10 | 000,018,288 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV:64bit: - [2010/10/05 13:26:02 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV:64bit: - [2010/10/05 13:26:00 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomvhid.sys -- (wacomvhid)
DRV:64bit: - [2010/03/22 22:39:20 | 003,060,800 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2010/03/12 18:21:52 | 000,097,280 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ser2pl64.sys -- (Ser2pl)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 15:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2007/08/31 14:15:34 | 000,079,872 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emAudio64.sys -- (emAudio)
DRV:64bit: - [2007/06/21 17:51:46 | 000,215,808 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emDevice64.sys -- (DCamUSBEMPIA)
DRV:64bit: - [2007/06/21 17:51:32 | 000,006,400 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emFilter64.sys -- (FiltUSBEMPIA)
DRV:64bit: - [2007/06/21 17:51:30 | 000,006,144 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emScan64.sys -- (ScanUSBEMPIA)
DRV:64bit: - [2005/09/23 22:18:34 | 000,261,120 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MarvinBus64.sys -- (MarvinBus)
DRV - [2014/01/20 18:28:20 | 000,521,944 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140226.001\IDSviA64.sys -- (IDSVia64)
DRV - [2013/12/17 19:32:10 | 001,526,488 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20140214.001\BHDrvx64.sys -- (BHDrvx64)
DRV - [2013/11/21 00:42:05 | 000,484,952 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2013/11/21 00:42:05 | 000,137,648 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2013/11/13 01:00:00 | 002,099,288 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140227.002\ex64.sys -- (NAVEX15)
DRV - [2013/11/13 01:00:00 | 000,126,040 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140227.002\eng64.sys -- (NAVENG)
DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.co...&l=dis&o=HPDTDF
IE:64bit: - HKLM\..\SearchScopes\{3B83A2C8-E0A9-4604-A14C-E96435CD4D3A}: "URL" = http://www.amazon.co...s={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo....psg&type=HPDTDF
IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia....h={searchTerms}
IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.co...w={searchTerms}
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope = {763CC174-CCD7-4972-8063-BEEEC2A8B7CE}
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.co...&l=dis&o=HPDTDF
IE - HKLM\..\SearchScopes\{3B83A2C8-E0A9-4604-A14C-E96435CD4D3A}: "URL" = http://www.amazon.co...s={searchTerms}
IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo....psg&type=HPDTDF
IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia....h={searchTerms}
IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.co...w={searchTerms}

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.myway.com/
IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKCU\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.co...&l=dis&o=HPDTDF
IE - HKCU\..\SearchScopes\{3B83A2C8-E0A9-4604-A14C-E96435CD4D3A}: "URL" = http://www.amazon.co...s={searchTerms}
IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7GGHP_enUS456
IE - HKCU\..\SearchScopes\{9B97950D-482C-1D79-568F-FC7B9D40C785}: "URL" = http://www.bing.com/...eferrer:source}
IE - HKCU\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo....psg&type=HPDTDF
IE - HKCU\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia....h={searchTerms}
IE - HKCU\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.co...w={searchTerms}
IE - HKCU\..\SearchScopes\{EC23C1C8-47E1-22F0-FF5D-CD82BE4273C8}: "URL" = http://www.bing.com/...eferrer:source}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@palmsource.com/installer,version=1.0: C:\PROGRA~2\palmOne\PACKAG~1\NPInstal.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\adobe.com/AdobeExManCCDetect32: C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\adobe.com/AdobeExManCCDetect64: C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect64.dll (Adobe Systems)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn\ [2014/02/25 14:59:14 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF [2013/11/13 15:40:34 | 000,000,000 | ---D | M]

[2013/06/08 10:39:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://my.myway.com/
CHR - plugin: Shockwave Flash (Enabled) = C:\Users\Glens\AppData\Local\Google\Chrome\Application\21.0.1180.89\PepperFlash\pepflashplayer.dll
CHR - plugin: Shockwave Flash (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\gcswf32.dll
CHR - plugin: Remoting Viewer (Enabled) = internal-remoting-viewer
CHR - plugin: Native Client (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ppGoogleNaClPluginChrome.dll
CHR - plugin: Chrome PDF Viewer (Enabled) = C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\pdf.dll
CHR - plugin: Simple Pass 2011 (Enabled) = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgfhihjicjofdejkbjgnjlaglaciobe\1.0_0\npwebsitelogon.dll
CHR - plugin: Norton Confidential (Enabled) = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2012.5.5.11_0\npcoplgn.dll
CHR - plugin: Adobe Acrobat (Enabled) = C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Browser\nppdf32.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin2.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin3.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin4.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin5.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin6.dll
CHR - plugin: QuickTime Plug-in 7.7.2 (Enabled) = C:\Program Files (x86)\QuickTime\plugins\npqtplugin7.dll
CHR - plugin: PalmSource Package Installer (Enabled) = C:\PROGRA~2\palmOne\PACKAG~1\NPInstal.dll
CHR - plugin: Google Earth Plugin (Enabled) = C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll
CHR - plugin: Google Update (Enabled) = C:\Program Files (x86)\Google\Update\1.3.21.123\npGoogleUpdate3.dll
CHR - plugin: NVIDIA 3D Vision (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll
CHR - plugin: NVIDIA 3D VISION (Enabled) = C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll
CHR - plugin: Wacom Dynamic Link Library (Enabled) = C:\Program Files (x86)\TabletPlugins\npwacom.dll
CHR - plugin: Windows Live Photo Gallery (Enabled) = C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll
CHR - plugin: iTunes Application Detector (Enabled) = C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll
CHR - plugin: Silverlight Plug-In (Enabled) = c:\Program Files (x86)\Microsoft Silverlight\5.1.10411.0\npctrl.dll
CHR - Extension: Dashlane = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\2.4.0.53495_1\
CHR - Extension: Website Logon = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgfhihjicjofdejkbjgnjlaglaciobe\1.0_0\
CHR - Extension: Norton Identity Protection = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0\
CHR - Extension: Google Wallet = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
O2 - BHO: (Dashlane BHO) - {42D79B50-CC4A-4A8E-860F-BE674AF053A2} - C:\Users\Glens\AppData\Roaming\Dashlane\ie\Dashlanei.dll (Dashlane)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\ipsbho.dll (Symantec Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Dashlane Toolbar) - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Glens\AppData\Roaming\Dashlane\ie\KWIEBar.dll (Dashlane)
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BeatsOSDApp] C:\Program Files\IDT\WDM\beats64.exe (Hewlett-Packard )
O4:64bit: - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\EPSON\Creativity Suite\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Dashlane] C:\Users\Glens\AppData\Roaming\Dashlane\Dashlane.exe ()
O4 - HKCU..\Run: [GarminExpressTrayApp] C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware)
O4 - HKCU..\Run: [TivoNotify] C:\Program Files (x86)\TiVo\Desktop\TiVoNotify.exe (TiVo Inc.)
O4 - HKCU..\Run: [TivoServer] C:\Program Files (x86)\TiVo\Desktop\TiVoServer.exe (TiVo Inc.)
O4 - HKCU..\Run: [TivoTransfer] C:\Program Files (x86)\TiVo\Desktop\TiVoTransfer.exe (TiVo Inc.)
O4 - HKCU..\Run: [TranscodingService] C:\Program Files (x86)\TiVo\Desktop\Plus\\TranscodingService.exe ()
O4:64bit: - HKLM..\RunOnce: [NCPluginUpdater] c:\program files (x86)\hewlett-packard\hp health check\activecheck\product_line\NCPluginUpdater.exe (Hewlett-Packard)
O4 - Startup: C:\Users\Glens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Glens\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: EnableLUA = 0
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9:64bit: - Extra Button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.h...pdetect1263.cab (GMNRev Class)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadbl...ivex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://linksyssuppo...rt/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: Garmin Communicator Plug-In https://static.garmi...xControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 207.69.188.186 207.69.188.187 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1F967591-0D7C-44B2-AED9-B9411FB2D3A5}: DhcpNameServer = 207.69.188.186 207.69.188.187 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{36AC44C1-9AA8-4744-805E-935E2827B256}: DhcpNameServer = 207.69.188.186 207.69.188.187 192.168.1.1
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/05 18:15:08 | 000,000,034 | ---- | M] () - H:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/01/18 16:12:59 | 000,000,067 | ---- | M] () - O:\Autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2009/05/07 07:35:55 | 000,000,063 | ---- | M] () - Q:\autorun.inf -- [ NTFS ]
O32 - AutoRun File - [2011/01/18 16:15:03 | 000,000,062 | ---- | M] () - Z:\Autorun.inf -- [ NTFS ]
O33 - MountPoints2\{0bba1dd7-04ba-11e1-8f1c-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{0bba1dd7-04ba-11e1-8f1c-d0df9aa5d807}\Shell\AutoRun\command - "" = I:\launcher.exe
O33 - MountPoints2\{0bba1ec5-04ba-11e1-8f1c-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{0bba1ec5-04ba-11e1-8f1c-d0df9aa5d807}\Shell\AutoRun\command - "" = J:\launcher.exe
O33 - MountPoints2\{30973883-1544-11e1-94b8-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{30973883-1544-11e1-94b8-d0df9aa5d807}\Shell\AutoRun\command - "" = I:\launcher.exe
O33 - MountPoints2\{3097389b-1544-11e1-94b8-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{3097389b-1544-11e1-94b8-d0df9aa5d807}\Shell\AutoRun\command - "" = I:\launcher.exe
O33 - MountPoints2\{98137975-1dc5-11e1-86c0-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{98137975-1dc5-11e1-86c0-d0df9aa5d807}\Shell\AutoRun\command - "" = H:\launcher.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2014/02/25 15:12:19 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2014/02/23 16:56:10 | 000,000,000 | ---D | C] -- C:\Users\Glens\Documents\Update Problem
[2014/02/23 15:40:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2014/02/23 15:39:41 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/02/23 15:39:24 | 000,000,000 | ---D | C] -- C:\Users\Glens\MBAR
[2014/02/23 13:22:20 | 000,000,000 | ---D | C] -- C:\Users\Glens\AppData\Roaming\Malwarebytes
[2014/02/23 13:21:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/02/23 13:21:46 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/02/23 13:21:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2014/02/22 17:06:05 | 000,000,000 | ---D | C] -- C:\Windows\Migration
[2014/02/22 15:07:46 | 000,000,000 | ---D | C] -- C:\Windows\CheckSur
[2014/02/22 14:07:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Stickies
[2014/02/20 17:55:08 | 000,210,216 | ---- | C] (Cisco WebEx LLC) -- C:\Windows\SysWow64\atsckernel.exe
[2014/02/20 17:55:06 | 000,118,056 | ---- | C] (Cisco WebEx LLC) -- C:\Windows\SysWow64\atashost.exe
[2014/02/20 17:54:38 | 000,000,000 | ---D | C] -- C:\ProgramData\WebEx
[2014/02/20 16:46:44 | 000,000,000 | ---D | C] -- C:\Users\Glens\AppData\Roaming\chc
[2014/02/19 15:06:19 | 000,000,000 | ---D | C] -- C:\Users\Glens\AppData\Local\ElevatedDiagnostics
[2014/02/18 18:37:34 | 000,000,000 | ---D | C] -- C:\Users\Glens\AppData\Roaming\Lavasoft
[2014/02/18 18:37:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft Ad-Aware SE Personal
[2014/02/18 18:37:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lavasoft
[2014/02/06 12:13:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ThumbsPlus
[2014/02/06 12:12:46 | 000,000,000 | -H-D | C] -- C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}
[2014/02/06 11:44:58 | 000,000,000 | -H-D | C] -- C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Users\Glens\*.tmp files -> C:\Users\Glens\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2014/02/27 11:10:12 | 000,001,864 | ---- | M] () -- C:\Users\Glens\Desktop\OTL.exe - Shortcut.lnk
[2014/02/27 10:57:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/02/27 10:51:38 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/02/27 02:00:00 | 000,000,510 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 0cf62b45-2ff6-4f51-a641-b157a3f6bd3f.job
[2014/02/27 01:15:00 | 000,000,572 | ---- | M] () -- C:\Windows\tasks\b4a_Active Data.job
[2014/02/27 00:30:12 | 000,000,580 | ---- | M] () -- C:\Windows\tasks\b4a_Digital Current.job
[2014/02/26 18:06:47 | 000,000,580 | ---- | M] () -- C:\Windows\tasks\b4a_Scrapbook Scans.job
[2014/02/26 18:06:47 | 000,000,574 | ---- | M] () -- C:\Windows\tasks\b4a_Zphotol to O.job
[2014/02/26 18:06:47 | 000,000,574 | ---- | M] () -- C:\Windows\tasks\b4a_Weather data.job
[2014/02/26 18:06:47 | 000,000,574 | ---- | M] () -- C:\Windows\tasks\b4a_Glens Videos.job
[2014/02/26 18:06:47 | 000,000,568 | ---- | M] () -- C:\Windows\tasks\b4a_Favorites.job
[2014/02/26 18:06:47 | 000,000,558 | ---- | M] () -- C:\Windows\tasks\b4a_Other Photo.job
[2014/02/26 18:06:46 | 000,000,610 | ---- | M] () -- C:\Windows\tasks\b4a_Glens HP to Bank non Zphoto.job
[2014/02/26 18:06:46 | 000,000,596 | ---- | M] () -- C:\Windows\tasks\b4a_Photo to velma - Photos.job
[2014/02/26 18:06:46 | 000,000,590 | ---- | M] () -- C:\Windows\tasks\b4a_Mirror to X3 from TO.job
[2014/02/26 16:45:16 | 000,782,470 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/02/26 16:45:16 | 000,662,384 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/02/26 16:45:16 | 000,122,252 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/02/26 14:51:00 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/02/26 12:42:00 | 000,000,510 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task d74c3073-85bd-4619-804e-5111bb8c2c67.job
[2014/02/26 10:57:03 | 000,001,303 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
[2014/02/26 09:24:19 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/02/25 15:06:51 | 000,027,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/02/25 15:06:51 | 000,027,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/02/25 14:58:20 | 4279,484,414 | -HS- | M] () -- C:\hiberfil.sys
[2014/02/24 17:22:03 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForGlens.job
[2014/02/24 11:25:27 | 000,000,349 | ---- | M] () -- C:\Users\Public\Documents\PCLECHAL.INI
[2014/02/23 16:57:12 | 000,001,208 | ---- | M] () -- C:\Users\Glens\Documents\details of KB954430 instal.rtf
[2014/02/23 15:39:41 | 000,091,352 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/02/23 13:21:47 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/02/22 17:26:20 | 000,774,592 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014/02/22 14:24:08 | 000,001,013 | ---- | M] () -- C:\Users\Glens\Desktop\stickies.chm - HELP.lnk
[2014/02/22 14:07:12 | 000,001,049 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Stickies.lnk
[2014/02/22 14:07:12 | 000,000,625 | ---- | M] () -- C:\Windows\uninstallstickies.bat
[2014/02/21 04:46:02 | 000,001,915 | ---- | M] () -- C:\Users\Glens\Desktop\Dashlane.lnk
[2014/02/20 20:01:41 | 000,002,185 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/02/20 17:55:04 | 000,210,216 | ---- | M] (Cisco WebEx LLC) -- C:\Windows\SysWow64\atsckernel.exe
[2014/02/20 17:55:04 | 000,118,056 | ---- | M] (Cisco WebEx LLC) -- C:\Windows\SysWow64\atashost.exe
[2014/02/17 12:41:35 | 000,007,663 | ---- | M] () -- C:\Users\Glens\AppData\Local\Resmon.ResmonCfg
[2014/02/15 14:36:23 | 000,001,456 | ---- | M] () -- C:\Users\Glens\AppData\Local\Adobe Save for Web 13.0 Prefs
[2014/02/13 13:21:03 | 010,094,603 | ---- | M] () -- C:\Users\Glens\Desktop\bird1.mp4
[2014/02/13 12:39:44 | 000,012,288 | ---- | M] () -- C:\Users\Glens\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/02/13 11:39:13 | 000,000,080 | ---- | M] () -- C:\Users\Glens\Videos.scn
[2014/02/06 12:13:12 | 000,001,089 | ---- | M] () -- C:\Users\Glens\Application Data\Microsoft\Internet Explorer\Quick Launch\ThumbsPlus 9.lnk
[2014/02/06 12:13:12 | 000,001,065 | ---- | M] () -- C:\Users\Glens\Desktop\ThumbsPlus 9.lnk
[2014/02/06 12:13:12 | 000,000,251 | ---- | M] () -- C:\Windows\ODBCINST.INI
[2014/02/06 11:49:50 | 000,000,308 | ---- | M] () -- C:\CD Drive - Shortcut.lnk
[2014/02/01 10:28:08 | 000,001,410 | ---- | M] () -- C:\Users\Glens\Desktop\stickies.exe - Shortcut.lnk
[2014/01/30 13:43:23 | 000,000,355 | ---- | M] () -- C:\Program Files\Homegroup - Shortcut.lnk
[2014/01/30 09:32:01 | 000,001,013 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk
[2014/01/30 09:31:52 | 000,000,981 | ---- | M] () -- C:\Users\Glens\Desktop\Dropbox.lnk
[2 C:\*.tmp files -> C:\*.tmp -> ]
[1 C:\Users\Glens\*.tmp files -> C:\Users\Glens\*.tmp -> ]

========== Files Created - No Company Name ==========

[2014/02/27 11:10:12 | 000,001,864 | ---- | C] () -- C:\Users\Glens\Desktop\OTL.exe - Shortcut.lnk
[2014/02/23 16:57:12 | 000,001,208 | ---- | C] () -- C:\Users\Glens\Documents\details of KB954430 instal.rtf
[2014/02/23 13:21:47 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/02/22 14:24:08 | 000,001,013 | ---- | C] () -- C:\Users\Glens\Desktop\stickies.chm - HELP.lnk
[2014/02/22 14:07:12 | 000,001,049 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Stickies.lnk
[2014/02/22 14:07:12 | 000,000,625 | ---- | C] () -- C:\Windows\uninstallstickies.bat
[2014/02/14 12:43:36 | 000,000,510 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task d74c3073-85bd-4619-804e-5111bb8c2c67.job
[2014/02/14 12:34:10 | 000,000,510 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 0cf62b45-2ff6-4f51-a641-b157a3f6bd3f.job
[2014/02/13 13:20:17 | 010,094,603 | ---- | C] () -- C:\Users\Glens\Desktop\bird1.mp4
[2014/02/06 12:13:12 | 000,001,089 | ---- | C] () -- C:\Users\Glens\Application Data\Microsoft\Internet Explorer\Quick Launch\ThumbsPlus 9.lnk
[2014/02/06 12:13:12 | 000,001,065 | ---- | C] () -- C:\Users\Glens\Desktop\ThumbsPlus 9.lnk
[2014/02/06 11:49:50 | 000,000,308 | ---- | C] () -- C:\CD Drive - Shortcut.lnk
[2014/02/01 10:28:08 | 000,001,410 | ---- | C] () -- C:\Users\Glens\Desktop\stickies.exe - Shortcut.lnk
[2014/01/30 13:43:23 | 000,000,355 | ---- | C] () -- C:\Program Files\Homegroup - Shortcut.lnk
[2013/12/12 10:02:03 | 000,001,456 | ---- | C] () -- C:\Users\Glens\AppData\Local\Adobe Save for Web 13.0 Prefs
[2013/10/15 11:07:47 | 000,000,884 | RHS- | C] () -- C:\Users\Glens\ntuser.pol
[2013/08/30 13:14:57 | 000,001,185 | ---- | C] () -- C:\Users\Glens\VG pictures - Shortcut.lnk
[2013/06/13 13:32:36 | 000,000,132 | ---- | C] () -- C:\Users\Glens\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2013/06/09 13:57:02 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2013/06/09 07:02:02 | 000,033,958 | ---- | C] () -- C:\ProgramData\uninstaller.exe
[2013/05/05 16:55:41 | 000,000,132 | ---- | C] () -- C:\Users\Glens\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2013/04/04 13:28:48 | 000,110,456 | ---- | C] () -- C:\Users\Glens\g2ax_customer_downloadhelper_win32_x86.exe
[2013/02/27 17:15:23 | 000,000,355 | ---- | C] () -- C:\Users\Glens\Homegroup - Shortcut.lnk
[2012/10/13 06:59:15 | 000,000,080 | ---- | C] () -- C:\Users\Glens\Videos.scn
[2012/08/29 11:05:04 | 000,100,344 | ---- | C] () -- C:\Windows\HPBroker.dll
[2012/07/18 07:16:03 | 000,000,036 | ---- | C] () -- C:\Windows\hdd.ini
[2012/07/03 12:02:46 | 000,000,029 | ---- | C] () -- C:\Windows\DEBUGSM.INI
[2012/06/26 06:10:06 | 003,668,480 | ---- | C] () -- C:\Windows\SysWow64\CosmoRenderer.dll
[2012/05/17 10:31:19 | 000,012,288 | ---- | C] () -- C:\Users\Glens\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/09 10:47:07 | 000,000,077 | ---- | C] () -- C:\Windows\EPSPR2000.ini
[2012/01/21 09:31:05 | 000,031,104 | ---- | C] () -- C:\Users\Glens\energy-report.html
[2012/01/02 14:48:37 | 000,000,047 | ---- | C] () -- C:\Program Files (x86)\sleep.bat
[2012/01/01 10:05:04 | 000,007,663 | ---- | C] () -- C:\Users\Glens\AppData\Local\Resmon.ResmonCfg
[2011/11/11 04:40:29 | 000,002,217 | ---- | C] () -- C:\ProgramData\repository.xml
[2011/11/10 11:44:44 | 000,001,456 | ---- | C] () -- C:\Users\Glens\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/11/01 19:46:41 | 000,713,728 | ---- | C] () -- C:\Program Files (x86)\FCW32.EXE
[2011/11/01 19:46:41 | 000,550,322 | ---- | C] () -- C:\Program Files (x86)\CARLSBAD.FCW
[2011/11/01 19:46:41 | 000,455,079 | ---- | C] () -- C:\Program Files (x86)\ADINIT.DAT
[2011/11/01 19:46:41 | 000,399,360 | ---- | C] () -- C:\Program Files (x86)\XPDWG.DLL
[2011/11/01 19:46:41 | 000,248,343 | ---- | C] () -- C:\Program Files (x86)\CMHOUSE.FCW
[2011/11/01 19:46:41 | 000,189,922 | ---- | C] () -- C:\Program Files (x86)\ELECTRIC.FSC
[2011/11/01 19:46:41 | 000,187,904 | ---- | C] () -- C:\Program Files (x86)\FCWLANG.DLL
[2011/11/01 19:46:41 | 000,174,797 | ---- | C] () -- C:\Program Files (x86)\TALI.FCW
[2011/11/01 19:46:41 | 000,164,244 | ---- | C] () -- C:\Program Files (x86)\MERPLAZA.FCW
[2011/11/01 19:46:41 | 000,128,000 | ---- | C] () -- C:\Program Files (x86)\UNINST.EXE
[2011/11/01 19:46:41 | 000,127,613 | ---- | C] () -- C:\Program Files (x86)\SOLAR.FCW
[2011/11/01 19:46:41 | 000,067,584 | ---- | C] () -- C:\Program Files (x86)\NED3.EXE
[2011/11/01 19:46:41 | 000,066,073 | ---- | C] () -- C:\Program Files (x86)\NOZZLE.FCW
[2011/11/01 19:46:41 | 000,054,863 | ---- | C] () -- C:\Program Files (x86)\LOGIC.FCW
[2011/11/01 19:46:41 | 000,044,032 | ---- | C] () -- C:\Program Files (x86)\XPLDFCD.DLL
[2011/11/01 19:46:41 | 000,043,329 | ---- | C] () -- C:\Program Files (x86)\USA.FCW
[2011/11/01 19:46:41 | 000,039,585 | ---- | C] () -- C:\Program Files (x86)\PADEMO.FCW
[2011/11/01 19:46:41 | 000,035,718 | ---- | C] () -- C:\Program Files (x86)\TRAIN.FCW
[2011/11/01 19:46:41 | 000,034,082 | ---- | C] () -- C:\Program Files (x86)\GALLERY.FCW
[2011/11/01 19:46:41 | 000,032,854 | ---- | C] () -- C:\Program Files (x86)\STONE.BMP
[2011/11/01 19:46:41 | 000,018,432 | ---- | C] () -- C:\Program Files (x86)\XPPRINTA.DLL
[2011/11/01 19:46:41 | 000,017,143 | ---- | C] () -- C:\Program Files (x86)\LINWIDTH.GDE
[2011/11/01 19:46:41 | 000,016,192 | ---- | C] () -- C:\Program Files (x86)\60.GDE
[2011/11/01 19:46:41 | 000,015,118 | ---- | C] () -- C:\Program Files (x86)\LEAVES.BMP
[2011/11/01 19:46:41 | 000,014,947 | ---- | C] () -- C:\Program Files (x86)\PULLEY.FCW
[2011/11/01 19:46:41 | 000,014,469 | ---- | C] () -- C:\Program Files (x86)\PRINTEST.FCW
[2011/11/01 19:46:41 | 000,013,312 | ---- | C] () -- C:\Program Files (x86)\XPGUIDE.DLL
[2011/11/01 19:46:41 | 000,013,009 | ---- | C] () -- C:\Program Files (x86)\FCDLOGO.FCW
[2011/11/01 19:46:41 | 000,012,288 | ---- | C] () -- C:\Program Files (x86)\XPLDECW.DLL
[2011/11/01 19:46:41 | 000,012,159 | ---- | C] () -- C:\Program Files (x86)\SYMCAT.GDE
[2011/11/01 19:46:41 | 000,011,776 | ---- | C] () -- C:\Program Files (x86)\XPSYMCAT.DLL
[2011/11/01 19:46:41 | 000,010,752 | ---- | C] () -- C:\Program Files (x86)\XPENT.DLL
[2011/11/01 19:46:41 | 000,010,062 | ---- | C] () -- C:\Program Files (x86)\BASICS.GDE
[2011/11/01 19:46:41 | 000,009,481 | ---- | C] () -- C:\Program Files (x86)\ACTDEMO.FCW
[2011/11/01 19:46:41 | 000,009,247 | ---- | C] () -- C:\Program Files (x86)\COLORS.FCW
[2011/11/01 19:46:41 | 000,009,141 | ---- | C] () -- C:\Program Files (x86)\TABLET.FCW
[2011/11/01 19:46:41 | 000,008,704 | ---- | C] () -- C:\Program Files (x86)\XPACT.DLL
[2011/11/01 19:46:41 | 000,008,124 | ---- | C] () -- C:\Program Files (x86)\3D.FCW
[2011/11/01 19:46:41 | 000,008,093 | ---- | C] () -- C:\Program Files (x86)\LSTYLES.fcw
[2011/11/01 19:46:41 | 000,008,012 | ---- | C] () -- C:\Program Files (x86)\FILLS.FCW
[2011/11/01 19:46:41 | 000,007,674 | ---- | C] () -- C:\Program Files (x86)\FCAD3.MNU
[2011/11/01 19:46:41 | 000,007,655 | ---- | C] () -- C:\Program Files (x86)\SYM.FCW
[2011/11/01 19:46:41 | 000,007,644 | ---- | C] () -- C:\Program Files (x86)\MULTIFIL.GDE
[2011/11/01 19:46:41 | 000,007,612 | ---- | C] () -- C:\Program Files (x86)\FCW32.MNU
[2011/11/01 19:46:41 | 000,007,537 | ---- | C] () -- C:\Program Files (x86)\SCREEN.GDE
[2011/11/01 19:46:41 | 000,007,521 | ---- | C] () -- C:\Program Files (x86)\GREEK.FNT
[2011/11/01 19:46:41 | 000,007,049 | ---- | C] () -- C:\Program Files (x86)\60NEW.FCW
[2011/11/01 19:46:41 | 000,006,933 | ---- | C] () -- C:\Program Files (x86)\CARTGRID.FCW
[2011/11/01 19:46:41 | 000,006,866 | ---- | C] () -- C:\Program Files (x86)\SMARTSYM.FCW
[2011/11/01 19:46:41 | 000,006,667 | ---- | C] () -- C:\Program Files (x86)\LESSON12.FCW
[2011/11/01 19:46:41 | 000,006,649 | ---- | C] () -- C:\Program Files (x86)\BURNER.FCW
[2011/11/01 19:46:41 | 000,006,545 | ---- | C] () -- C:\Program Files (x86)\LDIMS.FCW
[2011/11/01 19:46:41 | 000,006,274 | ---- | C] () -- C:\Program Files (x86)\CARTANGL.FCW
[2011/11/01 19:46:41 | 000,006,258 | ---- | C] () -- C:\Program Files (x86)\LWIDTHT.FCW
[2011/11/01 19:46:41 | 000,006,250 | ---- | C] () -- C:\Program Files (x86)\METRIC.FCT
[2011/11/01 19:46:41 | 000,006,169 | ---- | C] () -- C:\Program Files (x86)\ENGLISH.FCT
[2011/11/01 19:46:41 | 000,006,036 | ---- | C] () -- C:\Program Files (x86)\FANCY.FNT
[2011/11/01 19:46:41 | 000,005,728 | ---- | C] () -- C:\Program Files (x86)\PICTS.FCW
[2011/11/01 19:46:41 | 000,005,712 | ---- | C] () -- C:\Program Files (x86)\HANDW.FNT
[2011/11/01 19:46:41 | 000,005,632 | ---- | C] () -- C:\Program Files (x86)\XPASAVE.DLL
[2011/11/01 19:46:41 | 000,005,484 | ---- | C] () -- C:\Program Files (x86)\LESSON9.FCW
[2011/11/01 19:46:41 | 000,005,356 | ---- | C] () -- C:\Program Files (x86)\FSTYLES.FCW
[2011/11/01 19:46:41 | 000,005,175 | ---- | C] () -- C:\Program Files (x86)\LESSON8.FCW
[2011/11/01 19:46:41 | 000,005,105 | ---- | C] () -- C:\Program Files (x86)\MYSYMBOL.FCW
[2011/11/01 19:46:41 | 000,005,083 | ---- | C] () -- C:\Program Files (x86)\LWIDTH2.FCW
[2011/11/01 19:46:41 | 000,005,083 | ---- | C] () -- C:\Program Files (x86)\LWIDTH1.FCW
[2011/11/01 19:46:41 | 000,004,996 | ---- | C] () -- C:\Program Files (x86)\SQUARE.FCW
[2011/11/01 19:46:41 | 000,004,994 | ---- | C] () -- C:\Program Files (x86)\PALABEL.FCW
[2011/11/01 19:46:41 | 000,004,749 | ---- | C] () -- C:\Program Files (x86)\LESSON10.FCW
[2011/11/01 19:46:41 | 000,004,349 | ---- | C] () -- C:\Program Files (x86)\HELV.FNT
[2011/11/01 19:46:41 | 000,004,306 | ---- | C] () -- C:\Program Files (x86)\SMOOTH.FNT
[2011/11/01 19:46:41 | 000,004,227 | ---- | C] () -- C:\Program Files (x86)\HELVNRW.FNT
[2011/11/01 19:46:41 | 000,003,695 | ---- | C] () -- C:\Program Files (x86)\SYMBOLS.GDE
[2011/11/01 19:46:41 | 000,003,660 | ---- | C] () -- C:\Program Files (x86)\SLANT.FNT
[2011/11/01 19:46:41 | 000,003,541 | ---- | C] () -- C:\Program Files (x86)\STDTEXT.FNT
[2011/11/01 19:46:41 | 000,003,263 | ---- | C] () -- C:\Program Files (x86)\FCW32.IMN
[2011/11/01 19:46:41 | 000,003,079 | ---- | C] () -- C:\Program Files (x86)\AGRID.FCW
[2011/11/01 19:46:41 | 000,002,841 | ---- | C] () -- C:\Program Files (x86)\521.GDE
[2011/11/01 19:46:41 | 000,002,748 | ---- | C] () -- C:\Program Files (x86)\FONTS.GDE
[2011/11/01 19:46:41 | 000,002,460 | ---- | C] () -- C:\Program Files (x86)\TGRID.FCW
[2011/11/01 19:46:41 | 000,002,382 | ---- | C] () -- C:\Program Files (x86)\PENTEST.FCW
[2011/11/01 19:46:41 | 000,001,266 | ---- | C] () -- C:\Program Files (x86)\FCW32.MAC
[2011/11/01 19:46:41 | 000,001,117 | ---- | C] () -- C:\Program Files (x86)\SOLAR.MNU
[2011/11/01 19:46:41 | 000,000,756 | ---- | C] () -- C:\Program Files (x86)\START.GDE
[2011/11/01 19:46:41 | 000,000,745 | ---- | C] () -- C:\Program Files (x86)\NEW60.GDE
[2011/11/01 19:46:41 | 000,000,745 | ---- | C] () -- C:\Program Files (x86)\NEW521.GDE
[2011/11/01 19:46:41 | 000,000,606 | ---- | C] () -- C:\Program Files (x86)\ACTDEMO.MAC
[2011/11/01 19:46:41 | 000,000,603 | ---- | C] () -- C:\Program Files (x86)\INDEX.GDE
[2011/11/01 19:46:41 | 000,000,399 | ---- | C] () -- C:\Program Files (x86)\INTRO.GDE
[2011/11/01 19:46:41 | 000,000,310 | ---- | C] () -- C:\Program Files (x86)\HAMMER.BMP
[2011/11/01 19:46:41 | 000,000,246 | ---- | C] () -- C:\Program Files (x86)\TILE.BMP
[2011/11/01 19:46:41 | 000,000,039 | ---- | C] () -- C:\Program Files (x86)\NEW.GDE
[2011/10/22 18:01:38 | 000,002,792 | ---- | C] () -- C:\Program Files\HP SimplePass 2011

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/25 21:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 20:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2014/02/13 13:22:14 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Audacity
[2011/11/01 19:01:41 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Blio
[2014/02/20 16:46:44 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\chc
[2011/11/05 16:25:51 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2011/11/13 16:34:58 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\CleanMyPC Software
[2013/08/30 13:40:55 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\com.adobe.DC3Module.AdobeADC
[2014/02/22 00:42:04 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Dashlane
[2014/02/26 16:19:46 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Dropbox
[2011/11/08 15:13:35 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Easy Duplicate Finder
[2012/11/14 11:05:52 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\EasyDuplicateFinder
[2011/11/04 19:52:00 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\EPSON
[2011/11/14 17:22:45 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Forte
[2013/05/05 13:19:12 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\GARMIN
[2011/11/06 13:19:05 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\HotSync
[2011/11/04 18:28:58 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Leadertech
[2011/11/06 11:54:27 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\NCH Swift Sound
[2011/11/19 10:20:21 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\proDAD
[2011/11/01 12:53:48 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Qualcomm
[2014/02/15 10:00:50 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\R-Wipe&Clean
[2011/12/01 15:53:11 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Softland
[2011/11/10 08:42:30 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2014/02/25 14:59:27 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\stickies
[2012/01/14 17:20:58 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\TechSmith
[2014/02/15 17:26:28 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\ThumbsPlus
[2011/11/01 16:51:56 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\WinBatch
[2013/03/26 08:57:36 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\ZinioReader4

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 198 bytes -> C:\ProgramData\Temp:21654C57
@Alternate Data Stream - 173 bytes -> C:\ProgramData\Temp:ECF54A0E

< End of report >
  • 0

Advertisements


#2
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts
Greetings,

Welcome to Geeks to Go--the friendliest online community dedicated to the sole goal of helping people from all around the world! :)

I am Pyxis and I will be assisting you with the problem at hand. Whilst I am taking the time to analyse your set of provided logs, I would like to stress the following reminders:

  • I am a student that is currently undergoing training. As such, my responses have to be checked by a professional before I present them to you to ensure you get the best quality help. If you deem I have overlooked your thread, which is in a matter of more than 24 hours, please send me a PM and I will get back to you shortly.
  • It is important that you do not install anything unless asked while the process is ongoing. Doing so may hinder or even complicate the cleaning of your system. You will get the chance to install things as you would like after the process has been completed.
  • Ensure you take extra caution to precisely follow my instructions. It is important that you only use the tools I have asked you to. The instructions for your computer are unique and should therefore only apply to your system.
I hope you keep in mind these reminders. I will be right back with a full response! :thumbsup:

Thank you.
  • 0

#3
vgphoto

vgphoto

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
In my request I stated that Malwarebytes Anti-Malware is clear. That is correct however when I first installed and run it found problems and I run the option to "fix" the problems and it did that successfully. Malwarebytes Anti-Malware runs with out error at this time. I have the Malwarebytes log that I could send to you if you want it.
vgphoto
  • 0

#4
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts

In my request I stated that Malwarebytes Anti-Malware is clear. That is correct however when I first installed and run it found problems and I run the option to "fix" the problems and it did that successfully. Malwarebytes Anti-Malware runs with out error at this time. I have the Malwarebytes log that I could send to you if you want it.
vgphoto

Since you say it came back clean, I have no need to see the log. :) On another note, may I ask if you created these tasks?

[2014/02/27 01:15:00 | 000,000,572 | ---- | M] () -- C:\Windows\tasks\b4a_Active Data.job
[2014/02/27 00:30:12 | 000,000,580 | ---- | M] () -- C:\Windows\tasks\b4a_Digital Current.job
[2014/02/26 18:06:47 | 000,000,580 | ---- | M] () -- C:\Windows\tasks\b4a_Scrapbook Scans.job
[2014/02/26 18:06:47 | 000,000,574 | ---- | M] () -- C:\Windows\tasks\b4a_Zphotol to O.job
[2014/02/26 18:06:47 | 000,000,574 | ---- | M] () -- C:\Windows\tasks\b4a_Weather data.job
[2014/02/26 18:06:47 | 000,000,574 | ---- | M] () -- C:\Windows\tasks\b4a_Glens Videos.job
[2014/02/26 18:06:47 | 000,000,568 | ---- | M] () -- C:\Windows\tasks\b4a_Favorites.job
[2014/02/26 18:06:47 | 000,000,558 | ---- | M] () -- C:\Windows\tasks\b4a_Other Photo.job
[2014/02/26 18:06:46 | 000,000,610 | ---- | M] () -- C:\Windows\tasks\b4a_Glens HP to Bank non Zphoto.job
[2014/02/26 18:06:46 | 000,000,596 | ---- | M] () -- C:\Windows\tasks\b4a_Photo to velma - Photos.job
[2014/02/26 18:06:46 | 000,000,590 | ---- | M] () -- C:\Windows\tasks\b4a_Mirror to X3 from TO.job

  • Step 1

    If you haven't already, download 'OTL by OldTimer' and save it to your desktop or move your existing copy into the said location.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.

    Posted Image

  • Copy and paste the following into the Custom Scans/Fixes box:

    :OTL
    IE:64bit: - HKLM\..\SearchScopes,DefaultScope = {6A1806CD-94D4-4689-BA73-E35EA1EA9990}
    IE:64bit: - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
    IE:64bit: - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.co...&l=dis&o=HPDTDF
    IE:64bit: - HKLM\..\SearchScopes\{3B83A2C8-E0A9-4604-A14C-E96435CD4D3A}: "URL" = http://www.amazon.co...s={searchTerms}
    IE:64bit: - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
    IE:64bit: - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo....psg&type=HPDTDF
    IE:64bit: - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia....h={searchTerms}
    IE:64bit: - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.co...w={searchTerms}
    IE - HKLM\..\SearchScopes,DefaultScope = {763CC174-CCD7-4972-8063-BEEEC2A8B7CE}
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
    IE - HKLM\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.co...&l=dis&o=HPDTDF
    IE - HKLM\..\SearchScopes\{3B83A2C8-E0A9-4604-A14C-E96435CD4D3A}: "URL" = http://www.amazon.co...s={searchTerms}
    IE - HKLM\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...g}&sourceid=ie7
    IE - HKLM\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo....psg&type=HPDTDF
    IE - HKLM\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia....h={searchTerms}
    IE - HKLM\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.co...w={searchTerms}
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar = Preserve
    IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.myway.com/
    IE - HKCU\..\SearchScopes,DefaultScope = {0633EE93-D776-472f-A0FF-E1416B8B2E3A}
    IE - HKCU\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
    IE - HKCU\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.co...&l=dis&o=HPDTDF
    IE - HKCU\..\SearchScopes\{3B83A2C8-E0A9-4604-A14C-E96435CD4D3A}: "URL" = http://www.amazon.co...s={searchTerms}
    IE - HKCU\..\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}: "URL" = http://www.google.co...1I7GGHP_enUS456
    IE - HKCU\..\SearchScopes\{9B97950D-482C-1D79-568F-FC7B9D40C785}: "URL" = http://www.bing.com/...eferrer:source}
    IE - HKCU\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo....psg&type=HPDTDF
    IE - HKCU\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia....h={searchTerms}
    IE - HKCU\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.co...w={searchTerms}
    IE - HKCU\..\SearchScopes\{EC23C1C8-47E1-22F0-FF5D-CD82BE4273C8}: "URL" = http://www.bing.com/...eferrer:source}
    O32 - AutoRun File - [2008/02/05 18:15:08 | 000,000,034 | ---- | M] () - H:\autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2011/01/18 16:12:59 | 000,000,067 | ---- | M] () - O:\Autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2009/05/07 07:35:55 | 000,000,063 | ---- | M] () - Q:\autorun.inf -- [ NTFS ]
    O32 - AutoRun File - [2011/01/18 16:15:03 | 000,000,062 | ---- | M] () - Z:\Autorun.inf -- [ NTFS ]
    [2014/02/06 12:12:46 | 000,000,000 | -H-D | C] -- C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}
    [2014/02/06 11:44:58 | 000,000,000 | -H-D | C] -- C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}
    [2011/11/13 16:34:58 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\CleanMyPC Software
    @Alternate Data Stream - 198 bytes -> C:\ProgramData\Temp:21654C57
    @Alternate Data Stream - 173 bytes -> C:\ProgramData\Temp:ECF54A0E
    
    :Commands
    [emptytemp]
    
  • Click Run Fix.
  • OTL will reboot your system. Allow it by clicking OK.
  • After the reboot, a Notepad window will appear, named MMDDYYYY_HHMMSS.log. Alternatively, you can find that log at C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log.
  • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log in your next reply.
  • Step 2

    Download 'AdwCleaner by Xplode' and save it to your desktop.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.
  • Click Scan and choose Clean after.
  • Wait for it to finish. It won't take long.
  • Click OK for the next prompts. Your system will automatically reboot.
  • A log will automatically pop-up after rebooting. Alternatively, you can find it at C:\AdwCleaner[S*].txt.
  • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log in your next reply.
  • Step 3

    Download 'Junkware Removal Tool by thisisu' and save it to your desktop.

  • Ensure all programs and windows are closed before proceeding.
  • Simply double-click the program icon to run it. It will ask for administrator privileges.
  • A black window will appear. Press any key to continue.
  • Wait for it to finish. It won't take long.
  • A log will automatically pop-up once done. Alternatively, you can find JRT.txt at your desktop.
  • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log in your next reply.
  • Step 4

    If you haven't already, download 'OTL by OldTimer' and save it to your desktop or move your existing copy into the said location.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.

    Posted Image

  • Copy and paste the following into the Custom Scans/Fixes box:

    netsvcs
    BASESERVICES
    %SYSTEMDRIVE%\*.exe
    dir "%systemdrive%\*" /S /A:L /C
    /md5start
    services.*
    explorer.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT
  • Click Run Scan.
  • Files are being searched and it may take some time. Once done, two Notepad windows will appear, named OTL.txt and Extras.txt. Alternatively, you can also find these at your desktop.
  • Copy and paste (CTRL + A and CTRL + C) the content of these logs in your next reply.
  • Logs to Post
In summary of the above, I will need you to post the following log(s):
  • MMDDYYYY_HHMMSS.log (OTL)
  • Extras.txt (OTL)
  • OTL.txt (OTL)
  • AdwCleaner[S*].txt (AdwCleaner)
  • JRT.txt (Junkware Removal Tool)

  • 0

#5
vgphoto

vgphoto

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
The jobs like " C:\Windows\tasks\b4a_Active Data.job" are my normal backup jobs using backup4all.


I went to Google Chrome to try to run step 3. Programs other than JTR.txt downloaded and installed
so I am unsure how to proceed. Guidance would be appreciated. Logr from IE error is at end of this post.


Step 1 Logs:

All processes killed
========== OTL ==========
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3B83A2C8-E0A9-4604-A14C-E96435CD4D3A}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3B83A2C8-E0A9-4604-A14C-E96435CD4D3A}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ not found.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ deleted successfully.
64bit-Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found.
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3B83A2C8-E0A9-4604-A14C-E96435CD4D3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3B83A2C8-E0A9-4604-A14C-E96435CD4D3A}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found.
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Search Bar| /E : value set successfully!
HKCU\SOFTWARE\Microsoft\Internet Explorer\Main\\Start Page| /E : value set successfully!
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{2fa28606-de77-4029-af96-b231e3b8f827}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{3B83A2C8-E0A9-4604-A14C-E96435CD4D3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{3B83A2C8-E0A9-4604-A14C-E96435CD4D3A}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{6A1806CD-94D4-4689-BA73-E35EA1EA9990}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{9B97950D-482C-1D79-568F-FC7B9D40C785}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{9B97950D-482C-1D79-568F-FC7B9D40C785}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{d43b3890-80c7-4010-a95d-1e77b5924dc3}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{D944BB61-2E34-4DBF-A683-47E505C587DC}\ not found.
Registry key HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{EC23C1C8-47E1-22F0-FF5D-CD82BE4273C8}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{EC23C1C8-47E1-22F0-FF5D-CD82BE4273C8}\ not found.
File H:\autorun.inf not found.
O:\Autorun.inf moved successfully.
Q:\autorun.inf moved successfully.
Z:\Autorun.inf moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\FBAC2176\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\FBAC2176 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\F68E9151\683C59A2 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\F68E9151 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\F335D458\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\F335D458 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\F2DC11F0\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\F2DC11F0 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\F1DB38CF\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\F1DB38CF folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\F08E467E\3F4CF927 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\F08E467E folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\EF146539\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\EF146539 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\EDBA807A\3F4CF927 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\EDBA807A folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\E85F5194\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\E85F5194 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\E787258F\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\E787258F folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\E1718587\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\E1718587 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\d_\projects\thumbsmisc\installaware\thumbs9\files folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\d_\projects\thumbsmisc\installaware\thumbs9 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\d_\projects\thumbsmisc\installaware folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\d_\projects\thumbsmisc folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\d_\projects folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\d_ folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\D2908FBD\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\D2908FBD folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\CE6062FD\683C59A2 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\CE6062FD folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\CA9D981E\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\CA9D981E folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\C7332E5B\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\C7332E5B folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\C69A1547\3F4CF927 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\C69A1547 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\C4D5AFEB\683C59A2 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\C4D5AFEB folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\C362B230\3F4CF927 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\C362B230 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\BF9C8840\2AE47C53 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\BF9C8840 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\BE0359EF\683C59A2 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\BE0359EF folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\B9B9353D\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\B9B9353D folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\B7CB2236\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\B7CB2236 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\B3C157CB\F75F72CB folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\B3C157CB\D5709F1 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\B3C157CB\71EDB832 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\B3C157CB\21224B63 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\B3C157CB\1A8C708A folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\B3C157CB folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\ADC08B5D\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\ADC08B5D folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\AA69CC\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\AA69CC folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\A5AE5F65\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\A5AE5F65 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\9DB8BD6C\3F4CF927 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\9DB8BD6C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\9CA0A1C7\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\9CA0A1C7 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\9C49E1F5\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\9C49E1F5 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\9C27DD05\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\9C27DD05 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\9A10DD6C\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\9A10DD6C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\91885412\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\91885412 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\9043BFB2\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\9043BFB2 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\8D70CC42\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\8D70CC42 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\8BE39878\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\8BE39878 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\8AA2AD1E\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\8AA2AD1E folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\84B04336\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\84B04336 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\7BCAF060\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\7BCAF060 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\7774A189\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\7774A189 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\72B203EF\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\72B203EF folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\72A9536F\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\72A9536F folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\70DF0967\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\70DF0967 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\6F386D40\EC86A5F0 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\6F386D40 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\69672983\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\69672983 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\64112CDF\683C59A2 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\64112CDF folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\6363A3BC\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\6363A3BC folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\602D8D1F\3F4CF927 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\602D8D1F folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\57F6D705\BA8BEB93 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\57F6D705 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\4C379099\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\4C379099 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\48BD6EA8\683C59A2 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\48BD6EA8 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\48B898BD\683C59A2 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\48B898BD folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\48AC8D95\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\48AC8D95 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\46FC7C86\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\46FC7C86 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\3464431B\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\3464431B folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\2BF09435\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\2BF09435 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\2B706DD6\683C59A2 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\2B706DD6 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\27083357\683C59A2 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\27083357 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\264B1BA4\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\264B1BA4 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\26211B30\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\26211B30 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\2171557A\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\2171557A folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\1E629B32\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\1E629B32 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\1C28D0B8\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\1C28D0B8 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\1B58A7E5\3F4CF927 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\1B58A7E5 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\19B30641\3347E48C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\19B30641 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\FBBE04DB folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\F85CEFAD folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\F5318BCC folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\F5184C50 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\F44D2225 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\F1D2D5DB folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\F056731E folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\ED9456D7 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\EB7FC07 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\E64B63F2 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\E50445D7 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\E1777231 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\DE777783 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\DA61717A folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\D95E62D4 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\D840E08E folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\D19CED94 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\CFD3368F folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\CB135037 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\C8CCD3FF folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\C33D1B60 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\C0E84677 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\BB66C1BE folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\BA7908D4 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\B4431D44 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\B0A6503 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\B080483F folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\AB6DB9D5 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\A95067F1 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\A431F3AB folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\A2022901 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\99B54B7C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\984C5AB5 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\9393681D folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\928AF095 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\91130AAE folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\8C1AE14F folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\854A77BC folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\8056E097 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\7CAB0D2C folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\79491E5E folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\75572AD9 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\74B7F406 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\6E073DF3 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\6A178D0E folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\696CAD48 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\69289D4B folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\6001A2DE folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\56FFEC53 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\4DD2D6C2 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\4A49016B folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\4A0B60C5 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\454087C1 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\4423FC86 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\4110B730 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\3BA7AD0A folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\3AD30103 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\309FF8CB folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\2F98DB20 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\2A2700FF folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\27BEF0E1 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\1EBF1F1 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\18C60B03 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\16FEB468 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\161B96E folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\126FED65 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17\101D00D2 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE\12DA2C17 folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631}\OFFLINE folder moved successfully.
C:\Users\Glens\AppData\Local\{92F6014A-50F3-4BAB-B448-C57462950631} folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\FBAC2176\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\FBAC2176 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\F68E9151\683C59A2 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\F68E9151 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\F335D458\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\F335D458 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\F2DC11F0\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\F2DC11F0 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\F1DB38CF\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\F1DB38CF folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\F08E467E\3F4CF927 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\F08E467E folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\EF146539\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\EF146539 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\EDBA807A\3F4CF927 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\EDBA807A folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\E85F5194\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\E85F5194 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\E787258F\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\E787258F folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\E1718587\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\E1718587 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\d_\projects\thumbsmisc\installaware\thumbs9\files folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\d_\projects\thumbsmisc\installaware\thumbs9 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\d_\projects\thumbsmisc\installaware folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\d_\projects\thumbsmisc folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\d_\projects folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\d_ folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\D2908FBD\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\D2908FBD folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\CE6062FD\683C59A2 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\CE6062FD folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\CA9D981E\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\CA9D981E folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\C7332E5B\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\C7332E5B folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\C69A1547\3F4CF927 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\C69A1547 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\C4D5AFEB\683C59A2 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\C4D5AFEB folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\C362B230\3F4CF927 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\C362B230 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\BF9C8840\2AE47C53 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\BF9C8840 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\BE0359EF\683C59A2 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\BE0359EF folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\B9B9353D\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\B9B9353D folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\B7CB2236\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\B7CB2236 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\B3C157CB\F75F72CB folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\B3C157CB\D5709F1 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\B3C157CB\71EDB832 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\B3C157CB\21224B63 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\B3C157CB\1A8C708A folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\B3C157CB folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\ADC08B5D\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\ADC08B5D folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\AA69CC\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\AA69CC folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\A5AE5F65\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\A5AE5F65 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\9DB8BD6C\3F4CF927 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\9DB8BD6C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\9CA0A1C7\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\9CA0A1C7 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\9C49E1F5\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\9C49E1F5 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\9C27DD05\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\9C27DD05 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\9A10DD6C\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\9A10DD6C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\91885412\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\91885412 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\9043BFB2\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\9043BFB2 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\8D70CC42\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\8D70CC42 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\8BE39878\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\8BE39878 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\8AA2AD1E\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\8AA2AD1E folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\84B04336\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\84B04336 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\7BCAF060\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\7BCAF060 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\7774A189\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\7774A189 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\76BA49A1\3F4CF927 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\76BA49A1 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\72B203EF\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\72B203EF folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\72A9536F\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\72A9536F folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\70DF0967\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\70DF0967 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\6F386D40\EC86A5F0 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\6F386D40 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\69672983\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\69672983 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\64112CDF\683C59A2 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\64112CDF folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\6363A3BC\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\6363A3BC folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\602D8D1F\3F4CF927 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\602D8D1F folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\57F6D705\BA8BEB93 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\57F6D705 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\4C379099\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\4C379099 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\48BD6EA8\683C59A2 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\48BD6EA8 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\48B898BD\683C59A2 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\48B898BD folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\48AC8D95\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\48AC8D95 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\46FC7C86\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\46FC7C86 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\3464431B\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\3464431B folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\2BF09435\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\2BF09435 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\2B706DD6\683C59A2 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\2B706DD6 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\27083357\683C59A2 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\27083357 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\264B1BA4\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\264B1BA4 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\26211B30\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\26211B30 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\2171557A\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\2171557A folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\1E629B32\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\1E629B32 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\1C28D0B8\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\1C28D0B8 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\1B58A7E5\3F4CF927 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\1B58A7E5 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\19B30641\3347E48C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\19B30641 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\FBBE04DB folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\F85CEFAD folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\F5318BCC folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\F5184C50 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\F44D2225 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\F1D2D5DB folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\F056731E folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\ED9456D7 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\EB7FC07 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\E64B63F2 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\E50445D7 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\E1777231 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\DE777783 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\DA61717A folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\D95E62D4 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\D840E08E folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\D19CED94 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\CFD3368F folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\CB135037 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\C8CCD3FF folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\C33D1B60 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\C0E84677 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\BB66C1BE folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\BA7908D4 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\B4431D44 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\B0A6503 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\B080483F folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\AB6DB9D5 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\A95067F1 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\A431F3AB folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\A2022901 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\99B54B7C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\984C5AB5 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\9393681D folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\928AF095 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\91130AAE folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\8C1AE14F folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\854A77BC folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\8056E097 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\7CAB0D2C folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\79491E5E folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\75572AD9 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\74B7F406 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\6E073DF3 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\6A178D0E folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\696CAD48 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\69289D4B folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\6001A2DE folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\56FFEC53 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\4DD2D6C2 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\4A49016B folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\4A0B60C5 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\454087C1 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\4423FC86 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\4110B730 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\3BA7AD0A folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\3AD30103 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\309FF8CB folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\2F98DB20 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\2A2700FF folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\27BEF0E1 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\1EBF1F1 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\18C60B03 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\16FEB468 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\161B96E folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\126FED65 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17\101D00D2 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE\12DA2C17 folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B}\OFFLINE folder moved successfully.
C:\ProgramData\{771662D7-1083-4A59-B2C6-63C087C1F79B} folder moved successfully.
C:\Users\Glens\AppData\Roaming\CleanMyPC Software\CleanMyPC Registry Cleaner\UndoCenter folder moved successfully.
C:\Users\Glens\AppData\Roaming\CleanMyPC Software\CleanMyPC Registry Cleaner folder moved successfully.
C:\Users\Glens\AppData\Roaming\CleanMyPC Software folder moved successfully.
ADS C:\ProgramData\Temp:21654C57 deleted successfully.
ADS C:\ProgramData\Temp:ECF54A0E deleted successfully.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 57472 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Glens
->Temp folder emptied: 612186523 bytes
->Temporary Internet Files folder emptied: 410066087 bytes
->Java cache emptied: 597753 bytes
->Google Chrome cache emptied: 54085021 bytes
->Flash cache emptied: 58089 bytes

User: Public

User: TEMP

User: Test Account

User: Test Share - Anna

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 56475 bytes

%systemdrive% .tmp files removed: 621042 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 10544970 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 42321176 bytes
RecycleBin emptied: 0 bytes

Total Files Cleaned = 1,078.00 mb


OTL by OldTimer - Version 3.2.69.0 log created on 03022014_171735

Files\Folders moved on Reboot...
C:\Users\Glens\AppData\Local\Temp\VBE\MSForms.exd moved successfully.
C:\Users\Glens\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Users\Glens\AppData\Local\Temp\~DF07758126E5494FBA.TMP not found!
File\Folder C:\Users\Glens\AppData\Local\Temp\~DF12DE232B1CCA980D.TMP not found!
File\Folder C:\Users\Glens\AppData\Local\Temp\~DFA817A92DBD8DF0FA.TMP not found!
File\Folder C:\Users\Glens\AppData\Local\Temp\~DFB20D54A625E30011.TMP not found!
File\Folder C:\Users\Glens\AppData\Local\Temp\~DFDF8729C23C75703A.TMP not found!
File\Folder C:\Users\Glens\AppData\Local\Temp\~DFE3391317F2521AC7.TMP not found!
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\SH9VB4XY\ads[1].htm moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N86LOICL\1R14TXW3.htm moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N86LOICL\gca_iframe[1].htm moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N86LOICL\page__pid__2378290[1].htm moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N86LOICL\push[1].htm moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N86LOICL\request_ad[1].htm moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N86LOICL\si[1].htm moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\N86LOICL\zrt_lookup[1].htm moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MIA8SUW4\ads[1].htm moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MIA8SUW4\si[1].htm moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\MIA8SUW4\zrt_lookup[1].htm moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\B4K6WD1I\si[1].htm moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\4A72F430-B40C-4D36-A068-CE33ADA5ADF9.dat moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\MSIMGSIZ.DAT moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{B3B24C9D-4BA6-4E2E-B710-400FABEF404C}.tmp moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{446E0182-F9C7-4092-A55B-36984A31D2D4}.tmp moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{4C280E72-D803-4DAA-B927-CD9978CF3C67}.tmp moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{4E91E466-B04C-4863-8F6E-B93E15D36E71}.tmp moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{8031F262-4873-4E62-B185-83C499E7FB7B}.tmp moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{FFCB97E1-6C7B-44D5-8204-F118FF63A208}.tmp moved successfully.
File move failed. C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat scheduled to be moved on reboot.
C:\Windows\temp\wbxtra_02272014_163107.wbt moved successfully.
C:\Windows\SysNative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Step 2 Log

# AdwCleaner v3.020 - Report created 02/03/2014 at 18:00:30
# Updated 27/02/2014 by Xplode
# Operating System : Windows 7 Professional Service Pack 1 (64 bits)
# Username : Glens - GLENS-HP
# Running from : C:\Users\Glens\Downloads\AdwCleaner.exe
# Option : Clean

***** [ Services ] *****


***** [ Files / Folders ] *****

Folder Deleted : C:\ProgramData\Ask
Folder Deleted : C:\ProgramData\blekko toolbars
Folder Deleted : C:\ProgramData\Conduit
[x] Not Deleted : C:\ProgramData\NCH Software
Folder Deleted : C:\Program Files (x86)\MyPC Backup
[x] Not Deleted : C:\Program Files (x86)\NCH Software
Folder Deleted : C:\Program Files (x86)\Toolbar Cleaner
Folder Deleted : C:\Users\Glens\AppData\Local\Conduit
Folder Deleted : C:\Users\Glens\AppData\Local\NativeMessaging
Folder Deleted : C:\Users\Glens\AppData\Local\PackageAware
Folder Deleted : C:\Users\Glens\AppData\Local\WhiteListing
Folder Deleted : C:\Users\Glens\AppData\LocalLow\Conduit
Folder Deleted : C:\Users\Glens\AppData\LocalLow\PriceGong
[x] Not Deleted : C:\Users\Glens\AppData\Roaming\NCH Software
Folder Deleted : C:\Users\Glens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\BrowserDefender
File Deleted : C:\END
[x] Not Deleted : C:\Windows\System32\Tasks\NCH Software

***** [ Shortcuts ] *****


***** [ Registry ] *****

Key Deleted : HKLM\SOFTWARE\Classes\AppID\BHO.DLL
Key Deleted : HKLM\SOFTWARE\Classes\Applications\ilividsetup.exe
Key Deleted : HKLM\SOFTWARE\Classes\Prod.cap
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\adawarebp_rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\adawarebp_rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\apnstub_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\AskInstallChecker-1_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasapi32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\au__rasmancs
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\BingBar_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\HPSF_Tasks_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLivid_RASMANCS
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASAPI32
Key Deleted : HKLM\SOFTWARE\Microsoft\Tracing\iLividSetup_RASMANCS
Key Deleted : HKCU\Software\e5388d9e735e917
Key Deleted : HKLM\SOFTWARE\e5388d9e735e917
Key Deleted : HKLM\SOFTWARE\Classes\AppID\{0A18A436-2A7A-49F3-A488-30538A2F6323}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{007EFBDF-8A5D-4930-97CC-A4B437CBA777}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{42D79B50-CC4A-4A8E-860F-BE674AF053A2}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{6C97A91E-4524-4019-86AF-2AA2D567BF5C}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{DE9028D0-5FFA-4E69-94E3-89EE8741F468}
Key Deleted : HKLM\SOFTWARE\Classes\CLSID\{E7DF6BFF-55A5-4EB7-A673-4ED3E9456D39}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60}
Key Deleted : HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{9C049BA6-EA47-4AC3-AED6-A66D8DC9E1D8}
Key Deleted : HKLM\SOFTWARE\Classes\TypeLib\{FEB62B15-CC00-4736-AAEC-BA046C9DFF73}
Key Deleted : HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{42D79B50-CC4A-4A8E-860F-BE674AF053A2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{42D79B50-CC4A-4A8E-860F-BE674AF053A2}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{F25AF245-4A81-40DC-92F9-E9021F207706}
Key Deleted : HKCU\Software\Microsoft\Windows\CurrentVersion\Ext\Settings\{42D79B50-CC4A-4A8E-860F-BE674AF053A2}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{03E2A1F3-4402-4121-8B35-733216D61217}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1C888195-0160-4883-91B7-294C0CE2F277}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{1F8EDE97-36D5-422A-B8F0-9406E2D87C60}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{4E92DB5F-AAD9-49D3-8EAB-B40CBE5B1FF7}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{99ACA0F7-D864-45CB-8C40-FD42A077E7CA}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{9E3B11F6-4179-4603-A71B-A55F4BCB0BEC}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{C401D2CE-DC27-45C7-BC0C-8E6EA7F085D6}
Key Deleted : [x64] HKLM\SOFTWARE\Classes\Interface\{D54C859C-6066-4F31-8FE0-2AAEDCAE67D7}
Key Deleted : HKCU\Software\APN PIP
Key Deleted : HKCU\Software\BabSolution
Key Deleted : HKCU\Software\Conduit
Key Deleted : HKCU\Software\ilivid
Key Deleted : HKCU\Software\InstalledThirdPartyPrograms
Key Deleted : HKCU\Software\NCH Software
Key Deleted : HKCU\Software\PIP
Key Deleted : HKCU\Software\Zugo
Key Deleted : HKCU\Software\AppDataLow\Software\Conduit
Key Deleted : HKCU\Software\AppDataLow\Software\ConduitSearchScopes
Key Deleted : HKLM\Software\Babylon
Key Deleted : HKLM\Software\Conduit
Key Deleted : HKLM\Software\DataMngr
Key Deleted : HKLM\Software\NCH Software
Key Deleted : HKLM\Software\PIP
Key Deleted : HKLM\Software\Toolbar Cleaner
Key Deleted : [x64] HKLM\SOFTWARE\InstalledThirdPartyPrograms

***** [ Browsers ] *****

-\\ Internet Explorer v11.0.9600.16518


-\\ Google Chrome v33.0.1750.117

[ File : C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\preferences ]


*************************

AdwCleaner[R0].txt - [5972 octets] - [02/03/2014 17:55:17]
AdwCleaner[S0].txt - [5698 octets] - [02/03/2014 18:00:30]

########## EOF - C:\AdwCleaner\AdwCleaner[S0].txt - [5758 octets] ##########

We were not successful running step 3.
At the end of step 2 IE 11 failed to start with the following error:
Application Timestamp: 52f347b2
Fault Module Name: KWIEBar.dll
Fault Module Version: 2.4.0.56656
Fault Module Timestamp: 5303c818
Exception Code: c0000005
Exception Offset: 00002f92
OS Version: 6.1.7601.2.1.0.256.48
Locale ID: 1033
Additional Information 1: 0a9e
Additional Information 2: 0a9e372d3b4ad19135b953a78882e789
Additional Information 3: 0a9e
Additional Information 4: 0a9e372d3b4ad19135b953a78882e789
  • 0

#6
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts

I went to Google Chrome to try to run step 3. Programs other than JTR.txt downloaded and installed
so I am unsure how to proceed. Guidance would be appreciated. Logr from IE error is at end of this post.

I see. Kindly follow the below steps instead.

  • Step 1

    Locate your copy of 'OTL by OldTimer'.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.

    Posted Image

  • Copy and paste the following into the Custom Scans/Fixes box:

    :OTL
    O2 - BHO: (Dashlane BHO) - {42D79B50-CC4A-4A8E-860F-BE674AF053A2} - C:\Users\Glens\AppData\Roaming\Dashlane\ie\Dashlanei.dll (Dashlane)
    O3 - HKLM\..\Toolbar: (Dashlane Toolbar) - {669695BC-A811-4A9D-8CDF-BA8C795F261C} - C:\Users\Glens\AppData\Roaming\Dashlane\ie\KWIEBar.dll (Dashlane)
    
    
  • Click Run Fix.
  • After, a Notepad window will appear, named MMDDYYYY_HHMMSS.log. Alternatively, you can find that log at C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log.
  • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log in your next reply.
  • Step 2

    Download 'Junkware Removal Tool by thisisu' and save it to your desktop.

  • Ensure all programs and windows are closed before proceeding.
  • Simply double-click the program icon to run it. It will ask for administrator privileges.
  • A black window will appear. Press any key to continue.
  • Wait for it to finish. It won't take long.
  • A log will automatically pop-up once done. Alternatively, you can find JRT.txt at your desktop.
  • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log in your next reply.
  • Step 3

    Locate your copy of 'OTL by OldTimer'.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.

    Posted Image

  • Copy and paste the following into the Custom Scans/Fixes box:

    netsvcs
    BASESERVICES
    %SYSTEMDRIVE%\*.exe
    dir "%systemdrive%\*" /S /A:L /C
    /md5start
    services.*
    explorer.exe
    Userinit.exe
    svchost.exe
    /md5stop
    CREATERESTOREPOINT
  • Click Run Scan.
  • Files are being searched and it may take some time. Once done, two Notepad windows will appear, named OTL.txt and Extras.txt. Alternatively, you can also find these at your desktop.
  • Copy and paste (CTRL + A and CTRL + C) the content of these logs in your next reply.
  • Logs to Post
In summary of the above, I will need you to post the following log(s):
  • MMDDYYYY_HHMMSS.log (OTL)
  • Extras.txt (OTL)
  • OTL.txt (OTL)
  • JRT.txt (Junkware Removal Tool)

  • 0

#7
vgphoto

vgphoto

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
log from step 1:

========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{42D79B50-CC4A-4A8E-860F-BE674AF053A2}\ not found.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{42D79B50-CC4A-4A8E-860F-BE674AF053A2}\ not found.
C:\Users\Glens\AppData\Roaming\Dashlane\ie\Dashlanei.dll moved successfully.
Registry value HKEY_LOCAL_MACHINE\Software\Microsoft\Internet Explorer\Toolbar\\{669695BC-A811-4A9D-8CDF-BA8C795F261C} deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{669695BC-A811-4A9D-8CDF-BA8C795F261C}\ deleted successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\ie\KWIEBar.dll moved successfully.

OTL by OldTimer - Version 3.2.69.0 log created on 03032014_140012

Log from step 2:

~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Junkware Removal Tool (JRT) by Thisisu
Version: 6.1.2 (02.20.2014:1)
OS: Windows 7 Professional x64
Ran by Glens on Mon 03/03/2014 at 14:07:49.05
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~




~~~ Services

Successfully stopped: [Service] cltmngsvc
Successfully deleted: [Service] cltmngsvc



~~~ Registry Values

Successfully repaired: [Registry Value] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_DLLs
Successfully repaired: [Registry Value] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\.DEFAULT\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-18\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-19\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-20\Software\Microsoft\Internet Explorer\Main\\Start Page
Successfully repaired: [Registry Value] HKEY_USERS\S-1-5-21-3563443419-2258996029-2686041776-1001\Software\Microsoft\Internet Explorer\Main\\Start Page



~~~ Registry Keys

Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{1AA60054-57D9-4F99-9A55-D0FBFBE7ECD3}
Successfully deleted: [Registry Key] HKEY_CLASSES_ROOT\CLSID\{4AA46D49-459F-4358-B4D1-169048547C23}
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\searchprotect
Successfully deleted: [Registry Key] HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Uninstall\searchprotect
Successfully deleted: [Registry Key] HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\SearchScopes\{014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}



~~~ Files



~~~ Folders

Successfully deleted: [Folder] "C:\Users\Glens\appdata\local\cre"
Successfully deleted: [Folder] "C:\Users\Glens\appdata\local\searchprotect"
Successfully deleted: [Folder] "C:\Program Files (x86)\searchprotect"



~~~ Event Viewer Logs were cleared





~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Scan was completed on Mon 03/03/2014 at 14:12:54.27
End of JRT log
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~

Log from Step 3:

OTL logfile created on: 3/3/2014 2:19:10 PM - Run 2
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Glens\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

15.98 Gb Total Physical Memory | 12.93 Gb Available Physical Memory | 80.88% Memory free
31.96 Gb Paging File | 27.36 Gb Available in Paging File | 85.60% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1385.03 Gb Total Space | 794.76 Gb Free Space | 57.38% Space Free | Partition Type: NTFS
Drive D: | 12.13 Gb Total Space | 1.49 Gb Free Space | 12.26% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 189.21 Gb Free Space | 40.62% Space Free | Partition Type: NTFS
Drive O: | 931.51 Gb Total Space | 197.14 Gb Free Space | 21.16% Space Free | Partition Type: NTFS
Drive P: | 298.09 Gb Total Space | 71.58 Gb Free Space | 24.01% Space Free | Partition Type: NTFS
Drive Q: | 465.76 Gb Total Space | 93.60 Gb Free Space | 20.10% Space Free | Partition Type: NTFS
Drive R: | 596.17 Gb Total Space | 285.03 Gb Free Space | 47.81% Space Free | Partition Type: NTFS
Drive Y: | 298.09 Gb Total Space | 69.13 Gb Free Space | 23.19% Space Free | Partition Type: NTFS
Drive Z: | 931.51 Gb Total Space | 522.24 Gb Free Space | 56.06% Space Free | Partition Type: NTFS

Computer Name: GLENS-HP | User Name: Glens | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: Current user | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2014/02/27 11:07:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Glens\Desktop\OTL.exe
PRC - [2014/02/22 14:07:12 | 001,134,592 | ---- | M] (Zhorn Software) -- C:\Program Files (x86)\Stickies\stickies.exe
PRC - [2014/02/20 17:55:04 | 000,118,056 | ---- | M] (Cisco WebEx LLC) -- C:\Windows\SysWOW64\atashost.exe
PRC - [2014/02/19 20:03:06 | 000,859,464 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Chrome\Application\chrome.exe
PRC - [2014/02/18 15:54:54 | 000,219,832 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\Dashlane.exe
PRC - [2014/02/15 14:45:38 | 000,223,112 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe
PRC - [2014/02/11 15:05:14 | 000,395,120 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
PRC - [2014/02/11 10:54:18 | 002,239,376 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
PRC - [2014/01/15 11:02:16 | 004,697,456 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncV1\CoreSync.exe
PRC - [2014/01/02 19:46:10 | 030,714,328 | ---- | M] (Dropbox, Inc.) -- C:\Users\Glens\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013/12/18 13:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/12/13 05:16:54 | 000,769,904 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
PRC - [2013/11/08 15:14:26 | 000,250,712 | ---- | M] (Garmin Ltd or its subsidiaries) -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe
PRC - [2013/10/08 07:28:15 | 000,275,696 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
PRC - [2013/09/03 08:33:53 | 003,233,806 | ---- | M] () -- C:\Program Files (x86)\Tor\tor.exe
PRC - [2013/04/24 04:30:28 | 000,483,864 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
PRC - [2013/04/24 04:26:56 | 000,740,888 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
PRC - [2013/03/15 00:53:06 | 001,266,464 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2013/03/14 21:07:46 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/06/09 07:37:18 | 000,264,008 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
PRC - [2011/06/09 07:37:00 | 000,653,128 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
PRC - [2011/06/09 07:36:34 | 000,142,664 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
PRC - [2011/02/24 02:10:24 | 000,212,944 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
PRC - [2011/02/01 02:41:24 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2011/02/01 02:41:20 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/11/26 09:09:12 | 000,399,344 | ---- | M] (Roxio) -- C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
PRC - [2010/08/24 16:56:14 | 000,608,528 | ---- | M] (TiVo Inc.) -- C:\Program Files (x86)\TiVo\Desktop\TiVoTransfer.exe
PRC - [2010/08/24 16:56:12 | 002,264,336 | ---- | M] (TiVo Inc.) -- C:\Program Files (x86)\TiVo\Desktop\TiVoServer.exe
PRC - [2010/08/24 16:56:10 | 000,437,520 | ---- | M] (TiVo Inc.) -- C:\Program Files (x86)\TiVo\Desktop\TiVoNotify.exe
PRC - [2010/08/24 16:56:04 | 001,104,656 | ---- | M] (TiVo Inc.) -- C:\Program Files (x86)\TiVo\Desktop\TiVoBeacon.exe
PRC - [2010/02/18 16:01:06 | 000,462,632 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2008/11/20 12:47:28 | 000,062,768 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
PRC - [2008/04/17 05:33:14 | 000,181,544 | ---- | M] (Seagate Technology LLC) -- C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe
PRC - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe
PRC - [2006/10/12 15:57:08 | 000,102,400 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\EPSON\Creativity Suite\Event Manager\EEventManager.exe


========== Modules (No Company Name) ==========

MOD - [2014/02/22 14:07:11 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Stickies\shook70.dll
MOD - [2014/02/19 20:03:05 | 000,394,568 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ppgooglenaclpluginchrome.dll
MOD - [2014/02/19 20:03:03 | 004,060,488 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\pdf.dll
MOD - [2014/02/19 20:02:59 | 000,716,616 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\libglesv2.dll
MOD - [2014/02/19 20:02:58 | 000,100,168 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\libegl.dll
MOD - [2014/02/19 20:02:56 | 001,647,432 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\ffmpegsumo.dll
MOD - [2014/02/19 20:02:54 | 000,051,016 | ---- | M] () -- C:\Program Files (x86)\Google\Chrome\Application\33.0.1750.117\chrome_elf.dll
MOD - [2014/02/18 15:54:54 | 000,219,832 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\Dashlane.exe
MOD - [2014/02/18 15:54:02 | 000,423,096 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWUtils.2.4.0.56656.dll
MOD - [2014/02/18 15:54:02 | 000,263,352 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWMainLib_win.2.4.0.56656.dll
MOD - [2014/02/18 15:53:54 | 028,197,904 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWExternLib.2.4.0.56656.dll
MOD - [2014/02/18 15:53:54 | 000,254,648 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebugDll_win32.2.4.0.56656.dll
MOD - [2014/02/18 15:53:52 | 004,799,160 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWData.2.4.0.56656.dll
MOD - [2014/02/18 15:53:52 | 004,306,616 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWApplication.2.4.0.56656.dll
MOD - [2014/02/18 15:53:52 | 000,360,976 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components\KWDebug.2.4.0.56656.dll
MOD - [2014/02/11 15:09:42 | 032,733,080 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll
MOD - [2014/02/11 15:09:38 | 000,742,808 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libGLESv2.dll
MOD - [2014/02/11 15:09:38 | 000,136,600 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libEGL.dll
MOD - [2014/01/15 11:02:16 | 004,697,456 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncV1\CoreSync.exe
MOD - [2014/01/02 19:45:04 | 003,558,400 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2013/10/18 18:55:02 | 025,100,288 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2011/09/27 10:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 10:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/08/24 16:55:58 | 000,050,960 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\Plus\TranscodingServicePS.dll
MOD - [2010/08/24 16:34:24 | 000,259,584 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\Id3Lib.dll
MOD - [2010/05/17 21:56:22 | 000,684,032 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\LibEay32.dll
MOD - [2010/05/17 21:56:22 | 000,155,648 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\SslEay32.dll
MOD - [2010/05/17 21:54:54 | 000,716,800 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\loudmouth.dll
MOD - [2003/01/30 06:04:00 | 000,618,496 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\StlpMt45.dll


========== Services (SafeList) ==========

SRV:64bit: - [2014/02/06 05:48:45 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/10/10 17:54:28 | 000,144,152 | ---- | M] (SUPERAntiSpyware.com) [Auto | Running] -- C:\Program Files\SUPERAntiSpyware\SASCore64.exe -- (!SASCORE)
SRV:64bit: - [2013/05/27 00:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/04/24 19:38:30 | 000,318,464 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)
SRV:64bit: - [2011/09/27 14:04:08 | 000,359,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2011/03/25 19:19:08 | 000,956,192 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2010/10/13 11:41:06 | 000,487,280 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_TouchService.exe -- (TouchServicePen)
SRV:64bit: - [2010/10/13 11:41:04 | 005,790,064 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_Tablet.exe -- (TabletServicePen)
SRV:64bit: - [2010/10/11 04:48:14 | 000,346,168 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe -- (HPClientSvc)
SRV:64bit: - [2010/09/22 20:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/09/14 00:00:00 | 000,128,512 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE -- (EPSON_PM_RPCV4_04)
SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009/03/02 17:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\IDT\WDM\AESTSr64.exe -- (AESTFilters)
SRV - [2014/02/27 15:06:48 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/02/26 00:18:56 | 000,111,912 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\EnhanceTronic\updateEnhanceTronic.exe -- (Update EnhanceTronic)
SRV - [2014/02/20 17:55:04 | 000,118,056 | ---- | M] (Cisco WebEx LLC) [Auto | Running] -- C:\Windows\SysWOW64\atashost.exe -- (atashost)
SRV - [2013/12/18 13:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/11/08 15:14:26 | 000,250,712 | ---- | M] (Garmin Ltd or its subsidiaries) [Auto | Running] -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe -- (Garmin Core Update Service)
SRV - [2013/11/04 18:31:56 | 000,092,160 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)
SRV - [2013/10/08 07:28:15 | 000,275,696 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe -- (NIS)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/09/03 08:33:53 | 003,233,806 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Tor\tor.exe -- (tor)
SRV - [2013/04/24 04:30:28 | 000,483,864 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2013/03/15 00:53:06 | 001,266,464 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2013/03/14 21:07:46 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/06/09 07:37:18 | 000,264,008 | ---- | M] (HP) [Auto | Running] -- C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe -- (FPLService)
SRV - [2011/02/24 02:10:24 | 000,212,944 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe -- (jhi_service)
SRV - [2011/02/01 02:41:24 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/02/01 02:41:20 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/11/26 09:09:12 | 000,399,344 | ---- | M] (Roxio) [Auto | Running] -- C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe -- (RoxioNow Service)
SRV - [2010/10/12 12:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/08/24 16:56:04 | 001,104,656 | ---- | M] (TiVo Inc.) [Auto | Running] -- C:\Program Files (x86)\TiVo\Desktop\TiVoBeacon.exe -- (TivoBeacon2)
SRV - [2010/06/01 17:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010/02/19 15:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/02/18 16:01:06 | 000,462,632 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/04/17 05:33:14 | 000,181,544 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe -- (Maxtor Sync Service)
SRV - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/11/13 11:27:51 | 000,177,752 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2013/10/01 21:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013/09/26 22:18:30 | 001,147,480 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\SymEFA64.sys -- (SymEFA)
DRV:64bit: - [2013/09/26 21:45:56 | 000,264,280 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\Ironx64.sys -- (SymIRON)
DRV:64bit: - [2013/09/26 21:26:03 | 000,858,200 | R--- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2013/09/25 22:28:00 | 000,590,936 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\symnets.sys -- (SymNetS)
DRV:64bit: - [2013/09/25 21:50:25 | 000,162,392 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\ccSetx64.sys -- (ccSet_NIS)
DRV:64bit: - [2013/09/09 21:47:43 | 000,078,936 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SymIMV.sys -- (SymIM)
DRV:64bit: - [2013/09/09 21:47:26 | 000,493,656 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\SymDS64.sys -- (SymDS)
DRV:64bit: - [2013/09/09 20:49:49 | 000,036,952 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\srtspx64.sys -- (SRTSPX)
DRV:64bit: - [2012/12/19 00:41:52 | 000,194,488 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2012/12/13 14:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/08/23 09:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 09:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/08/13 20:36:38 | 000,013,120 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rcmirror64.sys -- (rcmirror)
DRV:64bit: - [2012/05/29 14:53:30 | 000,027,456 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cpqdfw.sys -- (CpqDfw)
DRV:64bit: - [2012/04/24 19:38:30 | 000,536,576 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/12/01 18:04:01 | 000,828,912 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2011/10/22 18:00:57 | 000,031,152 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pmxdrv.sys -- (pmxdrv)
DRV:64bit: - [2011/10/22 17:39:58 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/10/22 17:39:58 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/09/02 01:30:36 | 000,060,696 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2011/09/02 01:30:24 | 000,076,056 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LEqdUsb.sys -- (LEqdUsb)
DRV:64bit: - [2011/09/02 01:30:24 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2011/09/02 01:30:24 | 000,015,128 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidEqd.sys -- (LHidEqd)
DRV:64bit: - [2011/07/22 11:26:56 | 000,014,928 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\sasdifsv64.sys -- (SASDIFSV)
DRV:64bit: - [2011/07/12 16:55:18 | 000,012,368 | ---- | M] (SUPERAdBlocker.com and SUPERAntiSpyware.com) [Kernel | System | Running] -- C:\Program Files\SUPERAntiSpyware\saskutil64.sys -- (SASKUTIL)
DRV:64bit: - [2011/05/16 13:55:28 | 000,533,096 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/04/26 14:07:36 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/04/20 18:07:22 | 000,399,944 | ---- | M] (Texas Instruments Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tixhci.sys -- (tixhci)
DRV:64bit: - [2011/04/20 18:07:22 | 000,131,656 | ---- | M] (Texas Instruments Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tihub3.sys -- (tihub3)
DRV:64bit: - [2011/04/05 16:29:58 | 000,066,552 | ---- | M] (PalmSource, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AceecaUSBDx64.sys -- (AceecaUSBDx64)
DRV:64bit: - [2011/03/25 21:21:10 | 000,349,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (BTWAMPFL)
DRV:64bit: - [2011/03/25 21:21:06 | 000,138,280 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2011/03/25 21:21:06 | 000,107,560 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2011/03/25 21:21:06 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2011/03/25 21:21:06 | 000,021,416 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010/11/20 22:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/20 22:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/10/19 06:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010/10/05 13:26:10 | 000,018,288 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV:64bit: - [2010/10/05 13:26:02 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV:64bit: - [2010/10/05 13:26:00 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomvhid.sys -- (wacomvhid)
DRV:64bit: - [2010/03/22 22:39:20 | 003,060,800 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2010/03/12 18:21:52 | 000,097,280 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ser2pl64.sys -- (Ser2pl)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 15:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2007/08/31 14:15:34 | 000,079,872 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emAudio64.sys -- (emAudio)
DRV:64bit: - [2007/06/21 17:51:46 | 000,215,808 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emDevice64.sys -- (DCamUSBEMPIA)
DRV:64bit: - [2007/06/21 17:51:32 | 000,006,400 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emFilter64.sys -- (FiltUSBEMPIA)
DRV:64bit: - [2007/06/21 17:51:30 | 000,006,144 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emScan64.sys -- (ScanUSBEMPIA)
DRV:64bit: - [2005/09/23 22:18:34 | 000,261,120 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MarvinBus64.sys -- (MarvinBus)
DRV - [2014/01/20 18:28:20 | 000,521,944 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140228.001\IDSviA64.sys -- (IDSVia64)
DRV - [2013/12/17 19:32:10 | 001,526,488 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20140214.001\BHDrvx64.sys -- (BHDrvx64)
DRV - [2013/11/21 00:42:05 | 000,484,952 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2013/11/21 00:42:05 | 000,137,648 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2013/11/13 01:00:00 | 002,099,288 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140303.001\ex64.sys -- (NAVEX15)
DRV - [2013/11/13 01:00:00 | 000,126,040 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140303.001\eng64.sys -- (NAVENG)
DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC

IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKCU\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 50 6D FC C0 69 36 CF 01 [binary data]
IE - HKCU\..\SearchScopes,DefaultScope = {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@palmsource.com/installer,version=1.0: C:\PROGRA~2\palmOne\PACKAG~1\NPInstal.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\adobe.com/AdobeExManCCDetect32: C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\adobe.com/AdobeExManCCDetect64: C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect64.dll (Adobe Systems)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn\ [2014/03/03 09:13:34 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF [2013/11/13 15:40:34 | 000,000,000 | ---D | M]
FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Perk Prize Panel\FF\ [2014/03/02 18:32:14 | 000,000,000 | ---D | M]

[2013/06/08 10:39:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Conduit Search (Enabled)
CHR - default_search_provider: search_url = http://search.condui...PV=T21110_sp_ch
CHR - default_search_provider: suggest_url = http://suggest.searc...x={searchTerms},
CHR - homepage: http://search.condui...PV=T21110_sp_ch
CHR - plugin: Error reading preferences file
CHR - Extension: Perk Prize Panel = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfaifkapfifnanhhiidacmhldddojchn\1.0_0\
CHR - Extension: No name found = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\2.4.0.53495_1\
CHR - Extension: Website Logon = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgfhihjicjofdejkbjgnjlaglaciobe\1.0_0\
CHR - Extension: Website Logon = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgfhihjicjofdejkbjgnjlaglaciobe\1.0_1\
CHR - Extension: No name found = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0\
CHR - Extension: Google Wallet = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Google Wallet = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\

O1 HOSTS File: ([2009/06/10 16:00:26 | 000,000,824 | ---- | M]) - C:\Windows\SysNative\drivers\etc\hosts
O2:64bit: - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
O2 - BHO: (Perk Prize Panel) - {47F3EB15-C230-4A0B-BE4B-D527FF483B48} - C:\Program Files (x86)\Perk Prize Panel\pp.dll ()
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\ipsbho.dll (Symantec Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKCU\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BeatsOSDApp] C:\Program Files\IDT\WDM\beats64.exe (Hewlett-Packard )
O4:64bit: - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\EPSON\Creativity Suite\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKCU..\Run: [AdobeBridge] File not found
O4 - HKCU..\Run: [Dashlane] C:\Users\Glens\AppData\Roaming\Dashlane\Dashlane.exe ()
O4 - HKCU..\Run: [GarminExpressTrayApp] C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKCU..\Run: [SUPERAntiSpyware] C:\Program Files\SUPERAntiSpyware\SUPERANTISPYWARE.EXE (SUPERAntiSpyware)
O4 - HKCU..\Run: [TivoNotify] C:\Program Files (x86)\TiVo\Desktop\TiVoNotify.exe (TiVo Inc.)
O4 - HKCU..\Run: [TivoServer] C:\Program Files (x86)\TiVo\Desktop\TiVoServer.exe (TiVo Inc.)
O4 - HKCU..\Run: [TivoTransfer] C:\Program Files (x86)\TiVo\Desktop\TiVoTransfer.exe (TiVo Inc.)
O4 - HKCU..\Run: [TranscodingService] C:\Program Files (x86)\TiVo\Desktop\Plus\\TranscodingService.exe ()
O4:64bit: - HKLM..\RunOnce: [NCPluginUpdater] C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe (Hewlett-Packard)
O4 - Startup: C:\Users\Glens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Glens\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9:64bit: - Extra Button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.h...pdetect1263.cab (GMNRev Class)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadbl...ivex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://linksyssuppo...rt/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: Garmin Communicator Plug-In https://static.garmi...xControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 207.69.188.186 207.69.188.187 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1F967591-0D7C-44B2-AED9-B9411FB2D3A5}: DhcpNameServer = 207.69.188.186 207.69.188.187 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{36AC44C1-9AA8-4744-805E-935E2827B256}: DhcpNameServer = 207.69.188.186 207.69.188.187 192.168.1.1
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll) - File not found
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/05 18:15:08 | 000,000,034 | ---- | M] () - Y:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{0bba1dd7-04ba-11e1-8f1c-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{0bba1dd7-04ba-11e1-8f1c-d0df9aa5d807}\Shell\AutoRun\command - "" = I:\launcher.exe
O33 - MountPoints2\{0bba1ec5-04ba-11e1-8f1c-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{0bba1ec5-04ba-11e1-8f1c-d0df9aa5d807}\Shell\AutoRun\command - "" = J:\launcher.exe
O33 - MountPoints2\{30973883-1544-11e1-94b8-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{30973883-1544-11e1-94b8-d0df9aa5d807}\Shell\AutoRun\command - "" = I:\launcher.exe
O33 - MountPoints2\{3097389b-1544-11e1-94b8-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{3097389b-1544-11e1-94b8-d0df9aa5d807}\Shell\AutoRun\command - "" = I:\launcher.exe
O33 - MountPoints2\{98137975-1dc5-11e1-86c0-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{98137975-1dc5-11e1-86c0-d0df9aa5d807}\Shell\AutoRun\command - "" = H:\launcher.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

NetSvcs:64bit: AppMgmt - C:\Windows\SysNative\appmgmts.dll (Microsoft Corporation)

CREATERESTOREPOINT
Restore point Set: OTL Restore Point

========== Files/Folders - Created Within 30 Days ==========

[2014/03/03 14:07:46 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014/03/02 18:33:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EnhanceTronic
[2014/03/02 18:32:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Perk Prize Panel
[2014/03/02 18:21:39 | 001,037,734 | ---- | C] (Thisisu) -- C:\Users\Glens\Desktop\JRT.exe
[2014/03/02 17:54:45 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/03/02 17:17:35 | 000,000,000 | ---D | C] -- C:\_OTL
[2014/02/27 12:29:58 | 000,000,000 | ---D | C] -- C:\Users\Glens\Documents\Malware files
[2014/02/27 11:07:51 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Glens\Desktop\OTL.exe
[2014/02/25 15:12:19 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2014/02/25 14:51:17 | 006,574,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2014/02/25 14:51:17 | 005,694,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2014/02/25 14:19:29 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2014/02/25 14:19:20 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2014/02/25 14:19:20 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2014/02/25 14:19:20 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2014/02/25 14:19:16 | 001,147,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe
[2014/02/25 14:19:16 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
[2014/02/25 14:19:16 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprt.exe
[2014/02/25 14:19:16 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWbPrxy.exe
[2014/02/25 14:19:16 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
[2014/02/25 14:19:16 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsRdpWebAccess.dll
[2014/02/25 14:19:16 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
[2014/02/25 14:19:16 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MsRdpWebAccess.dll
[2014/02/25 14:19:16 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprtPS.dll
[2014/02/25 14:19:16 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wksprtPS.dll
[2014/02/25 14:19:10 | 001,057,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdvidcrl.dll
[2014/02/25 14:19:10 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdvidcrl.dll
[2014/02/25 14:17:27 | 001,030,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWorkspace.dll
[2014/02/25 14:17:26 | 000,792,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TSWorkspace.dll
[2014/02/23 16:56:10 | 000,000,000 | ---D | C] -- C:\Users\Glens\Documents\Update Problem
[2014/02/23 15:40:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2014/02/23 15:39:41 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/02/23 15:39:24 | 000,000,000 | ---D | C] -- C:\Users\Glens\MBAR
[2014/02/23 13:22:20 | 000,000,000 | ---D | C] -- C:\Users\Glens\AppData\Roaming\Malwarebytes
[2014/02/23 13:21:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/02/23 13:21:46 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/02/23 13:21:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2014/02/22 17:06:05 | 000,000,000 | ---D | C] -- C:\Windows\Migration
[2014/02/22 15:07:46 | 000,000,000 | ---D | C] -- C:\Windows\CheckSur
[2014/02/22 14:07:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Stickies
[2014/02/20 17:55:08 | 000,210,216 | ---- | C] (Cisco WebEx LLC) -- C:\Windows\SysWow64\atsckernel.exe
[2014/02/20 17:55:06 | 000,118,056 | ---- | C] (Cisco WebEx LLC) -- C:\Windows\SysWow64\atashost.exe
[2014/02/20 17:54:38 | 000,000,000 | ---D | C] -- C:\ProgramData\WebEx
[2014/02/20 16:46:44 | 000,000,000 | ---D | C] -- C:\Users\Glens\AppData\Roaming\chc
[2014/02/19 15:06:19 | 000,000,000 | ---D | C] -- C:\Users\Glens\AppData\Local\ElevatedDiagnostics
[2014/02/18 18:37:34 | 000,000,000 | ---D | C] -- C:\Users\Glens\AppData\Roaming\Lavasoft
[2014/02/18 18:37:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft Ad-Aware SE Personal
[2014/02/18 18:37:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lavasoft
[2014/02/13 03:02:41 | 000,548,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014/02/13 03:02:05 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/02/13 03:02:05 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/02/13 03:02:05 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/02/13 03:02:04 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/02/13 03:02:04 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/02/13 03:02:04 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/02/13 03:02:04 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/02/13 03:02:03 | 000,627,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/02/13 03:02:03 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/02/13 03:02:03 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/02/13 03:02:03 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/02/13 03:02:03 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/02/13 03:02:03 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/02/13 03:02:03 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/02/13 03:02:03 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/02/13 03:02:03 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/02/13 03:02:02 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/02/13 03:02:02 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/02/13 03:02:02 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/02/13 03:02:02 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/02/13 03:02:01 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/02/13 03:02:01 | 001,964,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/02/13 03:01:59 | 005,768,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/02/12 17:25:40 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll
[2014/02/12 17:25:40 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll
[2014/02/12 17:25:38 | 000,658,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe
[2014/02/12 17:25:38 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe
[2014/02/12 17:25:37 | 000,594,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe
[2014/02/12 17:25:37 | 000,572,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe
[2014/02/12 17:25:37 | 000,553,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe
[2014/02/12 17:25:37 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2014/02/12 17:25:37 | 000,528,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdrm.dll
[2014/02/12 17:25:37 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe
[2014/02/12 17:25:37 | 000,508,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2014/02/12 17:25:37 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll
[2014/02/12 17:25:37 | 000,485,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll
[2014/02/12 17:25:37 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2014/02/12 17:25:37 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll
[2014/02/12 17:25:37 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll
[2014/02/12 17:25:37 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll
[2014/02/12 17:25:37 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll
[2014/02/12 17:25:37 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll
[2014/02/12 17:25:32 | 003,928,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2014/02/12 17:25:32 | 002,565,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2014/02/06 12:13:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ThumbsPlus
[1 C:\Users\Glens\*.tmp files -> C:\Users\Glens\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2014/03/03 13:57:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/03/03 13:51:00 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/03/03 13:39:47 | 000,000,510 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task d74c3073-85bd-4619-804e-5111bb8c2c67.job
[2014/03/03 13:39:46 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/03/03 09:22:25 | 000,027,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/03/03 09:22:25 | 000,027,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/03/03 09:19:57 | 000,782,470 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/03/03 09:19:57 | 000,662,384 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/03/03 09:19:57 | 000,122,252 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/03/03 09:13:35 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/03/03 09:12:39 | 4279,484,414 | -HS- | M] () -- C:\hiberfil.sys
[2014/03/02 18:21:41 | 001,037,734 | ---- | M] (Thisisu) -- C:\Users\Glens\Desktop\JRT.exe
[2014/03/02 03:00:00 | 000,000,574 | ---- | M] () -- C:\Windows\tasks\b4a_Weather data.job
[2014/03/02 02:00:00 | 000,000,510 | ---- | M] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 0cf62b45-2ff6-4f51-a641-b157a3f6bd3f.job
[2014/03/02 01:00:00 | 000,000,580 | ---- | M] () -- C:\Windows\tasks\b4a_Scrapbook Scans.job
[2014/03/02 00:40:02 | 000,000,568 | ---- | M] () -- C:\Windows\tasks\b4a_Favorites.job
[2014/03/02 00:31:12 | 000,000,610 | ---- | M] () -- C:\Windows\tasks\b4a_Glens HP to Bank non Zphoto.job
[2014/03/02 00:31:12 | 000,000,596 | ---- | M] () -- C:\Windows\tasks\b4a_Photo to velma - Photos.job
[2014/03/02 00:31:12 | 000,000,580 | ---- | M] () -- C:\Windows\tasks\b4a_Digital Current.job
[2014/03/02 00:31:12 | 000,000,574 | ---- | M] () -- C:\Windows\tasks\b4a_Zphotol to O.job
[2014/03/02 00:31:12 | 000,000,574 | ---- | M] () -- C:\Windows\tasks\b4a_Glens Videos.job
[2014/03/02 00:31:12 | 000,000,572 | ---- | M] () -- C:\Windows\tasks\b4a_Active Data.job
[2014/03/02 00:31:12 | 000,000,558 | ---- | M] () -- C:\Windows\tasks\b4a_Other Photo.job
[2014/03/02 00:31:11 | 000,000,590 | ---- | M] () -- C:\Windows\tasks\b4a_Mirror to X3 from TO.job
[2014/02/28 17:22:04 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForGlens.job
[2014/02/27 15:06:47 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014/02/27 15:06:47 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014/02/27 11:10:12 | 000,001,864 | ---- | M] () -- C:\Users\Glens\Desktop\OTL.exe - Shortcut.lnk
[2014/02/27 11:07:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Glens\Desktop\OTL.exe
[2014/02/26 10:57:03 | 000,001,303 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
[2014/02/24 11:25:27 | 000,000,349 | ---- | M] () -- C:\Users\Public\Documents\PCLECHAL.INI
[2014/02/23 16:57:12 | 000,001,208 | ---- | M] () -- C:\Users\Glens\Documents\details of KB954430 instal.rtf
[2014/02/23 15:39:41 | 000,091,352 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/02/23 13:21:47 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/02/22 17:26:20 | 000,774,592 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014/02/22 14:24:08 | 000,001,013 | ---- | M] () -- C:\Users\Glens\Desktop\stickies.chm - HELP.lnk
[2014/02/22 14:07:12 | 000,001,049 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Stickies.lnk
[2014/02/22 14:07:12 | 000,000,625 | ---- | M] () -- C:\Windows\uninstallstickies.bat
[2014/02/21 04:46:02 | 000,001,915 | ---- | M] () -- C:\Users\Glens\Desktop\Dashlane.lnk
[2014/02/20 20:01:41 | 000,002,185 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/02/20 17:55:04 | 000,210,216 | ---- | M] (Cisco WebEx LLC) -- C:\Windows\SysWow64\atsckernel.exe
[2014/02/20 17:55:04 | 000,118,056 | ---- | M] (Cisco WebEx LLC) -- C:\Windows\SysWow64\atashost.exe
[2014/02/17 12:41:35 | 000,007,663 | ---- | M] () -- C:\Users\Glens\AppData\Local\Resmon.ResmonCfg
[2014/02/15 14:36:23 | 000,001,456 | ---- | M] () -- C:\Users\Glens\AppData\Local\Adobe Save for Web 13.0 Prefs
[2014/02/13 13:21:03 | 010,094,603 | ---- | M] () -- C:\Users\Glens\Desktop\bird1.mp4
[2014/02/13 12:39:44 | 000,012,288 | ---- | M] () -- C:\Users\Glens\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/02/13 11:39:13 | 000,000,080 | ---- | M] () -- C:\Users\Glens\Videos.scn
[2014/02/06 12:13:12 | 000,001,089 | ---- | M] () -- C:\Users\Glens\Application Data\Microsoft\Internet Explorer\Quick Launch\ThumbsPlus 9.lnk
[2014/02/06 12:13:12 | 000,001,065 | ---- | M] () -- C:\Users\Glens\Desktop\ThumbsPlus 9.lnk
[2014/02/06 12:13:12 | 000,000,251 | ---- | M] () -- C:\Windows\ODBCINST.INI
[2014/02/06 11:49:50 | 000,000,308 | ---- | M] () -- C:\CD Drive - Shortcut.lnk
[2014/02/06 06:30:12 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/02/06 06:07:39 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/02/06 06:06:47 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/02/06 05:56:03 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/02/06 05:52:11 | 000,574,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/02/06 05:49:03 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/02/06 05:48:45 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/02/06 05:48:11 | 000,708,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/02/06 05:32:49 | 000,218,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/02/06 05:17:15 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/02/06 05:11:37 | 005,768,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/02/06 05:01:36 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/02/06 05:00:46 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/02/06 04:57:13 | 000,627,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/02/06 04:52:21 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/02/06 04:50:32 | 002,041,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/02/06 04:49:22 | 000,440,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/02/06 04:47:22 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/02/06 04:46:27 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/02/06 04:25:43 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/02/06 04:09:30 | 001,964,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/02/06 03:40:06 | 000,817,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/02/06 03:34:31 | 000,703,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[1 C:\Users\Glens\*.tmp files -> C:\Users\Glens\*.tmp -> ]

========== Files Created - No Company Name ==========

[2014/02/27 11:10:12 | 000,001,864 | ---- | C] () -- C:\Users\Glens\Desktop\OTL.exe - Shortcut.lnk
[2014/02/23 16:57:12 | 000,001,208 | ---- | C] () -- C:\Users\Glens\Documents\details of KB954430 instal.rtf
[2014/02/23 13:21:47 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/02/22 14:24:08 | 000,001,013 | ---- | C] () -- C:\Users\Glens\Desktop\stickies.chm - HELP.lnk
[2014/02/22 14:07:12 | 000,001,049 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Stickies.lnk
[2014/02/22 14:07:12 | 000,000,625 | ---- | C] () -- C:\Windows\uninstallstickies.bat
[2014/02/14 12:43:36 | 000,000,510 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task d74c3073-85bd-4619-804e-5111bb8c2c67.job
[2014/02/14 12:34:10 | 000,000,510 | ---- | C] () -- C:\Windows\tasks\SUPERAntiSpyware Scheduled Task 0cf62b45-2ff6-4f51-a641-b157a3f6bd3f.job
[2014/02/13 13:20:17 | 010,094,603 | ---- | C] () -- C:\Users\Glens\Desktop\bird1.mp4
[2014/02/06 12:13:12 | 000,001,089 | ---- | C] () -- C:\Users\Glens\Application Data\Microsoft\Internet Explorer\Quick Launch\ThumbsPlus 9.lnk
[2014/02/06 12:13:12 | 000,001,065 | ---- | C] () -- C:\Users\Glens\Desktop\ThumbsPlus 9.lnk
[2014/02/06 11:49:50 | 000,000,308 | ---- | C] () -- C:\CD Drive - Shortcut.lnk
[2014/01/30 13:43:23 | 000,000,355 | ---- | C] () -- C:\Program Files\Homegroup - Shortcut.lnk
[2013/12/12 10:02:03 | 000,001,456 | ---- | C] () -- C:\Users\Glens\AppData\Local\Adobe Save for Web 13.0 Prefs
[2013/10/15 11:07:47 | 000,000,884 | RHS- | C] () -- C:\Users\Glens\ntuser.pol
[2013/08/30 13:14:57 | 000,001,185 | ---- | C] () -- C:\Users\Glens\VG pictures - Shortcut.lnk
[2013/06/13 13:32:36 | 000,000,132 | ---- | C] () -- C:\Users\Glens\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2013/06/09 13:57:02 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2013/06/09 07:02:02 | 000,033,958 | ---- | C] () -- C:\ProgramData\uninstaller.exe
[2013/05/05 16:55:41 | 000,000,132 | ---- | C] () -- C:\Users\Glens\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2013/04/04 13:28:48 | 000,110,456 | ---- | C] () -- C:\Users\Glens\g2ax_customer_downloadhelper_win32_x86.exe
[2013/02/27 17:15:23 | 000,000,355 | ---- | C] () -- C:\Users\Glens\Homegroup - Shortcut.lnk
[2012/10/13 06:59:15 | 000,000,080 | ---- | C] () -- C:\Users\Glens\Videos.scn
[2012/08/29 11:05:04 | 000,100,344 | ---- | C] () -- C:\Windows\HPBroker.dll
[2012/07/18 07:16:03 | 000,000,036 | ---- | C] () -- C:\Windows\hdd.ini
[2012/07/03 12:02:46 | 000,000,029 | ---- | C] () -- C:\Windows\DEBUGSM.INI
[2012/06/26 06:10:06 | 003,668,480 | ---- | C] () -- C:\Windows\SysWow64\CosmoRenderer.dll
[2012/05/17 10:31:19 | 000,012,288 | ---- | C] () -- C:\Users\Glens\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/09 10:47:07 | 000,000,077 | ---- | C] () -- C:\Windows\EPSPR2000.ini
[2012/01/21 09:31:05 | 000,031,104 | ---- | C] () -- C:\Users\Glens\energy-report.html
[2012/01/02 14:48:37 | 000,000,047 | ---- | C] () -- C:\Program Files (x86)\sleep.bat
[2012/01/01 10:05:04 | 000,007,663 | ---- | C] () -- C:\Users\Glens\AppData\Local\Resmon.ResmonCfg
[2011/11/11 04:40:29 | 000,002,217 | ---- | C] () -- C:\ProgramData\repository.xml
[2011/11/10 11:44:44 | 000,001,456 | ---- | C] () -- C:\Users\Glens\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/11/01 19:46:41 | 000,713,728 | ---- | C] () -- C:\Program Files (x86)\FCW32.EXE
[2011/11/01 19:46:41 | 000,550,322 | ---- | C] () -- C:\Program Files (x86)\CARLSBAD.FCW
[2011/11/01 19:46:41 | 000,455,079 | ---- | C] () -- C:\Program Files (x86)\ADINIT.DAT
[2011/11/01 19:46:41 | 000,399,360 | ---- | C] () -- C:\Program Files (x86)\XPDWG.DLL
[2011/11/01 19:46:41 | 000,248,343 | ---- | C] () -- C:\Program Files (x86)\CMHOUSE.FCW
[2011/11/01 19:46:41 | 000,189,922 | ---- | C] () -- C:\Program Files (x86)\ELECTRIC.FSC
[2011/11/01 19:46:41 | 000,187,904 | ---- | C] () -- C:\Program Files (x86)\FCWLANG.DLL
[2011/11/01 19:46:41 | 000,174,797 | ---- | C] () -- C:\Program Files (x86)\TALI.FCW
[2011/11/01 19:46:41 | 000,164,244 | ---- | C] () -- C:\Program Files (x86)\MERPLAZA.FCW
[2011/11/01 19:46:41 | 000,128,000 | ---- | C] () -- C:\Program Files (x86)\UNINST.EXE
[2011/11/01 19:46:41 | 000,127,613 | ---- | C] () -- C:\Program Files (x86)\SOLAR.FCW
[2011/11/01 19:46:41 | 000,067,584 | ---- | C] () -- C:\Program Files (x86)\NED3.EXE
[2011/11/01 19:46:41 | 000,066,073 | ---- | C] () -- C:\Program Files (x86)\NOZZLE.FCW
[2011/11/01 19:46:41 | 000,054,863 | ---- | C] () -- C:\Program Files (x86)\LOGIC.FCW
[2011/11/01 19:46:41 | 000,044,032 | ---- | C] () -- C:\Program Files (x86)\XPLDFCD.DLL
[2011/11/01 19:46:41 | 000,043,329 | ---- | C] () -- C:\Program Files (x86)\USA.FCW
[2011/11/01 19:46:41 | 000,039,585 | ---- | C] () -- C:\Program Files (x86)\PADEMO.FCW
[2011/11/01 19:46:41 | 000,035,718 | ---- | C] () -- C:\Program Files (x86)\TRAIN.FCW
[2011/11/01 19:46:41 | 000,034,082 | ---- | C] () -- C:\Program Files (x86)\GALLERY.FCW
[2011/11/01 19:46:41 | 000,032,854 | ---- | C] () -- C:\Program Files (x86)\STONE.BMP
[2011/11/01 19:46:41 | 000,018,432 | ---- | C] () -- C:\Program Files (x86)\XPPRINTA.DLL
[2011/11/01 19:46:41 | 000,017,143 | ---- | C] () -- C:\Program Files (x86)\LINWIDTH.GDE
[2011/11/01 19:46:41 | 000,016,192 | ---- | C] () -- C:\Program Files (x86)\60.GDE
[2011/11/01 19:46:41 | 000,015,118 | ---- | C] () -- C:\Program Files (x86)\LEAVES.BMP
[2011/11/01 19:46:41 | 000,014,947 | ---- | C] () -- C:\Program Files (x86)\PULLEY.FCW
[2011/11/01 19:46:41 | 000,014,469 | ---- | C] () -- C:\Program Files (x86)\PRINTEST.FCW
[2011/11/01 19:46:41 | 000,013,312 | ---- | C] () -- C:\Program Files (x86)\XPGUIDE.DLL
[2011/11/01 19:46:41 | 000,013,009 | ---- | C] () -- C:\Program Files (x86)\FCDLOGO.FCW
[2011/11/01 19:46:41 | 000,012,288 | ---- | C] () -- C:\Program Files (x86)\XPLDECW.DLL
[2011/11/01 19:46:41 | 000,012,159 | ---- | C] () -- C:\Program Files (x86)\SYMCAT.GDE
[2011/11/01 19:46:41 | 000,011,776 | ---- | C] () -- C:\Program Files (x86)\XPSYMCAT.DLL
[2011/11/01 19:46:41 | 000,010,752 | ---- | C] () -- C:\Program Files (x86)\XPENT.DLL
[2011/11/01 19:46:41 | 000,010,062 | ---- | C] () -- C:\Program Files (x86)\BASICS.GDE
[2011/11/01 19:46:41 | 000,009,481 | ---- | C] () -- C:\Program Files (x86)\ACTDEMO.FCW
[2011/11/01 19:46:41 | 000,009,247 | ---- | C] () -- C:\Program Files (x86)\COLORS.FCW
[2011/11/01 19:46:41 | 000,009,141 | ---- | C] () -- C:\Program Files (x86)\TABLET.FCW
[2011/11/01 19:46:41 | 000,008,704 | ---- | C] () -- C:\Program Files (x86)\XPACT.DLL
[2011/11/01 19:46:41 | 000,008,124 | ---- | C] () -- C:\Program Files (x86)\3D.FCW
[2011/11/01 19:46:41 | 000,008,093 | ---- | C] () -- C:\Program Files (x86)\LSTYLES.fcw
[2011/11/01 19:46:41 | 000,008,012 | ---- | C] () -- C:\Program Files (x86)\FILLS.FCW
[2011/11/01 19:46:41 | 000,007,674 | ---- | C] () -- C:\Program Files (x86)\FCAD3.MNU
[2011/11/01 19:46:41 | 000,007,655 | ---- | C] () -- C:\Program Files (x86)\SYM.FCW
[2011/11/01 19:46:41 | 000,007,644 | ---- | C] () -- C:\Program Files (x86)\MULTIFIL.GDE
[2011/11/01 19:46:41 | 000,007,612 | ---- | C] () -- C:\Program Files (x86)\FCW32.MNU
[2011/11/01 19:46:41 | 000,007,537 | ---- | C] () -- C:\Program Files (x86)\SCREEN.GDE
[2011/11/01 19:46:41 | 000,007,521 | ---- | C] () -- C:\Program Files (x86)\GREEK.FNT
[2011/11/01 19:46:41 | 000,007,049 | ---- | C] () -- C:\Program Files (x86)\60NEW.FCW
[2011/11/01 19:46:41 | 000,006,933 | ---- | C] () -- C:\Program Files (x86)\CARTGRID.FCW
[2011/11/01 19:46:41 | 000,006,866 | ---- | C] () -- C:\Program Files (x86)\SMARTSYM.FCW
[2011/11/01 19:46:41 | 000,006,667 | ---- | C] () -- C:\Program Files (x86)\LESSON12.FCW
[2011/11/01 19:46:41 | 000,006,649 | ---- | C] () -- C:\Program Files (x86)\BURNER.FCW
[2011/11/01 19:46:41 | 000,006,545 | ---- | C] () -- C:\Program Files (x86)\LDIMS.FCW
[2011/11/01 19:46:41 | 000,006,274 | ---- | C] () -- C:\Program Files (x86)\CARTANGL.FCW
[2011/11/01 19:46:41 | 000,006,258 | ---- | C] () -- C:\Program Files (x86)\LWIDTHT.FCW
[2011/11/01 19:46:41 | 000,006,250 | ---- | C] () -- C:\Program Files (x86)\METRIC.FCT
[2011/11/01 19:46:41 | 000,006,169 | ---- | C] () -- C:\Program Files (x86)\ENGLISH.FCT
[2011/11/01 19:46:41 | 000,006,036 | ---- | C] () -- C:\Program Files (x86)\FANCY.FNT
[2011/11/01 19:46:41 | 000,005,728 | ---- | C] () -- C:\Program Files (x86)\PICTS.FCW
[2011/11/01 19:46:41 | 000,005,712 | ---- | C] () -- C:\Program Files (x86)\HANDW.FNT
[2011/11/01 19:46:41 | 000,005,632 | ---- | C] () -- C:\Program Files (x86)\XPASAVE.DLL
[2011/11/01 19:46:41 | 000,005,484 | ---- | C] () -- C:\Program Files (x86)\LESSON9.FCW
[2011/11/01 19:46:41 | 000,005,356 | ---- | C] () -- C:\Program Files (x86)\FSTYLES.FCW
[2011/11/01 19:46:41 | 000,005,175 | ---- | C] () -- C:\Program Files (x86)\LESSON8.FCW
[2011/11/01 19:46:41 | 000,005,105 | ---- | C] () -- C:\Program Files (x86)\MYSYMBOL.FCW
[2011/11/01 19:46:41 | 000,005,083 | ---- | C] () -- C:\Program Files (x86)\LWIDTH2.FCW
[2011/11/01 19:46:41 | 000,005,083 | ---- | C] () -- C:\Program Files (x86)\LWIDTH1.FCW
[2011/11/01 19:46:41 | 000,004,996 | ---- | C] () -- C:\Program Files (x86)\SQUARE.FCW
[2011/11/01 19:46:41 | 000,004,994 | ---- | C] () -- C:\Program Files (x86)\PALABEL.FCW
[2011/11/01 19:46:41 | 000,004,749 | ---- | C] () -- C:\Program Files (x86)\LESSON10.FCW
[2011/11/01 19:46:41 | 000,004,349 | ---- | C] () -- C:\Program Files (x86)\HELV.FNT
[2011/11/01 19:46:41 | 000,004,306 | ---- | C] () -- C:\Program Files (x86)\SMOOTH.FNT
[2011/11/01 19:46:41 | 000,004,227 | ---- | C] () -- C:\Program Files (x86)\HELVNRW.FNT
[2011/11/01 19:46:41 | 000,003,695 | ---- | C] () -- C:\Program Files (x86)\SYMBOLS.GDE
[2011/11/01 19:46:41 | 000,003,660 | ---- | C] () -- C:\Program Files (x86)\SLANT.FNT
[2011/11/01 19:46:41 | 000,003,541 | ---- | C] () -- C:\Program Files (x86)\STDTEXT.FNT
[2011/11/01 19:46:41 | 000,003,263 | ---- | C] () -- C:\Program Files (x86)\FCW32.IMN
[2011/11/01 19:46:41 | 000,003,079 | ---- | C] () -- C:\Program Files (x86)\AGRID.FCW
[2011/11/01 19:46:41 | 000,002,841 | ---- | C] () -- C:\Program Files (x86)\521.GDE
[2011/11/01 19:46:41 | 000,002,748 | ---- | C] () -- C:\Program Files (x86)\FONTS.GDE
[2011/11/01 19:46:41 | 000,002,460 | ---- | C] () -- C:\Program Files (x86)\TGRID.FCW
[2011/11/01 19:46:41 | 000,002,382 | ---- | C] () -- C:\Program Files (x86)\PENTEST.FCW
[2011/11/01 19:46:41 | 000,001,266 | ---- | C] () -- C:\Program Files (x86)\FCW32.MAC
[2011/11/01 19:46:41 | 000,001,117 | ---- | C] () -- C:\Program Files (x86)\SOLAR.MNU
[2011/11/01 19:46:41 | 000,000,756 | ---- | C] () -- C:\Program Files (x86)\START.GDE
[2011/11/01 19:46:41 | 000,000,745 | ---- | C] () -- C:\Program Files (x86)\NEW60.GDE
[2011/11/01 19:46:41 | 000,000,745 | ---- | C] () -- C:\Program Files (x86)\NEW521.GDE
[2011/11/01 19:46:41 | 000,000,606 | ---- | C] () -- C:\Program Files (x86)\ACTDEMO.MAC
[2011/11/01 19:46:41 | 000,000,603 | ---- | C] () -- C:\Program Files (x86)\INDEX.GDE
[2011/11/01 19:46:41 | 000,000,399 | ---- | C] () -- C:\Program Files (x86)\INTRO.GDE
[2011/11/01 19:46:41 | 000,000,310 | ---- | C] () -- C:\Program Files (x86)\HAMMER.BMP
[2011/11/01 19:46:41 | 000,000,246 | ---- | C] () -- C:\Program Files (x86)\TILE.BMP
[2011/11/01 19:46:41 | 000,000,039 | ---- | C] () -- C:\Program Files (x86)\NEW.GDE
[2011/10/22 18:01:38 | 000,002,792 | ---- | C] () -- C:\Program Files\HP SimplePass 2011

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/25 21:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 20:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== Custom Scans ==========

========== Base Services ==========
SRV:64bit: - [2009/07/13 20:40:01 | 000,072,192 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\aelupsvc.dll -- (AeLookupSvc)
SRV:64bit: - [2013/02/27 00:47:10 | 000,070,144 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\appinfo.dll -- (Appinfo)
SRV:64bit: - [2009/07/13 20:38:55 | 000,079,360 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\alg.exe -- (ALG)
SRV:64bit: - [2010/11/20 22:23:51 | 000,849,920 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\qmgr.dll -- (BITS)
SRV:64bit: - [2010/11/20 22:24:00 | 000,705,024 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\BFE.DLL -- (BFE)
SRV:64bit: - [2013/09/24 20:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\lsass.exe -- (KeyIso)
SRV:64bit: - [2009/07/13 20:40:50 | 000,402,944 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\es.dll -- (EventSystem)
SRV - [2009/07/13 20:15:19 | 000,271,360 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\es.dll -- (EventSystem)
SRV:64bit: - [2012/07/04 17:13:27 | 000,136,704 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\browser.dll -- (Browser)
SRV:64bit: - [2013/07/09 00:46:20 | 000,184,320 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\cryptsvc.dll -- (CryptSvc)
SRV - [2013/07/08 23:46:31 | 000,140,288 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\cryptsvc.dll -- (CryptSvc)
SRV:64bit: - [2010/11/20 22:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (DcomLaunch)
SRV:64bit: - [2010/11/20 22:24:00 | 000,317,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dhcpcore.dll -- (Dhcp)
SRV - [2010/11/20 22:24:09 | 000,254,464 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\dhcpcore.dll -- (Dhcp)
SRV:64bit: - [2011/10/22 17:36:48 | 000,183,296 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\dnsrslvr.dll -- (Dnscache)
SRV:64bit: - [2009/07/13 20:40:35 | 000,111,104 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\eapsvc.dll -- (EapHost)
SRV:64bit: - [2009/07/13 20:41:00 | 000,038,912 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\hidserv.dll -- (hidserv)
SRV - [2009/07/13 20:15:24 | 000,049,152 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\hidserv.dll -- (hidserv)
SRV:64bit: - [2009/07/13 20:41:10 | 000,359,424 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\ipnathlp.dll -- (SharedAccess)
SRV:64bit: - [2010/11/20 22:23:48 | 000,501,248 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\IPSECSVC.DLL -- (PolicyAgent)
No service found with a name of MsMpSvc
No service found with a name of NisSrv
SRV:64bit: - [2009/07/13 20:41:54 | 000,524,288 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\swprv.dll -- (swprv)
SRV:64bit: - [2009/07/13 20:41:26 | 000,067,584 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\mmcss.dll -- (MMCSS)
SRV:64bit: - [2009/07/13 20:41:52 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netman.dll -- (Netman)
SRV:64bit: - [2009/07/13 20:41:52 | 000,459,776 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysNative\netprofm.dll -- (netprofm)
SRV - [2009/07/13 20:16:03 | 000,360,448 | ---- | M] (Microsoft Corporation) [On_Demand | Running] -- C:\Windows\SysWOW64\netprofm.dll -- (netprofm)
SRV:64bit: - [2012/10/03 12:44:21 | 000,303,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nlasvc.dll -- (NlaSvc)
SRV:64bit: - [2009/07/13 20:41:53 | 000,025,600 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\nsisvc.dll -- (nsi)
SRV:64bit: - [2011/10/22 17:39:31 | 000,404,480 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\umpnpmgr.dll -- (PlugPlay)
SRV:64bit: - [2012/02/11 01:36:02 | 000,559,104 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\spoolsv.exe -- (Spooler)
SRV:64bit: - [2013/09/24 20:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\lsass.exe -- (ProtectedStorage)
No service found with a name of EMDMgmt
SRV:64bit: - [2009/07/13 20:41:53 | 000,099,328 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasauto.dll -- (RasAuto)
SRV:64bit: - [2010/11/20 22:24:17 | 000,344,064 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\rasmans.dll -- (RasMan)
SRV:64bit: - [2010/11/20 22:24:01 | 000,512,000 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\rpcss.dll -- (RpcSs)
SRV:64bit: - [2010/11/20 22:24:16 | 000,030,720 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\seclogon.dll -- (seclogon)
SRV:64bit: - [2013/09/24 20:03:24 | 000,030,720 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\lsass.exe -- (SamSs)
SRV:64bit: - [2009/07/13 20:41:58 | 000,097,280 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wscsvc.dll -- (wscsvc)
SRV:64bit: - [2010/11/20 22:23:48 | 000,236,032 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\srvsvc.dll -- (LanmanServer)
SRV:64bit: - [2010/11/20 22:23:55 | 000,370,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\shsvcs.dll -- (ShellHWDetection)
SRV - [2010/11/20 22:24:03 | 000,328,192 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysWOW64\shsvcs.dll -- (ShellHWDetection)
No service found with a name of slsvc
SRV:64bit: - [2010/11/20 22:24:16 | 001,110,016 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\schedsvc.dll -- (Schedule)
SRV:64bit: - [2010/11/20 22:24:32 | 000,316,928 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\tapisrv.dll -- (TapiSrv)
SRV - [2010/11/20 22:24:00 | 000,242,176 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWOW64\tapisrv.dll -- (TapiSrv)
SRV:64bit: - [2009/07/13 20:41:55 | 000,044,544 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\themeservice.dll -- (Themes)
SRV:64bit: - [2012/05/01 00:40:20 | 000,209,920 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\profsvc.dll -- (ProfSvc)
SRV:64bit: - [2010/11/20 22:23:55 | 001,600,512 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\SysNative\VSSVC.exe -- (VSS)
SRV:64bit: - [2010/11/20 22:24:32 | 000,679,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioSrv)
SRV:64bit: - [2010/11/20 22:24:32 | 000,679,424 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\audiosrv.dll -- (AudioEndpointBuilder)
SRV:64bit: - [2010/11/20 22:25:06 | 000,170,496 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\sdrsvc.dll -- (SDRSVC)
SRV:64bit: - [2013/05/27 00:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2010/11/20 22:23:55 | 001,646,080 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wevtsvc.dll -- (eventlog)
SRV:64bit: - [2010/11/20 22:24:28 | 000,828,416 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\MPSSVC.dll -- (MpsSvc)
SRV:64bit: - [2010/11/20 22:24:48 | 000,580,096 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wiaservc.dll -- (stisvc)
SRV:64bit: - [2010/11/20 22:24:15 | 000,128,000 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\msiexec.exe -- (msiserver)
SRV - [2010/11/20 22:24:28 | 000,073,216 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysWow64\msiexec.exe -- (msiserver)
SRV:64bit: - [2009/07/13 20:41:56 | 000,242,688 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wbem\WMIsvc.dll -- (Winmgmt)
SRV:64bit: - [2012/06/02 17:19:43 | 002,428,952 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wuaueng.dll -- (wuauserv)
SRV:64bit: - [2010/11/20 22:24:09 | 000,252,416 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\dot3svc.dll -- (dot3svc)
SRV:64bit: - [2009/07/13 20:41:56 | 000,886,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wlansvc.dll -- (Wlansvc)
SRV:64bit: - [2010/11/20 22:24:32 | 000,118,784 | ---- | M] (Microsoft Corporation) [Auto | Running] -- C:\Windows\SysNative\wkssvc.dll -- (LanmanWorkstation)

< %SYSTEMDRIVE%\*.exe >

< dir "%systemdrive%\*" /S /A:L /C >
Volume in drive C is OS
Volume Serial Number is EEF0-C95F
Directory of C:\
07/14/2009 12:08 AM <JUNCTION> Documents and Settings [C:\Users]
0 File(s) 0 bytes
Directory of C:\ProgramData
07/14/2009 12:08 AM <JUNCTION> Application Data [C:\ProgramData]
07/14/2009 12:08 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM <JUNCTION> Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users
07/14/2009 12:08 AM <SYMLINKD> All Users [C:\ProgramData]
07/14/2009 12:08 AM <JUNCTION> Default User [C:\Users\Default]
0 File(s) 0 bytes
Directory of C:\Users\All Users
07/14/2009 12:08 AM <JUNCTION> Application Data [C:\ProgramData]
07/14/2009 12:08 AM <JUNCTION> Desktop [C:\Users\Public\Desktop]
07/14/2009 12:08 AM <JUNCTION> Documents [C:\Users\Public\Documents]
07/14/2009 12:08 AM <JUNCTION> Favorites [C:\Users\Public\Favorites]
07/14/2009 12:08 AM <JUNCTION> Start Menu [C:\ProgramData\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM <JUNCTION> Templates [C:\ProgramData\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default
07/14/2009 12:08 AM <JUNCTION> Application Data [C:\Users\Default\AppData\Roaming]
07/14/2009 12:08 AM <JUNCTION> Cookies [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Cookies]
07/14/2009 12:08 AM <JUNCTION> Local Settings [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM <JUNCTION> My Documents [C:\Users\Default\Documents]
07/14/2009 12:08 AM <JUNCTION> NetHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
07/14/2009 12:08 AM <JUNCTION> PrintHood [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
07/14/2009 12:08 AM <JUNCTION> Recent [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Recent]
07/14/2009 12:08 AM <JUNCTION> SendTo [C:\Users\Default\AppData\Roaming\Microsoft\Windows\SendTo]
07/14/2009 12:08 AM <JUNCTION> Start Menu [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Start Menu]
07/14/2009 12:08 AM <JUNCTION> Templates [C:\Users\Default\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Default\AppData\Local
07/14/2009 12:08 AM <JUNCTION> Application Data [C:\Users\Default\AppData\Local]
07/14/2009 12:08 AM <JUNCTION> History [C:\Users\Default\AppData\Local\Microsoft\Windows\History]
07/14/2009 12:08 AM <JUNCTION> Temporary Internet Files [C:\Users\Default\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Glens
10/31/2011 07:25 PM <JUNCTION> Application Data [C:\Users\Glens\AppData\Roaming]
10/31/2011 07:25 PM <JUNCTION> Cookies [C:\Users\Glens\AppData\Roaming\Microsoft\Windows\Cookies]
10/31/2011 07:25 PM <JUNCTION> Local Settings [C:\Users\Glens\AppData\Local]
10/31/2011 07:25 PM <JUNCTION> My Documents [C:\Users\Glens\Documents]
10/31/2011 07:25 PM <JUNCTION> NetHood [C:\Users\Glens\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
10/31/2011 07:25 PM <JUNCTION> PrintHood [C:\Users\Glens\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
10/31/2011 07:25 PM <JUNCTION> Recent [C:\Users\Glens\AppData\Roaming\Microsoft\Windows\Recent]
10/31/2011 07:25 PM <JUNCTION> SendTo [C:\Users\Glens\AppData\Roaming\Microsoft\Windows\SendTo]
10/31/2011 07:25 PM <JUNCTION> Start Menu [C:\Users\Glens\AppData\Roaming\Microsoft\Windows\Start Menu]
10/31/2011 07:25 PM <JUNCTION> Templates [C:\Users\Glens\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\Glens\AppData\Local
10/31/2011 07:25 PM <JUNCTION> Application Data [C:\Users\Glens\AppData\Local]
10/31/2011 07:25 PM <JUNCTION> History [C:\Users\Glens\AppData\Local\Microsoft\Windows\History]
10/31/2011 07:25 PM <JUNCTION> Temporary Internet Files [C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Users\Glens\Documents
10/31/2011 07:25 PM <JUNCTION> My Music [C:\Users\Glens\Music]
10/31/2011 07:25 PM <JUNCTION> My Pictures [C:\Users\Glens\Pictures]
10/31/2011 07:25 PM <JUNCTION> My Videos [C:\Users\Glens\Videos]
0 File(s) 0 bytes
Directory of C:\Users\Public\Documents
07/14/2009 12:08 AM <JUNCTION> My Music [C:\Users\Public\Music]
07/14/2009 12:08 AM <JUNCTION> My Pictures [C:\Users\Public\Pictures]
07/14/2009 12:08 AM <JUNCTION> My Videos [C:\Users\Public\Videos]
0 File(s) 0 bytes
Directory of C:\Users\UpdatusUser
04/04/2013 02:34 PM <JUNCTION> Application Data [C:\Users\UpdatusUser\AppData\Roaming]
04/04/2013 02:34 PM <JUNCTION> Cookies [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Cookies]
04/04/2013 02:34 PM <JUNCTION> Local Settings [C:\Users\UpdatusUser\AppData\Local]
04/04/2013 02:34 PM <JUNCTION> NetHood [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
04/04/2013 02:34 PM <JUNCTION> PrintHood [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
04/04/2013 02:34 PM <JUNCTION> Recent [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Recent]
04/04/2013 02:34 PM <JUNCTION> SendTo [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\SendTo]
04/04/2013 02:34 PM <JUNCTION> Start Menu [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Start Menu]
04/04/2013 02:34 PM <JUNCTION> Templates [C:\Users\UpdatusUser\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Users\UpdatusUser\AppData\Local
04/04/2013 02:34 PM <JUNCTION> Application Data [C:\Users\UpdatusUser\AppData\Local]
04/04/2013 02:34 PM <JUNCTION> History [C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\History]
04/04/2013 02:34 PM <JUNCTION> Temporary Internet Files [C:\Users\UpdatusUser\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile
11/06/2011 01:19 PM <JUNCTION> Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
11/06/2011 01:19 PM <JUNCTION> Cookies [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
11/06/2011 01:19 PM <JUNCTION> Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
11/06/2011 01:19 PM <JUNCTION> My Documents [C:\Windows\system32\config\systemprofile\Documents]
11/06/2011 01:19 PM <JUNCTION> NetHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
11/06/2011 01:19 PM <JUNCTION> PrintHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
11/06/2011 01:19 PM <JUNCTION> Recent [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent]
11/06/2011 01:19 PM <JUNCTION> SendTo [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo]
11/06/2011 01:19 PM <JUNCTION> Start Menu [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu]
11/06/2011 01:19 PM <JUNCTION> Templates [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\AppData\Local
11/06/2011 01:19 PM <JUNCTION> Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
11/06/2011 01:19 PM <JUNCTION> History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
11/06/2011 01:19 PM <JUNCTION> Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Windows\System32\config\systemprofile\Documents
11/06/2011 01:19 PM <JUNCTION> My Music [C:\Windows\system32\config\systemprofile\Music]
11/06/2011 01:19 PM <JUNCTION> My Pictures [C:\Windows\system32\config\systemprofile\Pictures]
11/06/2011 01:19 PM <JUNCTION> My Videos [C:\Windows\system32\config\systemprofile\Videos]
0 File(s) 0 bytes
Directory of C:\Windows\SysWOW64\config\systemprofile
11/06/2011 01:19 PM <JUNCTION> Application Data [C:\Windows\system32\config\systemprofile\AppData\Roaming]
11/06/2011 01:19 PM <JUNCTION> Cookies [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies]
11/06/2011 01:19 PM <JUNCTION> Local Settings [C:\Windows\system32\config\systemprofile\AppData\Local]
11/06/2011 01:19 PM <JUNCTION> My Documents [C:\Windows\system32\config\systemprofile\Documents]
11/06/2011 01:19 PM <JUNCTION> NetHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Network Shortcuts]
11/06/2011 01:19 PM <JUNCTION> PrintHood [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Printer Shortcuts]
11/06/2011 01:19 PM <JUNCTION> Recent [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Recent]
11/06/2011 01:19 PM <JUNCTION> SendTo [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\SendTo]
11/06/2011 01:19 PM <JUNCTION> Start Menu [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Start Menu]
11/06/2011 01:19 PM <JUNCTION> Templates [C:\Windows\system32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Templates]
0 File(s) 0 bytes
Directory of C:\Windows\SysWOW64\config\systemprofile\AppData\Local
11/06/2011 01:19 PM <JUNCTION> Application Data [C:\Windows\system32\config\systemprofile\AppData\Local]
11/06/2011 01:19 PM <JUNCTION> History [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\History]
11/06/2011 01:19 PM <JUNCTION> Temporary Internet Files [C:\Windows\system32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files]
0 File(s) 0 bytes
Directory of C:\Windows\SysWOW64\config\systemprofile\Documents
11/06/2011 01:19 PM <JUNCTION> My Music [C:\Windows\system32\config\systemprofile\Music]
11/06/2011 01:19 PM <JUNCTION> My Pictures [C:\Windows\system32\config\systemprofile\Pictures]
11/06/2011 01:19 PM <JUNCTION> My Videos [C:\Windows\system32\config\systemprofile\Videos]
0 File(s) 0 bytes
Total Files Listed:
0 File(s) 0 bytes
91 Dir(s) 852,248,780,800 bytes free

< MD5 for: EXPLORER.EXE >
[2011/10/22 17:37:12 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=0FB9C74046656D1579A64660AD67B746 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_ba87e574ddfe652d\explorer.exe
[2011/10/22 17:37:12 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\explorer.exe
[2011/10/22 17:37:12 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=332FEAB1435662FC6C672E25BEB37BE3 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_afa79dc39081d0ba\explorer.exe
[2011/10/22 17:37:12 | 002,871,808 | ---- | M] (Microsoft Corporation) MD5=3B69712041F3D63605529BD66DC00C48 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.21669_none_b0333b22a99da332\explorer.exe
[2010/11/20 22:24:25 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=40D777B7A95E00593EB1568C68514493 -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_ba2f56d3c4bcbafb\explorer.exe
[2011/10/22 17:37:12 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\SysWOW64\explorer.exe
[2011/10/22 17:37:12 | 002,616,320 | ---- | M] (Microsoft Corporation) MD5=8B88EBBB05A0E56B7DCC708498C02B3E -- C:\Windows\winsxs\wow64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17567_none_b9fc4815c4e292b5\explorer.exe
[2010/11/20 22:24:11 | 002,872,320 | ---- | M] (Microsoft Corporation) MD5=AC4C51EB24AA95B77F705AB159189E24 -- C:\Windows\winsxs\amd64_microsoft-windows-explorer_31bf3856ad364e35_6.1.7601.17514_none_afdaac81905bf900\explorer.exe

< MD5 for: SERVICES >
[2009/06/10 16:00:26 | 000,017,463 | ---- | M] () MD5=D9E1A01B480D961B7CF0509D597A92D6 -- C:\Windows\winsxs\amd64_microsoft-windows-w..nfrastructure-other_31bf3856ad364e35_6.1.7600.16385_none_6079f415110c0210\services

< MD5 for: SERVICES.CFG >
[2013/12/18 13:42:40 | 000,558,851 | ---- | M] () MD5=A044715A48D8FADB9366D554F20D3331 -- C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Services\Services.cfg
[2011/06/06 15:55:30 | 000,584,045 | R--- | M] () MD5=B82DD53FA8C260DDD7FDC42182DB816E -- C:\Windows\Installer\$PatchCache$\Managed\68AB67CA7DA73301B744AA0100000010\10.1.0\services.cfg

< MD5 for: SERVICES.CSS >
[2011/09/16 18:47:38 | 000,000,093 | ---- | M] () MD5=F15FB82C578490B209442B8C1D5076CC -- C:\ProgramData\Intuit\Quicken\Inet\Common\Localweb\Services\Services.css
[2011/09/16 18:47:38 | 000,000,093 | ---- | M] () MD5=F15FB82C578490B209442B8C1D5076CC -- C:\Users\All Users\Intuit\Quicken\Inet\Common\Localweb\Services\Services.css

< MD5 for: SERVICES.DAT >
[2014/02/20 01:17:07 | 000,004,182 | ---- | M] () MD5=78103C8B94CFA4006452BA74BE99DD51 -- C:\Users\Glens\AppData\Local\Temp\jrt\services.dat

< MD5 for: SERVICES.DLL >
[2011/01/21 11:03:46 | 004,493,080 | ---- | M] (SmartSound Software Inc.) MD5=953E89C12AA1E6E73B00DA8AB5819A30 -- C:\Program Files (x86)\SmartSound Software\Sonicfire Pro 5\Services.dll

< MD5 for: SERVICES.EXE >
[2009/07/13 20:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\SysNative\services.exe
[2009/07/13 20:39:37 | 000,328,704 | ---- | M] (Microsoft Corporation) MD5=24ACB7E5BE595468E3B9AA488B9B4FCB -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.exe

< MD5 for: SERVICES.EXE.MUI >
[2010/11/21 02:06:16 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 -- C:\Windows\SysNative\en-US\services.exe.mui
[2010/11/21 02:06:16 | 000,017,408 | ---- | M] (Microsoft Corporation) MD5=6507BF0DC2D1F5F32493C288EAA59277 -- C:\Windows\winsxs\amd64_microsoft-windows-s..ontroller.resources_31bf3856ad364e35_6.1.7600.16385_en-us_c5f238be3fa63468\services.exe.mui

< MD5 for: SERVICES.INI >
[2011/09/16 18:47:38 | 000,000,012 | ---- | M] () MD5=810C4D394B59FF7116A0CD6052286C41 -- C:\ProgramData\Intuit\Quicken\Inet\Common\Localweb\Services\Services.ini
[2011/09/16 18:47:38 | 000,000,012 | ---- | M] () MD5=810C4D394B59FF7116A0CD6052286C41 -- C:\Users\All Users\Intuit\Quicken\Inet\Common\Localweb\Services\Services.ini

< MD5 for: SERVICES.LNK >
[2009/07/13 23:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\Users\All Users\Microsoft\Windows\Start Menu\Programs\Administrative Tools\services.lnk
[2009/07/13 23:54:05 | 000,001,288 | ---- | M] () MD5=CA0D9F4743DFF86EBAF09D763139E958 -- C:\Users\Glens\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\services.lnk

< MD5 for: SERVICES.MOF >
[2009/06/10 15:44:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\SysNative\wbem\services.mof
[2009/06/10 15:44:06 | 000,002,866 | ---- | M] () MD5=26A11C895A7F0B6D32105EBE127D8500 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\services.mof

< MD5 for: SERVICES.MSC >
[2010/11/21 02:06:14 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysNative\en-US\services.msc
[2009/06/10 15:38:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysNative\services.msc
[2010/11/21 02:06:17 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysWOW64\en-US\services.msc
[2009/06/10 16:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\SysWOW64\services.msc
[2010/11/21 02:06:14 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\amd64_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_003408aa160fce5b\services.msc
[2009/06/10 15:38:36 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\amd64_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_2b58d44b5f6beb8a\services.msc
[2010/11/21 02:06:17 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-s..cessnapin.resources_31bf3856ad364e35_6.1.7600.16385_en-us_a4156d265db25d25\services.msc
[2009/06/10 16:21:09 | 000,092,745 | ---- | M] () MD5=7A1D35F59468B8118AF5B8E21DF78AE2 -- C:\Windows\winsxs\x86_microsoft-windows-servicessnapin_31bf3856ad364e35_6.1.7600.16385_none_cf3a38c7a70e7a54\services.msc

< MD5 for: SERVICES.PTXML >
[2009/07/13 15:16:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\SysNative\wdi\perftrack\Services.ptxml
[2009/07/13 15:16:17 | 000,001,061 | ---- | M] () MD5=640D7DD61B1CFA6C96F80F68F78CDFA7 -- C:\Windows\winsxs\amd64_microsoft-windows-s..s-servicecontroller_31bf3856ad364e35_6.1.7600.16385_none_2b54b20ee6fa07b1\Services.ptxml

< MD5 for: SVCHOST.EXE >
[2009/07/13 20:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\SysWOW64\svchost.exe
[2009/07/13 20:14:41 | 000,020,992 | ---- | M] (Microsoft Corporation) MD5=54A47F6B5E09A77E61649109C6A08866 -- C:\Windows\winsxs\x86_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_b591afc466a15356\svchost.exe
[2013/04/04 14:50:32 | 000,218,184 | ---- | M] () MD5=B4C6E3889BB310CA7E974A04EC6E46AC -- C:\Program Files (x86)\Malwarebytes' Anti-Malware\Chameleon\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\SysNative\svchost.exe
[2009/07/13 20:39:46 | 000,027,136 | ---- | M] (Microsoft Corporation) MD5=C78655BC80301D76ED4FEF1C1EA40A7D -- C:\Windows\winsxs\amd64_microsoft-windows-services-svchost_31bf3856ad364e35_6.1.7600.16385_none_11b04b481efec48c\svchost.exe

< MD5 for: USERINIT.EXE >
[2010/11/20 22:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\SysWOW64\userinit.exe
[2010/11/20 22:23:55 | 000,026,624 | ---- | M] (Microsoft Corporation) MD5=61AC3EFDFACFDD3F0F11DD4FD4044223 -- C:\Windows\winsxs\x86_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_de3024012ff21116\userinit.exe
[2010/11/20 22:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\SysNative\userinit.exe
[2010/11/20 22:24:28 | 000,030,720 | ---- | M] (Microsoft Corporation) MD5=BAFE84E637BF7388C96EF48D4D3FDD53 -- C:\Windows\winsxs\amd64_microsoft-windows-userinit_31bf3856ad364e35_6.1.7601.17514_none_3a4ebf84e84f824c\userinit.exe

< End of report >

Note: Extras.txt was not created by OTL.

IE will now open and function.

It looks like some of the work done today removed some programs installed by our mistake. but there are still the following 2 that I believe were installed in error. Should I uninstall them?
Perk Prize Panel 3/ 2/ 2014
EnhanceTronic EnhanceTronic 3/ 2/ 2014 2.27 MB 2014.02.26.051729

Looking back, our error was running a setup.exe that downloaded with the JRT.exe and that is what installed the extra programs.

Thank you for your help.
  • 0

#8
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts

It looks like some of the work done today removed some programs installed by our mistake. but there are still the following 2 that I believe were installed in error. Should I uninstall them?
Perk Prize Panel 3/ 2/ 2014
EnhanceTronic EnhanceTronic 3/ 2/ 2014 2.27 MB 2014.02.26.051729

The said tool does not do that--it so happens that there is still adware in your system and thus it re-installed several instances of itself again. Let's fix that. This will be quite a lot, but bear with me. :thumbsup:

  • Step 1

    Certain programs will hinder the cleaning process. As such, I ask that you uninstall all the below programs to ensure no such conflict arises. Note that you may choose to disable these instead. However, for a more hassle-free solution in the long run, I recommend removing them now and later re-installing them once I declare you clean.

    I advise you to uninstall all of following programs through Control Panel > Add or Remove Programs (Windows XP) or Control Panel > Programs and Features > Uninstall a Program (Windows Vista & Windows 7):

    Lavasoft Ad-Aware SE Personal
    SUPERAntiSpyware
If you are having difficulties, please tell me.
  • Step 2

    Your Google Chrome settings have been altered by malware. Please reset them by following 'this' guide.
  • Step 3

    Locate your copy of 'OTL by OldTimer'.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.

    Posted Image

  • Copy and paste the following into the Custom Scans/Fixes box:

    :OTL
    IE - HKLM\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...ms}&FORM=IE8SRC
    IE - HKCU\..\SearchScopes,DefaultScope = {014DB5FA-EAFB-4592-A95B-F44D3EE87FA9}
    SRV - [2014/02/26 00:18:56 | 000,111,912 | ---- | M] () [Auto | Stopped] -- C:\Program Files (x86)\EnhanceTronic\updateEnhanceTronic.exe -- (Update EnhanceTronic)
    [2014/03/02 18:33:00 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\EnhanceTronic
    [2014/03/02 18:32:14 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Perk Prize Panel
    O32 - AutoRun File - [2008/02/05 18:15:08 | 000,000,034 | ---- | M] () - Y:\autorun.inf -- [ NTFS ]
    O20:64bit: - AppInit_DLLs: (C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll) - File not found
    O2 - BHO: (Perk Prize Panel) - {47F3EB15-C230-4A0B-BE4B-D527FF483B48} - C:\Program Files (x86)\Perk Prize Panel\pp.dll ()
    FF - HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected]: C:\Program Files (x86)\Perk Prize Panel\FF\ [2014/03/02 18:32:14 | 000,000,000 | ---D | M]
    O4 - HKCU..\Run: [Dashlane] C:\Users\Glens\AppData\Roaming\Dashlane\Dashlane.exe ()
    [2014/02/21 04:46:02 | 000,001,915 | ---- | M] () -- C:\Users\Glens\Desktop\Dashlane.lnk
    
    :Files
    C:\Users\Glens\AppData\Roaming\Dashlane
    C:\Program Files (x86)\Perk Prize Panel
    C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk
    C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgfhihjicjofdejkbjgnjlaglaciobe
    C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg
    C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfaifkapfifnanhhiidacmhldddojchn
    C:\Program Files (x86)\EnhanceTronic
    
    :Commands
    [emptytemp]
    [resethosts]
    
  • Click Run Fix.
  • OTL will reboot your system. Allow it by clicking OK.
  • After the reboot, a Notepad window will appear, named MMDDYYYY_HHMMSS.log. Alternatively, you can find that log at C:\_OTL\MovedFiles\MMDDYYYY_HHMMSS.log.
  • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log in your next reply.
  • Step 4

    Run a free 'ESET Online Scan by ESET' by firstly saving the file to your desktop.

  • Double-click esetsmartinstaller_enu.exe. Accept the Terms of Use then click on Start.
  • Ensure the following settings are followed before clicking Start (you may or may not see the software warning at the very bottom):

    Posted Image

  • The virus signature database will begin to download. Wait for the scan to end--it may take several hours.
  • Upon completion, use Notepad to open and save C:\Program Files\ESET\EsetOnlineScanner\log.txt to your desktop.
  • Select Uninstall application on close and click Finish.
  • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log in your next reply.
  • Step 5

    Locate your copy of 'OTL by OldTimer'.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.
  • Ensure that the following settings are followed. Make sure all other windows are closed and let it run uninterrupted.

    Posted Image

  • Click Run Scan.
  • After a short while, two Notepad windows will appear, named OTL.txt and Extras.txt. Alternatively, you can also find these at your desktop.
  • Copy and paste (CTRL + A and CTRL + C) the content of these logs in your next reply.
  • Step 6

    Download 'SecurityCheck by screen317' and save it to your desktop.

  • Simply double-click the program icon to run it. It will ask for administrator privileges.
  • A black window will appear. Press any key to continue.
  • Wait for it to finish. It won't take long.
  • A log will automatically pop-up after once done.
  • Copy (CTRL + A and CTRL + C) and paste (CTRL + V) the content of the log in your next reply.
  • Logs to Post
In summary of the above, I will need you to post the following log(s):
  • MMDDYYYY_HHMMSS.log (OTL)
  • Extras.txt (OTL)
  • OTL.txt (OTL)
  • checkup.txt (SecurityCheck)
  • log.txt (ESET Online Scan)

  • 0

#9
vgphoto

vgphoto

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
Info that I would like to provide first: I have not checked today but the last I knew ar.voicefive.com was occurring during the use of Marketwatch.com and with no other activity. Also Dashlane is an important program to me it handles my passwords.

Todays activities:
I uninstalled SUPERAntiSpyware, but I could not find "Lavasoft Ad-Aware SE Personal" in the installed programs list.

OTL Log:
All processes killed
========== OTL ==========
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}\ not found.
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\SearchScopes\\DefaultScope| /E : value set successfully!
Service Update EnhanceTronic stopped successfully!
Service Update EnhanceTronic deleted successfully!
C:\Program Files (x86)\EnhanceTronic\updateEnhanceTronic.exe moved successfully.
C:\Program Files (x86)\EnhanceTronic folder moved successfully.
C:\Program Files (x86)\Perk Prize Panel\FF\chrome\content folder moved successfully.
C:\Program Files (x86)\Perk Prize Panel\FF\chrome folder moved successfully.
C:\Program Files (x86)\Perk Prize Panel\FF folder moved successfully.
C:\Program Files (x86)\Perk Prize Panel folder moved successfully.
Y:\autorun.inf moved successfully.
64bit-Registry value HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\\AppInit_Dlls:C:\PROGRA~2\SearchProtect\SearchProtect\bin\SPVC64Loader.dll deleted successfully.
Registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\{47F3EB15-C230-4A0B-BE4B-D527FF483B48}\ deleted successfully.
Registry key HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{47F3EB15-C230-4A0B-BE4B-D527FF483B48}\ deleted successfully.
File C:\Program Files (x86)\Perk Prize Panel\pp.dll not found.
Registry value HKEY_CURRENT_USER\software\mozilla\Firefox\Extensions\\[email protected] deleted successfully.
File C:\Program Files (x86)\Perk Prize Panel\FF\ not found.
Registry value HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\\Dashlane deleted successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\Dashlane.exe moved successfully.
C:\Users\Glens\Desktop\Dashlane.lnk moved successfully.
========== FILES ==========
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Websites folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Sync\uncompressAes folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Sync\tmp folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Sync\loadOnly folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Sync folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Settings\uncompressAes folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Settings\tmp folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Settings\loadOnly folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Settings folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\uncompressAes folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\tmp folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\loadOnly folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{E452DF7E-82D4-11E3-BFC7-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{DE6693D3-4FC5-11E3-96C4-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{C94952B6-7484-11E3-8DBC-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{BD565E7B-70C6-11E3-AC9B-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{B074C3BC-6835-11E3-86CB-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{AA63A38B-14E9-11E3-B7FB-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{8CBFD24C-6734-11E3-86CB-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{791A15FB-505C-11E3-96C4-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{5EA8E718-8B7B-11E3-AA25-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{5702B5B2-70C7-11E3-AC9B-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{551D0407-FAD8-11E2-BAE7-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{4EF64460-5B9E-11E3-87DD-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{472D80E0-1325-11E3-AB85-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{286CB7A8-6735-11E3-86CB-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{1FDD0D7B-14EB-11E3-B7FB-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{135C5705-132A-11E3-AB85-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{0D5EBCCD-6837-11E3-86CB-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files\{08FAA642-F223-11E2-A25C-D0DF9AA5D807} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase\Files folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Purchase folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Personaldata\uncompressAes folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Personaldata\tmp folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Personaldata\loadOnly folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected]\Personaldata folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles\[email protected] folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\profiles folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\ie folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\www\Onboarding\bootstrap\js folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\www\Onboarding\bootstrap\img folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\www\Onboarding\bootstrap\css folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\www\Onboarding\bootstrap folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\www\Onboarding folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\www\min folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\www\images\statusToolbar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\www\images\purchase folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\www\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\www folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\qss folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\popups\sharing folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\popups folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\Style folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\SettingsWindow folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\Popups folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\MainWindow\Services\SecurityDashboard folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\MainWindow\Services\DefaultScreens folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\MainWindow\Services\Credential folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\MainWindow\Services folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\MainWindow\LeftMenu folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\MainWindow folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\LoginView folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GettingStartedLite folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GettingStarted\videos folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GettingStarted\passwordsScan folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GettingStarted\numeros folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GettingStarted folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GenericControls\KWTextEdit folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GenericControls\KWScrollbar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GenericControls\KWRadioButton folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GenericControls\KWPushButton\imagebased folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GenericControls\KWPushButton\Icons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GenericControls\KWPushButton folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GenericControls\KWProgressBar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GenericControls\KWLineEdit folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GenericControls\KWComboBox folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GenericControls\KWCheckBox folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GenericControls folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources\GeneratedPasswords folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\NewResources folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\commun\plusminus folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\commun\icons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\commun folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\application\searchIcons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\application\passwordImportWindow folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\application\notifications folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\application\mainWindow\SecuredNotes folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\application\mainWindow\Credentials folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\application\mainWindow folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources\application folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\ressources folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\locale\ru folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\locale\it folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\locale\fr folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\locale\es folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\locale\en folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\locale\de folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\locale folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\license\license_files folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\license folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\config folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\certificates folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\x64 folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Prerequisites\x64 folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Prerequisites folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\config folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\popover folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images\toolbarbutton folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images\debugger\langs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images\debugger\flags folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images\debugger folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug\kwiftDebuggerTabs\unitaryTestsTabs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug\kwiftDebuggerTabs\learningTabs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug\kwiftDebuggerTabs\analyzeSenseTabs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug\kwiftDebuggerTabs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\utils folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\scripts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\gui folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\debug folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\contentScripts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\config folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\build folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Firefox_Extension folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin\Chrome_Extension folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\bin folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\background_cache folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\be folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\bc\as folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\bc folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\ax\ay folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\ax\ac folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\ax\ab folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\ax folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\aw folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\af\ap folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\af\ao folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\af\an folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\af\am folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\af\al folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\af\ak folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\af\aj folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\af\ai folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\af\ah folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\af\ag folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\af folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\aa\ac folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\aa\ab folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\aa folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\3rdParty\FF_nss_libs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData\3rdParty folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\applicationData folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\webCardsGenerator\images\providers folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\webCardsGenerator\images\coupons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\webCardsGenerator\images\cards\neutrals folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\webCardsGenerator\images\cards\creditCards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\webCardsGenerator\images\cards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\webCardsGenerator\images\banners folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\webCardsGenerator\images\banks folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\webCardsGenerator\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\webCardsGenerator folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\phonenumbers\closure\goog\useragent folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\phonenumbers\closure\goog\string folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\phonenumbers\closure\goog\proto2 folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\phonenumbers\closure\goog\object folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\phonenumbers\closure\goog\debug folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\phonenumbers\closure\goog\asserts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\phonenumbers\closure\goog\array folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\phonenumbers\closure\goog folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\phonenumbers\closure folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\phonenumbers folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\passwordWizard\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\passwordWizard folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\styles folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\scripts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\images\roundedContainer\shadowContainer folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\images\roundedContainer folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\images\global\scrollbar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\images\global folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\images\communs\creditCards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\images\communs\cards\neutrals folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\images\communs\cards\flags folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\images\communs\cards\banners folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\images\communs\cards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\images\communs\banks folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\images\communs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\images\buttons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\nativeDebug folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\styles folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\scripts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\images\roundedContainer\shadowContainer folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\images\roundedContainer folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\images\global\scrollbar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\images\global folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\images\communs\creditCards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\images\communs\cards\neutrals folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\images\communs\cards\flags folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\images\communs\cards\banners folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\images\communs\cards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\images\communs\banks folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\images\communs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\images\buttons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application\native folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656\application folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.4.0.56656 folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\www\Websites\tmp folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\www\Websites folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\www\Onboarding\bootstrap\js folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\www\Onboarding\bootstrap\img folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\www\Onboarding\bootstrap\css folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\www\Onboarding\bootstrap folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\www\Onboarding folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\www\min folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\www\images\statusToolbar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\www\images\purchase folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\www\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\www folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\Updates folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\qss folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\popups\sharing folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\popups folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\Style folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\SettingsWindow folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\Popups folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\MainWindow\Services\SecurityDashboard folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\MainWindow\Services\DefaultScreens folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\MainWindow\Services\Credential folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\MainWindow\Services folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\MainWindow\LeftMenu folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\MainWindow folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\LoginView folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GettingStartedLite folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GettingStarted\videos folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GettingStarted\passwordsScan folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GettingStarted\numeros folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GettingStarted folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GenericControls\KWTextEdit folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GenericControls\KWScrollbar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GenericControls\KWRadioButton folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GenericControls\KWPushButton\imagebased folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GenericControls\KWPushButton\Icons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GenericControls\KWPushButton folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GenericControls\KWProgressBar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GenericControls\KWLineEdit folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GenericControls\KWComboBox folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GenericControls\KWCheckBox folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GenericControls folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources\GeneratedPasswords folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\NewResources folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\commun\plusminus folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\commun\icons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\commun folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\application\searchIcons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\application\passwordImportWindow folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\application\notifications folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\application\mainWindow\SecuredNotes folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\application\mainWindow\Credentials folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\application\mainWindow folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources\application folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\ressources folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\locale\ru folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\locale\it folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\locale\fr folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\locale\es folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\locale\en folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\locale\de folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\locale folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\license\license_files folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\license folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\config folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\certificates folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\x64 folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Prerequisites\x64 folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Prerequisites folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\config folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\popover folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images\toolbarbutton folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images\debugger\langs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images\debugger\flags folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images\debugger folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug\kwiftDebuggerTabs\unitaryTestsTabs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug\kwiftDebuggerTabs\learningTabs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug\kwiftDebuggerTabs\analyzeSenseTabs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug\kwiftDebuggerTabs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\utils folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\scripts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\gui folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\debug folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\contentScripts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\config folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\build folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Firefox_Extension folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin\Chrome_Extension folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\bin folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\background_cache folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\be folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\bc\as folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\bc folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\ax\ay folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\ax\ac folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\ax\ab folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\ax folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\aw folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\Application\uncompressAes folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\Application\tmp folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\Application\loadOnly folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\Application folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\af\ap folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\af\ao folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\af\an folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\af\am folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\af\al folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\af\ak folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\af\aj folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\af\ai folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\af\ah folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\af\ag folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\af folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\aa\ac folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\aa\ab folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\aa folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\3rdParty\FF_nss_libs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData\3rdParty folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\applicationData folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\webCardsGenerator\images\providers folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\webCardsGenerator\images\coupons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\webCardsGenerator\images\cards\neutrals folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\webCardsGenerator\images\cards\creditCards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\webCardsGenerator\images\cards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\webCardsGenerator\images\banners folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\webCardsGenerator\images\banks folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\webCardsGenerator\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\webCardsGenerator folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\phonenumbers\closure\goog\useragent folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\phonenumbers\closure\goog\string folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\phonenumbers\closure\goog\proto2 folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\phonenumbers\closure\goog\object folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\phonenumbers\closure\goog\debug folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\phonenumbers\closure\goog\asserts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\phonenumbers\closure\goog\array folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\phonenumbers\closure\goog folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\phonenumbers\closure folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\phonenumbers folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\passwordWizard\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\passwordWizard folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\styles folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\scripts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\images\roundedContainer\shadowContainer folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\images\roundedContainer folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\images\global\scrollbar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\images\global folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\images\communs\creditCards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\images\communs\cards\neutrals folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\images\communs\cards\flags folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\images\communs\cards\banners folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\images\communs\cards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\images\communs\banks folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\images\communs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\images\buttons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\nativeDebug folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\styles folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\scripts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\images\roundedContainer\shadowContainer folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\images\roundedContainer folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\images\global\scrollbar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\images\global folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\images\communs\creditCards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\images\communs\cards\neutrals folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\images\communs\cards\flags folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\images\communs\cards\banners folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\images\communs\cards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\images\communs\banks folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\images\communs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\images\buttons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application\native folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783\application folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.3.3.52783 folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\www\Onboarding\bootstrap\js folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\www\Onboarding\bootstrap\img folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\www\Onboarding\bootstrap\css folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\www\Onboarding\bootstrap folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\www\Onboarding folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\www\min folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\www\images\statusToolbar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\www\images\purchase folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\www\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\www folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\qss folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\popups\sharing folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\popups folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\Style folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\SettingsWindow folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\Popups folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\MainWindow\Services\SecurityDashboard folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\MainWindow\Services\DefaultScreens folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\MainWindow\Services\Credential folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\MainWindow\Services folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\MainWindow\LeftMenu folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\MainWindow folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\LoginView folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GettingStartedLite folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GettingStarted\videos folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GettingStarted\passwordsScan folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GettingStarted\numeros folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GettingStarted folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GenericControls\KWTextEdit folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GenericControls\KWScrollbar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GenericControls\KWRadioButton folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GenericControls\KWPushButton\imagebased folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GenericControls\KWPushButton\Icons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GenericControls\KWPushButton folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GenericControls\KWProgressBar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GenericControls\KWLineEdit folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GenericControls\KWComboBox folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GenericControls\KWCheckBox folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GenericControls folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources\GeneratedPasswords folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\NewResources folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\commun\plusminus folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\commun\icons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\commun folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\application\searchIcons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\application\passwordImportWindow folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\application\notifications folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\application\mainWindow\SecuredNotes folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\application\mainWindow\Credentials folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\application\mainWindow folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources\application folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\ressources folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\locale\ru folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\locale\it folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\locale\fr folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\locale\es folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\locale\en folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\locale\de folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\locale folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\license\license_files folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\license folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\config folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\certificates folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Prerequisites folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\config folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\components folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\popover folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images\toolbarbutton folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images\debugger\langs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images\debugger\flags folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images\debugger folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\skin folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug\kwiftDebuggerTabs\unitaryTestsTabs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug\kwiftDebuggerTabs\learningTabs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug\kwiftDebuggerTabs\analyzeSenseTabs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug\kwiftDebuggerTabs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets\debug folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\widgets folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\utils folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\scripts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\gui folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\debug folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\contentScripts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content\config folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome\content folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\chrome folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f}\build folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension\{442718d9-475e-452a-b3e1-fb1ee16b8e9f} folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Firefox_Extension folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin\Chrome_Extension folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\bin folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\be folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\bc\as folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\bc folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\ax\ay folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\ax\ac folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\ax\ab folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\ax folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\aw folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\af\ap folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\af\ao folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\af\an folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\af\am folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\af\al folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\af\ak folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\af\aj folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\af\ai folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\af\ah folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\af\ag folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\af folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\aa\ac folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\aa\ab folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\aa folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\3rdParty\FF_nss_libs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData\3rdParty folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\applicationData folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\webCardsGenerator\images\providers folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\webCardsGenerator\images\coupons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\webCardsGenerator\images\cards\neutrals folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\webCardsGenerator\images\cards\creditCards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\webCardsGenerator\images\cards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\webCardsGenerator\images\banners folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\webCardsGenerator\images\banks folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\webCardsGenerator\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\webCardsGenerator folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\phonenumbers\closure\goog\useragent folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\phonenumbers\closure\goog\string folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\phonenumbers\closure\goog\proto2 folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\phonenumbers\closure\goog\object folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\phonenumbers\closure\goog\debug folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\phonenumbers\closure\goog\asserts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\phonenumbers\closure\goog\array folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\phonenumbers\closure\goog folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\phonenumbers\closure folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\phonenumbers folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\passwordWizard\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\passwordWizard folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\styles folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\scripts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\images\roundedContainer\shadowContainer folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\images\roundedContainer folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\images\global\scrollbar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\images\global folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\images\communs\creditCards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\images\communs\cards\neutrals folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\images\communs\cards\flags folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\images\communs\cards\banners folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\images\communs\cards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\images\communs\banks folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\images\communs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\images\buttons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\nativeDebug folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\styles folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\scripts folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\images\roundedContainer\shadowContainer folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\images\roundedContainer folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\images\global\scrollbar folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\images\global folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\images\communs\creditCards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\images\communs\cards\neutrals folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\images\communs\cards\flags folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\images\communs\cards\banners folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\images\communs\cards folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\images\communs\banks folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\images\communs folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\images\buttons folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native\images folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application\native folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689\application folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane\2.2.6.50689 folder moved successfully.
C:\Users\Glens\AppData\Roaming\Dashlane folder moved successfully.
File\Folder C:\Program Files (x86)\Perk Prize Panel not found.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0\_locales\en folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0\_locales folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0\RedirectPages folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0\images\Widgets folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0\images\StatusButton folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0\images\SafeBrowse folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0\images folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0\IdentitySafe folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk\2014.6.2.3_0 folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\mkfokfffehpeedafpekjeddnmnjhmcmk folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgfhihjicjofdejkbjgnjlaglaciobe\1.0_1 folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgfhihjicjofdejkbjgnjlaglaciobe\1.0_0 folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\jpgfhihjicjofdejkbjgnjlaglaciobe folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\2.4.0.53495_1\skin\popover folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\2.4.0.53495_1\skin\injectedJs\images\statusToolbar folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\2.4.0.53495_1\skin\injectedJs\images\purchase folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\2.4.0.53495_1\skin\injectedJs\images folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\2.4.0.53495_1\skin\injectedJs folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\2.4.0.53495_1\skin\icon folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\2.4.0.53495_1\skin folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\2.4.0.53495_1\content\scripts folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\2.4.0.53495_1\content\contentScripts folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\2.4.0.53495_1\content folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg\2.4.0.53495_1 folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\fdjamakpfbbddfjaooikfcpapjohcfmg folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfaifkapfifnanhhiidacmhldddojchn\1.0_0 folder moved successfully.
C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\cfaifkapfifnanhhiidacmhldddojchn folder moved successfully.
File\Folder C:\Program Files (x86)\EnhanceTronic not found.
========== COMMANDS ==========

[EMPTYTEMP]

User: All Users

User: Default
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Default User
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

User: Glens
->Temp folder emptied: 56533155 bytes
->Temporary Internet Files folder emptied: 58780631 bytes
->Java cache emptied: 0 bytes
->Google Chrome cache emptied: 819568 bytes
->Flash cache emptied: 0 bytes

User: Public

User: TEMP

User: Test Account

User: Test Share - Anna

User: UpdatusUser
->Temp folder emptied: 0 bytes
->Temporary Internet Files folder emptied: 0 bytes
->Flash cache emptied: 0 bytes

%systemdrive% .tmp files removed: 0 bytes
%systemroot% .tmp files removed: 0 bytes
%systemroot%\System32 .tmp files removed: 0 bytes
%systemroot%\System32 (64bit) .tmp files removed: 0 bytes
%systemroot%\System32\drivers .tmp files removed: 0 bytes
Windows Temp folder emptied: 6295318 bytes
%systemroot%\sysnative\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files folder emptied: 0 bytes
RecycleBin emptied: 32043 bytes

Total Files Cleaned = 117.00 mb

C:\Windows\System32\drivers\etc\Hosts moved successfully.
HOSTS file reset successfully

OTL by OldTimer - Version 3.2.69.0 log created on 03042014_102306

Files\Folders moved on Reboot...
C:\Users\Glens\AppData\Local\Temp\FXSAPIDebugLogFile.txt moved successfully.
File\Folder C:\Users\Glens\AppData\Local\Temp\SASFC83.tmp not found!
File\Folder C:\Users\Glens\AppData\Local\Temp\~DF0B1D384FA1FCDE13.TMP not found!
File\Folder C:\Users\Glens\AppData\Local\Temp\~DF221EEA826B8F2A82.TMP not found!
File\Folder C:\Users\Glens\AppData\Local\Temp\~DFADD9111D341AA932.TMP not found!
File\Folder C:\Users\Glens\AppData\Local\Temp\~DFC4899B4081F78155.TMP not found!
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\AntiPhishing\4A72F430-B40C-4D36-A068-CE33ADA5ADF9.dat moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\N7RYHMPL\page__gopid__2378586[1].htm moved successfully.
C:\Users\Glens\AppData\Local\Microsoft\Windows\Temporary Internet Files\counters.dat moved successfully.
C:\Windows\temp\wbxtra_03032014_091311.wbt moved successfully.

PendingFileRenameOperations files...

Registry entries deleted on Reboot...

Extras.txt from last run, step 5

OTL Extras logfile created on: 3/4/2014 10:09:08 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Glens\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

15.98 Gb Total Physical Memory | 11.10 Gb Available Physical Memory | 69.49% Memory free
31.96 Gb Paging File | 27.73 Gb Available in Paging File | 86.78% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1385.03 Gb Total Space | 792.82 Gb Free Space | 57.24% Space Free | Partition Type: NTFS
Drive D: | 12.13 Gb Total Space | 1.49 Gb Free Space | 12.26% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 189.21 Gb Free Space | 40.62% Space Free | Partition Type: NTFS
Drive O: | 931.51 Gb Total Space | 197.14 Gb Free Space | 21.16% Space Free | Partition Type: NTFS
Drive P: | 298.09 Gb Total Space | 71.80 Gb Free Space | 24.09% Space Free | Partition Type: NTFS
Drive Q: | 465.76 Gb Total Space | 93.60 Gb Free Space | 20.10% Space Free | Partition Type: NTFS
Drive R: | 596.17 Gb Total Space | 285.16 Gb Free Space | 47.83% Space Free | Partition Type: NTFS
Drive Y: | 298.09 Gb Total Space | 69.13 Gb Free Space | 23.19% Space Free | Partition Type: NTFS
Drive Z: | 931.51 Gb Total Space | 522.30 Gb Free Space | 56.07% Space Free | Partition Type: NTFS

Computer Name: GLENS-HP | User Name: Glens | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Extra Registry (SafeList) ==========


========== File Associations ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.html[@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)
.url[@ = InternetShortcut] -- C:\Windows\SysNative\rundll32.exe (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<extension>]
.cpl [@ = cplfile] -- C:\Windows\SysWow64\control.exe (Microsoft Corporation)
.html [@ = htmlfile] -- C:\Program Files\Internet Explorer\iexplore.exe (Microsoft Corporation)

========== Shell Spawning ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
InternetShortcut [open] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\ieframe.dll",OpenURL %l (Microsoft Corporation)
InternetShortcut [print] -- "C:\Windows\System32\rundll32.exe" "C:\Windows\System32\mshtml.dll",PrintHTML "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CC (64 Bit)\Bridge.exe "%L" (Adobe Systems Incorporated)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- "C:\Program Files\Internet Explorer\iexplore.exe" (Microsoft Corporation)

[HKEY_LOCAL_MACHINE\SOFTWARE\Classes\<key>\shell\[command]\command]
batfile [open] -- "%1" %*
cmdfile [open] -- "%1" %*
comfile [open] -- "%1" %*
cplfile [cplopen] -- %SystemRoot%\System32\control.exe "%1",%* (Microsoft Corporation)
exefile [open] -- "%1" %*
helpfile [open] -- Reg Error: Key error.
htmlfile [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
htmlfile [opennew] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
http [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
https [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
inffile [install] -- %SystemRoot%\System32\InfDefaultInstall.exe "%1" (Microsoft Corporation)
piffile [open] -- "%1" %*
regfile [merge] -- Reg Error: Key error.
scrfile [config] -- "%1"
scrfile [install] -- rundll32.exe desk.cpl,InstallScreenSaver %l
scrfile [open] -- "%1" /S
txtfile [edit] -- Reg Error: Key error.
Unknown [openas] -- %SystemRoot%\system32\rundll32.exe %SystemRoot%\system32\shell32.dll,OpenAs_RunDLL %1
Directory [Bridge] -- C:\Program Files\Adobe\Adobe Bridge CC (64 Bit)\Bridge.exe "%L" (Adobe Systems Incorporated)
Directory [cmd] -- cmd.exe /s /k pushd "%V" (Microsoft Corporation)
Directory [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [open] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Folder [explore] -- Reg Error: Value error.
Drive [find] -- %SystemRoot%\Explorer.exe (Microsoft Corporation)
Applications\iexplore.exe [open] -- "C:\Program Files\Internet Explorer\iexplore.exe" %1 (Microsoft Corporation)
CLSID\{871C5380-42A0-1069-A2EA-08002B30309D} [OpenHomePage] -- Reg Error: Value error.

========== Security Center Settings ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]
"cval" = 1

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Monitoring]

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]
"VistaSp1" = 28 4D B2 76 41 04 CA 01 [binary data]
"AntiVirusOverride" = 0
"AntiSpywareOverride" = 0
"FirewallOverride" = 0

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc\Vol]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Security Center\Svc]

========== Firewall Settings ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\PublicProfile]
"EnableFirewall" = 1
"DisableNotifications" = 0

========== Authorized Applications List ==========


========== Vista Active Open Ports Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{10C4A4DC-DC10-4D70-8DEE-4B5D2B3B2248}" = lport=808 | protocol=6 | dir=in | svc=nettcpactivator | app=c:\windows\microsoft.net\framework64\v4.0.30319\smsvchost.exe |
"{17DF9A50-7C21-4E8B-B75D-7BFF2DC0EEBD}" = lport=5353 | protocol=17 | dir=in | name=mdns-sd/bonjour |
"{2531E394-7802-4806-B16B-9691C08621AA}" = lport=rpc-epmap | protocol=6 | dir=in | svc=rpcss | [email protected],-28539 |
"{26AD27F6-367B-4F65-AE6D-C1F55F0DCA92}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=c:\windows\system32\svchost.exe |
"{34237F9D-6EBA-4CDC-96E4-D727DB0311ED}" = rport=139 | protocol=6 | dir=out | app=system |
"{36B3E069-8D6A-4990-8476-9131D7AC86A3}" = lport=2869 | protocol=6 | dir=in | name=windows live communications platform (upnp) |
"{3BEC25DF-B5A1-416F-8348-7872689584C2}" = lport=2869 | protocol=6 | dir=in | app=system |
"{55BA758B-110D-4CEC-92BA-D92462B9DB3B}" = lport=rpc | protocol=6 | dir=in | svc=spooler | app=%systemroot%\system32\spoolsv.exe |
"{5EEAEDB1-C97D-4C46-8EAA-7FFC8629BF44}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{65702AF9-A5FA-4FAE-ACC2-7C0A5A264E12}" = lport=7288 | protocol=6 | dir=in | name=tivo hme host: port %d |
"{68B5C7A1-438D-4417-9FBC-EC1F7FD93EAD}" = lport=1900 | protocol=17 | dir=in | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{69C3E402-8E95-4633-9DC8-2B67A73F87A8}" = lport=139 | protocol=6 | dir=in | app=system |
"{7335424F-8CA3-48C0-B2CC-97D93BB4D343}" = lport=138 | protocol=17 | dir=in | app=system |
"{7A9966D6-46E2-4B27-8586-10BC3096D4E9}" = rport=137 | protocol=17 | dir=out | app=system |
"{7B557985-E58D-4421-A927-DB50955D3158}" = lport=1900 | protocol=17 | dir=in | name=windows live communications platform (ssdp) |
"{8347575E-9597-49CA-8339-69D7EC3CE478}" = rport=5355 | protocol=17 | dir=out | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{8B56B762-68FE-4252-8F1A-17AB682354E8}" = rport=445 | protocol=6 | dir=out | app=system |
"{92538515-7061-4637-9C1E-2AA4ABA5A60E}" = lport=445 | protocol=6 | dir=in | app=system |
"{990C56DB-E663-49E8-8EB6-530391342FE7}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{9E872581-3ACA-413A-8AC9-929C9CF27350}" = lport=2869 | protocol=6 | dir=in | app=system |
"{ACDEA007-917D-492D-AD28-A1A3C03846CE}" = lport=2177 | protocol=6 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{B3A95D32-8A07-4105-AF0B-47455D9BD90F}" = rport=1900 | protocol=17 | dir=out | svc=ssdpsrv | app=%systemroot%\system32\svchost.exe |
"{C1DDD1DF-42D9-4046-91BC-1B03D319FE5B}" = lport=10243 | protocol=6 | dir=in | app=system |
"{CC3FE6B8-C84B-4CAD-8BB3-44F0E6BC2E84}" = lport=5355 | protocol=17 | dir=in | svc=dnscache | app=%systemroot%\system32\svchost.exe |
"{E841AFC2-0EBE-49C6-A2B3-9EFD7516D820}" = lport=2177 | protocol=17 | dir=in | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F2353F56-C709-4680-8092-E4ACC1385A23}" = rport=10243 | protocol=6 | dir=out | app=system |
"{F9630986-BA1D-4962-838C-55B923F9791B}" = rport=2177 | protocol=6 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{F9F8C607-361A-4255-BECF-EEA50D9C6B0A}" = rport=2177 | protocol=17 | dir=out | svc=qwave | app=%systemroot%\system32\svchost.exe |
"{FE2D3713-42CD-4A4F-85B9-A7F745674D5D}" = rport=138 | protocol=17 | dir=out | app=system |
"{FE4853B9-2EF3-4C71-8A0B-301B921F57F9}" = lport=137 | protocol=17 | dir=in | app=system |

========== Vista Active Application Exception List ==========

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\FirewallRules]
"{03EAD8A8-DE6C-4D3B-95A2-A63284107E30}" = protocol=17 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{0D7DE0AE-72BE-4031-8770-5514DFC32282}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{0ECD059D-6A3A-4C82-808A-930E52A1EE22}" = protocol=6 | dir=in | app=c:\program files (x86)\microsoft office\office12\onenote.exe |
"{0F8C7235-A6AD-470C-8CC8-24C094D6471D}" = protocol=17 | dir=in | app=c:\program files (x86)\tivo\desktop\tivobeacon.exe |
"{10EF6257-1FBB-4976-AC5B-AEF287B7268A}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\mediasmart\roxionow\rnow.exe |
"{11EABBE5-E3FC-472B-BBB2-12AB183B32DF}" = protocol=1 | dir=out | [email protected],-28544 |
"{12DF85FC-76C0-4C7B-A137-81B2B2A0D22F}" = protocol=17 | dir=in | app=c:\program files (x86)\tivo\desktop\curl.exe |
"{182602AE-3C39-43A0-ACE3-924504CAF4D4}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{21644CE1-5ED6-4233-A0B5-287C893B4140}" = protocol=17 | dir=in | app=c:\users\glens\appdata\roaming\dropbox\bin\dropbox.exe |
"{25D6C66D-35B0-43BB-A720-4A67C38DD634}" = dir=in | app=c:\program files (x86)\windows live\messenger\msnmsgr.exe |
"{2780DE3F-3DC6-4E50-AB4C-E828C59AC7F8}" = protocol=17 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |
"{2FFCEE63-42C7-48BF-9713-1795302E6F05}" = protocol=6 | dir=out | app=c:\program files (x86)\hewlett-packard\remote graphics receiver\rgreceiver.exe |
"{303D02AA-2F43-450A-9ACA-FA56E001D879}" = protocol=17 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{34397604-097D-4BE7-A5F5-C74D2603B20E}" = protocol=17 | dir=in | app=c:\program files (x86)\tivo\desktop\tivoserver.exe |
"{388EBCCC-51A0-4B55-BD47-7DC9AD995A18}" = protocol=6 | dir=in | app=c:\program files (x86)\tivo\desktop\tivoserver.exe |
"{38C03A14-2EE9-4501-BD74-D4DAB3EA2692}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{3CAFB893-F526-4D83-877D-51178E74BCF8}" = protocol=6 | dir=in | app=c:\program files (x86)\tivo\desktop\tivobeacon.exe |
"{435021CA-972B-4192-A676-00D0E433DB00}" = protocol=6 | dir=in | app=c:\program files (x86)\epsonnet\epsonnet setup\tool10\eneasyapp.exe |
"{4488BDFE-3EB7-4EAD-A9D6-B2C5E3544090}" = protocol=17 | dir=out | app=c:\program files (x86)\hewlett-packard\hp linkup\hp linkup viewer.exe |
"{44DC206C-A0E4-4238-B4E3-FEC8DA741A5F}" = protocol=17 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{44E20A46-6D1C-424D-AB75-04A099B1B72F}" = dir=in | app=c:\program files (x86)\windows live\mesh\moe.exe |
"{45475EC7-1131-4CF1-A04B-B90E0E00AD91}" = protocol=58 | dir=out | [email protected],-28546 |
"{46B7191D-CBCC-4D1D-AD5D-3E2DA1C455C7}" = protocol=6 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{4DFB6AAC-5C36-4342-8BF1-25129B9E8296}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{526B9DF1-507B-492D-BBE9-B27F7FA4D8F5}" = protocol=6 | dir=in | app=c:\users\glens\appdata\roaming\dropbox\bin\dropbox.exe |
"{5FC97C4C-FA00-4E91-91AC-F2C255977260}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{69E4E4DE-BB07-4CFB-81C2-C727BD4695D5}" = protocol=17 | dir=in | app=c:\program files (x86)\hewlett-packard\hp linkup\hp linkup viewer.exe |
"{6D701E4D-3C73-450F-B59D-6A50EBB5933F}" = protocol=58 | dir=in | [email protected],-28545 |
"{70A9E8AF-BD7C-4D21-BA45-C25C20F18B0D}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{75A7124E-9A1E-45A6-AF87-28076AA1F6B6}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpdevicedetection3.exe |
"{75DC93AE-10C5-4A5E-937C-1805F36CB6D8}" = dir=in | app=c:\program files (x86)\softland\backup4all professional 4\b4acmd.exe |
"{77775D5B-6F24-4BB2-96C1-877476B08A27}" = protocol=6 | dir=in | app=c:\program files (x86)\tivo\desktop\tivotransfer.exe |
"{79B0CBFF-A8B2-4139-B1A9-B12F07F81C86}" = protocol=17 | dir=in | app=c:\program files (x86)\epsonnet\epsonnet setup\tool10\eneasyapp.exe |
"{7E5EF4E8-700D-4819-A6D0-B7C923CF1485}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmplayer.exe |
"{7E845FF7-8831-444D-B7E5-27C1631E141D}" = protocol=6 | dir=in | app=c:\program files (x86)\tivo\desktop\tivodiag.exe |
"{7E92051D-D3F3-4F62-A9DA-31C5CE187C0C}" = dir=in | app=c:\program files (x86)\common files\apple\apple application support\webkit2webprocess.exe |
"{8B10A99F-DA93-4B25-A062-18D6A42221C9}" = protocol=6 | dir=in | app=c:\program files\bonjour\mdnsresponder.exe |
"{930768EB-4897-40A1-8B00-3F4FE6C4472A}" = protocol=17 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{9C04A427-1976-4A30-9D0B-9A59DC03B6C3}" = protocol=17 | dir=in | app=c:\program files (x86)\tivo\desktop\tivodesktop.exe |
"{A8C2F2E1-B973-4461-9C40-A68CFD7FCD46}" = protocol=6 | dir=in | app=c:\program files (x86)\roxio\roxionow player\rnowshell.exe |
"{B41A58A1-1B00-4882-888C-D93F357F354F}" = protocol=6 | dir=in | app=c:\program files (x86)\hewlett-packard\remote graphics receiver\rgreceiver.exe |
"{B6D048F6-95AF-4C98-975C-785AE024E97A}" = protocol=17 | dir=in | app=%programfiles%\windows media player\wmpnetwk.exe |
"{B974D509-AB7D-4AD2-904F-5F101B1CED52}" = protocol=6 | dir=in | app=c:\program files (x86)\bonjour\mdnsresponder.exe |
"{C1E75E1C-CEE5-4231-9BF8-8EA054022B2C}" = protocol=17 | dir=in | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{C4D87EDB-EC27-4241-A0D7-C7B4122EC92D}" = protocol=6 | dir=out | app=system |
"{C576E296-06ED-4511-A73B-EAD1E8371E11}" = protocol=6 | dir=out | app=%programfiles%\windows media player\wmplayer.exe |
"{C858905C-71A9-4DBE-B93C-F8673DA2C342}" = protocol=17 | dir=out | app=%programfiles%\windows media player\wmpnetwk.exe |
"{C8CD0899-779F-40A5-90EA-EB82826592B3}" = dir=in | app=c:\program files (x86)\softland\backup4all professional 4\backup4all.exe |
"{CE557C1A-A233-4927-81B1-08ACAD97E81A}" = dir=in | app=c:\program files (x86)\itunes\itunes.exe |
"{CE905925-75B4-4954-9AA1-4A7E92D4C544}" = protocol=6 | dir=out | app=%programfiles(x86)%\windows media player\wmplayer.exe |
"{CFA2B1F9-468A-4C5C-A3D7-97863983EF4F}" = dir=in | app=c:\program files (x86)\hewlett-packard\hp support framework\resources\hpwarrantycheck\hpwarrantychecker.exe |
"{D4C13C06-5C70-41AF-94EF-DF6C7230AE2C}" = protocol=17 | dir=in | app=c:\program files (x86)\tivo\desktop\tivotransfer.exe |
"{DD95CC7A-77E3-47C4-B358-ACFA64CDD6D9}" = protocol=17 | dir=in | app=c:\program files (x86)\tivo\desktop\tivodiag.exe |
"{DF97A3A1-5D0B-44E1-BC85-CC64C4D295A9}" = protocol=58 | dir=out | [email protected],-503 |
"{E3C47B81-A7FA-470D-A5CE-E21A6A5E9125}" = protocol=58 | dir=in | app=system |
"{E90C2E2C-5D4C-422F-B3CD-342F12D874CF}" = protocol=6 | dir=out | svc=upnphost | app=%systemroot%\system32\svchost.exe |
"{F13B3794-B9F3-407A-9629-BBF53C612B5C}" = dir=in | app=c:\program files (x86)\windows live\contacts\wlcomm.exe |
"{F31BD160-7B4F-413C-A166-4848883A7A5F}" = protocol=6 | dir=in | app=c:\program files (x86)\tivo\desktop\tivodesktop.exe |
"{F8755ED6-2FF3-4470-8196-B8D22D1EAC3E}" = protocol=6 | dir=in | app=c:\program files (x86)\tivo\desktop\curl.exe |
"{FB63991B-567E-4931-B613-FCDAC72AC421}" = protocol=1 | dir=in | [email protected],-28543 |
"TCP Query User{FFBBC4A6-7B83-44C9-8A16-50A30164301F}C:\program files (x86)\pinnacle\studio 15\programs\studio.exe" = protocol=6 | dir=in | app=c:\program files (x86)\pinnacle\studio 15\programs\studio.exe |
"UDP Query User{CC49C63A-6145-42F3-B553-0FEBD40422FB}C:\program files (x86)\pinnacle\studio 15\programs\studio.exe" = protocol=17 | dir=in | app=c:\program files (x86)\pinnacle\studio 15\programs\studio.exe |

========== HKEY_LOCAL_MACHINE Uninstall List ==========

64bit: [HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{054EF02F-95D8-48F4-9EEB-2F9CE3072ED8}" = AuthenTec TrueAPI
"{071c9b48-7c32-4621-a0ac-3f809523288f}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{15D07D6F-E4CC-41D9-88A3-94115E5E5A10}" = Desktop Restore
"{1B8ABA62-74F0-47ED-B18C-A43128E591B8}" = Windows Live ID Sign-in Assistant
"{1D8E6291-B0D5-35EC-8441-6616F567A0F7}" = Microsoft Visual C++ 2010 x64 Redistributable - 10.0.40219
"{1E9FC118-651D-4934-97BE-E53CAE5C7D45}" = Microsoft_VC80_MFCLOC_x86_x64
"{237D687E-9E50-4A30-B810-262764CC491B}" = Garmin Communicator Plugin x64
"{26A24AE4-039D-4CA4-87B4-2F86417017FF}" = Java 7 Update 17 (64-bit)
"{2856A1C2-70C5-4EC3-AFF7-E5B51E5530A2}" = HP Client Services
"{2EF5D87E-B7BD-458F-8428-E4D0B8B4E65C}" = Apple Mobile Device Support
"{436E0B79-2CFB-4E5F-9380-E17C1B25D0C5}" = Bluetooth by hp
"{4569AD91-47F4-4D9E-8FC9-717EC32D7AE1}" = Microsoft_VC80_CRT_x86_x64
"{4B6C7001-C7D6-3710-913E-5BC23FCE91E6}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.4148
"{5FCE6D76-F5DC-37AB-B2B8-22AB8CEDB1D4}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.6161
"{656DEEDE-F6AC-47CA-A568-A1B4E34B5760}" = Windows Live Remote Service Resources
"{6ce5bae9-d3ca-4b99-891a-1dc6c118a5fc}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{6DE721A5-5E89-4D74-994C-652BB3C0672E}" = Pinnacle Video Driver
"{6E3610B2-430D-4EB0-81E3-2B57E8B9DE8D}" = Bonjour
"{7DEBE4EB-6B40-3766-BB35-5CBBC385DA37}" = Microsoft .NET Framework 4.5.1
"{8220EEFE-38CD-377E-8595-13398D740ACE}" = Microsoft Visual C++ 2008 Redistributable - x64 9.0.30729.17
"{847B0532-55E3-4AAF-8D7B-E3A1A7CD17E5}" = Windows Live Remote Client Resources
"{8557397C-A42D-486F-97B3-A2CBC2372593}" = Microsoft_VC90_ATL_x86_x64
"{89F4137D-6C26-4A84-BDB8-2E5A4BB71E00}" = Microsoft Silverlight
"{90120000-002A-0000-1000-0000000FF1CE}" = Microsoft Office Office 64-bit Components 2007
"{90120000-002A-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit MUI (English) 2007
"{90120000-0116-0409-1000-0000000FF1CE}" = Microsoft Office Shared 64-bit Setup Metadata MUI (English) 2007
"{925D058B-564A-443A-B4B2-7E90C6432E55}" = Microsoft_VC80_ATL_x86_x64
"{92A3CA0D-55CD-4C5D-BA95-5C2600C20F26}" = Microsoft_VC90_CRT_x86_x64
"{92FB6C44-E685-45AD-9B20-CADF4CABA132} - 1033" = Microsoft .NET Framework 4.5.1
"{95120000-00B9-0409-1000-0000000FF1CE}" = Microsoft Application Error Reporting
"{A472B9E4-0AFF-4F7B-B25D-F64F8E928AAB}" = Microsoft_VC90_MFC_x86_x64
"{a9264802-8a7a-40fe-a135-5c6d204aed7a}.sdb" = Internet Explorer (Enable DEP)
"{ad8a2fa1-06e7-4b0d-927d-6e54b3d31028}" = Microsoft Visual C++ 2005 Redistributable (x64)
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.3DVision" = NVIDIA 3D Vision Driver 314.22
"{B2FE1952-0186-46c3-BAEC-A80AA35AC5B8}_Display.ControlPanel" = NVIDIA Control Panel 314.22
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Driver" = NVIDIA Graphics Driver 314.22
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.NVIRUSB" = NVIDIA 3D Vision Controller Driver 314.22
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.PhysX" = NVIDIA PhysX System Software 9.12.1031
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_Display.Update" = NVIDIA Update 1.12.12
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_HDAudio.Driver" = NVIDIA HD Audio Driver 1.3.23.1
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_installer" = NVIDIA Install Application
"{B2FE1952-0186-46C3-BAEC-A80AA35AC5B8}_NVIDIA.Update" = NVIDIA Update Components
"{BCA9334F-B6C9-4F65-9A73-AC5A329A4D04}" = PlayReady PC Runtime amd64
"{C8C1BAD5-54E6-4146-AD07-3A8AD36569C3}" = Microsoft_VC80_MFC_x86_x64
"{CC4D56B7-6F18-470B-8734-ABCD75BCF4F1}" = HP Auto
"{CD95F661-A5C4-44F5-A6AA-ECDD91C240C7}" = WinZip 16.0
"{D07A61E5-A59C-433C-BCBD-22025FA2287B}" = Windows Live Language Selector
"{D601CEAD-2E4F-4BBB-85CC-C29A4CE6A3C0}" = iTunes
"{D79A02E9-6713-4335-9668-AAC7474C0C0E}" = HP Vision Hardware Diagnostics
"{DA54F80E-261C-41A2-A855-549A144F2F59}" = Windows Live MIME IFilter
"{DF6D988A-EEA0-4277-AAB8-158E086E439B}" = Windows Live Remote Client
"{E02A6548-6FDE-40E2-8ED9-119D7D7E641F}" = Windows Live Remote Service
"98157A226B40B173301B0F53C8E98C47805D5152" = Windows Driver Package - Garmin (grmnusb) GARMIN Devices (04/19/2012 2.3.1.0)
"CCleaner" = CCleaner
"Easy Duplicate Finder 4_is1" = EasyDuplicateFinder v4.4
"EnhanceTronic" = EnhanceTronic
"EPSON Printer and Utilities" = EPSON Printer Software
"Epson Stylus Photo R2000" = Epson Stylus Photo R2000 Printer Uninstall
"Logitech Unifying" = Logitech Unifying Software 2.00
"Pen Tablet Driver" = Bamboo
"sp6" = Logitech SetPoint 6.32
"WinRAR archiver" = WinRAR 4.10 beta 3 (64-bit)

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"{00FE2935-FB56-4410-AB5F-D6E70C1771D2}" = Garmin WebUpdater
"{00FF4EB6-6AAC-4E9D-A60A-8F388691BB27}" = HP SimplePass PE 2011
"{01DC28DE-5E5E-4B4F-BA87-B89518181FC5}" = WeatherLink 5.5.1
"{033E378E-6AD3-4AD5-BDEB-CBD69B31046C}" = Microsoft_VC90_ATL_x86
"{05181A78-3BA6-4B63-BCE8-888A4BCAACFA}" = Creative Pack Volume 1
"{0657DE52-8F5C-4073-B70C-ED4F3F7FA076}" = PlayMemories Home
"{065F384A-5C64-4532-814A-A24BA5374503}" = WinDFT
"{07FA4960-B038-49EB-891B-9F95930AA544}" = HP Customer Experience Enhancements
"{08C8666B-C502-4AB3-B4CB-D74AC42D14FE}" = Nero BackItUp 10 Help (CHM)
"{08D2E121-7F6A-43EB-97FD-629B44903403}" = Microsoft_VC90_CRT_x86
"{0A1E0BDA-5E8F-436d-8BE5-7E97C5CB899D}" = Quicken 2012
"{0B0F231F-CE6A-483D-AA23-77B364F75917}" = Windows Live Installer
"{0EDEB615-1A60-425E-8306-0E10519C7B55}" = RoxioNow Player
"{0F3647F8-E51D-4FCC-8862-9A8D0C5ACF25}" = Microsoft_VC80_ATL_x86
"{0FDA9ECA-6DA3-480E-B7A9-76F353AF6B6C}" = ScoreFitter Volumes 1-2
"{120262A6-7A4B-4889-AE85-F5E5688D3683}" = HP MovieStore
"{1362E602-9625-42D3-B57F-CDA9D26F9DA8}" = Pinnacle Studio 15
"{15FEDA5F-141C-4127-8D7E-B962D1742728}" = Adobe Photoshop CS5
"{16987E99-C95C-4513-9239-7B44A0A71DB5}" = Nero SoundTrax 10 Help (CHM)
"{16FC3056-90C0-4757-8A68-64D8DA846ADA}" = Remote Graphics Receiver
"{178D71F4-DFB1-40EC-9D95-326FD8A3E7A0}" = Motion Graphics Toolkit for Studio
"{18455581-E099-4BA8-BC6B-F34B2F06600C}" = Google Toolbar for Internet Explorer
"{18A8E78B-9EF2-496E-B310-BCD8E4C1DAB3}" = iSEEK AnswerWorks English Runtime
"{19BA08F7-C728-469C-8A35-BFBD3633BE08}" = Windows Live Movie Maker
"{1D273D91-D7D5-4036-8B84-EB4615FF5F81}" = SmartSound Sonicfire Pro 5
"{1EABDDCB-B788-4FD2-BA76-23472D8DD1D6}" = EPSON Easy Photo Print
"{1EC083EE-5B76-4A2A-B95A-CAF460AA29D6}" = Adobe Touch App Plugins
"{1F1C2DFC-2D24-3E06-BCB8-725134ADF989}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.4148
"{1F6AB0E7-8CDD-4B93-8A23-AA9EB2FEFCE4}" = Junk Mail filter update
"{1FBAE18D-4DE4-47AA-83EC-D1B046F262DC}" = PDF Settings CC
"{200FEC62-3C34-4D60-9CE8-EC372E01C08F}" = Windows Live SOXE Definitions
"{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"{2318C2B1-4965-11d4-9B18-009027A5CD4F}" = Google Toolbar for Internet Explorer
"{237CCB62-8454-43E3-B158-3ACD0134852E}" = High-Definition Video Playback 10
"{2436F2A8-4B7E-4B6C-AE4E-604C84AA6A4F}" = Nero Core Components 10
"{244FD30F-63F1-49B9-9D98-1150FF4FFCB1}" = Adobe Extension Manager CC
"{277C1559-4CF7-44FF-8D07-98AA9C13AABD}" = Nero Multimedia Suite 10
"{2902F983-B4C1-44BA-B85D-5C6D52E2C441}" = Windows Live Mesh ActiveX Control for Remote Connections
"{2A88F1BF-7041-4E42-84B1-6B4ACB83AC64}" = EPSON Scan Assistant
"{2D99B50E-431D-4AA8-85C1-172A6F8BCF09}" = Adobe Photoshop CC
"{2FA94A64-C84E-49d1-97DD-7BF06C7BBFB2}.WildTangent Games App" = Update Installer for WildTangent Games App
"{329411A0-19F3-4740-874F-17400B126F27}" = Nero Vision 10 Help (CHM)
"{3336F667-9049-4D46-98B6-4C743EEBC5B1}" = Windows Live Photo Gallery
"{33643918-7957-4839-92C7-EA96CB621A98}" = Nero Express 10 Help (CHM)
"{33d1fd90-4274-48a1-9bc1-97e33d9c2d6f}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.61030
"{34490F4E-48D0-492E-8249-B48BECF0537C}" = Nero DiscSpeed 10
"{34F4D9A4-42C2-4348-BEF4-E553C84549E7}" = Windows Live Photo Gallery
"{359F8007-6486-429C-A8C5-D67F6897C88C}" = Adobe Bridge CC (64 Bit)
"{3AB18A98-082D-41A1-B269-7FA8AD3AA30C}" = Garmin Express Tray
"{3D5D6CFC-3097-425A-8D8F-7EAF5D57641D}" = Garmin USB Drivers
"{3E31400D-274E-4647-916C-2CACC3741799}" = EpsonNet Print
"{3EE9BCAE-E9A9-45E5-9B1C-83A4D357E05C}" = eReg
"{40A66DF6-22D3-44B5-A7D3-83B118A2C0DC}" = Norton Online Backup
"{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"{41A12FFC-89E9-4743-A51E-00975CA31F40}" = Adobe Exchange Panel
"{4220E523-EDE1-449F-83F5-8267D20E1ED0}" = Maxtor Manager
"{42C8B7DF-FEB0-4D51-B169-506B6BEC5797}" = Nero 10 Menu TemplatePack 1
"{43FBAB46-5969-4200-9958-1FF81FEE506F}" = Nero 10 Movie ThemePack 1
"{44B2A0AB-412E-4F8C-B058-D1E8AECCDFF5}" = Recovery Manager
"{45A1BF92-700A-4408-B95E-79F462E3D67D}" = Studio 11 Bonus DVD
"{46CBBDF8-55B5-40DB-B459-7B848394309C}" = EPSON File Manager
"{46F044A5-CE8B-4196-984E-5BD6525E361D}" = Apple Application Support
"{48F22622-1CC2-4A83-9C1E-644DD96F832D}" = EPSON Event Manager
"{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"{4CF172C5-F121-41FA-B0B0-0D49840BF003}" = Filmmaker's Toolkit for Studio
"{4D090F70-6F08-4B60-9357-A1DFD4458F09}" = Microsoft Mathematics
"{4D2A6330-2F8B-11E3-9C40-B8AC6F97B88E}" = Google Earth
"{4E839090-3B68-436A-B3CF-A2A08C38DD26}" = TiVo Desktop 2.8.3
"{555868C6-49FB-484F-BB43-8980651A1B00}" = Nero BurnRights 10 Help (CHM)
"{579684A4-DDD5-4CA3-9EA8-7BE7D9593DB4}" = Windows Live UX Platform Language Pack
"{5ED7CD44-1A33-4B36-BA09-0B55FE82AF95}" = Garmin MapInstall
"{6297487E-3778-4F72-B458-55690418DB98}" = Adobe ExtendScript Toolkit CC
"{635FED5B-2C6D-49BE-87E6-7A6FCD22BC5A}" = Microsoft_VC90_MFC_x86
"{63AA3EAB-23BB-48B2-9AD0-44F878075604}" = Nero 10 Menu TemplatePack Basic
"{647BB978-2876-487B-9B0E-FDB73F0EA4A2}" = Garmin Communicator Plugin
"{65153EA5-8B6E-43B6-857B-C6E4FC25798A}" = Intel® Management Engine Components
"{65BB0407-4CC8-4DC7-952E-3EEFDF05602A}" = Nero Update
"{66049135-9659-4AAD-9169-9CCA269EBB3E}" = Nero InfoTool 10 Help (CHM)
"{67EDD823-135A-4D59-87BD-950616D6E857}" = EPSON Copy Utility 3
"{682B3E4F-696A-42DE-A41C-4C07EA1678B4}" = Windows Live SOXE
"{6DFB899F-17A2-48F0-A533-ED8D6866CF38}" = Nero Control Center 10
"{6F340107-F9AA-47C6-B54C-C3A19F11553F}" = Hewlett-Packard ACLM.NET v1.2.2.3
"{6F50C41C-6CFB-49E1-AF91-E1AACDE24FBA}" = Garmin City Navigator North America NT 2012.30 Update
"{6f60b921-2ae3-43fe-a6fb-ad849bd91451}" = Garmin Express
"{70550193-1C22-445C-8FA4-564E155DB1A7}" = Nero Express 10
"{70B446D1-E03B-4ab0-9B3C-0832142C9AA8}.WildTangent Games App-hp" = WildTangent Games App (HP Games)
"{70F19404-B96C-4EBB-AD2B-3574F8736197}" = Nero 10 Movie ThemePack 2
"{710f4c1c-cc18-4c49-8cbf-51240c89a1a2}" = Microsoft Visual C++ 2005 Redistributable
"{7299052b-02a4-4627-81f2-1818da5d550d}" = Microsoft Visual C++ 2005 Redistributable
"{74619A00-3DE7-4487-A42D-5075DD8BD683}" = Garmin City Navigator North America NT 2014.20 Update
"{74E5BA31-CB34-4388-BC7F-91DC8830AABC}" = ScoreFitter Volume 2
"{7A295D8F-484B-4FFB-89AB-C1FD497591FE}" = Nero WaveEditor 10 Help (CHM)
"{7A5D731D-B4B3-490E-B339-75685712BAAB}" = Nero Burning ROM 10
"{7F2A11F4-EAE8-4325-83EC-E3E99F85169E}" = HP Support Information
"{80956555-A512-4190-9CAD-B000C36D6B6B}" = Windows Live Messenger
"{820B6609-4C97-3A2B-B644-573B06A0F0CC}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729
"{837b34e3-7c30-493c-8f6a-2b0f04e2912c}" = Microsoft Visual C++ 2005 Redistributable
"{83C292B7-38A5-440B-A731-07070E81A64F}" = Windows Live PIMT Platform
"{8B922CF8-8A6C-41CE-A858-F1755D7F5D29}" = NVIDIA PhysX
"{8C6D6116-B724-4810-8F2D-D047E6B7D68E}" = Mesh Runtime
"{8DD46C6A-0056-4FEC-B70A-28BB16A1F11F}" = MSVCRT
"{8e70e4e1-06d7-470b-9f74-a51bef21088e}" = Microsoft Visual C++ 2012 Redistributable (x86) - 11.0.51106
"{8ECEC853-5C3D-4B10-B5C7-FF11FF724807}" = Nero Recode 10
"{8F4ED1E4-4AAD-4A4A-B8E0-FA3EFAAE2960}" = Backup4all Professional 4
"{9008D736-35CA-40DB-A2BE-5F32D954E5AA}" = HP MovieStore
"{90120000-0016-0409-0000-0000000FF1CE}" = Microsoft Office Excel MUI (English) 2007
"{90120000-0016-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0018-0409-0000-0000000FF1CE}" = Microsoft Office PowerPoint MUI (English) 2007
"{90120000-0018-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001B-0409-0000-0000000FF1CE}" = Microsoft Office Word MUI (English) 2007
"{90120000-001B-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-001F-0409-0000-0000000FF1CE}" = Microsoft Office Proof (English) 2007
"{90120000-001F-0409-0000-0000000FF1CE}_HOMESTUDENTR_{1FF96026-A04A-4C3E-B50A-BB7022654D0F}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-040C-0000-0000000FF1CE}" = Microsoft Office Proof (French) 2007
"{90120000-001F-040C-0000-0000000FF1CE}_HOMESTUDENTR_{71F055E8-E2C6-4214-BB3D-BFE03561B89E}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-001F-0C0A-0000-0000000FF1CE}" = Microsoft Office Proof (Spanish) 2007
"{90120000-001F-0C0A-0000-0000000FF1CE}_HOMESTUDENTR_{2314F9A1-126F-45CC-8A5E-DFAF866F3FBC}" = Microsoft Office Proofing Tools 2007 Service Pack 3 (SP3)
"{90120000-002A-0000-1000-0000000FF1CE}_HOMESTUDENTR_{664655D8-B9BB-455D-8A58-7EAF7B0B2862}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002A-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-002C-0409-0000-0000000FF1CE}" = Microsoft Office Proofing (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}" = Microsoft Office Shared MUI (English) 2007
"{90120000-006E-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-00A1-0409-0000-0000000FF1CE}" = Microsoft Office OneNote MUI (English) 2007
"{90120000-00A1-0409-0000-0000000FF1CE}_HOMESTUDENTR_{AAA19365-932B-49BD-8138-BE28CEE9C4B4}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0115-0409-0000-0000000FF1CE}" = Microsoft Office Shared Setup Metadata MUI (English) 2007
"{90120000-0115-0409-0000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90120000-0116-0409-1000-0000000FF1CE}_HOMESTUDENTR_{98333358-268C-4164-B6D4-C96DF5153727}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{90140000-2005-0000-0000-0000000FF1CE}" = Microsoft Office File Validation Add-In
"{91120000-002F-0000-0000-0000000FF1CE}" = Microsoft Office Home and Student 2007
"{91120000-002F-0000-0000-0000000FF1CE}_HOMESTUDENTR_{6E107EB7-8B55-48BF-ACCB-199F86A2CD93}" = Microsoft Office 2007 Service Pack 3 (SP3)
"{912CED74-88D3-4C5B-ACB0-132318649765}" = PressReader
"{92146419-AE44-4C8B-A48B-0ABB1B5EC026}" = Nero 10 Menu TemplatePack 3
"{92A10E9D-EA00-4A46-8F22-EEA660992D61}" = Nero 10 Sample Videos
"{92D194E7-AEF9-4A9E-8620-8F3AE712E3F7}" = Snagit 10.0.2
"{92D58719-BBC1-4CC3-A08B-56C9E884CC2C}" = Microsoft_VC80_CRT_x86
"{92E25238-61A3-4ACD-A407-3C480EEF47A7}" = Nero RescueAgent 10 Help (CHM)
"{92EA4134-10D1-418A-91E1-5A0453131A38}" = Windows Live Movie Maker
"{9368DDD5-CE7F-4BD7-A83A-F00FABE338EC}" = Blio
"{943CFD7D-5336-47AF-9418-E02473A5A517}" = Nero BurnRights 10
"{95140000-0070-0000-0000-0000000FF1CE}" = Microsoft Office 2010
"{96ED4B78-300E-4033-AE6C-C115CEB4DF07}" = Nero 10 ClipartPack
"{9A25302D-30C0-39D9-BD6F-21E6EC160475}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.17
"{9A4297F3-2A51-4ED9-92CA-4BCB8380947E}" = Nero Vision 10
"{9B6B24BE-80E7-46C4-9FA5-B167D5E0F345}" = Nero BurningROM 10 Help (CHM)
"{9bcd38e7-1f9a-4536-8cd4-96448263f367}" = Lightroom 5.2
"{9BE518E6-ECC6-35A9-88E4-87755C07200F}" = Microsoft Visual C++ 2008 Redistributable - x86 9.0.30729.6161
"{9D3C2A92-D1AD-43FD-9434-3821749C3BA2}" = Eudora
"{9D56775A-93F3-44A3-8092-840E3826DE30}" = Windows Live Mail
"{9D7C721E-9861-4994-A91E-2E219CC4A7FD}" = ThumbsPlus
"{9DCBDF08-F1C0-4935-A958-9501384FC528}" = ScoreFitter Volume 1
"{A0C91188-C88F-4E86-93E6-CD7C9A266649}" = Windows Live Mesh
"{A127C3C0-055E-38CF-B38F-1E85F8BBBFFE}" = Adobe Community Help
"{A436F67F-687E-4736-BD2B-537121A804CF}" = HP Product Detection
"{A726AE06-AAA3-43D1-87E3-70F510314F04}" = Windows Live Writer
"{A7284E29-CC2E-48E8-AB86-0D32B247B7A5}" = ThumbsPlus Digicam Plug-in Pack
"{A75949C3-DC28-42CA-9C56-24C002B93D89}" = Garmin City Navigator North America v8
"{A78FE97A-C0C8-49CE-89D0-EDD524A17392}" = PDF Settings CS5
"{A92DAB39-4E2C-4304-9AB6-BC44E68B55E2}" = Google Update Helper
"{A9BDCA6B-3653-467B-AC83-94367DA3BFE3}" = Windows Live Photo Common
"{AAAFC670-569B-4A2F-82B4-42945E0DE3EF}" = Windows Live Writer
"{AAF454FC-82CA-4F29-AB31-6A109485E76E}" = Windows Live Writer
"{AC76BA86-7AD7-1033-7B44-AA1000000001}" = Adobe Reader X (10.1.9)
"{AC816FE8-3022-404F-8BE4-A07B5586F4E3}" = Garmin BaseCamp
"{ACD15FDF-FC42-4175-B477-576F92FF2256}" = Nero 10 Sample ImagePack
"{ACF60000-22B9-4CE9-98D6-2CCF359BAC07}" = ABBYY FineReader 6.0 Sprint
"{AD1FE8DD-0A6A-46E7-9B5F-8A70DD75CA93}" = ThumbsPlus
"{AE856388-AFAD-4753-81DF-D96B19D0A17C}" = HP Setup Manager
"{AFBAB9A0-DDE8-49AE-8C17-A01B61BEE64B}" = Garmin MapSource
"{B175520C-86A2-35A7-8619-86DC379688B9}" = Microsoft Visual C++ 2012 x86 Additional Runtime - 11.0.61030
"{B2C7EA7C-4714-4682-ACDB-EEADA9830F86}" = Glossy Paper ICC Profiles
"{B3931BE3-3189-4A07-833C-50527AC4F2F4}" = Garmin Express
"{B67BAFBA-4C9F-48FA-9496-933E3B255044}" = QuickTime
"{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"{B8AC1A89-FFD1-4F97-8051-E505A160F562}" = HP Odometer
"{B92C2C6C-F70E-497B-88A7-1FEF9888272B}" = Adobe AIR
"{BC7BED89-618B-4E89-8ADF-75D47F276223}" = Pinnacle Studio 15 Ultimate Collection Plugins
"{BD95A8CD-1D9F-35AD-981A-3E7925026EBB}" = Microsoft Visual C++ 2012 x86 Minimum Runtime - 11.0.61030
"{C01A86F5-56E7-101F-9BC9-E3F1025EB779}" = Intel® Identity Protection Technology 1.1.2.0
"{C0227F6C-C9B9-4FD6-9545-A252187CFA57}" = Matte Paper ICC Profiles
"{C18A0418-442A-4186-AF98-D08F5054A2FC}" = Nero DiscSpeed 10 Help (CHM)
"{C3273C55-E1E4-41FF-8D69-0158090DB8D8}" = Nero CoverDesigner 10 Help (CHM)
"{C3580AC4-C827-4332-B935-9A282ED5BB97}" = Nero Dolby Files 10
"{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"{C6579A65-9CAE-4B31-8B6B-3306E0630A66}" = Apple Software Update
"{C66824E4-CBB3-4851-BB3F-E8CFD6350923}" = Windows Live Mail
"{C9D8A041-2963-4B31-8FFC-1500F3DB9293}" = EpsonNet Setup 3.3
"{CCA5EAAD-92F4-4B7A-B5EE-14294C66AB61}" = PlayReady PC Runtime x86
"{CCF6F57B-F6B4-4508-BF45-63AAC9DE416A}" = Quicken 2010
"{CE24B4AE-6EB4-4AFC-80F1-057309575D45}" = BoxCar Pro 4.3.1.1
"{CE95A79E-E4FC-4FFF-8A75-29F04B942FF2}" = Windows Live UX Platform
"{D0B44725-3666-492D-BEF6-587A14BD9BD9}" = MSVCRT_amd64
"{D16A31F9-276D-4968-A753-FFEAC56995D0}" = Epson Print CD
"{D1A19B02-817E-4296-A45B-07853FD74D57}" = Microsoft_VC80_MFC_x86
"{D24DB8B9-BB6C-4334-9619-BA1C650E13D3}" = Microsoft Primary Interoperability Assemblies 2005
"{D35B72B6-F0E4-462B-BDEB-E08032B3B681}" = HP Setup
"{D436F577-1695-4D2F-8B44-AC76C99E0002}" = Windows Live Photo Common
"{D45240D3-B6B3-4FF9-B243-54ECE3E10066}" = Windows Live Communications Platform
"{D92BBB52-82FF-42ED-8A3C-4E062F944AB7}" = Microsoft_VC80_MFCLOC_x86
"{DA5ECEAB-28C6-4306-9FBB-811DEF6DD780}" = Forté Agent
"{DB3147AB-4024-4773-8EC0-A1FE5B44933D}" = HP LinkUp
"{DB7C1D4A-08BA-4C7E-A8AA-B7F9BB372DCF}" = Nero Recode 10 Help (CHM)
"{DBCC73BA-C69A-4BF5-B4BF-F07501EE7039}" = AnswerWorks 5.0 English Runtime
"{DDC8BDEE-DCAC-404D-8257-3E8D4B782467}" = Windows Live Writer Resources
"{DE2E1909-12C2-4249-8003-7978BEA3A14F}" = Garmin City Navigator North America NT 2013.10 Update
"{DE3A9DC5-9A5D-6485-9662-347162C7E4CA}" = Adobe Media Player
"{DE77FE3F-A33D-499A-87AD-5FC406617B40}" = HP Update
"{DECDCB7C-58CC-4865-91AF-627F9798FE48}" = Windows Live Mesh
"{E09C4DB7-630C-4F06-A631-8EA7239923AF}" = D3DX10
"{E1EE5339-5D32-458F-BAAB-B19F6301BCE2}" = Nero SoundTrax 10
"{E337E787-CF61-4B7B-B84F-509202A54023}" = Nero RescueAgent 10
"{E35A3B13-78CD-4967-8AC8-AA9FDA693EDE}" = HP Support Assistant
"{E3A5A8AB-58F6-45FF-AFCB-C9AE18C05001}" = IDT Audio
"{E3D181F8-246B-497F-945E-6DB98CBA6677}" = Hollywood FX Volumes 1-3
"{E3E71D07-CD27-46CB-8448-16D4FB29AA13}" = Microsoft WSE 3.0 Runtime
"{E712C273-7564-4C8E-AA59-0FA19BC35117}" = Nero 10 Menu TemplatePack 2
"{E7B46D0D-A63D-42AB-9D1D-75A88C280F78}" = Epson Professional Print Sample
"{EB4DF488-AAEF-406F-A341-CB2AAA315B90}" = Windows Live Messenger
"{ECC3713C-08A4-40E3-95F1-7D0704F1CE5E}" = PL-2303 USB-to-Serial
"{EDCDFAD5-DF80-4600-A493-E9DAD6810230}" = Nero WaveEditor 10
"{F0B430D1-B6AA-473D-9B06-AA3DD01FD0B8}" = Microsoft SQL Server 2005 Compact Edition [ENU]
"{F0C3E5D1-1ADE-321E-8167-68EF0DE699A5}" = Microsoft Visual C++ 2010 x86 Redistributable - 10.0.40219
"{F2E9C364-0DFD-434B-AF0D-3F5D095B3F8F}" = Elevated Installer
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}" = Visual C++ 2008 x86 Runtime - (v9.0.30729)
"{F333A33D-125C-32A2-8DCE-5C5D14231E27}.vc_x86runtime_30729_01" = Visual C++ 2008 x86 Runtime - v9.0.30729.01
"{F412B4AF-388C-4FF5-9B2F-33DB1C536953}" = Nero InfoTool 10
"{F467862A-D9CA-47ED-8D81-B4B3C9399272}" = Nero MediaHub 10 Help (CHM)
"{F5CB822F-B365-43D1-BCC0-4FDA1A2017A7}" = Nero 10 Movie ThemePack Basic
"{F6117F9C-ADB5-4590-9BE4-12C7BEC28702}" = Nero StartSmart 10 Help (CHM)
"{F61D489E-6C44-49AC-AD02-7DA8ACA73A65}" = Nero StartSmart 10
"{FC030CB5-46A6-4229-AD6E-0AC869F509C8}" = Pinnacle Studio Bonus Content
"{FC7C2707-5E28-4653-8922-CADDD6C439D9}" = WeatherLink 5.9.3
"{FCF00A6E-FB58-477A-ABE9-232907105521}" = Nero CoverDesigner 10
"{FD6034A3-655C-49F0-B496-D4CBFD74D7A7}" = Palm Desktop by ACCESS
"{FE044230-9CA5-43F7-9B58-5AC5A28A1F33}" = Windows Live Essentials
"ActiveTouchMeetingClient" = Cisco WebEx Meetings
"Adobe AIR" = Adobe AIR
"Adobe Creative Cloud" = Adobe Creative Cloud
"Adobe Flash Player ActiveX" = Adobe Flash Player 12 ActiveX
"Adobe Flash Player Plugin" = Adobe Flash Player 12 Plugin
"Audacity_is1" = Audacity 2.0
"Backup4all 3_is1" = Backup4all 3.1
"BadCopy Pro" = BadCopy Pro
"chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Community Help
"Cisco Connect" = Cisco Connect
"com.adobe.amp.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1" = Adobe Media Player
"EPSON Printer and Utilities" = EPSON Printer Software
"EPSON Scanner" = EPSON Scan
"FastCAD" = FastCAD
"FFmpeg for Audacity_is1" = FFmpeg v0.6.2 for Audacity
"Google Chrome" = Google Chrome
"HOMESTUDENTR" = Microsoft Office Home and Student 2007
"InstallShield_{178D71F4-DFB1-40EC-9D95-326FD8A3E7A0}" = Motion Graphics Toolkit for Studio
"InstallShield_{1D273D91-D7D5-4036-8B84-EB4615FF5F81}" = SmartSound Sonicfire Pro 5
"InstallShield_{20C45B32-5AB6-46A4-94EF-58950CAF05E5}" = EPSON Attach To Email
"InstallShield_{40BF1E83-20EB-11D8-97C5-0009C5020658}" = Power2Go
"InstallShield_{4220E523-EDE1-449F-83F5-8267D20E1ED0}" = Maxtor Manager
"InstallShield_{4A7FDA4D-F4D7-4A49-934A-066D59A43C7E}" = SmartSound Quicktracks Plugin
"InstallShield_{4CF172C5-F121-41FA-B0B0-0D49840BF003}" = Filmmaker's Toolkit for Studio
"InstallShield_{B8A2869E-30CA-40C5-9CF8-BD7354E57EF8}" = SmartSound Common Data
"InstallShield_{C59C179C-668D-49A9-B6EA-0121CCFC1243}" = LabelPrint
"InstallShield_{CE24B4AE-6EB4-4AFC-80F1-057309575D45}" = BoxCar Pro 4.3.1.1
"Knoll Light Factory EZ Studio 15" = Knoll Light Factory EZ Studio 15
"Kobo" = Kobo
"LAME_is1" = LAME v3.99.3 (for Windows)
"LView Pro Full Version" = LView Pro Full Version
"Magic Bullet Looks Studio 15" = Magic Bullet Looks Studio 15
"Malwarebytes' Anti-Malware_is1" = Malwarebytes Anti-Malware version 1.75.0.1300
"NirSoft BlueScreenView" = NirSoft BlueScreenView
"NIS" = Norton Internet Security
"NVIDIAStereo" = NVIDIA Stereoscopic 3D Driver
"[email protected]" = Perk Prize Panel
"Prism" = Prism Video File Converter
"proDAD-Heroglyph-2.5" = proDAD Heroglyph 2.5
"proDAD-Vitascene-1.0" = proDAD Vitascene 1.0
"QuickPar" = QuickPar 0.9
"Red Giant ToonIt Studio 15" = Red Giant ToonIt Studio 15
"R-Wipe&Clean_is1" = R-Wipe&Clean 6.5
"Silent Package Run-Time Sample" = EPSON Perf 4490P Guide
"SIUSBXP&10C4&EA61" = Silicon Laboratories USBXpress Device (Driver Removal)
"SLABCOMM&10C4&EA60" = Silicon Laboratories CP210x USB to UART Bridge (Driver Removal)
"SMPlayer" = SMPlayer 0.8.6.0
"Switch" = Switch Sound File Converter
"TempoPerfect" = TempoPerfect Metronome Software
"ThumbsPlus" = ThumbsPlus
"ThumbsPlus Digicam Plug-in" = ThumbsPlus Digicam Plug-in
"ThumbsPlus Digicam Plug-in Pack" = ThumbsPlus Digicam Plug-in Pack
"ToneGen" = NCH Tone Generator
"ToolBox" = NCH Toolbox
"Trapcode 3DStroke Studio 15" = Trapcode 3DStroke Studio 15
"Trapcode Particular Studio" = Trapcode Particular Studio
"Trapcode Shine Studio 15" = Trapcode Shine Studio 15
"Uninstall Presto! BizCard 4.1 Eng" = Presto! BizCard 4.1 Eng
"VIP Access SDK" = VIP Access SDK (1.0.1.4)
"Wacom WebTabletPlugin for IE" = WebTablet IE Plugin
"Wacom WebTabletPlugin for Netscape" = WebTablet Netscape Plugin
"Wash N' Go" = Wash N' Go 2.3.4.1
"WavePad" = WavePad Sound Editor
"WildTangent hp Master Uninstall" = HP Games
"WinLiveSuite" = Windows Live Essentials
"WTA-02256e7d-d56b-498d-8cd5-d0fe2aedc854" = Virtual Villagers 5 - New Believers
"WTA-0ab0630c-3e14-4e67-8367-12edec1c0a6c" = Blasterball 3
"WTA-0cb8d170-4e28-4cb9-9c79-d6f0422047db" = Governor of Poker 2 Premium Edition
"WTA-187673b1-58ee-46e3-bd85-aa073c7ddb61" = Bejeweled 3
"WTA-24a362ea-2ce7-4209-b290-8e441c2ae605" = Cradle of Rome 2
"WTA-2f4723d7-09f2-4bb6-b254-1ac517c23cb9" = Penguins!
"WTA-3ab7ae9a-70b8-4de6-87be-aa649793bf56" = Blackhawk Striker 2
"WTA-4bf4532a-2265-452a-9033-de02b7e05d14" = Chuzzle Deluxe
"WTA-4f840ba7-741e-43df-843e-7a32bacbe8e1" = Zuma Deluxe
"WTA-5254b775-e662-4162-9206-f6a88e39e569" = Namco All-Stars: PAC-MAN
"WTA-6a3aeab8-bbec-42fc-9c36-2207d4137198" = Farm Frenzy
"WTA-6d4939c6-3a87-46ff-94eb-0210bde67b69" = Mah Jong Medley
"WTA-8a31cb5f-dbbd-4b9e-befb-f8633d344310" = Vacation Quest - The Hawaiian Islands
"WTA-8bb6308f-f4ef-4dc6-9c45-3c03d0ad8ce6" = Plants vs. Zombies - Game of the Year
"WTA-917ebd75-e140-4cae-b2d1-c49fad64f8ac" = Cake Mania
"WTA-9ea72cc7-63c5-4eca-935b-16ff9f0c02ff" = Chronicles of Albian
"WTA-a30f4b59-3404-4e16-8b98-78b25b28d707" = Poker Superstars III
"WTA-c335b39c-7c23-4383-b109-e5ef846ae670" = Agatha Christie - Peril at End House
"WTA-c4370fd8-a8c9-4fe5-93a8-4105a731e765" = Mystery of Mortlake Mansion
"WTA-c50073b7-0243-415c-a466-d650c573719c" = Slingo Supreme
"WTA-d0770925-f132-4356-85bd-86e291c0f171" = Bounce Symphony
"WTA-dee54ec1-d7cb-4373-967f-aa9e37571dbe" = Polar Bowler
"WTA-ecaba5cb-3031-4ce1-a420-4ae9f9133163" = FATE
"WTA-ed84e918-51ff-4493-8214-bc4d99c5448d" = Jewel Quest: The Sleepless Star - Collector's Edition
"WTA-edae7203-f5ea-4012-9c95-eade70b514fa" = Polar Golfer
"ZhornStickies" = Stickies 7.1e

========== HKEY_USERS Uninstall List ==========

[HKEY_USERS\S-1-5-21-3563443419-2258996029-2686041776-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall]
"Dashlane" = Dashlane
"Dropbox" = Dropbox
"f031ef6ac137efc5" = Dell Driver Download Manager
"ThumbsPlus" = ThumbsPlus

========== Last 20 Event Log Errors ==========

[ Application Events ]
Error - 3/4/2014 4:42:50 AM | Computer Name = Glens-HP | Source = Bonjour Service | ID = 100
Description = Task Scheduling Error: m->NextScheduledSPRetry 8081

Error - 3/4/2014 11:30:10 AM | Computer Name = Glens-HP | Source = TivoTransfer | ID = 0
Description =

Error - 3/4/2014 11:43:08 AM | Computer Name = Glens-HP | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Glens\Downloads\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 3/4/2014 11:43:21 AM | Computer Name = Glens-HP | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Glens\Desktop\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 3/4/2014 11:44:09 AM | Computer Name = Glens-HP | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Glens\Desktop\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 3/4/2014 11:44:09 AM | Computer Name = Glens-HP | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Glens\Desktop\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 3/4/2014 11:44:09 AM | Computer Name = Glens-HP | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Glens\Desktop\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 3/4/2014 11:44:09 AM | Computer Name = Glens-HP | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Glens\Desktop\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 3/4/2014 11:44:30 AM | Computer Name = Glens-HP | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Users\Glens\Desktop\esetsmartinstaller_enu.exe".Error
in manifest or policy file "" on line . A component version required by the application
conflicts with another component version already active. Conflicting components
are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

Error - 3/4/2014 8:42:31 PM | Computer Name = Glens-HP | Source = SideBySide | ID = 16842832
Description = Activation context generation failed for "C:\Program Files (x86)\ESET\ESET
Online Scanner\ESETSmartInstaller.exe".Error in manifest or policy file "" on line
. A component version required by the application conflicts with another component
version already active. Conflicting components are:. Component 1: C:\Windows\WinSxS\manifests\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_fa396087175ac9ac.manifest.
Component
2: C:\Windows\WinSxS\manifests\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2.manifest.

[ Hewlett-Packard Events ]
Error - 11/27/2012 12:20:15 PM | Computer Name = Glens-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261HPSF.exe at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckResult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckResult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
8172 Ram Utilization: 20 TargetSite: Void loadActiveCheckResult(Boolean)

Error - 11/27/2012 12:20:15 PM | Computer Name = Glens-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261HPSF.exe at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckResult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckResult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
8172 Ram Utilization: 20 TargetSite: Void loadActiveCheckResult(Boolean)

Error - 11/27/2012 12:20:18 PM | Computer Name = Glens-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckResult(Boolean
includeIgnored) Message: Object reference not set to an instance of an object. StackTrace:
at HP.SupportFramework.Utilities.HPSAIssues.ActionItemCollection.loadActiveCheckResult(Boolean
includeIgnored) Source: HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US
RAM:
8172 Ram Utilization: 20 TargetSite: Void loadActiveCheckResult(Boolean)

Error - 12/23/2012 11:09:38 PM | Computer Name = Glens-HP | Source = HPSF.exe | ID = 2000
Description = HP Error ID: -2147467261 at HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Message:
Object reference not set to an instance of an object. StackTrace: at HP.SupportFramework.Utilities.CustomerExperience.HPSASession.AddNavigationProperties()
Source:
HP.SupportFramework.Utilities Name: HPSF.exe Version: 07.00.01.01 Path: C:\Program
Files (x86)\Hewlett-Packard\HP Support Framework\HPSF.exe Format: en-US RAM: 8172
Ram
Utilization: 20 TargetSite: HP.SupportFramework.HPSFReporting._Property[] AddNavigationProperties()


Error - 1/1/2014 3:11:38 PM | Computer Name = Glens-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at HP.ActiveCheckLocalMode.ServiceFacade.HPAsset.HPAssetRelease()

at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.GetTelemetry(String
ini, String xmlout) at HP.SupportFramework.Service.ACLM.AssetAgent.ExecuteAssetAgent(Boolean
isFirst) Message: HPAsset fails to release. StackTrace: at HP.ActiveCheckLocalMode.ServiceFacade.HPAsset.HPAssetRelease()

at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.GetTelemetry(String
ini, String xmlout) at HP.SupportFramework.Service.ACLM.AssetAgent.ExecuteAssetAgent(Boolean
isFirst) Source: HP.ActiveCheckLocalMode.ServiceFacade InnerException.Message: Object
reference not set to an instance of an object. Name: hpsa_service.exe Version: 07.00.00.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe Format:
en-US RAM: 8172 Ram Utilization: 30 TargetSite: Void HPAssetRelease()

Error - 1/8/2014 3:08:15 PM | Computer Name = Glens-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at HP.ActiveCheckLocalMode.ServiceFacade.HPAsset.HPAssetRelease()

at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.GetTelemetry(String
ini, String xmlout) at HP.SupportFramework.Service.ACLM.AssetAgent.ExecuteAssetAgent(Boolean
isFirst) Message: HPAsset fails to release. StackTrace: at HP.ActiveCheckLocalMode.ServiceFacade.HPAsset.HPAssetRelease()

at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.GetTelemetry(String
ini, String xmlout) at HP.SupportFramework.Service.ACLM.AssetAgent.ExecuteAssetAgent(Boolean
isFirst) Source: HP.ActiveCheckLocalMode.ServiceFacade InnerException.Message: Object
reference not set to an instance of an object. Name: hpsa_service.exe Version: 07.00.00.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe Format:
en-US RAM: 16364 Ram Utilization: 10 TargetSite: Void HPAssetRelease()

Error - 1/9/2014 3:38:08 PM | Computer Name = Glens-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088hpsa_service.exe at HP.ActiveCheckLocalMode.ServiceFacade.HPAsset.HPAssetRelease()

at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.GetTelemetry(String
ini, String xmlout) at HP.SupportFramework.Service.ACLM.AssetAgent.ExecuteAssetAgent(Boolean
isFirst) Message: HPAsset fails to release. StackTrace: at HP.ActiveCheckLocalMode.ServiceFacade.HPAsset.HPAssetRelease()

at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.GetTelemetry(String
ini, String xmlout) at HP.SupportFramework.Service.ACLM.AssetAgent.ExecuteAssetAgent(Boolean
isFirst) Source: HP.ActiveCheckLocalMode.ServiceFacade InnerException.Message: Object
reference not set to an instance of an object. Name: hpsa_service.exe Version: 07.00.00.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe Format:
en-US RAM: 16364 Ram Utilization: 30 TargetSite: Void HPAssetRelease()

Error - 1/10/2014 4:08:10 PM | Computer Name = Glens-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088hpsa_service.exe at HP.ActiveCheckLocalMode.ServiceFacade.HPAsset.HPAssetRelease()

at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.GetTelemetry(String
ini, String xmlout) at HP.SupportFramework.Service.ACLM.AssetAgent.ExecuteAssetAgent(Boolean
isFirst) Message: HPAsset fails to release. StackTrace: at HP.ActiveCheckLocalMode.ServiceFacade.HPAsset.HPAssetRelease()

at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.GetTelemetry(String
ini, String xmlout) at HP.SupportFramework.Service.ACLM.AssetAgent.ExecuteAssetAgent(Boolean
isFirst) Source: HP.ActiveCheckLocalMode.ServiceFacade InnerException.Message: Object
reference not set to an instance of an object. Name: hpsa_service.exe Version: 07.00.00.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe Format:
en-US RAM: 16364 Ram Utilization: 40 TargetSite: Void HPAssetRelease()

Error - 1/11/2014 4:38:05 PM | Computer Name = Glens-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088hpsa_service.exe at HP.ActiveCheckLocalMode.ServiceFacade.HPAsset.HPAssetRelease()

at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.GetTelemetry(String
ini, String xmlout) at HP.SupportFramework.Service.ACLM.AssetAgent.ExecuteAssetAgent(Boolean
isFirst) Message: HPAsset fails to release. StackTrace: at HP.ActiveCheckLocalMode.ServiceFacade.HPAsset.HPAssetRelease()

at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.GetTelemetry(String
ini, String xmlout) at HP.SupportFramework.Service.ACLM.AssetAgent.ExecuteAssetAgent(Boolean
isFirst) Source: HP.ActiveCheckLocalMode.ServiceFacade InnerException.Message: Object
reference not set to an instance of an object. Name: hpsa_service.exe Version: 07.00.00.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe Format:
en-US RAM: 16364 Ram Utilization: 20 TargetSite: Void HPAssetRelease()

Error - 1/15/2014 3:23:19 PM | Computer Name = Glens-HP | Source = hpsa_service.exe | ID = 2000
Description = HP Error ID: -2146233088 at HP.ActiveCheckLocalMode.ServiceFacade.HPAsset.HPAssetRelease()

at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.GetTelemetry(String
ini, String xmlout) at HP.SupportFramework.Service.ACLM.AssetAgent.ExecuteAssetAgent(Boolean
isFirst) Message: HPAsset fails to release. StackTrace: at HP.ActiveCheckLocalMode.ServiceFacade.HPAsset.HPAssetRelease()

at HP.ActiveCheckLocalMode.SessionManager.ActiveCheckManager.GetTelemetry(String
ini, String xmlout) at HP.SupportFramework.Service.ACLM.AssetAgent.ExecuteAssetAgent(Boolean
isFirst) Source: HP.ActiveCheckLocalMode.ServiceFacade InnerException.Message: Object
reference not set to an instance of an object. Name: hpsa_service.exe Version: 07.00.00.01
Path:
C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\hpsa_service.exe Format:
en-US RAM: 16364 Ram Utilization: 20 TargetSite: Void HPAssetRelease()

[ System Events ]
Error - 3/3/2014 3:21:47 PM | Computer Name = Glens-HP | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Volume
Shadow Copy service to connect.

Error - 3/3/2014 3:21:47 PM | Computer Name = Glens-HP | Source = Service Control Manager | ID = 7000
Description = The Volume Shadow Copy service failed to start due to the following
error: %%1053

Error - 3/3/2014 3:22:18 PM | Computer Name = Glens-HP | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Volume
Shadow Copy service to connect.

Error - 3/3/2014 3:22:18 PM | Computer Name = Glens-HP | Source = Service Control Manager | ID = 7000
Description = The Volume Shadow Copy service failed to start due to the following
error: %%1053

Error - 3/3/2014 6:07:06 PM | Computer Name = Glens-HP | Source = DCOM | ID = 10010
Description =

Error - 3/4/2014 2:59:47 AM | Computer Name = Glens-HP | Source = Disk | ID = 262155
Description = The driver detected a controller error on \Device\Harddisk4\DR4.

Error - 3/4/2014 11:23:06 AM | Computer Name = Glens-HP | Source = Service Control Manager | ID = 7034
Description = The TrueSuiteService service terminated unexpectedly. It has done
this 1 time(s).

Error - 3/4/2014 11:28:45 AM | Computer Name = Glens-HP | Source = Service Control Manager | ID = 7009
Description = A timeout was reached (30000 milliseconds) while waiting for the Garmin
Core Update Service service to connect.

Error - 3/4/2014 11:28:45 AM | Computer Name = Glens-HP | Source = Service Control Manager | ID = 7000
Description = The Garmin Core Update Service service failed to start due to the
following error: %%1053

Error - 3/4/2014 11:28:54 AM | Computer Name = Glens-HP | Source = Service Control Manager | ID = 7026
Description = The following boot-start or system-start driver(s) failed to load:
Lbd


< End of report >

OTL.txt from step 5

OTL logfile created on: 3/4/2014 10:09:08 PM - Run 3
OTL by OldTimer - Version 3.2.69.0 Folder = C:\Users\Glens\Desktop
64bit- Professional Service Pack 1 (Version = 6.1.7601) - Type = NTWorkstation
Internet Explorer (Version = 9.11.9600.16518)
Locale: 00000409 | Country: United States | Language: ENU | Date Format: M/d/yyyy

15.98 Gb Total Physical Memory | 11.10 Gb Available Physical Memory | 69.49% Memory free
31.96 Gb Paging File | 27.73 Gb Available in Paging File | 86.78% Paging File free
Paging file location(s): ?:\pagefile.sys [binary data]

%SystemDrive% = C: | %SystemRoot% = C:\Windows | %ProgramFiles% = C:\Program Files (x86)
Drive C: | 1385.03 Gb Total Space | 792.82 Gb Free Space | 57.24% Space Free | Partition Type: NTFS
Drive D: | 12.13 Gb Total Space | 1.49 Gb Free Space | 12.26% Space Free | Partition Type: NTFS
Drive E: | 465.76 Gb Total Space | 189.21 Gb Free Space | 40.62% Space Free | Partition Type: NTFS
Drive O: | 931.51 Gb Total Space | 197.14 Gb Free Space | 21.16% Space Free | Partition Type: NTFS
Drive P: | 298.09 Gb Total Space | 71.80 Gb Free Space | 24.09% Space Free | Partition Type: NTFS
Drive Q: | 465.76 Gb Total Space | 93.60 Gb Free Space | 20.10% Space Free | Partition Type: NTFS
Drive R: | 596.17 Gb Total Space | 285.16 Gb Free Space | 47.83% Space Free | Partition Type: NTFS
Drive Y: | 298.09 Gb Total Space | 69.13 Gb Free Space | 23.19% Space Free | Partition Type: NTFS
Drive Z: | 931.51 Gb Total Space | 522.30 Gb Free Space | 56.07% Space Free | Partition Type: NTFS

Computer Name: GLENS-HP | User Name: Glens | Logged in as Administrator.
Boot Mode: Normal | Scan Mode: All users | Include 64bit Scans
Company Name Whitelist: Off | Skip Microsoft Files: Off | No Company Name Whitelist: On | File Age = 30 Days

========== Processes (SafeList) ==========

PRC - [2014/02/27 11:07:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Glens\Desktop\OTL.exe
PRC - [2014/02/22 14:07:12 | 001,134,592 | ---- | M] (Zhorn Software) -- C:\Program Files (x86)\Stickies\stickies.exe
PRC - [2014/02/20 17:55:04 | 000,118,056 | ---- | M] (Cisco WebEx LLC) -- C:\Windows\SysWOW64\atashost.exe
PRC - [2014/02/15 14:45:38 | 000,223,112 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Update\1.3.22.5\GoogleCrashHandler.exe
PRC - [2014/02/11 15:05:14 | 000,395,120 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\Adobe CEF Helper.exe
PRC - [2014/02/11 10:54:18 | 002,239,376 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe
PRC - [2014/01/15 11:02:16 | 004,697,456 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncV1\CoreSync.exe
PRC - [2014/01/02 19:46:10 | 030,714,328 | ---- | M] (Dropbox, Inc.) -- C:\Users\Glens\AppData\Roaming\Dropbox\bin\Dropbox.exe
PRC - [2013/12/18 13:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
PRC - [2013/12/13 05:16:54 | 000,769,904 | ---- | M] (Adobe Systems Incorporated) -- C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\IPC\AdobeIPCBroker.exe
PRC - [2013/12/12 22:37:01 | 000,309,328 | ---- | M] (Google Inc.) -- C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbarUser_32.exe
PRC - [2013/10/08 07:28:15 | 000,275,696 | R--- | M] (Symantec Corporation) -- C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe
PRC - [2013/09/03 08:33:53 | 003,233,806 | ---- | M] () -- C:\Program Files (x86)\Tor\tor.exe
PRC - [2013/04/24 04:30:28 | 000,483,864 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe
PRC - [2013/04/24 04:26:56 | 000,740,888 | ---- | M] (Sony Corporation) -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe
PRC - [2013/03/15 00:53:06 | 001,266,464 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe
PRC - [2013/03/14 21:07:46 | 000,383,264 | ---- | M] (NVIDIA Corporation) -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
PRC - [2011/06/09 07:37:18 | 000,264,008 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe
PRC - [2011/06/09 07:37:00 | 000,653,128 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\TouchControl.exe
PRC - [2011/06/09 07:36:34 | 000,142,664 | ---- | M] (HP) -- C:\Program Files (x86)\HP SimplePass 2011\BioMonitor.exe
PRC - [2011/02/24 02:10:24 | 000,212,944 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe
PRC - [2011/02/01 02:41:24 | 002,656,280 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe
PRC - [2011/02/01 02:41:20 | 000,326,168 | ---- | M] (Intel Corporation) -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe
PRC - [2010/11/26 09:09:12 | 000,399,344 | ---- | M] (Roxio) -- C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe
PRC - [2010/08/24 16:56:14 | 000,608,528 | ---- | M] (TiVo Inc.) -- C:\Program Files (x86)\TiVo\Desktop\TiVoTransfer.exe
PRC - [2010/08/24 16:56:12 | 002,264,336 | ---- | M] (TiVo Inc.) -- C:\Program Files (x86)\TiVo\Desktop\TiVoServer.exe
PRC - [2010/08/24 16:56:10 | 000,437,520 | ---- | M] (TiVo Inc.) -- C:\Program Files (x86)\TiVo\Desktop\TiVoNotify.exe
PRC - [2010/08/24 16:56:04 | 001,104,656 | ---- | M] (TiVo Inc.) -- C:\Program Files (x86)\TiVo\Desktop\TiVoBeacon.exe
PRC - [2010/02/18 16:01:06 | 000,462,632 | ---- | M] (Nero AG) -- C:\Program Files (x86)\Nero\Update\NASvc.exe
PRC - [2008/11/20 12:47:28 | 000,062,768 | ---- | M] (Hewlett-Packard) -- C:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe
PRC - [2008/04/17 05:33:14 | 000,181,544 | ---- | M] (Seagate Technology LLC) -- C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe
PRC - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe
PRC - [2006/10/12 15:57:08 | 000,102,400 | ---- | M] (SEIKO EPSON CORPORATION) -- C:\Program Files (x86)\EPSON\Creativity Suite\Event Manager\EEventManager.exe


========== Modules (No Company Name) ==========

MOD - [2014/02/22 14:07:11 | 000,049,152 | ---- | M] () -- C:\Program Files (x86)\Stickies\shook70.dll
MOD - [2014/02/11 15:09:42 | 032,733,080 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libcef.dll
MOD - [2014/02/11 15:09:38 | 000,742,808 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libGLESv2.dll
MOD - [2014/02/11 15:09:38 | 000,136,600 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\HEX\libEGL.dll
MOD - [2014/01/15 11:02:16 | 004,697,456 | ---- | M] () -- C:\Program Files (x86)\Adobe\Adobe Creative Cloud\CoreSyncV1\CoreSync.exe
MOD - [2014/01/02 19:45:04 | 003,558,400 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dropbox\bin\wxmsw28uh_vc.dll
MOD - [2013/10/18 18:55:02 | 025,100,288 | ---- | M] () -- C:\Users\Glens\AppData\Roaming\Dropbox\bin\libcef.dll
MOD - [2011/09/27 10:23:00 | 000,087,912 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\zlib1.dll
MOD - [2011/09/27 10:22:40 | 001,242,472 | ---- | M] () -- C:\Program Files (x86)\Common Files\Apple\Apple Application Support\libxml2.dll
MOD - [2010/08/24 16:55:58 | 000,050,960 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\Plus\TranscodingServicePS.dll
MOD - [2010/08/24 16:34:24 | 000,259,584 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\Id3Lib.dll
MOD - [2010/05/17 21:56:22 | 000,684,032 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\LibEay32.dll
MOD - [2010/05/17 21:56:22 | 000,155,648 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\SslEay32.dll
MOD - [2010/05/17 21:54:54 | 000,716,800 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\loudmouth.dll
MOD - [2003/01/30 06:04:00 | 000,618,496 | ---- | M] () -- C:\Program Files (x86)\TiVo\Desktop\StlpMt45.dll


========== Services (SafeList) ==========

SRV:64bit: - [2014/02/06 05:48:45 | 000,111,616 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\IEEtwCollector.exe -- (IEEtwCollectorService)
SRV:64bit: - [2013/05/27 00:50:47 | 001,011,712 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Program Files\Windows Defender\MpSvc.dll -- (WinDefend)
SRV:64bit: - [2012/04/24 19:38:30 | 000,318,464 | ---- | M] (IDT, Inc.) [Auto | Running] -- C:\Program Files\IDT\WDM\stacsv64.exe -- (STacSV)
SRV:64bit: - [2011/09/27 14:04:08 | 000,359,192 | ---- | M] (Logitech, Inc.) [On_Demand | Stopped] -- C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe -- (LBTServ)
SRV:64bit: - [2011/03/25 19:19:08 | 000,956,192 | ---- | M] (Broadcom Corporation.) [Auto | Running] -- c:\Program Files\WIDCOMM\Bluetooth Software\btwdins.exe -- (btwdins)
SRV:64bit: - [2010/10/13 11:41:06 | 000,487,280 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_TouchService.exe -- (TouchServicePen)
SRV:64bit: - [2010/10/13 11:41:04 | 005,790,064 | ---- | M] (Wacom Technology, Corp.) [Auto | Running] -- C:\Program Files\Tablet\Pen\Pen_Tablet.exe -- (TabletServicePen)
SRV:64bit: - [2010/10/11 04:48:14 | 000,346,168 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files\Hewlett-Packard\HP Client Services\HPClientServices.exe -- (HPClientSvc)
SRV:64bit: - [2010/09/22 20:10:10 | 000,057,184 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Program Files\Windows Live\Mesh\wlcrasvc.exe -- (wlcrasvc)
SRV:64bit: - [2009/09/14 00:00:00 | 000,128,512 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files\Common Files\EPSON\EPW!3 SSRP\E_S50RPB.EXE -- (EPSON_PM_RPCV4_04)
SRV:64bit: - [2009/07/13 20:40:01 | 000,193,536 | ---- | M] (Microsoft Corporation) [On_Demand | Stopped] -- C:\Windows\SysNative\appmgmts.dll -- (AppMgmt)
SRV:64bit: - [2009/03/02 17:42:58 | 000,089,600 | ---- | M] (Andrea Electronics Corporation) [Auto | Running] -- C:\Program Files\IDT\WDM\AESTSr64.exe -- (AESTFilters)
SRV - [2014/02/27 15:06:48 | 000,257,928 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe -- (AdobeFlashPlayerUpdateSvc)
SRV - [2014/02/20 17:55:04 | 000,118,056 | ---- | M] (Cisco WebEx LLC) [Auto | Running] -- C:\Windows\SysWOW64\atashost.exe -- (atashost)
SRV - [2013/12/18 13:42:32 | 000,065,432 | ---- | M] (Adobe Systems Incorporated) [Auto | Running] -- C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe -- (AdobeARMservice)
SRV - [2013/11/08 15:14:26 | 000,250,712 | ---- | M] (Garmin Ltd or its subsidiaries) [Auto | Stopped] -- C:\Program Files (x86)\Garmin\Core Update Service\Garmin.Cartography.MapUpdate.CoreService.exe -- (Garmin Core Update Service)
SRV - [2013/11/04 18:31:56 | 000,092,160 | ---- | M] (Hewlett-Packard Company) [Auto | Running] -- C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\HPSA_Service.exe -- (HP Support Assistant Service)
SRV - [2013/10/08 07:28:15 | 000,275,696 | R--- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\NIS.exe -- (NIS)
SRV - [2013/09/11 21:21:54 | 000,105,144 | ---- | M] (Microsoft Corporation) [Auto | Stopped] -- C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorsvw.exe -- (clr_optimization_v4.0.30319_32)
SRV - [2013/09/03 08:33:53 | 003,233,806 | ---- | M] () [Auto | Running] -- C:\Program Files (x86)\Tor\tor.exe -- (tor)
SRV - [2013/04/24 04:30:28 | 000,483,864 | ---- | M] (Sony Corporation) [Auto | Running] -- C:\Program Files (x86)\Sony\PlayMemories Home\PMBDeviceInfoProvider.exe -- (PMBDeviceInfoProvider)
SRV - [2013/03/15 00:53:06 | 001,266,464 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\NVIDIA Update Core\daemonu.exe -- (nvUpdatusService)
SRV - [2013/03/14 21:07:46 | 000,383,264 | ---- | M] (NVIDIA Corporation) [Auto | Running] -- C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe -- (Stereo Service)
SRV - [2011/06/09 07:37:18 | 000,264,008 | ---- | M] (HP) [Auto | Running] -- C:\Program Files (x86)\HP SimplePass 2011\TrueSuiteService.exe -- (FPLService)
SRV - [2011/02/24 02:10:24 | 000,212,944 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Services\IPT\jhi_service.exe -- (jhi_service)
SRV - [2011/02/01 02:41:24 | 002,656,280 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\UNS\UNS.exe -- (UNS)
SRV - [2011/02/01 02:41:20 | 000,326,168 | ---- | M] (Intel Corporation) [Auto | Running] -- C:\Program Files (x86)\Intel\Intel® Management Engine Components\LMS\LMS.exe -- (LMS)
SRV - [2010/11/26 09:09:12 | 000,399,344 | ---- | M] (Roxio) [Auto | Running] -- C:\Program Files (x86)\Roxio\RoxioNow Player\RNowSvc.exe -- (RoxioNow Service)
SRV - [2010/10/12 12:59:12 | 000,206,072 | ---- | M] (WildTangent, Inc.) [On_Demand | Stopped] -- C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe -- (GamesAppService)
SRV - [2010/08/24 16:56:04 | 001,104,656 | ---- | M] (TiVo Inc.) [Auto | Running] -- C:\Program Files (x86)\TiVo\Desktop\TiVoBeacon.exe -- (TivoBeacon2)
SRV - [2010/06/01 17:31:28 | 002,804,568 | ---- | M] (Symantec Corporation) [Auto | Running] -- C:\Program Files (x86)\Symantec\Norton Online Backup\NOBuAgent.exe -- (NOBU)
SRV - [2010/02/19 15:37:14 | 000,517,096 | ---- | M] (Adobe Systems Incorporated) [On_Demand | Stopped] -- C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe -- (SwitchBoard)
SRV - [2010/02/18 16:01:06 | 000,462,632 | ---- | M] (Nero AG) [Auto | Running] -- C:\Program Files (x86)\Nero\Update\NASvc.exe -- (NAUpdate)
SRV - [2009/06/10 16:23:09 | 000,066,384 | ---- | M] (Microsoft Corporation) [Disabled | Stopped] -- C:\Windows\Microsoft.NET\Framework\v2.0.50727\mscorsvw.exe -- (clr_optimization_v2.0.50727_32)
SRV - [2008/04/17 05:33:14 | 000,181,544 | ---- | M] (Seagate Technology LLC) [Auto | Running] -- C:\Program Files (x86)\Maxtor\Sync\SyncServices.exe -- (Maxtor Sync Service)
SRV - [2006/12/19 18:23:20 | 000,094,208 | ---- | M] (SEIKO EPSON CORPORATION) [Auto | Running] -- C:\Program Files (x86)\Common Files\EPSON\EBAPI\eEBSvc.exe -- (EpsonBidirectionalService)


========== Driver Services (SafeList) ==========

DRV:64bit: - [2013/11/13 11:27:51 | 000,177,752 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\SYMEVENT64x86.SYS -- (SymEvent)
DRV:64bit: - [2013/10/01 21:22:20 | 000,056,832 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbFlt.sys -- (TsUsbFlt)
DRV:64bit: - [2013/09/26 22:18:30 | 001,147,480 | R--- | M] (Symantec Corporation) [File_System | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\SymEFA64.sys -- (SymEFA)
DRV:64bit: - [2013/09/26 21:45:56 | 000,264,280 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\Ironx64.sys -- (SymIRON)
DRV:64bit: - [2013/09/26 21:26:03 | 000,858,200 | R--- | M] (Symantec Corporation) [File_System | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\srtsp64.sys -- (SRTSP)
DRV:64bit: - [2013/09/25 22:28:00 | 000,590,936 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\symnets.sys -- (SymNetS)
DRV:64bit: - [2013/09/25 21:50:25 | 000,162,392 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\ccSetx64.sys -- (ccSet_NIS)
DRV:64bit: - [2013/09/09 21:47:43 | 000,078,936 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\SymIMV.sys -- (SymIM)
DRV:64bit: - [2013/09/09 21:47:26 | 000,493,656 | R--- | M] (Symantec Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\SymDS64.sys -- (SymDS)
DRV:64bit: - [2013/09/09 20:49:49 | 000,036,952 | R--- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Windows\SysNative\drivers\NISx64\1501000.012\srtspx64.sys -- (SRTSPX)
DRV:64bit: - [2012/12/19 00:41:52 | 000,194,488 | ---- | M] (NVIDIA Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\nvhda64v.sys -- (NVHDA)
DRV:64bit: - [2012/12/13 14:50:36 | 000,054,784 | ---- | M] (Apple, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\usbaapl64.sys -- (USBAAPL64)
DRV:64bit: - [2012/08/23 09:10:20 | 000,019,456 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rdpvideominiport.sys -- (RdpVideoMiniport)
DRV:64bit: - [2012/08/23 09:08:26 | 000,030,208 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\TsUsbGD.sys -- (TsUsbGD)
DRV:64bit: - [2012/08/21 13:01:20 | 000,033,240 | ---- | M] (GEAR Software Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\GEARAspiWDM.sys -- (GEARAspiWDM)
DRV:64bit: - [2012/08/13 20:36:38 | 000,013,120 | ---- | M] (Windows ® Win 7 DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\rcmirror64.sys -- (rcmirror)
DRV:64bit: - [2012/05/29 14:53:30 | 000,027,456 | ---- | M] (Windows ® Codename Longhorn DDK provider) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\cpqdfw.sys -- (CpqDfw)
DRV:64bit: - [2012/04/24 19:38:30 | 000,536,576 | ---- | M] (IDT, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\stwrt64.sys -- (STHDA)
DRV:64bit: - [2012/03/01 01:46:16 | 000,023,408 | ---- | M] (Microsoft Corporation) [Recognizer | Boot | Unknown] -- C:\Windows\SysNative\drivers\fs_rec.sys -- (Fs_Rec)
DRV:64bit: - [2011/12/01 18:04:01 | 000,828,912 | ---- | M] () [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\sptd.sys -- (sptd)
DRV:64bit: - [2011/10/22 18:00:57 | 000,031,152 | ---- | M] () [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\pmxdrv.sys -- (pmxdrv)
DRV:64bit: - [2011/10/22 17:39:58 | 000,107,904 | ---- | M] (Advanced Micro Devices) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsata.sys -- (amdsata)
DRV:64bit: - [2011/10/22 17:39:58 | 000,027,008 | ---- | M] (Advanced Micro Devices) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\amdxata.sys -- (amdxata)
DRV:64bit: - [2011/09/02 01:30:36 | 000,060,696 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LMouFilt.Sys -- (LMouFilt)
DRV:64bit: - [2011/09/02 01:30:24 | 000,076,056 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LEqdUsb.sys -- (LEqdUsb)
DRV:64bit: - [2011/09/02 01:30:24 | 000,066,840 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidFilt.Sys -- (LHidFilt)
DRV:64bit: - [2011/09/02 01:30:24 | 000,015,128 | ---- | M] (Logitech, Inc.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\LHidEqd.sys -- (LHidEqd)
DRV:64bit: - [2011/05/16 13:55:28 | 000,533,096 | ---- | M] (Realtek ) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\Rt64win7.sys -- (RTL8167)
DRV:64bit: - [2011/04/26 14:07:36 | 000,557,848 | ---- | M] (Intel Corporation) [Kernel | Boot | Running] -- C:\Windows\SysNative\drivers\iaStor.sys -- (iaStor)
DRV:64bit: - [2011/04/20 18:07:22 | 000,399,944 | ---- | M] (Texas Instruments Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tixhci.sys -- (tixhci)
DRV:64bit: - [2011/04/20 18:07:22 | 000,131,656 | ---- | M] (Texas Instruments Incorporated) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\tihub3.sys -- (tihub3)
DRV:64bit: - [2011/04/05 16:29:58 | 000,066,552 | ---- | M] (PalmSource, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\AceecaUSBDx64.sys -- (AceecaUSBDx64)
DRV:64bit: - [2011/03/25 21:21:10 | 000,349,736 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwampfl.sys -- (BTWAMPFL)
DRV:64bit: - [2011/03/25 21:21:06 | 000,138,280 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwavdt.sys -- (btwavdt)
DRV:64bit: - [2011/03/25 21:21:06 | 000,107,560 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwaudio.sys -- (btwaudio)
DRV:64bit: - [2011/03/25 21:21:06 | 000,039,464 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwl2cap.sys -- (btwl2cap)
DRV:64bit: - [2011/03/25 21:21:06 | 000,021,416 | ---- | M] (Broadcom Corporation.) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\btwrchid.sys -- (btwrchid)
DRV:64bit: - [2010/11/20 22:23:48 | 000,071,168 | ---- | M] (Microsoft Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\dmvsc.sys -- (dmvsc)
DRV:64bit: - [2010/11/20 22:23:47 | 000,078,720 | ---- | M] (Hewlett-Packard Company) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\HpSAMD.sys -- (HpSAMD)
DRV:64bit: - [2010/10/19 06:34:26 | 000,056,344 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\HECIx64.sys -- (MEIx64)
DRV:64bit: - [2010/10/05 13:26:10 | 000,018,288 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacmoumonitor.sys -- (wacmoumonitor)
DRV:64bit: - [2010/10/05 13:26:02 | 000,012,848 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacommousefilter.sys -- (wacommousefilter)
DRV:64bit: - [2010/10/05 13:26:00 | 000,016,168 | ---- | M] (Wacom Technology) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\wacomvhid.sys -- (wacomvhid)
DRV:64bit: - [2010/03/22 22:39:20 | 003,060,800 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\BCMWL664.SYS -- (BCM43XX)
DRV:64bit: - [2010/03/12 18:21:52 | 000,097,280 | ---- | M] (Prolific Technology Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\ser2pl64.sys -- (Ser2pl)
DRV:64bit: - [2009/07/13 20:52:20 | 000,194,128 | ---- | M] (AMD Technologies Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\amdsbs.sys -- (amdsbs)
DRV:64bit: - [2009/07/13 20:48:04 | 000,065,600 | ---- | M] (LSI Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\lsi_sas2.sys -- (LSI_SAS2)
DRV:64bit: - [2009/07/13 20:45:55 | 000,024,656 | ---- | M] (Promise Technology) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\stexstor.sys -- (stexstor)
DRV:64bit: - [2009/06/10 15:37:05 | 006,108,416 | ---- | M] (Intel Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\igdkmd64.sys -- (igfx)
DRV:64bit: - [2009/06/10 15:34:33 | 003,286,016 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\evbda.sys -- (ebdrv)
DRV:64bit: - [2009/06/10 15:34:28 | 000,468,480 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\bxvbda.sys -- (b06bdrv)
DRV:64bit: - [2009/06/10 15:34:23 | 000,270,848 | ---- | M] (Broadcom Corporation) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\b57nd60a.sys -- (b57nd60a)
DRV:64bit: - [2009/06/10 15:31:59 | 000,031,232 | ---- | M] (Hauppauge Computer Works, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\hcw85cir.sys -- (hcw85cir)
DRV:64bit: - [2007/08/31 14:15:34 | 000,079,872 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emAudio64.sys -- (emAudio)
DRV:64bit: - [2007/06/21 17:51:46 | 000,215,808 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emDevice64.sys -- (DCamUSBEMPIA)
DRV:64bit: - [2007/06/21 17:51:32 | 000,006,400 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emFilter64.sys -- (FiltUSBEMPIA)
DRV:64bit: - [2007/06/21 17:51:30 | 000,006,144 | ---- | M] (eMPIA Technology, Inc.) [Kernel | On_Demand | Stopped] -- C:\Windows\SysNative\drivers\emScan64.sys -- (ScanUSBEMPIA)
DRV:64bit: - [2005/09/23 22:18:34 | 000,261,120 | ---- | M] (Pinnacle Systems GmbH) [Kernel | On_Demand | Running] -- C:\Windows\SysNative\drivers\MarvinBus64.sys -- (MarvinBus)
DRV - [2014/01/20 18:28:20 | 000,521,944 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\IPSDefs\20140303.001\IDSviA64.sys -- (IDSVia64)
DRV - [2013/12/17 19:32:10 | 001,526,488 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\BASHDefs\20140214.001\BHDrvx64.sys -- (BHDrvx64)
DRV - [2013/11/21 00:42:05 | 000,484,952 | ---- | M] (Symantec Corporation) [Kernel | System | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\eeCtrl64.sys -- (eeCtrl)
DRV - [2013/11/21 00:42:05 | 000,137,648 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys -- (EraserUtilRebootDrv)
DRV - [2013/11/13 01:00:00 | 002,099,288 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140304.018\ex64.sys -- (NAVEX15)
DRV - [2013/11/13 01:00:00 | 000,126,040 | ---- | M] (Symantec Corporation) [Kernel | On_Demand | Running] -- C:\Program Files (x86)\Norton Internet Security\NortonData\21.1.0.18\Definitions\VirusDefs\20140304.018\eng64.sys -- (NAVENG)
DRV - [2009/07/13 20:19:10 | 000,019,008 | ---- | M] (Microsoft Corporation) [File_System | On_Demand | Stopped] -- C:\Windows\SysWOW64\drivers\wimmount.sys -- (WIMMount)


========== Standard Registry (SafeList) ==========


========== Internet Explorer ==========

IE:64bit: - HKLM\..\SearchScopes,DefaultScope =
IE - HKLM\SOFTWARE\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
IE - HKLM\..\SearchScopes,DefaultScope =


IE - HKU\.DEFAULT\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\.DEFAULT\..\SearchScopes,DefaultScope =
IE - HKU\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-18\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-18\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-18\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0

IE - HKU\S-1-5-19\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-19\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-20\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://www.google.com
IE - HKU\S-1-5-20\..\SearchScopes,DefaultScope =

IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Search Bar =
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://my.myway.com/
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache = http://www.msn.com/
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache AcceptLangs = en-US
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page Redirect Cache_TIMESTAMP = 50 6D FC C0 69 36 CF 01 [binary data]
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyEnable" = 0
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings: "ProxyOverride" = *.local

IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Default_Page_URL = http://g.msn.com/HPDSK/1
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1008\SOFTWARE\Microsoft\Internet Explorer\Main,First Home Page = http://g.msn.com/HPDSK/1
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1008\SOFTWARE\Microsoft\Internet Explorer\Main,Start Page = http://g.msn.com/HPDSK/1
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1008\..\SearchScopes,DefaultScope =
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1008\..\SearchScopes\{0633EE93-D776-472f-A0FF-E1416B8B2E3A}: "URL" = http://www.bing.com/...rc=IE-SearchBox
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1008\..\SearchScopes\{2fa28606-de77-4029-af96-b231e3b8f827}: "URL" = http://search.ask.co...&l=dis&o=HPDTDF
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1008\..\SearchScopes\{3B83A2C8-E0A9-4604-A14C-E96435CD4D3A}: "URL" = http://www.amazon.co...s={searchTerms}
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1008\..\SearchScopes\{b7fca997-d0fb-4fe0-8afd-255e89cf9671}: "URL" = http://search.yahoo....psg&type=HPDTDF
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1008\..\SearchScopes\{d43b3890-80c7-4010-a95d-1e77b5924dc3}: "URL" = http://en.wikipedia....h={searchTerms}
IE - HKU\S-1-5-21-3563443419-2258996029-2686041776-1008\..\SearchScopes\{D944BB61-2E34-4DBF-A683-47E505C587DC}: "URL" = http://rover.ebay.co...w={searchTerms}


========== FireFox ==========

FF:64bit: - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\system32\Macromed\Flash\NPSWF64_12_0_0_70.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/DTPlugin,version=10.17.2: C:\Windows\system32\npDeployJava1.dll File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@java.com/JavaPlugin,version=10.17.2: C:\Program Files\Java\jre7\bin\plugin2\npjp2.dll (Oracle Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF:64bit: - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF:64bit: - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect_x86_64: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect64.dll (Adobe Systems)
FF - HKLM\Software\MozillaPlugins\@adobe.com/FlashPlayer: C:\Windows\SysWOW64\Macromed\Flash\NPSWF32_12_0_0_70.dll ()
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=: File not found
FF - HKLM\Software\MozillaPlugins\@Apple.com/iTunes,version=1.0: C:\Program Files (x86)\iTunes\Mozilla Plugins\npitunes.dll ()
FF - HKLM\Software\MozillaPlugins\@garmin.com/GpsControl: C:\Program Files (x86)\Garmin GPS Plugin\npGarmin.dll (GARMIN Corp.)
FF - HKLM\Software\MozillaPlugins\@Google.com/GoogleEarthPlugin: C:\Program Files (x86)\Google\Google Earth\plugin\npgeplugin.dll (Google)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/GENUINE: disabled File not found
FF - HKLM\Software\MozillaPlugins\@Microsoft.com/NpCtrl,version=1.0: c:\Program Files (x86)\Microsoft Silverlight\5.1.20913.0\npctrl.dll ( Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3502.0922: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@microsoft.com/WLPG,version=15.4.3508.1109: C:\Program Files (x86)\Windows Live\Photo Gallery\NPWLPG.dll (Microsoft Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVision: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dv.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@nvidia.com/3DVisionStreaming: C:\Program Files (x86)\NVIDIA Corporation\3D Vision\npnv3dvstreaming.dll (NVIDIA Corporation)
FF - HKLM\Software\MozillaPlugins\@palmsource.com/installer,version=1.0: C:\PROGRA~2\palmOne\PACKAG~1\NPInstal.dll ()
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=3: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@tools.google.com/Google Update;version=9: C:\Program Files (x86)\Google\Update\1.3.22.5\npGoogleUpdate3.dll (Google Inc.)
FF - HKLM\Software\MozillaPlugins\@wacom.com/wacom-plugin,version=1.1.0.5: C:\Program Files (x86)\TabletPlugins\npwacom.dll (Wacom, Inc.)
FF - HKLM\Software\MozillaPlugins\@WildTangent.com/GamesAppPresenceDetector,Version=1.0: C:\Program Files (x86)\WildTangent Games\App\BrowserIntegration\Registered\0\NP_wtapp.dll ()
FF - HKLM\Software\MozillaPlugins\Adobe Reader: C:\Program Files (x86)\Adobe\Reader 10.0\Reader\AIR\nppdf32.dll (Adobe Systems Inc.)
FF - HKLM\Software\MozillaPlugins\adobe.com/AdobeAAMDetect: C:\Program Files (x86)\Adobe\Adobe Creative Cloud\Utils\npAdobeAAMDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\adobe.com/AdobeExManCCDetect32: C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect32.dll (Adobe Systems)
FF - HKCU\Software\MozillaPlugins\adobe.com/AdobeExManCCDetect64: C:\Program Files (x86)\Adobe\Adobe Extension Manager CC\npAdobeExManCCDetect64.dll (Adobe Systems)

FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{2D3F3651-74B9-4795-BDEC-6DA2F431CB62}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\coFFPlgn\ [2014/03/04 10:28:54 | 000,000,000 | ---D | M]
FF - HKEY_LOCAL_MACHINE\software\mozilla\Firefox\Extensions\\{BBDA0591-3099-440a-AA10-41764D9DB4DB}: C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_21.1.0.18\IPSFF [2013/11/13 15:40:34 | 000,000,000 | ---D | M]

[2013/06/08 10:39:36 | 000,000,000 | ---D | M] (No name found) -- C:\Program Files (x86)\Mozilla Firefox\extensions

========== Chrome ==========

CHR - default_search_provider: Google (Enabled)
CHR - default_search_provider: search_url = {google:baseURL}search?q={searchTerms}&{google:RLZ}{google:originalQueryForSuggestion}{google:assistedQueryStats}{google:searchFieldtrialParameter}{google:bookmarkBarPinned}{google:searchClient}{google:sourceId}{google:instantExtendedEnabledParameter}{google:omniboxStartMarginParameter}ie={inputEncoding}
CHR - default_search_provider: suggest_url = {google:baseSuggestURL}search?{google:searchFieldtrialParameter}client={google:suggestClient}&gs_ri={google:suggestRid}&xssi=t&q={searchTerms}&{google:cursorPosition}{google:currentPageUrl}{google:pageClassification}sugkey={google:suggestAPIKeyParameter},
CHR - homepage: http://search.condui...PV=T21110_sp_ch
CHR - plugin: Error reading preferences file
CHR - Extension: Google Wallet = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_0\
CHR - Extension: Google Wallet = C:\Users\Glens\AppData\Local\Google\Chrome\User Data\Default\Extensions\nmmhkkegccagdldgiimedpiccmgmieda\0.0.6.1_1\

O1 HOSTS File: ([2014/03/04 10:24:58 | 000,000,098 | ---- | M]) - C:\Windows\SysNative\drivers\etc\Hosts
O1 - Hosts: 127.0.0.1 localhost
O1 - Hosts: ::1 localhost
O2:64bit: - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
O2:64bit: - BHO: (Java™ Plug-In SSV Helper) - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre7\bin\ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (Google Toolbar Helper) - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O2:64bit: - BHO: (Java™ Plug-In 2 SSV Helper) - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre7\bin\jp2ssv.dll (Oracle Corporation)
O2:64bit: - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll (Hewlett-Packard)
O2 - BHO: (Norton Identity Protection) - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coieplg.dll (Symantec Corporation)
O2 - BHO: (Norton Vulnerability Protection) - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\IPS\ipsbho.dll (Symantec Corporation)
O2 - BHO: (HP Network Check Helper) - {E76FD755-C1BA-4DCB-9F13-99BD91223ADE} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll (Hewlett-Packard)
O3:64bit: - HKLM\..\Toolbar: (Google Toolbar) - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O3:64bit: - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine64\21.1.0.18\CoIEPlg.dll (Symantec Corporation)
O3:64bit: - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\DLLx64\SnagitIEAddin64.dll (TechSmith Corporation)
O3:64bit: - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3 - HKLM\..\Toolbar: (Norton Toolbar) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files (x86)\Norton Internet Security\Engine\21.1.0.18\coieplg.dll (Symantec Corporation)
O3 - HKLM\..\Toolbar: (Snagit) - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files (x86)\TechSmith\Snagit 10\SnagitIEAddin.dll (TechSmith Corporation)
O3 - HKLM\..\Toolbar: (no name) - Locked - No CLSID value found.
O3:64bit: - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001\..\Toolbar\WebBrowser: (Google Toolbar) - {2318C2B1-4965-11D4-9B18-009027A5CD4F} - C:\Program Files (x86)\Google\Google Toolbar\GoogleToolbar_64.dll (Google Inc.)
O4:64bit: - HKLM..\Run: [AdobeAAMUpdater-1.0] C:\Program Files (x86)\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe (Adobe Systems Incorporated)
O4:64bit: - HKLM..\Run: [BeatsOSDApp] C:\Program Files\IDT\WDM\beats64.exe (Hewlett-Packard )
O4:64bit: - HKLM..\Run: [hpsysdrv] c:\Program Files (x86)\Hewlett-Packard\HP Odometer\hpsysdrv.exe (Hewlett-Packard)
O4:64bit: - HKLM..\Run: [SysTrayApp] C:\Program Files\IDT\WDM\sttray64.exe (IDT, Inc.)
O4 - HKLM..\Run: [Adobe Creative Cloud] C:\Program Files (x86)\Adobe\Adobe Creative Cloud\ACC\Creative Cloud.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [AdobeCS5ServiceManager] C:\Program Files (x86)\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe (Adobe Systems Incorporated)
O4 - HKLM..\Run: [APSDaemon] C:\Program Files (x86)\Common Files\Apple\Apple Application Support\APSDaemon.exe (Apple Inc.)
O4 - HKLM..\Run: [EEventManager] C:\Program Files (x86)\EPSON\Creativity Suite\Event Manager\EEventManager.exe (SEIKO EPSON CORPORATION)
O4 - HKLM..\Run: [PMBVolumeWatcher] C:\Program Files (x86)\Sony\PlayMemories Home\PMBVolumeWatcher.exe (Sony Corporation)
O4 - HKU\S-1-5-19..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-20..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4 - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001..\Run: [AdobeBridge] File not found
O4 - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001..\Run: [GarminExpressTrayApp] C:\Program Files (x86)\Garmin\Express Tray\ExpressTray.exe (Garmin Ltd or its subsidiaries)
O4 - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001..\Run: [TivoNotify] C:\Program Files (x86)\TiVo\Desktop\TiVoNotify.exe (TiVo Inc.)
O4 - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001..\Run: [TivoServer] C:\Program Files (x86)\TiVo\Desktop\TiVoServer.exe (TiVo Inc.)
O4 - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001..\Run: [TivoTransfer] C:\Program Files (x86)\TiVo\Desktop\TiVoTransfer.exe (TiVo Inc.)
O4 - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001..\Run: [TranscodingService] C:\Program Files (x86)\TiVo\Desktop\Plus\\TranscodingService.exe ()
O4 - HKU\S-1-5-21-3563443419-2258996029-2686041776-1008..\Run: [Sidebar] C:\Program Files (x86)\Windows Sidebar\Sidebar.exe (Microsoft Corporation)
O4:64bit: - HKLM..\RunOnce: [NCPluginUpdater] C:\Program Files (x86)\Hewlett-Packard\HP Health Check\ActiveCheck\product_line\NCPluginUpdater.exe (Hewlett-Packard)
O4 - HKU\S-1-5-19..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-20..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - HKU\S-1-5-21-3563443419-2258996029-2686041776-1008..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe File not found
O4 - Startup: C:\Users\Glens\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Dropbox.lnk = C:\Users\Glens\AppData\Roaming\Dropbox\bin\Dropbox.exe (Dropbox, Inc.)
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktop = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoActiveDesktopChanges = 1
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorAdmin = 5
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: ConsentPromptBehaviorUser = 3
O6 - HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\System: PromptOnSecureDesktop = 0
O7 - HKU\S-1-5-21-3563443419-2258996029-2686041776-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\Explorer: NoDriveTypeAutoRun = 145
O9:64bit: - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9:64bit: - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPluginx64.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9:64bit: - Extra Button: @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9:64bit: - Extra 'Tools' menuitem : @c:\Program Files\WIDCOMM\Bluetooth Software\btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra Button: @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-103 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra 'Tools' menuitem : @C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\HPNetworkCheckPlugin.dll,-102 - {25510184-5A38-4A99-B273-DCA8EEF6CD08} - C:\Program Files (x86)\Hewlett-Packard\HP Support Framework\Resources\HPNetworkCheck\NCLauncherFromIE.exe (Hewlett-Packard)
O9 - Extra Button: Send To Bluetooth - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O9 - Extra 'Tools' menuitem : Send to &Bluetooth Device... - {CCA281CA-C863-46ef-9331-5C8D4460577F} - c:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htm ()
O10:64bit: - NameSpace_Catalog5\Catalog_Entries64\000000000010 [] - C:\Program Files\Bonjour\mdnsNSP.dll (Apple Inc.)
O10 - NameSpace_Catalog5\Catalog_Entries\000000000010 [] - C:\Program Files (x86)\Bonjour\mdnsNSP.dll (Apple Inc.)
O1364bit: - gopher Prefix: missing
O13 - gopher Prefix: missing
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} http://download.micr...heckControl.cab (Windows Genuine Advantage Validation Tool)
O16 - DPF: {73ECB3AA-4717-450C-A2AB-D00DAD9EE203} http://h20614.www2.h...pdetect1263.cab (GMNRev Class)
O16 - DPF: {B1E2B96C-12FE-45E2-BEF1-44A219113CDD} http://www.superadbl...ivex/sabspx.cab (SABScanProcesses Class)
O16 - DPF: {E06E2E99-0AA1-11D4-ABA6-0060082AA75C} https://linksyssuppo...rt/ieatgpc1.cab (GpcContainer Class)
O16 - DPF: Garmin Communicator Plug-In https://static.garmi...xControl_32.CAB (Reg Error: Key error.)
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: DhcpNameServer = 207.69.188.186 207.69.188.187 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{1F967591-0D7C-44B2-AED9-B9411FB2D3A5}: DhcpNameServer = 207.69.188.186 207.69.188.187 192.168.1.1
O17 - HKLM\System\CCS\Services\Tcpip\Parameters\Interfaces\{36AC44C1-9AA8-4744-805E-935E2827B256}: DhcpNameServer = 207.69.188.186 207.69.188.187 192.168.1.1
O18:64bit: - Protocol\Handler\belarc - No CLSID value found
O18:64bit: - Protocol\Handler\livecall - No CLSID value found
O18:64bit: - Protocol\Handler\ms-help - No CLSID value found
O18:64bit: - Protocol\Handler\msnim - No CLSID value found
O18:64bit: - Protocol\Handler\wlmailhtml - No CLSID value found
O18:64bit: - Protocol\Handler\wlpg - No CLSID value found
O18 - Protocol\Handler\belarc {6318E0AB-2E93-11D1-B8ED-00608CC9A71F} - C:\Program Files (x86)\Belarc\Advisor\System\BAVoilaX.dll (Belarc, Inc.)
O20:64bit: - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\explorer.exe (Microsoft Corporation)
O20:64bit: - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysNative\userinit.exe (Microsoft Corporation)
O20 - HKLM Winlogon: Shell - (explorer.exe) - C:\Windows\SysWow64\explorer.exe (Microsoft Corporation)
O20 - HKLM Winlogon: UserInit - (C:\Windows\system32\userinit.exe) - C:\Windows\SysWOW64\userinit.exe (Microsoft Corporation)
O20:64bit: - Winlogon\Notify\LBTWlgn: DllName - (c:\program files\common files\logishrd\bluetooth\LBTWlgn.dll) - c:\Program Files\Common Files\Logishrd\Bluetooth\LBTWLgn.dll (Logitech, Inc.)
O21:64bit: - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O21 - SSODL: WebCheck - {E6FB5E20-DE35-11CF-9C87-00AA005127ED} - No CLSID value found.
O32 - HKLM CDRom: AutoRun - 1
O32 - AutoRun File - [2008/02/05 18:15:08 | 000,000,034 | ---- | M] () - Y:\autorun.inf -- [ NTFS ]
O33 - MountPoints2\{0bba1dd7-04ba-11e1-8f1c-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{0bba1dd7-04ba-11e1-8f1c-d0df9aa5d807}\Shell\AutoRun\command - "" = I:\launcher.exe
O33 - MountPoints2\{0bba1ec5-04ba-11e1-8f1c-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{0bba1ec5-04ba-11e1-8f1c-d0df9aa5d807}\Shell\AutoRun\command - "" = J:\launcher.exe
O33 - MountPoints2\{30973883-1544-11e1-94b8-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{30973883-1544-11e1-94b8-d0df9aa5d807}\Shell\AutoRun\command - "" = I:\launcher.exe
O33 - MountPoints2\{3097389b-1544-11e1-94b8-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{3097389b-1544-11e1-94b8-d0df9aa5d807}\Shell\AutoRun\command - "" = I:\launcher.exe
O33 - MountPoints2\{98137975-1dc5-11e1-86c0-d0df9aa5d807}\Shell - "" = AutoRun
O33 - MountPoints2\{98137975-1dc5-11e1-86c0-d0df9aa5d807}\Shell\AutoRun\command - "" = H:\launcher.exe
O34 - HKLM BootExecute: (autocheck autochk *)
O35:64bit: - HKLM\..comfile [open] -- "%1" %*
O35:64bit: - HKLM\..exefile [open] -- "%1" %*
O35 - HKLM\..comfile [open] -- "%1" %*
O35 - HKLM\..exefile [open] -- "%1" %*
O37:64bit: - HKLM\...com [@ = comfile] -- "%1" %*
O37:64bit: - HKLM\...exe [@ = exefile] -- "%1" %*
O37 - HKLM\...com [@ = comfile] -- "%1" %*
O37 - HKLM\...exe [@ = exefile] -- "%1" %*
O38 - SubSystems\\Windows: (ServerDll=winsrv:UserServerDllInitialization,3)
O38 - SubSystems\\Windows: (ServerDll=winsrv:ConServerDllInitialization,2)
O38 - SubSystems\\Windows: (ServerDll=sxssrv,4)

========== Files/Folders - Created Within 30 Days ==========

[2014/03/04 10:44:34 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\ESET
[2014/03/04 10:40:46 | 002,347,384 | ---- | C] (ESET) -- C:\Users\Glens\Desktop\esetsmartinstaller_enu.exe
[2014/03/03 14:07:46 | 000,000,000 | ---D | C] -- C:\Windows\ERUNT
[2014/03/02 18:21:39 | 001,037,734 | ---- | C] (Thisisu) -- C:\Users\Glens\Desktop\JRT.exe
[2014/03/02 17:54:45 | 000,000,000 | ---D | C] -- C:\AdwCleaner
[2014/03/02 17:17:35 | 000,000,000 | ---D | C] -- C:\_OTL
[2014/02/27 12:29:58 | 000,000,000 | ---D | C] -- C:\Users\Glens\Documents\Malware files
[2014/02/27 11:07:51 | 000,602,112 | ---- | C] (OldTimer Tools) -- C:\Users\Glens\Desktop\OTL.exe
[2014/02/25 15:12:19 | 000,000,000 | ---D | C] -- C:\ProgramData\McAfee
[2014/02/25 14:51:17 | 006,574,592 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstscax.dll
[2014/02/25 14:51:17 | 005,694,464 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstscax.dll
[2014/02/25 14:19:29 | 000,044,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbGDCoInstaller.dll
[2014/02/25 14:19:20 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\drivers\TsUsbFlt.sys
[2014/02/25 14:19:20 | 000,013,824 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyControl.exe
[2014/02/25 14:19:20 | 000,012,800 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TsUsbRedirectionGroupPolicyExtension.dll
[2014/02/25 14:19:16 | 001,147,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\mstsc.exe
[2014/02/25 14:19:16 | 001,068,544 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\mstsc.exe
[2014/02/25 14:19:16 | 000,420,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprt.exe
[2014/02/25 14:19:16 | 000,083,968 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWbPrxy.exe
[2014/02/25 14:19:16 | 000,062,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\tsgqec.dll
[2014/02/25 14:19:16 | 000,056,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\MsRdpWebAccess.dll
[2014/02/25 14:19:16 | 000,053,248 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\tsgqec.dll
[2014/02/25 14:19:16 | 000,050,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\MsRdpWebAccess.dll
[2014/02/25 14:19:16 | 000,018,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\wksprtPS.dll
[2014/02/25 14:19:16 | 000,017,920 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\wksprtPS.dll
[2014/02/25 14:19:10 | 001,057,280 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\rdvidcrl.dll
[2014/02/25 14:19:10 | 000,855,552 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\rdvidcrl.dll
[2014/02/25 14:17:27 | 001,030,144 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\TSWorkspace.dll
[2014/02/25 14:17:26 | 000,792,576 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\TSWorkspace.dll
[2014/02/23 16:56:10 | 000,000,000 | ---D | C] -- C:\Users\Glens\Documents\Update Problem
[2014/02/23 15:40:55 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes' Anti-Malware (portable)
[2014/02/23 15:39:41 | 000,091,352 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/02/23 15:39:24 | 000,000,000 | ---D | C] -- C:\Users\Glens\MBAR
[2014/02/23 13:22:20 | 000,000,000 | ---D | C] -- C:\Users\Glens\AppData\Roaming\Malwarebytes
[2014/02/23 13:21:47 | 000,000,000 | ---D | C] -- C:\ProgramData\Malwarebytes
[2014/02/23 13:21:46 | 000,025,928 | ---- | C] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbam.sys
[2014/02/23 13:21:46 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Malwarebytes' Anti-Malware
[2014/02/22 17:06:05 | 000,000,000 | ---D | C] -- C:\Windows\Migration
[2014/02/22 15:07:46 | 000,000,000 | ---D | C] -- C:\Windows\CheckSur
[2014/02/22 14:07:11 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Stickies
[2014/02/20 17:55:08 | 000,210,216 | ---- | C] (Cisco WebEx LLC) -- C:\Windows\SysWow64\atsckernel.exe
[2014/02/20 17:55:06 | 000,118,056 | ---- | C] (Cisco WebEx LLC) -- C:\Windows\SysWow64\atashost.exe
[2014/02/20 17:54:38 | 000,000,000 | ---D | C] -- C:\ProgramData\WebEx
[2014/02/20 16:46:44 | 000,000,000 | ---D | C] -- C:\Users\Glens\AppData\Roaming\chc
[2014/02/19 15:06:19 | 000,000,000 | ---D | C] -- C:\Users\Glens\AppData\Local\ElevatedDiagnostics
[2014/02/18 18:37:34 | 000,000,000 | ---D | C] -- C:\Users\Glens\AppData\Roaming\Lavasoft
[2014/02/18 18:37:22 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Lavasoft Ad-Aware SE Personal
[2014/02/18 18:37:21 | 000,000,000 | ---D | C] -- C:\Program Files (x86)\Lavasoft
[2014/02/13 03:02:41 | 000,548,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\vbscript.dll
[2014/02/13 03:02:05 | 000,440,832 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/02/13 03:02:05 | 000,195,584 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/02/13 03:02:05 | 000,164,864 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/02/13 03:02:04 | 000,574,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/02/13 03:02:04 | 000,218,624 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/02/13 03:02:04 | 000,033,792 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/02/13 03:02:04 | 000,004,096 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/02/13 03:02:03 | 000,627,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/02/13 03:02:03 | 000,139,264 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/02/13 03:02:03 | 000,112,128 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/02/13 03:02:03 | 000,111,616 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/02/13 03:02:03 | 000,066,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/02/13 03:02:03 | 000,061,952 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/02/13 03:02:03 | 000,051,200 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/02/13 03:02:03 | 000,048,640 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/02/13 03:02:03 | 000,032,768 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/02/13 03:02:02 | 000,817,664 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/02/13 03:02:02 | 000,708,608 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/02/13 03:02:02 | 000,703,488 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[2014/02/13 03:02:02 | 000,553,472 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/02/13 03:02:01 | 002,041,856 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/02/13 03:02:01 | 001,964,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/02/13 03:01:59 | 005,768,704 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/02/12 17:25:40 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\msxml3r.dll
[2014/02/12 17:25:40 | 000,002,048 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msxml3r.dll
[2014/02/12 17:25:38 | 000,658,432 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_isv.exe
[2014/02/12 17:25:38 | 000,626,176 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate.exe
[2014/02/12 17:25:37 | 000,594,944 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_isv.exe
[2014/02/12 17:25:37 | 000,572,416 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate.exe
[2014/02/12 17:25:37 | 000,553,984 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp.exe
[2014/02/12 17:25:37 | 000,552,960 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\RMActivate_ssp_isv.exe
[2014/02/12 17:25:37 | 000,528,384 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\msdrm.dll
[2014/02/12 17:25:37 | 000,510,976 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp.exe
[2014/02/12 17:25:37 | 000,508,928 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\RMActivate_ssp_isv.exe
[2014/02/12 17:25:37 | 000,488,448 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc.dll
[2014/02/12 17:25:37 | 000,485,888 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_isv.dll
[2014/02/12 17:25:37 | 000,428,032 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc.dll
[2014/02/12 17:25:37 | 000,423,936 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_isv.dll
[2014/02/12 17:25:37 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp_isv.dll
[2014/02/12 17:25:37 | 000,123,392 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\secproc_ssp.dll
[2014/02/12 17:25:37 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp_isv.dll
[2014/02/12 17:25:37 | 000,087,040 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysWow64\secproc_ssp.dll
[2014/02/12 17:25:32 | 003,928,064 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d2d1.dll
[2014/02/12 17:25:32 | 002,565,120 | ---- | C] (Microsoft Corporation) -- C:\Windows\SysNative\d3d10warp.dll
[2014/02/06 12:13:08 | 000,000,000 | ---D | C] -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ThumbsPlus
[1 C:\Users\Glens\*.tmp files -> C:\Users\Glens\*.tmp -> ]

========== Files - Modified Within 30 Days ==========

[2014/03/04 21:57:00 | 000,000,830 | ---- | M] () -- C:\Windows\tasks\Adobe Flash Player Updater.job
[2014/03/04 21:51:00 | 000,000,896 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineUA.job
[2014/03/04 17:22:04 | 000,000,332 | ---- | M] () -- C:\Windows\tasks\HPCeeScheduleForGlens.job
[2014/03/04 15:13:52 | 000,782,470 | ---- | M] () -- C:\Windows\SysNative\PerfStringBackup.INI
[2014/03/04 15:13:52 | 000,662,384 | ---- | M] () -- C:\Windows\SysNative\perfh009.dat
[2014/03/04 15:13:52 | 000,122,252 | ---- | M] () -- C:\Windows\SysNative\perfc009.dat
[2014/03/04 14:51:01 | 000,000,892 | ---- | M] () -- C:\Windows\tasks\GoogleUpdateTaskMachineCore.job
[2014/03/04 10:40:46 | 002,347,384 | ---- | M] (ESET) -- C:\Users\Glens\Desktop\esetsmartinstaller_enu.exe
[2014/03/04 10:38:04 | 012,761,127 | ---- | M] () -- C:\Users\Glens\Desktop\Windows NT.rtf
[2014/03/04 10:36:21 | 000,027,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-1.C7483456-A289-439d-8115-601632D005A0
[2014/03/04 10:36:21 | 000,027,568 | -H-- | M] () -- C:\Windows\SysNative\7B296FB0-376B-497e-B012-9C450E1B7327-5P-0.C7483456-A289-439d-8115-601632D005A0
[2014/03/04 10:27:49 | 000,067,584 | --S- | M] () -- C:\Windows\bootstat.dat
[2014/03/04 10:27:28 | 4279,484,414 | -HS- | M] () -- C:\hiberfil.sys
[2014/03/04 10:24:58 | 000,000,098 | ---- | M] () -- C:\Windows\SysNative\drivers\etc\Hosts
[2014/03/04 09:22:15 | 000,002,185 | ---- | M] () -- C:\Users\Public\Desktop\Google Chrome.lnk
[2014/03/04 01:00:00 | 000,000,580 | ---- | M] () -- C:\Windows\tasks\b4a_Scrapbook Scans.job
[2014/03/04 00:40:00 | 000,000,568 | ---- | M] () -- C:\Windows\tasks\b4a_Favorites.job
[2014/03/04 00:30:15 | 000,000,574 | ---- | M] () -- C:\Windows\tasks\b4a_Glens Videos.job
[2014/03/04 00:30:14 | 000,000,610 | ---- | M] () -- C:\Windows\tasks\b4a_Glens HP to Bank non Zphoto.job
[2014/03/04 00:30:14 | 000,000,596 | ---- | M] () -- C:\Windows\tasks\b4a_Photo to velma - Photos.job
[2014/03/04 00:30:14 | 000,000,590 | ---- | M] () -- C:\Windows\tasks\b4a_Mirror to X3 from TO.job
[2014/03/04 00:30:14 | 000,000,580 | ---- | M] () -- C:\Windows\tasks\b4a_Digital Current.job
[2014/03/04 00:30:14 | 000,000,574 | ---- | M] () -- C:\Windows\tasks\b4a_Zphotol to O.job
[2014/03/04 00:30:14 | 000,000,574 | ---- | M] () -- C:\Windows\tasks\b4a_Weather data.job
[2014/03/04 00:30:14 | 000,000,572 | ---- | M] () -- C:\Windows\tasks\b4a_Active Data.job
[2014/03/04 00:30:14 | 000,000,558 | ---- | M] () -- C:\Windows\tasks\b4a_Other Photo.job
[2014/03/02 18:21:41 | 001,037,734 | ---- | M] (Thisisu) -- C:\Users\Glens\Desktop\JRT.exe
[2014/02/27 15:06:47 | 000,692,616 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerApp.exe
[2014/02/27 15:06:47 | 000,071,048 | ---- | M] (Adobe Systems Incorporated) -- C:\Windows\SysWow64\FlashPlayerCPLApp.cpl
[2014/02/27 11:10:12 | 000,001,864 | ---- | M] () -- C:\Users\Glens\Desktop\OTL.exe - Shortcut.lnk
[2014/02/27 11:07:52 | 000,602,112 | ---- | M] (OldTimer Tools) -- C:\Users\Glens\Desktop\OTL.exe
[2014/02/26 10:57:03 | 000,001,303 | ---- | M] () -- C:\Users\Public\Desktop\Adobe Creative Cloud.lnk
[2014/02/24 11:25:27 | 000,000,349 | ---- | M] () -- C:\Users\Public\Documents\PCLECHAL.INI
[2014/02/23 16:57:12 | 000,001,208 | ---- | M] () -- C:\Users\Glens\Documents\details of KB954430 instal.rtf
[2014/02/23 15:39:41 | 000,091,352 | ---- | M] (Malwarebytes Corporation) -- C:\Windows\SysNative\drivers\mbamchameleon.sys
[2014/02/23 13:21:47 | 000,001,115 | ---- | M] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/02/22 17:26:20 | 000,774,592 | ---- | M] () -- C:\Windows\SysWow64\PerfStringBackup.INI
[2014/02/22 14:24:08 | 000,001,013 | ---- | M] () -- C:\Users\Glens\Desktop\stickies.chm - HELP.lnk
[2014/02/22 14:07:12 | 000,001,049 | ---- | M] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Stickies.lnk
[2014/02/22 14:07:12 | 000,000,625 | ---- | M] () -- C:\Windows\uninstallstickies.bat
[2014/02/20 17:55:04 | 000,210,216 | ---- | M] (Cisco WebEx LLC) -- C:\Windows\SysWow64\atsckernel.exe
[2014/02/20 17:55:04 | 000,118,056 | ---- | M] (Cisco WebEx LLC) -- C:\Windows\SysWow64\atashost.exe
[2014/02/17 12:41:35 | 000,007,663 | ---- | M] () -- C:\Users\Glens\AppData\Local\Resmon.ResmonCfg
[2014/02/15 14:36:23 | 000,001,456 | ---- | M] () -- C:\Users\Glens\AppData\Local\Adobe Save for Web 13.0 Prefs
[2014/02/13 13:21:03 | 010,094,603 | ---- | M] () -- C:\Users\Glens\Desktop\bird1.mp4
[2014/02/13 12:39:44 | 000,012,288 | ---- | M] () -- C:\Users\Glens\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2014/02/13 11:39:13 | 000,000,080 | ---- | M] () -- C:\Users\Glens\Videos.scn
[2014/02/06 12:13:12 | 000,001,089 | ---- | M] () -- C:\Users\Glens\Application Data\Microsoft\Internet Explorer\Quick Launch\ThumbsPlus 9.lnk
[2014/02/06 12:13:12 | 000,001,065 | ---- | M] () -- C:\Users\Glens\Desktop\ThumbsPlus 9.lnk
[2014/02/06 12:13:12 | 000,000,251 | ---- | M] () -- C:\Windows\ODBCINST.INI
[2014/02/06 11:49:50 | 000,000,308 | ---- | M] () -- C:\CD Drive - Shortcut.lnk
[2014/02/06 06:30:12 | 000,004,096 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollectorres.dll
[2014/02/06 06:07:39 | 000,066,048 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iesetup.dll
[2014/02/06 06:06:47 | 000,048,640 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwproxystub.dll
[2014/02/06 05:56:03 | 000,033,792 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\iernonce.dll
[2014/02/06 05:52:11 | 000,574,976 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieui.dll
[2014/02/06 05:49:03 | 000,139,264 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieUnatt.exe
[2014/02/06 05:48:45 | 000,111,616 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieetwcollector.exe
[2014/02/06 05:48:11 | 000,708,608 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9diag.dll
[2014/02/06 05:32:49 | 000,218,624 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ie4uinit.exe
[2014/02/06 05:17:15 | 000,195,584 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msrating.dll
[2014/02/06 05:11:37 | 005,768,704 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\jscript9.dll
[2014/02/06 05:01:36 | 000,061,952 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iesetup.dll
[2014/02/06 05:00:46 | 000,051,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieetwproxystub.dll
[2014/02/06 04:57:13 | 000,627,200 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\msfeeds.dll
[2014/02/06 04:52:21 | 000,032,768 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\iernonce.dll
[2014/02/06 04:50:32 | 002,041,856 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\inetcpl.cpl
[2014/02/06 04:49:22 | 000,440,832 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieui.dll
[2014/02/06 04:47:22 | 000,112,128 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieUnatt.exe
[2014/02/06 04:46:27 | 000,553,472 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\jscript9diag.dll
[2014/02/06 04:25:43 | 000,164,864 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\msrating.dll
[2014/02/06 04:09:30 | 001,964,032 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\inetcpl.cpl
[2014/02/06 03:40:06 | 000,817,664 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysNative\ieapfltr.dll
[2014/02/06 03:34:31 | 000,703,488 | ---- | M] (Microsoft Corporation) -- C:\Windows\SysWow64\ieapfltr.dll
[1 C:\Users\Glens\*.tmp files -> C:\Users\Glens\*.tmp -> ]

========== Files Created - No Company Name ==========

[2014/03/04 10:38:04 | 012,761,127 | ---- | C] () -- C:\Users\Glens\Desktop\Windows NT.rtf
[2014/02/27 11:10:12 | 000,001,864 | ---- | C] () -- C:\Users\Glens\Desktop\OTL.exe - Shortcut.lnk
[2014/02/23 16:57:12 | 000,001,208 | ---- | C] () -- C:\Users\Glens\Documents\details of KB954430 instal.rtf
[2014/02/23 13:21:47 | 000,001,115 | ---- | C] () -- C:\Users\Public\Desktop\Malwarebytes Anti-Malware.lnk
[2014/02/22 14:24:08 | 000,001,013 | ---- | C] () -- C:\Users\Glens\Desktop\stickies.chm - HELP.lnk
[2014/02/22 14:07:12 | 000,001,049 | ---- | C] () -- C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Startup\Stickies.lnk
[2014/02/22 14:07:12 | 000,000,625 | ---- | C] () -- C:\Windows\uninstallstickies.bat
[2014/02/13 13:20:17 | 010,094,603 | ---- | C] () -- C:\Users\Glens\Desktop\bird1.mp4
[2014/02/06 12:13:12 | 000,001,089 | ---- | C] () -- C:\Users\Glens\Application Data\Microsoft\Internet Explorer\Quick Launch\ThumbsPlus 9.lnk
[2014/02/06 12:13:12 | 000,001,065 | ---- | C] () -- C:\Users\Glens\Desktop\ThumbsPlus 9.lnk
[2014/02/06 11:49:50 | 000,000,308 | ---- | C] () -- C:\CD Drive - Shortcut.lnk
[2014/01/30 13:43:23 | 000,000,355 | ---- | C] () -- C:\Program Files\Homegroup - Shortcut.lnk
[2013/12/12 10:02:03 | 000,001,456 | ---- | C] () -- C:\Users\Glens\AppData\Local\Adobe Save for Web 13.0 Prefs
[2013/10/15 11:07:47 | 000,000,884 | RHS- | C] () -- C:\Users\Glens\ntuser.pol
[2013/08/30 13:14:57 | 000,001,185 | ---- | C] () -- C:\Users\Glens\VG pictures - Shortcut.lnk
[2013/06/13 13:32:36 | 000,000,132 | ---- | C] () -- C:\Users\Glens\AppData\Roaming\Adobe BMP Format CS5 Prefs
[2013/06/09 13:57:02 | 000,000,193 | ---- | C] () -- C:\Windows\WORDPAD.INI
[2013/06/09 07:02:02 | 000,033,958 | ---- | C] () -- C:\ProgramData\uninstaller.exe
[2013/05/05 16:55:41 | 000,000,132 | ---- | C] () -- C:\Users\Glens\AppData\Roaming\Adobe GIF Format CS5 Prefs
[2013/04/04 13:28:48 | 000,110,456 | ---- | C] () -- C:\Users\Glens\g2ax_customer_downloadhelper_win32_x86.exe
[2013/02/27 17:15:23 | 000,000,355 | ---- | C] () -- C:\Users\Glens\Homegroup - Shortcut.lnk
[2012/10/13 06:59:15 | 000,000,080 | ---- | C] () -- C:\Users\Glens\Videos.scn
[2012/08/29 11:05:04 | 000,100,344 | ---- | C] () -- C:\Windows\HPBroker.dll
[2012/07/18 07:16:03 | 000,000,036 | ---- | C] () -- C:\Windows\hdd.ini
[2012/07/03 12:02:46 | 000,000,029 | ---- | C] () -- C:\Windows\DEBUGSM.INI
[2012/06/26 06:10:06 | 003,668,480 | ---- | C] () -- C:\Windows\SysWow64\CosmoRenderer.dll
[2012/05/17 10:31:19 | 000,012,288 | ---- | C] () -- C:\Users\Glens\AppData\Local\DCBC2A71-70D8-4DAN-EHR8-E0D61DEA3FDF.ini
[2012/03/09 10:47:07 | 000,000,077 | ---- | C] () -- C:\Windows\EPSPR2000.ini
[2012/01/21 09:31:05 | 000,031,104 | ---- | C] () -- C:\Users\Glens\energy-report.html
[2012/01/02 14:48:37 | 000,000,047 | ---- | C] () -- C:\Program Files (x86)\sleep.bat
[2012/01/01 10:05:04 | 000,007,663 | ---- | C] () -- C:\Users\Glens\AppData\Local\Resmon.ResmonCfg
[2011/11/11 04:40:29 | 000,002,217 | ---- | C] () -- C:\ProgramData\repository.xml
[2011/11/10 11:44:44 | 000,001,456 | ---- | C] () -- C:\Users\Glens\AppData\Local\Adobe Save for Web 12.0 Prefs
[2011/11/01 19:46:41 | 000,713,728 | ---- | C] () -- C:\Program Files (x86)\FCW32.EXE
[2011/11/01 19:46:41 | 000,550,322 | ---- | C] () -- C:\Program Files (x86)\CARLSBAD.FCW
[2011/11/01 19:46:41 | 000,455,079 | ---- | C] () -- C:\Program Files (x86)\ADINIT.DAT
[2011/11/01 19:46:41 | 000,399,360 | ---- | C] () -- C:\Program Files (x86)\XPDWG.DLL
[2011/11/01 19:46:41 | 000,248,343 | ---- | C] () -- C:\Program Files (x86)\CMHOUSE.FCW
[2011/11/01 19:46:41 | 000,189,922 | ---- | C] () -- C:\Program Files (x86)\ELECTRIC.FSC
[2011/11/01 19:46:41 | 000,187,904 | ---- | C] () -- C:\Program Files (x86)\FCWLANG.DLL
[2011/11/01 19:46:41 | 000,174,797 | ---- | C] () -- C:\Program Files (x86)\TALI.FCW
[2011/11/01 19:46:41 | 000,164,244 | ---- | C] () -- C:\Program Files (x86)\MERPLAZA.FCW
[2011/11/01 19:46:41 | 000,128,000 | ---- | C] () -- C:\Program Files (x86)\UNINST.EXE
[2011/11/01 19:46:41 | 000,127,613 | ---- | C] () -- C:\Program Files (x86)\SOLAR.FCW
[2011/11/01 19:46:41 | 000,067,584 | ---- | C] () -- C:\Program Files (x86)\NED3.EXE
[2011/11/01 19:46:41 | 000,066,073 | ---- | C] () -- C:\Program Files (x86)\NOZZLE.FCW
[2011/11/01 19:46:41 | 000,054,863 | ---- | C] () -- C:\Program Files (x86)\LOGIC.FCW
[2011/11/01 19:46:41 | 000,044,032 | ---- | C] () -- C:\Program Files (x86)\XPLDFCD.DLL
[2011/11/01 19:46:41 | 000,043,329 | ---- | C] () -- C:\Program Files (x86)\USA.FCW
[2011/11/01 19:46:41 | 000,039,585 | ---- | C] () -- C:\Program Files (x86)\PADEMO.FCW
[2011/11/01 19:46:41 | 000,035,718 | ---- | C] () -- C:\Program Files (x86)\TRAIN.FCW
[2011/11/01 19:46:41 | 000,034,082 | ---- | C] () -- C:\Program Files (x86)\GALLERY.FCW
[2011/11/01 19:46:41 | 000,032,854 | ---- | C] () -- C:\Program Files (x86)\STONE.BMP
[2011/11/01 19:46:41 | 000,018,432 | ---- | C] () -- C:\Program Files (x86)\XPPRINTA.DLL
[2011/11/01 19:46:41 | 000,017,143 | ---- | C] () -- C:\Program Files (x86)\LINWIDTH.GDE
[2011/11/01 19:46:41 | 000,016,192 | ---- | C] () -- C:\Program Files (x86)\60.GDE
[2011/11/01 19:46:41 | 000,015,118 | ---- | C] () -- C:\Program Files (x86)\LEAVES.BMP
[2011/11/01 19:46:41 | 000,014,947 | ---- | C] () -- C:\Program Files (x86)\PULLEY.FCW
[2011/11/01 19:46:41 | 000,014,469 | ---- | C] () -- C:\Program Files (x86)\PRINTEST.FCW
[2011/11/01 19:46:41 | 000,013,312 | ---- | C] () -- C:\Program Files (x86)\XPGUIDE.DLL
[2011/11/01 19:46:41 | 000,013,009 | ---- | C] () -- C:\Program Files (x86)\FCDLOGO.FCW
[2011/11/01 19:46:41 | 000,012,288 | ---- | C] () -- C:\Program Files (x86)\XPLDECW.DLL
[2011/11/01 19:46:41 | 000,012,159 | ---- | C] () -- C:\Program Files (x86)\SYMCAT.GDE
[2011/11/01 19:46:41 | 000,011,776 | ---- | C] () -- C:\Program Files (x86)\XPSYMCAT.DLL
[2011/11/01 19:46:41 | 000,010,752 | ---- | C] () -- C:\Program Files (x86)\XPENT.DLL
[2011/11/01 19:46:41 | 000,010,062 | ---- | C] () -- C:\Program Files (x86)\BASICS.GDE
[2011/11/01 19:46:41 | 000,009,481 | ---- | C] () -- C:\Program Files (x86)\ACTDEMO.FCW
[2011/11/01 19:46:41 | 000,009,247 | ---- | C] () -- C:\Program Files (x86)\COLORS.FCW
[2011/11/01 19:46:41 | 000,009,141 | ---- | C] () -- C:\Program Files (x86)\TABLET.FCW
[2011/11/01 19:46:41 | 000,008,704 | ---- | C] () -- C:\Program Files (x86)\XPACT.DLL
[2011/11/01 19:46:41 | 000,008,124 | ---- | C] () -- C:\Program Files (x86)\3D.FCW
[2011/11/01 19:46:41 | 000,008,093 | ---- | C] () -- C:\Program Files (x86)\LSTYLES.fcw
[2011/11/01 19:46:41 | 000,008,012 | ---- | C] () -- C:\Program Files (x86)\FILLS.FCW
[2011/11/01 19:46:41 | 000,007,674 | ---- | C] () -- C:\Program Files (x86)\FCAD3.MNU
[2011/11/01 19:46:41 | 000,007,655 | ---- | C] () -- C:\Program Files (x86)\SYM.FCW
[2011/11/01 19:46:41 | 000,007,644 | ---- | C] () -- C:\Program Files (x86)\MULTIFIL.GDE
[2011/11/01 19:46:41 | 000,007,612 | ---- | C] () -- C:\Program Files (x86)\FCW32.MNU
[2011/11/01 19:46:41 | 000,007,537 | ---- | C] () -- C:\Program Files (x86)\SCREEN.GDE
[2011/11/01 19:46:41 | 000,007,521 | ---- | C] () -- C:\Program Files (x86)\GREEK.FNT
[2011/11/01 19:46:41 | 000,007,049 | ---- | C] () -- C:\Program Files (x86)\60NEW.FCW
[2011/11/01 19:46:41 | 000,006,933 | ---- | C] () -- C:\Program Files (x86)\CARTGRID.FCW
[2011/11/01 19:46:41 | 000,006,866 | ---- | C] () -- C:\Program Files (x86)\SMARTSYM.FCW
[2011/11/01 19:46:41 | 000,006,667 | ---- | C] () -- C:\Program Files (x86)\LESSON12.FCW
[2011/11/01 19:46:41 | 000,006,649 | ---- | C] () -- C:\Program Files (x86)\BURNER.FCW
[2011/11/01 19:46:41 | 000,006,545 | ---- | C] () -- C:\Program Files (x86)\LDIMS.FCW
[2011/11/01 19:46:41 | 000,006,274 | ---- | C] () -- C:\Program Files (x86)\CARTANGL.FCW
[2011/11/01 19:46:41 | 000,006,258 | ---- | C] () -- C:\Program Files (x86)\LWIDTHT.FCW
[2011/11/01 19:46:41 | 000,006,250 | ---- | C] () -- C:\Program Files (x86)\METRIC.FCT
[2011/11/01 19:46:41 | 000,006,169 | ---- | C] () -- C:\Program Files (x86)\ENGLISH.FCT
[2011/11/01 19:46:41 | 000,006,036 | ---- | C] () -- C:\Program Files (x86)\FANCY.FNT
[2011/11/01 19:46:41 | 000,005,728 | ---- | C] () -- C:\Program Files (x86)\PICTS.FCW
[2011/11/01 19:46:41 | 000,005,712 | ---- | C] () -- C:\Program Files (x86)\HANDW.FNT
[2011/11/01 19:46:41 | 000,005,632 | ---- | C] () -- C:\Program Files (x86)\XPASAVE.DLL
[2011/11/01 19:46:41 | 000,005,484 | ---- | C] () -- C:\Program Files (x86)\LESSON9.FCW
[2011/11/01 19:46:41 | 000,005,356 | ---- | C] () -- C:\Program Files (x86)\FSTYLES.FCW
[2011/11/01 19:46:41 | 000,005,175 | ---- | C] () -- C:\Program Files (x86)\LESSON8.FCW
[2011/11/01 19:46:41 | 000,005,105 | ---- | C] () -- C:\Program Files (x86)\MYSYMBOL.FCW
[2011/11/01 19:46:41 | 000,005,083 | ---- | C] () -- C:\Program Files (x86)\LWIDTH2.FCW
[2011/11/01 19:46:41 | 000,005,083 | ---- | C] () -- C:\Program Files (x86)\LWIDTH1.FCW
[2011/11/01 19:46:41 | 000,004,996 | ---- | C] () -- C:\Program Files (x86)\SQUARE.FCW
[2011/11/01 19:46:41 | 000,004,994 | ---- | C] () -- C:\Program Files (x86)\PALABEL.FCW
[2011/11/01 19:46:41 | 000,004,749 | ---- | C] () -- C:\Program Files (x86)\LESSON10.FCW
[2011/11/01 19:46:41 | 000,004,349 | ---- | C] () -- C:\Program Files (x86)\HELV.FNT
[2011/11/01 19:46:41 | 000,004,306 | ---- | C] () -- C:\Program Files (x86)\SMOOTH.FNT
[2011/11/01 19:46:41 | 000,004,227 | ---- | C] () -- C:\Program Files (x86)\HELVNRW.FNT
[2011/11/01 19:46:41 | 000,003,695 | ---- | C] () -- C:\Program Files (x86)\SYMBOLS.GDE
[2011/11/01 19:46:41 | 000,003,660 | ---- | C] () -- C:\Program Files (x86)\SLANT.FNT
[2011/11/01 19:46:41 | 000,003,541 | ---- | C] () -- C:\Program Files (x86)\STDTEXT.FNT
[2011/11/01 19:46:41 | 000,003,263 | ---- | C] () -- C:\Program Files (x86)\FCW32.IMN
[2011/11/01 19:46:41 | 000,003,079 | ---- | C] () -- C:\Program Files (x86)\AGRID.FCW
[2011/11/01 19:46:41 | 000,002,841 | ---- | C] () -- C:\Program Files (x86)\521.GDE
[2011/11/01 19:46:41 | 000,002,748 | ---- | C] () -- C:\Program Files (x86)\FONTS.GDE
[2011/11/01 19:46:41 | 000,002,460 | ---- | C] () -- C:\Program Files (x86)\TGRID.FCW
[2011/11/01 19:46:41 | 000,002,382 | ---- | C] () -- C:\Program Files (x86)\PENTEST.FCW
[2011/11/01 19:46:41 | 000,001,266 | ---- | C] () -- C:\Program Files (x86)\FCW32.MAC
[2011/11/01 19:46:41 | 000,001,117 | ---- | C] () -- C:\Program Files (x86)\SOLAR.MNU
[2011/11/01 19:46:41 | 000,000,756 | ---- | C] () -- C:\Program Files (x86)\START.GDE
[2011/11/01 19:46:41 | 000,000,745 | ---- | C] () -- C:\Program Files (x86)\NEW60.GDE
[2011/11/01 19:46:41 | 000,000,745 | ---- | C] () -- C:\Program Files (x86)\NEW521.GDE
[2011/11/01 19:46:41 | 000,000,606 | ---- | C] () -- C:\Program Files (x86)\ACTDEMO.MAC
[2011/11/01 19:46:41 | 000,000,603 | ---- | C] () -- C:\Program Files (x86)\INDEX.GDE
[2011/11/01 19:46:41 | 000,000,399 | ---- | C] () -- C:\Program Files (x86)\INTRO.GDE
[2011/11/01 19:46:41 | 000,000,310 | ---- | C] () -- C:\Program Files (x86)\HAMMER.BMP
[2011/11/01 19:46:41 | 000,000,246 | ---- | C] () -- C:\Program Files (x86)\TILE.BMP
[2011/11/01 19:46:41 | 000,000,039 | ---- | C] () -- C:\Program Files (x86)\NEW.GDE
[2011/10/22 18:01:38 | 000,002,792 | ---- | C] () -- C:\Program Files\HP SimplePass 2011

========== ZeroAccess Check ==========

[2009/07/13 23:55:00 | 000,000,227 | RHS- | M] () -- C:\Windows\assembly\Desktop.ini

[HKEY_CURRENT_USER\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]

[HKEY_CURRENT_USER\Software\Classes\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32] /64

[HKEY_CURRENT_USER\Software\Classes\Wow6432node\clsid\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InProcServer32]

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32] /64
"" = C:\Windows\SysNative\shell32.dll -- [2013/07/25 21:24:57 | 014,172,672 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{42aedc87-2188-41fd-b9a3-0c966feabec1}\InProcServer32]
"" = %SystemRoot%\system32\shell32.dll -- [2013/07/25 20:55:59 | 012,872,704 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Apartment

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\fastprox.dll -- [2009/07/13 20:40:51 | 000,909,312 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{5839FCA9-774D-42A1-ACDA-D6A79037F57F}\InProcServer32]
"" = %systemroot%\system32\wbem\fastprox.dll -- [2010/11/20 22:24:25 | 000,606,208 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Free

[HKEY_LOCAL_MACHINE\Software\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32] /64
"" = C:\Windows\SysNative\wbem\wbemess.dll -- [2009/07/13 20:41:56 | 000,505,856 | ---- | M] (Microsoft Corporation)
"ThreadingModel" = Both

[HKEY_LOCAL_MACHINE\Software\Wow6432Node\Classes\clsid\{F3130CDB-AA52-4C3A-AB32-85FFC23AF9C1}\InProcServer32]

========== LOP Check ==========

[2014/02/13 13:22:14 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Audacity
[2011/11/01 19:01:41 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Blio
[2014/02/20 16:46:44 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\chc
[2011/11/05 16:25:51 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
[2013/08/30 13:40:55 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\com.adobe.DC3Module.AdobeADC
[2014/03/04 10:30:30 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Dropbox
[2011/11/08 15:13:35 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Easy Duplicate Finder
[2012/11/14 11:05:52 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\EasyDuplicateFinder
[2011/11/04 19:52:00 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\EPSON
[2011/11/14 17:22:45 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Forte
[2013/05/05 13:19:12 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\GARMIN
[2011/11/06 13:19:05 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\HotSync
[2011/11/04 18:28:58 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Leadertech
[2011/11/06 11:54:27 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\NCH Swift Sound
[2011/11/19 10:20:21 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\proDAD
[2011/11/01 12:53:48 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Qualcomm
[2014/02/15 10:00:50 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\R-Wipe&Clean
[2011/12/01 15:53:11 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\Softland
[2011/11/10 08:42:30 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\StageManager.BD092818F67280F4B42B04877600987F0111B594.1
[2014/03/03 09:14:35 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\stickies
[2012/01/14 17:20:58 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\TechSmith
[2014/02/15 17:26:28 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\ThumbsPlus
[2011/11/01 16:51:56 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\WinBatch
[2013/03/26 08:57:36 | 000,000,000 | ---D | M] -- C:\Users\Glens\AppData\Roaming\ZinioReader4

========== Purity Check ==========



========== Alternate Data Streams ==========

@Alternate Data Stream - 198 bytes -> C:\ProgramData\Temp:21654C57

< End of report >

Checkup.txt from step 6

Results of screen317's Security Check version 0.99.79
Windows 7 Service Pack 1 x64 (UAC is enabled)
Internet Explorer 11
``````````````Antivirus/Firewall Check:``````````````
Windows Firewall Enabled!
Norton Internet Security
WMI entry may not exist for antivirus; attempting automatic update.
`````````Anti-malware/Other Utilities Check:`````````
Malwarebytes Anti-Malware version 1.75.0.1300
Adobe Flash Player 12.0.0.70 Flash Player out of Date!
Adobe Reader 10.1.9 Adobe Reader out of Date!
Google Chrome 33.0.1750.117
Google Chrome 33.0.1750.146
````````Process Check: objlist.exe by Laurent````````
Symantec Norton Online Backup NOBuAgent.exe
`````````````````System Health check`````````````````
Total Fragmentation on Drive C: 0%
````````````````````End of Log``````````````````````

Log.txt ESET online scan:

[email protected] as downloader log:
all ok
# version=8
# OnlineScannerApp.exe=1.0.0.1
# OnlineScanner.ocx=1.0.0.6920
# api_version=3.0.2
# EOSSerial=502c43526aa43a46957685a888fa23ec
# engine=17313
# end=finished
# remove_checked=true
# archives_checked=true
# unwanted_checked=true
# unsafe_checked=true
# antistealth_checked=true
# utc_time=2014-03-05 12:15:07
# local_time=2014-03-04 07:15:07 (-0500, Eastern Standard Time)
# country="United States"
# lang=1033
# osver=6.1.7601 NT Service Pack 1
# compatibility_mode=3591 16777213 100 88 1351533 156485092 0 0
# compatibility_mode=5893 16776574 100 94 19010520 145521957 0 0
# scanned=1232379
# found=68
# cleaned=68
# scan_time=30044
sh=526C685B52444130CD450DEC45826528AD21DFB2 ft=1 fh=8cfb9e08e6192fa7 vn="a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application (deleted - quarantined)" ac=C fn="C:\AdwCleaner\Quarantine\C\ProgramData\Ask\APN-Stub\WBM3\APNIC.dll.vir"
sh=97BCCD25561F44E9B13F05F6EEF083C9CE9BA529 ft=1 fh=641f1fb3d2e699c4 vn="Win32/Toolbar.Conduit.Y potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\Conduit-old\Community Alerts\Alert.dll"
sh=A033CC58A848309C839C636370383A81481BD426 ft=1 fh=cc9ff824932b8bdf vn="a variant of Win32/Toolbar.Conduit.H potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\NCH Software\Prism\prism.exe"
sh=31D8C3EDE22AFD8B1CA5CAC4FDD27A245F6CC7B6 ft=1 fh=5dda5872f4087e13 vn="a variant of Win32/Toolbar.Conduit.H potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\NCH Software\Prism\prismsetup_v1.82.exe"
sh=7841824088542F907AD2A804AE53FE62D201E298 ft=1 fh=36a1bcee932b8bdf vn="a variant of Win32/Toolbar.Conduit.H potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\NCH Software\Prism\uninst.exe"
sh=ECD883A1063580112DC9B270F17F2F052550A1C9 ft=1 fh=ee21ff8b8c096b47 vn="a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\NCH Software\TempoPerfect\tempoperfect.exe"
sh=25B160D297729659980C1310A9F44E58CA5DE427 ft=1 fh=a758d828b4be77df vn="a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\NCH Software\TempoPerfect\tempoperfectsetup_v3.06.exe"
sh=AD013DC22D67048F07EF20409D4244614F98AD5C ft=1 fh=06e5f03d5fcfade3 vn="a variant of Win32/Toolbar.Conduit.H potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\NCH Software\ToneGen\tnsetup_v3.02.exe"
sh=3F8C3DA895A93B1B4B8D75AD81E291B558DF937A ft=1 fh=74bd5c2798857287 vn="a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\NCH Software\ToneGen\tonegen.exe"
sh=01E12C47829AD164DF69067BDA3318F60AB2012D ft=1 fh=902d5e5aba45473c vn="a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\NCH Software\ToneGen\tonegensetup_v3.07.exe"
sh=D15AC1231AB6E375D4E5719D60B819A0BC970BEB ft=1 fh=dfd20b7536c29781 vn="a variant of Win32/Toolbar.Conduit.H potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Program Files (x86)\NCH Software\ToneGen\uninst.exe"
sh=A1280B1F085B8284DC157EC359BD1ADA091CFE7E ft=1 fh=d8aa3384d1249a40 vn="a variant of Win32/Toolbar.Conduit.P potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Glens\AppData\Local\Produtools_Manuals_2.1\ldrtbProd.dll"
sh=92E84D2216A7763D580E42FA2493CCF67D0D0560 ft=1 fh=e8efc42494afd9f6 vn="a variant of Win32/Toolbar.Conduit.B potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Glens\AppData\Local\Produtools_Manuals_2.1\tbProd.dll"
sh=ABF759CA3BFB16DE62197DD7C417AC5039A43AE0 ft=1 fh=1801af74030ebca1 vn="a variant of Win32/PriceGong.A potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Glens\AppData\Local\Produtools_Manuals_2.1\plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.5.3\bin\PriceGongIE.dll"
sh=E1D57D7AB45B2C7B5BC7A2E97C8365D535F50D42 ft=0 fh=0000000000000000 vn="a variant of Win32/Spy.VB.NSC trojan (deleted - quarantined)" ac=C fn="C:\Users\Glens\AppData\Roaming\Qualcomm\Eudora\attach\TT COPY.rar"
sh=60C77FF66F63F585FCE95C78FF44B513E2AAB9F9 ft=1 fh=17494879e4339ab3 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\Glens\Downloads\ccsetup400.exe"
sh=A4854C3C5A7277D3C02F88330D2023AAD3667533 ft=1 fh=818bd9cd8f0d2ffa vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\Glens\Downloads\ccsetup403.exe"
sh=ADF2AD3B94EB35DC371AB7A1A49B004B7C76BFA5 ft=1 fh=f95766f30bc4ebc6 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\Glens\Downloads\ccsetup406.exe"
sh=84460101AD0296C3200E585ECF1650FEF05DE682 ft=1 fh=1da5439e840e24b5 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\Glens\Downloads\rcsetup147.exe"
sh=09CC84E1C28FA6079B657564612203B315D7A84A ft=1 fh=c7c76b7f0612b720 vn="Win32/AdWare.iBryte.S application (cleaned by deleting - quarantined)" ac=C fn="C:\Users\Glens\Downloads\Setup.exe"
sh=3D84C7C0E316EAD02DD7A59E746EC798DAB8BC0C ft=1 fh=ce50a11e70bad71c vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\Glens\Downloads-Glens\CClean\ccsetup328.exe"
sh=60C77FF66F63F585FCE95C78FF44B513E2AAB9F9 ft=1 fh=17494879e4339ab3 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\Glens\Downloads-Glens\CClean\ccsetup400.exe"
sh=6A6CBEA394F0791F24002B96AF5AC5FE2B269BB2 ft=1 fh=aa459271b90173bd vn="Win32/InstallMonetizer.AF potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Glens\Downloads-Glens\Defrag\boost-speed-setup.exe"
sh=04B61B341EF0D6D849B69E4C25D57AFDB7F04F1F ft=1 fh=7865e3c5df5803f6 vn="a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\Glens\Downloads-Glens\Easy_duplicate_finder\easy_duplicate_setup.exe"
sh=31D8C3EDE22AFD8B1CA5CAC4FDD27A245F6CC7B6 ft=1 fh=5dda5872f4087e13 vn="a variant of Win32/Toolbar.Conduit.H potentially unwanted application (deleted - quarantined)" ac=C fn="C:\Users\Glens\Downloads-Glens\NCH MOVIE CONVERSION\Switch Sound File Comverter\prismsetup_v1.82.exe"
sh=3D84C7C0E316EAD02DD7A59E746EC798DAB8BC0C ft=1 fh=ce50a11e70bad71c vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\Glens\Downloads-Glens\New folder\ccsetup328.exe"
sh=C21295C5D9799C95DADBF50C8C73236159CB6EBB ft=1 fh=d7e1d79cf98f7108 vn="Win32/OpenCandy potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\Glens\Downloads-Glens\Smplayer\smplayer-0.8.6-ps-win32.exe"
sh=78271767C62EF85C1B851A420507804BB2AB97AA ft=1 fh=ea2be65b861dd2c8 vn="Win32/OpenCandy potentially unsafe application (deleted - quarantined)" ac=C fn="C:\Users\Glens\Downloads-Glens\Win Zip\winzip160.exe"
sh=73E0E41678D0E431715490F8A05801B84D369C2D ft=1 fh=c4f9ac627cfc565f vn="Win32/BrowseFox.C potentially unwanted application (deleted - quarantined)" ac=C fn="C:\_OTL\MovedFiles\03042014_102306\C_Program Files (x86)\EnhanceTronic\EnhanceTronicUninstall.exe"
sh=B0CE64B7E0EB8D26F49C468FC684192CB318B83A ft=1 fh=6656c3b046bc8132 vn="a variant of Win32/BrowseFox.G potentially unwanted application (deleted - quarantined)" ac=C fn="C:\_OTL\MovedFiles\03042014_102306\C_Program Files (x86)\EnhanceTronic\updateEnhanceTronic.exe"
sh=E7C3EB67F86E29DCD8DA609E83B66ACFDD918EE8 ft=0 fh=0000000000000000 vn="a variant of Win32/Spy.VB.NSC trojan (deleted - quarantined)" ac=C fn="P:\Backup Favorites\Favorites\310_C.zip"
sh=97BCCD25561F44E9B13F05F6EEF083C9CE9BA529 ft=1 fh=641f1fb3d2e699c4 vn="Win32/Toolbar.Conduit.Y potentially unwanted application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Program Files (x86)\Conduit-old\Community Alerts\Alert.dll"
sh=A033CC58A848309C839C636370383A81481BD426 ft=1 fh=cc9ff824932b8bdf vn="a variant of Win32/Toolbar.Conduit.H potentially unwanted application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Program Files (x86)\NCH Software\Prism\prism.exe"
sh=31D8C3EDE22AFD8B1CA5CAC4FDD27A245F6CC7B6 ft=1 fh=5dda5872f4087e13 vn="a variant of Win32/Toolbar.Conduit.H potentially unwanted application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Program Files (x86)\NCH Software\Prism\prismsetup_v1.82.exe"
sh=7841824088542F907AD2A804AE53FE62D201E298 ft=1 fh=36a1bcee932b8bdf vn="a variant of Win32/Toolbar.Conduit.H potentially unwanted application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Program Files (x86)\NCH Software\Prism\UNINST.EXE"
sh=ECD883A1063580112DC9B270F17F2F052550A1C9 ft=1 fh=ee21ff8b8c096b47 vn="a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Program Files (x86)\NCH Software\TempoPerfect\tempoperfect.exe"
sh=25B160D297729659980C1310A9F44E58CA5DE427 ft=1 fh=a758d828b4be77df vn="a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Program Files (x86)\NCH Software\TempoPerfect\tempoperfectsetup_v3.06.exe"
sh=AD013DC22D67048F07EF20409D4244614F98AD5C ft=1 fh=06e5f03d5fcfade3 vn="a variant of Win32/Toolbar.Conduit.H potentially unwanted application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Program Files (x86)\NCH Software\ToneGen\tnsetup_v3.02.exe"
sh=3F8C3DA895A93B1B4B8D75AD81E291B558DF937A ft=1 fh=74bd5c2798857287 vn="a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Program Files (x86)\NCH Software\ToneGen\tonegen.exe"
sh=01E12C47829AD164DF69067BDA3318F60AB2012D ft=1 fh=902d5e5aba45473c vn="a variant of Win32/Bundled.Toolbar.Google.C potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Program Files (x86)\NCH Software\ToneGen\tonegensetup_v3.07.exe"
sh=D15AC1231AB6E375D4E5719D60B819A0BC970BEB ft=1 fh=dfd20b7536c29781 vn="a variant of Win32/Toolbar.Conduit.H potentially unwanted application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Program Files (x86)\NCH Software\ToneGen\UNINST.EXE"
sh=526C685B52444130CD450DEC45826528AD21DFB2 ft=1 fh=8cfb9e08e6192fa7 vn="a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\ProgramData\Ask\APN-Stub\WBM3\APNIC.dll"
sh=A1280B1F085B8284DC157EC359BD1ADA091CFE7E ft=1 fh=d8aa3384d1249a40 vn="a variant of Win32/Toolbar.Conduit.P potentially unwanted application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\AppData\local\Produtools_Manuals_2.1\ldrtbProd.dll"
sh=92E84D2216A7763D580E42FA2493CCF67D0D0560 ft=1 fh=e8efc42494afd9f6 vn="a variant of Win32/Toolbar.Conduit.B potentially unwanted application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\AppData\local\Produtools_Manuals_2.1\tbProd.dll"
sh=ABF759CA3BFB16DE62197DD7C417AC5039A43AE0 ft=1 fh=1801af74030ebca1 vn="a variant of Win32/PriceGong.A potentially unwanted application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\AppData\local\Produtools_Manuals_2.1\Plugins\{5E1360DC-8FA8-40df-A8CD-FC3831B3634B}\3.5.3\bin\PriceGongIE.dll"
sh=E1D57D7AB45B2C7B5BC7A2E97C8365D535F50D42 ft=0 fh=0000000000000000 vn="a variant of Win32/Spy.VB.NSC trojan (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\AppData\Roaming\Qualcomm\Eudora\attach\TT COPY.rar"
sh=60C77FF66F63F585FCE95C78FF44B513E2AAB9F9 ft=1 fh=17494879e4339ab3 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\Downloads\ccsetup400.exe"
sh=A4854C3C5A7277D3C02F88330D2023AAD3667533 ft=1 fh=818bd9cd8f0d2ffa vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\Downloads\ccsetup403.exe"
sh=ADF2AD3B94EB35DC371AB7A1A49B004B7C76BFA5 ft=1 fh=f95766f30bc4ebc6 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\Downloads\ccsetup406.exe"
sh=84460101AD0296C3200E585ECF1650FEF05DE682 ft=1 fh=1da5439e840e24b5 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\Downloads\rcsetup147.exe"
sh=3D84C7C0E316EAD02DD7A59E746EC798DAB8BC0C ft=1 fh=ce50a11e70bad71c vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\Downloads-Glens\CClean\ccsetup328.exe"
sh=60C77FF66F63F585FCE95C78FF44B513E2AAB9F9 ft=1 fh=17494879e4339ab3 vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\Downloads-Glens\CClean\ccsetup400.exe"
sh=6A6CBEA394F0791F24002B96AF5AC5FE2B269BB2 ft=1 fh=aa459271b90173bd vn="Win32/InstallMonetizer.AF potentially unwanted application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\Downloads-Glens\Defrag\boost-speed-setup.exe"
sh=04B61B341EF0D6D849B69E4C25D57AFDB7F04F1F ft=1 fh=7865e3c5df5803f6 vn="a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\Downloads-Glens\Easy_duplicate_finder\easy_duplicate_setup.exe"
sh=31D8C3EDE22AFD8B1CA5CAC4FDD27A245F6CC7B6 ft=1 fh=5dda5872f4087e13 vn="a variant of Win32/Toolbar.Conduit.H potentially unwanted application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\Downloads-Glens\NCH MOVIE CONVERSION\Switch Sound File Comverter\prismsetup_v1.82.exe"
sh=3D84C7C0E316EAD02DD7A59E746EC798DAB8BC0C ft=1 fh=ce50a11e70bad71c vn="Win32/Bundled.Toolbar.Google.D potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\Downloads-Glens\New folder\ccsetup328.exe"
sh=C21295C5D9799C95DADBF50C8C73236159CB6EBB ft=1 fh=d7e1d79cf98f7108 vn="Win32/OpenCandy potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\Downloads-Glens\SMPlayer\smplayer-0.8.6-ps-win32.exe"
sh=78271767C62EF85C1B851A420507804BB2AB97AA ft=1 fh=ea2be65b861dd2c8 vn="Win32/OpenCandy potentially unsafe application (deleted - quarantined)" ac=C fn="R:\Data_02-26-14\Gen Data Backup\C\Users\Glens\Downloads-Glens\Win Zip\winzip160.exe"
sh=0B05EF00BA7CEEADEDF617E5A72A7CACAF08FE1A ft=0 fh=0000000000000000 vn="Java/Agent.BV trojan (cleaned by deleting - quarantined)" ac=C fn="Z:\Old Dell C Drive\C\Documents and Settings\Glen.GLENS-DELL\Application Data\Sun\Java\Deployment\cache\6.0\21\d50c015-35640813"
sh=591FF427C836067615AAA8532CA999B9D389D960 ft=0 fh=0000000000000000 vn="Java/Agent.BV trojan (cleaned by deleting - quarantined)" ac=C fn="Z:\Old Dell C Drive\C\Documents and Settings\Glen.GLENS-DELL\Application Data\Sun\Java\Deployment\cache\6.0\31\2f31845f-29158d6e"
sh=618BAE93F06718D5CC115FB464136B184F50C910 ft=0 fh=0000000000000000 vn="Java/Agent.BV trojan (cleaned by deleting - quarantined)" ac=C fn="Z:\Old Dell C Drive\C\Documents and Settings\Glen.GLENS-DELL\Application Data\Sun\Java\Deployment\cache\6.0\43\6b4d836b-501973cb"
sh=AE295385D4F268E7FFDC7FA0845F23C512DD76EB ft=0 fh=0000000000000000 vn="a variant of Java/Agent.BR trojan (cleaned by deleting - quarantined)" ac=C fn="Z:\Old Dell C Drive\C\Documents and Settings\Glen.GLENS-DELL\Application Data\Sun\Java\Deployment\cache\6.0\61\469f7ebd-1bdf8f44"
sh=613BDCDC4B16EB466124A549D021646EAFB70B7C ft=1 fh=9de8d346ff807dc8 vn="Win32/Bundled.Toolbar.Ask potentially unsafe application (deleted - quarantined)" ac=C fn="Z:\Old Dell C Drive\C\Documents and Settings\Glen.GLENS-DELL\Local Settings\Application Data\AskToolbar\SETUP.EXE"
sh=BAD46EEE370B186E64CC2C01E5CAE9A40A5F62E2 ft=0 fh=0000000000000000 vn="a variant of Win32/RegistryBooster potentially unwanted application (deleted - quarantined)" ac=C fn="Z:\Old Dell C Drive\C\Documents and Settings\Glen.GLENS-DELL\Local Settings\Application Data\Downloaded Installations\{1975FDD5-4BDD-4257-8D27-D8A4DA128159}\PCmover Professional.msi"
sh=73015CF7A92047C909187CA2463ED2D4CA391DE1 ft=1 fh=81fae6a0ae917d5c vn="a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application (deleted - quarantined)" ac=C fn="Z:\Old Dell C Drive\C\Documents and Settings\Glen.GLENS-DELL\My Documents\disk-defrag-setup.exe"
sh=0CB41D707440FB3A2B2570595E780A4955911A7D ft=0 fh=0000000000000000 vn="a variant of Win32/Bundled.Toolbar.Ask potentially unsafe application (deleted - quarantined)" ac=C fn="Z:\Old Dell C Drive\C\Windows\installer\6315563.msi"
sh=68AAF253E822A8F368C197AF04FDAF210F1219FD ft=1 fh=d45450c1d7a7f23b vn="a variant of Win32/RegistryBooster potentially unwanted application (deleted - quarantined)" ac=C fn="Z:\Old Dell D drive\Program Files\Laplink\PCmover\ThirdParty\registrybooster.exe"
sh=AB66BE42F5806EC658CB2DE8C83070F7C5824FA3 ft=1 fh=f6afa6d66a5184aa vn="a variant of Win32/PSWTool.PWDump.A potentially unsafe application (deleted - quarantined)" ac=C fn="Z:\Old Dell D drive\Program Files\Laplink\PCmover\x32\cppwdsvc.exe"
  • 0

#10
vgphoto

vgphoto

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
I checked this morning and the ar.voicefive.com popup still occurs in "marketwatch.com". When I first open Market Watch it seems to take a few seconds before the popup appears and it is blocked by IE. If I do nothing the popup request goes away until I click on something to view a new screen then it comes back. This cycle repeats as different screens are selected. So our activates to date have had no affect on ar.voicefive.com. I do not know of any harm it is doing. The other problem that we started with was that Adobe Flash would not install and work with IE. That has not been tested and will not be until you let me know that insulations can be done. I believe the machine responsiveness has been improved, but I can not quantify that.
I appreciate your work on this.

vgphotog
  • 0

#11
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts
Do you use Twitter? The problematic pop-up is said to be associated with it.

Also Dashlane is an important program to me it handles my passwords.

I see. Various anti-virus companies find it questionable. May I offer an alternative? If not, you may re-install the program at the end this clean-up.

  • Step 1

    You currently have the following outdated program(s) installed. I highly recommend that you perform an update. You will find the download link(s) for the new version(s) below.

    Adobe Flash Player -- Update
    Adobe Reader -- Update

    Note: Please untick any optional offers Adobe products might come with.
Uninstall the previous version(s) before installing the updated one(s). If you run into any errors, let me know.
  • Step 2

    Your Google Chrome settings have been altered by malware. Please reset them by following 'this' guide.
  • Step 3

    Your Internet Explorer settings have been altered by malware. Please reset them by doing the below:

  • Open Internet Explorer.
  • Click the gear icon and choose Internet options.
  • Go to the Advanced tab.
  • Click the Reset... button at the bottom.
  • Place a check on the only option and press Reset.
  • Your computer will be asked to reboot.
  • Test your browser and see whether pop-ups are still present.

Edited by Pyxis, 05 March 2014 - 12:55 PM.

  • 0

#12
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts
I decided to bump the thread to let you know I have updated my post. :)
  • 0

#13
vgphoto

vgphoto

    New Member

  • Topic Starter
  • Member
  • Pip
  • 7 posts
No, I do not use Twitter but it seems most sites are pushing it, including yours. I see the little t symbol on the line above.
I did the uninstall and install process for Adobe Flash and Adobe Reader. The installs went smoothly and they worked correctly.

I went through the reset steps for EI and Chrome. immediately after the reset process I opened Myway and Marketwatch to look for the popup. After maybe a minute it popped up and was blocked. It went away and came back a little later and I unblocked it to see what it was. It was an add for an online bank. The popup has not showed up again.

I reinstalled Dashlane and it restored without any problems. I have Dashlane on two other machines and it has not caused any problems and we are very pleased with its function.

How much cleanup work should I do to get rid of the diagnostic programs that were used?

Thank you very much for you work on this problem.

vgphoto
  • 0

#14
Pyxis

Pyxis

    Trusted Helper

  • Malware Removal
  • 1,228 posts
Thank you for your cooperation. Your logs show no sign of infection. Congratulations, your system is now clean. :thumbsup: Below are a few more steps you have to complete to ensure the good working condition of your system.

Remove Special Tools with OTL by OldTimer

Using this tool will remove all temporary, and unnecessary files still in your computer after using the tools I asked you to run earlier.

  • Double-click OTL.exe to run it. For Windows Vista and Windows 7 users, please run it as an administrator.

  • As seen on the interface, click the CleanUp button.
  • You will be asked to reboot after. Please allow it to do so by clicking Yes on the next prompt.
Set a Clean Restore Point

Doing this will prevent you from a possible reinfection. You see, malicious files try to save a copy of themselves in the System Volume Information storage. The latter is a protected directory; the best way to get rid of these possible copies is to do the step below. Since your system is now clean, it is essential to set a clean and working backup.

  • Navigate to Start, right-click Computer and click Properties.

    • On the left, click System protection.
    • Click Create.... Input any title and press Create.
    • Once done, press Close > OK.
    • Click Start > All Programs > Accessories > System Tools.
    • Right-click on Disk Cleanup. Run it as an administrator.
    • If you have more than one drive, select your default one (C:). Otherwise, wait for its initialization to finish.
    • Check the following boxes (you may choose to add more):
    • Temporary Internet Files
    • Recycle Bin
    • Temporary Files
  • Navigate to the More Options tab.
  • Under System Restore and Shadow Copies, click Cleanup... > Delete > OK.
I will now proceed to giving to tips on how to maintain your system as it is. You can do the following as a routine to ensure that your system will work properly. Anytime you encounter an infection again, please do not hesitate to go back here at Geeks to Go. :)

Keep Your Computer Updated

Your current Windows operating system needs to install additional updates which are important, one of which is the Service Pack. The latter and other updates contain fixes and patches to prevent attackers from compromising your system. It is imperative that you keep your system up-to-date by obtaining free updates whenever they are available.

Install the latest Service Pack by going 'here'. If you already have, continually visit the official 'Microsoft Windows Update' site to keep your system up-to-date. Update Java

One of the programs you use every day unknowingly is Java. It is necessary for a lot of applications thus you should make sure it is always up-to-date. Older versions may be prone to exploits and vulnerabilities.

  • Download the latest 'Java' installation and save it to your desktop.
    • You need to uninstall any previous Java installations.
    • For Windows XP: Navigate to Start > Control Panel > Add or Remove Programs.
    • For Windows Vista: Navigate to Start > Control Panel > Programs and Features or Uninstall a Program.
    • For Windows 7: Navigate to Start > Control Panel > Programs and Features or Uninstall a Program.
  • Search the list for previous installations of Java such as all versions below:
    • Java™ 7 Update 51
  • Proceed to uninstalling the old versions and install the one you've just downloaded.
Update Your Anti-Virus Every Day

UpdatingEnsuring that you have one anti-virus installed in your system is a good way to prevent being infected. You must always make sure to update your anti-virus every day; anti-virus companies see to to it that the latest definition updates are distributed to be in par with the growing advancement and propagation of malware. Your anti-virus is useless if you do not update it.

ScanningSet a scanning routine. Ensure that you do a full scan with your anti-virus monthly. This is part of maintaining a clean system--a scanning routine proves to be effective. You can never be sure when your computer has caught an infection.

Surf Safe

Alongside your anti-virus and firewall, various programs such as SpywareBlaster can be obtained to help you avoid malicious sites. Don't worry as it poses no conflict to your current installation. Please find the download link in the program's name below.

SpywareBlasterSpywareBlaster can help keep your system secure, without interfering with the "good side" of the web. Unlike other programs, it does not have to remain running in the background. It works alongside the programs you have to ensure safe surfing.

  • Just like your regular security programs, SpywareBlaster needs to be updated every day.

  • Open the program by clicking the icon.
  • Click Updates > Check For Updates.
  • If there happens to be an update, a Enable All Protection button will appear. Please click that button.
If you have any unresolved issues with regard to this thread or you need more :help: please ask me. I would assist you further, should it be required. Otherwise, enjoy your clean system.

:cheers:

Thank you.
  • 0

#15
Essexboy

Essexboy

    GeekU Moderator

  • Retired Staff
  • 69,964 posts
Since this issue appears to be resolved ... this Topic has been closed. Glad we could help. :)

If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread.

Everyone else please begin a New Topic.
  • 0






Similar Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users

As Featured On:

Microsoft Yahoo BBC MSN PC Magazine Washington Post HP